Browse all guides
Your account and security
There are two kinds of account in CleanFlo and one of them can see everything. This is how you look after yours, how your cleaners get theirs, and what the product genuinely does and does not do about security.
On this page
The second tab of Settings is My Account, headed with the subtitle "Update your personal details and login credentials." It holds three fields and two save buttons, and that is the whole of it. Everything else about security in CleanFlo happens somewhere other than a settings screen, which is worth understanding before you go looking for options that are not there.
The My Account tab
Manage your company and account
The password rule is one rule: at least eight characters. There is no complexity requirement, no expiry, no history check and no ban list. The two things that can stop a change are both spelled out in the save bar in red.
If your login has expired in the background while the tab sat open, the save bar tells you rather than failing quietly: "Your session has expired. Sign in again to save." Nothing is lost, but the form has to be resubmitted after signing back in.
What CleanFlo does not have
This section exists because assuming a security feature is present is worse than knowing it is absent. None of the following is in the product.
- No two-factor authentication. There is no authenticator app, no SMS code and no backup codes. Your password is the whole of your login.
- No session list and no sign-out-everywhere. You cannot see which devices are signed in, and you cannot remotely end a session. Changing your password is the nearest lever you have.
- No audit log. The Activity tab of the notification feed shows recent events, but it is a feed rather than a tamper-evident record, and it does not go back indefinitely.
- No roles or permissions screen. There are exactly two kinds of account, and neither can be reshaped.
- No account deletion button. There is no danger zone anywhere in Settings.
What it does have is worth stating in the same breath. Data is held on servers in the EU and encrypted at rest with AES-256. Every table is protected by row-level security keyed to your company, so a query from one account physically cannot return another company's rows. Signing out is a real button, in the account row at the very bottom of the sidebar.
Owner and cleaner: who sees what
Every account is one of two kinds, and the difference is absolute rather than a matter of degree.
| Owner | Cleaner | |
|---|---|---|
| Signs in to | The web app, all fourteen screens | The phone app only |
| Sees the schedule | Every job for every cleaner | Only jobs assigned to them |
| Sees clients and locations | The full record, contacts and all | The site and access notes for their own jobs |
| Sees money | Quotes, invoices, revenue, reports | Nothing. No prices anywhere |
| Sees other staff | The whole team and their performance | Only colleagues in shared channels |
| Sees inventory and equipment | The full register | What they have on loan, and can request supplies |
| Sees health and safety | Every incident, audit and risk assessment | Can report an incident from a job |
| Settings | All four tabs | None. Their own profile lives on the Me tab |
It is enforced at the front door rather than by hiding menu items. A cleaner who signs in on a laptop and types the address of the invoicing screen is redirected straight to the phone app, and the database refuses the queries behind it regardless.
How a cleaner gets a login
There is no PIN anywhere in CleanFlo, and no shared device code. A cleaner has a real account with an email address and a password, the same as you. There are two routes to creating one, offered as a choice under the legend "How should they get in?" at the top of the Add Staff Member drawer.
The invite route is the better one for anybody who is not in the room, and not only for security. An invite can be pushed through WhatsApp or SMS from your own phone, which is the channel a new hire actually reads, rather than an email from a sender they have never heard of about software they have not agreed to use. Pending invites get their own tab on the Staff screen so you can see who never set themselves up, and each one can be resent or revoked.
If someone loses their password, the Staff screen has a Resend Login Credentials drawer: you set a new password and it is emailed to them. There is no self-service reset link inside the cleaner app.
When someone leaves
Deactivate them on the Staff screen
Deactivating removes their access immediately. Their record, their job history and their messages all stay, which is what you want if a question comes up afterwards.
Get the equipment back
Open Equipment, filter to Loaned, and see what is out in their name. Confirm each return as it comes back so the register is honest.
Reassign their jobs
Deactivating does not unassign anything. Anything still booked to them stays booked to them until you move it, and it will keep showing on the schedule.
Leave the conversations alone
Their threads and channel messages stay in your account. That is the point of running team messaging here rather than in a group chat on their personal phone.
Common questions
How do I change the email address I log in with?
Is there two-factor authentication?
Can I give someone access to the schedule without showing them the money?
A cleaner has forgotten their password. What do I do?
Still stuck?
Open Support in the app and send us a ticket, or email the team. A real person reads every one.