Privacy
A plain description of what FluxDigest stores, where it goes, and who processes it on our behalf.
This page is a factual summary of how the product handles data, not a lawyer-reviewed privacy policy — we would rather tell you that than dress up a template as one. If you need the executed policy, a DPA, or a completed security questionnaire, ask and we will tell you exactly where we stand.
hello@fluxdigest.comWhat we hold
Two different kinds of data sit in FluxDigest, and it matters which is which.
- Your account: the email address and credentials you sign in with, the workspaces you belong to, and your role in each.
- Your workspace content: newsletters, campaigns, templates, forms, automations, and media you upload.
- Your subscribers: the contacts you import or collect, their tags and segments, and the engagement events recorded against them — opens, clicks, subscribes, unsubscribes, and bounces.
- Operational records: activity logs of what changed in a workspace, notifications, and billing history.
Your subscribers are yours
We process subscriber data on your behalf, to deliver the campaigns you send and report on what happened. We do not sell it, rent it, or use one customer's list to inform another's.
Subscribers, campaigns, media, and integration credentials are scoped to a single workspace, and every request to the API is authorised against that workspace before it returns anything.
Who else touches it
Running the product means some data reaches other providers. The ones that apply depend on which integrations you connect.
- Authentication and the primary database — Supabase.
- Email delivery — whichever of Resend, Mailgun, or Amazon SES you have connected.
- Payments and subscription billing — Stripe.
- Anything else you connect yourself: Slack, Discord, Zapier, HubSpot, Notion, Google Analytics, or Meta Pixel. Connecting one is your decision, and disconnecting it stops the flow.
Sending domains
When you add a sending domain we read its public DNS records to check SPF, DKIM, and DMARC, and we re-check them periodically. That is a lookup of published records — it gives us no access to your DNS or your registrar.
Getting your data out, or deleting it
Subscribers can be exported to CSV from the workspace at any time. For deletion of an account, a workspace, or a specific subscriber's records, write to us and we will action it.

