Demo. This is a working prototype shown for evaluation. It is not a live public service and nothing here is medical advice. More

Privacy, for humans.

Last updated 16 September 2026. This is everything we collect, why, how long we keep it, and who can see it. The whole app is built around one idea — that nobody should ever know you looked — so this is the page we care most about getting right.

The short version

  • We store a scrambled version of your phone number, the name from your ID, your test date and what it covered, and your block or invite lists.
  • We never store who checked whom. Looking someone up writes nothing.
  • Your result and ID photos are deleted the moment they've been checked.
  • A positive result is never stored and never shown to anyone.
  • No ads, no analytics, no tracking, no selling or sharing your data.
  • Delete everything in one tap, any time.

Who's responsible

Flex Technologies Group Ltd is the "data controller" — the organisation responsible for your data. We're a private limited company registered in England and Wales, company number 15882806, registered office 850 Green Lanes, London N21 2RS, trading as Clean Sheets. Contact: admin@flexgroup.dev.

What we collect, and why

WhatWhyHow long
Your phone numberTo sign you in by text message. The number itself lives in one place: the sign-in system, which runs inside our own app on our own database. It's sent to our text-message provider so they can deliver your code, and nowhere else. Everywhere else in the app we use only a one-way scrambled version (a "hash", mixed with a secret key) that can't be turned back into your number.Until you remove your tick or delete your account.
The six-digit sign-in codeTo prove it's your phone.Five minutes.
Your sign-in sessionSo you stay signed in. The session record holds a random token, the IP address and browser type you signed in from, and when it expires.14 days, or until you sign out.
The name on your IDTo check the test result is yours. Nobody else ever sees it.Until you delete your account.
Your tick: the test date, what it covered, when it was issued and whether by software or a personThis is your green tick. People who hold a tick and type your number can see "tested X days ago" and the panel — nothing else.The tick stops being valid 90 days after the test date. The record stays on your account until you delete it or upload a new result, which replaces it.
Result and ID photosRead once to decide whether to issue a tick. They're sent to Google's Gemini API, which reads out the name, date, results and reference number, and — only if the software isn't sure — looked at by a person on our team.Deleted the moment a decision is made. Usually minutes, at most a few hours.
Two reuse-check fingerprintsA scrambled fingerprint of the result image and one of the provider's reference number, so the same result can't be used on two accounts. Neither can be turned back into the picture or the number.90 days from the test date, or until you delete your account.
Review recordsOnly for uploads a person looked at: the text our software read from both photos (name, date, results, provider, reference number, and the name on the ID), why it needed a person, what was decided, when and by whom. Not the photos. If a person declined because of a positive, the text is wiped and the record says only "declined". This lets us spot fakes and check our own decisions.Until you delete your account.
Block and invite listsSo you control who can see your tick. Stored as scrambled numbers plus the last three digits so you can recognise them.Until you remove them or delete your account.
How many checks you've runA simple count so nobody can look up hundreds of numbers. We count the checks. We don't record which numbers.Rolls over every hour and every day.
One sign-in cookieSo you stay signed in. It's the only cookie we set, and it's needed for the app to work, which is why there's no cookie banner.14 days, or until you sign out.
  • We never store who checked whom. Checking a number writes nothing to any database or log. The number you type is scrambled in memory, compared, and forgotten.
  • We never tell anyone they were checked. There's no notification, no "seen by", no history.
  • We never store or show a positive result. If the software sees a positive, it says no on the spot, the photos are deleted, and nothing about the result is written down. If a person declines for that reason, the record says only "declined". Either way the person simply has no tick.
  • We never use analytics, advertising or tracking tools. There are no third-party scripts in the app.
  • We never sell, rent or share your data with anyone, for any reason, except the providers below who run the app for us.

Who can see what

Other users can see one thing about you: whether you hold a valid tick, and if so, how many days ago you tested and what the test covered. They can only see that if they hold a valid tick themselves, type in your exact number, aren't on your block list, and — if you're invite-only — are on your invite list. They can't search for you, browse, or tell that you use the app at all.

Our team — a small number of named people, each signed in with their own phone — can see your result and ID photos only if your upload needs a human decision, and only until that decision is made. We can't see who you've checked, because that information doesn't exist.

