Privacy policy

How Fluxer handles personal data and what we refuse to do with it. Learn about your controls and rights.

Last updated on August 12, 2026.

Effective date: 14 August 2026

The short version

Fluxer is a chat service run by Fluxer Platform AB, a Swedish company. This policy explains what personal data we handle and why, in plain language. It forms part of our terms of service, so you can hold us to it.

We do not sell, rent, or trade personal data. We have no advertising partners and no dealings with data brokers. Fluxer is paid for by the people who use it.

We run no AI or LLM inference over your messages, files, or calls, and none of your content is used to train or evaluate AI models. The only automated look at media is a small image classifier, running on our own servers, that helps respect explicit content preferences and keep flagged media away from under-18s.

Nothing on Fluxer is end-to-end encrypted yet. Your data is encrypted in transit and at rest, and end-to-end encryption for voice and video calls, covering microphone audio, camera video, and screen sharing, is in development. Sharing your screen creates a small preview thumbnail by default, so that people permitted to join the call can see what is being shared; you can turn it off when you start sharing.

We do not use tracking cookies, third-party analytics SDKs, or browser fingerprinting, and you can export your data, delete your messages, and close your account whenever you like.

Most stored account and content data is hosted in New Jersey, in the United States, where US law, including the CLOUD Act, applies. Section 6 explains that choice and what it means for you.

1. Who we are

This policy covers the official Fluxer instance, apps, APIs, and websites operated by Fluxer Platform AB. Fluxer is open source, so if you use an instance hosted by someone else, that operator is the data controller for it and publishes its own privacy notice.

For the official service, Fluxer Platform AB is the controller of your personal data under the General Data Protection Regulation, supervised in Sweden by the Swedish Authority for Privacy Protection (IMY). Our legal identity, registered address, representative, and every contact route are on our company information page.

We have not appointed a formal Data Protection Officer under GDPR Article 37 or a UK representative under UK GDPR Article 27. Both are kept under review, and this section will be updated if that changes.

2. What we process

2.1 What you give us

Creating an account needs an email address, a username, a password, and your date of birth. Profile details such as an avatar, display name, and bio are optional. Passwords are hashed with Argon2id, so even we cannot read them.

Your content is what you create and share: messages, files, images, reactions, Communities, and profile information. Calls need connection information to work, and call media is encrypted in transit (Section 9). Sharing your screen also creates a small preview thumbnail by default, so that people permitted to join the call can see what is being shared. You can turn the preview off when you start sharing.

Some registrations trigger phone verification to prevent large-scale abuse. We process the number to complete that request, and Section 7.2 explains the little that is kept afterwards.

Support messages and their attachments are handled by our support team in helpdesk software that we host on our own infrastructure, so no third-party support provider processes them. Stripe processes payments, so full card numbers never reach us. We receive only what is needed to record and manage a purchase, such as billing country, partial card details, payment status, and dates.

We do not ask for special category data such as health, religion, ethnicity, sexual orientation, or political views. If you choose to include something like that in a message or profile, we will not use it to profile you, target you, or treat you differently.

2.2 What we collect through use

Technical information covers the IP address you connect from, device and browser details, operating system, language, and similar connection data. We keep server-side request metrics, error logs, and aggregate performance measurements so the service stays reliable. They are built from request and error information, not from message or file content.

We keep aggregate, non-identifying records of which features get used and how often, such as calls started, files uploaded, and reactions used, along with screens visited, timestamps, session lengths, and crash reports. Message content is never read to produce any of this. A metric that counts messages sent counts the event and nothing more.

Security records cover login attempts, account changes, rate limit events, service errors, and signals used to spot spam, fraud, abuse, or unusual activity. We record the connecting IP address against security-relevant events such as sign-ins and file uploads, keep those records for the period in Section 7, and keep your most recent active IP address as an account security record until it is more than 90 days old.

Fluxer has no advertising trackers, no third-party analytics SDKs, no cross-site tracking pixels, and no browser fingerprinting, and we do not build behavioural profiles or track which other sites you visit.

