Privacy Notice
Version: 2026-08-11
Effective date: August 11, 2026
This Privacy Notice explains how Infer by Flow7 collects, uses, discloses, retains, and protects personal data when people visit the website, create an account, fund a wallet, use the API, request support, or otherwise interact with Infer.
The controller for Infer’s direct account and operational processing is the legal person or entity identified in the current Legal Operator Notice (“Infer,” “we,” “us,” or “our”). For personal data in Customer Content processed on behalf of a Business User, Infer generally acts as processor or service provider under the Data Processing Addendum.
For transactions using Stripe Managed Payments, Sold through Link, LLC (displayed as “Sold through Link”) is the merchant of record and separately processes payment, tax, fraud, dispute, and transaction-support data under its own notices. Infer remains responsible for the account, wallet, service delivery, and product support described here.
1. Scope and roles
Infer acts as controller or business for data used to:
- create and administer accounts and workspaces;
- authenticate users and secure the Service;
- process service-credit funding, usage, refunds, disputes, taxes, and accounting;
- provide support and communications;
- prevent fraud, abuse, sanctions violations, and security incidents;
- operate, measure, price, and improve the Service; and
- comply with law and establish or defend legal claims.
When a Business User submits personal data in prompts, files, tool calls, or other Customer Content and determines the processing purpose, that Business User is normally the controller or processor and Infer is its processor or subprocessor. The Business User is responsible for its own privacy notice, legal basis, rights handling, and instructions.
2. Personal data we collect
Account and workspace data
- email address;
- password hash;
- account type, workspace or organization name, roles, memberships, and invitations;
- email-verification state;
- OAuth identity information when Google login is used;
- account, security, eligibility, and risk state; and
- policy acceptance, version, timestamp, and immediate-performance acknowledgement records.
Authentication, security, and network data
- session and CSRF identifiers;
- API-key prefix and cryptographic hash, key limits, and key activity;
- IP address, approximate location derived from IP, user agent, browser/device information, and referring page where collected;
- login, access, rate-limit, abuse, bot, fraud, sanctions, and security events; and
- logs generated by hosting, edge-security, identity, payment, email, and monitoring systems.
Public product-action measurement
When someone completes one of Infer's measured public product actions—such as calculating a Route Sheet, generating a supported integration configuration, downloading the provider doctor, copying an Infer Agent Skill command, or selecting the pilot call to action—the application records an aggregate action event. The event has no anonymous user identifier or IP address. Its optional dimensions are limited to fixed Infer-owned vocabularies for product page, asset, currently published model family, policy, campaign, channel, and coarse referrer source.
Infer discards raw unknown dimension values before storing the event. The aggregate event does not retain an email address, arbitrary client-supplied identifier, full URL, raw hostname, prompt, generated output, token counts, or calculated result. Values containing control characters, secret-like content, or a valid payment-card number are rejected rather than recorded.
Inference content
Infer forwards prompts, inputs, files, tool definitions, request parameters, and related Customer Content to the selected model-processing supplier as needed to perform the request.
Infer does not intentionally persist prompt or request
content in its application inference database. For ordinary
standard or no-training inference, a generated
response body may be temporarily retained for idempotent replay for up
to approximately 24 hours. After expiration, the stored response body is
cleared. In zero-retention mode, the response body is not
persisted for replay.
A supplier or underlying model provider may process or retain content according to the selected route, privacy setting, contract, and provider terms. Route-specific information is provided through the Service, model registry, Documentation, and Subprocessor Notice.
Inference and usage metadata
Infer may retain:
- model requested and model actually resolved;
- routing tier and internal supplier/route;
- token and cached-token counts;
- latency and timestamps;
- request, response, provider, and idempotency identifiers;
- status, error, safety, and diagnostic information;
- usage, supplier cost, customer charge, pricing version, and accounting receipt; and
- provider-health, integrity, fraud, security, and audit evidence.
Payments, tax, wallet, and accounting data
Stripe or Link processes payment instruments. Infer does not intend to store full card numbers or card security codes.
Infer stores operational records such as:
- Stripe customer, Checkout Session, Payment Intent, charge, and refund identifiers;
- selected USD wallet amount, amount paid, currency, tax, processor fee, and settlement status;
- billing name, address, account type, tax or exemption status when provided;
- wallet balance, ledger entries, holds, negative balances, and usage receipts;
- refund, dispute, chargeback, reversal, and reconciliation records; and
- fraud, sanctions, legal, and accounting evidence.
