The short version
- We don’t sell your data or show ads. No analytics, no trackers, no third-party scripts.
- Only you decide what’s on today. AI can sort and suggest; every AI change has a receipt and an undo.
- Voice isn’t stored. Recordings become text and are thrown away. Chat isn’t stored on our servers.
- Your public page is off until you turn it on, and it only ever shows finished work.
- Download everything or delete your account anytime, from settings. Deleting is immediate.
on this page
Who we are
#Nuffo (nuffo.app, the iPhone app, the @nuffo/cli command-line tool and the Nuffo connection for AI assistants) is made and run by Thomas Kanze. In this policy, “Nuffo”, “we” and “us” mean him and the service. For the purposes of data protection law, we are the controller of the personal data described here.
Questions, requests or complaints: hello@nuffo.app. A real person reads every email.
What we collect
#Only what Nuffo needs to do its job. Here it is, piece by piece.
Your account
- Your email address, the name you give us, and a handle made from it (you can see it in settings).
- Your password, if you use one. We never store it: we keep a salted, slow hash (PBKDF2-SHA256), which can check a password but can’t be turned back into one.
- If you sign in with Google or Apple: the account ID that provider gives us, your email, and your name if the provider shares it. With Apple you can hide your email; we then get Apple’s relay address. We don’t get your password or access to anything else in that account.
- Your time zone and settings: whether your public page is on, email preferences and send hour, builder mode, and whether Nuffo may add a short line to your AI’s answers.
What you put in
- Everything you dump or create: tasks, deadlines, wishes (with links you save, plus the page title and preview image we fetch for them), ideas waiting in the 7-day cooling rule, your three projects with their steps, notes and parking notes, today’s picks and how they ended (done, moved, let go).
- The “about you” note, if you keep one (a few sentences that help Nuffo plan your days). You can edit or clear it in settings.
- Receipts: a log of every change made by you, by Nuffo or by a connected AI, with which one made it, so any of them can be undone.
- Sorting corrections: when you move something Nuffo sorted into a different place, we record what it guessed and what you chose, so we can measure and improve how well sorting works.
- A list of existing projects, if you type or paste one in during “find my three”.
Talking to Nuffo
The chat (“talk to nuffo” and “talk it through”) is not stored on our servers. On the web the conversation lives in your browser tab (the last 30 turns, cleared when the tab closes); on iPhone it lives in the app’s memory. Only what you choose to keep becomes part of your account: things Nuffo captures for you (each with a receipt and undo), and plans or notes you tick and save.
Voice
- On the web, when you hold to talk, the recording is sent to our servers, turned into text by a speech-to-text model run by our hosting provider, and then thrown away. The audio is never stored. The text is only saved if you then dump it.
- On iPhone, speech becomes text using your iPhone’s built-in speech recognition. Audio is never sent to Nuffo. When your language supports it, recognition happens entirely on the phone; if it doesn’t, iOS may send the audio to Apple to transcribe, under Apple’s own privacy terms.
Emails you forward
If you use your private forwarding address (something like you.x7k2m@nuffo.email), we read each email that arrives from you or a sender you allowed: we check it really came from that sender, strip the forwarding noise, and turn what it asks of you into items. The raw email is never stored. We keep the items it produced and the email’s subject line as their source. Mail from unknown or unverified senders is dropped. The extra sender addresses you allow are stored with your settings.
Connected AIs, the CLI and hooks
- When you connect an AI assistant or coding agent (for example through the CLI, or by approving a connection from an AI app), we store the connection’s name, when it was created and last used, and a hash of its access token (never the token itself). Apps that connect this way register a name and return address with us.
- A connected AI can add things to your dump and read your today, your three and related context. Each change it makes carries a receipt with its name.
- The coding-agent hook runs on your computer. It only contacts Nuffo when a command looks like it starts a new project (like
npm createorgit clone), and then sends that command, the target folder path and, if there is one, the git remote address. At the start of an agent session it asks for your context. We use these to decide whether the work fits one of your three. They are stored only if the work gets linked to a project (the folder or remote is saved as that project’s scope) or in the receipt that records what happened. The hook never sends your code or file contents.