2.3 What we receive from others

Other users create data involving you when they mention, message, add, report, or otherwise interact with you. Service providers return limited operational information, such as email or SMS delivery status, payment and fraud signals, and infrastructure alerts. Public sources occasionally supply narrow security signals, such as the reputation of an IP address. All of it is combined with what we collect directly only to run, secure, and support Fluxer.

3. How we use information

We use personal data to run accounts and communications, provide support, process payments, prevent abuse, enforce our rules, keep the service reliable, comply with the law, and protect users, the public, and Fluxer.

We do not use your content for advertising, behavioural profiling, AI training, or commercial research, and we do not sell, rent, license, or broker it.

Where the GDPR or similar law applies, our processing rests on the following grounds.

Contract necessity, under Article 6(1)(b), covers what is needed to deliver the service you signed up for: delivering messages, running Communities, managing your account, processing purchases, and providing support.

Legitimate interests, under Article 6(1)(f), cover security, fraud prevention, service reliability, limited analysis of aggregate feature use, and messages about changes to the service or these policies. Each activity has a documented assessment of its purpose, its necessity, and the balance against your rights, and none of it is used for advertising. You can object at any time, as described in Section 10.

Legal obligations, under Article 6(1)(c), cover accounting and tax duties under Swedish law, valid requests from public authorities, and compliance with data protection, security, and consumer law.

Consent, under Article 6(1)(a), covers the small set of processing that needs it, such as optional communications. You can withdraw consent at any time, and doing so does not affect earlier lawful processing.

3.2 Approximate location and network checks

We derive an approximate city, region, and country from your IP address for login alerts, session information, fraud prevention, regional age rules, sanctions compliance, and other legal duties. Where a local geolocation database on our own servers can answer the question, we use that, with no per-lookup call to any third party.

Some registration and abuse checks need network risk signals we do not hold locally, such as whether an address belongs to a VPN, a commercial proxy, or a Tor exit node. For those, IPinfo receives only the IP address, with no account identifier, session token, or device information, so the lookup cannot be tied to your Fluxer account. Results are cached on our servers so the same address is not sent again during the cache window. These signals are used only for security and abuse prevention, never for advertising, profiling, or personalisation.

Some regional access decisions are automated and rely on approximate location, because we are not willing to demand government ID uploads or biometric scans for general access. Travel, VPNs, and unusual network setups can produce the wrong outcome. If you think a restriction is wrong, use the privacy route on our company information page. We will acknowledge it promptly, have a person review it while your access stays as it is, and send you the outcome with the reasoning, and you can put your point of view at any stage. Current restrictions are listed on our regional restrictions page.

4. Who receives data

Your personal data is not sold, rented, traded, or licensed to anyone. Sharing is limited to the situations below.

4.1 Sharing you choose

Messages and files go to the people and Communities you select, your profile is visible according to your choices, and integrations you connect receive only the access you grant. The optional stream preview is visible only to people permitted to join the call. Remember that recipients can save or pass on what you share, so be deliberate about what you send and to whom.

4.2 Our service providers

A small set of providers processes data on our behalf. Each is reviewed for privacy and security before we use it, acts only on our instructions, and is bound by a data processing agreement under GDPR Article 28.

Vultr hosts the service and relays call traffic, which is encrypted in transit. Bunny.net delivers user-generated files. IPinfo supplies the network signals described in Section 3.2. Stripe processes payments, Sweego, hosted in the EU, sends transactional email, and Twilio delivers SMS verification. hCaptcha runs CAPTCHA challenges to catch automated abuse and receives your IP address to assess the challenge.

If you turn on push notifications, we send device push tokens and message, call, or event identifiers to the services that wake your device: Apple Push Notification service, Google's Firebase Cloud Messaging, or your browser vendor's push service. They never receive notification content.

Google provides YouTube embeds, and Klipy provides GIF search. Klipy never receives your IP address or device identifiers. Playing an embedded YouTube video connects your device to Google under Google's own terms and privacy policy. Error monitoring and observability run on infrastructure we control, and no application errors or crash data go to any third-party monitoring service.

