Provision record
Fly.io · Fly.io Privacy Policy · View original document ↗

User Sensitive Information Storage Consent

Medium severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Fly.io and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy states that if users store sensitive personal information (such as health data, racial or ethnic origin, or political opinions) in their Fly.io applications or account, the act of storage constitutes consent to Fly.io storing that information on U.S. servers.

This analysis describes what Fly.io's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision asserts that storage of sensitive personal information by a user constitutes consent to processing in the United States. This implied consent mechanism may require evaluation under GDPR Article 9 (which governs processing of special category data and requires explicit consent) and applicable data localization or transfer restrictions in specific jurisdictions.

Interpretive note: Whether the act-of-storage consent mechanism satisfies GDPR Article 9 explicit consent requirements is legally uncertain and may depend on supervisory authority interpretation in specific EU member states.

Recent Activity

This document changed recently

Medium Aug 7, 2026

The updated policy now explicitly discloses that Fly.io uses third-party fraud-prevention services that collect device and browser signals (such as device identifiers and browser fingerprints) when you create an account or sign in. The policy states this data collection is mandatory and cannot be opted out of, distinguishing it from analytics collection, which remains optional. The company asserts its legal basis is its legitimate interest in protecting the platform and its users.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, users who store sensitive personal information in Fly.io-hosted applications are deemed to have consented to that data being stored on Fly.io's U.S. servers. The agreement does not provide a mechanism for users to restrict or remove sensitive data separately from full account deletion.

Cross-platform context

See how other platforms handle User Sensitive Information Storage Consent and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Although fly.io does not request or intentionally collect any sensitive personal information, we realize that you might store this kind of information in your account, such as in an application. If you store any sensitive personal information on our servers, you are consenting to our storage of that information on our servers, which are in the United States.

Excerpt from Fly.io's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages GDPR Article 9 (processing of special categories of personal data), which requires explicit consent or another specified legal basis for processing sensitive data including health information, racial or ethnic …

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • Department Of Health & Human Services, Office For Civil Rights (hhs Ocr)
    Enforces HIPAA Privacy and Security Rules, which protect health information held by healthcare providers, health plans, and their business associates.
    Who can file: Anyone whose HIPAA rights may have been violated by a covered entity (healthcare provider, health plan, or healthcare clearinghouse)
    What you need: Name of the entity, description of the violation, date of the incident, and your contact information. Must file within 180 days of the violation.
    What to expect: HHS OCR investigates and may require the entity to take corrective action. Does not provide individual compensation. Serious violations can result in civil monetary penalties.
    File a complaint →

Provision details

Document information
Document
Fly.io Privacy Policy
Entity
Fly.io
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
July 9, 2026
Record ID
CA-P-016169
Document ID
CA-D-00688
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7b088457a7650aebc6c3d2148a9feb8df76a3839f92e7594fa35251c10c942a0
Analysis generated
May 7, 2026 18:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Fly.io
Document: Fly.io Privacy Policy
Record ID: CA-P-016169
Captured: 2026-05-07 18:51:54 UTC
SHA-256: 7b088457a7650aeb…
URL: https://conductatlas.com/platform/flyio/flyio-privacy-policy/provision/CA-P-016169/user-sensitive-information-storage-consent/
Accessed: Aug. 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Fly.io's User Sensitive Information Storage Consent clause do?

This provision asserts that storage of sensitive personal information by a user constitutes consent to processing in the United States. This implied consent mechanism may require evaluation under GDPR Article 9 (which governs processing of special category data and requires explicit consent) and applicable data localization or transfer restrictions in specific jurisdictions.

How does this clause affect you?

Under this clause, users who store sensitive personal information in Fly.io-hosted applications are deemed to have consented to that data being stored on Fly.io's U.S. servers. The agreement does not provide a mechanism for users to restrict or remove sensitive data separately from full account deletion.

Is ConductAtlas affiliated with Fly.io?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Fly.io.