Privacy

Privacy policy.

What this site collects, why it collects it, who else touches it and how long it stays — written to be read rather than to be survived.

Last updated 18 August 2026 · effective 18 August 2026

Who we are

This site is operated by Fluvius USA Inc, a company incorporated in California and shipping software since 2017, with senior engineers across Europe. For everything described on this page, Fluvius USA Inc is the controller of your personal data under the UK and EU General Data Protection Regulation, and the business under the California Consumer Privacy Act as amended by the CPRA.

Registered address: 1401 21st St, Ste R, Sacramento, CA 95811, United States.

This page covers fluvius.co and the forms on it. Work we do for a client is governed by the agreement signed with that client, and any personal data inside a client's own systems is handled under that agreement and the data processing addendum attached to it, where we act as a processor rather than a controller.

What we collect

Three kinds of information, and nothing beyond them.

What you choose to send us

Every form on this site is the same short brief. Depending on which one you use, it carries:

  • your name;
  • your business email address, and the domain it belongs to;
  • your company website, where you give one;
  • your role, chosen from a list;
  • what needs work, and your budget and timeline, chosen from a list;
  • the message you write, and the answers you give to the 60-second quiz;
  • the transcript, if you talk to the assistant on the site;
  • the details you type into the booking calendar, if you pick a slot.

All of it is optional in the ordinary sense: it reaches us because you typed it and pressed send.

What arrives with it

A form submission carries a small amount of context that the browser sends by design, and that we record alongside it:

  • your IP address;
  • your browser's user-agent string;
  • the page you sent it from, and the page that referred you there;
  • UTM parameters, where the link you followed carried them;
  • the date and time.

We use this to answer you in context, to keep the channel clear of automated submissions, and to understand which pages bring real conversations.

What we deliberately leave alone

Reading these pages sets nothing on your device until you say so. Measurement and advertising cookies stay switched off until you accept them in the bar that greets a first visit, and the Cookies section below sets out exactly what each one does. We ask for no special category data — health, biometrics, politics, beliefs, union membership, sex life or orientation — and we ask you not to put any into the message box.

Why, and on what basis

Under the GDPR every use of personal data needs a lawful basis. Ours are these.

What we doWhyLawful basis
Read your brief and reply to itYou asked us to. This is the whole point of the form.Steps taken at your request before entering a contract — Art. 6(1)(b)
Hold the brief so the conversation has a historySo a later reply still knows what you first asked.Legitimate interests — Art. 6(1)(f)
Check the submission is from a person, and rate-limit by IPTo keep the channel usable and free of automated submissions.Legitimate interests — Art. 6(1)(f)
Check that an email domain can receive mailSo a reply reaches you rather than bouncing.Legitimate interests — Art. 6(1)(f)
Confirm a booking you asked forTo send the invitation to the slot you picked.Steps taken at your request — Art. 6(1)(b)
Measure how the site is read, and which advertisement led hereTo learn which pages earn attention and where the budget is useful.Consent — Art. 6(1)(a), given in the cookie bar and withdrawable at any time
Send you the offer you asked for, and occasional email about our servicesYou ticked the box on the offer, so you are expecting to hear from us.Consent — Art. 6(1)(a), withdrawable from any message we send
Keep records where the law requires itTax, accounting and comparable duties.Legal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we have weighed them against your own interests and rights, and you may object at any time — see Your rights.

We do not use your details for unrelated marketing, and sending a brief leaves you off every mailing list. The one route onto a list is the offer popup, where a tick box asks in plain words and every message we send carries a one-click way back off.

Cookies

Two of the cookies here are what make the site work, and they are set whatever you choose. Everything else waits for your agreement: on a first visit a bar asks, and until you answer it — and afterwards, if you choose essentials only — every measurement and advertising key stays denied. Your answer is kept on your own device, and the Cookies link in the footer of every page brings the choice back whenever you want it.

Always on

CookieWhat it is forLife
Human checkRecords that you have already passed the Cloudflare Turnstile check, so you are asked once rather than at every step.1 day
SessionSet after a business email is verified, so the assistant and the booking step already know who they are talking to.Up to 30 days
Your cookie choiceRemembers the answer you gave the bar, so it is asked once. Stored in your browser rather than sent to us.Until you clear it

The first two are signed on our server, so a browser can see that they exist but cannot forge one. Cloudflare Turnstile itself may store a token on your device while it runs its check.

Only with your agreement

CookieSet byWhat it is forLife
_ga, _ga_<id>Google Analytics 4Counts a visit as one visit across pages: which pages hold attention, how long a reading lasts, and the route that brought you.Up to 2 years
_gcl_auGoogle AdsConnects a conversation that starts here to the advertisement that led to it, so the budget goes where it is useful.90 days
IDE, test_cookieGoogle (doubleclick.net)Audience and remarketing signals, where Google serves an advertisement of ours.Up to 13 months

We use Google Consent Mode v2, which means the tags on this page read your answer before they do anything. Choose essentials only and Google receives a signal that storage is denied: nothing is written to your device and nothing identifies you, while Google still counts the visit toward anonymous totals. Choose to accept and the cookies above are set. Either way, clearing your cookies clears all of it, and the site keeps working exactly as before.

