nuffo
how it works/compare/scatter-o-meter/about
sign inStart free

privacy policy

Your stuff.Stays yours.

Nuffo holds what’s on your mind, so it should be clear what happens to it. Here’s everything we collect, why, and who helps us run it, in plain words.

effective 28 September 2026 · last updated 28 September 2026

Nuffo hugging a locked notebook, a little key hanging from its string

on this page

  1. the short version
  2. Who we are
  3. What we collect
  4. How we use it
  5. AI in Nuffo
  6. Who helps us run it
  7. Your public page
  8. Cookies and storage
  9. The iPhone app
  10. How long we keep it
  11. Download or delete everything
  12. Security
  13. Your rights
  14. Children
  15. Where your data lives
  16. Changes to this policy
  17. Contact

terms of service →

The short version

  • We don’t sell your data or show ads. No analytics, no trackers, no third-party scripts.
  • Only you decide what’s on today. AI can sort and suggest; every AI change has a receipt and an undo.
  • Voice isn’t stored. Recordings become text and are thrown away. Chat isn’t stored on our servers.
  • Your public page is off until you turn it on, and it only ever shows finished work.
  • Download everything or delete your account anytime, from settings. Deleting is immediate.
on this page
  1. the short version
  2. Who we are
  3. What we collect
  4. How we use it
  5. AI in Nuffo
  6. Who helps us run it
  7. Your public page
  8. Cookies and storage
  9. The iPhone app
  10. How long we keep it
  11. Download or delete everything
  12. Security
  13. Your rights
  14. Children
  15. Where your data lives
  16. Changes to this policy
  17. Contact

terms of service →

01

Who we are

#

Nuffo (nuffo.app, the iPhone app, the @nuffo/cli command-line tool and the Nuffo connection for AI assistants) is made and run by Thomas Kanze. In this policy, “Nuffo”, “we” and “us” mean him and the service. For the purposes of data protection law, we are the controller of the personal data described here.

Questions, requests or complaints: hello@nuffo.app. A real person reads every email.

02

What we collect

#

Only what Nuffo needs to do its job. Here it is, piece by piece.

Your account

  • Your email address, the name you give us, and a handle made from it (you can see it in settings).
  • Your password, if you use one. We never store it: we keep a salted, slow hash (PBKDF2-SHA256), which can check a password but can’t be turned back into one.
  • If you sign in with Google or Apple: the account ID that provider gives us, your email, and your name if the provider shares it. With Apple you can hide your email; we then get Apple’s relay address. We don’t get your password or access to anything else in that account.
  • Your time zone and settings: whether your public page is on, email preferences and send hour, builder mode, and whether Nuffo may add a short line to your AI’s answers.

What you put in

  • Everything you dump or create: tasks, deadlines, wishes (with links you save, plus the page title and preview image we fetch for them), ideas waiting in the 7-day cooling rule, your three projects with their steps, notes and parking notes, today’s picks and how they ended (done, moved, let go).
  • The “about you” note, if you keep one (a few sentences that help Nuffo plan your days). You can edit or clear it in settings.
  • Receipts: a log of every change made by you, by Nuffo or by a connected AI, with which one made it, so any of them can be undone.
  • Sorting corrections: when you move something Nuffo sorted into a different place, we record what it guessed and what you chose, so we can measure and improve how well sorting works.
  • A list of existing projects, if you type or paste one in during “find my three”.

Talking to Nuffo

The chat (“talk to nuffo” and “talk it through”) is not stored on our servers. On the web the conversation lives in your browser tab (the last 30 turns, cleared when the tab closes); on iPhone it lives in the app’s memory. Only what you choose to keep becomes part of your account: things Nuffo captures for you (each with a receipt and undo), and plans or notes you tick and save.

Voice

  • On the web, when you hold to talk, the recording is sent to our servers, turned into text by a speech-to-text model run by our hosting provider, and then thrown away. The audio is never stored. The text is only saved if you then dump it.
  • On iPhone, speech becomes text using your iPhone’s built-in speech recognition. Audio is never sent to Nuffo. When your language supports it, recognition happens entirely on the phone; if it doesn’t, iOS may send the audio to Apple to transcribe, under Apple’s own privacy terms.

Emails you forward

If you use your private forwarding address (something like you.x7k2m@nuffo.email), we read each email that arrives from you or a sender you allowed: we check it really came from that sender, strip the forwarding noise, and turn what it asks of you into items. The raw email is never stored. We keep the items it produced and the email’s subject line as their source. Mail from unknown or unverified senders is dropped. The extra sender addresses you allow are stored with your settings.

Connected AIs, the CLI and hooks

  • When you connect an AI assistant or coding agent (for example through the CLI, or by approving a connection from an AI app), we store the connection’s name, when it was created and last used, and a hash of its access token (never the token itself). Apps that connect this way register a name and return address with us.
  • A connected AI can add things to your dump and read your today, your three and related context. Each change it makes carries a receipt with its name.
  • The coding-agent hook runs on your computer. It only contacts Nuffo when a command looks like it starts a new project (like npm create or git clone), and then sends that command, the target folder path and, if there is one, the git remote address. At the start of an agent session it asks for your context. We use these to decide whether the work fits one of your three. They are stored only if the work gets linked to a project (the folder or remote is saved as that project’s scope) or in the receipt that records what happened. The hook never sends your code or file contents.