Communications
- verification, password-reset, invitation, receipt, service, security, and operational email delivery records;
- pilot-access requests and optional design-partner or product-update preferences, including the choice shown, its version, the recorded time, and the source hostname;
- support messages, case references, and response records;
- privacy, appeal, refund, and legal requests; and
- survey, feedback, or marketing preferences when provided.
3. Sources of personal data
We collect data:
- directly from you and workspace administrators;
- from applications using your API keys;
- from identity providers such as Google when you choose OAuth;
- from Stripe, Link, payment methods, tax systems, and fraud tools;
- from Cloudflare Email Service and other enabled communications infrastructure;
- from hosting, security, database, logging, and monitoring infrastructure;
- from OpenRouter, ModelFlare, and underlying model providers; and
- from public or commercial sanctions, fraud, and security sources where lawful.
4. Why we process personal data and legal bases
Depending on the context and applicable law, we process personal data for the following purposes and legal bases:
| Purpose | Typical legal basis |
|---|---|
| Create accounts, provide API access, route inference, meter usage, maintain wallets, and provide support | Contract performance; steps requested before contract |
| Authenticate users, prevent fraud and abuse, secure systems, enforce spend/rate limits, and investigate incidents | Contract performance; legitimate interests; legal obligations |
| Process payments, refunds, tax, disputes, reconciliation, and accounting | Contract performance; legal obligations; legitimate interests |
| Send verification, security, transaction, policy, and service notices | Contract performance; legal obligations; legitimate interests |
| Improve reliability, pricing, documentation, route health, and user experience using operational data | Legitimate interests, balanced against user rights |
| Screen sanctions, comply with court process, and establish or defend legal claims | Legal obligations; legitimate interests |
| Send optional marketing | Consent where required; otherwise legitimate interests with opt-out |
When consent is the legal basis, you may withdraw it without affecting earlier lawful processing. Business Users are responsible for the lawful basis for personal data they submit in Customer Content.
5. How we disclose personal data
We disclose personal data only as reasonably needed to operate, protect, and comply in connection with the Service, including to:
- hosting, database, storage, deployment, cache, logging, monitoring, and edge-security providers;
- Stripe and Link for Checkout, merchant-of-record services, payment processing, tax, fraud, refunds, disputes, invoices, and transaction support;
- Cloudflare for transactional email delivery and related delivery-event metadata;
- Google when you use Google OAuth;
- OpenRouter, ModelFlare, and underlying model developers or hosts selected for inference;
- workspace administrators and authorized members;
- professional advisers, auditors, insurers, banks, and corporate transaction participants under appropriate duties;
- authorities, courts, or other persons when legally required or reasonably necessary to protect rights, safety, or security; and
- a successor operator in a merger, financing, restructuring, or sale, subject to applicable notice requirements.
The Subprocessor Notice describes relevant provider categories and named model-processing and payment providers.
Infer does not sell personal data for money. Infer does not share personal data for cross-context behavioral advertising and does not currently use third-party behavioral advertising cookies. Infer honors a legally applicable Global Privacy Control signal as an opt-out of sale or sharing, even though those practices are not currently used.
6. Cookies and similar technology
Infer uses strictly necessary cookies or similar storage for signed-in sessions, security, CSRF protection, OAuth state, fraud prevention, and preferences. Theme preference may be stored locally.
Optional analytics or advertising technology will not be enabled unless the Privacy Notice and any required consent or opt-out controls are updated first. Rejecting nonessential cookies does not prevent account or API use.
7. International transfers
Infer and its service providers may process personal data in the United States and other countries that may have different data-protection laws.
Where required, transfers may rely on:
- an adequacy decision;
- the European Commission Standard Contractual Clauses;
- the UK International Data Transfer Addendum or another UK mechanism;
- contractual, organizational, and technical safeguards; or
- another lawful transfer mechanism.
The DPA provides transfer terms for Business Users. Model-processing location can vary by selected route and provider.
8. Retention
We retain personal data only for the period reasonably needed for the purposes described here, including security, fraud, accounting, tax, disputes, legal claims, and compliance.
Operational retention schedule
- Prompt/request content in Infer’s application inference database: not intentionally persisted.
- Generated response body: up to approximately 24
hours for
standardandno-trainingidempotent replay; not persisted for replay inzero-retentionmode; cleared after expiry. - Request metadata and usage receipts: generally up to seven years when connected to billing, supplier reconciliation, fraud, accounting, or legal evidence; shorter operational copies may be deleted earlier.
- Wallet, ledger, payment, refund, dispute, tax, invoice, and accounting records: generally seven years after the transaction or longer if law, audit, litigation hold, or an active dispute requires.
- Sanctions/export screening records: up to ten years or longer if required by applicable law or an active investigation.
