FormFlow privacy policy
Last updated: 12 August 2026
FormFlow is a tool for filling in work forms on site — inspections, permits, sign-offs — run by Naylo Systems Ltd (“we”). This page says what information the product holds, where it goes, and how long it stays, in plain words. If anything here is unclear, or you want something corrected or deleted, contact hello@naylosystems.com.
The short version
- FormFlow stores what your workspace puts into it: accounts, forms, and the answers, photos, signatures and locations filled into those forms. That data belongs to the company running the workspace — usually your employer — and we process it on their behalf.
- We use no cookies and no analytics or tracking of any kind.
- We never sell data, and nothing is shared with a third party except the services named below, each for a specific job.
- Your location is captured only when you tap the button on a location question — never in the background.
What we collect
Your account
Your work email address, an account identifier, your role in the workspace (“badge”), and when you joined. Your password is held by our database provider’s sign-in system in protected (hashed) form — we never see it. If you were invited but haven’t joined yet, the invite holds your email and who invited you.
What goes on the forms
Everything filled in: text answers, dates, numbers — and, where the form includes those questions, photos you take or attach, a signature drawn on screen, files you upload (we keep the filename you gave them), and a location point. The location is precise coordinates, captured only at the moment you tap the location button on that question. Photos and files are stored in a private bucket that only your workspace can access.
Records of who did what
Every submission is stamped with who filed it and when. Corrections keep a permanent before-and-after copy, and multi-stage forms keep a sign-off trail: who approved, who sent back (with the note they wrote when sending back), and when. This is deliberate — these are site records, and their value is that they cannot be quietly altered. Where a job’s attendance feature is used, tapping “Mark me present” records your name against that site and day, like a signing-in sheet.
Public form links
A form shared by public link can be filled without an account. We store the answers and, if the person chooses to give one, their email address. Their IP address is used only in the server’s memory for up to a minute to limit abuse — it is never written to the database or to any log.
Where it lives
All of the above is stored with Supabase (our database, sign-in and file-storage provider), in their Central EU (Frankfurt, Germany) region. Access is controlled row by row in the database itself: a field worker sees their own work, and wider access follows the role your workspace gave you.
On your phone, the app keeps an offline copy of your workspace — forms, site documents, and submissions you’re allowed to see — so it works with no signal. Signing out wipes that copy. One exception, on purpose: finished forms still waiting to send stay on the phone until they reach the server, so signing out in a dead zone can’t destroy a day’s work.
In your browser, we keep your sign-in session and the same offline outbox. We set no cookies at all.
What leaves FormFlow, and to whom
- Supabase — hosts everything above; that is where the data lives.
- Anthropic — only if an admin uses “Build from a document”: the single document they chose (a PDF, Word file or photo of a paper form) is sent, via our server, to Anthropic’s AI to suggest form questions. Whatever is written on that document goes with it. Nothing is stored by that process, and nothing else is ever sent there.
- OpenStreetMap — the little map behind a recorded location is drawn from their map tiles. Requesting tiles tells their servers your device’s IP address and the rough map area being viewed. If tiles are unavailable, the coordinates still show.
- Services your workspace admin connects — a workspace can set up automatic actions: emailing a copy of a submission (including to addresses outside the workspace), or filing it into Google Sheets/Drive, Microsoft SharePoint/OneDrive, Slack or similar. What leaves is the answers as text and file names — photos and signatures themselves are never attached; the copy says to open them in FormFlow. These actions only exist if an admin sets them up.
- Email — sign-in and password-reset emails, and the workspace-configured notifications above.
There is no analytics, advertising, tracking or crash-reporting service in the product. If that ever changes, this page will change first.
How long we keep it
Submissions and their history are the point of the product — they are kept for as long as the workspace keeps them. A workspace admin can delete a submission, and deleting a form removes its submissions. When someone leaves a workspace, their access ends immediately; records they created remain, as they would on paper, with their name on them.
Your rights
Under UK data protection law you can ask for a copy of what we hold about you, ask for corrections, and ask for deletion. Because most data here belongs to the workspace that employs or engages you, the quickest route is usually your workspace admin — but you can always contact us directly at hello@naylosystems.com and we will help, normally within one month. If you are unhappy with our answer you can complain to the ICO (ico.org.uk).
To have your account and its data deleted, see Delete your FormFlow account, which explains how to ask and what happens to site records.
Children
FormFlow is a workplace tool and is not directed at children.
Changes
If we change what is collected or where it goes, we will update this page and change the date at the top before the change goes live.