What we collect
- Account and identity: name, email, role, organization ID, authentication events, and session identifiers.
- Product usage: feature interactions, dashboard views, API requests, performance metrics, and error logs.
- Integration metadata only: channel or issue IDs, timestamps, actor IDs, and status fields. We do not ingest message bodies, attachments, or code.
- Support: what you share in tickets, feedback, or interviews.
- Device/technical: IP address, browser/OS, referrer, and cookies or local storage identifiers for authentication and preferences.
How we use data
- Deliver and secure the service (authentication, sessions, permissions, rate limiting).
- Generate forecasts, alerts, and reports from collaboration metadata.
- Improve reliability and performance through debugging, quality work, and analytics.
- Communicate about product changes, security updates, and support.
- Meet legal, security, and compliance requirements.
Legal bases (where required)
- Contract necessity to provide the service you request.
- Legitimate interests such as security, service improvement, and preventing abuse.
- Consent where required (for example, optional analytics or marketing).
Sharing and processors
- Infrastructure and storage: Vercel (hosting) and Supabase (database).
- Email delivery: Resend, which is how a demo request reaches us.
- Telemetry and monitoring: Sentry (errors) and PostHog (analytics) when enabled.
- AI processing: OpenRouter, used only for assistant and summary features inside a connected workspace.
- Other subprocessors under written agreements for support or operations.
- Legal or safety disclosures required by law or to protect rights and security.
- We do not sell personal data, and we do not use your data to train models.
When an agent acts
- FluxLens agents take no action in your tools unless you authorize them, and no customer has authorized one today.
- Where you do authorize an action, the agent proposes it first, a person confirms it, and the executed action is written to an audit record for your organization.
- You can withdraw that authorization at any time by disconnecting the integration.
Data retention
- We retain data while your account is active and as needed to operate the service, meet legal obligations, resolve disputes, and enforce agreements.
- We de-identify or delete data when it is no longer required.
Security
- Encryption in transit and at rest via our cloud providers.
- Access controls and least-privilege roles for service accounts.
- Audit logging and monitoring for anomalous access patterns.
- No system is 100% secure; report issues to support@fluxlensai.com.
International transfers
- Data may be processed in the United States or other regions where our providers operate, with appropriate safeguards such as contractual data protection terms.
Your choices and rights
- Access, correction, or deletion of your account data where applicable.
- Opt out of non-essential analytics or marketing where offered.
- Disable or remove integrations to stop further ingestion.
- Contact support@fluxlensai.com to exercise rights; we may need to verify identity.
Children
- The service is not directed to children under 16, and we do not knowingly collect their data.
Changes
- We may update this policy. Material changes will be communicated via the product or email. Continued use after an update means you accept the revised policy.