Privacy Policy
Last updated: 5 October 2026
The short version
floi never uploads your files to a server or sells them. Every tool but one processes your file entirely on your own device, and the exception, File Transfer, is described in full below. Signing in is optional. While signed in, your settings, text drafts and numeric activity save automatically to your private account. Signed out, text work stays on this device. Files and text opened from files are never included in account saving. Imported text and later edits stay in this browser. Tools with saved text drafts use local storage.
Google Analytics is on by default. You can turn it off through Analytics settings in the footer. Google receives information about public pages and tool actions while it is on. Your files, entered text and account details are excluded.
Your files
Video files you open are never uploaded. They are read directly from disk by your browser using a local object URL, decoded on your device, and discarded when you close the tab. Temporary file handoffs between pages use local IndexedDB, as described below.
AI paraphrasing
The paraphrasing tool downloads Qwen3 model files from Hugging Face and a WebLLM runtime from GitHub when you request a rewrite. Those hosts receive their respective download requests, including the usual connection information. Your passage is processed by the downloaded model in your browser, not submitted to an inference service. The browser may cache the model for later use.
Signed-in text drafts and settings still save automatically to your private floi account. That saving is separate from local AI processing. Signed-out drafts remain on your device.
Links you paste
YouTube URLs are parsed in your browser. To show a video's title and thumbnails, your browser requests them directly from YouTube's servers (youtube.com and i.ytimg.com). Those requests go from you to YouTube, not through us, and are subject to Google's privacy policy. We never see them.
Screen capture
Live Capture uses your browser's Screen Capture API. The stream exists only in the page, is used solely to draw the frames you explicitly capture, and is never recorded or transmitted. Sharing stops the moment you press Stop or close the tab.
Cookies and storage
A service worker keeps public pages you visit and their static code in this browser's cache. It tries the network first for pages, so your next online visit gets the current version. Account pages, account requests, analytics, device pairing and country lookup are excluded. AI model downloads and YouTube access may still need a connection. Clear this site's browser data to remove the offline cache.
An installed app can receive shared photos and PDFs on Android Chrome. Supporting desktop Chromium browsers can open registered image and PDF files with floi. iOS does not support these two entry points. These files enter the homepage's local picker through this browser's IndexedDB. They are not uploaded.
Your analytics preference is stored on this device under floi:analytics-consent for 180 days. When it is on, Google sets first-party _ga cookies to recognise your browser. These cookies expire after 180 days. Turning analytics off stops collection and removes these cookies on this domain. Your saved opt-out prevents new Analytics cookies. After the preference expires or is cleared, the default applies again. You can change it through Analytics settings in the footer.
Signed out, these are written, and none of them is ever sent anywhere:
floi:theme, your light or dark choice.floi:pomodoroandfloi:flashcards, which hold the timer's settings and your flashcard decks.floi:usage, numeric tool use and file counts with their dates.floi:recentandfloi:workspace-width, the last few pages you opened from the search box and how wide you like full screen.
One store holds a file rather than a setting. When you choose a tool for a dropped file, share to the installed app or continue with a result, the file waits in this browser's IndexedDB, under floi-handoff, so the tool page can open it. The receiving page deletes it when it takes it. Unused records expire after 30 minutes. They are pruned on the next handoff. It never leaves your device and is never added to an account.
Signing in adds three more, and they are what keep you signed in:
floi:auth, your email, display name and avatar link. The header reads this before paint without asking the auth server to render.floi:auth:tok, the tokens that prove the session is yours. Treat this the way you would treat being signed in on a shared computer.floi:favs, the list of tools you pinned, so the Pin button on a tool page can be drawn without a round trip.
Signing out removes the sign-in snapshot, tokens and pinned-tool cache. Text and settings caches use separate account namespaces. A different account cannot see the previous account’s work through the tools. Pending writes keep their original account owner and never upload under a different sign-in. Clear site data to remove all device caches.
Browser security policy
The build includes a Content Security Policy in report-only mode for testing. It names the origins needed for accounts, model downloads, YouTube and analytics. It reports unexpected connections in your browser's developer console. Report-only mode does not block requests. We do not collect violation reports on a server. This policy is a compatibility check, not a guarantee that permitted hosts cannot receive data.
Google Analytics
floi loads Google Analytics 4 on public pages by default. The settings panel opens only when you click Analytics settings in the footer. Turn Usage analytics off to stop collection on this browser. Your browser's Global Privacy Control or Do Not Track preference also keeps it off. Every tool works with analytics off.
We measure public page visits, tool selections, first interactions, output actions and departures without output. We also measure selected formats and modes, coarse file-size groups, batch counts, processing time and generic error categories. Site search records result-count groups, never your search words. Completion counts describe an export, copy or finished session. They do not prove that a downloaded file was saved or that its result was correct.
Google receives normal connection information, including your IP address, and derives approximate location and device information. Analytics cookies give your browser a pseudonymous identifier. We do not send your floi account ID, email or name. Account, profile, history and sign-in pages are excluded. Query strings, URL fragments, transfer codes and pasted links are excluded from page measurements.
No filenames, file bytes, previews, clipboard contents, typed text, personal form values, credentials or raw error messages enter our analytics events. Selected tool modes and formats use a reviewed list of fixed options. Tool processing still happens in your browser. Signed-in drafts and settings still save separately to your private account.
Google Signals, advertising personalisation and user-provided data collection are disabled. We use analytics to improve tools, not to build advertising audiences. Read how Google uses information from sites that use its services and Google's privacy policy. You can also install Google's Analytics opt-out browser add-on.
Cloudflare, which serves the site, keeps standard edge request logs. Turning Google Analytics off does not change those hosting logs.
