Fluxion
ProductFluxion OSIntegrationsSecurityPricing
PrivacyTermsDPA

Privacy Policy

What Fluxion collects from you and from the systems you connect, how it is used and protected, and the control you keep over it.

Last updated
12 January 2026
Effective
1 February 2026
Entity
Fluxion, Inc.
Contents
  • 1Introduction
  • 2Information we collect
  • 3How we use information
  • 4How connected data is accessed
  • 5Storage and security
  • 6Sharing and sub-processors
  • 7Data retention
  • 8Your rights
  • 9Cookies and similar technologies
  • 10International transfers
  • 11Children’s data
  • 12Changes to this policy
  • 13Contact us
1

Introduction

In short

We read the systems you connect, only to answer your questions. We never sell your data and we never write to your systems.

Summary only — the clause below is what binds

Fluxion, Inc. (“Fluxion”, “we”, “us”) provides an AI executive platform that connects to the business systems you authorise, computes metrics from them using deterministic code, and explains those metrics in plain language. This policy describes what personal data we process in the course of providing that service, why we process it, and the rights you have over it.

This policy applies to the Fluxion website, the Fluxion application, and any related services that link to it. It does not apply to third-party services you connect to Fluxion, which remain governed by their own privacy policies.

Where you have entered into a separate written agreement with Fluxion, and that agreement conflicts with this policy, the agreement controls to the extent of the conflict.

2

Information we collect

In short

Three things: who you are, what your connected systems say, and how you use the product.

Summary only — the clause below is what binds

We collect information in three categories, described below. We request the narrowest scope necessary in each case.

CategoryExamplesSource
Account dataName, work email, company name, role, billing contactYou, at sign-up
Connected dataTransactions and balances, deals and contacts, calendar events, email metadataSystems you authorise
Usage dataPages viewed, features used, questions asked, device and browser typeAutomatically, in product
Support dataMessages you send us and their contentsYou, when you contact us
Categories of data processed
2.1

Account data

When you create a workspace we collect your name, work email address, company name and, on paid plans, billing details. Payment card data is processed by our payment provider and is never stored on Fluxion systems.

2.2

Connected-service data

When you authorise a source — a bank or accounting system, a CRM, an email account or a calendar — Fluxion reads records from it in order to compute your metrics. We request read-only scopes wherever the provider offers them, and we request the narrowest scope that will answer the questions the product is designed to answer.

  • Banking and accounting — balances, transactions, invoices and their statuses.
  • CRM — accounts, contacts, opportunities, pipeline stages and close dates.
  • Email — metadata such as sender, recipient, timestamp and thread; message bodies are read only where required to answer a question you have asked.
  • Calendar — event times, durations, titles and attendees.
2.3

Usage data

We record how the product is used so that we can operate, secure and improve it — which screens are opened, which questions are asked, and which errors occur. Usage data does not include the contents of your connected sources.

3

How we use information

In short

To run the product for you, keep it secure, and bill you. Nothing else.

Summary only — the clause below is what binds

We process the data described above for the following purposes:

  1. 1.To provide the service — computing your metrics, generating your briefs, and answering the questions you ask.
  2. 2.To secure the service — detecting abuse, investigating incidents, and maintaining audit logs.
  3. 3.To support you — responding to your requests and diagnosing faults you report.
  4. 4.To bill you — administering subscriptions, invoices and taxes.
  5. 5.To improve the product — using aggregated usage data, never the contents of your connected sources.
  6. 6.To comply with law — meeting our legal, accounting and regulatory obligations.

We do not use your connected data to train foundation models, and we do not sell personal data to any party for any purpose.

4

How connected data is accessed

In short

Read-only by architecture — there is no code path by which Fluxion can write to your systems.

Summary only — the clause below is what binds

Connected sources are accessed through the provider’s official API using credentials you grant and can revoke at any time. Fluxion holds no write scopes: it cannot move money, send mail, create records or modify anything in a connected system. This is a property of how the integration layer is built, not a setting that can be changed.

Every figure the product shows you is computed by deterministic code from records that can be traced back to their source. The language model explains figures that have already been calculated; it does not calculate them and it cannot alter them.

Each access to a connected source is written to an audit log that is visible to you inside the product, including what was read, when, and on whose behalf.

5

Storage and security

In short

Encrypted in transit and at rest, isolated per workspace, least privilege internally.

