Last updated: 28 September 2026
Flow Metro ("the app") is an independent home-screen launcher for Android, published by Ashay Mandwarya ("we"). It is not affiliated with Microsoft. This policy explains exactly what the app accesses, why, and what does or does not leave your device. The short version: Flow Metro runs on your device and sends only the limited data listed below to the named provider for the feature you chose.
Flow Metro has no login. We do not ask for, collect, or store your name, email, phone number, or any personal identifier on our servers. We do not have servers that receive your personal content.
These permissions power launcher features. The data is read on your device and is not transmitted to Flow Metro:
| Access | Why |
|---|---|
| Contacts, call logs & messages | Show People and Threads content, call history, caller details and messaging views when you choose those features. Read and written on-device only; Flow does not upload this content. Threads asks for Android's default SMS app role before it uses SMS permissions. |
| Calendar | Show your events on the Calendar tile and in Cal Sense, add or edit events you create there, and fire their reminders. Read and written on-device only. |
| Photos, videos & audio | Show your gallery on the Photos tile, set a Start background, and list and play local media. Read on-device only; Flow does not upload these files by itself. |
| Notification access | Mirror notifications into the action center, tile badges, and toast banners. Notification content is processed on your device and is not sent anywhere. |
| Installed apps (query all packages) | List and launch your apps — the core job of a launcher. On-device only. |
| Files (optional) | File Sense can browse and manage device files after you grant its all-files access. File names and contents stay on the device unless you explicitly share or use a named cloud provider. |
| Accessibility service (optional) | Only if you explicitly accept the separate in-app disclosure and enable it: powers navigation overlays (a long press on Back opens recent apps), the global volume panel, the top-swipe action center, and locking the screen when you double-tap Start or when Flow's Glance clock or lock screen times out. It receives window-change events, the foreground package and volume-key events only; it does not retrieve window content, read screen text, take screenshots or transmit anything. |
| Bluetooth / Wi-Fi / network state | Reflect and toggle these from the action center quick toggles. On-device only. |
| Microphone (optional keyboard voice input) | Used only after you choose voice input in the Flow keyboard. Audio is passed to Android's selected speech recognizer; Flow does not store recordings. |
| Location (optional) | Local weather on the Weather tile, the city name in quick toggles and the map. Your position is read on the device; only a rounded position leaves it (see below). |
| Physical activity (optional) | The Steps tile shows today's step count from the phone's step counter. On-device only; Flow does not use Health Connect and sends no health data. |
| Usage access (optional) | Orders your recent apps in the app list. On-device only. |
| Alarms & reminders (optional) | Lets Cal Sense reminders fire at the exact minute. Without it Android may deliver them a few minutes late. |
| Lock screen, full-screen notifications and display over other apps (optional) | Show Flow's Glance clock and lock screen over Android's lock when the screen wakes, and show Flow toasts. On-device only. |
| Foreground work | A visible foreground service with a notification runs only while the Flow lock screen is turned on, or while a File Sense copy, move, zip or cloud transfer you started is running. It stops when the feature or the job ends. |
| Modify system settings (optional) | Lets action-center toggles change brightness and rotation. Android shows its own grant page. |
A few optional features contact third-party services. Each is limited to what the feature needs:
| Feature | What is sent | To whom |
|---|---|---|
| Weather tile | Your approximate location, rounded to about 1 km before it is sent, to return local weather. If the phone has no location fix, your IP address is used to estimate a city instead. You can instead set a default city, or leave weather unused. City names you search for. No account, no identifier. | Open-Meteo (open-meteo.com); ipwho.is for the IP estimate |
| Map | Standard map-tile requests for the area you view. | OpenStreetMap (tile.openstreetmap.org) |
| Wallpaper search (optional) | The search words you type and standard image requests. | Unsplash, Picsum |
| Pinned website tiles (optional) | The domain name of a website you pin, to fetch its icon. | The website itself, DuckDuckGo and Google icon services |
| Reddit tile (optional) | A standard request for Reddit's public front-page feed. No Reddit account is used. | |
| Album art | A standard image request for the cover art of the song playing, when the music app provides only a web address for it. | The music service's image server (for example Spotify) |
| Daily wallpaper (optional) | A standard image request to fetch the Bing image of the day. No personal data attached. | Bing / Microsoft |
| Optional cloud storage | OAuth authorization codes and access tokens only when you explicitly connect Google Drive, OneDrive or Dropbox; file bytes go to the provider you choose when you start a transfer. Tokens are stored encrypted on the device, and disconnecting the provider in File Sense removes them. | Google Drive, Microsoft OneDrive or Dropbox |
Flow Metro uses Google Firebase Analytics and Firebase Crashlytics to understand which features are used and to fix crashes. They receive anonymous feature events (for example "a quick toggle was used"), crash reports with device model and Android version, and a random app-instance identifier. They never receive your contacts, messages, call history, calendar, photos, files, notifications, location or typed text. Flow does not use the advertising identifier. You can turn analytics and crash reporting off at any time in Settings → privacy; to delete data already collected, email the address below. Firebase is operated by Google under the Firebase privacy terms.
The optional one-time "Metro Pro" unlock is processed by Google Play Billing. We never see or store your payment details; Google handles the transaction.
On-device data stays in the app's private storage and is removed when you uninstall. Any data sent to the third-party services above is transmitted over encrypted (HTTPS) connections. We run no servers of our own. Anonymous analytics and crash reports are kept in Firebase only for the retention period set in the Firebase console and are deleted on request.
Flow Metro is a general-audience utility intended for adults and is not directed at children. We do not knowingly collect data from children.
If this policy changes, we will update the "Last updated" date above and post the new version at this URL.
Questions about privacy? Email ashaymurceilago@gmail.com.