We keep this list current and note material changes in our changelog. A few providers act as independent controllers when you deal with them directly, for example Google when you play a YouTube video, or hCaptcha during a challenge, and their own policies then apply alongside ours.

4.3 Law, safety, and business changes

Beyond that, personal data leaves Fluxer only to comply with a valid legal obligation, legal process, or enforceable governmental request, to enforce our terms of service and other agreements, to protect the safety, rights, or property of users, the public, or Fluxer, or to detect and deal with fraud, security, or technical issues.

Where we lawfully and safely can, we tell affected users about a legal request for their account information before we respond, and if we are barred from telling them at the time, we tell them once that restriction ends.

If Fluxer Platform AB is reorganised, acquired, or sold, personal data may transfer with it. Where legally permitted, affected users get at least 30 days' advance notice and a chance to delete their account and request deletion of their data first. Any recipient must keep honouring this policy unless you affirmatively agree to a replacement, and data will not go to any entity that refuses those protections.

5. Content safety

Fluxer runs no AI or LLM inference over your messages, files, or calls. For explicit content preferences we use OpenNSFW2, a small pretrained image classifier running on Fluxer-operated infrastructure. It is not a generative AI system or an LLM. Given an image, it returns a single probability that the image is explicit, and it cannot read text, remember, or learn. It runs on unmodified published weights with no external API call, and nothing it sees or produces enters any training pipeline. The result is used only to respect explicit content preferences and to restrict flagged media to users aged 18 or over. It does not punish accounts, and no report is filed.

Other automated protections work from narrow metadata and patterns, such as message frequency, link structure, account age, IP reputation, email domain, and client details, to spot spam, coordinated abuse, and account compromise. They do not use message bodies or file contents, and they feed no advertising or behavioural profiles.

Authorised staff may review specific stored content when needed to investigate a report, enforce policy, or respond to a credible safety issue. Access is restricted by role and recorded in an audit log, so every access is attributable and reviewable.

Where processing may create a high risk to people's rights, we carry out Data Protection Impact Assessments, as GDPR Article 35 requires. Two are complete: the explicit content classifier and the automated regional access decisions in Section 3.2. Each examines necessity and proportionality, identifies risks, and records the measures that reduce them. We revisit them when processing materially changes or on a regular schedule, whichever comes first.

6. Where data lives

Most stored account information, messages, Communities, files, and other content is hosted with Vultr in Piscataway, New Jersey. Call traffic may pass through Vultr locations worldwide so calls route near the participants, encrypted in transit through the relay. Bunny.net delivers user content through edge locations worldwide. Encrypted disaster recovery copies are kept separately, and only Fluxer holds the keys to read them.

Hosting data in the United States brings it within reach of lawful access requests under US law, including the Clarifying Lawful Overseas Use of Data Act, the CLOUD Act, under which a provider subject to US jurisdiction can be required to produce data in its possession, custody, or control even if stored elsewhere. We treat that as a real privacy issue, factor it into our transfer assessments, provider reviews, and legal request procedures, and keep looking at ways to rely less on US-hosted infrastructure. If regional hosting ships, we will explain what it changes, what it does not, and which legal regimes still apply.

Personal data may be processed outside your own country, including in the United States and Canada. Our data processing agreements include standard contractual clauses approved by the European Commission or UK authorities, kept in place even where another transfer mechanism would apply, and are backed by transfer impact assessments for each destination, encryption in transit and at rest, access controls, audit logging, and contractual limits on provider use. These measures reduce risk, but for data that our servers must be able to process to run Fluxer, they cannot make lawful access impossible. Your data is never transferred to any third party for that party's own advertising or marketing.

7. Retention

We keep personal data only as long as it is needed for the purposes in this policy, legal obligations, disputes, and enforcement. Data that is no longer needed is deleted or anonymised.