Technical data
- IP address, used briefly for rate limits (to stop abuse such as password guessing). These counters are kept for minutes, not days.
- Standard request logs and error logs from our hosting provider (time, address, page, status, browser type), kept for a few days to keep the service running and secure.
- The device label of each signed-in session (for example “iPhone”), so you can tell them apart.
No analytics, no ad trackers, no third-party scripts, no tracking pixels. The site’s fonts are served from our own domain.
If you don’t have an account
- Waitlist: if you joined it, your email, the three things you entered, and the rough number of projects you said you started this year.
- The scatter-o-meter (/scatter): anyone can type an X handle. We read that account’s recent public posts through a data provider, have an AI model find the projects and ideas in them, and save only the resulting card: the handle, display name, the counts, up to three short exact quotes from the posts, and the playful text. The posts themselves are not stored. Cards are public at their own link (and kept out of search engines). Anyone can press “remove this result” on a card, which deletes it and stops that handle from being run again. To ask for removal another way, email hello@nuffo.app.
How we use it
#- To run Nuffo: store your things, sort what you dump, suggest your three, keep the limits, show receipts and undo.
- To send you emails: account emails (welcome, password reset) and, unless you turn them off, the morning plan and the Sunday recap. Every ritual email has a one-click stop link, and you can change them in settings.
- To keep Nuffo safe: rate limits, sign-in checks, abuse prevention, fixing errors.
- To make sorting better, by measuring how often it gets things right (from your corrections).
- To answer you when you write to us.
We don’t sell your data. We don’t show ads. We don’t share your data for advertising, and we don’t build a profile of you for anyone else.
Legal bases (for people in the EU, UK and similar places)
- Contract: running the service you signed up for, including sorting, AI features you use, and account emails.
- Legitimate interests: security, rate limits and logs; measuring sorting quality; ritual emails (which you can stop in one click); the scatter-o-meter’s processing of public posts, which is limited to a playful card and can be removed at any time.
- Consent: your public page (off until you turn it on), microphone access, and connecting an AI. You can withdraw any of these at any time.
AI in Nuffo
#Nuffo uses AI models to do the tedious parts. Here is exactly what each feature sends, and to whom (by kind of provider):
| feature | what is sent | who processes it |
|---|---|---|
| sorting | the text you dump and the names and keywords of your three projects | a specialised AI judgment provider; if it's unavailable, an AI model run by our hosting provider |
| suggested three | the text of candidate tasks and your projects' names | the AI judgment provider |
| does this fit your three? (hooks) | the command, folder path and git remote, and your projects' names and keywords | the AI judgment provider |
| chat and talk it through | your messages, your local time, and a short snapshot: today, your three, up to 25 later items, 12 wishes, ideas cooling off, and your about-you note | an AI model provider, reached through an AI routing service |
| help me break it down | the project's name and its existing steps | an AI model provider (same route as chat) |
| voice on the web | the audio recording | a speech-to-text model run by our hosting provider |
| forwarded emails | the subject, your note and the email text (up to about 5,000 characters) | an AI model run by our hosting provider |
| scatter-o-meter | the public posts of the handle entered | an AI model provider (same route as chat); optionally the AI judgment provider |
Training. We don’t use your content to train AI models. The provider that runs our sorting, voice and email models and the AI judgment provider both state in their terms that they do not train models on what we send them. For chat and step drafting, we only allow model providers that don’t store or train on what we send, and the routing service in between doesn’t train on it either.
AI can be wrong. Sorting that isn’t confident asks you instead of acting. Every AI change comes with a receipt and can be undone. And no AI, chat or connected agent can put anything on your today: only you can.
Your public page
#Your public page (nuffo.app/your-handle) is off unless you turn it on in settings. When it is on, it shows your first name and handle, the month you joined, the projects you marked public with their progress, and what you finished in the last seven days on those projects, plus counts (wins this week, ideas cooled). It never shows what you started, your today, your later list, your wishes or your notes. There are no public like counts, follower counts or leaderboards. Turn it off and the page disappears.
