Privacy Policy
Last updated: October 9, 2026 · The English version controls in case of any translation conflict.
Plain summary: we do not ask for your SSN or immigration status. We do not sell your data. Your Practical Proof photos are private, have their metadata (GPS) stripped, and are never used for marketing or AI training without your separate consent. You can access, correct, or delete your data at any time.
1. Who we are and scope
This policy describes how CleanerFlow Academy handles personal data in the app and learning services. It applies to accounts created by email/password, Google sign-in, or Sign in with Apple. We voluntarily grant the rights of U.S. privacy laws (California CCPA/CPRA and similar state laws) to all users, regardless of state. The data controller is CleanerFlow LLC, San Diego, California.
2. Age (18+) and children
The platform is intended only for people 18 and older. We do not knowingly collect data from children under 13 (COPPA); if we identify any, we delete it. We do not target the service to minors.
3. What data we collect, source, and purpose
Identifiers: email (required), display name (optional), password (hashed), Google identifier, or Apple identifier. If you sign in with Apple and choose “Hide My Email,” we receive a forwarding address created by Apple, not your real email. Approximate location: the U.S. ZIP code of the area where you work, required to use the Academy. From it, we store the matching city and state. We ask only for the ZIP code, never your address or any client's address. We use it to fit suggested prices and content to your area and to know, in overall numbers, where the Academy is used. Your ZIP code is never shown publicly and is never used for ads. Preferences: language and email preferences. Usage and learning data: lessons completed, your answers, certificate and badges (private). Audio/visual (sensitive): optional Practical Proof photos (see Section 9). Phone (optional): if you add a number in settings or claim the CleanerFlow Leads benefit, we store the number and a hashed version, used to confirm by SMS, unlock the benefit, and prevent duplicates — never for ads or marketing. We collect this directly from you (or from Google or Apple, if you use their sign-in).
Your connection data. When you sign in or earn your certificate, our server records where the request came from: country, state, approximate city, time zone, and the name of your internet provider. We do not keep your IP address in readable form; we keep an identifier derived from it, which does not allow the address to be reconstructed. There are two: the network it belongs to, with the last number replaced by zero (108.249.104.14 becomes 108.249.104.0), and a scrambled version (a hash). What it is for: confirming the service is being used in the United States, where it works; protecting Founding spots from duplicate accounts; and looking into misuse. Never for ads, never for marketing, and never shared with third parties. You do not have to do anything to provide this — it is your device talking to our server, the way it happens on any website.
Phone notifications (optional). If you allow notifications in the app, your phone creates a notification code (provided by Apple or Google), and the app sends us that code along with the app language. It is used only to send your account notices to that device: lesson progress, badges, your certificate, and its expiration. It does not identify you outside the Academy and is never used for ads. You can turn it off at any time in your phone or app settings.
How you found us. On your first visit, your browser notes how you got here, and we attach it to your account when you sign in. It is only a few things: the link's label, if you came through a link we handed out (an invitation from your city's group, for example); the source the link itself reports (ChatGPT, for example, tags the links it cites with "chatgpt.com"); the name of the site you came from, such as google.com or chatgpt.com — only the site's name, never the page address or what you searched for; and the page you landed on, with the date of that first visit. And if the link came from another CleanerFlow product — Agenda, Leads or CleanerFlow Pro — we also keep which ad and which page of that product you clicked. It does three things: tells us which cities answered the invitation, which group your Founding spot belongs to, and how people find the Academy — search engines like Google or assistants like ChatGPT — and which of our ads between CleanerFlow products work. This is not advertising: we do not build a profile about you, we do not follow you across other sites, we do not store ad-click identifiers, and we do not share this with anyone. Because a Founding spot is for life, we keep this for as long as your account exists and delete it along with the account. You can also ask us to remove it sooner, at any time.
App and website usage. While you are signed in, we record which screens you open, how long you stay on each, the days you used the Academy and, while the app or website is open, a presence signal every minute. If something goes wrong, the app or website sends us an error report with the screen, the version, and the technical message. All of this is linked to your account and is used for only two things: improving the product and finding and fixing errors. It is not used for ads, it is not sold, it is not shared with anyone, and we do it ourselves, with no third-party analytics tool. Retention periods are in Section 11.
Profile photo (optional). If you choose a profile photo, we crop it and save it again on our server with no metadata: no location (GPS), no device details, and no date. It is stored at a web address that is not listed or shared anywhere, but anyone with the exact link can open it. It is shown to you and, if you take part, to other people in the Community. You can change it whenever you want, and it is deleted along with your account.
Community. If you take part in the Community, which is open to people with an active certificate, we keep your posts, comments, and reactions to show them to other people in the Community. If you block someone, we keep the list of people you blocked for one purpose only: you and that person stop seeing each other's posts and comments in the Community. The person you block is not notified. If you report a post or comment, we keep the report (what was reported, the reason, and who reported it) for our moderation to review. The person reported is not told who reported them. Your posts, comments, and blocks are deleted along with your account.
Messages to support. When you write to us through Help, in the app or on the website, we keep the topic you chose, the text of the messages (yours and our replies), and the dates, linked to your account. We use them only to answer and resolve your request. They are deleted along with your account.
We do NOT collect: SSN, government ID, immigration status, financial data (until payments are eventually activated), precise GPS location, biometric identifiers, or data revealing race, ethnicity, or health.
