The policy states that if users store sensitive personal information (such as health data, racial or ethnic origin, or political opinions) in their Fly.io applications or account, the act of storage constitutes consent to Fly.io storing that information on U.S. servers.
This analysis describes what Fly.io's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision asserts that storage of sensitive personal information by a user constitutes consent to processing in the United States. This implied consent mechanism may require evaluation under GDPR Article 9 (which governs processing of special category data and requires explicit consent) and applicable data localization or transfer restrictions in specific jurisdictions.
Interpretive note: Whether the act-of-storage consent mechanism satisfies GDPR Article 9 explicit consent requirements is legally uncertain and may depend on supervisory authority interpretation in specific EU member states.
The updated policy now explicitly discloses that Fly.io uses third-party fraud-prevention services that collect device and browser signals (such as device identifiers and browser fingerprints) when you create an account or sign in. The policy states this data collection is mandatory and cannot be opted out of, distinguishing it from analytics collection, which remains optional. The company asserts its legal basis is its legitimate interest in protecting the platform and its users.
View change record →Under this clause, users who store sensitive personal information in Fly.io-hosted applications are deemed to have consented to that data being stored on Fly.io's U.S. servers. The agreement does not provide a mechanism for users to restrict or remove sensitive data separately from full account deletion.
Cross-platform context
See how other platforms handle User Sensitive Information Storage Consent and similar clauses.
Compare across platforms →"Although fly.io does not request or intentionally collect any sensitive personal information, we realize that you might store this kind of information in your account, such as in an application. If you store any sensitive personal information on our servers, you are consenting to our storage of that information on our servers, which are in the United States.Excerpt from Fly.io's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Article 9 (processing of special categories of personal data), which requires explicit consent or another specified legal basis for processing sensitive data including health information, racial or ethnic …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision asserts that storage of sensitive personal information by a user constitutes consent to processing in the United States. This implied consent mechanism may require evaluation under GDPR Article 9 (which governs processing of special category data and requires explicit consent) and applicable data localization or transfer restrictions in specific jurisdictions.
Under this clause, users who store sensitive personal information in Fly.io-hosted applications are deemed to have consented to that data being stored on Fly.io's U.S. servers. The agreement does not provide a mechanism for users to restrict or remove sensitive data separately from full account deletion.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Fly.io.