Legal
Privacy Policy
FluxSend is a self-hostable file storage, sharing, and transfer platform. This Privacy Policy explains what personal data we collect when you use the Service, why we collect it, how we share and protect it, and the rights you have over it.
Please read it together with our Terms of Service. By creating an account or using the Service, you acknowledge this policy.
1. Who we are
FluxSend is a self-hostable file storage, sharing, and transfer platform. For the FluxSend instance we operate, the entity below is the data controller for personal data processed through the Service, within the meaning of the EU General Data Protection Regulation (GDPR).
| Operator | Orion Software Tomasz Skrond |
|---|---|
| Country | Poland |
| NIP | 5482778053 |
| Registered address | Józefa Madzi 3 43-438 Brenna |
| Contact email | contact@fluxsend.app |
For privacy questions, data subject requests, or complaints, contact us at contact@fluxsend.app.
FluxSend can be self-hosted. If you use an instance operated by someone other than us — for example, an instance run by your employer, another administrator, or yourself — then that operator is the data controller for the data in that instance. This policy describes how the FluxSend software and a typical deployment handle personal data, but it is the operator of your instance who is responsible for it. To exercise your rights on a self-hosted instance, contact that instance's administrator.
2. Scope
This policy applies to personal data processed when you:
- use the FluxSend web application;
- use the FluxSend API, including requests made with an API key or the CLI;
- receive emails or other communications we send you (for example account verification, password reset, or share notifications).
It does not apply to third-party websites or services we link to, or to services you connect to a self-hosted deployment. Those are governed by their own privacy notices.
3. What we collect
We collect only the personal data we need to provide the Service.
3.1 Account and authentication data
When you create an account or sign in, we process:
- Email address — used for authentication, transactional email, account recovery, and to deliver files that other users share with you.
- Display name — shown in the app next to your shares and workspace membership.
- Password — stored only as a cryptographic hash (Argon2id). We never store or log your plain-text password. Password auth is optional and may be disabled on some instances.
- Linked sign-in identities — if you sign in with Google or GitHub, the provider name, provider user ID, email address, display name, avatar URL, and the scopes you granted. We use these only to authenticate you.
- Email verification status — whether your email address has been confirmed.
- One-time verification codes — for registration, password reset, and similar flows. Codes are stored only as a hash, expire quickly, are limited in the number of attempts, and are deleted once used.
- Account metadata — such as your plan tier and account creation date.
3.2 Session and technical data
When you sign in and use the Service, we process:
- Session data — a session identifier and an authentication cookie, the session expiry, and (for OAuth-linked sessions) the provider access token used to keep you signed in.
- IP address and user agent — recorded with authentication challenges and rate-limit records to protect sessions and prevent brute-force and abuse.
- Request logs — basic technical records used to operate and secure the Service.
3.3 Files, shares, and workspace data
To store, organise, preview, and share files, we process:
- File and folder metadata — file name, type, size, checksum, folder structure, and the storage bucket or object key the file lives in.
- File notes — any note you attach to a file.
- Share records — who you shared a file with, the sharing token, and its creation and expiry times, plus quick-share links and their download activity counters.
- Received-files state — which files have been shared with you and whether you have read them.
- Workspace data — workspace name, slug, members, roles, and pending invitations.
- API key data — the key name, description, a hash of the key, its scopes, status, and last used time. The plain-text key is shown once and never stored.
The contents of your files are stored in the object storage backend configured for your instance (see section 5). Files are private by default: they are only accessible to you, and to recipients you explicitly share them with, or through download links you create.
3.4 Usage and quota data
We keep counters and aggregates that make the Service work — such as storage used, number of files, daily upload and share counts, your plan tier, and the analytics shown in the app. These are used to enforce plan limits and to give you visibility into your own usage.
3.5 Communications
If you contact us, we process your email address and the content of your message in order to respond. We also keep delivery and notification metadata for the transactional emails we send.
FluxSend does not include a payment processor, and we do not collect or store payment card details. Plan tiers on an instance are assigned by that instance's administrator.
4. Why we use your data, and our legal bases
Under the GDPR (Article 6), we rely on the following legal bases:
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and manage your account, authenticate you, and let you upload, organise, preview, and share files | Account, session, file, share, and workspace data | Performance of a contract — Art. 6(1)(b) |
| Send transactional emails (account verification, password reset, share notifications) | Email address and verification data | Performance of a contract — Art. 6(1)(b) |
| Enforce plan limits and quotas | Usage and quota data | Performance of a contract — Art. 6(1)(b) |
| Keep the Service secure — detect fraud, prevent brute-force and abuse, and protect sessions | IP address, user agent, session and rate-limit records | Legitimate interests — Art. 6(1)(f) |
| Operate, monitor, and improve the Service — diagnose errors and maintain request logs | Request logs, error data, and usage data | Legitimate interests — Art. 6(1)(f) |
| Comply with legal obligations and respond to lawful requests | Data required by the relevant obligation | Legal obligation — Art. 6(1)(c) |
| Establish, exercise, or defend legal claims | Records relevant to the claim | Legitimate interests — Art. 6(1)(f) |
We do not use your personal data for advertising or profiling, we do not sell it, and we do not make decisions about you by automated means that produce legal or similarly significant effects.
