Legal

Privacy Policy

Last updated: 4 October 2026

FluxSend is a self-hostable file storage, sharing, and transfer platform. This Privacy Policy explains what personal data we collect when you use the Service, why we collect it, how we share and protect it, and the rights you have over it.

1. Who we are

FluxSend is a self-hostable file storage, sharing, and transfer platform. For the FluxSend instance we operate, the entity below is the data controller for personal data processed through the Service, within the meaning of the EU General Data Protection Regulation (GDPR).

Operator Orion Software Tomasz Skrond
Country Poland
NIP 5482778053
Registered address Józefa Madzi 3 43-438 Brenna
Contact email contact@fluxsend.app

For privacy questions, data subject requests, or complaints, contact us at contact@fluxsend.app.

Using a self-hosted instance?

FluxSend can be self-hosted. If you use an instance operated by someone other than us — for example, an instance run by your employer, another administrator, or yourself — then that operator is the data controller for the data in that instance. This policy describes how the FluxSend software and a typical deployment handle personal data, but it is the operator of your instance who is responsible for it. To exercise your rights on a self-hosted instance, contact that instance's administrator.

2. Scope

This policy applies to personal data processed when you:

It does not apply to third-party websites or services we link to, or to services you connect to a self-hosted deployment. Those are governed by their own privacy notices.

3. What we collect

We collect only the personal data we need to provide the Service.

3.1 Account and authentication data

When you create an account or sign in, we process:

3.2 Session and technical data

When you sign in and use the Service, we process:

3.3 Files, shares, and workspace data

To store, organise, preview, and share files, we process:

Your file contents

The contents of your files are stored in the object storage backend configured for your instance (see section 5). Files are private by default: they are only accessible to you, and to recipients you explicitly share them with, or through download links you create.

3.4 Usage and quota data

We keep counters and aggregates that make the Service work — such as storage used, number of files, daily upload and share counts, your plan tier, and the analytics shown in the app. These are used to enforce plan limits and to give you visibility into your own usage.

3.5 Communications

If you contact us, we process your email address and the content of your message in order to respond. We also keep delivery and notification metadata for the transactional emails we send.

No payment data

FluxSend does not include a payment processor, and we do not collect or store payment card details. Plan tiers on an instance are assigned by that instance's administrator.

4. Why we use your data, and our legal bases

Under the GDPR (Article 6), we rely on the following legal bases:

Purpose Data used Legal basis
Create and manage your account, authenticate you, and let you upload, organise, preview, and share files Account, session, file, share, and workspace data Performance of a contract — Art. 6(1)(b)
Send transactional emails (account verification, password reset, share notifications) Email address and verification data Performance of a contract — Art. 6(1)(b)
Enforce plan limits and quotas Usage and quota data Performance of a contract — Art. 6(1)(b)
Keep the Service secure — detect fraud, prevent brute-force and abuse, and protect sessions IP address, user agent, session and rate-limit records Legitimate interests — Art. 6(1)(f)
Operate, monitor, and improve the Service — diagnose errors and maintain request logs Request logs, error data, and usage data Legitimate interests — Art. 6(1)(f)
Comply with legal obligations and respond to lawful requests Data required by the relevant obligation Legal obligation — Art. 6(1)(c)
Establish, exercise, or defend legal claims Records relevant to the claim Legitimate interests — Art. 6(1)(f)

We do not use your personal data for advertising or profiling, we do not sell it, and we do not make decisions about you by automated means that produce legal or similarly significant effects.

5. Sharing and sub-processors

We do not sell your data. We share it only with the service providers we need to run the Service, and only to the extent necessary. Each provider listed below acts as a data processor under a contract with us.

Provider Purpose Data involved Location
Google LLC Sign in with Google (OAuth); Google Cloud Storage when configured as the storage backend Name, email, avatar, provider user ID; stored files and metadata USA / configured region
GitHub, Inc. Sign in with GitHub (OAuth) Name, email, avatar, provider user ID USA
Amazon Web Services (S3, SES, CloudFront) Object storage, transactional email, and CDN delivery when configured File contents and metadata; recipient email and message content; download requests Configured AWS region
Self-hosted MinIO Object storage when configured File contents and metadata Operator's own infrastructure
Managed PostgreSQL provider Application database hosting Account, file metadata, share, workspace, and API-key records Configured region
SMTP / email provider Delivery of transactional emails Recipient email address and email content Provider-dependent

The exact list of providers depends on how your instance is configured. Because FluxSend is self-hostable, a self-hosted operator may use entirely different providers, and it is that operator's responsibility to disclose them to you.

International transfers

Some of the providers above are based in the United States. Where personal data is transferred from the European Economic Area (EEA) to those providers, the transfer is protected by appropriate safeguards, such as the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or an EU adequacy decision. You can request a copy of the applicable safeguards by contacting us at contact@fluxsend.app.

6. How long we keep your data

Data category Retention period
Account data (email, display name, password hash, linked identities) For the lifetime of your account; deleted within 30 days of account closure
Session records and authentication cookie Until the session expires or you sign out
One-time verification codes Minutes; deleted immediately once used or expired
File metadata and stored files Until you delete them or close your account; deleted within 30 days of account closure
Share records and quick-share links Until they expire or are revoked, or until your account is closed
Workspace data For the lifetime of the workspace; deleted with the workspace or account
API keys Until revoked or deleted, or until your account is closed
Application and request logs A short period (typically up to 30 days), unless retained longer for a security investigation
Backups Up to the retention window of your configured storage or database provider
Records we must keep by law For as long as the applicable law requires

After the applicable retention period, data is deleted or irreversibly anonymised.

7. Your rights under the GDPR

If you are in the EEA, the United Kingdom, or Switzerland, you have the following rights:

To exercise any of these rights, email us at contact@fluxsend.win with the subject line "Data Subject Request". We will respond within 30 days and may ask you to verify your identity first. If you use a self-hosted instance, send your request to that instance's operator.

If you are not satisfied with our response, you may lodge a complaint with the Polish supervisory authority:

8. Account deletion

You can delete your account at any time from the Settings page in the app. When you do, you can choose whether to also delete the files you have uploaded. Deleting your account removes your account details, linked identities, password credentials, active sessions, API keys, and share records.

Deleting your account does not delete files that other users have shared with you — those remain with the sender. It also does not delete data that we are required to retain for legal, tax, or security reasons, and we may keep limited records where necessary to resolve disputes or prevent abuse.

If you cannot access Settings, or you use a self-hosted instance, contact the instance administrator to request deletion. On the instance we operate, you can also email contact@fluxsend.win.

9. Children's privacy

The Service is not directed to children. You must be at least 16 years old to create an account, which reflects the age of digital consent in Poland under the GDPR (Article 8). We do not knowingly collect personal data from anyone below that age. If you believe a child has created an account without appropriate consent, contact us at contact@fluxsend.win and we will delete the account promptly.

10. Cookies and local storage

Technology Where used Purpose
Session cookie Web app Keeps you signed in; set by FluxSend, expiring when your session ends
Local storage (theme-mode) Web app Remembers your light or dark theme choice on your device

We do not use advertising cookies, analytics cookies, or cross-site tracking technologies, so a cookie consent banner is not required for the Service. Necessary cookies are used only to operate the Service.

11. Security

We apply the following technical and organisational measures:

No system is perfectly secure. If a personal data breach poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Articles 33 and 34.

12. Changes to this policy

We may update this policy from time to time. For material changes — those that significantly affect your rights or how we use your data — we will notify you by email at least 30 days before the change takes effect and show a notice in the app. The updated policy will be published at this URL with a new "Last updated" date. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact