Privacy policy
This policy explains how ArkaType Intelligence Inc. handles information for FlowSense and the GetFlowSense portal.
Last updated: October 8, 2026. For privacy questions or requests, contact hani@arka-type.com.
The Mac app is currently in private testing and has not been distributed to external users. The app sections below describe that test implementation. Public downloads, purchases, and Mac account sign-in are not available through this portal.
Summary
- FlowSense inspects network traffic on your Mac and keeps its flow history in a local database on that Mac.
- Usage analytics and crash and error reports are separate choices. Both are off by default.
- Some features make external requests when used: metadata lookups, destination probes, model downloads, and connected external agents. Each is described below.
- The test account service uses Clerk. Google sign-in requests only your identifier, email, and basic profile.
- The portal stores one appearance preference in your browser and includes no analytics tracker.
- Downloads, pricing, checkout, license retrieval, and the changelog are not currently available.
Accounts and sign-in
Our test account service uses Clerk to handle identity and authentication. Its hosted sign-in domain is accounts.arka-type.com and the authentication API is clerk.arka-type.com. These services run on the arka-type.com domain even though the portal address is www.getflowsense.com. Google sign-in is currently limited to approved test users; native Mac sign-in configuration is not complete.
Google sign-in requests only the openid, email, and profile scopes. This gives the authentication service your Google account identifier, your email address, and basic profile information such as your name and profile image when Google supplies them. We use this to create or identify your FlowSense account and sign you in. These scopes do not grant access to Gmail, Google Drive, contacts, or calendars.
Clerk processes account and session information on our behalf, including account identifiers, sign-in status, and session records. Authentication requests also expose ordinary connection information, such as your IP address and browser details, to the authentication service. Clerk uses cookies to maintain authentication sessions; see Clerk's authentication cookie documentation.
Clerk states that its hosting is in the United States. Our configured maximum session lifetime is seven days, with no inactivity timeout. Session expiry ends authentication; it does not delete an account or establish how long Clerk retains security records.
Signing in does not authorize sharing your traffic records with us.
Traffic processing and local records
The Mac app uses the fs-dpi engine to inspect network traffic on your machine and records flow history in a local SQLite database. Records can include connection addresses and ports, detected applications and protocols, hostnames, timestamps, traffic volumes, and inspection metadata. FlowSense uses these records to show connections, history, insights, and rule behavior.
How long local history is kept depends on the engine configuration on your Mac, including whether age and database-size limits are enabled. There is no single retention period that applies to every installation.
Local storage does not mean every feature works without external requests. The metadata, intelligence, and diagnostics sections below describe the cases where information leaves your Mac.
Usage analytics and crash and error reports
The Mac app has two separate choices in Settings: usage analytics, and crash and error reports. Both are off by default. You can change either at any time.
If you enable usage analytics, FlowSense sends screen names and the outcomes of capture and rule actions to PostHog so we can understand how the product is used. Events carry a random installation identifier rather than your email or account identity, plus app release and runtime information. Events are filtered so they do not include raw flow logs, traffic addresses, hostnames, rule names, personal file paths, search text, or conversations. A random identifier does not make an upload anonymous: the receiving service sees the IP address it came from.
If you enable crash and error reports, selected operation logs, errors, and UI crash stacks go to PostHog so we can diagnose problems. UI reports are filtered to exclude traffic data and the personal content listed above. Under the current diagnostics terms, engine crash reports from fs-dpi go to Sentry. An engine report is a Crashpad minidump containing registers, thread stacks, and loaded modules. Stack data can contain fragments of the network traffic being processed at the time. An earlier diagnostics choice that covered only UI reports does not turn on engine crash reporting. Sentry processes the minidump, but storage of the original minidump as an attachment is disabled.
The configured PostHog and Sentry endpoints are in the United States and receive and may store the IP address of each upload. Turning a choice off attempts to cancel pending uploads and clear queued reports for that choice. If saving consent or clearing the app's telemetry queue fails, app reporting pauses. An engine configuration change can also fail: Settings reports the error, and the previous engine configuration may remain until the change succeeds. An engine upload already in progress may still arrive after you turn diagnostics off. These controls do not delete reports the services have already received. Removing or restoring the UI crash handler may require relaunching the app; Settings says so when it applies.
