Last updated: September 13, 2026
This Privacy Policy explains how Flux Plugins (“Flux,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit fluxplugins.com, create an account, purchase or use a Flux Suite subscription, contact us, join our newsletter or affiliate program, or use a Flux Plugins WordPress plugin or hosted service (collectively, the “Services”).
Flux Plugins is based in California, United States. For questions or privacy requests, contact us at eddie@fluxplugins.com.
1. Scope and our role
This policy applies to information that Flux receives through the Services. It does not govern information that remains only on a customer’s WordPress server or information a customer sends directly to a third-party provider through a bring-your-own-key (“BYOK”) integration.
For account, purchase, marketing, affiliate, website, and support information, Flux generally determines why and how the information is processed.
When a customer enables a Flux-hosted feature and sends website content to Flux for processing, the customer controls that content and is responsible for providing required notices and obtaining required permissions from its users. Flux processes that content to provide the requested service. Customers should not submit personal or sensitive information unless they have authority to do so.
2. Information we collect
Information you provide
- Account and contact information: such as your name, email address, organization, username, and account preferences.
- Purchase and subscription information: such as billing contact details, products or plans purchased, transaction status, renewal and cancellation information, and license keys. Payment credentials are handled by the payment provider presented at checkout; Flux generally receives transaction details and limited payment-method information rather than a complete card number.
- Marketing information: such as your email address, consent status, communication preferences, and interactions with our messages when you subscribe or otherwise opt in.
- Affiliate information: such as account, contact, referral, payout, and tax information needed to operate the affiliate program.
- Support and feedback: such as messages, attachments, diagnostic details, survey responses, and other information you choose to provide.
Information collected through our website and services
- Device and network information: such as IP address, browser type, device type, operating system, referring page, and approximate location derived from IP address.
- Usage and diagnostic information: such as pages visited, feature interactions, request timestamps, error messages, job status, performance information, and security events.
- Cookie and similar-technology information: such as login, session, cart, checkout, security, consent, and preference data. If optional analytics or marketing technologies are used, they are subject to the choices available through our cookie controls where required.
- License and site information: when a plugin connects to Flux services, requests may include the license key, locally generated account identifier (UUID), site URL or domain, plugin name and version, WordPress or PHP compatibility information, and request or job identifiers.
3. WordPress plugin and hosted-service data
Local plugin features
Features described as local run on the customer’s WordPress server. Flux does not receive media merely because a customer installs a plugin or uses a local feature. A plugin may still contact Flux when an administrator activates or validates a license, runs a compatibility check, opts into a newsletter, or requests an optional hosted feature. The relevant plugin settings and WordPress.org listing describe when those requests occur.
Flux Media Optimizer
Flux Media Optimizer uses local processing by default. If an administrator activates a valid Flux Suite license and explicitly enables cloud processing or CDN delivery, Flux may receive:
- media and other files selected or uploaded for cloud processing or CDN delivery, including images, videos, PDFs, documents, and supported attachment types;
- attachment metadata, such as filename, file type, dimensions, and file size;
- license key, account identifier, site URL or domain, plugin version, job identifiers, webhook data, and processing status; and
- resulting optimized files, CDN URLs, and technical records needed to complete and secure the job.
Images and videos may be processed and optimized. Other supported files may be stored and delivered without optimization. Customers can disable cloud processing to return new work to local-only processing. Files already stored or cached through the CDN may remain until the customer removes them, the service is terminated, or normal cache and backup cycles complete.
Flux AI Alt Text & Accessibility Audit
Compliance scans run locally and do not, by themselves, send images to an external vision service. AI generation follows the option selected by the administrator:
- BYOK: the plugin sends the image file or URL, related context selected for the request, and the configured API credential directly from the customer’s WordPress site to the selected provider: OpenAI, Google Gemini, or Anthropic Claude. The API credential is stored in the customer’s WordPress database and is transmitted to that provider to authenticate requests. Flux does not control the provider’s independent handling of BYOK requests.
- Flux-hosted generation: when an administrator chooses hosted generation with a valid Flux Suite license, the plugin may send the image file or URL, relevant post or product context, site and license identifiers, request metadata, and job status to Flux-hosted services for processing.
Manual generation sends data when the administrator requests it. Upload-time or scheduled generation may send data automatically after the administrator enables that automation.
Flux One – Command Bar
Core command-bar and local workflow features operate within WordPress. License activation, validation, and compatibility checks may send the limited license and site information described above. If an administrator uses a Flux-hosted AI email-summary feature, captured outbound email content and associated metadata may be sent to Flux-hosted services to generate summaries and identify items that may require attention. Customers should avoid sending sensitive email content unless they have a lawful basis and appropriate authorization.
4. How we use information
- provide, operate, authenticate, and maintain the Services;
- process cloud media, deliver CDN assets, and generate requested AI outputs;
- create and administer accounts, purchases, subscriptions, licenses, affiliate relationships, and payments;
- respond to support requests and communicate about service, security, billing, or policy changes;
- monitor reliability, troubleshoot errors, prevent abuse, and protect the Services and users;
- understand and improve product performance and user experience;
- send newsletters or promotions when you have opted in, subject to your communication choices;
- comply with law, enforce agreements, resolve disputes, and establish or defend legal claims; and
- complete a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all business assets, subject to applicable law.
