All topics

Security & data

Workspace isolation, data export, deletion, what we collect.

Workspace isolation

Every tenant-owned table in Phloz carries a workspace_id column with Postgres row-level security policies enforcing workspace_id = auth.jwt()→'workspace_id' on every read + write. We can't see your data cross-tenant; neither can anyone else on Phloz.

The same RLS function (phloz_is_assigned_to) enforces per-client access for member + viewer roles when the workspace policy is "Restricted by assignment".

Exporting your data

Clients, contacts, tasks, and tracking-health data export as CSV from each list's Exportbutton, and any single client's record exports for a clean handoff.

A full workspace backup — clients, contacts, tasks, the tracking map, the files index, and access grants, as portable JSON — is available on Pro and above under Settings → Backup & export, and also runs automatically each week. Messages and comments aren't in the JSON backup yet; reach out via support if you need them.

Deleting your workspace

You can delete individual clients, tasks, tracking nodes, and other records yourself at any time from within the app.

To delete an entire workspace and all its data, email privacy@phloz.comfrom the owner account. We verify the request, then delete or anonymise the workspace's data within 30 days and cancel any active subscription. A self-serve "Delete workspace" control is on our roadmap. There's no recovery once data is deleted — export first if you need a copy.

What we collect

Marketing analytics (GTM + GA4) on the public site only — standard pageviews + UTM. No tracking on app.phloz.combeyond the product analytics you'd expect (PostHog session activity, error reports via Sentry). Both can be opted out via standard browser controls.

We never collect data from your tracking map nodes, your clients, or any of the metadata you put into the platform. That data is yours; we just store it on your behalf.