Product-specific notice

Prompt Engineer privacy & AI notice

This notice explains the exact Prompt Engineer data flow. It supplements the general FluxonLab Privacy Policy and does not replace the controller identity, legal rights or contact information stated there.

prompt-engineer-privacy-v3-2026-08-10

At a glance

Default route

OpenAI EU API

Fluxie uses GPT-5.6 Luna and the prompt writer uses GPT-5.6 Terra. Provider requests set store:false.

Browser storage

Device-only prompt data

Saved conversations and generated-prompt history stay in this browser until you delete them.

Access

FluxonLab Account required

A short-lived first-party product session verifies the account without putting credentials in a URL or browser storage.

FC usage

Quote, reserve, then settle

The retry-protected maximum must be available before sending; accepted measured usage is settled and only unaccepted open reservations are released.

Fallback

No provider switching

Prompt Engineer never silently sends a failed request to a different AI provider.

What is sent

When you send a message, Prompt Engineer sends the message and the relevant visible conversation context needed to answer it to the provider shown in the interface. Long conversations may include a locally generated continuity summary. The provider request does not include your password, provider key, payment details or the browser’s saved history as a separate bulk export.

The public edge uses your network address to protect the service and enforce rate limits. The AI-provider request does not include that address as a user identifier. Do not enter personal data, special-category data, secrets, confidential business information or third-party content you are not entitled to disclose.

OpenAI default processing

The default route calls the OpenAI Responses API through the configured EU regional endpoint. Fluxie uses GPT-5.6 Luna and the prompt writer uses GPT-5.6 Terra. Every application request sets store:false, so Prompt Engineer does not ask OpenAI to store Responses API application state.

OpenAI states that API data is not used to train its models by default unless the customer opts in. Its default abuse-monitoring logs may contain prompts and responses for up to 30 days, unless approved account controls or a longer legal or security need apply. Prompt caching may retain encrypted cache material for up to 24 hours. Regional data residency is project- and account-specific; system data such as billing or usage metadata may still be processed outside the selected region.

The route remains fail-closed until the exact production OpenAI project, processor terms, EU processing configuration and retention controls are approved and proven for the release candidate.

Data kept in this browser

Prompt Engineer can keep up to 30 conversation threads, up to 120 messages per thread and up to 6,000 characters per saved message under ps-fluxie-threads-v1. It also keeps up to 20 generated prompts under ps-history. These records may contain your brief, answers, preferences, continuity summary and generated outputs.

This content is not an account database and is not synced by Prompt Studio. It remains until you delete individual conversations, use the clear control below or clear prompt.fluxonlab.com site data in your browser. Theme and dismissed-notice preferences are separate device settings.

Account session and FC accounting

Prompt Engineer requires a verified FluxonLab Account. After apex login or signup, Account/Admin creates a single-use handoff valid for at most two minutes and exchanges it server-to-server for a Prompt product session. The product session lasts no longer than the parent Account session and at most 12 hours. Its token is held in an HttpOnly, Secure, SameSite=Strict, host-only cookie; a separate host-only CSRF cookie is readable by this site only so state-changing requests can be protected. Parent logout revokes the child product session.

Before an AI-provider call, the Platform Postgres ledger quotes the selected provider and model under the displayed versioned FC rate card, requires the retry-protected maximum to be available and reserves a conservative ceiling for each call. Every call whose provider usage was accepted settles its measured input, cached-input, cache-write and output tokens even if a later request step fails. Only open reservations that never produced accepted usage are released. Prompt Engineer cannot mint FC, change balances, set pack prices, calculate refunds or override Platform capability rules.

Account and Platform store hashed handoff and product-session credentials, stable account/tenant/principal references, expiry and revocation evidence, and append-only FC reservation, settlement or release facts. Economic facts include the action, provider/model, token counts, FC amount, operation identifiers, timestamps and rate-card evidence, but not prompt or output bodies. Their retention follows the general FluxonLab policy and applicable security, dispute, accounting and statutory requirements.

Cookies, logs and security metadata

Prompt Engineer uses no advertising or analytics cookies and loads no third-party tracker. Its product-session and CSRF cookies are strictly necessary for authenticated access and request protection. Shared login remains owned by the FluxonLab Account service; Prompt Studio removes the retired flux.session browser record and never places credentials, product-session tokens or provider tokens in URLs or localStorage.

Prompt and output bodies are not written to Prompt Studio application logs. Operational failures log only a random request ID and status class. The persistent rate limiter stores a salted, non-reversible identifier derived from the network address in minute and hour buckets; stale bucket files are removed after approximately two hours unless incident preservation or another legal requirement applies.

Purpose, legal basis and your rights

Requested prompt processing is used to provide the service you ask for and is generally handled for contract or pre-contract performance under Article 6(1)(b) GDPR. Abuse prevention, service security and bounded operational logging rely on FluxonLab’s legitimate interests under Article 6(1)(f), balanced against data minimisation.

The general FluxonLab Privacy Policy identifies the controller, contact channel, applicable retention rules and your rights of access, correction, deletion, restriction, objection, portability and complaint. For local browser content, use the controls below. For account or provider-related requests, contact FluxonLab; you may also complain to the Austrian Data Protection Authority.

AI output and human review

Fluxie and generated prompts can be incomplete, inaccurate or unsuitable. Verify outputs before use, especially for legal, medical, financial, employment, safety or other consequential decisions. Prompt Engineer does not present AI output as a final professional decision.

Your controls

These controls act only on this browser and Prompt Engineer surface.

Clear saved prompt content

Deletes saved conversations and generated-prompt history from this browser. Theme and interface preferences remain.

Official sources and general legal pages

Provider terms can change. These are the primary documents reviewed for this notice; account-specific contracts and configuration evidence remain separate release gates.