5. Legal bases for EEA, UK, and similar jurisdictions
Where a law requires a legal basis, we process personal information as needed to perform a contract or provide a requested service; comply with legal obligations; pursue legitimate interests such as securing, supporting, and improving the Services where those interests are not overridden by your rights; or act with consent, such as for optional marketing or non-essential cookies. You may withdraw consent at any time, but withdrawal does not affect earlier lawful processing.
6. How we disclose information
We may disclose information only as reasonably necessary for the purposes described in this policy:
- Cloud hosting, processing, and CDN providers: including Google Cloud Platform for infrastructure used by Flux-hosted services.
- AI providers: OpenAI, Google Gemini, or Anthropic Claude when selected for a BYOK request; and infrastructure or model providers used to deliver a Flux-hosted AI feature.
- Commerce providers: payment, billing, fraud-prevention, accounting, and subscription-management providers involved in a transaction.
- Communications and support providers: email delivery, newsletter, customer-support, and similar vendors used to communicate with you.
- Analytics and security providers: vendors that help measure use, detect abuse, maintain logs, or protect the Services, subject to applicable consent requirements.
- Professional advisers and authorities: lawyers, accountants, auditors, insurers, regulators, courts, law enforcement, or other parties when disclosure is necessary to meet legal obligations or protect rights and safety.
- Business transaction parties: actual or prospective buyers, investors, lenders, or advisers involved in a transaction described above, subject to appropriate confidentiality measures.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising as those terms are defined by California law. If our practices change, we will update this policy and provide any legally required opt-out method before applying the change.
7. Third-party services and links
Third-party providers process information under their own terms and privacy notices when they act independently, including when a customer chooses a BYOK provider. Review the notices relevant to the services you enable:
The Services may link to other websites or services. Their privacy practices are not controlled by this policy.
8. Cookies and your choices
We may use essential cookies and similar technologies for login, security, session management, shopping-cart and checkout functions, consent records, and preferences. Where optional analytics or marketing technologies are used, we provide choices when required by law. You may also control cookies through your browser, although blocking essential cookies may prevent parts of the Services from working.
You may unsubscribe from marketing email through the link in the message or by contacting us. We may still send non-promotional messages about an account, purchase, license, security issue, or requested support.
9. Data retention
We retain information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, keep required business and tax records, maintain security, resolve disputes, and enforce agreements. The retention period depends on the type of information and applicable legal or operational requirements.
- Account, license, and subscription information is generally retained while the account or service relationship is active and afterward when needed for legitimate business records, disputes, fraud prevention, or legal obligations.
- Transaction and tax records are retained for the period required by applicable accounting and tax law.
- Marketing information is retained until you unsubscribe or request deletion, after which we may keep a minimal suppression record so we do not contact you again.
- Support communications and diagnostic logs are retained for a limited period based on their support, security, and troubleshooting value.
- Customer content stored for Flux cloud processing or CDN delivery is retained while needed to provide the enabled service. After deletion, disabling, or termination, residual copies may remain temporarily in backups, processing queues, or distributed caches until normal deletion and expiration cycles complete.
We may retain de-identified or aggregated information that cannot reasonably identify an individual.
10. Security and incident response
We use reasonable technical and organizational safeguards designed to protect information, including transport encryption, access restrictions, authentication controls, logging, and infrastructure safeguards appropriate to the service. No storage or transmission method is completely secure, and we cannot guarantee absolute security.
If we confirm a personal-data breach, we will investigate, take reasonable steps to contain and remediate it, and notify affected users or authorities when required by applicable law.
11. International data transfers
Flux is based in the United States, and our providers may process information in the United States and other countries. Those countries may have privacy laws different from the laws where you live. Where applicable law requires a transfer mechanism, we use recognized safeguards or rely on another lawful transfer basis. You may contact us for more information about safeguards relevant to your information.
12. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- request access to or a copy of personal information we hold about you;
- request correction or deletion;
- request restriction of or object to certain processing;
- request data portability;
- withdraw consent;
- opt out of certain sales, sharing, targeted advertising, or profiling if any applies;
- appeal a decision on a privacy request where applicable; and
- complain to a privacy or data-protection authority.
To exercise a right, email eddie@fluxplugins.com and describe your request. We may need to verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authorization. We will not discriminate against you for exercising an applicable privacy right.
If your request concerns data controlled by a Flux customer, such as content originating from that customer’s WordPress site, contact the customer first. We will assist the customer as required by our obligations and applicable law.
13. Automated processing and AI outputs
Our AI features generate suggested alt text, filenames, summaries, classifications, or prioritized items. These outputs may be inaccurate and should be reviewed by an authorized user before use. Flux does not use these features to make decisions about individuals that produce legal or similarly significant effects.
14. Children’s privacy
The Services are designed for businesses, website administrators, and other professional users and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information to us, contact us so we can review and delete it where appropriate.
15. Changes to this policy
We may update this policy as our Services or legal obligations change. We will post the revised policy on this page and update the “Last updated” date. If a change is material, we will provide additional notice when required by law. Changes apply from the stated effective date and do not retroactively reduce rights where prohibited by law.
16. Contact us
For privacy questions, requests, or complaints, contact:
- Flux Plugins
- California, United States
- Email: eddie@fluxplugins.com
- Website: https://fluxplugins.com/