Privacidade

Política de privacidade

Sua privacidade é importante para nós. Esta política explica como coletamos, usamos e protegemos suas informações.

Última atualização: August 24, 2026

This Privacy Policy explains how INSPIREUI COMPANY LIMITED (“InspireUI”, “FluxBuilder”, “we”, “us”, or “our”) collects, uses, discloses, retains, and lets you control personal data when you use FluxBuilder.

It covers every FluxBuilder surface that can receive or return data, including:

  • fluxbuilder.com and localized marketing pages
  • FluxBuilder Cloud (web.fluxbuilder.com), the desktop builder, and related APIs
  • The on-site AI wizard and chat-to-build flow
  • The FluxBuilder MCP server at https://ai.fluxbuilder.com/mcp
  • The FluxBuilder ChatGPT connector, Custom GPT, and any other AI assistant that calls our tools
  • Cloud test builds, account, billing, support, and analytics

Effective date: August 24, 2026. This version replaces the August 17, 2026 policy.

If you do not agree with this policy, do not use the Services. Questions: [email protected].

Contents

  1. Who we are
  2. Data we collect
  3. ChatGPT, MCP, and other AI tools — current inputs and outputs
  4. Purposes
  5. Recipients
  6. Retention
  7. User controls
  8. Cookies and similar technologies
  9. Apps you build with FluxBuilder
  10. International transfers
  11. Legal bases (GDPR)
  12. Your rights (GDPR, UK GDPR, CCPA/CPRA, and similar laws)
  13. Children
  14. Security
  15. Changes
  16. Contact

Who we are

Controller: INSPIREUI COMPANY LIMITED
Product: FluxBuilder
Address: SBI Building, District 12, Ho Chi Minh City, Vietnam
Privacy email: [email protected]
Support email: [email protected]
Phone: +84 989 908 854

When you connect FluxBuilder from ChatGPT, Claude, Cursor, or another assistant, you choose that assistant. That provider is an independent controller of the chat you type there. FluxBuilder is the controller of the account, project, store-connection, and build data we process after a tool runs.

Data we collect

We collect only what is needed to run FluxBuilder. Categories:

Information you provide

Category Examples
Account Name, email, password or SSO token, company, phone, country, plan
Billing Name, email, tax/VAT ID, country, and payment-method tokens handled by our payment processors. We do not store full card numbers.
Project and app config App name, bundle ID, icon and splash images, colors, fonts, navigation, template, language, theme.json / design JSON
Store connection Website URL, detected or selected platform (WooCommerce, Shopify, WordPress, Magento, OpenCart, PrestaShop, BigCommerce, Notion, Strapi, and similar), API base URL, consumer key / consumer secret, Storefront or Admin tokens, key permissions (read, write, read_write)
AI prompts Text you type in the FluxBuilder wizard or that an assistant sends as a tool argument (store URL, “build my app”, design instructions, feature requests)
Support Emails, chat transcripts, attachments, meeting bookings
Marketing preferences Newsletter opt-in, cookie and advertising consent

Information collected automatically

Category Examples
Device and log IP address, user-agent, OS, browser, language, approximate location from IP, Cloudflare country code
Session thread_id, device_id, FluxBuilder user ID, session cookies, first-touch referrer and UTM parameters
Usage Pages viewed, clicks (including download and pricing events), wizard steps, build requests, feature use
Diagnostics Error messages, build logs, scope-check results for the AI wizard

Information from other sources

  • Google sign-in / One Tap: email, name, Google subject ID, and ID token. Sign-in is not consent to advertising.
  • Your store, after you authorize it: public catalog structure (platform, categories, product counts, sample titles/images needed to design the app). We do not scrape customer PII from your store to market FluxBuilder.
  • Payment processors (Paddle, and Lemon Squeezy where still used): payment success/failure, subscription status, refunds.
  • AI clients you connect (ChatGPT, Claude, Cursor, and others): OAuth identity, tool-call arguments, and the fact that a tool was invoked.

We do not sell personal information. We do not use store customer lists, order PII, or payment-card data from your store to train models or to advertise FluxBuilder.

