Last updated: 3 October 2026
Privacy Policy
MUSCLE Flex is operated by Adhibita, St. Louis, Missouri, USA. Contact: [email protected]. MUSCLE Flex is in beta. We will notify you of material changes by email before they take effect.
1. Scope.
This policy covers the adhibita.com website and its access-request form, the Flex API, and the account portal. It does not cover the processing of your requests by third-party AI model providers (see section 4).
2. What we collect.
- Access requests: the name, work email, project description, client or SDK, workflow, and team or organization you enter in the request-access form. It is sent to our team to evaluate beta fit and to contact you about access.
- Account data: email address, name or handle, and account settings you provide at registration or in the portal, plus the messages you send through portal support.
- Credentials: the Flex API keys issued to you and your sign-in credentials. We store a one-way hash of each API key, not the key itself, and use it only to authenticate your requests. You never supply keys for third-party AI model providers.
- Usage and metering data: for each request, an identifier, timing, token counts, status or error code, routing outcome, and cost accounting, together with a one-way hash of your IP address and your client’s user-agent string. These records are designed to be categorical and do not store the text of your prompts or outputs. One exception: when a request goes through an automated code-verification step that fails, the routing record can keep the generated code and the verification report, so we can diagnose routing quality.
- Request content: prompts, source code, tool schemas, tool results and generated output are processed to fulfill your requests and are sent to the third-party model provider that serves the request. They are not sold and are not used by us to train models. Response caching is off unless it is enabled for your account; when it is on, exact-match replies are stored for up to 24 hours.
- Operational logs: security and diagnostic logs, kept in a fixed-size rolling store (see Retention).
- Portal sign-in: when you sign in to the portal we record the session, including your IP address and browser user-agent, to keep you signed in and to protect your account.
- Cookies and local storage: what is needed to keep you signed in to the portal and to protect sign-in, plus a cookie that remembers your light or dark theme choice. No advertising trackers.
3. How we use data.
To operate and secure the Service (routing, metering, billing, abuse prevention, support), to improve routing using categorical records, to communicate service updates, and to comply with law. We send service email (invitations, sign-in and verification links, and notices) from [email protected]. We do not sell personal information and do not use it for third-party advertising.
4. Third-party processors.
Requests are routed to third-party AI model providers that we contract with; the content of your prompts and their completions is processed by the provider that serves the request, under our agreement with that provider and its terms and privacy policy. We do not control a provider’s retention practices and do not promise that a provider keeps nothing. We also use hosting infrastructure and an email delivery service. There is no online checkout during the beta; if payments are enabled later, payment processors will handle payment details and we will update this policy.
5. Retention.
We keep each kind of data only as long as the schedule below says. Periods count from when the record was created. Deletion runs automatically several times a day, so a record can outlast its period by a few days.
- Routing details for each request (including any generated code and verification report kept from a failed code-verification step) and internal copies of accounting jobs: 30 days.
- Per-request usage records (identifier, timing, token counts, status, routing outcome, cost accounting, IP-address hash and user-agent string): 90 days. After that we keep only daily totals per account, API key and model.
- Records that reconcile our costs with model providers: 13 months.
- Billing records (credit purchases and grants, balance changes, monthly usage totals, and payment events): 7 years, for tax and accounting.
- Portal sign-in sessions and email verification links: deleted 30 days after they expire.
- Access requests that do not lead to an account: 12 months.
- Account data and support messages: while your account is active, and for a short wind-down period after you ask us to delete your account, except the billing records above.
- Operational logs: a fixed-size rolling store per service; the oldest entries are overwritten as new ones are written.
- Cached replies, where enabled: 24 hours.
- Encrypted database backups: the 14 most recent daily backups are kept, so deleted data can remain in a backup for up to about 14 days.
A record tied to an unsettled charge, an open dispute or an unresolved reconciliation is kept until that is resolved, even past its period.
6. Security.
Transport encryption (TLS) for our endpoints; API keys stored only as one-way hashes; secrets protected with least-privilege access; and logging of administrative actions. No system is perfectly secure, and we do not claim any security certification.
7. Your choices and rights.
You may access, correct, or delete account data, and rotate or revoke API keys, through the portal or by contacting [email protected]. We will honor applicable U.S. state privacy rights requests. As a U.S.-operated service, we do not claim EU/UK adequacy. Do not submit regulated or special-category data (for example health data or payment card numbers) through the beta Service.
8. Children.
The Service is not directed to children under 18, and we do not knowingly collect their data.
9. Changes.
Material changes will be notified by email, or through the Service, before they take effect. The "Last updated" date above shows the current version.
10. Contact.
[email protected] · Adhibita, St. Louis, Missouri, USA.