- We collect what we need to run your account, your builds and your billing — not more.
- We do not sell or share your personal information for cross-context behavioural advertising, and we never train foundation models on your private project code.
- Your prompts are sent to the model provider you selected so a build can run. Those providers process them under contract and do not retain them for training.
- Florgin runs on third-party infrastructure and third-party AI models. The ones we appoint are bound by contract; the ones you connect yourself answer to their own policies, not ours.
- Do not put health records, card numbers or government ID numbers into Florgin — the Acceptable Use Policy prohibits it and we are not a HIPAA or PCI DSS environment.
- You can export everything, correct it, or ask us to delete it — from Settings or by emailing us.
1. Who we are and what this covers
Yusuf UYAR, an individual trading as Florgin ("Florgin", "we", "us") is the controller of personal information processed through the Florgin website, studio and related services (the "Services"). We can be reached at 1florginai@gmail.com, which is monitored for privacy and legal correspondence and is the address to use for any request under this Policy.
This Policy explains what we collect, why, who we share it with, how long we keep it and the rights you can exercise. It does not apply to third-party services you connect to Florgin, or to products you build and operate yourself — when your product collects data from your own users, you are the controller of that data and you are responsible for your own privacy notice.
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account information | Name, email address, display name, authentication identifiers, workspace membership and role | You, or your identity provider at sign-in |
| Project content | Prompts, product descriptions, uploaded files, generated code, Product Brain versions, build history | You, and output generated at your request |
| Workspace and collaboration data | Invitations you send, membership changes, connector assignments | You and your workspace owner |
| Billing information | Plan, subscription status, order identifiers, billing country, invoice history | Lemon Squeezy as Merchant of Record |
| Integration credentials | OAuth tokens and access tokens for services you connect, held separately from project content in encrypted-at-rest storage | You, when you authorise a connection |
| Technical and usage data | IP address, browser and device type, pages viewed, feature usage, build durations, error and performance logs | Automatically, when you use the Services |
| Support communications | Messages you send us and our replies | You |
We do not collect special category data, and the Acceptable Use Policy prohibits you from submitting it. Health and medical records, genetic and biometric data, full payment card numbers, government identity numbers and other regulated data must not be placed in prompts, uploaded files, seed data or test fixtures. Prompts are stored in your project history and sent to model providers so a build can run, so anything pasted into one leaves systems we alone control. Build against synthetic or anonymised data and connect the real source from your own infrastructure.
We do not knowingly collect personal information from children under 13, or under 16 where local law sets that threshold. If you believe a child has given us personal information, contact us and we will delete it.
3. How we use information, and our legal bases
| Purpose | Data used | Legal basis (EEA/UK) |
|---|---|---|
| Provide the Services — run builds, store projects, maintain the Product Brain | Account, project content, technical data | Performance of a contract |
| Authenticate you and secure accounts | Account, technical data | Performance of a contract; legitimate interests in security |
| Process payments and manage subscriptions | Billing data | Performance of a contract; legal obligation (tax records) |
| Support and communicate about the Services | Account, support communications | Performance of a contract; legitimate interests |
| Detect abuse, fraud and violations of our policies | Technical data, project content where a report is made | Legitimate interests; legal obligation |
| Screen submitted text for payment card and identity numbers we are not permitted to accept, and refuse it | The text you submit, at the moment you submit it | Legitimate interests in not holding data we cannot lawfully hold; legal obligation |
| Measure and improve the Services | Aggregated and de-identified usage data | Legitimate interests |
| Send product updates and marketing | Account, email address | Consent, or legitimate interests where permitted; you can unsubscribe at any time |
| Comply with law and defend legal claims | Any relevant category | Legal obligation; legitimate interests |
4. How your prompts reach AI model providers
To run a build, Florgin sends the relevant portions of your Input — and, where necessary, the current state of your project — to the model provider that serves the model you or the auto-router selected. These providers act as our processors (sub-processors to you) and are contractually restricted to processing the data only to return a response.
We select providers that offer zero-retention or short-retention terms for API traffic and that do not use API inputs to train their models by default. A provider may retain data briefly for abuse monitoring as described in its own terms. If you need a specific provider excluded from processing, choose a model explicitly rather than leaving the workspace on autonomous routing.
