Fly.io revised its privacy policy to clarify third-party data collection on its platform. Previously, the policy stated that third-party tracking was not permitted except for described analytics, which users could opt out of. The updated policy now discloses a second category of third-party data collection: fraud and abuse prevention services that collect device and browser signals to detect automated abuse. This fraud prevention processing is mandatory and cannot be opted out of, and Fly.io states its legal basis is its legitimate interest in protecting the platform.
Consumers: When you create an account or sign in, Fly.io uses third-party services to collect device and browser signals to detect abuse, and you cannot opt out of this.
The updated policy now explicitly discloses that Fly.io uses third-party fraud-prevention services that collect device and browser signals (such as device identifiers and browser fingerprints) when you create an account or sign in. The policy states this data collection is mandatory and cannot be opted out of, distinguishing it from analytics collection, which remains optional. The company asserts its legal basis is its legitimate interest in protecting the platform and its users.
→ Review the Sub-processors page linked in the policy to identify the specific fraud-prevention service providers and their privacy practices.
Fly.io now discloses mandatory collection of device and browser signals by third-party fraud-prevention services; this processing cannot be opted out of and is justified by legitimate interest in platform protection.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Fly.io has added explicit disclosure of mandatory third-party fraud-prevention data collection, separated from optional analytics. The disclosure establishes a legitimate-interest legal basis under GDPR Article 6(1)(f). Organizations using Fly.io infrastructure should assess whether this mandatory …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004239.
Fly.io's privacy policy, effective July 20, 2026, now explicitly discloses the use of two analytics services: Google Analytics and PostHog. …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.