Effective October 6, 2026

Privacy Policy

Jotflow is a personal, day-centric task manager. This policy explains what information Jotflow collects when you use it, how that information is used, who it is shared with, and the choices you have. The short version: your data is used only to run Jotflow for you. It is never sold, never used for advertising, and no one else can read your tasks.

Who we are

Jotflow is an independent project run by Thinh Dinh (“Jotflow”, “we”, “us”). You can reach us about anything in this policy at thinh@lowcode.agency.

Information we collect

Account information. When you sign in with Google, we receive your name, email address and profile picture from your Google account. We use these to create your account, show who is signed in, and contact you about your account if needed. We do not receive your Google password.

Content you create. Everything you put into Jotflow is stored so the app can show it back to you: tasks and notes, checklists, comments, categories, links, energy estimates, due dates and calendar time blocks, recurring tasks, trip stops (including any locations you type), focus timer sessions, and feedback or votes you submit on the Roadmap page.

Settings. Preferences such as your daily energy limit, default category, onboarding progress, and whether you have accepted these terms.

Data stored on your device. Jotflow uses cookies to keep you signed in, and your browser’s local storage to remember display preferences and to hold changes you make while offline until they can be saved. We do not use advertising or cross-site tracking cookies.

Technical information. Like any website, our hosting provider processes your IP address, browser type and request logs to deliver pages, keep the service secure and diagnose errors. We do not use third-party analytics or advertising tools.

Google user data

Jotflow uses Google in two ways:

  • Sign in with Google. We request only your basic profile (name, email address and profile picture) to create and identify your Jotflow account.
  • Google Calendar (optional). If you choose to connect Google Calendar, Jotflow requests read-only access to your calendar events. We read the title, time, duration and location of events on your primary calendar and show them as read-only blocks on your Jotflow calendar, so you can plan tasks around your existing commitments. Jotflow never creates, changes or deletes anything in your Google Calendar.

Google user data is used only to provide these features to you. We do not sell it, use it for advertising, use it to train AI or machine-learning models, or let humans read it, except where you ask us to for support, where it is needed for security or to comply with the law, or where the data has been aggregated and anonymised. Calendar access tokens are stored encrypted and are used only to fetch your events.

You can disconnect Google Calendar at any time in Jotflow, which deletes the stored access token and the imported events. You can also revoke Jotflow’s access from your Google Account permissions page.

Jotflow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Capture by email

You can forward an email to Jotflow’s capture address to turn it into a task. Jotflow puts it in the account whose sign-in email sent it, or in the account that confirmed that sender address in Settings, and refuses mail whose sender fails the standard email authenticity checks (SPF, DKIM and DMARC). Jotflow reads what you send — the sender, subject and message text — to create one task from it; attachments are not stored.

Mail to the capture address is received by Cloudflare Email Routing on Jotflow’s behalf and is not kept after the task is created. The task itself (title, notes and link) is stored like any other task. The extra sender addresses you add are stored with your account until you remove them.

How we use information

  • To provide Jotflow: store, sync and display your tasks, calendar and analytics.
  • To keep your account secure and prevent abuse.
  • To fix bugs and keep the service running reliably.
  • To respond to you when you contact us or submit feedback.

We do not sell your information, show you ads, or build advertising profiles.

AI features

Jotflow includes an optional AI assistant, Nib, that is off unless you turn it on and agree to its terms. When you use it, the message you send and the Jotflow tasks relevant to your request are sent to OpenRouter, which routes them to a third-party AI model to generate a reply. Those providers may process and retain prompts under their own policies. Google user data, including Google Calendar events, and events from calendar links are never sent to AI providers.

If “Tidy captured mail with AI” is on (Settings → Capture by email; on by default), an email you forward to Jotflow’s capture address is sent to Cloudflare Workers AI to write the task’s title and notes. It runs on Cloudflare’s network, which already hosts Jotflow; Cloudflare does not use it to train models. Nothing else you have in Jotflow is sent with it. Turn the setting off and captured mail is made into a task without AI. If you use neither Nib nor AI tidying, none of your data is sent to an AI provider.

Service providers

We rely on a small number of providers to run Jotflow. Each processes data only to provide its service:

  • Supabase — database and sign-in. Stores your account and everything you create.
  • Cloudflare — hosting. Serves the app and processes request logs; receives mail sent to the capture address; runs Workers AI if you use AI tidying.
  • Google — Sign in with Google and, if you connect it, Google Calendar.
  • Calendar providers you link (such as Apple iCloud) — Jotflow downloads the calendars you add by link from them; it does not send them your Jotflow data.
  • OpenRouter — only if you use the optional AI assistant.

We may also disclose information if required by law, to protect the rights and safety of our users or the public, or as part of a transfer of the service to a new owner, who would remain bound by this policy.

How your data is protected

All traffic to Jotflow is encrypted with HTTPS. Database access rules ensure each account can read and change only its own data. The Jotflow administrator can manage account status (for example, suspending an account) but administrative tools do not display the content of your tasks. No method of storage or transmission is perfectly secure, but we work to protect your information and will notify affected users of a breach where required by law.

Keeping and deleting your data

We keep your information for as long as your account exists. Deleted tasks are removed from our database; routine backups held by our database provider expire on their normal schedule. To delete your account and all associated data, email thinh@lowcode.agency from the address you sign in with and we will complete the deletion within 30 days.

Your choices and rights

You can view and edit your content in the app at any time. You can also ask us to provide a copy of your data, correct it, or delete it. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict processing and to complain to your local data protection authority. To make a request, email thinh@lowcode.agency.

Browser extension

If you install the Jotflow browser extension, it uses your existing Jotflow sign-in to save the tasks you type into it. It does not read the content of the pages you visit or your browsing history.

Children

Jotflow is not intended for children under 13 (or the minimum age required in your country), and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.

International transfers

Our providers may store and process information in countries other than yours, including the United States. By using Jotflow you understand that your information may be transferred to those countries, which may have different data protection rules.

Changes to this policy

If we change this policy we will update the effective date above, and for significant changes we will let you know in the app or by email before they take effect. See also our Terms of Service.

Contact

Questions or requests about your privacy: thinh@lowcode.agency.