ChatGPT, MCP, and other AI tools

This section distinguishes the public FluxBuilder ChatGPT / MCP connector from FluxBuilder’s separate website, dashboard, and on-site wizard. The public connector is served from https://ai.fluxbuilder.com/mcp and currently exposes the 22 tools listed below. If we add a public tool that collects a new data type, we will update this policy first.

The public connector does not accept store credentials, access tokens, signing passwords, certificate or keystore files, health or biometric data, Social Security numbers or similar government identifiers, payment-card data, or arbitrary file/image uploads as tool arguments. Do not put those data types in design text or other free-text fields.

How a tool call moves data

  1. You sign in to FluxBuilder with OAuth.
  2. The AI client sends the OAuth access token in the HTTP Authorization header. The token is not a tool argument and is never returned in tool output.
  3. The assistant may send the non-sensitive tool inputs listed below to our server.
  4. Our server runs the tool against your workspace only.
  5. We return the listed tool outputs to the assistant so it can continue the conversation.

FluxBuilder does not use tool inputs or outputs to train third-party foundation models. The AI client you chose (for example OpenAI for ChatGPT) processes the conversation and tool payloads under that provider’s privacy policy. In ChatGPT, use Settings → Data controls to manage chat history and whether OpenAI may use your content to improve models.

Public ChatGPT / MCP tools — current inputs and outputs

Tools Inputs we receive Outputs we return Why
Account and projects: whoami, list_projects, open_project No tool argument for account/list; project ID when opening a project Account identity and plan; project IDs, names, platforms, store URLs, status and editor links; selected project summary Identify the signed-in user and select only projects they can access
Build setup: get_build_setup, set_build_setup Project ID; optional app name, bundle ID, version/build number, OneSignal toggle and requested output platforms Non-sensitive build metadata and saved setup status Read or update build metadata without collecting credentials or signing material
Build actions: build_test, build_cloud, stop_build Project ID; optional language code; requested output platforms for a release build Build acceptance/status, job IDs, progress or stop result, and artifact links when ready Run an Android test build or protected cloud build using setup already stored securely in FluxBuilder
Design and documentation reads: overview, list_schemas, inspect, lookup, docs_search Project ID; schema/object targets, IDs or documentation query; optional depth/result limit Project/design summaries, schemas, selected objects and relevant documentation excerpts Let the assistant understand an existing project before proposing changes
Connected-store catalog: catalog_search Project ID, search query, optional resource type and result limit Matching catalog records and public product/category fields made available by the connected store Find existing catalog content without requesting store credentials
Preview: capture, preview_link Project ID; object ID for a capture Screenshot/capture result or a public preview URL Let the user inspect and share the current app design
Design writes: create, update, replace, remove, move Project ID; design object data, schema name, object IDs, update mode or position Created/updated object summaries and operation status Apply user-requested changes to app layout and configuration
Asset resolution: resolve_assets Project ID and text queries for icons, logos, avatars or illustrations Selected third-party asset URLs and the updated project references Find public visual assets and attach their URLs to the design

Tools cannot see other customers’ workspaces. They cannot download your full customer or order database into the chat.

Website, dashboard, and on-site wizard

FluxBuilder’s website, dashboard, and on-site wizard are separate from the public ChatGPT / MCP connector. When needed to connect a store or prepare a signed release build, those surfaces may collect store API credentials, platform tokens, signing passwords, certificates, provisioning profiles, or keystore files. These values are submitted directly to FluxBuilder, stored with restricted access, used only to provide the requested connection or build, and are not exposed as public MCP tool inputs or outputs. Their collection, recipients, retention, and deletion controls are described in the other sections of this policy.

The on-site wizard may separately receive a thread_id, device_id, account details, user messages, selected options, and connection/setup status. Its outputs can include streamed text, design choices, status messages, and a project ID. Its scope check may send the latest wizard message to Google Gemini solely to determine whether the request concerns FluxBuilder.

What we do not do with tool data

  • We do not sell ChatGPT, MCP, or wizard data.
  • We do not use it for third-party advertising.
  • We do not use it to train a public FluxBuilder or third-party foundation model.
  • We do not retain raw payment-card numbers (those stay with Paddle / the card network).
  • We do not require you to paste store admin passwords into ChatGPT.