5. Sharing and sub-processors
We do not sell your data. We share it only with the service providers we need to run the Service, and only to the extent necessary. Each provider listed below acts as a data processor under a contract with us.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Google LLC | Sign in with Google (OAuth); Google Cloud Storage when configured as the storage backend | Name, email, avatar, provider user ID; stored files and metadata | USA / configured region |
| GitHub, Inc. | Sign in with GitHub (OAuth) | Name, email, avatar, provider user ID | USA |
| Amazon Web Services (S3, SES, CloudFront) | Object storage, transactional email, and CDN delivery when configured | File contents and metadata; recipient email and message content; download requests | Configured AWS region |
| Self-hosted MinIO | Object storage when configured | File contents and metadata | Operator's own infrastructure |
| Managed PostgreSQL provider | Application database hosting | Account, file metadata, share, workspace, and API-key records | Configured region |
| SMTP / email provider | Delivery of transactional emails | Recipient email address and email content | Provider-dependent |
The exact list of providers depends on how your instance is configured. Because FluxSend is self-hostable, a self-hosted operator may use entirely different providers, and it is that operator's responsibility to disclose them to you.
International transfers
Some of the providers above are based in the United States. Where personal data is transferred from the European Economic Area (EEA) to those providers, the transfer is protected by appropriate safeguards, such as the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or an EU adequacy decision. You can request a copy of the applicable safeguards by contacting us at contact@fluxsend.app.
6. How long we keep your data
| Data category | Retention period |
|---|---|
| Account data (email, display name, password hash, linked identities) | For the lifetime of your account; deleted within 30 days of account closure |
| Session records and authentication cookie | Until the session expires or you sign out |
| One-time verification codes | Minutes; deleted immediately once used or expired |
| File metadata and stored files | Until you delete them or close your account; deleted within 30 days of account closure |
| Share records and quick-share links | Until they expire or are revoked, or until your account is closed |
| Workspace data | For the lifetime of the workspace; deleted with the workspace or account |
| API keys | Until revoked or deleted, or until your account is closed |
| Application and request logs | A short period (typically up to 30 days), unless retained longer for a security investigation |
| Backups | Up to the retention window of your configured storage or database provider |
| Records we must keep by law | For as long as the applicable law requires |
After the applicable retention period, data is deleted or irreversibly anonymised.
7. Your rights under the GDPR
If you are in the EEA, the United Kingdom, or Switzerland, you have the following rights:
- Access (Art. 15) — request a copy of the personal data we hold about you.
- Rectification (Art. 16) — ask us to correct inaccurate data.
- Erasure (Art. 17) — ask us to delete your personal data. See section 8 for how to delete your account.
- Restriction (Art. 18) — ask us to pause processing while a dispute is resolved.
- Data portability (Art. 20) — receive your data in a machine-readable format.
- Objection (Art. 21) — object to processing based on our legitimate interests.
- Withdraw consent — where we rely on consent, you may withdraw it at any time without affecting processing carried out before the withdrawal.
To exercise any of these rights, email us at contact@fluxsend.win with the subject line "Data Subject Request". We will respond within 30 days and may ask you to verify your identity first. If you use a self-hosted instance, send your request to that instance's operator.
If you are not satisfied with our response, you may lodge a complaint with the Polish supervisory authority:
- Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, Poland
- uodo.gov.pl
8. Account deletion
You can delete your account at any time from the Settings page in the app. When you do, you can choose whether to also delete the files you have uploaded. Deleting your account removes your account details, linked identities, password credentials, active sessions, API keys, and share records.
Deleting your account does not delete files that other users have shared with you — those remain with the sender. It also does not delete data that we are required to retain for legal, tax, or security reasons, and we may keep limited records where necessary to resolve disputes or prevent abuse.
If you cannot access Settings, or you use a self-hosted instance, contact the instance administrator to request deletion. On the instance we operate, you can also email contact@fluxsend.win.
9. Children's privacy
The Service is not directed to children. You must be at least 16 years old to create an account, which reflects the age of digital consent in Poland under the GDPR (Article 8). We do not knowingly collect personal data from anyone below that age. If you believe a child has created an account without appropriate consent, contact us at contact@fluxsend.win and we will delete the account promptly.
10. Cookies and local storage
| Technology | Where used | Purpose |
|---|---|---|
| Session cookie | Web app | Keeps you signed in; set by FluxSend, expiring when your session ends |
Local storage (theme-mode) |
Web app | Remembers your light or dark theme choice on your device |
We do not use advertising cookies, analytics cookies, or cross-site tracking technologies, so a cookie consent banner is not required for the Service. Necessary cookies are used only to operate the Service.
11. Security
We apply the following technical and organisational measures:
- Passwords are hashed with Argon2id; plain-text passwords are never stored or logged.
- Data in transit is encrypted with TLS.
- API keys, verification codes, and sharing tokens are stored as hashes, and download links are signed and short-lived.
- Files are private by default and shared only through explicit, revocable shares or links.
- Authentication endpoints are rate-limited, and verification codes are attempt-limited.
- Access to production infrastructure and databases is restricted to authorised personnel.
No system is perfectly secure. If a personal data breach poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Articles 33 and 34.
12. Changes to this policy
We may update this policy from time to time. For material changes — those that significantly affect your rights or how we use your data — we will notify you by email at least 30 days before the change takes effect and show a notice in the app. The updated policy will be published at this URL with a new "Last updated" date. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact
- Email: contact@fluxsend.win
- Subject line: Privacy Inquiry for general questions, or Data Subject Request for rights requests.