Privacy policy

What we collect when you use Flourish, why we hold it, who else sees it, and how to get it back or get rid of it.

Last updated 2 August 2026

Who we are

Flourish is a service run by Institute for the Future of Work, a charity registered in England and Wales, charity number 1180718, company number 11263261, registered at Fieldfisher, Riverbank House, 2 Swan Lane, London EC4R 3TT.

We are the data controller for the personal data described here. That means we decide what is collected and why. Questions about data protection go to privacy@flourish.so.

This policy covers the Flourish app you sign in to. Partner pages that carry another organisation’s branding are still run by us and still covered.

What we collect

Almost everything we hold is something you told us. The rest is what the software has to record to work.

  • Your account. An email address, and a name if you give one. Sign-in is handled by Clerk, so your password is held by Clerk and never reaches us.
  • Your answers during setup. Where you are, roughly what stage of life you are at, what you want out of work, and which kinds of work interest you. Location can be a town, a city or a postcode.
  • Your CV, if you add one. You can upload a file or paste the text. We keep the file and the skills and experience read out of it.
  • What you say to Moss, our assistant. Conversations are saved so you can come back to them.
  • What you do in the product. Jobs and courses you save, plans you make, exercises you finish, check-ins you answer, searches you run.
  • Support conversations, if you use the chat or email us.
  • Technical records. Your IP address, your browser and device, and the pages you asked for. This is how any website works, and it is how we find faults.
  • Measurement of how the product is used, which is switched on only if you agree. See the cookie policy for exactly what that involves.

We do not ask for your ethnicity, your health, your religion or anything else the law calls special category data. If you happen to write something like that to Moss or into your CV, it is stored the same way as the rest of that conversation or document, and you can delete it.

Flourish is built for adults looking for work. It is not designed for children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will remove it.

Why we use it

  • To show you work, courses and next steps that fit what you can do and where you are.
  • To read a CV you give us, so you do not have to type your history into a form.
  • To answer you through Moss, using what you have already told us so you are not asked twice.
  • To keep your account secure and to stop misuse.
  • To fix things that break, which means reading error reports and, sometimes, a masked replay of what happened on screen.
  • To understand which parts of the product help and which do not, if you have agreed to analytics.
  • To email you about your account, and about other things only if you asked for them.

We do not sell your data. We do not share it with advertisers. We do not show your profile to employers unless you ask us to.

Our lawful basis

UK data protection law asks us to name a reason for each use. Ours are these.

  • Performing our contract with you. Running your account, saving your work and answering you through Moss are the service you signed up for.
  • Your consent. Analytics, and any marketing email, happen only if you say yes, and you can change your mind at any time in Settings.
  • Our legitimate interests. Keeping the service secure, preventing abuse, diagnosing faults and improving the product, weighed against the effect on you.
  • Legal obligation. Keeping records we are required to keep, such as records of payment.

Moss, and what happens to what you type

Moss is an assistant built on large language models we do not own. When you send a message, that message and the parts of your profile Moss needs are sent to Google Cloud Vertex AI, which runs the Gemini models. If Gemini is unavailable, the same content may go to Anthropic instead.

When Moss needs something from the open web, the search it runs is sent to Firecrawl. When Moss answers, a trace of the exchange is sent to Langfuse, which is how we find out that an answer was wrong or unhelpful. Those traces contain what you asked.

Moss can be wrong. It is a starting point for thinking about work, not advice about your benefits, your immigration status, your health or your legal position. Check anything that matters with the organisation responsible for it.

Do not type anything into Moss that you would not want stored. If you already have, you can delete the conversation, and you can ask us to remove it from our systems.

Your CV

A CV you upload goes straight from your browser to Google Cloud Storage using a one-time link we issue. We then read the text out of it, and send that text to a language model, currently OpenAI or a model reached through OpenRouter, to turn it into a structured list of skills and experience.