Purposes

Purpose Data used
Create and operate your account, projects, and sessions Account, session IDs, SSO
Detect your store, connect its API, and generate app config Store URL, credentials, catalog summary, design JSON
Run ChatGPT / MCP / wizard tools and return results Tool inputs and outputs listed above
Run Android previews and protected cloud builds Project ID, language/output selection, non-sensitive build metadata, and protected setup already stored in FluxBuilder
Process subscriptions, invoices, taxes, and refunds Billing and processor events
Customer support and onboarding (email, optional live chat, Cal.com) Contact and support content
Secure the service, prevent abuse, and keep the wizard on-scope Logs, IP, device, prompts
Measure product use and advertising performance Usage events, cookies, consent record, Google Ads / GTM signals where allowed
Comply with law, enforce terms, and keep tax/accounting records Account, billing, logs

We do not use store customer PII, order contents, or tool secrets for marketing.

Recipients

We share personal data only with the parties below, and only as needed for the purposes above.

Recipient Role Data they may receive
InspireUI infrastructureserver2.inspireui.com, fluxbuilder.inspireui.com, ai.fluxbuilder.com, gen-ai.fluxbuilder.com Operate accounts, projects, MCP, wizard, and builds Account, projects, credentials, builds, tool I/O
Cloudflare Hosting, CDN, TLS, bot protection IP, request logs, cached assets
OpenAI ChatGPT connector / Custom GPT, if you use ChatGPT Prompts you type in ChatGPT; tool inputs and outputs for that session
Anthropic, Cursor, and other MCP clients Only if you connect them Same tool I/O for that client
Google One Tap / Google sign-in; Gemini for the public wizard scope check and optional on-site chat; Google Ads (AW-1021634780) and Tag Manager (GTM-KRMNSMB) SSO token; wizard message for allow/deny; advertising/analytics signals after consent where required
Paddle (and Lemon Squeezy on legacy checkouts) Payments and tax invoicing Name, email, plan, payment tokens
Appetize iOS web preview in supported website/dashboard flows; not a public MCP tool input or output Preview token and the iOS build needed to stream the preview
Umami (umami-inspireui.vercel.app) First-party product analytics Page views and named events, IP truncated per Umami settings
Cal.com Optional sales / onboarding booking Name, email, meeting notes you submit
Chatwoot / FluxChat Optional support widget, only when that widget is enabled Messages you send in support chat
Email delivery Transactional mail (account, build-ready, receipts) Email and message content
Professional advisers and authorities Legal, tax, or compulsory process The minimum required

Affiliates under common control with InspireUI may access the same data to operate FluxBuilder.

We do not sell personal information and we do not share it for cross-context behavioral advertising in the CCPA/CPRA “sale/share” sense except for advertising cookies you can refuse in our consent banner (EEA/UK/Switzerland/Brazil) or via your browser / Global Privacy Control where we honor it.

Each recipient’s own policy also applies when they are an independent controller (notably OpenAI, Google, and the AI client you pick).

Retention

We keep data only as long as needed for the purpose, then delete or irreversibly anonymize it.

Data Retention
Account profile Life of the account + 30 days after deletion
Projects, design JSON, store connection metadata Until you delete the project or the account, then up to 30 days in backups
Store API secrets Until you disconnect the store, rotate the key, or delete the project/account
ChatGPT / MCP / wizard tool logs (inputs, outputs, thread_id, device_id) 90 days, unless needed longer for an active abuse or support case
On-site wizard scope-check payload sent to Gemini Not stored by us beyond the request, other than ordinary server logs (90 days)
Test-build artifacts (APK, preview links, build logs) 30 days after the job finishes
Payment and invoice records 7 years (tax and accounting)
Support tickets and email 3 years after the last reply
Analytics events (Umami / first-party events) 13 months
Cookie / advertising consent record 13 months, or until you change it
Security and access logs 90 days (longer if an incident is open)

You can ask us to delete sooner; see User controls. We may keep a minimal record of the request and any data the law requires us to keep.

