Confluye

Privacy Policy

This policy explains how Confluye handles information when you use the service.

Effective September 15, 2026

Information we collect

We collect account information such as your name, email address, authentication records, organization and workspace membership, and security and audit events. We also process content you or your organization place in Confluye, including workflows, files, tables, prompts, run output, credentials, and integration data.

Enterprise inquiries

When you request an Enterprise proposal, we collect your name, email address, company, optional team size, and the message you submit. We send these details to our team through Resend to respond to your inquiry and discuss a proposal. Submitting an inquiry does not subscribe you to marketing emails. You can contact us to request deletion of your inquiry.

GitHub sign-in data

GitHub sign-in provides your GitHub account identifier, basic profile, and verified primary email so you can create or access your Confluye account. Authentication access is separate from any GitHub integration you connect to a workspace, and Confluye does not request repository access for sign-in.

Google user data

Google sign-in provides basic profile and verified email information so you can create or access your Confluye account. If you separately connect a Google integration, Confluye requests only the permissions shown during consent. Depending on the connector you choose, those permissions may let a workflow list, read, upload, copy, or move any file in your Google Drive; create, read, or update Google Docs, Sheets, and Slides; read, send, organize, and move Gmail messages and threads to Trash when your workflow does so; and discover calendars, check availability, and manage calendar events on your instruction.

Confluye uses Google user data only to authenticate you, display or retrieve data you request, and execute the workflows and actions you configure. We do not sell Google user data or use it for advertising.

Our use of raw and derived data received from Google Workspace APIs will adhere to the Google API Services User Data Policy and Google Workspace API User Data and Developer Policy, including the Limited Use requirements. Google user data, including aggregated or anonymized data, must not be used, transferred or sold to create, train or improve foundational or generalized AI or machine learning models.

Microsoft sign-in data

Microsoft sign-in provides your Microsoft account identifier, basic profile, and verified email so you can create or access your Confluye account. Confluye requests only the OpenID Connect sign-in scopes and does not request access to Microsoft 365 files, mail, calendars, or contacts for authentication.

Storage, sharing, and AI processing

Credentials and OAuth tokens are stored in encrypted form. Application data is stored with the infrastructure providers that operate Confluye. When a workflow or AI feature is configured to use an AI or integration provider, the content necessary to perform that request is sent to that provider under its terms. Workspace administrators choose those connections and are responsible for confirming that their use is appropriate.

We may disclose information to service providers that operate hosting, storage, email, monitoring, or AI functionality, to the organization that controls your workspace, or when required to protect the service and comply with law. We do not permit service providers to use Google user data for unrelated purposes.

Protection of sensitive data

We encrypt stored credentials and OAuth tokens using AES-256-GCM authenticated encryption. Google OAuth and API requests use HTTPS. Credential access is checked against the signed-in user, workspace membership and assigned permissions; credential listings show masked values. Sensitive credential actions can require an additional authentication step under the applicable account policy.

Workflows can save Google content in outputs, files, tables, logs and knowledge collections. These copies are sensitive data too. Access to workspace resources is subject to workspace and organization authorization. Removing a connection does not by itself delete previously saved outputs, copies or backups; include those resources when requesting deletion.

Retention, deletion, and control

We retain information while the applicable account or workspace is active and as needed for security, recovery, legal obligations, and the workflows you configure. You can disconnect a Google integration from Confluye and revoke its access in your Google Account. Ask your workspace administrator or contact us to request access, correction, export, or deletion. Backups and security records may persist for a limited period before scheduled deletion.

Contact and policy changes

Questions and privacy requests can be sent to support@confluye.run. We may update this policy as the service changes and will publish the effective date on this page.