7.1 Active accounts and content

Account information, messages, Communities, and other content are kept while your active account needs them. Attachments may expire based on factors such as size, age, and use, and items in Saved Media are not subject to ordinary expiry. Details are in the attachment expiry guide. Optional stream previews stay available for at most 24 hours after the latest upload, and only to people permitted to join the call.

7.2 Phone verification

Phone numbers used for verification are not stored on your account. After a successful verification, the account records only that verification happened.

To stop the same number being reused across suspicious registrations, we keep an encrypted reuse record for about a month. It contains neither the phone number nor any account reference, and it exists only to let a number verify at most twice in that period. It is never used for SMS two-factor authentication, recovery, advertising, profiling, contact discovery, or linking accounts, and its encryption key is rotated roughly every 30 days so old records expire naturally.

7.3 Deletion

Deleted messages and account data normally leave active use within minutes. Encrypted disaster recovery copies may hold them for up to 30 days, without any active processing, until scheduled deletion. Deleted media normally leaves active use within hours, though a hidden copy of each deleted attachment may be kept for up to 24 hours before final erasure, invisible to users and restorable only by authorised operators in a genuine disaster recovery situation. Deleted media is not included in longer-term backups, and CDN-cached copies are purged as soon as possible after deletion, though rate limits and global propagation can add short delays. An erasure request under GDPR Article 17 is complete once the data has left active systems and backup cycles. Longer retention applies only where the law requires it, for example tax records.

Deleting a Community or channel starts a 14-day grace period. During it, the Community or channel and all its contents (messages, attachments, roles, settings, and other associated data) are hidden from users and inaccessible through the app, API, media proxy, search, data exports, and bulk-deletion operations, but remain in our systems so that accidental or unauthorised deletions can be recovered. Only authorised staff can view and restore it during the window, and you can ask support for a restoration. After 14 days it is permanently deleted through the procedures above and cannot be restored.

Accounts may be scheduled for deletion after 2 years of inactivity, with advance notice to the registered email address. Messages you previously shared with others may stay visible unless you delete them first or choose message deletion when closing your account. The account deletion guide has the details.

7.4 Other retention periods

Payment and transaction records are kept for at least seven years, as Swedish bookkeeping law (Bokföringslag 1999:1078) requires, and longer only where needed for legal compliance, disputes, or fraud prevention. Full card numbers are never stored.

Security and usage logs are kept for up to 90 days in normal conditions, then deleted or anonymised. Specific records may be kept longer only for an active security investigation, a binding legal obligation, or an ongoing dispute, and are deleted once that reason ends. Administrative audit records of enforcement decisions and account changes are kept as long as accountability, appeals, disputes, and legal compliance require, and are reviewed periodically.

When content is reported, we may preserve a snapshot of the reported item, relevant surrounding context, attachments, and report details, even if the original is later deleted, so that investigation and appeal remain possible. Snapshots are stored separately from ordinary user content, are never served to users, indexed, or exported, and are readable only by authorised staff, with every access recorded. They are deleted after at most 1 year, unless a binding legal obligation requires specific material to be kept longer.

Content removed or disabled under a valid order under Regulation (EU) 2021/784 on terrorist content, and related data, is preserved for six months, or longer where applicable law requires. Generated self-service export files are kept for up to 7 days.

8. Your controls

The Privacy Dashboard in your settings lets you request an export, delete messages, and schedule account deletion. An export is a ZIP archive of machine-readable JSON covering account, message, payment, relationship, session, security, preference, and profile information, with download links for attachments that are still available. Content in a deletion grace period is excluded (Section 7.3). Download anything you want to keep before deleting it or letting it expire.

Deleting a message also deletes its attachments. Bulk message deletion runs in the background, can take a while for large accounts, and skips content in a deletion grace period. Scheduled account deletion can be cancelled by signing back in during its grace period. Current instructions are in our data export, data deletion, and account deletion guides.

For anything you cannot do in the app, use the privacy route on our company information page, writing from the email address on your account where possible. We may ask for the information needed to verify your identity.