Who else sees it

We sell nothing. A small number of services process data on our behalf so the site can function; each is bound by its own contract with us. Two of them — Google Analytics and Google Ads — run only once you have accepted them, and the row below says what reaches each.

ServiceIts partWhat reaches it
DigitalOceanHosting for the site and the form endpointEverything, in transit and at rest on the server
Cloudflare (Turnstile)Confirms a submission comes from a personIP address, browser signals, a challenge token
Google (Apps Script and Sheets)Where a brief is recordedThe brief and the context that arrived with it
SlackNotifies us that a brief has landedThe brief in summary
TidyCalThe booking calendarYour name and email, and the slot you pick
Google Analytics 4Measures how the site is read (only with your agreement)Page paths, time on page, referrer, device, and a coarse location that Google derives from an IP address it discards rather than stores, plus a cookie identifier
Google AdsConnects a conversation to the advertisement that led to it, and builds advertising audiences (only with your agreement)A click identifier, the pages you reached, whether a form was sent
Google FontsServes the two typefaces this site usesYour IP address, when a page loads
YouTube, via youtube-nocookie.comPlays the founder's introductionYour IP address — and only once you press play
Google (Gemini) and Anthropic (Claude)Answer questions in the assistant on the siteWhat you type into the assistant

The video is the clearest example of how we treat this: nothing is requested from YouTube, and no cookie of theirs is set, until you click play. Until then the page shows an image we host ourselves.

Beyond these, we disclose personal data only where the law requires it, or to our own professional advisers under a duty of confidence. If Fluvius is ever party to a merger or acquisition, personal data may pass to the successor under the same commitments, and we will say so here first.

Where it goes

We are a US company with a team across Europe, and the services above are largely US-based, so personal data from the UK or the EEA is transferred to the United States. Those transfers rest on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, and — for the providers that have certified — the EU-US, UK and Swiss-US Data Privacy Frameworks. You may ask us for a copy of the safeguards that apply to a given transfer.

How long we keep it

WhatHow long
A brief that led to no engagement24 months from your last message, then deleted
A brief that became a client relationshipFor the engagement, and 6 years after it ends, for tax and legal records
Assistant transcripts12 months
Server logs, including IP addresses90 days
CookiesAs set out above — 1 day, or up to 30 days

Ask us to erase your details sooner and we will, subject only to records we are required to keep.

Your rights

If the UK or EU GDPR applies to you, you have the right to:

  • know what we hold about you, and get a copy of it;
  • correct anything inaccurate or incomplete;
  • erase it, where we have no overriding reason to keep it;
  • restrict how we use it while a question about it is open;
  • receive it in a portable form, and have it sent to another controller where that is technically feasible;
  • object to any use that rests on our legitimate interests, including profiling;
  • withdraw consent at any time, where consent is what we relied on, without affecting what came before.

No decision about you is made by automated means alone. The lightweight score attached to a brief only decides the order we read them in; a person reads every one.

Write to us using the details below and we will answer within one month. There is no charge. We may ask a question or two to confirm it is really you asking. If our answer leaves you unsatisfied, you may complain to your local supervisory authority — in Ireland, the Data Protection Commission at dataprotection.ie; in the UK, the Information Commissioner's Office at ico.org.uk.

California

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we have collected, used and disclosed; to have it corrected; to have it deleted; and to be free of retaliation for exercising any of these.

In the last twelve months we have collected the categories described in What we collect — identifiers, commercial information, internet activity and professional information — for the purposes described in Why, and on what basis, from you directly and from your browser, and disclosed them for business purposes to the service providers listed in Who else sees it.

We do not sell personal information, and no financial incentive is attached to your data. Accepting advertising cookies lets Google Ads build audiences from your visit, which the CPRA counts as sharing for cross-context behavioural advertising. That happens only on your say-so: leaving the bar on essentials only, or returning to it through the Cookies link in the footer and choosing essentials, is the opt-out, and it takes effect immediately. A browser sending Global Privacy Control is honoured on arrival: advertising cookies stay off for that visit whichever button is pressed. None of this reaches the personal information of anyone under 16, from whom we knowingly collect nothing.

You may use an authorised agent to make a request. To exercise any of these rights, use the details below.

Security

The site is served over HTTPS throughout. Credentials for the services above live only in the server's environment, readable by root alone, and never in our source code. Access to briefs is limited to the people who answer them. Session cookies are signed server-side. Submissions are rate-limited and checked by Cloudflare Turnstile before anything is recorded.

No arrangement of this kind is absolute, and we say so plainly. Should a breach ever affect your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and you directly where the law requires.

Children

This site addresses people buying software engineering for a company. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us something, tell us and we will remove it.

Changes

When this page changes, the date at the top changes with it. Where a change materially affects how we handle personal data already given to us, we will say so here prominently, and where the law requires, we will contact you about it.

Contact

For anything on this page — a question, a request about your data, or a complaint — the quickest route is the form on our contact page, which reaches the founder directly. By post: Fluvius USA Inc, 1401 21st St, Ste R, Sacramento, CA 95811, United States.

We answer privacy requests in writing, and we answer them ourselves. There is no ticketing system between you and a person here.