Privacy Policy

Last updated: 26 August 2026

1. Who is responsible

emitforge is operated by FLUXIUM LTDA, a company registered in Brazil under CNPJ 60.123.373/0001-81. Contact for any privacy matter, including exercising your rights: contato@fluxium.pro.

2. Our two roles — please read this one

We handle personal data in two distinct capacities, and the difference decides who is responsible for what:

3. What we handle

CategoryWhat it includes
Account dataName, email address, API keys
Billing dataReceived from Paddle: country, tax status, transaction history. We never see or store your full card details
Technical dataIP address, user agent, timestamps, endpoint called, response status, render duration
Your contentThe template and data payload you submit, and the file we produce from them

4. Why, and on which legal basis

PurposeGDPR Art. 6LGPD Art. 7
Providing the Service and rendering your filesContract — 6(1)(b)Contract — V
Account management and supportContract — 6(1)(b)Contract — V
Security, abuse prevention, rate limiting, loggingLegitimate interests — 6(1)(f)Legitimate interests — IX
Accounting and tax recordsLegal obligation — 6(1)(c)Legal obligation — II
Product emails you opted intoConsent — 6(1)(a)Consent — I

Our legitimate interest in the security purposes above is keeping the Service available and preventing abuse. You may object to that processing at any time, and we will assess the objection on its merits.

We do not send marketing to people whose details reach us through Paddle. Paddle passes buyer data for fulfilment, order processing, fraud prevention and support only. If we ever run a mailing list, it will use consent collected by us, directly.

5. How long we keep it

Retention is short by design. It reduces what can be exposed, and it is simpler to promise something specific than something vague.

DataRetention
Template and data payloadNot persisted beyond processing the request
Generated fileDeleted automatically 24 hours after creation
Request logs — metadata only, never the payload body30 days
Account dataFor the life of the account, then 30 days after closure
Tax and accounting recordsAs required by law. Paddle holds most of these as Merchant of Record

6. Who else processes data

We use a small number of providers. Each is bound by a data processing agreement and, where data leaves the EEA, by Standard Contractual Clauses.

ProviderRoleWhere
PaddlePayments, invoicing, tax, fraud preventionUK / EU
VercelHosting and request executionUnited States
SupabaseDatabase, authentication, file storageEU region

We do not sell personal data, and we do not share it with anyone for advertising.

7. International transfers

We are established in Brazil and use providers in the United States and the European Union. Transfers out of the EEA rely on Standard Contractual Clauses (GDPR Arts. 44–49); a copy can be requested from us. Transfers under the LGPD rely on Art. 33, on the same contractual safeguards.

8. Your rights

Wherever you are, you may ask us to give you access to your data, correct it, delete it, restrict or object to its processing, or provide it in a portable format. Where processing rests on consent, you may withdraw it at any time without affecting what came before.

Under the LGPD (Art. 18) you may additionally ask us to confirm the existence of processing, to tell you with whom data has been shared, and to review decisions taken solely by automated means (Art. 20). We do not make automated decisions that produce legal effects — rendering a file is not one.

Write to contato@fluxium.pro and we answer within one month.

You also have the right to complain to a supervisory authority — the data protection authority of the country where you live or work, or the ANPD in Brazil.

On the Brazilian data protection officer: as a small-scale agent under ANPD Resolution CD/ANPD No. 2/2022, we are not required to appoint a formal DPO, provided we publish a channel for data subjects to reach us. That channel is the email address above.

9. Cookies

This website sets no cookies and runs no third-party analytics. There is nothing to consent to and no banner to dismiss. If that changes, we will ask for consent before setting anything that is not strictly necessary, and we will update this section first.

10. Children

The Service is intended for professional use and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us with data, write to us and we will delete it.

11. Security

Data is encrypted in transit with TLS and at rest by our storage providers. Access to production systems is restricted and authenticated. Generated files sit behind signed, expiring URLs rather than public paths.

We describe what we actually do and no more: this is a small operation without a formal security certification, and we are not going to imply otherwise.

12. Changes

When this policy changes, the date at the top changes with it. For material changes affecting active customers, we give notice by email before they take effect.