We do not sell personal information or customer data.
Customer runtime data is processed in Fused-operated infrastructure only when an organization chooses a Fused Cloud service. A self-hosted Fused Engine keeps API payloads, provider credentials, connections, and execution records in the customer’s environment.
1. Scope and roles
Fused is an integration gateway for applications and AI agents. The parts of Fused do different jobs, and that affects which data each part handles.
Fused Registry
Fused Engine
Fused Auth
Fused Managed Auth
2. Information we process when you use Fused Cloud
- Account and identity data: name, email address, verified identity claims, organization or workspace membership, roles, invitations, and authentication events.
- Service and app configuration: imported API descriptions, reviewed overlays, service metadata, selected operations, generated app configuration, connection profiles, webhook definitions, and publication choices.
- Credentials and connection data: by default, encrypted secrets, OAuth or OIDC grants, provider resource identifiers, connection metadata, consent state, and token lifecycle information remain in the Engine. A self-hosted Engine’s local credentials and connections are not copied to Fused Cloud merely because the Engine uses a Fused license. If a customer separately enables Fused Managed Auth, its broker processes and stores the encrypted refresh credentials needed to provide that selected service.
- Operational data: request and execution identifiers, timestamps, outcomes, bounded diagnostics, usage totals, audit events, IP-derived security signals, and service health information. Fused is designed to exclude credentials and raw provider payloads from ordinary logs and telemetry.
- Commercial and support data: plan, billing, support correspondence, and information supplied when requesting access or assistance.
- Website data: cookies, session state, and limited analytics about use of Fused-operated web pages.
3. How we use information
We use information to provide, secure, maintain, and improve Fused; authenticate users and Engines; enforce permissions and plan limits; import and version service contracts; route approved operations; manage connections; generate requested SDK, REST, and MCP interfaces; prevent abuse; diagnose failures; communicate service and security notices; provide support; and meet legal obligations.
We do not sell or rent personal information or customer data. We also do not share it for cross-context behavioural advertising. Data supplied to a Fused Cloud service is used to provide that service and the related security, support, billing, and compliance functions described in this policy.
Using Registry or a Fused license does not give Fused access to the API payloads, credentials, connected-user tokens, or webhook state inside a self-hosted Engine. Those boundaries change only when the customer deliberately publishes or imports information, requests support involving that information, chooses a Fused Cloud Engine, or separately enables a managed feature that clearly describes the additional processing.
We do not use provider credentials or customer API payloads to train general-purpose AI models. If an optional feature needs additional processing, its interface or separate terms will describe that processing before it is enabled.
5. Your controls and responsibilities
Workspace administrators control membership, roles, service visibility, app selection, credential buckets, connected accounts, and the removal of workspace resources. Customers are responsible for providing appropriate notices and obtaining any consent required from their own users before connecting accounts or processing their data through Fused.
You may request access, correction, deletion, or another privacy right that applies to your account by contacting hello@usefused.com. We may need to verify the request and may direct requests about a customer-operated Engine to that Engine’s operator.
6. Retention and deletion
We retain information while an account, workspace, service publication, connection, or legal obligation requires it. Retention periods vary by data type, configuration, backup cycle, dispute, security need, and applicable law. Removing a service from a workspace does not delete a separately published Registry definition. Disconnecting an auth connection removes its local execution eligibility and may also trigger provider revocation where supported.
7. Security and international processing
Fused uses technical and organizational safeguards designed for the sensitivity of the information, including scoped authorization, encryption for protected credentials, short-lived transactions, audit records, and secret-safe logging. No system is completely secure, so customers should use least privilege, protect keys, keep Engines updated, and promptly report suspected compromise.
Fused and its service providers may process information in countries other than where you live. Where required, we use appropriate contractual or legal safeguards for those transfers.
8. Children
Fused is a business service and is not directed to children. Do not use Fused to knowingly collect children’s personal information unless you have all authority, safeguards, and consent required by applicable law.
9. Changes and contact
We may update this policy as Fused changes. We will update the date above and provide additional notice when a change is material and notice is required. Questions or requests can be sent to hello@usefused.com.