Privacy policy
This describes what FlozentAi collects when you use the console and the platform, what it deliberately never collects, and how data that belongs to your customers is handled.
Controller and processor
For your own account and workspace configuration, FlozentAi is the controller. For data belonging to your customers that passes through the platform when your agents run, FlozentAi is a processor acting on your instructions — you decide which systems are connected and which actions are published.
What we collect
- Account data. The name and email address used to create your workspace, and the sign-in events associated with it.
- Workspace configuration. Applications, environments, host tenants, imported API specifications, reviewed actions, deployments and knowledge documents you add.
- Run records. For each agent run: the identity it ran as, the context retrieved, the policy decision, the provider request made and the result, together with approval decisions and who made them.
- Operational telemetry. Request logs, error traces and performance metrics needed to keep the service running.
What we do not collect
The product has no field that accepts a password, API key or token. A connection stores a reference to a secret held in your own vault, and the value is resolved inside the execution layer at call time. We cannot disclose a credential we never receive.
We also do not sell personal data, do not use your run content to train models, and do not build advertising profiles.
Data belonging to your customers
When an agent reads from a system you connected, that data passes through the platform to produce the answer or proposal, and a record of the request is retained in the run trace. Each run is bound to one host tenant, and isolation between tenants is enforced in the database through row-level security. You choose what is reachable by choosing what to import and publish.
Cookies
The console sets a session cookie so you stay signed in, and a companion token used to protect against cross-site request forgery. Both are strictly necessary for the console to function. The public marketing pages set no analytics or advertising cookies.
Retention
- Account and workspace configuration is retained while your workspace exists.
- Run records and audit events are retained so they remain useful as an audit trail; enterprise agreements may set a different period.
- On closure, configuration is deleted and audit records are retained only as long as required, then removed.
Subprocessors
We use infrastructure and model providers to operate the service. Where you route runs to a model you have configured, that provider receives the content of those runs. Enterprise agreements can restrict routing to private or self-hosted models. A current list of subprocessors is available on request.
Your rights
Depending on where you are, you may have rights to access, correct, export or delete personal data we hold about you, and to object to certain processing. Write to rajkumar00999.rk@gmail.com and we will respond. If you are an end user of a product built on FlozentAi, your request belongs with that product’s operator, who is the controller for your data — we will forward it to them.
Changes
Material changes to this policy will be announced in the console before they take effect. The date at the top of this page always reflects the current version.
Contact
Questions about this policy go to rajkumar00999.rk@gmail.com.