Our providers process data on our behalf, under written contracts, and can't use it for their own purposes:

  • Neon (Neon, Inc.) hosts our database and the private storage where your two photos sit while they're being checked. Frankfurt, Germany.
  • Vercel (Vercel Inc.) hosts the app. The code runs in Frankfurt; Vercel's network of edge servers around the world passes requests through. Its logs record the method, path and status of each request, and nothing about who you checked.
  • GetOTP (otp.dev, run by NextID Software Solutions FZCO) delivers your sign-in code by text. It receives your phone number and the code, and nothing else.
  • Google (the Gemini API) reads your two uploaded photos and returns the name, date, results and reference number as text. We use Google's paid service, and under its terms Google doesn't use what we send to improve its products, processes it under a data-processing agreement, and keeps a log of it only for a limited period to detect abuse of the service. Google says that log may be held temporarily in any country where it has facilities.

Where your data lives

In the EU, in Neon's Frankfurt region. Google, Vercel and GetOTP are outside the UK or may handle data outside it, so those transfers happen under the contract terms and safeguards UK data-protection law allows for sending data abroad. If you want the detail on which safeguard applies to which provider, email us.

The legal bit on why we're allowed to do this

UK data protection law asks us to say which legal basis we rely on for each thing.

For your phone number, your sign-in, the name from your ID and your lists: performing our agreement with you — you can't have an account without them.

For your result and ID photos, and for your tick (the test date and panel): this is health data, so the rules are stricter and we rely on your explicit consent. You give it when you upload a result, and it covers us reading the photos with software and, if it isn't sure, a person on our team, keeping your test date and panel as your tick, and showing that tick to other tick-holders who type your number (unless you've blocked them or gone invite-only). You can withdraw it at any time with "Remove my tick" in Settings, by deleting your account, or by emailing admin@flexgroup.dev and asking us to remove your tick, and we'll do it straight away. Withdrawing doesn't affect anything we did while you'd consented.

For the sign-in session details, the check counters, the reuse-check fingerprints, the review records, and the scrambled numbers on other people's block and invite lists: our legitimate interest in keeping the app secure, stopping fakes and reuse, and giving people control over who sees their tick. We've weighed that against your interests and kept each of these as small as we can.

Decisions made by software. Your tick is usually issued by software with no person involved, and a positive result is declined by software with no person involved. The rules it applies are set out in plain words in the terms, section 10. Anything the software isn't sure about goes to a person; nobody is refused by the software except for a positive. You have the right to ask for a person to look at any decision, to tell us your side, and to challenge it: email admin@flexgroup.dev. Because we delete the photos on every decision, you'll need to upload them again for a person to see them.

We don't use your data for anything you'd find surprising, and if we ever wanted to, we'd ask.

Your rights

You can ask us to show you what we hold about you, correct it, delete it, restrict what we do with it, send you a copy in a usable format, or stop using it where we rely on legitimate interests. You also have the right not to be subject to a decision made only by software, described above. The fastest way to delete is the button in Settings, which removes everything immediately and permanently. For anything else, email admin@flexgroup.dev and we'll respond within a month, usually much faster. We may need to confirm it's you, which we'll do with a text to your number.

If you're unhappy with how we've handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113 — but we'd rather you told us first so we can fix it.

Under 18s

Clean Sheets is for adults. When you sign up you confirm you're 18 or over; we take your word for it and we don't read the date of birth from your ID. We don't knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18, we delete the account and everything in it, and we don't issue a tick.

Security

All connections are encrypted. Phone numbers are stored only as scrambled hashes mixed with a secret key, except in the sign-in table, which holds the number itself and nothing else about you. Photos live in private storage that no public link can reach, and are deleted after use. Access to the review queue is limited to named team members using their own phone sign-in. If the secret key ever had to be changed — we'd only do that if it leaked — every block list and invite list would be wiped, because they can't be rebuilt, and we'd show a notice in Settings asking you to add yours again.

No security is perfect. If we ever have a breach that affects you, we'll tell you plainly and quickly, and we'll report it to the ICO within 72 hours where the law requires it.

Changes

If we change this notice we'll update the date at the top and show you a notice in the app. If we ever wanted to collect something new, we'd ask you first rather than bury it here.

The longer versions

The cookies page covers the one cookie. The data protection page is the version for professionals: lawful basis per field, processor list, security measures, breach handling and what partners can ask for. The accessibility statement is there too.

Contact

admin@flexgroup.dev. A person reads every message.