9. Security

Technical and organisational measures protect your personal data against accidental or unlawful destruction, loss, alteration, disclosure, and unauthorised access. They include encryption in transit and at rest, access controls, security monitoring, physically secure data centres, patching and hardening, rate limiting, encrypted backups, and audit logging of access to user data.

Nothing on Fluxer is currently end-to-end encrypted. Your data is encrypted in transit between your device and our servers and at rest on our servers and backups, but because the service relies on server-side processing to function, message content and call media are technically accessible to our systems while being handled. In plain terms, you are trusting Fluxer and our hosting providers to protect that traffic.

End-to-end encryption for voice and video calls is in development, designed to cover microphone audio, camera video, and screen sharing with its audio, and to leave the keys with the participants alone. Optional end-to-end encryption is also planned for supported text areas, starting with Personal Notes, direct messages, and group DMs. Until a feature like that launches and applies to your call or content, nothing on Fluxer is end-to-end encrypted, and we will announce it when it ships. Security vulnerabilities can be reported through our security page.

If a personal data breach happens, we investigate and take remedial steps. As GDPR Articles 33 and 34 require, we notify IMY within 72 hours of becoming aware of a breach, unless it is unlikely to risk people's rights and freedoms, explaining the reasons for any delay, and we notify affected users without undue delay where the risk to them is high. Notifications explain what happened, what data is likely affected, the probable consequences, and what you can do to protect yourself.

10. Your rights

Depending on where you live, you may have the right to access your personal data and receive a copy of it, to correct data that is inaccurate or incomplete, to erasure, to restrict processing in certain situations, to object to processing based on legitimate interests, to data portability in a structured, commonly used, machine-readable format, to withdraw consent at any time without affecting earlier lawful processing, and, for automated decisions that significantly affect you, to human review, to put your point of view, and to contest the decision. If you object to legitimate-interest processing, it stops unless compelling legitimate grounds override your interests, rights, and freedoms, or the processing is needed for legal claims.

You can exercise these rights through your account controls or the privacy route on our company information page. We may need to verify your identity, and an authorised agent can act for you where the law permits. We respond within the period applicable law requires, usually within 30 days, or up to 45 where permitted. If we cannot fully comply, for example because of a legal obligation or another person's rights, we explain why and what options remain.

You can also complain to your data protection authority. In Sweden that is the Swedish Authority for Privacy Protection at imy.se, and in the UK the Information Commissioner's Office at ico.org.uk. The authority where you live is always an option too, and you are welcome to raise the issue with us first so we can try to fix it directly.

11. Children and age requirements

You must meet the minimum age for your country, generally 13 and higher in some places, as listed in our minimum age guide. Where required, a parent or guardian must agree to our terms for a user who has reached the minimum age but is not yet legally an adult.

Younger users may get stricter privacy and safety defaults and limits on age-restricted features. Because nobody on Fluxer is profiled for advertising, minors are not either. We do not use government ID uploads or biometric scans for general access, and where a legal framework demands methods we do not support, access is restricted as described in Section 3.2 and on the regional restrictions page.

We do not knowingly collect personal information from children below the minimum age for their region, which in the United States means children under 13, in line with COPPA. If such information reaches us, we delete it and, where appropriate, the account. A parent or guardian can use the privacy route on our company information page, and we may ask for proof of guardianship.

12. Cookies and browser storage

The Fluxer app sets no first-party cookies. Authentication and recent identity checks use request and response headers instead. Our marketing site sets one strictly necessary cookie, fluxer-locale, which remembers your language preference for 1 year. Strictly necessary cookies need no consent under the ePrivacy rules, and if we ever introduce a non-essential cookie we will update this section and ask for consent before setting it.

The app uses your browser's local storage for account switching, interface state, and preferences. Some preferences sync to your account so they follow you between devices, and everything else stays on your device.

The CAPTCHA provider and embedded YouTube content may set their own cookies when you interact with them, under hCaptcha's privacy policy and Google's privacy policy.

We honour Global Privacy Control, though since Fluxer does not sell or share personal information for advertising it changes nothing in practice. Do Not Track signals are not treated differently, because Fluxer already does not track anyone across other sites.

