Confluir

Privacy policy

Version 1.0 · Last updated: August 28, 2026

What we collect, what for, who we share it with, and what you can ask us. No clauses that say one thing and permit another: if it is not described here, we do not do it.

1. Who processes your data

The controller is Motus International, LLC (Puerto Rico), which operates Confluir, with a notice address at 151 San Francisco St., Suite 200, PMB 5261, San Juan, PR 00901 and contact at help@confluir.io. The business address shown on your invoices and receipts is our operating address, and may differ from the notice address: the first identifies where we operate from, the second is where we receive legal correspondence.

2. What we collect

From your account: email address (required — it is how you sign in), your name if you provide it, preferred language, and optionally the industry and region you declare so we can filter content and alerts.

From your use: conversations with the agents and their content, course progress, certificates issued, policies generated, consultations sent, cases contributed, community posts and messages, and a daily counter of messages and tokens per member that we use to apply plan limits and control costs.

From your payment: we neither receive nor store your card details. Stripe processes them and we keep only its identifiers (customer and subscription), the subscription status, and the period end date.

Technical: application error records and the server logs of our hosting. We use no third-party analytics, no advertising pixels, and no tracking cookies — the only cookie is your signed-in session.

3. What we use it for

To provide the service: authenticate you, grant the access your plan includes, answer your consultations, issue certificates, and charge what you signed up for.

To operate it safely: enforce usage limits, detect abuse, diagnose errors, and keep the access record our own internal policy requires.

To tell you what you need to know: sign-in links, billing notices, changes to the terms, and service alerts. We do not sell your data, do not share it with advertisers, and do not build advertising profiles.

4. What happens when you use the AI agents

The text of your question and the regulatory-corpus excerpts that accompany it are sent to Anthropic, which generates the answer. By default, Anthropic's API does not use that data to train its models.

We do not send your name, your email, or your account identifiers to the model: the conversation travels, your identity does not.

We store your conversations in your account so you can come back to them — the free plan keeps the last three, paid plans the full history. You can delete a conversation from the interface.

The home page also has an assistant that only answers questions about Confluir and works without an account. From those conversations we store the text of the question, the language, and a value derived from your IP address through an irreversible hash function, which we use to limit abuse. We do not store the IP address. These records are deleted after 30 days and are not linked to any account.

5. Officer consultations are genuinely anonymous

When a consultation is routed to a compliance officer, the officer receives the topic, your question, the language, and the thread's messages. They do not receive your name, your email, or any identifier of your account — and that is verified in the code, not merely promised here.

Officers work over Telegram, so that thread's messages pass through its infrastructure. That is exactly why the bridge carries no identity: what travels is the question, not who asked it.

6. What you choose to publish

The member directory is opt-in: without your explicit consent you are neither listed nor discoverable, and you can leave whenever you want.

Cases you contribute to the library go through AI-assisted anonymization and human moderation before publication. Even so, the first line of defense is you: do not submit real customer data (see section 8 of the terms).

7. Who we share data with

Only the providers needed to operate, and none receives more than it needs: Vercel (hosting and application logs), Neon (database), Stripe (payments: name, email, payment method), Resend (transactional email), Anthropic (the text of questions to the assistant), and Telegram (only a consultation thread, with no user identity).

All process data in the United States, except Telegram, whose operation is global. The full list, with what each one receives and a link to its data-processing agreement, is maintained in the project repository and reviewed quarterly.

We will also share data when a valid legal order requires it, and in that case we will notify you unless the order itself forbids it.

8. How long we keep it

While your account is active, we keep what is needed to serve you. Billing records are retained for as long as applicable tax and accounting obligations require.

When you close your account we delete or anonymize your personal data, with two exceptions: billing records for their legal retention period, and content you contributed to the case library, which is already anonymized and stays published precisely because it does not identify you.

Issued certificates remain verifiable by their code, which does not expose your email.

9. Your rights

You can ask us for access to your data, correction of anything wrong, an exportable copy, or deletion of your account. Write to help@confluir.io from your account's email address and we respond within 30 days.

Today deletion is handled by email, not by a button in the app. We say so because it is true, and it is on the list of what remains to be built.

If you live in a jurisdiction that grants you additional rights over your data, we honor them even where they are not listed here.

10. Security

We store no passwords: access is by single-use link to your email. We store no card numbers. The database connection is encrypted with certificate verification, and administrative access is limited to an explicit list of email addresses.

No system is infallible. If a breach affects your personal data, we will notify you without undue delay and tell you what happened and what to do.

11. Minors

The service is for professionals and is not directed to anyone under 18. We do not knowingly collect data from minors; if we identify a minor's account, we close it and delete the data.

12. Changes to this policy

If we change something material — what we collect, what for, or who we share it with — we will tell you by email or inside the platform before it takes effect. The date in the header always identifies the version in force.

13. Contact

Privacy questions, or to exercise any of your rights: help@confluir.io. Notice address: Motus International, LLC, 151 San Francisco St., Suite 200, PMB 5261, San Juan, PR 00901.