Effective October 6, 2026
Privacy Policy
Jotflow is a personal, day-centric task manager. This policy explains what information Jotflow collects when you use it, how that information is used, who it is shared with, and the choices you have. The short version: your data is used only to run Jotflow for you. It is never sold, never used for advertising, and no one else can read your tasks.
Who we are
Jotflow is an independent project run by Thinh Dinh (“Jotflow”, “we”, “us”). You can reach us about anything in this policy at thinh@lowcode.agency.
Information we collect
Account information. When you sign in with Google, we receive your name, email address and profile picture from your Google account. We use these to create your account, show who is signed in, and contact you about your account if needed. We do not receive your Google password.
Content you create. Everything you put into Jotflow is stored so the app can show it back to you: tasks and notes, checklists, comments, categories, links, energy estimates, due dates and calendar time blocks, recurring tasks, trip stops (including any locations you type), focus timer sessions, and feedback or votes you submit on the Roadmap page.
Settings. Preferences such as your daily energy limit, default category, onboarding progress, and whether you have accepted these terms.
Data stored on your device. Jotflow uses cookies to keep you signed in, and your browser’s local storage to remember display preferences and to hold changes you make while offline until they can be saved. We do not use advertising or cross-site tracking cookies.
Technical information. Like any website, our hosting provider processes your IP address, browser type and request logs to deliver pages, keep the service secure and diagnose errors. We do not use third-party analytics or advertising tools.
Google user data
Jotflow uses Google in two ways:
- Sign in with Google. We request only your basic profile (name, email address and profile picture) to create and identify your Jotflow account.
- Google Calendar (optional). If you choose to connect Google Calendar, Jotflow requests read-only access to your calendar events. We read the title, time, duration and location of events on your primary calendar and show them as read-only blocks on your Jotflow calendar, so you can plan tasks around your existing commitments. Jotflow never creates, changes or deletes anything in your Google Calendar.
Google user data is used only to provide these features to you. We do not sell it, use it for advertising, use it to train AI or machine-learning models, or let humans read it, except where you ask us to for support, where it is needed for security or to comply with the law, or where the data has been aggregated and anonymised. Calendar access tokens are stored encrypted and are used only to fetch your events.
You can disconnect Google Calendar at any time in Jotflow, which deletes the stored access token and the imported events. You can also revoke Jotflow’s access from your Google Account permissions page.
Jotflow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Calendar links (iCloud, Outlook and others)
You can add a calendar by pasting its sharing link — for example an iCloud “Public Calendar” link or an Outlook published calendar. Jotflow downloads that calendar to show its events (title, time, duration and location) as read-only blocks on your Jotflow calendar. Jotflow never changes the calendar.
A sharing link works like a password: anyone who has it can see that calendar, which is how the calendar provider designed public links. Jotflow stores the link encrypted, never shows it back in full, uses it only to fetch your events, and never sends it or the events to AI providers or anyone else.
Removing a calendar link in Jotflow deletes the stored link and every event imported from it. To stop sharing the calendar entirely, also turn off public sharing in the calendar app (on iPhone: Calendar → Calendars → ⓘ → Public Calendar).
Capture by email
You can forward an email to Jotflow’s capture address to turn it into a task. Jotflow puts it in the account whose sign-in email sent it, or in the account that confirmed that sender address in Settings, and refuses mail whose sender fails the standard email authenticity checks (SPF, DKIM and DMARC). Jotflow reads what you send — the sender, subject and message text — to create one task from it; attachments are not stored.
Mail to the capture address is received by Cloudflare Email Routing on Jotflow’s behalf and is not kept after the task is created. The task itself (title, notes and link) is stored like any other task. The extra sender addresses you add are stored with your account until you remove them.
How we use information
- To provide Jotflow: store, sync and display your tasks, calendar and analytics.
- To keep your account secure and prevent abuse.
- To fix bugs and keep the service running reliably.
- To respond to you when you contact us or submit feedback.
We do not sell your information, show you ads, or build advertising profiles.
AI features
Jotflow includes an optional AI assistant, Nib, that is off unless you turn it on and agree to its terms. When you use it, the message you send and the Jotflow tasks relevant to your request are sent to OpenRouter, which routes them to a third-party AI model to generate a reply. Those providers may process and retain prompts under their own policies. Google user data, including Google Calendar events, and events from calendar links are never sent to AI providers.
If “Tidy captured mail with AI” is on (Settings → Capture by email; on by default), an email you forward to Jotflow’s capture address is sent to Cloudflare Workers AI to write the task’s title and notes. It runs on Cloudflare’s network, which already hosts Jotflow; Cloudflare does not use it to train models. Nothing else you have in Jotflow is sent with it. Turn the setting off and captured mail is made into a task without AI. If you use neither Nib nor AI tidying, none of your data is sent to an AI provider.
Service providers
We rely on a small number of providers to run Jotflow. Each processes data only to provide its service:
- Supabase — database and sign-in. Stores your account and everything you create.
- Cloudflare — hosting. Serves the app and processes request logs; receives mail sent to the capture address; runs Workers AI if you use AI tidying.
- Google — Sign in with Google and, if you connect it, Google Calendar.
- Calendar providers you link (such as Apple iCloud) — Jotflow downloads the calendars you add by link from them; it does not send them your Jotflow data.
- OpenRouter — only if you use the optional AI assistant.
We may also disclose information if required by law, to protect the rights and safety of our users or the public, or as part of a transfer of the service to a new owner, who would remain bound by this policy.
How your data is protected
All traffic to Jotflow is encrypted with HTTPS. Database access rules ensure each account can read and change only its own data. The Jotflow administrator can manage account status (for example, suspending an account) but administrative tools do not display the content of your tasks. No method of storage or transmission is perfectly secure, but we work to protect your information and will notify affected users of a breach where required by law.
Keeping and deleting your data
We keep your information for as long as your account exists. Deleted tasks are removed from our database; routine backups held by our database provider expire on their normal schedule. To delete your account and all associated data, email thinh@lowcode.agency from the address you sign in with and we will complete the deletion within 30 days.
Your choices and rights
You can view and edit your content in the app at any time. You can also ask us to provide a copy of your data, correct it, or delete it. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict processing and to complain to your local data protection authority. To make a request, email thinh@lowcode.agency.
Browser extension
If you install the Jotflow browser extension, it uses your existing Jotflow sign-in to save the tasks you type into it. It does not read the content of the pages you visit or your browsing history.
Children
Jotflow is not intended for children under 13 (or the minimum age required in your country), and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.
International transfers
Our providers may store and process information in countries other than yours, including the United States. By using Jotflow you understand that your information may be transferred to those countries, which may have different data protection rules.
Changes to this policy
If we change this policy we will update the effective date above, and for significant changes we will let you know in the app or by email before they take effect. See also our Terms of Service.
Contact
Questions or requests about your privacy: thinh@lowcode.agency.