The iPhone app
#- Your sign-in token is kept in the iPhone Keychain. The app, its widgets and its share extension share a small local store on your phone: the latest copy of your day (so widgets can show it), captures waiting to be sent while you’re offline, and app settings.
- Microphone and speech recognition are asked for only when you first hold to talk. See Voice above.
- The morning nudge is a notification scheduled on your phone. No push server is involved. A few times a day iOS may wake the app in the background to send waiting captures and refresh your widgets.
- The share extension only saves something when you tap to save it.
- The app contains no analytics or advertising code.
How long we keep it
#- Your account and everything in it: until you delete it (or delete the things themselves).
- Voice recordings: not kept at all. Forwarded emails: not kept, only the items they became.
- Chat conversations: not kept on our servers.
- Password reset links: expire after one hour. Sign-in sessions: expire after 30 days without use.
- Rate-limit counters: minutes. Request and error logs: a few days.
- Backups: our database provider keeps point-in-time backups for up to 30 days, so deleted data fully disappears from backups within about 30 days.
- Waitlist entries: until you ask us to remove them, or until the waitlist is no longer needed.
- Scatter-o-meter cards: until removed (anyone can remove one from the card itself).
Download or delete everything
#In settings, under “your data”:
- Download everything gives you one JSON file with your account details, items, projects and steps, ideas, today history, receipts and sorting corrections.
- Delete my account permanently deletes your account and everything in it right away: your things, your projects, receipts, connections to AIs, sessions and sign-in links. It can’t be undone. Copies in backups expire within about 30 days.
To disconnect a coding agent, run npx @nuffo/cli disconnect or revoke it in settings. If you joined the waitlist or can’t sign in, email hello@nuffo.app and we’ll handle it.
Security
#- Everything travels over HTTPS (with HSTS). The site uses a strict content security policy.
- Passwords are stored only as salted PBKDF2 hashes.
- Session tokens, AI connection tokens, password reset links and sign-in codes are stored only as SHA-256 hashes, so a copy of our database wouldn’t let anyone sign in as you.
- AI connection tokens can only add to your dump and read context; they can’t write your today. You can revoke them anytime.
- Link preview images are fetched by our server, so the sites you save never see your IP address.
No system is perfectly secure. If we ever learn of a breach that affects your data, we’ll tell you and the relevant authorities as the law requires. Found a security issue? Please write to hello@nuffo.app.
Your rights
#Wherever you live, you can ask us to:
- tell you what personal data we hold about you and give you a copy;
- correct it;
- delete it;
- give it to you in a portable format (the JSON download does this);
- stop or limit using it, or object to how we use it;
- withdraw a consent you gave.
Most of this you can do yourself in settings. For anything else, email hello@nuffo.app from the address on your account. We’ll answer within 30 days, and it’s free. We may need to check it’s really you.
If you’re in the EU, UK or a similar place, you can also complain to your local data protection authority. If you’re in California or another US state with a privacy law: we don’t sell or share personal information for cross-context behavioral advertising, we don’t use sensitive data to infer things about you, and we won’t treat you differently for using your rights.
Children
#Nuffo is not for anyone under 16, and we don’t knowingly collect data from them. If you think a child under 16 has an account, write to hello@nuffo.app and we’ll delete it.
Where your data lives
#Nuffo runs on a global cloud network, and our service providers may process data in the United States and other countries, which may have different data protection laws from yours. We choose providers that commit to protecting the data they handle for us, and we send them only what their job needs.
Changes to this policy
#If we change this policy, we’ll update the date at the top. If a change is significant (for example a new kind of data or a new use), we’ll tell you by email or in the app before it takes effect.
Contact
#Thomas Kanze, Nuffo · hello@nuffo.app · about Nuffo
Questions about any of this? Write to hello@nuffo.app. A real person answers.