Technical data

  • IP address, used briefly for rate limits (to stop abuse such as password guessing). These counters are kept for minutes, not days.
  • Standard request logs and error logs from our hosting provider (time, address, page, status, browser type), kept for a few days to keep the service running and secure.
  • The device label of each signed-in session (for example “iPhone”), so you can tell them apart.

No analytics, no ad trackers, no third-party scripts, no tracking pixels. The site’s fonts are served from our own domain.

If you don’t have an account

  • Waitlist: if you joined it, your email, the three things you entered, and the rough number of projects you said you started this year.
  • The scatter-o-meter (/scatter): anyone can type an X handle. We read that account’s recent public posts through a data provider, have an AI model find the projects and ideas in them, and save only the resulting card: the handle, display name, the counts, up to three short exact quotes from the posts, and the playful text. The posts themselves are not stored. Cards are public at their own link (and kept out of search engines). Anyone can press “remove this result” on a card, which deletes it and stops that handle from being run again. To ask for removal another way, email hello@nuffo.app.
03

How we use it

#
  • To run Nuffo: store your things, sort what you dump, suggest your three, keep the limits, show receipts and undo.
  • To send you emails: account emails (welcome, password reset) and, unless you turn them off, the morning plan and the Sunday recap. Every ritual email has a one-click stop link, and you can change them in settings.
  • To keep Nuffo safe: rate limits, sign-in checks, abuse prevention, fixing errors.
  • To make sorting better, by measuring how often it gets things right (from your corrections).
  • To answer you when you write to us.

We don’t sell your data. We don’t show ads. We don’t share your data for advertising, and we don’t build a profile of you for anyone else.

Legal bases (for people in the EU, UK and similar places)

  • Contract: running the service you signed up for, including sorting, AI features you use, and account emails.
  • Legitimate interests: security, rate limits and logs; measuring sorting quality; ritual emails (which you can stop in one click); the scatter-o-meter’s processing of public posts, which is limited to a playful card and can be removed at any time.
  • Consent: your public page (off until you turn it on), microphone access, and connecting an AI. You can withdraw any of these at any time.
04

AI in Nuffo

#

Nuffo uses AI models to do the tedious parts. Here is exactly what each feature sends, and to whom (by kind of provider):

What each AI feature sends
featurewhat is sentwho processes it
sortingthe text you dump and the names and keywords of your three projectsa specialised AI judgment provider; if it's unavailable, an AI model run by our hosting provider
suggested threethe text of candidate tasks and your projects' namesthe AI judgment provider
does this fit your three? (hooks)the command, folder path and git remote, and your projects' names and keywordsthe AI judgment provider
chat and talk it throughyour messages, your local time, and a short snapshot: today, your three, up to 25 later items, 12 wishes, ideas cooling off, and your about-you notean AI model provider, reached through an AI routing service
help me break it downthe project's name and its existing stepsan AI model provider (same route as chat)
voice on the webthe audio recordinga speech-to-text model run by our hosting provider
forwarded emailsthe subject, your note and the email text (up to about 5,000 characters)an AI model run by our hosting provider
scatter-o-meterthe public posts of the handle enteredan AI model provider (same route as chat); optionally the AI judgment provider

Training. We don’t use your content to train AI models. The provider that runs our sorting, voice and email models and the AI judgment provider both state in their terms that they do not train models on what we send them. For chat and step drafting, we only allow model providers that don’t store or train on what we send, and the routing service in between doesn’t train on it either.

AI can be wrong. Sorting that isn’t confident asks you instead of acting. Every AI change comes with a receipt and can be undone. And no AI, chat or connected agent can put anything on your today: only you can.

05

Who helps us run it

#

We use a small number of service providers (“processors”) who handle data only to provide their service to us. They are:

Service providers by category
provider typewhat they dowhat they see
hosting providerruns the website, apps' backend, database, backups, logs, inbound email and some AI modelseverything stored in Nuffo, requests, forwarded emails, web voice recordings
AI judgment providersorting, the suggested three, matching work to your threethe text described in the AI table above
AI routing service and model providerchat, talk it through, step drafting, scatter-o-meterthe text described in the AI table above
email delivery providersends account and ritual emailsyour email address and the email's content (for example your plan for the day)
sign-in providers you chooseGoogle or Apple sign-inthat you signed in to Nuffo
social-post data providerscatter-o-meter onlythe X handle entered (it returns that account's public posts)

Beyond these, we share personal data only if the law requires it (for example a valid court order), to protect people’s safety or the service from abuse, or as part of a sale or transfer of Nuffo, in which case this policy keeps applying to your data and we’ll tell you first.