We keep both the file and the structured version so you can see what we read and correct it. Deleting the document in Flourish removes both.

Who else sees it

We use other companies to run parts of the service. They act on our instructions and may only use your data to do the job we ask of them.

Companies that process data on our behalf
WhoWhat they do for usWhat reaches them
ClerkSigns you in and holds your account credentials.Your email address, your name if you give one, and sign-in activity such as the times and devices you signed in from.
Google CloudRuns our servers, our database and the store your CV is uploaded to.Everything you save in Flourish. Our production services run in Google’s European regions.
Google Cloud Vertex AIRuns the Gemini models behind Moss, our assistant.What you type to Moss, and the parts of your profile Moss needs to answer.
AnthropicProvides a Claude model Moss falls back to when Gemini is unavailable.The same conversation content, only during a fallback.
LangfuseRecords what Moss did with a question so we can find and fix bad answers.Conversation traces, which include what you asked and what Moss replied.
FirecrawlFetches pages from the open web when Moss needs to look something up.The search terms Moss sends, which can contain what you asked.
OpenAI, and OpenRouter where it is configured as the route to a modelReads an uploaded CV and turns it into a list of skills and experience.The text of your CV.
PostHogMeasures which parts of the product get used, once you have agreed.Pages viewed and actions taken, tied to your account identifier after you sign in. Our project is hosted in the European Union.
SentryTells us when the app breaks, and records a replay of some sessions.Error reports, and session replays with all text masked and images blocked.
StripeTakes payment for paid plans.Your payment details, which go to Stripe directly. We never see or store your card number.
Better StackCollects our server logs so we can diagnose faults.Technical records of requests, which can include an account identifier.
Google MapsDraws the maps on pages that show where work is.Your browser’s requests to Google for map tiles when you open one of those pages.
VercelHosts and serves the website itself.The technical details of every request, such as your IP address.

We also share data when the law requires it, and if Flourish is ever sold or merged, in which case we would tell you first.

Where your data is held

Our own systems run in Google Cloud’s European regions, and our analytics project is hosted in the European Union. Some of the companies above are based outside the UK, or run part of their service outside it, so some data is transferred abroad. Where that happens we rely on the transfer safeguards UK law provides, such as the International Data Transfer Agreement or an adequacy decision.

Ask privacy@flourish.so about any particular provider and we will tell you where it holds data and which safeguard applies.

How long we keep it

We keep your data while your account is open. Closing your account deletes it straight away, not after a waiting period: your record goes, then your uploaded files and your sign-in. What survives is records we are required to keep, such as payment records, and backups that expire on their own schedule.

Some things go sooner than that, while your account is still open. Searches you have run are deleted after 90 days, conversations with Moss after 365 days, and the security records of who changed what after 730 days.

Measurement data held by PostHog and error data held by Sentry are kept to those providers’ retention settings, and are not tied to you once your account is gone.

Your rights

UK data protection law gives you rights over your data, and you do not need a reason to use them.

  • See what we hold. Settings has a button that sends you a copy of your data.
  • Correct anything wrong. Most of it you can edit yourself.
  • Delete your account and your data. Settings has a delete option, and it removes the account, not just the login.
  • Take your data elsewhere in a machine-readable form.
  • Object to, or ask us to limit, processing we do on the basis of our legitimate interests.
  • Withdraw consent for analytics or marketing, at any time, without affecting anything that happened before.

Write to privacy@flourish.so to use any of these. We answer within one month. If you are not happy with how we handled it you can complain to the Information Commissioner’s Office at ico.org.uk, and we would rather you told us first so we can put it right.

Automated decisions

Flourish sorts and suggests. It ranks jobs and courses against what you told us, and Moss writes answers using a model. None of that decides anything about you. We do not use automated processing to grant or refuse anything with a legal or similarly significant effect, and no employer gets a score for you from us.