4. How we use data
We use data to: create, maintain, and secure your account; deliver content in your language; issue private certificate and badges; track progress; send service messages and, only if you ask for them, news and offers emails (see below); maintain security and prevent fraud; and comply with the law. We do NOT build advertising profiles, do NOT sell data, and do NOT use Practical Proof photos for marketing or AI training without separate opt-in consent.
News and offers emails. We send these emails only if you ask for them. At signup there is a separate box for this, which comes unchecked, and you can also turn them on or off in Settings. Every email of this kind has a one-click unsubscribe link that works without signing in. When you opt in or out, we keep the date, where you made the choice (signup or Settings, on the website or in the app), and the version of the text you saw, as a record of your choice. Account emails (sign-in, password, and security notices) still arrive, because the service needs them.
5. We do not sell or share for ads
We do not sell your personal information and do not share it for cross-context behavioral advertising, as defined by the CCPA and state laws. Because we do not do this, there is nothing to “opt out” of, but we honor requests and browser opt-out signals (such as Global Privacy Control) should this ever change.
6. Service providers (subprocessors)
We use trusted providers who process data only on our instructions and under contract, without selling it: hosting and database (Supabase), web hosting/CDN (Vercel, Cloudflare), email (Amazon SES), for both account emails and news and offers emails, for those who asked for them, phone notifications (Google Firebase Cloud Messaging and Apple Push Notification service), authentication (Google and Apple), and, if/when payments exist, payment processing (Stripe). Data may be processed in the United States. A current list of subprocessors is available on request.
7. Sharing with other CleanerFlow products
The other CleanerFlow LLC products do not receive your data automatically. Nothing leaves the Academy until YOU take the step of entering one of them and providing there the email you use here.
When you do that to unlock the Helpers platform, we confirm your certification by returning only: the certificate status, the issue and expiry dates, the certification name, your member identifier, the public verification link, the list of badges you have earned, and your name in abbreviated form (first name plus the initial of your last name — for example, “Maria S.”). Your email is used only to find the record: it is not stored by that lookup and is not echoed back in the response.
What does NOT leave the Academy in that confirmation: your Practical Proof photos, your quiz answers, your lesson history, your ZIP code, your phone number, and your email. If you do not hold a valid certificate, the answer is always the same one — we do not even reveal whether an account exists for that email.
From the moment you create an account in another product, that product becomes responsible for the data you give it directly, under its own Privacy Policy. Deleting your Academy account does not delete the account you created in the other product, and vice versa: request deletion in each one. We never sell your data or share it for advertising, here or in any other product in the family.
8. Your privacy rights
We grant all users: the right to know/access data; to correct; to delete; to port (receive a copy); to opt out of sale/sharing (not applicable, since we do neither); to limit the use of sensitive data; and to be free from discrimination for exercising rights. Many of these are already available in the app (edit profile, change language/preferences, delete account).
To exercise a right, email privacy@cleanerflowacademy.com. We may verify your identity and respond within 45 days (extendable as allowed by law). Authorized-agent requests and appeals are accepted at the same contact.
9. Photos and sensitive data: Practical Proof
Practical Proof photos are 100% optional and default OFF (opt-in only). They are stored privately on the server, never public, and visible only to you and the review team. Metadata (GPS, device, date) is removed twice: first on your device, before sending, and again on our server when the photo arrives. They are never used for marketing or AI training without a separate, revocable opt-in consent. You can delete your photos at any time.
10. Cookies, analytics, and tracking
We use strictly necessary cookies (session/authentication) and preference cookies (language). We do NOT use ad pixels, third-party trackers, or cross-site behavioral tracking. The only analytics we run are our own, described in Section 3 (“App and website usage”): done by us, with no third-party company, and never for advertising.
11. Data retention
We keep data only as long as needed to provide the service and meet legal obligations. Account and learning data are kept while the account is active; photos are kept until you delete them or close the account. When you cancel your account, it stays deactivated for 45 days. During that time, you can change your mind and reactivate everything just as it was. After 45 days, we delete it for good: your sign-in account, profile, progress and answers, badges, your certificate (which can no longer be verified by its code or QR), your profile photo, your Practical Proof photos, your phone notification codes, the records of emails we sent you, your access-origin records, your messages to support, and your Community posts and comments. We keep only what the law requires us to keep, such as payment records, if there are any, for as long as the law requires and for no other use. Backups renew on a rolling cycle, and deleted data leaves them once that cycle completes.
How long we keep technical records: records of the emails we sent you (address, subject, date, and whether it was delivered), 12 months from sending; your connection data (Section 3), 12 months from your last visit; app and website usage records (screens opened and time on each), 90 days; error reports, 90 days; the presence signal, 30 days from the last signal; the days you used the Academy, 13 months; Community reports, 12 months after the moderation decision. When each period ends, the record is deleted automatically. Daily totals that identify no one (for example, how many times a screen was opened on a given day) may be kept longer, because they say nothing about you.
The phone notification code is deleted immediately when you sign out on that device, turn off notifications in the app, or delete your account, and also when Apple or Google tell us it is no longer valid.
12. Security
We adopt reasonable technical and administrative measures: encryption in transit and at rest, hashed passwords, access controls, row-level isolation (RLS), and photo metadata stripping. No system is 100% secure; in case of an incident, we will notify affected people and authorities as required by applicable law.
13. International users, changes, and contact
Data is processed in the United States; by using the service outside the U.S., you consent to this processing. We may update this policy; material changes will be communicated (in-app notice or email) and the date at the top updated. Continued use after the effective date means acceptance. Privacy questions and requests: privacy@cleanerflowacademy.com. This policy is not legal advice and is subject to attorney review.