06

Your public page

#

Your public page (nuffo.app/your-handle) is off unless you turn it on in settings. When it is on, it shows your first name and handle, the month you joined, the projects you marked public with their progress, and what you finished in the last seven days on those projects, plus counts (wins this week, ideas cooled). It never shows what you started, your today, your later list, your wishes or your notes. There are no public like counts, follower counts or leaderboards. Turn it off and the page disappears.

07

Cookies and storage

#

Nuffo uses only what it needs to work. No tracking or advertising cookies, so there’s no cookie banner.

Cookies and browser storage
namewhat forhow long
nuffo_sessionkeeps you signed in30 days, renewed while you use Nuffo; removed when you sign out
g_state, g_verifier, g_nextprotect Google sign-in and remember where to go after10 minutes
nuffo_spot_skipremembers that you skipped this week's wish spotlight8 days
chat history (session storage)keeps your chat while the tab is openuntil you close the tab
08

The iPhone app

#
  • Your sign-in token is kept in the iPhone Keychain. The app, its widgets and its share extension share a small local store on your phone: the latest copy of your day (so widgets can show it), captures waiting to be sent while you’re offline, and app settings.
  • Microphone and speech recognition are asked for only when you first hold to talk. See Voice above.
  • The morning nudge is a notification scheduled on your phone. No push server is involved. A few times a day iOS may wake the app in the background to send waiting captures and refresh your widgets.
  • The share extension only saves something when you tap to save it.
  • The app contains no analytics or advertising code.
09

How long we keep it

#
  • Your account and everything in it: until you delete it (or delete the things themselves).
  • Voice recordings: not kept at all. Forwarded emails: not kept, only the items they became.
  • Chat conversations: not kept on our servers.
  • Password reset links: expire after one hour. Sign-in sessions: expire after 30 days without use.
  • Rate-limit counters: minutes. Request and error logs: a few days.
  • Backups: our database provider keeps point-in-time backups for up to 30 days, so deleted data fully disappears from backups within about 30 days.
  • Waitlist entries: until you ask us to remove them, or until the waitlist is no longer needed.
  • Scatter-o-meter cards: until removed (anyone can remove one from the card itself).
10

Download or delete everything

#

In settings, under “your data”:

  • Download everything gives you one JSON file with your account details, items, projects and steps, ideas, today history, receipts and sorting corrections.
  • Delete my account permanently deletes your account and everything in it right away: your things, your projects, receipts, connections to AIs, sessions and sign-in links. It can’t be undone. Copies in backups expire within about 30 days.

To disconnect a coding agent, run npx @nuffo/cli disconnect or revoke it in settings. If you joined the waitlist or can’t sign in, email hello@nuffo.app and we’ll handle it.

11

Security

#
  • Everything travels over HTTPS (with HSTS). The site uses a strict content security policy.
  • Passwords are stored only as salted PBKDF2 hashes.
  • Session tokens, AI connection tokens, password reset links and sign-in codes are stored only as SHA-256 hashes, so a copy of our database wouldn’t let anyone sign in as you.
  • AI connection tokens can only add to your dump and read context; they can’t write your today. You can revoke them anytime.
  • Link preview images are fetched by our server, so the sites you save never see your IP address.

No system is perfectly secure. If we ever learn of a breach that affects your data, we’ll tell you and the relevant authorities as the law requires. Found a security issue? Please write to hello@nuffo.app.

12

Your rights

#

Wherever you live, you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct it;
  • delete it;
  • give it to you in a portable format (the JSON download does this);
  • stop or limit using it, or object to how we use it;
  • withdraw a consent you gave.

Most of this you can do yourself in settings. For anything else, email hello@nuffo.app from the address on your account. We’ll answer within 30 days, and it’s free. We may need to check it’s really you.

If you’re in the EU, UK or a similar place, you can also complain to your local data protection authority. If you’re in California or another US state with a privacy law: we don’t sell or share personal information for cross-context behavioral advertising, we don’t use sensitive data to infer things about you, and we won’t treat you differently for using your rights.

13

Children

#

Nuffo is not for anyone under 16, and we don’t knowingly collect data from them. If you think a child under 16 has an account, write to hello@nuffo.app and we’ll delete it.

14

Where your data lives

#

Nuffo runs on a global cloud network, and our service providers may process data in the United States and other countries, which may have different data protection laws from yours. We choose providers that commit to protecting the data they handle for us, and we send them only what their job needs.

15

Changes to this policy

#

If we change this policy, we’ll update the date at the top. If a change is significant (for example a new kind of data or a new use), we’ll tell you by email or in the app before it takes effect.

16

Contact

#

Thomas Kanze, Nuffo · hello@nuffo.app · about Nuffo

Questions about any of this? Write to hello@nuffo.app. A real person answers.

Three things
is enough.

nuffonuffo.app · made by Thomas, @thomaskanze
how it workscomparescatter-o-meteraboutsign inhello@nuffo.appprivacyterms