Legal
Privacy Policy
What we collect, why we collect it, who else ends up handling it, and what you can ask us to do with it. Written to be read, not to be survived.
Last updated 28 August 2026
Who we are
FluxDM is operated by FluxDM LLC, a limited liability company registered in Delaware, United States. You can reach us at [email protected].
Two different jobs we do with data
This distinction decides which parts of this policy apply to you, so it comes first.
- Your account, our decisions. When you sign up, we decide what to collect about you and why. For that data we are the controller, and this policy is the full description.
- Your customers’ conversations, your decisions. When a customer messages your connected WhatsApp, Instagram or other channel, we hold that conversation on your behalf. You decide what is collected and why; we act on your instructions. For that data we are a processor, you are the controller, and the terms are in our data processing agreement.
If you are someone’s customer and you found this page after messaging a business that uses FluxDM: we hold that conversation for them, not for ourselves. Ask them, and they can have it corrected or deleted. If you cannot reach them, write to us and we will pass it on.
What we collect
- Account details. Your name, email address, and — if you sign in with Google — your Google account identifier. We never receive your Google password.
- Workspace and team data. Your workspace name and settings, who you have invited, their roles, and which channels each person may work on.
- Channel connections. Access tokens and connection metadata for the channels you connect, so we can send and receive on your behalf.
- Connected mailbox data. If a workspace admin connects Gmail or Microsoft sending, we handle the authenticated primary mailbox address and the email content sent through FluxDM. If the admin separately enables inbox sync, we also handle new Inbox messages, headers and attachments from the time of connection. We do not import older mailbox history. A send-only connection does not let FluxDM read the inbox.
- Conversation content. Messages to and from your customers on channels you have connected, including attachments, plus the profile information the platform gives us — usually a name or handle, sometimes a phone number or email address.
- Customer profiles you build. Contact details, tags and notes your team adds, and the links between a person’s identities across channels.
- Device and technical data. Push notification tokens for the mobile apps, IP address, browser or device type, and server logs.
- Billing details. Your billing contact and subscription state. Card numbers go straight to Stripe and never reach our systems.
Why we collect it
To run the product you signed up for: receiving messages, letting your team reply, resolving one customer’s identities into a single profile, sending push notifications, taking payment, keeping the service up, and answering you when you contact support.
We do not sell your data. We do not sell your customers’ data. We do not use the content of your customers’ conversations to train machine-learning models.
For customers in the UK and EU, our legal bases are: performing our contract with you (running the service), our legitimate interests (security, preventing abuse, and improving the product using aggregate usage rather than message content), consent where we ask for it, and compliance with law where it applies.
Google Workspace and Microsoft mailbox connections
Where FluxDM offers a Gmail or Microsoft mailbox connection, a workspace admin chooses sending and inbox sync separately. Sending lets FluxDM send email from the authenticated primary mailbox. The optional inbox grant lets FluxDM fetch new Inbox email and attachments so the team can handle them in the shared inbox. We do not use mailbox access for advertising, credit decisions or selling data.
We keep encrypted mailbox credentials only while the matching connection is active. Disconnecting inbox sync deletes its token and cursor and stops the Google watch or Microsoft subscription where the provider allows it. Email already brought into FluxDM remains part of the workspace’s conversation history until an admin deletes it, the workspace is deleted, or you ask us to help at [email protected]. Disconnecting inbox sync does not interrupt a separate sending grant.
FluxDM’s use of information received from Google Workspace scopes follows the Google API Services User Data Policy, including its Limited Use requirements. We use Google mailbox data only for the user-facing email features you connect. Human access is limited to your team in FluxDM, your specific consent for support, security needs, or a legal requirement.
Gmail sending remains unavailable until Google approves the sensitive scope. Gmail inbox sync remains unavailable until restricted-scope review and any required security assessment are complete. Microsoft own-mailbox access has its own publisher and security gates. Gmail aliases, Google Groups, delegated Gmail mailboxes, Microsoft shared mailboxes and Send As are not supported through these OAuth connections at launch; Resend forwarding remains the fallback.
Who else handles it
We use third parties to host the service, deliver messages, send email, push notifications and take payment. Each one is named on our sub-processors page along with what it handles and where it sits.
The one worth understanding: sending a WhatsApp message means giving that message to Meta. Same for Instagram, Messenger, Telegram, TikTok, X and SMS. Connecting Gmail or Microsoft email likewise means giving that provider the email it sends or receives. Connecting a channel necessarily involves that platform in your customers’ conversations, and that is true of any tool that connects to it.
We may also disclose data if the law requires it, or to protect the service and its users from abuse.
Where it lives, and transfers
The application, its database and its cache run on infrastructure in Germany, so your conversation history is stored in the EU. FluxDM is a US company, so our own staff and systems access it from the United States, and some sub-processors operate globally.
For transfers of UK and EU personal data outside the region we rely on the European Commission’s standard contractual clauses. If you need those executed as part of a data processing agreement, ask and we will do it rather than pointing you at a page.
How long we keep it
We keep your workspace data for as long as your workspace is active. We are being precise rather than reassuring here: there is currently no automatic expiry, so conversation history stays until it is deleted.
If you close your account or ask us to delete your data, workspace admins can schedule account or workspace deletion from Settings. You can also email [email protected] and we will help. Workspace admins can also erase one end-customer’s data in their workspace through the product API.
Backups and server logs may hold copies for a short period after deletion. Some records, such as billing history, are kept where the law requires it.
How we protect it
Traffic is encrypted in transit. Every incoming platform webhook is signature-verified before we act on it, so a forged message does not enter your inbox. Access to a workspace is limited to the people you invite, and admin actions are limited to admins. Tokens and secrets are kept out of application logs.
No service is immune. If a breach affects your data we will tell you without undue delay and explain what happened rather than what we would prefer had happened.
Your rights
Depending on where you live, you can ask us for a copy of your data, ask us to correct or delete it, object to certain processing, or ask us to restrict it. Email [email protected]. We will not charge you for asking and we will not make it difficult.
If you are in the UK or EU and you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first, but that is your right and not ours to gate.
Cookies
We use cookies to keep you signed in and to remember your workspace. That is what they are for. We do not run third-party advertising or cross-site tracking cookies in the product.
Children
FluxDM is a tool for businesses and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes
If we change this policy in a way that materially affects you, we will tell you before it takes effect rather than quietly updating the date at the top.
Questions about anything on this page? [email protected].