Privacy policy
What we collect when you use Flourish, why we hold it, who else sees it, and how to get it back or get rid of it.
Last updated 2 August 2026
Who we are
Flourish is a service run by Institute for the Future of Work, a charity registered in England and Wales, charity number 1180718, company number 11263261, registered at Fieldfisher, Riverbank House, 2 Swan Lane, London EC4R 3TT.
We are the data controller for the personal data described here. That means we decide what is collected and why. Questions about data protection go to privacy@flourish.so.
This policy covers the Flourish app you sign in to. Partner pages that carry another organisation’s branding are still run by us and still covered.
What we collect
Almost everything we hold is something you told us. The rest is what the software has to record to work.
- Your account. An email address, and a name if you give one. Sign-in is handled by Clerk, so your password is held by Clerk and never reaches us.
- Your answers during setup. Where you are, roughly what stage of life you are at, what you want out of work, and which kinds of work interest you. Location can be a town, a city or a postcode.
- Your CV, if you add one. You can upload a file or paste the text. We keep the file and the skills and experience read out of it.
- What you say to Moss, our assistant. Conversations are saved so you can come back to them.
- What you do in the product. Jobs and courses you save, plans you make, exercises you finish, check-ins you answer, searches you run.
- Support conversations, if you use the chat or email us.
- Technical records. Your IP address, your browser and device, and the pages you asked for. This is how any website works, and it is how we find faults.
- Measurement of how the product is used, which is switched on only if you agree. See the cookie policy for exactly what that involves.
We do not ask for your ethnicity, your health, your religion or anything else the law calls special category data. If you happen to write something like that to Moss or into your CV, it is stored the same way as the rest of that conversation or document, and you can delete it.
Flourish is built for adults looking for work. It is not designed for children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will remove it.
Why we use it
- To show you work, courses and next steps that fit what you can do and where you are.
- To read a CV you give us, so you do not have to type your history into a form.
- To answer you through Moss, using what you have already told us so you are not asked twice.
- To keep your account secure and to stop misuse.
- To fix things that break, which means reading error reports and, sometimes, a masked replay of what happened on screen.
- To understand which parts of the product help and which do not, if you have agreed to analytics.
- To email you about your account, and about other things only if you asked for them.
We do not sell your data. We do not share it with advertisers. We do not show your profile to employers unless you ask us to.
Our lawful basis
UK data protection law asks us to name a reason for each use. Ours are these.
- Performing our contract with you. Running your account, saving your work and answering you through Moss are the service you signed up for.
- Your consent. Analytics, and any marketing email, happen only if you say yes, and you can change your mind at any time in Settings.
- Our legitimate interests. Keeping the service secure, preventing abuse, diagnosing faults and improving the product, weighed against the effect on you.
- Legal obligation. Keeping records we are required to keep, such as records of payment.
Moss, and what happens to what you type
Moss is an assistant built on large language models we do not own. When you send a message, that message and the parts of your profile Moss needs are sent to Google Cloud Vertex AI, which runs the Gemini models. If Gemini is unavailable, the same content may go to Anthropic instead.
When Moss needs something from the open web, the search it runs is sent to Firecrawl. When Moss answers, a trace of the exchange is sent to Langfuse, which is how we find out that an answer was wrong or unhelpful. Those traces contain what you asked.
Moss can be wrong. It is a starting point for thinking about work, not advice about your benefits, your immigration status, your health or your legal position. Check anything that matters with the organisation responsible for it.
Do not type anything into Moss that you would not want stored. If you already have, you can delete the conversation, and you can ask us to remove it from our systems.
Your CV
A CV you upload goes straight from your browser to Google Cloud Storage using a one-time link we issue. We then read the text out of it, and send that text to a language model, currently OpenAI or a model reached through OpenRouter, to turn it into a structured list of skills and experience.
We keep both the file and the structured version so you can see what we read and correct it. Deleting the document in Flourish removes both.
