Version: 2026-08-11
Effective date: August 11, 2026
This Privacy Notice explains how Infer by Flow7 collects, uses, discloses, retains, and protects personal data when people visit the website, create an account, fund a wallet, use the API, request support, or otherwise interact with Infer.
The controller for Infer’s direct account and operational processing is the legal person or entity identified in the current Legal Operator Notice (“Infer,” “we,” “us,” or “our”). For personal data in Customer Content processed on behalf of a Business User, Infer generally acts as processor or service provider under the Data Processing Addendum.
For transactions using Stripe Managed Payments, Sold through Link, LLC (displayed as “Sold through Link”) is the merchant of record and separately processes payment, tax, fraud, dispute, and transaction-support data under its own notices. Infer remains responsible for the account, wallet, service delivery, and product support described here.
Infer acts as controller or business for data used to:
When a Business User submits personal data in prompts, files, tool calls, or other Customer Content and determines the processing purpose, that Business User is normally the controller or processor and Infer is its processor or subprocessor. The Business User is responsible for its own privacy notice, legal basis, rights handling, and instructions.
When someone completes one of Infer's measured public product actions—such as calculating a Route Sheet, generating a supported integration configuration, downloading the provider doctor, copying an Infer Agent Skill command, or selecting the pilot call to action—the application records an aggregate action event. The event has no anonymous user identifier or IP address. Its optional dimensions are limited to fixed Infer-owned vocabularies for product page, asset, currently published model family, policy, campaign, channel, and coarse referrer source.
Infer discards raw unknown dimension values before storing the event. The aggregate event does not retain an email address, arbitrary client-supplied identifier, full URL, raw hostname, prompt, generated output, token counts, or calculated result. Values containing control characters, secret-like content, or a valid payment-card number are rejected rather than recorded.
Infer forwards prompts, inputs, files, tool definitions, request parameters, and related Customer Content to the selected model-processing supplier as needed to perform the request.
Infer does not intentionally persist prompt or request
content in its application inference database. For ordinary
standard or no-training inference, a generated
response body may be temporarily retained for idempotent replay for up
to approximately 24 hours. After expiration, the stored response body is
cleared. In zero-retention mode, the response body is not
persisted for replay.
A supplier or underlying model provider may process or retain content according to the selected route, privacy setting, contract, and provider terms. Route-specific information is provided through the Service, model registry, Documentation, and Subprocessor Notice.
Infer may retain:
Stripe or Link processes payment instruments. Infer does not intend to store full card numbers or card security codes.
Infer stores operational records such as:
We collect data:
Depending on the context and applicable law, we process personal data for the following purposes and legal bases:
| Purpose | Typical legal basis |
|---|---|
| Create accounts, provide API access, route inference, meter usage, maintain wallets, and provide support | Contract performance; steps requested before contract |
| Authenticate users, prevent fraud and abuse, secure systems, enforce spend/rate limits, and investigate incidents | Contract performance; legitimate interests; legal obligations |
| Process payments, refunds, tax, disputes, reconciliation, and accounting | Contract performance; legal obligations; legitimate interests |
| Send verification, security, transaction, policy, and service notices | Contract performance; legal obligations; legitimate interests |
| Improve reliability, pricing, documentation, route health, and user experience using operational data | Legitimate interests, balanced against user rights |
| Screen sanctions, comply with court process, and establish or defend legal claims | Legal obligations; legitimate interests |
| Send optional marketing | Consent where required; otherwise legitimate interests with opt-out |
When consent is the legal basis, you may withdraw it without affecting earlier lawful processing. Business Users are responsible for the lawful basis for personal data they submit in Customer Content.
We disclose personal data only as reasonably needed to operate, protect, and comply in connection with the Service, including to:
The Subprocessor Notice describes relevant provider categories and named model-processing and payment providers.
Infer does not sell personal data for money. Infer does not share personal data for cross-context behavioral advertising and does not currently use third-party behavioral advertising cookies. Infer honors a legally applicable Global Privacy Control signal as an opt-out of sale or sharing, even though those practices are not currently used.
Infer uses strictly necessary cookies or similar storage for signed-in sessions, security, CSRF protection, OAuth state, fraud prevention, and preferences. Theme preference may be stored locally.
Optional analytics or advertising technology will not be enabled unless the Privacy Notice and any required consent or opt-out controls are updated first. Rejecting nonessential cookies does not prevent account or API use.
Infer and its service providers may process personal data in the United States and other countries that may have different data-protection laws.
Where required, transfers may rely on:
The DPA provides transfer terms for Business Users. Model-processing location can vary by selected route and provider.
We retain personal data only for the period reasonably needed for the purposes described here, including security, fraud, accounting, tax, disputes, legal claims, and compliance.
standard and no-training idempotent
replay; not persisted for replay in zero-retention mode;
cleared after expiry.Deletion can be delayed by backup cycles, legal holds, fraud or security investigations, accounting duties, disputes, or technical necessity. When deletion is not possible, data may be isolated, restricted, or deidentified.
Infer uses safeguards designed to protect personal data, including encrypted transport, password hashing, hashed API keys, secure cookies, CSRF controls, role-based access, rate limiting, spend limits, signed webhook verification, idempotent financial processing, provider-health and pricing-integrity controls, monitoring, backups, retention minimization, and incident response.
No system is completely secure. Protect your credentials, use key
limits, and avoid submitting data unnecessary for the model task. Report
suspected compromise to security@flow7.org.
Depending on your jurisdiction and our role, you may have the right to:
Submit a request through the privacy-request
workflow or email privacy@flow7.org.
We may verify your identity, authority, account, and request scope. An authorized agent may be required to provide proof of authorization, and we may verify the request directly with the individual. We aim to respond within 30 days and will meet shorter or longer statutory periods where applicable. We will not discriminate against you for exercising a privacy right.
If Infer acts only as a processor for Customer Content, we may direct you to the relevant Business User/controller and assist that customer as required by the DPA.
Depending on statutory thresholds and context, residents of certain U.S. states may have rights to know, access, correct, delete, obtain a copy, opt out of sale/sharing/targeted advertising, limit certain sensitive-data uses, and appeal.
Infer does not sell personal information and does not share it for cross-context behavioral advertising. Categories collected include identifiers, customer records, commercial/payment information, internet/network activity, approximate location, professional or organization information, user content, and inferences used for security or service operation. Sources, purposes, disclosures, and retention are described above.
The pilot-access form uses a separate, optional checkbox for Infer by Flow7 design-partner and product updates. The box is unchecked by default, and submitting a pilot request without selecting it does not opt you in. Infer records the choice shown, its version, the time it was recorded, and the referring hostname. Infer does not retain the full referring URL for this attribution.
You may withdraw consent for promotional email by submitting the dedicated product-email opt-out through the Infer privacy request form. No extra narrative or identity proof is required for that email opt-out. When Infer processes it, the product records a durable suppression before closing the request. You will continue to receive transactional, security, legal, payment, and service notices needed for the account.
Infer does not currently use Customer Content to build advertising profiles or send third-party targeted advertising.
Infer is for adults 18 and older and is not directed to children. A person under 18 may not create an account. Do not submit children’s personal data unless you have a lawful basis, required consent, and an agreement expressly permitting the processing.
Contact privacy@flow7.org if you believe a child
created an account or data was submitted unlawfully.
We may update this Notice to reflect product, legal, or operational changes. A new version will identify its effective date. Material changes will be communicated through the Service or account email where required. Prior versions and acceptance records may be retained to document the notice in effect.
The current controller’s legal name and postal address are in the Legal Operator Notice.
privacy@flow7.orgsecurity@flow7.orglegal@flow7.org