Change record
CA-C-004239
Fly.io Privacy Policy
Entity
Date detected
August 7, 2026
Severity
Direction
Neutral
Taxonomy
Disclosure requirement change
Changes
+5 sentences added · 2 sentences modified

Impact Summary

Medium Neutral for users
Affected users
All users EU users

Fly.io revised its privacy policy to clarify third-party data collection on its platform. Previously, the policy stated that third-party tracking was not permitted except for described analytics, which users could opt out of. The updated policy now discloses a second category of third-party data collection: fraud and abuse prevention services that collect device and browser signals to detect automated abuse. This fraud prevention processing is mandatory and cannot be opted out of, and Fly.io states its legal basis is its legitimate interest in protecting the platform.

1 new obligation

Consumers: When you create an account or sign in, Fly.io uses third-party services to collect device and browser signals to detect abuse, and you cannot opt out of this.

Stay ahead of the changes
Track Fly.io and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

The updated policy now explicitly discloses that Fly.io uses third-party fraud-prevention services that collect device and browser signals (such as device identifiers and browser fingerprints) when you create an account or sign in. The policy states this data collection is mandatory and cannot be opted out of, distinguishing it from analytics collection, which remains optional. The company asserts its legal basis is its legitimate interest in protecting the platform and its users.

What you can do

Review the Sub-processors page linked in the policy to identify the specific fraud-prevention service providers and their privacy practices.

Key Clauses Affected

Fraud and abuse prevention processing

Fly.io now discloses mandatory collection of device and browser signals by third-party fraud-prevention services; this processing cannot be opted out of and is justified by legitimate interest in platform protection.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
e2c89424e23a0dbc51e89e8a1dc9856eb577085a875868699cb4fb30e1253bb7
July 21, 2026 01:18 UTC
✓ Verified
Current Version
bae6d90946ef6a187b4c3311152c53d998577a5ae54645daede753a712e0f3b4
August 7, 2026 01:16 UTC
✓ Verified
Change Detected
August 7, 2026 01:16 UTC
Analysis Methodology
✓ Verified
Source Document
https://fly.io/legal/privacy-policy/
Citation Record
Entity: Fly.io
Document: Fly.io Privacy Policy
Record ID: CA-C-004239
Captured: 2026-08-07 01:16:56 UTC
URL: https://conductatlas.com/change/2026-08-07-flyio-flyio-privacy-policy-4239/
Accessed: Aug. 7, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

Fly.io has added explicit disclosure of mandatory third-party fraud-prevention data collection, separated from optional analytics. The disclosure establishes a legitimate-interest legal basis under GDPR Article 6(1)(f). Organizations using Fly.io infrastructure should assess whether this mandatory …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004239.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
Fly.io Privacy Policy
Entity
Fly.io
Captured
August 7, 2026
Source URL
https://fly.io/legal/privacy-policy/
Other changes to Fly.io Privacy Policy
Previous change Jul 21, 2026
Fly.io's privacy policy, effective July 20, 2026, now explicitly discloses the use of two analytics services: Google Analytics and PostHog. …
Low Neutral
View full version history →
More from Fly.io
Jul 21, 2026 Low
Fly.io Privacy Policy

Fly.io's privacy policy, effective July 20, 2026, now explicitly discloses the use of two analytics services: Google Analytics and PostHog. …

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track Fly.io policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All Fly.io changes →