Metadata and intelligence features
The Mac app can request app descriptions and logos from DuckDuckGo. App-description lookups are on by default and permit app/provider-logo lookups too. These requests send detected app names or the corresponding website domains. Traffic-derived site and network logo lookups are off by default. When enabled, they send a domain, which can be derived from an observed hostname or network metadata. These requests expose the requested name or domain and your connection IP address to DuckDuckGo. The switches are under "Fetch additional metadata" in Settings.
When you run a destination probe, FlowSense makes the selected DNS lookup, ping, TCP connection, or HTTPS HEAD request. DNS queries go through your configured resolver; the other probes contact the selected destination, which receives the probe and your connection IP address. These are user-initiated network checks.
Downloading a local model contacts Hugging Face and its download infrastructure. For models requiring access, the app can use an optional Hugging Face read token. A token saved through FlowSense is stored in your Mac's Keychain; the app can also read an existing local token or environment configuration. The token is sent only to HTTPS requests to huggingface.co and is removed from redirected requests.
If you choose an installed connected agent, such as Codex or Claude, FlowSense supplies conversation context, selected traffic summaries, and the results of requested read-only tools to that agent. What the agent's provider does with that information depends on the provider and on your own account and configuration with it. This is a separate processing path from usage analytics and is not covered by the analytics choice. FlowSense's local-model inference runs on your Mac and does not itself send that inference context to an external model service.
The portal
The portal at www.getflowsense.com is a static site. It stores your light or dark appearance preference in your browser's local storage. It includes no website analytics tracker or download counter. Fonts and scripts are served from the portal itself, with none loaded from other servers.
Downloads, pricing, checkout, license retrieval, and the changelog are not available yet. The portal does not currently collect an email address or payment information, and this policy does not describe a payment processor or license service.
The public portal is hosted by Amazon Web Services using a private S3 origin in Northern California and CloudFront edge delivery. Website requests expose connection information, such as your IP address and browser details, to AWS. Processing is not confined to the S3 region. We do not enable S3 or CloudFront visitor access logs for this site. AWS may retain its own operational and security records under its service terms; disabling our access logs does not mean AWS receives no connection data.
Retention and your requests
We keep test account records in Clerk while the account exists, without a scheduled inactivity purge. You can request account deletion at the contact below. The hosted account page also shows a Delete account control. Deleting an account is separate from deleting telemetry or provider security records, and does not establish immediate erasure of provider backups. We keep no separate account or report exports or backups outside Clerk, PostHog, and Sentry.
PostHog Logs is configured for 14-day retention. Our paid PostHog plan has a seven-year event query-retention window, covering analytics and UI error/crash events; that window is not a promise that all stored copies are erased when it ends. Sentry's current trial has 90-day error-event retention. Retention for newly uploaded data can change with the provider plan; existing Sentry events retain the period set when ingested. Sentry documents backup lifetimes of 30 or 90 days depending on data type. We do not promise immediate erasure from provider backups or a fixed retention period for provider operational/security records.
Account identity is not attached to optional analytics and UI reports. We may need an installation identifier, event reference, or approximate time to locate a report, and some logs cannot be linked to an individual. We use the providers' available deletion tools or support where data can be located. Sentry's event deletion operates on an entire issue, and PostHog event deletion is asynchronous. Turning reporting off, signing out, or deleting a Clerk account does not delete past reports from these services.
To ask about your information, or to request access, correction, or deletion, contact hani@arka-type.com. Tell us which account or data your request concerns. We may need information to verify the request, and we will explain what we can do and any limits that apply. Do not send passwords or raw traffic logs with your request.
If you email us, we process your email address and message to handle your request and keep the correspondence in the contact mailbox as needed to document its handling. We do not maintain a separate portal visitor database.
Changes to this policy
We will update this page as the service and its data practices change and will change the "Last updated" date when we do.