6. International transfers
We operate internationally, and information may be processed in the United States and other countries whose data protection laws differ from those where you live. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an appropriate safeguard — usually the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum. Where another country's law requires a specific transfer basis, we rely on the one that law provides.
7. How long we keep information
| Data | Retention |
|---|---|
| Account and workspace records | While your account is open, then deleted within 30 days of closure |
| Project content and Product Brain versions | While your account is open; deleted with the account or when you delete the project |
| Build and application logs | 90 days, then deleted or aggregated |
| Billing and tax records | As required by tax law, typically 7–10 years; held largely by the Merchant of Record |
| Support communications | Up to 3 years after the last message |
| Backups | Rolling backups are overwritten within 35 days of deletion from live systems |
We may keep information longer where necessary to comply with a legal obligation, resolve a dispute, investigate abuse or enforce our agreements.
8. Your privacy rights
Depending on where you live, you may have some or all of the following rights. We honour these requests for everyone where we reasonably can, not only where the law requires it.
- Know and access — a copy of the personal information we hold about you and the categories we collect, use and disclose.
- Correct — fix information that is inaccurate.
- Delete — ask us to erase your personal information, subject to legal retention obligations.
- Portability — receive your data in a portable format. You can export your projects at any time from Settings → Data & privacy.
- Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of.
- Limit use of sensitive personal information — we do not collect sensitive personal information for the purposes that trigger this right.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
- Object or restrict — object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
- Non-discrimination — we will not deny service, charge a different price or provide a lower quality of service because you exercised a privacy right.
- Complain — lodge a complaint with your data protection authority. In the EEA this is your national supervisory authority; in the UK it is the ICO; elsewhere it is the regulator for the country you live in.
To exercise a right, email 1florginai@gmail.com from the address on your account, or use the controls in Settings. We verify requests by confirming control of the account email; for high-risk requests we may ask for additional verification. We respond within 45 days, extendable once by a further 45 days where permitted, or sooner where the law that applies to you requires it. An authorised agent may submit a request on your behalf with written proof of authorisation.
9. Notice for United States residents
This section supplements the rest of this Policy for residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws.
In the 12 months before the effective date of this Policy, we collected the categories of personal information described in Section 2 — identifiers, commercial information, internet or network activity, professional information, and content you submit — for the business purposes described in Section 3, and disclosed them to the categories of recipients described in Section 5.
- We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding 12 months, including personal information of consumers under 16.
- We do not use or disclose sensitive personal information for purposes that require the right to limit under the CCPA as amended by the CPRA.
- We do not use personal information for profiling that produces legal or similarly significant effects.
- California residents may request the categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties to whom it was disclosed.
- Where a state law provides an appeal process for a denied request, you may appeal by replying to our decision; we will respond in writing within the statutory period and tell you how to contact your state attorney general.
We do not sell or share personal information for cross-context behavioural advertising, and we set no advertising or analytics storage on your device. An opt-out preference signal such as Global Privacy Control therefore has no processing to switch off: there is nothing here that it would change. If we ever begin any processing a signal would apply to, we will honour the signal and say so in this Policy before we start.
Nevada residents may submit a verified request that we not sell their covered information. We do not sell covered information, but we will record your request.
10. How we protect information
- Encryption in transit (TLS), and encryption at rest applied by our storage provider to stored project data and credentials.
- Server-side authorisation checks on every workspace and project read and write, with the acting account taken from your session rather than from the request.
- A session cookie that scripts cannot read and that browsers do not send on cross-site requests.
- Automated screening of submitted text for payment card and national identity numbers, which are refused before they are stored or forwarded. The check is a pattern match, involves no human review, and retains nothing from a refused submission.
- Integration credentials held in a separate store from your project content, and never written into project files or generated output.
- Least-privilege internal access, with access to production data limited to staff who need it.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law and without undue delay. Report a vulnerability to 1florginai@gmail.com.
12. Changes to this Policy
We will update this Policy as the Services change. For material changes we will give notice by email or in-product at least 30 days before they take effect, and we will update the effective date at the top. Continued use after the effective date means you accept the updated Policy.
13. Contact us
- Privacy requests and questions: 1florginai@gmail.com
- Security reports: 1florginai@gmail.com
This document is published in English. Any translation provided for convenience is not an official version, and the English text controls except where mandatory local law requires otherwise.