Privacy Policy

Your Privacy Matters

We're committed to being transparent about how we collect, use, and protect your data when you use the Flux platform.

1. Information We Collect

Account Information

When you create a Flux account, we collect your name, email address, and authentication credentials through our identity provider (Clerk). If you sign in via a third-party provider like Google or GitHub, we receive basic profile information from that service.

Workflow and Agent Data

We store the workflows, agent templates, step configurations, prompts, tool definitions, and task data you create on the platform. This includes both private workflows visible only to you and public templates you choose to share.

Usage Data

We collect information about how you interact with Flux, including workflow executions, approval decisions, pages visited, features used, and performance metrics.

Device and Connection Information

We automatically collect your IP address, browser type, operating system, device identifiers, and referring URLs when you access Flux.

Communications

If you contact us for support or participate in our community, we retain those communications to improve our service and respond to your requests.

2. How We Use Your Information

Platform Operation

We use your data to provide, maintain, and improve the Flux platform — including running your workflows, serving your agent templates, and displaying your dashboards.

Workflow Execution

When you run a workflow, your agent prompts, tool inputs, and step data are processed by our execution engine. This may involve sending data to third-party AI model providers to generate agent responses.

Email Sending (Action Steps)

If your workflow includes a send-email action step, recipient addresses, subject lines, and email bodies are transmitted to SendGrid for delivery. We record sent emails and any replies for your review.

Personalization

We use usage patterns to suggest relevant agent templates, surface helpful documentation, and improve the overall experience.

Security and Abuse Prevention

We use device and connection data to detect unauthorized access, prevent abuse, and protect the integrity of the platform.

3. AI Agent Data Processing

Execution Data

When an AI agent runs as part of your workflow, the prompts, tool calls, and outputs are processed in real time. Execution data is stored so you can review results, debug issues, and audit agent behavior.

Approval Gates

Flux's approval system ensures that sensitive actions — like sending emails or executing code — require your explicit consent before proceeding. Approval decisions and any feedback you provide are logged.

Public vs. Private Data

Agent templates you mark as public are visible to other users and may appear in the Flux template library. Private workflows and their execution data are never shared with other users or used to train AI models.

4. Data Sharing and Third Parties

Identity and Authentication

We use Clerk for user authentication. Clerk processes your login credentials and session data under its own privacy policy.

Email Delivery

Emails sent through action steps are delivered via SendGrid. SendGrid processes recipient addresses, email content, and delivery metadata.

AI Model Providers

Agent prompts and tool inputs are sent to third-party AI providers (such as Anthropic) for inference. We select providers that offer strong data-handling commitments.

No Selling of Data

We do not sell your personal information or workflow data to third parties. We do not use your private data for advertising purposes.

5. Data Security

Encryption

All data in transit is encrypted using TLS. Sensitive data at rest, including credentials and API keys, is encrypted using industry-standard algorithms.

Access Controls

Access to user data is restricted to authorized personnel on a need-to-know basis. We use role-based access controls and audit logging internally.

Regular Reviews

We conduct periodic security reviews of our infrastructure, dependencies, and data-handling practices to identify and address vulnerabilities.

6. Your Rights and Choices

Data Export

You can export your workflow data, agent templates, and execution history at any time from your account settings.

Account Deletion

You may delete your account and all associated data by contacting us. We will process deletion requests within 30 days, subject to legal retention requirements.

GDPR Rights

If you are in the European Economic Area, you have the right to access, rectify, port, and erase your personal data, as well as the right to restrict or object to processing.

CCPA Rights

California residents have the right to know what personal information we collect, request its deletion, and opt out of any sale of personal information (which we do not engage in).

7. Cookies and Tracking

Essential Cookies

We use cookies that are strictly necessary for authentication, session management, and security. These cannot be disabled while using Flux.

Analytics

We use privacy-respecting analytics to understand how users interact with the platform. You can opt out of non-essential analytics cookies in your browser settings.

8. Changes and Contact

Policy Updates

We may update this privacy policy from time to time. Material changes will be communicated via email or a prominent notice on the platform at least 30 days before they take effect.

Contact Us

If you have questions or concerns about this policy or your data, contact us at privacy@agentflux.org.

Effective Date

This privacy policy is effective as of February 16, 2026.

Agent Flux - The Hugging Face for AI Agents and Workflows