Privacy Policy
Last updated: October 1, 2026
You can delete your results anytime
You are always in control of what you create here. Open your Gallery, click the trash icon on any image, and confirm. We immediately delete the active image files used to serve that result, including any reference photos you uploaded and the generated image. A limited internal safety or quality sample may be retained separately under the rules below. Deleting a gallery result cannot be undone. You can also delete your account and request deletion of associated evaluation data at any time (see Your rights below).
What we collect
When you sign up we store your email, display name, and the authentication token issued by the sign-in provider (Google OAuth or email + password). When you create an image, we process your prompt, the model and size you chose, any reference photos you upload, and the generated image. We log the IP address and approximate location of each request for fraud and abuse prevention and to enforce daily free limits.
You can use the free model without an account. In that case we set a cookie with a random browser identifier and use it, together with your IP address, to enforce the daily free limits and prevent abuse. For these limits we store the IP address only as a one-way keyed hash, not the address itself. The browser identifier is not linked to your name or email.
How we use it
The free model (FLUX.2) runs on our own GPU server. Premium models run at third-party AI image providers, which receive your prompt and any reference photos needed to create the image. We also run automated safety checks on uploaded photos, prompts and generated images. The finished image is saved to our storage (Cloudflare R2) so you can view and download it. We do not use your uploads or images to train any model.
Advertising, analytics and cookies
We do not show ads on flux-3image. We use cookies that are needed to keep you signed in and to protect the service from abuse (for example, Cloudflare’s bot check, and the browser identifier cookie that applies the daily free limits when you use the free model without an account). If we ever add advertising, we will update this policy first.
To see how the site is used and fix problems, we use Google Analytics and Microsoft Clarity. They set cookies and record things like the pages you visit, clicks, scrolling and your device type. Clarity can replay a session to show us where something went wrong; what you type into form fields is masked in these recordings. See how Google uses this data and the Microsoft privacy statement.
Retention
Uploaded reference photos are stored with the image they were used for, so we can investigate a failed or wrong result. Uploads and generated images stay until you delete them (the trash icon on any result removes its generated image and the photos you uploaded for it) or until you close your account.
We may retain a limited, access-controlled sample of uploads or results for longer when it is needed for internal safety and quality evaluation. We minimize associated account information, restrict access, do not publish these samples, and do not use them to train a model. You may ask us to delete data associated with your account at any time.
You can request deletion of your account and all associated data by emailing the address at the bottom of this page.
Images made without an account are stored the same way, but there is no gallery to delete them from. To have one removed, email us the image link.
Sharing
We do not sell your data. We use the following infrastructure, systems, and service providers solely to operate the service:
- Cloudflare — hosting, network, R2 storage, Hyperdrive caching.
- Supabase — managed PostgreSQL database for accounts and generations.
- AI image-generation providers — fal (fal.ai), the API provider that runs the Black Forest Labs models (FLUX 3 Image, FLUX.2, FLUX1.1, FLUX.1 Kontext). It receives the prompt and reference photos needed to create the image you asked for.
- Content-safety systems and providers — self-hosted systems and, where needed, service providers that run automated moderation on uploaded photos and generated results.
- Google — Google OAuth when you choose Google sign-in.
- Stripe — payments. We never see or store your full card number.
- Resend — sends account and receipt emails.
- Crisp — the support chat widget. If you open the chat, Crisp receives the messages you send, your email if you give it, and basic browser details, and sets a cookie to keep the conversation.
Your rights
You can access, export, or delete your data at any time. Email us at the address below and we will respond within a reasonable window.
Security
Traffic is encrypted in transit (HTTPS). Storage at rest is encrypted by the respective providers (Cloudflare R2, Supabase PostgreSQL). Passwords are hashed; we never store plaintext credentials. No system is invulnerable — if you believe an incident has occurred, please email us so we can investigate.
Changes
We may update this policy as the service evolves. The “Last updated” date at the top reflects the most recent change. For material changes we will notify signed-in users by email.
Contact
Questions, requests, or concerns: support@flux-3image.com.