Developer signup is open. Create your account →

Legal

Privacy Policy

How Fused handles account, service, connection, and operational data across the Registry, Engine, Fused Auth, and Fused Managed Auth.

Last updated 16 September 2026

We do not sell personal information or customer data.

Customer runtime data is processed in Fused-operated infrastructure only when an organization chooses a Fused Cloud service. A self-hosted Fused Engine keeps API payloads, provider credentials, connections, and execution records in the customer’s environment.

1. Scope and roles

Fused is an integration gateway for applications and AI agents. The parts of Fused do different jobs, and that affects which data each part handles.

Fused Registry

Stores account and workspace identity, licensing and entitlement state, versioned service contracts, public catalogue information, and the source material needed to review and reproduce an import. A service owner decides whether eligible service metadata is made public.

Fused Engine

Runs approved operations, applies workspace access rules, and stores workspace configuration, execution records, buckets, provider credentials, connected-user tokens, and webhook delivery state. A self-hosted Engine keeps that runtime data in the customer’s environment. A Fused Cloud Engine is an isolated Engine operated for the customer in Fused-managed infrastructure.

Fused Auth

Lets a workspace connect provider accounts with an OAuth, OIDC, API-key, or other supported authentication configuration. For customer-owned OAuth applications, the customer supplies the provider application credentials and the Engine manages the resulting connection.

Fused Managed Auth

Where expressly offered and separately enabled, uses a Fused-managed provider application and broker to complete consent, protect application secrets, and maintain encrypted refresh credentials. This is an explicit exception to the default Engine-local token model and is disclosed before consent. Availability depends on provider, scopes, environment, plan, and approval status.

2. Information we process when you use Fused Cloud

  • Account and identity data: name, email address, verified identity claims, organization or workspace membership, roles, invitations, and authentication events.
  • Service and app configuration: imported API descriptions, reviewed overlays, service metadata, selected operations, generated app configuration, connection profiles, webhook definitions, and publication choices.
  • Credentials and connection data: by default, encrypted secrets, OAuth or OIDC grants, provider resource identifiers, connection metadata, consent state, and token lifecycle information remain in the Engine. A self-hosted Engine’s local credentials and connections are not copied to Fused Cloud merely because the Engine uses a Fused license. If a customer separately enables Fused Managed Auth, its broker processes and stores the encrypted refresh credentials needed to provide that selected service.
  • Operational data: request and execution identifiers, timestamps, outcomes, bounded diagnostics, usage totals, audit events, IP-derived security signals, and service health information. Fused is designed to exclude credentials and raw provider payloads from ordinary logs and telemetry.
  • Commercial and support data: plan, billing, support correspondence, and information supplied when requesting access or assistance.
  • Website data: cookies, session state, and limited analytics about use of Fused-operated web pages.

3. How we use information

We use information to provide, secure, maintain, and improve Fused; authenticate users and Engines; enforce permissions and plan limits; import and version service contracts; route approved operations; manage connections; generate requested SDK, REST, and MCP interfaces; prevent abuse; diagnose failures; communicate service and security notices; provide support; and meet legal obligations.

We do not sell or rent personal information or customer data. We also do not share it for cross-context behavioural advertising. Data supplied to a Fused Cloud service is used to provide that service and the related security, support, billing, and compliance functions described in this policy.

Using Registry or a Fused license does not give Fused access to the API payloads, credentials, connected-user tokens, or webhook state inside a self-hosted Engine. Those boundaries change only when the customer deliberately publishes or imports information, requests support involving that information, chooses a Fused Cloud Engine, or separately enables a managed feature that clearly describes the additional processing.

We do not use provider credentials or customer API payloads to train general-purpose AI models. If an optional feature needs additional processing, its interface or separate terms will describe that processing before it is enabled.

4. When information is shared

We share information only as needed to operate the service: with infrastructure, identity, monitoring, communications, and payment providers acting for us; with third-party API providers when an authorized request or consent flow requires it; with workspace administrators according to configured permissions; during a corporate transaction; or when required to protect rights, safety, and the service or comply with law.

Publishing a service or version to the public Registry intentionally makes the selected catalogue metadata and contract available to other users. Credentials, private bucket values, private connection records, and Engine-local authorization rules are not public Registry content.

5. Your controls and responsibilities

Workspace administrators control membership, roles, service visibility, app selection, credential buckets, connected accounts, and the removal of workspace resources. Customers are responsible for providing appropriate notices and obtaining any consent required from their own users before connecting accounts or processing their data through Fused.

You may request access, correction, deletion, or another privacy right that applies to your account by contacting hello@usefused.com. We may need to verify the request and may direct requests about a customer-operated Engine to that Engine’s operator.

6. Retention and deletion

We retain information while an account, workspace, service publication, connection, or legal obligation requires it. Retention periods vary by data type, configuration, backup cycle, dispute, security need, and applicable law. Removing a service from a workspace does not delete a separately published Registry definition. Disconnecting an auth connection removes its local execution eligibility and may also trigger provider revocation where supported.

7. Security and international processing

Fused uses technical and organizational safeguards designed for the sensitivity of the information, including scoped authorization, encryption for protected credentials, short-lived transactions, audit records, and secret-safe logging. No system is completely secure, so customers should use least privilege, protect keys, keep Engines updated, and promptly report suspected compromise.

Fused and its service providers may process information in countries other than where you live. Where required, we use appropriate contractual or legal safeguards for those transfers.

8. Children

Fused is a business service and is not directed to children. Do not use Fused to knowingly collect children’s personal information unless you have all authority, safeguards, and consent required by applicable law.

9. Changes and contact

We may update this policy as Fused changes. We will update the date above and provide additional notice when a change is material and notice is required. Questions or requests can be sent to hello@usefused.com.