Summary only — the clause below is what binds

Connected data is encrypted in transit using TLS 1.3 and at rest using AES-256. Each workspace is isolated with its own encryption keys, so data from one customer is not co-mingled with another’s.

Internal access is granted on a least-privilege basis, requires multi-factor authentication, and is logged. Personnel with access are subject to confidentiality obligations and background screening appropriate to their role.

No system is perfectly secure. Where we become aware of a personal data breach affecting your data, we will notify you without undue delay and in accordance with applicable law and any data processing agreement in place between us.

6

Sharing and sub-processors

In short

A short list of vetted vendors. No data brokers, no advertising networks.

Summary only — the clause below is what binds

We share personal data only with sub-processors who help us operate the service, and only to the extent necessary. Each is bound by a written agreement imposing obligations no less protective than those in this policy. The current list is maintained in our Data Processing Addendum.

We may also disclose data where required by law, to enforce our agreements, or in connection with a merger or acquisition — in which case we will give notice before your data becomes subject to a different privacy policy.

We do not share personal data with advertising networks or data brokers, and we do not permit sub-processors to use your data for their own purposes.

7

Data retention

In short

Disconnect a source and its data is deleted within 30 days.

Summary only — the clause below is what binds
DataRetained for
Connected dataWhile the source is connected, then deleted within 30 days
Account dataFor the life of the account, then 90 days
Audit logs24 months
Billing recordsAs required by tax and accounting law, typically 7 years
Retention periods

You can disconnect any source at any time from inside the product. Doing so revokes our credentials immediately and begins deletion of the data derived from it.

8

Your rights

In short

Access, export, correct or delete — write to us and we will action it.

Summary only — the clause below is what binds

Depending on where you live, you may have some or all of the following rights in respect of your personal data:

  • Access — to obtain a copy of the personal data we hold about you.
  • Portability — to receive that data in a structured, machine-readable format.
  • Rectification — to have inaccurate data corrected.
  • Erasure — to have your data deleted, subject to our legal retention obligations.
  • Restriction and objection — to limit or object to certain processing.
  • Withdrawal of consent — where processing is based on consent, at any time.

To exercise any of these, write to privacy@fluxion.co. We will respond within the period required by applicable law, and in any case within 30 days. You also have the right to complain to your local supervisory authority.

9

Cookies and similar technologies

In short

Strictly necessary cookies only. No advertising trackers.

Summary only — the clause below is what binds

We use cookies that are strictly necessary to operate the service — to keep you signed in, to remember your theme preference, and to protect against cross-site request forgery. We use a privacy-preserving analytics tool that does not set cross-site identifiers.

We do not use advertising cookies or third-party tracking pixels. Because we set no non-essential cookies, there is no consent banner to dismiss.

10

International transfers

In short

EU data can stay in the EU. Where it moves, Standard Contractual Clauses cover it.

Summary only — the clause below is what binds

Fluxion is operated from the United States and processes data in the United States and the European Union. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards including the European Commission’s Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.

EU data residency is available on eligible plans, in which case connected data is stored and processed within the EU.

11

Children’s data

Fluxion is a business product and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@fluxion.co and we will delete it.

12

Changes to this policy

We may update this policy as the product and the law evolve. The “last updated” date at the top of this document always reflects the current version. Where changes are material, we will give at least 30 days’ notice by email or in-product before they take effect.

13

Contact us

For questions about this policy or about how your data is handled, write to privacy@fluxion.co. For security matters and vulnerability disclosure, write to security@fluxion.co. Postal enquiries can be addressed to Fluxion, Inc., San Francisco, California.

Questions about this document
  • Legallegal@fluxion.co
  • Privacyprivacy@fluxion.co
  • Securitysecurity@fluxion.co
Related documents
  • Terms of Service→
  • Data Processing Addendum→
  • Security overview→

This document is a template prepared for design purposes. It is not legal advice, and final wording must be provided by counsel before it is relied upon.

Fluxion

An intelligence layer above your business data. Serious, precise, engineered — for founders, not governments.

PRODUCTProductFluxion OSIntegrationsSecurityPricing
COMPANYAboutCareersContactPress
LEGALPrivacyTermsSecurityDPA
© 2026 Fluxion — all systems nominalBUILT FOR FOUNDERS