Legal

Privacy policy

Effective to be published

Draft pending legal review

Written to describe what the systems actually do. The sub-processor list and the retention periods in particular must be checked against production before this is published, because both are statements of fact that can be verified against us.

Who is responsible

The data controller is to be published, to be published. For any privacy question or to exercise a right, write to to be published.

What we collect

Account data

Email address, authentication identifiers, team membership, plan and billing history. We need this to give you an account and to charge you for it.

Content you upload

Files you store or process, and the metadata attached to them. Files may contain personal data of other people; where they do, you are the controller of that data and we process it on your behalf under our agreement with you.

Conversation data

Where you use FluidTalk, the messages exchanged on channels you connect, and information extracted from them to maintain conversational context. This can include personal data about the people your characters talk to. You are the controller for that data.

Technical data

IP address, request logs, device and browser information, and error diagnostics. We use it to keep the service running, to investigate abuse, and to enforce anti-abuse limits.

Why we are allowed to process it

  • Performance of a contract for account data, content and anything needed to deliver a feature you asked for.
  • Legitimate interests for security, abuse prevention, service diagnostics and product improvement, balanced against your rights.
  • Legal obligation for tax, accounting and records we are required to keep.
  • Consent where we ask for it, for example non-essential analytics. You can withdraw it at any time.

Who processes data on our behalf

We use a small set of sub-processors, each engaged under a data processing agreement: infrastructure and object storage providers that host the service and your files, a model provider that generates conversational responses, a transactional email provider, and payment processors that handle card and cryptocurrency payments. The current list with names and locations is available on request from to be published.

Where a sub-processor is outside the European Economic Area, transfers rely on an adequacy decision or on standard contractual clauses.

How long we keep it

  • Account and billing records for as long as required by tax law after the account closes.
  • Files you upload until you delete them, or for 30 days after an account closes.
  • Conversation history for as long as the associated character or session exists.
  • Technical logs for a short operational window, then deleted or aggregated.

Your rights

Under the GDPR you can request access to your data, correction of it, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests. Write to to be published and we will respond within one month. You also have the right to complain to your national data protection authority.

Cookies

We use cookies that are strictly necessary to keep you signed in across the products on this domain. Any non-essential cookie is set only with your consent, and you can change that choice at any time.

Security

Access to production data is restricted and authenticated, traffic is encrypted in transit, and file links can be expired, password-protected or revoked by you at any time. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authority as required by law.

Children

The products are not for anyone under 18 and we do not knowingly collect data from children.