53 Total
16 High severity
28 Medium severity
9 Low severity

Key Facts

What governs over the terms of the Privacy Statement in any conflict between the two?
Fly.io's Data Privacy Framework (DPF) Principles govern over the terms of the Privacy Statement in any conflict between the two.
Do Fly.io's Data Privacy Framework Principles govern over the terms of the Privacy Statement?
Fly.io's Data Privacy Framework (DPF) Principles govern over the terms of the Privacy Statement in any conflict between the two.
May Fly.io share User Personal Information in the event of a merger or sale?
Fly.io may share User Personal Information in the event of a merger, sale, or acquisition, under terms that preserve the confidentiality of that information.
May Fly.io disclose personally-identifying information to law enforcement in response to a valid subpoena or court order?
Fly.io may disclose personally-identifying information or other collected information about users to law enforcement in response to a valid subpoena, court order, warrant, or similar government order.
Does Fly.io automatically delete inactive accounts?
Fly.io retains user account information indefinitely unless the user chooses to delete their account, because Fly.io does not automatically delete inactive accounts.
How will Fly.io notify users of material changes to its Privacy Statement?
Fly.io will notify users of material changes to its Privacy Statement at least 30 days before those changes take effect, by posting a notice on its home page or sending email.
When will Fly.io notify users of material changes to its Privacy Statement?
Fly.io will notify users of material changes to its Privacy Statement at least 30 days before those changes take effect, by posting a notice on its home page or sending email.
Will Fly.io notify users of material changes to its Privacy Statement at least 30 days before those changes take effect?
Fly.io will notify users of material changes to its Privacy Statement at least 30 days before those changes take effect, by posting a notice on its home page or sending email.
Can children under the age of 13 hold an account on fly.io?
Fly.io prohibits children under the age of 13 from holding an account on fly.io and does not knowingly collect information from or direct content specifically to children under 13.
Does Fly.io knowingly collect information from children under 13?
Fly.io prohibits children under the age of 13 from holding an account on fly.io and does not knowingly collect information from or direct content specifically to children under 13.
Stay ahead of the changes
Track Fly.io and get the diff the day its terms change.
Summary

Fly.io's Privacy Policy explains what information it collects about you, how it uses it, and who it can share it with. Fly.io will not sell or trade your personal information to third parties for their commercial purposes, but it can share it during a merger or acquisition, or hand it over to law enforcement under a valid legal order. Your account information is kept indefinitely unless you actively delete your account, and Fly.io must give you at least 30 days' notice before making significant changes to this policy.

Analysis

This Privacy Statement establishes Fly.io's obligations and limitations regarding the collection, use, retention, and sharing of User Personal Information. Fly.io limits data use to stated purposes and requires user permission before expanding those uses; it does not sell, rent, or trade User Personal Information to third parties for commercial purposes. Account information is retained indefinitely absent user-initiated deletion, and data stored on Fly.io's servers is held on US-based infrastructure, with the act of uploading sensitive data constituting implied consent to that arrangement. In any conflict between the Privacy Statement and Fly.io's Data Privacy Framework Principles, the DPF Principles govern. Users are afforded self-service access, correction, and deletion rights, and are entitled to at least 30 days' advance notice of material policy changes.

What this means for you

As a Fly.io user, your personal information is used only for purposes stated in the Privacy Policy, and Fly.io must obtain your permission before using it for anything else. Your account data is retained forever unless you take action: you can delete your account using the simple deletion methods Fly.io provides, which is the direct way to stop ongoing retention. Storing sensitive personal information on Fly.io's servers constitutes your consent to that data being held on servers in the United States. Law enforcement can obtain your data through a valid subpoena, court order, or warrant without your prior notice or consent, and Fly.io cannot guarantee absolute security of your data.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

2 important changes detected

3 versions captured · Last updated: August 2026

What changed Fly.io revised its privacy policy to clarify third-party data collection on its platform. Previously, the policy stated that third-party tracking was not permitted except for described analytics, which users could opt out of. The updated policy now discloses a second category of third-party data collection: fraud and abuse prevention services that collect device and browser signals to detect automated abuse. This fraud prevention processing is mandatory and cannot be opted out of, and Fly.io states its legal basis is its legitimate interest in protecting the platform.
Why this matters The updated policy now explicitly discloses that Fly.io uses third-party fraud-prevention services that collect device and browser signals (such as device identifiers and browser fingerprints) when you create an account or sign in. The policy states this data collection is mandatory and cannot be opted out of, distinguishing it from analytics collection, which remains optional. The company asserts its legal basis is its legitimate interest in protecting the platform and its users.
View full change record →
What changed Fly.io's privacy policy, effective July 20, 2026, now explicitly discloses the use of two analytics services: Google Analytics and PostHog. The policy previously described only Google Analytics tracking. The updated policy clarifies that PostHog operates on public, logged-out pages only (marketing, blog, and documentation), stores data in the EU, does not enable session recording or capture keystrokes, and deletes analytics events after 12 months. For EU, UK, and Switzerland users, both services require explicit cookie consent with withdrawal options.
Why this matters The updated policy discloses that Fly.io uses PostHog in addition to Google Analytics on public, logged-out pages (marketing pages, blog, and documentation). PostHog stores a random identifier and pageview data in first-party cookies, with data retained for no more than 12 months. The policy states that PostHog does not track authenticated activity or link identifiers to account information. For users in the EEA, UK, or Switzerland, PostHog remains off unless you accept the cookie banner, and you can withdraw consent anytime using the 'Cookie preferences' link in the page footer.
View full change record →

Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

53 provisions
12 featured
15 clause types
16 high severity
Acceptable Use Restrictions 1 1 high
Account Control 1 1 high
Enforcement Actions 1 1 high
General Contract Terms 1 1 high
Liability Limitation 1 1 high
Monetization Rules 1
Stay ahead of the changes

Monitoring

Fly.io has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Acquiring organization must honor privacy promises and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured August 7, 2026 01:16 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000688
Version ID CA-V-005595
SHA-256 bae6d90946ef6a187b4c3311152c53d998577a5ae54645daede753a712e0f3b4
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans