Privacy Policy
Last updated 6 September 2026
1. Who we are and what this page covers
FlintBeam is an API gateway: you send us a request, we forward it to an AI model provider, and we return the answer. This page describes what we record while doing that, where your prompts go, who else receives data, how long each thing is kept, and what you can do about it. It describes what the service actually does today, not what it might do one day; when the service changes, this page changes with it.
FlintBeam is operated by CONNECT GLOBAL LIMITED, a company registered in England and Wales, number 16714288. For the personal data that describes you as our customer — your account, your keys, your payments, your usage records — we are the controller. For the content of the requests you send through the gateway we act on your instructions and only in transit: we forward it to the provider you named and return the answer, and we do not keep it. You can reach us about any of this at support@flintbeam.com.
2. What we collect and keep
About your account:
- Your email address, and a display name if you set one.
- A hash of your password, never the password itself. We use argon2id, which cannot be reversed back into what you typed.
- The IP address you signed up from, and the IP address and browser description of each session you open. This is what lets you see where your account is signed in and end a session you do not recognise.
- The IP address of each attempt to sign in or register, whether it succeeded or not. Without it, the limits that stop someone guessing at your password could not count anything.
- When you agreed to the terms, and when you agreed to the plan terms, so that the agreement can be shown to have happened.
- Your interface language, so we can write to you in it.
- If you turn on two-factor authentication: the shared secret, encrypted before it is stored, and a hash of each recovery code.
- If you sign in through Google or GitHub: that provider's own identifier for you and the email address on that account.
- Your account settings — what happens when a plan's allowance runs out, what happens when an Economy model is unavailable.
About each request through the gateway:
- Which model you asked for and which version answered, how many tokens went in and out (including how many were served from the provider's cache), how long it took, whether it succeeded, which of your keys made it, which upstream account served it, and what it cost you and cost us. That is what your usage page, your bill and our books are built from.
- A request identifier, returned to you in the x-request-id header, so that a question about one request can be answered.
About money:
- Every credit and debit on your balance, with a description, and every payment: the amount, the currency, the processor's reference and the state of the payment. For crypto payments we store the notification the processor sends us in full. Card numbers, wallet keys and bank details never reach us.
When you write to us, we keep the correspondence for as long as it takes to deal with it and to show afterwards what was agreed.
3. What we do not store
We do not store the content of your prompts, of the images or files you send with them, or of the answers that come back. No table in our database has a column for them, and the gateway does not write request or response bodies to its logs. Nothing on our side reads your prompts for any purpose — not to train a model, not to improve the service, not to look at what people ask.
One exception is worth stating rather than leaving for you to find. When a provider refuses or fails a request, we keep the beginning of the error it sent back — at most 400 characters — attached to the record of that failed request, and the same text can appear in our server logs. Providers normally explain themselves rather than quote you, but a refusal on content grounds sometimes repeats the phrase it objected to. That fragment is the only way any part of what you sent can end up in our records.
4. Where your prompts go
The provider behind the model you chose receives your request in full — the messages, any images, tool definitions and parameters — because it cannot answer without it, and its answer comes back through us. Which provider that is depends on the model and on the route available at that moment; the catalogue names the vendor behind each model, and the Model and Provider Terms link each major provider's data policy. The provider processes your request under its own terms, which we cannot change on your behalf.
What that means in practice: the provider may keep your request and the answer for a limited time to monitor for abuse — each provider's own data policy, linked from the Model and Provider Terms, says how long — and may process it in a country other than yours, most often the United States. OpenAI, Anthropic, Google, Microsoft and Amazon each state that data sent through their APIs is not used to train their models; we do not opt into any programme that would change that. Other providers named in the catalogue set their own rules, and we do not speak for them. If what happens to a prompt after it leaves us matters for your work, choose the model with the provider's policy in mind.
For some routes, the connection from our gateway to the provider passes through a third-party network provider. That connection is an encrypted tunnel from our gateway to the provider; the network provider sees where the traffic goes, not what it says.
5. The chat playground
The chat page on this site is the same gateway with a page in front of it. The conversation you see there is kept in your own browser, not on our server; clearing your browser data clears it. Requests made from it are recorded exactly like requests made with a key, and their content goes to the provider exactly the same way.
6. Why we process personal data
- To provide the service you asked for: your account, your keys, your balance and the record of what each request cost. This is performance of our contract with you; without it there is no service to provide.
- Because the law requires it: payment and accounting records are kept to meet tax, company-law and anti-fraud obligations.
- Because we have a legitimate interest in the service surviving and in keeping it safe for everyone: the sign-in attempt log, the session records, the rate limits and the abuse checks exist to stop password guessing, card testing, fraud and attacks, and they cannot work without recording what happened.
- Because you agreed, where that is the basis — for example when you connect a Google or GitHub account. You can withdraw that consent by disconnecting it.
7. Cookies
One cookie signs you in and keeps you signed in; a short-lived one carries a two-factor challenge between the password step and the code step; and one remembers the language you chose. All three are needed for the site to work, which is why there is no cookie banner. There is no advertising cookie here and no third-party analytics or tracking script: nothing on this site follows you anywhere else.
8. Who else receives data
We use other companies to run the service. Each receives only what its job needs:
- AI model providers — the request itself and the answer, as described in section 4. OpenAI, Anthropic, Google, Microsoft and Amazon are the ones behind most models; the catalogue names the vendor behind each, and which one serves a request can change.
