Privacy Policy
Last updated: September 9, 2026 · The English version controls in case of any translation conflict.
Plain summary: we do not ask for your SSN or immigration status. We do not sell your data. Your Practical Proof photos are private, have their metadata (GPS) stripped, and are never used for marketing or AI training without your separate consent. You can access, correct, or delete your data at any time.
1. Who we are and scope
This policy describes how CleanerFlow Academy handles personal data in the app and learning services. It applies to accounts created by email/password or Google sign-in. We voluntarily grant the rights of U.S. privacy laws (California CCPA/CPRA and similar state laws) to all users, regardless of state. The data controller is CleanerFlow LLC, San Diego, California.
2. Age (18+) and children
The platform is intended only for people 18 and older. We do not knowingly collect data from children under 13 (COPPA); if we identify any, we delete it. We do not target the service to minors.
3. What data we collect, source, and purpose
Identifiers: email (required), display name (optional), password (hashed) or Google identifier. Approximate location: U.S. ZIP code (optional, for relevance only — not used for ads). Preferences: language and email preferences. Usage and learning data: lessons completed, your answers, certificate and badges (private). Audio/visual (sensitive): optional Practical Proof photos (see Section 9). Phone (optional): if you add a number in settings or claim the CleanerFlow Leads benefit, we store the number and a hashed version, used to confirm by SMS, unlock the benefit, and prevent duplicates — never for ads or marketing. We collect this directly from you (or from Google, if you use its sign-in).
Your connection data. When you sign in or earn your certificate, our server records where the request came from: country, state, approximate city, time zone, and the name of your internet provider. We do not keep your IP address in readable form; we keep an identifier derived from it, which does not allow the address to be reconstructed. There are two: the network it belongs to, with the last number replaced by zero (108.249.104.14 becomes 108.249.104.0), and a scrambled version (a hash). What it is for: confirming the service is being used in the United States, where it works; protecting Founding spots from duplicate accounts; and looking into misuse. Never for ads, never for marketing, and never shared with third parties. You do not have to do anything to provide this — it is your device talking to our server, the way it happens on any website.
We do NOT collect: SSN, government ID, immigration status, financial data (until payments are eventually activated), precise GPS location, biometric identifiers, or data revealing race, ethnicity, or health.
4. How we use data
We use data to: create, maintain, and secure your account; deliver content in your language; issue private certificate and badges; track progress; send service messages and, with your consent, preference-based emails (with unsubscribe at any time); maintain security and prevent fraud; and comply with the law. We do NOT build advertising profiles, do NOT sell data, and do NOT use Practical Proof photos for marketing or AI training without separate opt-in consent.
5. We do not sell or share for ads
We do not sell your personal information and do not share it for cross-context behavioral advertising, as defined by the CCPA and state laws. Because we do not do this, there is nothing to “opt out” of, but we honor requests and browser opt-out signals (such as Global Privacy Control) should this ever change.
6. Service providers (subprocessors)
We use trusted providers who process data only on our instructions and under contract, without selling it: hosting and database (Supabase), web hosting/CDN (Vercel, Cloudflare), transactional email (Amazon SES), authentication (Google), and, if/when payments exist, payment processing (Stripe). Data may be processed in the United States. A current list of subprocessors is available on request.
7. Sharing with other CleanerFlow products
The other CleanerFlow LLC products do not receive your data automatically. Nothing leaves the Academy until YOU take the step of entering one of them and providing there the email you use here.
When you do that to unlock the Helpers platform, we confirm your certification by returning only: the certificate status, the issue and expiry dates, the certification name, your member identifier, the public verification link, the list of badges you have earned, and your name in abbreviated form (first name plus the initial of your last name — for example, “Maria S.”). Your email is used only to find the record: it is not stored by that lookup and is not echoed back in the response.
What does NOT leave the Academy in that confirmation: your Practical Proof photos, your quiz answers, your lesson history, your ZIP code, your phone number, and your email. If you do not hold a valid certificate, the answer is always the same one — we do not even reveal whether an account exists for that email.
From the moment you create an account in another product, that product becomes responsible for the data you give it directly, under its own Privacy Policy. Deleting your Academy account does not delete the account you created in the other product, and vice versa: request deletion in each one. We never sell your data or share it for advertising, here or in any other product in the family.
8. Your privacy rights
We grant all users: the right to know/access data; to correct; to delete; to port (receive a copy); to opt out of sale/sharing (not applicable, since we do neither); to limit the use of sensitive data; and to be free from discrimination for exercising rights. Many of these are already available in the app (edit profile, change language/preferences, delete account).
To exercise a right, email privacy@cleanerflowacademy.com. We may verify your identity and respond within 45 days (extendable as allowed by law). Authorized-agent requests and appeals are accepted at the same contact.
9. Photos and sensitive data: Practical Proof
Practical Proof photos are 100% optional and default OFF (opt-in only). They are stored privately on the server, never public, and visible only to you and the review team. Metadata (GPS, device, date) is stripped on the server at upload. They are never used for marketing or AI training without a separate, revocable opt-in consent. You can delete your photos at any time.
10. Cookies, analytics, and tracking
We use strictly necessary cookies (session/authentication) and preference cookies (language). We do NOT use ad pixels, third-party trackers, or cross-site behavioral tracking. If we use any analytics, it respects privacy and is never for advertising.
11. Data retention
We keep data only as long as needed to provide the service and meet legal obligations. Account and learning data are kept while the account is active; photos are kept until you delete them or close the account; after an account-deletion request, we remove data within 30 days, with backups purged on a rolling cycle.
12. Security
We adopt reasonable technical and administrative measures: encryption in transit and at rest, hashed passwords, access controls, row-level isolation (RLS), and photo metadata stripping. No system is 100% secure; in case of an incident, we will notify affected people and authorities as required by applicable law.
13. International users, changes, and contact
Data is processed in the United States; by using the service outside the U.S., you consent to this processing. We may update this policy; material changes will be communicated (in-app notice or email) and the date at the top updated. Continued use after the effective date means acceptance. Privacy questions and requests: privacy@cleanerflowacademy.com. This policy is not legal advice and is subject to attorney review.
