Skip to main content
legal
HomeOpen Studio

00 /Privacy policy

How we handle your data.

The short version: we collect what we need to run the studio, we don't sell it, and we give you the switches to pull it back.

In effect from [[LEGAL ENTITY — TO BE COMPLETED: effective date]]

On this page

01Who is responsible for your data02What we collect03Why we collect it04Third-party processors05How long we keep it06Your rights07Security08Children09Changes
01 /Who is responsible for your data
The data controller for Flogen is [[LEGAL ENTITY — TO BE COMPLETED: company legal name]], registered at [[LEGAL ENTITY — TO BE COMPLETED: registered address]] under company / licence number [[LEGAL ENTITY — TO BE COMPLETED: company registration or licence number]]. This policy is governed by the laws of [[LEGAL ENTITY — TO BE COMPLETED: governing law]], and disputes about it fall to the courts of [[LEGAL ENTITY — TO BE COMPLETED: jurisdiction / competent courts]] — without displacing any data right you hold under the mandatory law of your own country of residence. Reach the privacy contact at privacy@flogen.ai.
02 /What we collect
  • Account info: name, email, password hash, role, company affiliation.
  • Workspace content: prompts, uploaded references, brand assets, generated images/video/audio, meeting messages.
  • Usage: credit transactions, feature interactions, session titles, timestamps.
  • Device: IP address, browser type, OS — for security, abuse detection, and debugging.
03 /Why we collect it
To deliver the service — running the studio, routing turns to agents, generating content, billing. To prevent abuse. To show you your history. To support you if you ask for help. We do not sell personal data.
04 /Third-party processors
Flogen is glue around best-in-class AI providers, running on third-party infrastructure. The list below is the full set a Flogen deployment can reach — it is reconciled against the credentials the platform is actually configured with, so a provider cannot quietly join the stack without appearing here. Providers marked optional only receive data when that integration is switched on.

AI processors — we send prompt text, generation parameters, and (where applicable) reference images when you invoke them:
  • Anthropic — agent language and synthesis (Claude).
  • plug-in.ai (Plugged in AI - F.Z.E) — image, video, music, voice and upscale generation, served through the model providers it lists (Google, OpenAI, ByteDance, Black Forest Labs, Kuaishou, Recraft, ElevenLabs and others).
  • ElevenLabs — live agent voices, transcription, and voice agents.
  • OpenAI — the Creative Director’s language model (optional).
  • Tavily, Exa, or Brave Search — web research queries run by the research agent (optional; whichever key is configured).
Infrastructure and operations — these hold or transit your data to run the service:
  • Neon — the managed Postgres database holding accounts, workspaces, and content metadata.
  • Vercel — application hosting, edge delivery, and scheduled jobs.
  • Stripe — payment processing for subscriptions and credit packs. Card details go to Stripe directly; we never see or store them.
  • Resend — transactional email (verification, invites, notifications) (optional).
  • Upstash — Redis and vector caching, rate limiting, idempotency keys (optional).
  • Cloudflare R2, AWS S3, or MinIO — private object storage for generated and uploaded assets when configured; otherwise assets stay on our own server filesystem (optional).
  • Google, Microsoft, or Apple — single sign-on, if you choose to sign in with one of them (optional).
Each processor handles data under their own terms. Where a provider offers a tier that excludes your content from model training, we use it.
05 /How long we keep it
Workspace content is kept until you delete it or cancel your plan; after termination we delete workspace data within 30 days, except where law or an audit hold requires retention. Credit transactions are kept for 7 years for audit. Server logs are rotated at 30 days unless a security incident requires longer retention. Credit balances themselves are never aged out — no scheduled job expires or claws back unspent credits.
06 /Your rights
You can access, export, or delete your data from your workspace settings. Company admins can export every member’s data. For data-subject requests under GDPR/CCPA reach out to privacy@flogen.ai and we’ll respond within 30 days.
07 /Security
Passwords are hashed with bcrypt. Session cookies are httpOnly and SameSite=Lax. API keys are never exposed to the client. All traffic is encrypted in transit. We maintain role-based access controls (SUPER_ADMIN / ADMIN / MEMBER) and audit logs of admin actions.
08 /Children
Flogen is not intended for users under 16. If you believe a minor has created an account, let us know at privacy@flogen.ai and we’ll delete it.
09 /Changes
We’ll post updates to this policy here and notify admins via email when substantive changes happen. Continued use after a change constitutes acceptance.

Privacy requests

Write to privacy@flogen.ai — we respond within 30 days to data-subject requests.

Terms of Service© 2026 FlogenPricing