AI FEATURES TERMS
Version 1.0 · Effective 18 September 2026 · Part of the Agreement (Terms of Service Section 6; DPA Section 5)
Convenience translation; the Ukrainian text prevails. Product note: this is not "consent" under Article 6(1)(a) GDPR but a controller instruction and prior sub-processor authorisation (Article 28(2), (3)(a)) — hence "confirmation", not "consent", throughout. Theconsentstable key may stayai.
Part A. Screen text (shown before the first AI node is added)
Before you add an AI step
AI steps — nodes, agents, vector search, the editor assistant — send data to a language model. Here is what you need to know.
Where the data goes.
- Oxta key (default): requests run on Cloudflare Workers AI — the same infrastructure the platform runs on. Data does not leave Cloudflare's perimeter. Models:
glm-5.3-flash(text),embeddinggemma-300m(vectors). We do not grant Cloudflare permission to use request content to train models. - Your own key: requests go directly to the provider you specify, under your contract with it. We do not control how it stores or uses them.
What exactly is sent. Your prompt with values substituted from previous steps, the node's system instruction, and for search — the query text and fragments of your dataset.
What is not sent. Your e-mail and name, credentials and keys (redacted automatically), payment history, data from other flows.
Important: if you place your customers' personal data in a prompt, it will be sent to the model. You are responsible for having a legal basis. Health, biometric, belief and criminal-record data must not pass through the platform.
What we store. The model's request and response are written to run history like any other step and kept under the same rules (up to the 10,000 most recent runs per flow). There is no separate switch for AI steps.
Limitations. The model can be wrong or make things up. Output is not professional advice. Reproducibility is not guaranteed. Verify results before use.
Your control. You can withdraw this confirmation in settings → "Documents & consents". After withdrawal you cannot add new AI steps; you must modify or stop already-configured flows with AI steps yourself.
By confirming, you as data controller instruct us to send data to language models as described above and authorise Cloudflare Workers AI as a sub-processor.
☐ I have read and understand what data is sent to models
[ Confirm and add AI step ] [ Cancel ]
Part B. Full text
1. What AI features are
1.1. AI features are: AI nodes in flows (text generation, classification, extraction); agents; vector search in datasets, including converting uploaded text into vectors; the editor assistant and help search.
1.2. Data is sent to language models only when these features are used. Flows without AI steps send nothing to models.
2. Two modes and the responsibility boundary
2.1. "Oxta key" mode (default). Model calls run via Cloudflare Workers AI. Cloudflare is our sub-processor (DPA Annex 2); data stays within the Cloudflare infrastructure the whole platform runs on. Models as of this version: @cf/zai-org/glm-5.3-flash (text, agents, assistant) and @cf/google/embeddinggemma-300m (vectors). We may swap models for functionally equivalent ones within Workers AI with notice on the sub-processor page. Operations count against plan quota.
2.2. "Own key" mode. You provide a key and endpoint for an OpenAI-API-compatible provider. Requests go directly to it and do not consume quota. Responsibility boundary: we are responsible for sending the request unaltered (except secret redaction) only to the endpoint you specified and to no one else; the provider is responsible, under your contract with it, for storing, using and protecting requests. This is a transfer on your instruction (DPA Sections 2.3, 5.3, 6.5).
3. What is and is not sent
3.1. Sent: your prompt with substituted values from prior steps; the node's or agent's system instruction; for vector search — the query text and dataset fragments; for the assistant — your question and the flow structure.
3.2. Not sent: the account owner's e-mail and name; credentials, keys and passwords stored on the platform (redacted automatically); payment history; data of other flows and other accounts.
3.3. Personal data in prompts. The platform does not filter prompt content. If you place personal data in a prompt (a customer's name, message, order) it will be sent to the model — that is your instruction as controller. You are responsible for the legal basis and for informing data subjects. Special categories are prohibited (Terms Section 5.3).
4. What we store
4.1. The model request and response are stored in run history as a step result — with the same access and retention as other steps (up to the 10,000 most recent runs per flow; DPA Annex 1). No separate history switch exists for AI steps; you may delete the run or the flow with its history.
4.2. Dataset vectors are stored in Cloudflare Vectorize until the dataset is deleted.
5. Limitations
Model outputs may be inaccurate, incomplete or fabricated; are not legal, medical, financial or other professional advice; may differ on re-run with identical input. You are responsible for verifying results and for actions your flow takes on them (sending messages, changing records, etc.). Our liability is limited per Section 14 of the Terms.
6. Confirmation and withdrawal
6.1. Confirmation is requested once before the first AI step is added and recorded in consent records with this document's version, time and location (editor). A substantive change to this document = new version = renewed confirmation.
6.2. Legal nature. The confirmation is a documented controller instruction to the processor (Article 28(3)(a) GDPR) and prior written authorisation of the Cloudflare Workers AI sub-processor (Article 28(2)). The basis for processing your own data as a user when using the assistant is contract performance (Article 6(1)(b)). The basis for processing your customers' data is determined by you as controller.
6.3. Withdrawal. You may withdraw in settings → "Documents & consents". Effects: (a) adding new AI steps is blocked immediately; (b) execution of already-configured AI steps does not stop automatically — you undertake to modify or stop flows with AI steps within 7 days, after which we may stop them ourselves; (c) requests already sent cannot be recalled; results stored in history remain until you delete them.
6.4. Withdrawal does not affect the lawfulness of processing before it.
7. Changes
Changes follow Section 17 of the Terms. A change of AI sub-processor follows DPA Section 6 (30 days, right to object).