What Neaflo knows about you.
Draft · last reviewed 24 July 2026
This is a working draft, not a finished legal document. It describes current behaviour accurately, but it has not been reviewed by a lawyer and must be replaced before Neaflo collects emails at scale or opens paid plans.
The short version
Your files
Scanning, planning, previewing, and moving local files happen entirely on your device through the local engine bundled with the app. Neaflo does not need to upload local files to its servers to run a workflow, and the current build contains no code path that does so.
Rules operate on file metadata only: name, extension, derived file category, dates, size, and file age. File contents are never opened, parsed, or interpreted.
What stays on your machine
The following live in a local database next to the application and are not synced anywhere:
- Your workflows, including folder paths and rule configuration.
- Run history: each run, each individual operation, and its source and destination path.
- Application settings, including onboarding progress.
Google Drive (beta)
If you connect a Google account, the connection is made from your device. The refresh token is stored in your operating system credential vault, not in the local database and not on a Neaflo server.
Drive operations use Google APIs directly, addressing files by their Drive file and parent IDs together with a version, so recovery and undo can be performed safely. File content is not proxied through Neaflo infrastructure.
The desktop app requests exactly two Google Drive scopes, and only when you choose to connect Drive:
- drive.metadata — to read file names, types, and folder structure so a workflow can decide where a file belongs. Neaflo does not open file contents.
- drive.file — to move and organise only the files you have opened with or created through Neaflo. It gives no access to the rest of your Drive.
What Neaflo never sends to its own servers
This holds for local folders and for Google Drive alike. Neaflo's own backend never receives:
- File contents.
- File names, folder names, or paths — local or in Drive.
- File metadata such as sizes, dates, or types.
- Your workflows, or the history of runs they produced.
The website
This site is separate from the desktop app, and being local-first is a property of the app rather than of the website. Any analytics used here will be named on this page before it is enabled, kept minimal, and will never receive file names, workflow contents, or demo data.
The interactive demo on this site runs in your browser with fictional filenames. It does not read anything from your computer.
Accounts and sign-in
Creating an account on this website is optional and only needed to manage a plan. Sign-in is handled by our authentication provider; your password never touches Neaflo servers. The account stores your email address and plan status, nothing about your files.
Email addresses
If you give us an email address—for product updates, a purchase, the waitlist, or feedback—it is used for that purpose and nothing else. It is not sold, and it is not used to build a profile.
You can ask for it to be deleted at any time and we will remove it.
Changes to this notice
This notice will change as the product does. Material changes—new data collection, analytics, or a payment provider—will be reflected here with a new review date before the behaviour ships.
Questions about any of this
If something here is unclear, or you want your email removed from our list, ask and we will do it. No form to fill in twice.
Contact us