User controls

You can:

  • Access, correct, or export your account and project data from FluxBuilder Cloud or by emailing [email protected].
  • Delete a project in the builder, which removes that app’s config and stored store credentials.
  • Disconnect a store so API keys are dropped from our servers.
  • Delete your account by requesting it at [email protected] or [email protected]. We complete verified deletion requests within 30 days.
  • Revoke ChatGPT / MCP access in the AI client (ChatGPT: Settings → Connectors / Apps; Claude, Cursor, and others have an equivalent disconnect) and in your FluxBuilder connected-apps / security settings. Revoking stops new tool calls. Data already written into a project stays until you delete that project.
  • Opt out of marketing email via the unsubscribe link. We still send transactional mail (receipts, build-ready, security).
  • Refuse or change advertising cookies via Cookie settings in the footer, or the consent banner where it is shown.
  • Control ChatGPT training / history in ChatGPT’s own Data controls. That setting is between you and OpenAI; we cannot flip it for you.

We will not discriminate against you for exercising these rights. We may need to verify your email before fulfilling a request.

Cookies and similar technologies

Type Examples Control
Strictly necessary Login session, CSRF, consent cookie (fb_consent), first-party fb_aid event cookie Required for the site to work
Analytics Umami first-party analytics Limited identifiers; not used to sell your data
Advertising Google Ads / Tag Manager (AW-1021634780, GTM-KRMNSMB) Off by default in the EEA, UK, Switzerland, and Brazil until you accept. Change anytime via Cookie settings

Google sign-in cookies are set by Google when you use One Tap. That is authentication, not ad consent.

Apps you build with FluxBuilder

If you publish an app with FluxBuilder, you are the controller of that app’s end users (your shoppers). You must publish your own privacy policy in App Store / Google Play and collect only what your store and plugins require.

FluxBuilder does not automatically become the controller of your shoppers. We process store data on your behalf solely to build, preview, and update your app. End-user account deletion, GDPR, and COPPA obligations for that app are yours, except where a FluxBuilder-hosted feature we operate is the processor — in which case we follow this policy and your documented instructions.

International transfers

We are based in Vietnam. We and our processors also operate in the United States, the European Economic Area, and other countries (for example Cloudflare, Google, OpenAI, Paddle). Those countries may not provide the same legal protections as your home country. Where required, we use appropriate safeguards such as Standard Contractual Clauses and processor terms.

If EU/UK GDPR applies, we process data on these bases:

  • Contract — account, builder, MCP/ChatGPT tools, builds, billing
  • Legitimate interests — product analytics, security, abuse prevention, limited B2B marketing to existing customers
  • Consent — advertising cookies in consent-required regions; optional newsletters
  • Legal obligation — tax, accounting, and compulsory requests

Your rights

GDPR / UK GDPR

You may request access, rectification, erasure, restriction, objection, and portability, and you may withdraw consent at any time. You may complain to your local supervisory authority. We respond within one month.

CCPA / CPRA (California) and similar US state laws

You have the right to know, access, correct, delete, and opt out of sale/share of personal information, and not to be discriminated against for exercising those rights. We do not sell personal information. To opt out of advertising cookies, use Cookie settings. Authorized agents may email [email protected] with proof of authority.

Categories collected in the last 12 months match Data we collect. Categories disclosed match Recipients. We do not use or disclose sensitive personal information (such as store API secrets) for purposes other than providing the Services.

Children

The Services are for people 16 or older. We do not knowingly collect personal data from children under 16. If you believe we have, contact [email protected] and we will delete it.

Security

We use TLS in transit, access-controlled servers, hashed passwords, scoped OAuth tokens, and least-privilege access to store secrets. No method of transmission or storage is 100% secure. If a breach affecting your personal data occurs, we will investigate and notify you and regulators when the law requires it.

Changes

We will change the date at the top of this page when we update the policy. If we add a tool that collects a new category of personal data, or if we change recipients or retention in a material way, we will post the update here before that tool ships and, where required, email account holders or ask for consent.

Review this page when you connect ChatGPT or another assistant so it always matches current tool inputs and outputs.

Contact

INSPIREUI COMPANY LIMITED
SBI Building
District 12, Ho Chi Minh City, Vietnam

Email: [email protected] or [email protected]
Phone: +84 989 908 854

Related: Terms of Service · Support policies · MCP server