- Security and audit logs: generally 12 to 24 months, with relevant incident evidence retained longer.
- Account and workspace data: while active and afterward as needed for closure, security, refunds, disputes, legal duties, or a verified request; ordinarily deleted or deidentified within 30 days after those needs end.
- Email verification and password-reset tokens: until used or expired, followed by a short cleanup period not exceeding 30 days.
- Invitations: accepted, revoked, or long-expired invitations generally deleted within 365 days.
- Transactional email delivery records: successful delivery records generally up to 365 days; failed, skipped, bounced, complained, suppressed, delayed, or stale pending records generally up to 90 days after their latest delivery-state update, unless needed for security or a dispute.
- Pilot-access requests: submitted identifiers, free-form text, source host, campaign attribution, and exact optional product-update consent evidence are retained for no more than 365 days from submission, then redacted. Infer may preserve the non-identifying request kind, status, timestamps, and aggregate consent state.
- Product-email suppressions: Infer stores no plaintext email address in the suppression ledger. It stores a keyed, versioned pseudonymous digest plus limited source and timing evidence while needed to honor a withdrawal and prevent future product-update email. This suppression survives routine contact-request and email-delivery redaction.
- Privacy, refund, appeal, support, and legal requests: generally up to six years after closure to document response and resolve claims, with unnecessary copied content removed sooner. The public support form does not accept attachments.
Deletion can be delayed by backup cycles, legal holds, fraud or security investigations, accounting duties, disputes, or technical necessity. When deletion is not possible, data may be isolated, restricted, or deidentified.
9. Security
Infer uses safeguards designed to protect personal data, including encrypted transport, password hashing, hashed API keys, secure cookies, CSRF controls, role-based access, rate limiting, spend limits, signed webhook verification, idempotent financial processing, provider-health and pricing-integrity controls, monitoring, backups, retention minimization, and incident response.
No system is completely secure. Protect your credentials, use key
limits, and avoid submitting data unnecessary for the model task. Report
suspected compromise to security@flow7.org.
10. Your privacy rights
Depending on your jurisdiction and our role, you may have the right to:
- access personal data;
- correct inaccurate data;
- delete data;
- restrict or object to processing;
- receive portable data;
- withdraw consent;
- opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
- appeal a privacy decision; and
- complain to a regulator.
Submit a request through the privacy-request
workflow or email privacy@flow7.org.
We may verify your identity, authority, account, and request scope. An authorized agent may be required to provide proof of authorization, and we may verify the request directly with the individual. We aim to respond within 30 days and will meet shorter or longer statutory periods where applicable. We will not discriminate against you for exercising a privacy right.
If Infer acts only as a processor for Customer Content, we may direct you to the relevant Business User/controller and assist that customer as required by the DPA.
11. California and other U.S. state disclosures
Depending on statutory thresholds and context, residents of certain U.S. states may have rights to know, access, correct, delete, obtain a copy, opt out of sale/sharing/targeted advertising, limit certain sensitive-data uses, and appeal.
Infer does not sell personal information and does not share it for cross-context behavioral advertising. Categories collected include identifiers, customer records, commercial/payment information, internet/network activity, approximate location, professional or organization information, user content, and inferences used for security or service operation. Sources, purposes, disclosures, and retention are described above.
12. Marketing communications
The pilot-access form uses a separate, optional checkbox for Infer by Flow7 design-partner and product updates. The box is unchecked by default, and submitting a pilot request without selecting it does not opt you in. Infer records the choice shown, its version, the time it was recorded, and the referring hostname. Infer does not retain the full referring URL for this attribution.
You may withdraw consent for promotional email by submitting the dedicated product-email opt-out through the Infer privacy request form. No extra narrative or identity proof is required for that email opt-out. When Infer processes it, the product records a durable suppression before closing the request. You will continue to receive transactional, security, legal, payment, and service notices needed for the account.
Infer does not currently use Customer Content to build advertising profiles or send third-party targeted advertising.
13. Children
Infer is for adults 18 and older and is not directed to children. A person under 18 may not create an account. Do not submit children’s personal data unless you have a lawful basis, required consent, and an agreement expressly permitting the processing.
Contact privacy@flow7.org if you believe a child
created an account or data was submitted unlawfully.
14. Changes
We may update this Notice to reflect product, legal, or operational changes. A new version will identify its effective date. Material changes will be communicated through the Service or account email where required. Prior versions and acceptance records may be retained to document the notice in effect.
15. Contact
The current controller’s legal name and postal address are in the Legal Operator Notice.
- Privacy requests:
privacy@flow7.org - Support: Infer support request form
- Security:
security@flow7.org - Legal:
legal@flow7.org