Flow Self-Regulation Skills
A 14-day practice programme

Flow is a subjective state of ease, alignment and balance in autonomic nervous system regulation.

Flow delivers a structured 14-day programme of daily practices that support neuroregulation and autonomic functioning. It is licensed to research institutions and delivered to participants on their own phone.

What the programme is

An intervention delivery tool. Not a data capture system, and not a replacement for one.

Participants work through fourteen days of guided practices, short audio narration and written reflection. Each day carries its own theme and a small set of practices, sequenced so that skills build rather than accumulate.

The programme is not tied to any one condition or setting. Its first deployments are in clinical research, and it is designed to be equally usable for chronic health recovery and for general practice.

Daily Practices Short guided exercises with optional audio narration, sequenced by day.
Daily Reflection Written entries kept by the participant and visible only to them.
Ongoing Practice library The full set, browsable outside the day structure once encountered.
Ongoing Own routine Participants assemble a personal daily selection from what they have learned.

How participant data is handled

The short version, in full below. A detailed governance summary is available on request.

Held by Flow

  • participant identifier
  • password hash
  • project membership
  • programme progress
  • reflections
  • activity timestamps

Never held by Flow

  • name
  • email address
  • phone number
  • date of birth
  • any contactable identifier
The institution holds identity without content. Flow holds content without identity. The record connecting a participant identifier to a real person exists only in the institution's own register.
Where it lives
Australia. An Amazon Web Services region in Sydney, ap-southeast-2.
Separation between institutions
Database-level access controls. This is logical separation, not separate infrastructure, and we describe it that way.
Who can see reflections
The participant. Coordinators see status only - registered, locked, reset pending - never content.
Passwords
Stored as an unrecoverable hash. A coordinator can clear one; nobody can retrieve one.
Third-party analytics
None. Crash reporting captures device and error information only, and excludes participant content.
Retention
Determined by the institution under its own ethics approval, and actioned on its instruction.

Licensing

One licence per institution. Each study activated under it separately.

Annual, per institution

Institution licence

Platform maintenance, security patching, app store presence and operating system compatibility, database operation and backup, the practice content, and current governance documentation.

One-off, per study

Study activation

Configuration, study-specific orientation wording, coordinator provisioning and training, enrolment setup, and a defined support allocation for that study's duration.

Where responsibility sits. Flow owns the platform; the institution owns the study.
Flow The application and its builds, store submission, operating system compatibility, the database and its backups, security patching, uptime and incident detection, the practice content, coordinator tooling, and support to coordinators.
The institution Ethics approval, recruitment and consent, participant identity and the register, appointing and training coordinators, study-specific wording, first-line participant support, and its own data export and destruction.
Participant support Participants contact their own coordinator, never Flow. Flow does not know who an institution's participants are and cannot verify a person contacting it.

What we would want a reviewer to press us on

Listed deliberately. A reviewer finds these either way, and finding them listed is a different conversation.

  1. Separation is logical, not physical. One database with access controls, rather than one instance per institution. An institution requiring physical separation should raise it early; it is possible and priced differently.
  2. Flow is a small supplier. Business continuity is a genuine risk. The mitigation is data export on request and at termination, not redundancy of the supplier.
  3. Consent is recorded as a flag, not as a versioned record of the exact wording a participant saw. The institution's own consent records remain the authoritative ones.
  4. No retention schedule is enforced by Flow. The institution sets its position and instructs us.
  5. Some administration is not yet self-service. Enrolment provisioning and study setup are currently performed by Flow on request. A capability statement accompanies every licence and is re-verified on the day it is issued.

Enquiries

For licensing, governance and ethics correspondence, and to request the full data governance summary, the sub-processor list, or the licensee manual.

contact@flowselfregulation.com