Privacy Policy

In Flux Studio — Privacy Policy


In Flux Studio, LLC (“we,” “our,” or “us”) — Hoboken, NJ & Seattle, WA · hey@influxstudio.co

We are building the future of creative workflows. This policy explains how we handle your information across our website (influxstudio.co) and our beta SaaS platform (the “Service”) during the Beta phase.

1. Information we collect

  • Account information — your email and name, provided at signup. Account/contact records may be held in our CRM (HubSpot) for communications.
  • Customer Content — the master edits, assets, and media you upload to the Service (defined as in the Terms of Service; treated separately from Inputs below).
  • Inputs — the prompts and parameters you provide to generate Outputs.
  • Beta feedback — bug reports, suggestions, and survey responses you share.
  • Usage data — technical information such as IP address, browser type, and interaction patterns, collected by the Service.
  • Google Drive import (optional). If you import from Google Drive, we access only the files you explicitly select for import. The Google Drive access token is cleared from our server immediately after your import completes and is not retained beyond that action.

New Jersey sensitive-data notice (NJDPA): we do not collect “Sensitive Data” as defined by the NJDPA (e.g., precise geolocation or genetic data). We will obtain your unbundled, explicit opt-in consent before any future collection of such data.

2. How we use your information, and AI

  • Service delivery. Outputs are generated by In Flux Studio’s own variation system. We do not use generative AI to create your media, and we do not send your Customer Content to any third-party AI model.
  • No AI training on your data. We do not train AI or machine-learning models on your Customer Content or your Inputs, and we do not use your identifiable data to train or improve models.
  • Service improvement. We may use aggregated, de-identified usage and feedback data to operate, secure, and improve the Service.
  • Anthropic. We use Anthropic’s Claude as an internal software-development tool. It is not part of the running Service and does not process your Customer Content or account data.

3. Sub-processors

We rely on a limited set of vendors to run the Service — currently Railway (application and database hosting; US), Google (sign-in and optional Google Drive import), Resend (transactional email), and Stripe (billing). The current list, the data each processes, and data regions are maintained in docs/legal/sub-processors.md. We provide notice before adding a sub-processor.

4. Data retention & deletion

We retain your data for the duration of the Beta or until you delete your account. Per-category retention schedules are maintained in docs/legal/data-retention.md.

Self-service account deletion. You can delete your account yourself from the danger zone on your account page. After you type your email to confirm, your account enters a 30-day grace period: it stays fully usable and an in-app banner shows the scheduled deletion date with a one-click Cancel option. If you do nothing, an automated sweeper runs the deletion on the scheduled date — permanently removing your account, the projects you own, and your uploaded Customer Content, cancelling your billing subscription, and requesting erasure of your record from the relevant processor. You receive email at each stage (scheduled, cancelled, and completed). You may still email privacy@influxstudio.co if you prefer an operator-assisted deletion.

A small amount of data is retained after deletion only where the law permits it (GDPR Art. 17(3)(b)): billing records required for tax/legal obligations, anonymized audit-log entries, and an anonymized consent acceptance record (the document type, version, and acceptance date with no personal identifiers) proving you accepted the terms in force at the time. See the account-deletion runbook and the user guide.

5. Your jurisdictional rights

  • 5.1 New Jersey (NJDPA). You may access, correct, and delete your personal data, and opt out of targeted advertising or profiling that produces legal or similarly significant effects.
  • 5.2 Washington (MHMDA / SSB 5207). We do not collect “Consumer Health Data” as defined by the MHMDA; you may request deletion of any potentially sensitive personal data without exception, and you may be entitled to pro-rata refunds for unused subscription portions where Washington law requires.
  • 5.3 EU / UK (GDPR). You have the rights of access, rectification, erasure, portability, restriction, and objection (Arts. 15–22). You can exercise erasure yourself in-app (see Section 4); we also accept requests by email, acknowledge them within 5 business days, and fulfil them within 30 calendar days; see docs/legal/data-subject-rights.md. EU→US transfers are made under Standard Contractual Clauses.
  • 5.4 California (CCPA/CPRA). 〔Applicability to be confirmed — see docs/legal/index.md.〕

6. Cookies

We use strictly necessary cookies (session, authentication, security), which require no consent, and non-essential cookies only with your opt-in consent. See docs/legal/cookie-policy.md.

7. Changes to this policy

For material changes we provide prominent in-app notice at least 30 days before the change takes effect and re-request your acceptance through the in-app consent flow. Your recorded acceptance always references the specific version in force at the time.

8. Security & Beta disclaimer

We apply industry-standard security controls, including encryption in transit and access controls, with hosting on Railway. This is Beta software. We do not guarantee uninterrupted availability, error-free operation, or the permanence of your data, and you are responsible for retaining independent backups of your Customer Content.