Privacy

What Flora stores, who else can see it, how long we keep it, and how to get rid of it. No cookies, no advertising, no sale of anything.

What we store

Your account. An identifier and an email address, both from Auth0, who handle signing in. Flora never sees a password.

What you’re learning. The documents you add, the text we read from them, the questions generated or written from that text, and your answers over time. The review history is what the schedule is calculated from, so it’s the one thing that can’t be thrown away while the product still works.

How to reach you. If you turn on reminders: the time of day you chose, your timezone, and a push token for the phone, which comes from Expo and identifies a device rather than you.

That’s the lot. There’s no profile, no inferred interests, and nothing collected in case it turns out to be useful later.

What we don’t do

No advertising, ever, and nothing here is sold or shared with an advertiser.

No cookies, anywhere in Flora. Not on this site, not in the app, and none for analytics. The app keeps your session in your browser’s local storage; Auth0 sets its own cookies on its own domain while you’re signing in.

What we count

We measure whether people keep using Flora, because a spaced repetition tool nobody returns to doesn’t work, however good its schedule is. Two ways, and they’re different.

From your account. How many people signed up on a given day and how many were still reviewing a week and a month later. That’s counted from the review history already described above — no extra collection, and it’s the number we hold ourselves to.

From the pages and screens. PostHog, on servers in the EU, records which pages you read here and roughly what you do in the app: a deck added, a card answered, a session finished. It’s how we find out where the product is confusing. It stores an identifier in your browser’s local storage rather than a cookie, and once you sign in that record is joined to your account so the same person on a laptop and a phone isn’t counted twice. PostHog keeps it for a year.

What it never gets: the text of your documents, your questions, your answers, or the addresses of the pages you turn into decks — only which site they came from. Nothing records your screen, and there’s no session replay.

What the app reports when things go wrong

The app and the API record how they’re working: which requests were made, how long they took, and what failed. It’s how we find out something is broken without waiting for someone to tell us. It includes your account identifier, so that a fault can be traced through to the person who hit it, and it is kept for 30 days.

One part of it is worth stating plainly rather than leaving you to infer. When questions are generated from a document, the text sent to the model and the text it sends back are both recorded. That is the same text described above under “what you’re learning”, and it’s recorded because a bad question is otherwise impossible to explain after the fact. It goes to Pydantic Logfire, on servers in the EU, and ages out after 30 days like the rest.

Who else handles it

Six companies, each doing one thing:

  • Auth0 - signing in, and the email address attached to your account
  • Railway - hosting for the API and the database it writes to
  • OpenRouter - passing the text of your documents to a model to generate questions, covered in more detail in how we use AI
  • Expo - delivering push notifications, if you’ve turned them on
  • Pydantic Logfire - the error and performance records described above, including the text sent to and from the model
  • PostHog - which pages and screens get used, described above under what we count

How long we keep it

Your documents stay until you delete them or your account. Delete a document and its questions and their review history go with it, immediately and for real.

One thing outlives a deletion: a row recording that a generation happened, with the model used, how many tokens it took and when. There’s nothing of yours in it, and it’s what we count our running costs from.

Getting your data, or getting rid of it

Email hello@harrisonpim.com and we’ll send you a copy of everything. That’s done by hand at the moment, so it takes a day or two; an export button is on the list.

To delete your account, use Delete account on the Account screen in the iOS app. It deletes everything attached to your account straight away, including your sign-in at Auth0. Two things aren’t deleted with it: the logs described above, which age out after 30 days anyway, and the usage record PostHog holds, which it keeps for a year. If you only use the web app, email hello@harrisonpim.com and we’ll do it for you.

You can also delete any document, question or answer yourself, at any time, without asking us.

Changes

If this changes in a way that affects what we do with your documents, we’ll say so here and date it. The date at the bottom of this page is the last time anything on it changed.

Asking about any of this

hello@harrisonpim.com reaches a person.

Last updated 24 September 2026