The data controller for Flogen is [[LEGAL ENTITY — TO BE COMPLETED: company legal name]], registered at [[LEGAL ENTITY — TO BE COMPLETED: registered address]] under company / licence number [[LEGAL ENTITY — TO BE COMPLETED: company registration or licence number]]. This policy is governed by the laws of [[LEGAL ENTITY — TO BE COMPLETED: governing law]], and disputes about it fall to the courts of [[LEGAL ENTITY — TO BE COMPLETED: jurisdiction / competent courts]] — without displacing any data right you hold under the mandatory law of your own country of residence. Reach the privacy contact at privacy@flogen.ai.
00 /Privacy policy
How we handle your data.
The short version: we collect what we need to run the studio, we don't sell it, and we give you the switches to pull it back.
In effect from [[LEGAL ENTITY — TO BE COMPLETED: effective date]]
- Account info: name, email, password hash, role, company affiliation.
- Workspace content: prompts, uploaded references, brand assets, generated images/video/audio, meeting messages.
- Usage: credit transactions, feature interactions, session titles, timestamps.
- Device: IP address, browser type, OS — for security, abuse detection, and debugging.
To deliver the service — running the studio, routing turns to agents, generating content, billing. To prevent abuse. To show you your history. To support you if you ask for help. We do not sell personal data.
Flogen is glue around best-in-class AI providers, running on third-party infrastructure. The list below is the full set a Flogen deployment can reach — it is reconciled against the credentials the platform is actually configured with, so a provider cannot quietly join the stack without appearing here. Providers marked optional only receive data when that integration is switched on.
AI processors — we send prompt text, generation parameters, and (where applicable) reference images when you invoke them:
AI processors — we send prompt text, generation parameters, and (where applicable) reference images when you invoke them:
- Anthropic — agent language and synthesis (Claude).
- plug-in.ai (Plugged in AI - F.Z.E) — image, video, music, voice and upscale generation, served through the model providers it lists (Google, OpenAI, ByteDance, Black Forest Labs, Kuaishou, Recraft, ElevenLabs and others).
- ElevenLabs — live agent voices, transcription, and voice agents.
- OpenAI — the Creative Director’s language model (optional).
- Tavily, Exa, or Brave Search — web research queries run by the research agent (optional; whichever key is configured).
- Neon — the managed Postgres database holding accounts, workspaces, and content metadata.
- Vercel — application hosting, edge delivery, and scheduled jobs.
- Stripe — payment processing for subscriptions and credit packs. Card details go to Stripe directly; we never see or store them.
- Resend — transactional email (verification, invites, notifications) (optional).
- Upstash — Redis and vector caching, rate limiting, idempotency keys (optional).
- Cloudflare R2, AWS S3, or MinIO — private object storage for generated and uploaded assets when configured; otherwise assets stay on our own server filesystem (optional).
- Google, Microsoft, or Apple — single sign-on, if you choose to sign in with one of them (optional).
Workspace content is kept until you delete it or cancel your plan; after termination we delete workspace data within 30 days, except where law or an audit hold requires retention. Credit transactions are kept for 7 years for audit. Server logs are rotated at 30 days unless a security incident requires longer retention. Credit balances themselves are never aged out — no scheduled job expires or claws back unspent credits.
You can access, export, or delete your data from your workspace settings. Company admins can export every member’s data. For data-subject requests under GDPR/CCPA reach out to privacy@flogen.ai and we’ll respond within 30 days.
Passwords are hashed with bcrypt. Session cookies are httpOnly and SameSite=Lax. API keys are never exposed to the client. All traffic is encrypted in transit. We maintain role-based access controls (SUPER_ADMIN / ADMIN / MEMBER) and audit logs of admin actions.
Flogen is not intended for users under 16. If you believe a minor has created an account, let us know at privacy@flogen.ai and we’ll delete it.
We’ll post updates to this policy here and notify admins via email when substantive changes happen. Continued use after a change constitutes acceptance.
Privacy requests
Write to privacy@flogen.ai — we respond within 30 days to data-subject requests.