Who else sees it
We use other companies to run parts of the service. They act on our instructions and may only use your data to do the job we ask of them.
| Who | What they do for us | What reaches them |
|---|---|---|
| Clerk | Signs you in and holds your account credentials. | Your email address, your name if you give one, and sign-in activity such as the times and devices you signed in from. |
| Google Cloud | Runs our servers, our database and the store your CV is uploaded to. | Everything you save in Flourish. Our production services run in Google’s European regions. |
| Google Cloud Vertex AI | Runs the Gemini models behind Moss, our assistant. | What you type to Moss, and the parts of your profile Moss needs to answer. |
| Anthropic | Provides a Claude model Moss falls back to when Gemini is unavailable. | The same conversation content, only during a fallback. |
| Langfuse | Records what Moss did with a question so we can find and fix bad answers. | Conversation traces, which include what you asked and what Moss replied. |
| Firecrawl | Fetches pages from the open web when Moss needs to look something up. | The search terms Moss sends, which can contain what you asked. |
| OpenAI, and OpenRouter where it is configured as the route to a model | Reads an uploaded CV and turns it into a list of skills and experience. | The text of your CV. |
| PostHog | Measures which parts of the product get used, once you have agreed. | Pages viewed and actions taken, tied to your account identifier after you sign in. Our project is hosted in the European Union. |
| Sentry | Tells us when the app breaks, and records a replay of some sessions. | Error reports, and session replays with all text masked and images blocked. |
| Stripe | Takes payment for paid plans. | Your payment details, which go to Stripe directly. We never see or store your card number. |
| Better Stack | Collects our server logs so we can diagnose faults. | Technical records of requests, which can include an account identifier. |
| Google Maps | Draws the maps on pages that show where work is. | Your browser’s requests to Google for map tiles when you open one of those pages. |
| Vercel | Hosts and serves the website itself. | The technical details of every request, such as your IP address. |
We also share data when the law requires it, and if Flourish is ever sold or merged, in which case we would tell you first.
Where your data is held
Our own systems run in Google Cloud’s European regions, and our analytics project is hosted in the European Union. Some of the companies above are based outside the UK, or run part of their service outside it, so some data is transferred abroad. Where that happens we rely on the transfer safeguards UK law provides, such as the International Data Transfer Agreement or an adequacy decision.
Ask privacy@flourish.so about any particular provider and we will tell you where it holds data and which safeguard applies.
How long we keep it
We keep your data while your account is open. Closing your account deletes it straight away, not after a waiting period: your record goes, then your uploaded files and your sign-in. What survives is records we are required to keep, such as payment records, and backups that expire on their own schedule.
Some things go sooner than that, while your account is still open. Searches you have run are deleted after 90 days, conversations with Moss after 365 days, and the security records of who changed what after 730 days.
Measurement data held by PostHog and error data held by Sentry are kept to those providers’ retention settings, and are not tied to you once your account is gone.
Your rights
UK data protection law gives you rights over your data, and you do not need a reason to use them.
- See what we hold. Settings has a button that sends you a copy of your data.
- Correct anything wrong. Most of it you can edit yourself.
- Delete your account and your data. Settings has a delete option, and it removes the account, not just the login.
- Take your data elsewhere in a machine-readable form.
- Object to, or ask us to limit, processing we do on the basis of our legitimate interests.
- Withdraw consent for analytics or marketing, at any time, without affecting anything that happened before.
Write to privacy@flourish.so to use any of these. We answer within one month. If you are not happy with how we handled it you can complain to the Information Commissioner’s Office at ico.org.uk, and we would rather you told us first so we can put it right.
Automated decisions
Flourish sorts and suggests. It ranks jobs and courses against what you told us, and Moss writes answers using a model. None of that decides anything about you. We do not use automated processing to grant or refuse anything with a legal or similarly significant effect, and no employer gets a score for you from us.
Keeping it safe
Traffic to Flourish is encrypted in transit, and data is encrypted at rest by Google Cloud. Access to production systems is limited to people who need it. Sign-in is handled by Clerk, so we never hold your password. Sentry session replays mask all text and block images before they leave your browser.
No service is perfectly secure. If you think you have found a weakness in ours, write to security@flourish.so and we will look at it.
Changes to this policy
When we change something that matters, we will update the date at the top and tell you in the app or by email. Smaller corrections are made without notice.
Contact us
Email privacy@flourish.so about anything in this policy, or write to us at Fieldfisher, Riverbank House, 2 Swan Lane, London EC4R 3TT.
