The policy states that Fly.io does not automatically delete inactive accounts and will retain associated User Personal Information indefinitely unless the user takes affirmative action to delete the account or requests deletion.
This analysis describes what Fly.io's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision requires users to take affirmative action to trigger data deletion; absent that action, the agreement asserts Fly.io retains account data without a defined expiration period. This default retention posture may require evaluation under GDPR storage limitation principles and CCPA deletion rights obligations for affected data subjects.
The updated policy now explicitly discloses that Fly.io uses third-party fraud-prevention services that collect device and browser signals (such as device identifiers and browser fingerprints) when you create an account or sign in. The policy states this data collection is mandatory and cannot be opted out of, distinguishing it from analytics collection, which remains optional. The company asserts its legal basis is its legitimate interest in protecting the platform and its users.
View change record →Under this clause, User Personal Information associated with inactive accounts is retained indefinitely unless the user logs in and initiates account deletion through the dashboard or contacts support. The agreement states that full profile deletion occurs within 30 days following a deletion request, subject to legal retention obligations.
Cross-platform context
See how other platforms handle Indefinite Data Retention for Inactive Accounts and similar clauses.
Compare across platforms →"We may retain certain User Personal Information indefinitely, unless you delete it or request its deletion. For example, we don't automatically delete inactive user accounts, so unless you choose to delete your account, we will retain your account information indefinitely.Excerpt from Fly.io's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR Article 5(1)(e) (storage limitation principle), which requires personal data to be kept no longer than necessary for the specified purpose.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision requires users to take affirmative action to trigger data deletion; absent that action, the agreement asserts Fly.io retains account data without a defined expiration period. This default retention posture may require evaluation under GDPR storage limitation principles and CCPA deletion rights obligations for affected data subjects.
Under this clause, User Personal Information associated with inactive accounts is retained indefinitely unless the user logs in and initiates account deletion through the dashboard or contacts support. The agreement states that full profile deletion occurs within 30 days following a deletion request, subject to legal retention obligations.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Fly.io.