Privacy Policy
Effective August 16, 2026
This Privacy Policy explains how Golden Eagles Tech LLC (“FluxDatum,” “we,” “us”) collects, uses, shares, and protects information when you use FluxDatum (the “Service”). It’s written to be read alongside our Terms of Service.
1. Information We Collect
- Account information: name, email address, password (stored as a salted bcrypt hash, never in plain text), timezone, avatar, and — if you sign in via a third-party provider — the identifiers that provider shares with us.
- Workspace and billing information: workspace name, member roles, budget settings, and billing details processed by Stripe. We do not store full payment card numbers.
- Your Data: datasets you upload for analysis, and the results, profiles, and derived artifacts FluxDatum generates from them.
- Usage and device information: IP address, browser/user-agent, pages and API routes accessed, and timestamps — collected automatically for every request as part of our access logging (see “Audit and Access Logs” below).
- Communications: messages you send us (e.g., support requests) and, if you use FluxAsk, the natural-language questions you ask and the generated SQL and answers.
2. How We Use Information
- To provide the Service: authenticate you, run the analytics jobs you request, route them to the best available compute option, render results, and answer FluxAsk queries.
- To operate and secure the Service: detect and prevent abuse, fraud, and security incidents; enforce plan limits and budgets; debug and improve reliability.
- To bill you: process subscriptions and metered usage through Stripe.
- To communicate with you: service notices, security alerts, and — where you’ve opted in — product updates.
- To comply with law and enforce our Terms.
We do not sell your personal information, and we do not use Your Data (the datasets you upload) to train foundation models.
3. Legal Bases for Processing (EEA/UK Users)
Where GDPR applies, we process personal data under these legal bases: performance of a contract (providing the Service you signed up for), legitimate interests (security, fraud prevention, service improvement), consent (e.g., optional marketing communications, which you can withdraw at any time), and legal obligation (e.g., tax and accounting records).
4. How We Share Information — Subprocessors
We share information with the following categories of service providers, only as needed to operate FluxDatum:
| Category | Provider(s) | Purpose |
|---|---|---|
| Hosting / control plane | Railway | Runs the web app, API, and databases |
| Object storage | Cloudflare (R2) | Stores uploaded datasets and analysis results |
| Compute (analytics jobs) | AWS, Google Cloud, Microsoft Azure, Oracle Cloud Infrastructure, RunPod, Vast.ai, Lambda Cloud | Executes the analytics job FluxRouter selects for cost/performance/availability — see “Cloud-Agnostic Processing” below |
| LLM / natural-language features | Anthropic (Claude API) | Powers FluxAsk’s EDA narratives and query answers, under commercial terms that exclude your data from model training |
| Payments | Stripe | Processes subscription and metered billing |
| Transactional email | Resend | Sends verification, password-reset, and invitation emails |
| Error tracking / observability | Sentry, Grafana Cloud | Diagnoses and fixes reliability issues |
| Sign-in (optional) | Google, GitHub, Microsoft | If you choose to sign in with one of these, per their own privacy policies |
We require subprocessors to protect information consistent with this Policy and only use it to provide services to us — never for their own independent purposes.
5. Cloud-Agnostic Processing
FluxDatum’s core function is to route each analytics job to whichever supported cloud is currently the best combination of cost, performance, and availability — which may be our own Local execution tier or any of the third-party compute providers listed above. This means Your Data may be transmitted to, and processed within, any of those providers’ infrastructure for the duration of a job, plus checkpoint/result storage until the job completes and the runner instance is torn down. Runner instances receive only a time-limited, scoped credential to read your dataset and write results — never your account credentials or other tenants’ data. Workspace Owners/Admins on Team and Enterprise plans can configure hard cloud exclusions and data-residency constraints that the router will never violate, including during automatic failover.
6. Data Retention
- Datasets and results: retained until you delete them or your workspace is deleted; job checkpoints auto-expire after 7 days.
- Access logs: 90 days in hot storage, archived for 13 months.
- Audit logs (security- and business-relevant events, including reads): 12 months in hot storage, archived for 7 years, in an append-only, hash-chained format for integrity.
- Account data: retained while your account is active, and for a limited period afterward as needed for legal, tax, or security purposes.
- Deletion requests: honored within 30 days (see “Your Rights” below).
7. Data Security
We encrypt data in transit (TLS 1.2+) and at rest (AES-256), enforce per-workspace data isolation, and log all access to Restricted and Confidential data. Passwords are hashed with bcrypt and never stored or logged in plain text. Cloud compute credentials are never exposed to job runners — only short-lived, scoped, single-use credentials are. Despite these measures, no system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you as required by law (generally within 72 hours of confirming a reportable incident, per GDPR).
8. Your Rights
Depending on where you live, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion (“erasure”); export your data in a portable format; object to or restrict certain processing; and withdraw consent where processing is based on consent. To exercise these rights, email privacy@fluxdatum.com. We will verify your identity and respond within 30 days. If you’re in the EEA/UK, you also have the right to lodge a complaint with your local data protection authority.
9. International Data Transfers
Because FluxDatum is cloud-agnostic by design (§5), your data may be transferred to and processed in countries other than your own, including the United States, wherever our hosting and compute subprocessors operate. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these transfers.
10. Cookies and Local Storage
We use a small number of essential cookies/local mechanisms: an httpOnly session cookie that keeps you signed in (not accessible to page scripts), and — where you’ve consented — analytics cookies to understand product usage. We do not use third-party advertising cookies. Your browser lets you block cookies, though doing so may prevent you from staying signed in.
11. Children’s Privacy
FluxDatum is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact privacy@fluxdatum.com and we will delete it.
12. Changes to This Policy
We’ll post updates here and, for material changes, provide reasonable notice (e.g., email or in-app notice) before they take effect.
13. Contact Us
Golden Eagles Tech LLC — hello@fluxdatum.com (general) · privacy@fluxdatum.com (privacy requests) · security@goldeneaglestech.com (security).