Privacy Policy
Last updated: January 12, 2026
1. Who We Are
No Friction Flow is operated by Jedrzej Tabaczynski ("we", "us", "our"). We create tools and resources for indie founders.
Contact: privacy@nofrictionflow.com
2. What Data We Collect
When you subscribe to our newsletter, we collect:
- Email address - to send you the newsletter
- IP address - for security and rate limiting
- Referral source - if you came from a shared link
- Subscription timestamp - when you signed up
3. How We Use Your Data
We use your data to:
- Send you our weekly newsletter with tools, tips, and insights
- Occasionally inform you about our products and services
- Prevent spam and abuse
- Improve our services based on aggregate analytics
4. Legal Basis (GDPR)
We process your personal data based on:
- Consent - you explicitly opt-in by checking the consent box
- Legitimate interests - for security and service improvement
5. Who Has Access to Your Data
We share your data with these service providers who help us operate:
- ConvertKit - email service provider (US-based)
- Vercel - website hosting (US-based)
These providers are bound by data processing agreements and handle your data according to applicable privacy laws.
6. International Data Transfers
Your data may be transferred to and processed in the United States. We ensure appropriate safeguards through Standard Contractual Clauses (SCCs) with our service providers.
7. How Long We Keep Your Data
We retain your data:
- Active subscribers: Until you unsubscribe
- After unsubscribe: Up to 2 years for legal compliance, then deleted
- Inactive subscribers: We may remove emails that haven't engaged in 12+ months
8. Your Rights (GDPR)
If you're in the EU/EEA, you have the right to:
- Access - request a copy of your data
- Rectification - correct inaccurate data
- Erasure - request deletion of your data
- Restriction - limit how we process your data
- Portability - receive your data in a portable format
- Object - object to direct marketing at any time
- Withdraw consent - unsubscribe at any time
To exercise these rights, email privacy@nofrictionflow.com. We'll respond within 30 days.
9. Your Rights (CCPA/CPRA)
If you're a California resident, you have the right to:
- Know what personal information we collect
- Delete your personal information
- Opt-out of the sale of personal information
- Non-discrimination for exercising your rights
10. Cookies and Tracking
Our website uses minimal tracking:
- Session cookies - to remember your signup status
- Analytics - we may use privacy-respecting analytics
We do not use advertising cookies or cross-site tracking.
11. Security
We implement reasonable technical and organizational measures to protect your data, including:
- HTTPS encryption for all connections
- Rate limiting to prevent abuse
- Access controls for our systems
12. Children's Privacy
Our services are not directed to children under 16 (EU) or 13 (US). We do not knowingly collect data from children. If you believe we have, please contact us immediately.
13. Changes to This Policy
We may update this policy from time to time. For significant changes, we'll notify you via email before they take effect.
14. Complaints
If you're in the EU/EEA and believe we've violated your privacy rights, you can lodge a complaint with your local data protection authority.
15. Contact
For any privacy-related questions or requests:
Email: privacy@nofrictionflow.com
Response time: Within 30 days