Cloudflare Web Analytics
Cloudflare also measures page visits and loading performance through its Web Analytics script. It loads on live pages, including sign-in. The Google Analytics settings and browser privacy preferences described above do not disable it. Its observed requests use /cdn-cgi/rum on this domain. The current script removes queries and fragments from page addresses before sending its measurements.
File Transfer, and the servers on this site
The File Transfer tool sends a file from one of your devices straight to another. The file itself is never uploaded and never stored: it travels over an encrypted connection the two browsers open between themselves.
Two browsers cannot open that connection out of nothing. They first have to swap a session description, which is a few kilobytes listing the network addresses each can be reached on and the public half of the keys the connection will use. The six digit code you type opens a short-lived room on a Cloudflare Durable Object that passes those two messages between you.
That room:
- holds at most two connections, and is sealed once the second one arrives;
- copies messages between them without reading them, and refuses anything larger than 16 KB;
- never receives a filename, a byte of a file, or a message you send, because those travel on the direct connection it is not part of;
- stores nothing but an expiry timer, and is destroyed when you both leave or after ten minutes, whichever comes first.
Your browser also contacts a public STUN server to discover the addresses it can be reached on. That tells the STUN operator your IP address and nothing else, and it is the same mechanism every video call on the web uses. There is no TURN relay here, so no file ever passes through a third party even when a direct connection cannot be made.
No isolate runs for any page on this site. Requests reach that code at two paths and nowhere else: /signal/, above, and /geo, which the sign-up form asks once for the country code described below.
Your profile and activity
Your profile and activity pages are private. There are no public profiles, rankings, points or achievements on floi. Nothing on either page can be seen by anyone else.
Activity records which tool you finished a task in, when, and a few numbers such as files, pages or words. It never holds your files, text, settings or filenames. Signed out, it stays in this browser as floi:usage. Signed in, it also saves to your account, so the activity page can show every device together. Your typing best is worked out from the numbers of your typing tests.
Your profile reads your own saved drafts to show you a short preview of each one. That preview is drawn in your browser from data that is already yours. Suggestions for a next tool are worked out in your browser too, from the tools you have used.
You can export your activity as CSV or JSON, and clear it, from your activity page. Clearing it removes the counts from this browser and, signed in, from your account. Deleting your account removes it as well.
Accounts, pinned tools and saved work
On the ideas board, approved requests, votes, comments and dated progress notes are public. Your request text is reviewed before publication. Public threads use labels such as “Member 1”. They do not publish your account name, email address or profile. Other people can copy public posts, so do not include private information in a request or comment.
An unfinished suggestion stays in that tab's sessionStorage while you sign in. It is sent to the ideas board only when you submit it. A successful submission clears that temporary copy.
Your pending ideas are visible only to you and the review team. Reports are private to the review team. Signed-in notifications show status changes on ideas you submitted or voted for. They appear in the site and are not sent by email. Deleting your account removes your requests, votes, comments, reports and notifications. It can also remove a public request and its discussion.
Signing in is optional and no tool requires it. If you choose to sign in, floi stores your account identifier and email address, your display name, your country, the list of tools you have pinned, numeric tool activity, text drafts and settings.
The country is filled in when you create the account, from the two letter code Cloudflare has already worked out for your connection. Your IP address is not sent to anyone to get it, it is not stored, and it never leaves the Cloudflare machine that answered the request. What is stored is the two letters. It is a guess, and you can change it or clear it on your account page at any time.
That storage never holds a file. Not one byte of an image, a PDF, an audio file or a video has ever reached it, and no tool on this site can put one there.
Text work saves automatically while you are signed in. This includes notes, flashcards, timer tasks, typed or pasted custom passages and tool form values. Where a tool saves text drafts, text opened from files or recognised from images stays in localStorage, including later edits. Imported notes and decks containing imported cards stay local too. Tools such as Difference Checker keep comparison content only in tab memory. File processing stays in your browser. Nothing from the signed-out storage namespace is automatically copied into an account. Sign out before entering text you want to keep only on this device.
Each automatically saved state item holds up to 1 MB, with at most 200 keys per account. Ten earlier versions are retained to protect against accidental overwrites. They are private and are deleted with your account.
Imported text uses floi:local: keys, separate for each account and for signed-out work. It is never queued for cloud saving. Clearing site data deletes it. Text saved under the earlier behaviour may remain in your account and its version history until the account is deleted.
The device cache uses floi:data: keys and interrupted writes use floi:pending: keys. Changes retry automatically after connectivity returns. The saving status distinguishes a confirmed account save from a change still waiting on this device. Clearing site data before a pending write succeeds loses that unsynced change.
Account data loads in the background when you open a tool. The page and header are static; no file processing moves to a server. Concurrent edits use the last accepted save, with earlier versions retained in the account.
Completed tasks have separate numeric activity records. A row holds a tool path, a date and numeric metrics such as use count, file count, words per minute or focus minutes. The database will physically not accept text in those metrics. Favouriting a tool is likewise a record of which page you starred, enforced by a column that only accepts a short tool path.
Accounts are held by Supabase, on servers in the United States. They are the only third party that sees your email address, and they see it because they are the database it is stored in. If you sign in with Google instead of a password, Google tells us your email address, your name and your profile picture link, and nothing else. We ask for nothing else.
Deleting your account deletes all of it: the account itself, the email address and country on it, every saved tool, every activity record and every session score, immediately and for good. The button is on your account page. What is left afterwards is whatever is still in your own browser, which your browser settings clear, and no file, because no tool has ever sent us one.
Children
The tools collect nothing from anyone, including children under 13. An account is the only thing on this site that records anything about a person, it is entirely optional, and it is not intended for children under 13.
Changes
If this policy changes, the date above will change with it.