nflo Sign in

Legal

Privacy Policy

The Bearded Developer Ltd — Last updated: August 2026

This Privacy Policy explains how The Bearded Developer Ltd (“we”, “us”, “our”) collects, uses, and protects your personal data when you use nflo (“the Service”) at my.nflo.app.

We are committed to handling your data responsibly and in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

The Bearded Developer Ltd is the data controller for personal data processed through nflo.

For any privacy-related questions or requests, contact us at: [email protected]

2. What data we collect

Account data

You can sign in with a Google account, a GitHub account, or a one-time link sent to your email address. Depending on the method you choose, we receive and store:

  • Your name, where the provider supplies one
  • Your email address
  • Your profile avatar URL, where the provider supplies one
  • An OAuth account reference (used to link your Google or GitHub login to your nflo account)
  • For email sign-in, a short-lived, single-use verification token that expires after 30 minutes

We never receive or store your Google or GitHub password, and we never post to either service on your behalf. nflo has no password of its own.

If you sign in with more than one method using the same verified email address, they resolve to a single nflo account rather than creating duplicates.

Content you create

nflo stores the data you enter while using the Service, including:

  • Clients, projects, and tasks (titles, descriptions, statuses, priorities, due dates, points)
  • Time entries (start time, end time, duration, description, linked client)
  • Documents and notes (stored as markdown files)
  • Folder structure for your document library
  • Gamification data (streak, points, daily task counts)

Session data

We store a session record to keep you signed in. This is a standard authentication mechanism and contains no personal data beyond a reference to your account.

Data we do not collect

  • We do not use analytics tools — no page views, click tracking, or behavioural data is collected
  • We do not collect payment information — nflo is currently free to use
  • We do not serve advertising or share data with advertisers

3. How we use your data

PurposeLegal basis
Providing and operating the Service (storing your tasks, projects, time entries, and documents) Performance of a contract (UK GDPR Art. 6(1)(b))
Authenticating you via Google OAuth, GitHub OAuth, or an emailed sign-in link Performance of a contract (UK GDPR Art. 6(1)(b))
Sending the reminder notifications you have opted in to, and storing the device registration and preferences needed to deliver them Consent (UK GDPR Art. 6(1)(a)), withdrawable at any time in Settings
AI features — sending task context to the Claude API to generate focus suggestions, and sending document content to the Claude API when you ask it to extract tasks from a document Performance of a contract (UK GDPR Art. 6(1)(b))
Maintaining security, preventing fraud, and resolving technical issues Legitimate interests (UK GDPR Art. 6(1)(f))
Complying with legal obligations Legal obligation (UK GDPR Art. 6(1)(c))

4. AI features and the Claude API

nflo has two features that send data to the Claude API, provided by Anthropic, PBC. They send different things, so we describe them separately.

Today’s Focus

Runs automatically when you open the dashboard. It sends a subset of your task data — task titles, due dates, priorities, point values and recurrence flags — and returns three suggested tasks. It does not send document content, time entries or client names.

Extract tasks from a document

Runs only when you press “Extract tasks” on a document you have open. It never runs on its own. When you do press it, this feature sends:

  • Document text — the whole document, including anything personal, confidential or commercially sensitive it happens to contain
  • Document title — as it appears in your document list
  • Client and project names — so the suggested tasks can be matched to the right one

Because a document can contain anything — a meeting transcript, third-party personal data, contract terms — you should treat pressing that button as a decision to send that document to Anthropic. Documents you do not run it on are never sent. If a document contains someone else’s personal data, you are responsible for having a lawful basis to process it that way.

Common to both

Data is transmitted securely. Anthropic processes it as a data processor acting on our behalf, and Anthropic’s handling is governed by their Privacy Policy. We do not retain the request contents after the response comes back, and neither feature is used to train any model.

5. Notifications

Notifications are off by default. If you turn them on, we store a device registration supplied by your browser (an endpoint URL and two public keys), along with your reminder preferences, quiet hours, and time zone.

Delivering a notification means sending it through the push service operated by your browser vendor — Google for Chrome and Android, Apple for Safari, iPhone and iPad, Mozilla for Firefox. We cannot choose or avoid this; it is how web notifications work on every site.