GIF searches go to Klipy through our servers, so Klipy never sees your IP address or device identifiers. When a message contains a link, Fluxer may fetch the linked site from our servers to build a preview, so the site sees a request from Fluxer, not from your device. Those requests carry a User-Agent containing Fluxerbot, and a site operator can block them, which stops previews and embedded media for that site appearing in Fluxer.

YouTube previews are fetched server-side, so your device does not contact YouTube until you press play. Playing an embedded video connects your device to Google, which may then process information under its own privacy policy, and other embedded content behaves the same way when you interact with it.

Every request for user information gets careful review, with the privacy and security of the people involved as the primary consideration, and we narrow or reject requests that are invalid or overbroad. Authorities should use the legal route on our company information page and identify the requesting authority, the legal basis, and the specific information sought. Where we lawfully and safely can, we notify affected users before disclosure so they can object. In a genuine emergency, disclosure may happen without prior notice where reasonably necessary to prevent serious harm.

For call-related requests, connection information, and the stream preview where one exists, may be available as this policy describes.

15. Changes to this policy

We may update this policy as our service, practices, or legal duties change. Every update is recorded in our changelog, and the effective date at the top is updated.

A change is material when it is adverse to you. That means it reduces your rights or protections, expands what we collect or how long we keep it, adds recipients or uses in ways that increase risk to you, or otherwise leaves you worse off than under the previous version. Material changes take effect no earlier than 30 days after we notify you by email, in the app, or both, so that before they apply you can review them, export your data, delete your messages, or delete your account using the tools in Section 8. A change may take effect sooner only where the law requires it or it is urgently needed for security, and we then notify you as soon as we reasonably can and explain why. Where it is genuinely unclear whether a change is adverse, we treat it as material.

Changes that are neutral or in your favour, such as new protections, stronger encryption, or clearer descriptions of existing practice, take effect when published. Where such a change is significant, we tell you about it in the app or by email rather than relying on the changelog alone.

16. Contact

All privacy, support, legal, postal, and telephone contact routes are on our company information page. For account-related requests, write from the email address on your account where possible, because it makes verifying your identity easier and protects the account.

17. California disclosures

This section adds the disclosures the California Consumer Privacy Act requires and applies only to California residents, alongside the rest of this policy.

The personal information we collect falls into these categories. Identifiers means username, email address, user ID, IP address, and device identifiers, which come from you, from automatic collection, and from service providers. Customer records under Cal. Civ. Code § 1798.80(e) means billing country and partial card details, which come from you and Stripe. Internet or network activity means pages visited, features used, session timestamps, and browser and operating system details, from automatic collection. Geolocation means the approximate city, region, and country derived from your IP address, from automatic collection. Audio, electronic, or visual information means uploaded files, screen share previews, and call traffic, which come from you. Inferences means regional eligibility results and spam or abuse risk signals, from automatic collection. We collect no biometric, employment, or education information.

The only sensitive personal information we collect is your account log-in credentials, meaning an email address with a password, used to run and secure the service. California law also treats the personal information of consumers under 16 as sensitive, and we use it only to provide and secure the service, never for advertising or unrelated profiling.

We disclose identifiers, payment records, network and location information, push tokens, call traffic, previews, and uploaded files to the providers named in Section 4, for hosting, delivery, payments, communications, push notifications, bot prevention, and security. Payment records go to Stripe, and network and location signals go to IPinfo under the conditions in Section 3.2. Call traffic is encrypted in transit through the relaying providers.

We do not sell personal information and do not share it for cross-context behavioural advertising. That applies to everyone, including users under 16.

California residents can request access, deletion, or correction, can limit the use and disclosure of sensitive personal information, can opt out of sale or advertising sharing, neither of which happens, and can act through an authorised agent where the law permits, all without being discriminated against for it. Requests go through your account controls or the privacy route on our company information page. Retention follows Section 7, and Global Privacy Control is honoured as described in Section 12.