Last updated: 26 July 2026

Privacy Policy

This policy explains what personal data Flidel Technosoft ("we", "us") collects when you use the FLUX3 API and related services, why we collect it, and what rights you have over it.

1. Data we collect

Account data

Name, email address, and, where you subscribe to a paid plan, billing details. Card numbers are handled by our payment processor and are never stored on our systems.

Request data

Prompts, input images, parameters, and generated output submitted through the API, together with the model called and the timestamp. This is necessary to fulfil the request and to enforce usage limits.

Usage and technical data

API call counts, error rates, latency, IP address, and user agent. Used for billing accuracy, abuse detection, and capacity planning.

Website data

Aggregate analytics on pages visited and referring source. See section 10.

2. How we use it

  • To provide and operate the Service, including routing requests to models.
  • To meter usage and bill accurately.
  • To detect, investigate, and prevent abuse, fraud, and breaches of our Terms of Service.
  • To provide support when you contact us.
  • To send service notices such as outages, deprecations, and billing alerts.
  • To comply with legal obligations.

We do not sell personal data. We do not use your prompts or generated output to train our own models.

3. Legal bases

Flidel Technosoft is established in India and processes personal data under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Where we serve users in the UK or EEA, we also rely on the UK GDPR / EU GDPR bases set out below.

  • Contract — providing the Service you signed up for.
  • Legitimate interests — security, abuse prevention, service improvement, balanced against your rights.
  • Legal obligation — tax, accounting, and lawful requests.
  • Consent — optional analytics and marketing communications, withdrawable at any time. Under the DPDP Act, consent is the primary basis for processing and may be withdrawn as easily as it was given.

4. Retention

  • Account data: for the life of the account, then up to 12 months after closure.
  • Prompts and generated output: 30 days, after which they are deleted from active storage.
  • Billing records: as required by tax law in India, typically 6–7 years.
  • Security and abuse logs: up to 12 months.

5. Sharing and subprocessors

We share data only as necessary to run the Service:

  • Cloud and GPU infrastructure providers — hosting and model inference.
  • Upstream model providers — where you call a partner model, the request is forwarded to that provider under their terms.
  • Payment processor — subscription billing and wallet top-ups.
  • Email and support tooling — service notices and support tickets.
  • Analytics — aggregate website usage.

We may also disclose data where required by law, or to protect our rights, users, or the public. If we are involved in a merger or acquisition, data may transfer as part of that transaction; you will be notified.

6. International transfers

We are based in India, and our infrastructure and providers may process data in India and other countries. Transfers outside India are made in accordance with the DPDP Act and any restrictions notified by the Central Government. Where data leaves the UK/EEA, we rely on adequacy decisions or Standard Contractual Clauses with appropriate safeguards.

7. Security

We use encryption in transit, access controls, and audit logging. API keys are the primary access credential — protect them accordingly. No system is perfectly secure, and we cannot guarantee absolute security.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, to object to processing based on legitimate interests, and to withdraw consent. Under CCPA/CPRA, California residents may request disclosure or deletion and may opt out of "sharing" — note that we do not sell personal data.

Under the DPDP Act, Data Principals in India have the right to access a summary of their personal data and its processing, to correction and erasure, to nominate another person to exercise these rights in the event of death or incapacity, and to an accessible grievance redressal mechanism.

To exercise any right, email [email protected]. We respond within 30 days. If your grievance is not resolved, you may escalate to the Data Protection Board of India, or to your local data protection authority if you are in the UK or EEA.

9. Children

The Service is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

10. Cookies and analytics

This website uses only what is necessary to serve pages, plus aggregate analytics to understand traffic. We do not use advertising cookies to build cross-site profiles of visitors. Where consent is required in your jurisdiction, non-essential analytics load only after you consent.

11. Changes

We may update this policy. Material changes will be notified by email or in-product notice before taking effect, and the "last updated" date above will change.

12. Contact

Flidel Technosoft
Bangalore, India
Privacy enquiries: [email protected]