Cookies and browser storage

The cookie policy has the full detail. In short, a few cookies are needed for the product to work at all, analytics cookies are set only after you agree, and quite a lot is kept in your browser’s own storage rather than in a cookie so that pages open quickly.

Cookies Flourish needs to work
NameSet byWhat it doesHow long it lasts
__session, __client_uat and other names beginning __clerkClerk, our sign-in providerKeeps you signed in and stops someone else using your session.Managed by Clerk. Cleared when you sign out.
flourish_analytics_consentFlourishRemembers whether you said yes or no to analytics, so we stop asking.365 days
flourish_marketing_consentFlourishRemembers whether you said yes or no to advertising measurement. Nothing of that kind is loaded yet, and this cookie is how it stays that way until you change your mind.365 days
flourish_attrFlourishRemembers which page or partner site sent you here, so sign-up can be credited to it. It holds a page name, a partner name, a category and campaign tags. It holds nothing about you.60 minutes, and it is cleared as soon as you sign in
NEXT_LOCALEFlourish, through the next-intl libraryRemembers which language you chose.Set by the library, typically one year
sidebar:stateFlourishRemembers whether you left the side menu open or closed.7 days
Cookies and storage used for analytics, only after you agree
NameSet byWhat it doesHow long it lasts
ph_… _posthog cookie and matching browser storagePostHogRecognises the same browser across visits, so a return visit is not counted as a new person. Nothing is written until you agree. Before then we measure in memory only, and it disappears when you close the tab.Set by PostHog, typically one year
flourish:sign_up_recordedFlourishRemembers that your sign-up has already been counted, so it is not counted twice.Until you clear your browser storage
What Flourish keeps in your browser storage rather than in a cookie
KeyWhereWhat it holds
flourish-query-cacheLocal storageA copy of recent answers from our API so pages open instantly instead of reloading. On a signed-in device this can include your profile, saved jobs and other things you have already seen. Signing out and clearing your browser data removes it.
flourish_moss_messages, flourish_moss_quick_replies, flourish_moss_extras, flourish_moss_session_mapSession storage, and local storage for the session mapKeeps a conversation with Moss on screen while you move between pages. Session storage clears when you close the tab.
flourish:assistant-chatLocal storageKeeps the corner assistant conversation when you navigate.
flourish:attributionSession storageThe same arrival context as the flourish_attr cookie, kept for the rest of the visit so onboarding can prefill.
flourish:localeLocal storageThe language you chose.
themeLocal storageLight or dark mode, set by the next-themes library.
flourish.search.recent and flourish.search.historyLocal storageYour recent searches, so the search box can offer them again.
flourish-active-location, flourish-my-location, flourish-search-location and flourish-recent-locationsLocal storageThe area you were last looking at, and areas you searched for before, so a page does not ask again.
flourish:today-mood and flourish:checkin-todayLocal storageYour answer to today’s check-in, so the same question is not asked twice in one day.
flourish:motivation-map and flourish:guided-unit:…Local storageDraft answers in a guided exercise, kept on your device so you do not lose them.
flourish:landing-researchSession storageThe question you asked before signing in, and what we found, so you can carry on where you left off. Cleared when you close the tab.
flourish:cv-nudge-dismissed, flourish:setup-banner-dismissed, flourish-welcome-dismissedLocal storageRemembers that you closed a prompt, so it stays closed.

Keeping it safe

Traffic to Flourish is encrypted in transit, and data is encrypted at rest by Google Cloud. Access to production systems is limited to people who need it. Sign-in is handled by Clerk, so we never hold your password. Sentry session replays mask all text and block images before they leave your browser.

No service is perfectly secure. If you think you have found a weakness in ours, write to security@flourish.so and we will look at it.

Changes to this policy

When we change something that matters, we will update the date at the top and tell you in the app or by email. Smaller corrections are made without notice.

Contact us

Email privacy@flourish.so about anything in this policy, or write to us at Fieldfisher, Riverbank House, 2 Swan Lane, London EC4R 3TT.