- Stripe, for card payments — your email address, an account reference, the amount, and whatever you type on Stripe's own payment page. Stripe is the one that sees your card.
- NOWPayments and CoinGate, for cryptocurrency payments — an order reference, the amount and the currency.
- Resend, which delivers our email — the address we are writing to and the letter itself.
- Neon, which hosts our database in the European Union (Frankfurt) — everything listed in section 2.
- Render, which hosts the website and console in the European Union (Frankfurt) — what passes through the site as you use it.
- Oracle Cloud, which hosts the gateway in the European Union (Frankfurt) — what passes through the gateway as requests are served, and the encrypted backups of the database.
- A network provider through which some routes to the providers pass, as an encrypted tunnel — the destination of the traffic, not its content.
- GitHub, which holds the encrypted copies of our database backups. The copies are encrypted before they leave our servers, with a key GitHub does not have.
We do not sell personal data, we do not share it for advertising, and we do not give it to anyone else except where the law requires us to — a court order, a lawful request from an authority, or a report we are obliged to make. Where we must disclose something, we disclose only what is required.
9. International transfers
Our own infrastructure is in the European Union. The providers that answer requests, the payment processors and the email service are mostly in the United States, so using this service means personal data leaves the United Kingdom and the European Union. Those transfers rely on the protections in our agreements with each company — the UK Addendum to the EU standard contractual clauses, the EU–US Data Privacy Framework where a company is certified under it, or an adequacy decision where one covers the destination. You can ask us at support@flintbeam.com which applies to which.
10. How long we keep things
- Your account details: for as long as your account is open, and until the closing described in section 11.
- Sessions, sign-in attempts, email confirmation tokens and two-factor challenges: a nightly job deletes each of them 90 days after it stopped mattering — after a session expired or was ended, after an attempt was made, after a token was used or expired.
- Request records: for as long as the payments they explain are kept, because they are what each charge on your balance is made of.
- Ledger entries and payments: for at least six years after the year they belong to, as UK tax and company law require, including after an account closes.
- Encrypted database backups: kept on our server for fourteen days (the daily copies) and two days (the hourly copies). The daily copies are also kept in an encrypted archive indefinitely — an archive is not edited when a record inside it reaches the end of its retention, and it is opened only to restore the database.
- Support correspondence: as long as the matter is open, and up to two years afterwards.
If you want something removed sooner, ask us at support@flintbeam.com. We will do it where the law lets us, and tell you which part we cannot remove and why — an accounting record we are required to keep is the usual reason.
11. Closing an account
Closing an account revokes every API key on it, ends every session, deletes your password, your name, your two-factor secret and your recovery codes, and releases your email address so that it can be used again — the address on the record is replaced with one that belongs to nobody. Session and sign-in records are removed by the nightly job on the schedule above.
What stays is the accounting: the requests, the ledger and the payments, along with the identifier they hang from and the IP address the account was opened with. They are records of money moving, and they have to remain readable for the time the law requires. Nothing in them says who you are once the account has been closed.
12. Your rights
From the account page, without asking anyone, you can:
- Change your email address. We send a confirmation to the new address and tell the old one afterwards.
- Change your password, or set one if you signed up through a provider, using the reset link on the sign-in page.
- See and end every session on your account.
- Turn two-factor authentication on or off, and reissue recovery codes.
- Disconnect Google or GitHub, as long as another way to sign in remains.
- Close your account.
The law also gives you the right to ask for a copy of the personal data we hold about you, to have it corrected, to have it deleted, to object to how we use it, to ask us to restrict what we do with it, to receive it in a portable form, and to withdraw a consent you gave. Write to support@flintbeam.com from the address on your account and we will answer within one month. Where we cannot do what you ask, we will say which part and why.
13. Automated decisions
Rate limits and spending ceilings are arithmetic you can see and set, and a refusal from a provider is the provider's. A suspension can be triggered automatically — by a reversed payment, or by traffic that looks like an attack — because waiting for a person would cost someone else money. What happens after a suspension is not automatic: a person reviews it, records the outcome and explains it, and you can appeal under the Model and Provider Terms.
14. Children
This service is not for children. Accounts are for adults, or for those old enough to enter a contract where they live, and we do not knowingly collect anything about anyone younger. If you believe a child has an account here, tell us at support@flintbeam.com and we will remove it.
15. How we protect data
- Passwords are hashed with argon2id, API keys are stored only as hashes, and two-factor secrets are encrypted with a key kept apart from the database.
- The database is reached through roles that can see only what they need: the console's role cannot read another account's rows even when asked to, because the database itself refuses.
- Everything travels over TLS — between you and us, between us and the providers, and between our own components. The site is served with a content security policy that stops a model's answer from fetching anything from the network.
- Administrative access requires two-factor authentication. Backups are encrypted before they leave our servers and are restored in a rehearsal every month.
- No security is perfect. If we learn of a breach that affects your personal data, we will tell you and the supervisory authority as the law requires, without undue delay.
16. Complaints
Tell us first at support@flintbeam.com — most things are quicker to fix directly. If that does not resolve it, you can complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk, or to the data protection authority of the country where you live.
17. Changes to this page
This page changes when the service does, and the date at the top says when it last did. If a change means we start doing something with your data that this page does not already describe, we will tell you by email at least 14 days before it starts rather than let you find it.