The contents of each notification are encrypted before they leave our servers, using a key derived from your device's own keys. The push service can see that a message is destined for your device, but not what it says. Notification text may include a task title or a client name, which is why this matters.

You can withdraw consent at any time by turning notifications off in Settings, which deletes the device registration. Revoking permission in your browser has the same effect the next time we attempt delivery.

6. Who we share your data with

We do not sell your data. We share data only with the following infrastructure providers who process it on our behalf as data processors:

ProviderPurposeLocation
Cloudflare, Inc. Database (D1) and file storage (R2) hosting your account, content, and documents United States (with global edge infrastructure)
Anthropic, PBC AI task prioritisation, and task extraction from documents you choose to run it on, via the Claude API United States
GitHub, Inc. OAuth authentication provider, where you choose to sign in with GitHub United States
Google LLC OAuth authentication provider, where you choose to sign in with Google United States
Resend (Plus Five Five, Inc.) Delivering sign-in link emails, where you choose to sign in by email United States
Browser push services
(Google LLC, Apple Inc., Mozilla Corporation)
Relaying notifications to your device, if you have opted in. Message contents are encrypted and not readable by the relay. United States

Which of these apply to you depends on how you sign in and whether you enable notifications. Signing in with Google means no data reaches GitHub or Resend, and leaving notifications off means no data reaches a push service.

7. International data transfers

The processors above are all based in the United States. Transfers of your personal data to the United States are made under appropriate safeguards, including Standard Contractual Clauses (SCCs) as recognised under the UK GDPR and the UK’s International Data Transfer Agreements (IDTAs) where applicable.

By using nflo, you acknowledge that your data will be processed in the United States for the purposes described in this policy.

8. Cookies and local storage

nflo uses a single session cookie to keep you signed in. This cookie:

  • Is strictly necessary for the Service to function
  • Contains only a session identifier — no personal data
  • Is not used for tracking or advertising
  • Is deleted when you sign out

We do not use any third-party tracking cookies or analytics scripts.

9. How long we keep your data

DataRetention
Account data (name, email, avatar)Until you delete your account
Tasks, projects, clients, time entriesUntil you delete them or delete your account
DocumentsUntil you delete them or delete your account
Session dataUntil the session expires or you sign out
AI request data (sent to Claude API, including document text where you use task extraction)Not retained by us after the request; subject to Anthropic’s retention policy
Email sign-in tokens30 minutes, or until used — whichever comes first
Notification device registrations and preferencesUntil you turn notifications off, revoke browser permission, or delete your account
Record of which reminders have been sent (to avoid repeats)60 days, then deleted automatically

10. Your rights under UK GDPR

You have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — ask us to correct inaccurate data
  • Right to erasure — ask us to delete your data (“right to be forgotten”)
  • Right to restriction — ask us to limit how we process your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests

Two of these you can exercise yourself, immediately, without asking us:

  • Access and portability — Settings → Your data → Export everything downloads a single JSON file containing your clients, projects, tasks, time entries, documents, notes and settings. Document text is included in full.
  • Erasure — Settings → Your data → Delete your account removes your account and everything in it, including files in storage. This is immediate and permanent; there is no grace period and no backup we can restore from.

For anything else — rectification, restriction, or objection — email [email protected]. We will respond within one calendar month.

11. Children

nflo is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided us with their data, please contact us at [email protected] and we will delete it promptly.

12. Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), authentication-gated access to all data, and scoping all database queries to your individual account. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

13. Changes to this policy

We may update this Privacy Policy from time to time. Where changes are material, we will make reasonable efforts to notify you. The “last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

14. Complaints

If you have concerns about how we handle your data and are not satisfied with our response, you have the right to lodge a complaint with the UK’s supervisory authority:

Information Commissioner’s Office (ICO)
ico.org.uk/make-a-complaint
Telephone: 0303 123 1113

15. Contact

For any privacy-related questions, requests, or concerns:

The Bearded Developer Ltd
[email protected]

nflo
Privacy Policy Terms of Service
© 2026 The Bearded Developer Ltd — Created by James Plant