1. Who this policy covers
This Privacy Policy explains how FluxNote (“FluxNote,” “we,” “us,” or “our”) handles personal information when you visit our website, create an account, use the FluxNote application, or contact support. FluxNote is operated from China and may process information in China and in other countries where our service providers operate.
In this policy, “content” means the writing, documents, outlines, prompts, writing-memory material, conversations, and AI results that you choose to put into FluxNote. “Personal information” means information that identifies or can reasonably be linked to you.
2. Information we collect
Account and sign-in information
- email address, name, and password-related records when you create an account;
- email verification and password-reset records; and
- if you use Google sign-in, the Google account identifier, email, and name supplied in the sign-in token.
Writing and product content
We collect the content you choose to save or submit, including document titles and body blocks, folders, articles, structural outlines, prompts, assistant conversations, organization and voice samples and profiles, reasoning inputs and results, generated drafts, and revision history. Revision history is used to let you review and reverse AI edits.
Billing and usage information
For a subscription, FluxNote receives transaction and subscription metadata from Paddle, such as a Paddle customer or subscription identifier, plan, status, billing period, and payment amount or currency information. Paddle Checkout processes full payment-card details; FluxNote does not need to store your complete card number.
To operate points and billing, we record model, token-usage, operation, document or session, period, and exact usage-cost ledger information. These records help us display your balance, prevent abuse, reconcile Paddle events, and answer billing questions.
Technical, security, and support information
We may receive IP address, browser or user-agent information, session timestamps and expiry, authentication-token records, error or security events, and information you include in a support message. We use essential cookies and browser storage needed for authentication and session preferences. We do not intentionally use advertising cookies or sell personal information for behavioral advertising in the current implementation.
Product analytics
If you use the application, we may send a limited set of manual product events to Mixpanel to understand activation, repeat use, Writing Flow outcomes, subscription behavior, and product-market-fit feedback. The events use a pseudonymous identifier and may include broad properties such as plan, locale, workflow target, status, and duration bucket. We do not send your email address, document title or body, prompts, assistant history, or editor contents to Mixpanel. We do not enable automatic collection or session replay in the writing editor.
3. How we use information
- create and secure accounts, authenticate sessions, and send verification or password-reset emails;
- store, organize, transform, and display the content you ask FluxNote to process;
- run assistant, structure, drafting, reasoning, and writing-memory features you request;
- save outputs and revisions so you can inspect or reverse AI-generated edits;
- measure points, provide subscriptions, process cancellations and plan changes, and reconcile payment events;
- maintain reliability, prevent abuse, debug errors, and protect FluxNote and its users; and
- comply with legal obligations and respond to lawful requests.
Depending on the law that applies, our bases may include providing the service you request, performing a contract, legitimate interests such as security and billing, consent where required, and compliance with legal obligations.
4. AI processing and model providers
An AI operation sends only the relevant material needed for that operation, which can include your prompt, selected document text, structural data, organization or voice context, and relevant assistant history. We use the response to complete the requested feature and to save the result and revision records in FluxNote.
The current production default is an OpenAI-compatible DeepSeek API endpoint. The deployment can be configured to use another compatible provider, so this policy describes the provider as the “configured model provider” where appropriate. We do not control that provider’s separate privacy practices or retention settings. You can review the current default provider’s policy at DeepSeek Privacy Policy.
Do not upload passwords, payment-card information, trade secrets, regulated data, or another person’s personal information unless you have a lawful basis and permission to do so. Review AI output before relying on it or publishing it.
5. When we share information
We share information with service providers only as needed for the purposes described here, subject to their contracts and applicable law:
- Paddle: checkout, payment processing, subscription management, receipts, taxes, and refund handling.
- Configured model provider: AI processing for an operation you request; the current default is DeepSeek.
- Resend: email delivery for verification, password reset, and service communications.
- Google: optional authentication. FluxNote receives the identity data in the sign-in token and does not request general access to your Google account.
- Mixpanel: limited pseudonymous product analytics for activation, retention, reliability, and research measurement. Mixpanel’s separate privacy practices apply to that processing.
- Infrastructure providers: hosting, database, storage, monitoring, and security services needed to run FluxNote. The specific infrastructure provider may vary by deployment.
- Authorities or other parties: when required by law, legal process, security, or protection of rights.
We do not sell your writing or personal information. If we transfer the service or business, information may be transferred as part of that transaction subject to applicable law.
6. Retention
We keep information for as long as needed to provide FluxNote, fulfill the purposes above, resolve disputes, keep billing records, enforce agreements, and meet legal or security needs. Current operational defaults include:
- documents and agent sessions are soft-deleted first and normally remain in trash for 15 days before hard deletion;
- document revisions retain at least the latest 10 revisions per document;
- temporary reasoning inputs and terminal snapshots are generally cleared after 24–48 hours, while superseded analysis has shorter operational windows;
- completed rebuild records may be retained for up to 180 days for reliability and debugging;
- expired sessions and authentication tokens may be retained for an additional 30 days for security cleanup;
- usage ledger records are retained by default for billing and audit reconciliation; and
- processed Paddle webhook event records may be cleaned up after approximately 180 days.
Retention periods are operational defaults, not a promise that every copy disappears at the same instant. Backups, legal holds, fraud prevention, and mandatory accounting requirements may require longer retention.
7. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information, and to withdraw consent where processing is based on consent. You may also have the right to complain to a privacy regulator.
To make a request, email ezra.su@fluxlinks.com from the address associated with your account. Tell us what you need and include enough detail for us to verify the request. We may retain information needed for billing, security, legal compliance, or dispute resolution. Paddle may separately receive and process requests relating to payment transactions.
8. Security and international processing
We use reasonable technical and organizational safeguards for the service, including encrypted connections, protected session cookies, hashed authentication tokens, access controls, and usage and security monitoring. No internet service is completely secure, so do not submit information that you cannot risk exposing.
Because FluxNote is operated from China and uses providers that may operate elsewhere, your information may be transferred to, stored in, or accessed from countries different from your own. Where required, we use an appropriate legal transfer mechanism and provide protections required by applicable law.
9. Changes and contact
We may update this policy when the service, providers, or legal requirements change. We will update the date above and provide additional notice when required. Questions or requests can be sent to: