Saltar al contenido

Privacy Policy

What Neoflow collects, why, where it lives, and how to get it back or delete it.

Última actualización · Regido por las leyes de Quebec, Canadá.

Disponible en inglés y francés

Nuestros textos legales se publican solo en inglés y francés. La versión inglesa es la que rige. Escríbenos si necesitas que te los expliquemos en otro idioma.

The short version

  • We collect what the product needs to work, and nothing to sell.
  • We do not sell or rent personal data, ever.
  • We do not use your content to train AI models.
  • We use no advertising cookies and no third-party tracking pixels on this website.
  • You can export your data, and you can delete it.

1. What we collect

  • Account details: name, email address, and a password hash if you did not sign in with Google. We never store a password itself.
  • Workspace content: everything you put into Neoflow: projects, files, proposals, invoices, and the client details attached to them.
  • Billing details: held by Stripe. We keep an identifier, the plan, and the status. Card numbers never reach our servers.
  • Operational records: sign-ins, security events such as two-factor changes, a log of every email we send you, and what the operator did on your behalf. These exist so that both of us can reconstruct what happened.
  • Technical data: IP address and browser user-agent, used for rate limiting, abuse prevention and error diagnosis.
  • Anything you send us: a message through the contact form, and our reply to it.

2. Why, and on what basis

To provide the service you asked for and to perform our contract with you; to keep accounts and payments secure, which is a legitimate interest and in places a legal obligation; and to answer you when you write to us. Where consent is the right basis, such as optional product email, we ask for it, and you can withdraw it with the link in the footer of any such message.

3. Cookies, pixels and analytics

This site sets no advertising cookies, embeds no social media trackers, and loads nothing from a third-party domain. The Content-Security-Policy on every page enforces that rather than merely promising it.

  • A session cookie, once you sign in. Strictly necessary; without it you cannot stay signed in. It is httpOnly, so no script can read it.
  • A language preference, so an unprefixed page speaks the language you chose. Readable by scripts, contains a two-letter code, and nothing else.
  • A theme preference, stored in your browser rather than as a cookie, so the page does not flash the wrong colour before it loads.

Those are the only cookies set unless you ask for more. On your first visit you are shown a choice with two categories beyond the strictly necessary ones — product analytics, and advertising — and both start switched off. Declining is a button of the same size as accepting, sitting beside it, and closing the notice without choosing is treated as declining. Nothing on this site is withheld from you for saying no, because none of it needs a cookie to work.

No advertising cookie is set today, whatever you choose; that category exists so that the day one is proposed it cannot be switched on without asking you first. Product analytics, if you turn it on, is measurement of the application — which pages get opened, which features get reached — and not of you across the web.

Your choice is stored in a cookie for six months so we do not ask again, and, if you are signed in, as a dated record of the exact wording you were shown. You can change it at any time, and changing it to "no" stops the relevant cookies immediately. If we change the categories or the wording, the notice appears again rather than assuming your old answer covers the new thing.

On email: transactional messages such as password resets and receipts contain no tracking pixel. Where a message is not transactional, our provider may record delivery, bounce and open events so we can tell whether important mail is arriving. Every one of those carries a one-click unsubscribe, and unsubscribing works.

4. Who else processes it

We use a small number of processors, each for one job, each under contract, and none of them permitted to use your data for their own purposes:

  • Supabase: database, authentication and file storage.
  • Vercel: application hosting and delivery.
  • Stripe: payment processing and the billing portal.
  • Resend: sending transactional email.
  • AI model providers: the third-party models NeoAI runs on. NeoAI is our name for the intelligence in the product; the models behind it are operated by third parties, and this list is where they are disclosed as processors. One receives the context needed to plan an action, not your whole workspace, and every provider we use is configured not to train on submitted content.

Some of these operate outside Canada, which means data may be processed elsewhere under appropriate contractual safeguards. We will name any addition here before it starts handling your data.

5. Where it lives, and for how long

Your data lives in Postgres with row-level security on every table, so a query can only ever reach the workspace it belongs to. That is enforced by the database, not by application code that might have a bug.

  • Workspace content: kept while your account is open.
  • Your clients’ stored correspondence — email, WhatsApp and Slack messages Neoflow has ingested: kept for as long as your workspace sets, one year by default, and you can set it as low as thirty days from Settings → Workspace. A job deletes anything past that date every hour.
  • Your workspace’s activity feed: two years by default, on the same setting.
  • Delete your workspace and the content is removed promptly; encrypted backups roll off within 30 days.
  • Security and audit records: kept up to 24 months, because "who signed in and when" is the question you will ask after an incident. That period is ours rather than yours, deliberately — a workspace able to shorten its own audit trail is one where a change nobody should have made can be made to leave no record.
  • Email delivery logs: kept up to 12 months.
  • Billing records: kept as long as tax and accounting law requires, typically seven years.

Deletion here means deletion, not a flag on a row. There is no recycle bin for an erased account and no grace period from which it can be restored.

6. Your rights

Two of these are buttons rather than requests. From Settings → Account you can download everything your account holds as a single JSON file — your clients, projects, tasks, invoices, meetings and the full text of every stored message, decrypted so you can actually read it — and you can delete your account outright. The deletion shows you exactly what would be destroyed before it asks you to confirm, revokes every account you have connected at the provider rather than merely forgetting our copy, empties the file storage, and removes any workspace you are the last member of.

You can also ask us to correct your data, object to a particular use, or stop processing while a complaint is resolved. Write to hello@getneoflow.com and we will answer within 30 days. If you are in Québec you may also complain to the Commission d’accès à l’information; in the EU or UK, to your local supervisory authority.

Where you have put a client’s details into Neoflow, you are the controller of that data and we are the processor. A request from your client should reach you, and we will help you act on it.

7. Security

  • Encrypted in transit everywhere, and at rest by our infrastructure providers.
  • Row-level security on every table; two-factor authentication available and enforceable per workspace.
  • A strict Content-Security-Policy with a fresh nonce on every request, HSTS, and rate limits on every authentication, payment and email path.
  • Every action the operator takes is written to an audit log and can be undone.

No system is perfect. If we discover a breach affecting your personal data we will notify you and the relevant authority as the law requires, and we will tell you what we know rather than what sounds best. Report anything you find to support@getneoflow.com. We answer security mail first.

8. AI and your data

NeoAI is sent the context needed to plan a specific action, and returns a plan chosen from a fixed list of actions we wrote. NeoAI runs on third-party models, named as processors in section 7 — a privacy notice that hid that behind a brand name would be the wrong document to be tidy in. Your content is not used to train models, ours or a provider’s. NeoAI cannot write to your database; it can only propose an action that our code then validates and executes.

9. Children

Neoflow is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

10. Changes, and how to reach us

If this policy changes materially we will tell you before it takes effect. The date at the top of this page is always the date of the version you are reading. Questions, requests and complaints: hello@getneoflow.com, or Neoflow, Rosemère, Québec, Canada.

Nada opcional se activa sin que lo digas.

Las cookies que te mantienen con la sesión iniciada, y nada más hasta que lo actives. Qué recogemos