Privacy Policy

Last updated: January 25, 2026 • Axiom by FastenAI

1. Introduction

Welcome to Axiom, a product of FastenAI. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you visit our website and engage with our workflow automation services.

2. Data We Collect

We collect the following categories of data:

  • Identity Data: Name, email address, and profile information provided during registration.
  • Technical Data: IP address, browser type, device information, and usage patterns.
  • Workflow Data: The structure and configuration of your automations, including node types and connections.
  • Credentials: API keys and authentication tokens you provide for integrations (stored encrypted).

Important: We do not train our AI models on your specific workflow inputs or outputs. Your data remains private.

3. How We Use Your Data

We use your data for the following purposes:

  • To provide and maintain the Axiom service.
  • To process your subscription payments via our payment provider (Polar.sh).
  • To send you administrative emails (password resets, security alerts, service updates).
  • To improve our website and services through aggregated, anonymized analytics.
  • To respond to your support requests and inquiries.

4. Data Security

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way:

  • Encryption at Rest: Your API credentials are encrypted using AES-256 encryption before being stored in our database.
  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3.
  • Access Controls: Only authorized personnel have access to your data, and all access is logged.
  • Secure Infrastructure: Our servers are hosted on secure, SOC2-compliant cloud infrastructure.

5. Third-Party Services

We integrate with the following third-party services:

  • Polar.sh: For subscription and payment processing.
  • Resend: For transactional email delivery.
  • Sentry: For error tracking and performance monitoring (no personal data is shared).
  • AI Providers (OpenAI, Anthropic, Google): When you use AI nodes, your prompts are sent to these providers according to their respective privacy policies.

6. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (account deletion).
  • Object to processing of your data.
  • Request data portability (export your workflows).

7. Data Retention

We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes.

8. Cookies

We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any significant changes by email or through a notice on our website.

10. Contact Us

If you have any questions about this privacy policy or our data practices, please reach out to us.