fluxer.app — 88/100 (Niskie ryzyko prywatności)
Ostatnia analiza
Fluxer Platform AB · fluxer.app
Szczegóły raportu
Niskie ryzyko prywatnościFluxer (Fluxer Platform AB) to wysoce dbający o prywatność serwis do przesyłania wiadomości, który minimalizuje zbieranie danych, unika reklam/śledzenia i jasno wyjaśnia swoje praktyki, ale przechowuje niektóre dane w USA, co wiąże się z ryzykiem prawnym.
Fluxer Platform AB’s privacy policy demonstrates strong commitments to data minimization, transparency, and user control, with explicit rejections of advertising, tracking, AI training, and third-party analytics. Data is processed under clear GDPR legal bases (contract, legitimate interest, legal obligation, consent), and user rights are well-documented. However, primary hosting with Vultr in the US (Piscataway, NJ) introduces CLOUD Act exposure, mitigated by Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs). The policy is detailed, specific, and avoids vague language, but lacks end-to-end encryption (E2EE) for most content (planned for future). Retention periods are reasonable, with clear deletion timelines and grace periods. Third-party sharing is limited to necessary service providers (e.g., Stripe, Vultr, Twilio) under GDPR Article 28 agreements. No behavioral profiling or AI model training occurs on user content.
Nie udało się teraz przetłumaczyć tego raportu, więc szczegóły poniżej są po angielsku.
Ocena według kategorii
Podział polityki na kluczowe obszary zgodności. Dobry = silny, umiarkowany = mieszany, słaby = niepokojący.
Collects only necessary data (e.g., email, username, password, IP for security), avoids special category data, and explicitly rejects behavioral profiling or unnecessary analytics.
Policy is exceptionally detailed, with specific examples, legal bases, retention periods, and third-party lists. Few ambiguities.
Sharing is limited to essential service providers (e.g., Vultr, Stripe, Twilio) under GDPR Article 28 DPAs, with no data sold or shared for advertising. Push notifications and embedded content (e.g., YouTube) involve minimal, controlled data exposure.
Data hosted in US (Vultr) with SCCs + TIAs, but CLOUD Act exposure remains a significant risk. No adequacy decision; mitigation is contractual, not technical.
Explicitly states no AI/LLM training on user content. Uses OpenNSFW2 (a non-generative classifier) for explicit content detection, with no external API calls or training pipelines.
All GDPR rights (access, deletion, portability, objection, etc.) are clearly described, with practical instructions and response timelines (30–45 days).
Kluczowe ustalenia
Istotne klauzule, problemy lub dobre praktyki (krytyczne na początku)
US Hosting Introduces CLOUD Act Risk Despite SCCs and TIAs
Section 6 explicitly states that primary data hosting is with Vultr in Piscataway, NJ (US), and call traffic may route globally. The policy acknowledges CLOUD Act exposure and notes that SCCs + TIAs are in place, but admits these cannot eliminate the risk of lawful US government access. This is a critical gap for EU users, as US law may override contractual safeguards.
No End-to-End Encryption (E2EE) for Most Content
Section 9 states that 'nothing on Fluxer is currently end-to-end encrypted' and that message content/call media are technically accessible to Fluxer’s systems. E2EE is in development for calls and some text areas, but until implemented, users must trust Fluxer and its hosting providers (e.g., Vultr) to protect their data. This is a significant privacy limitation for a messaging service.
No Formal DPO Appointed
Section 1 states that Fluxer has not appointed a DPO under GDPR Article 37 or a UK representative under UK GDPR Article 27, though this is 'kept under review.' For a service processing significant personal data (including messages, calls, and payments), this is a compliance gap, as Article 37(1) may require a DPO for large-scale monitoring of publicly accessible areas or processing of special categories of data (even if not intentionally collected).
Limited Retention of Deleted Data in Backups
Section 7.3 notes that deleted messages leave active use within minutes, but encrypted disaster recovery copies may retain them for up to 30 days, and deleted media may persist for up to 24 hours. While this is reasonable for operational resilience, it means 'deletion' is not immediate or absolute, which may not align with user expectations of GDPR Article 17 (right to erasure).
Approximate Location Derived from IP Address
Section 3.2 describes deriving approximate location (city/region/country) from IP addresses for security, fraud prevention, and regional age rules. While this is minimal and not shared with third parties, it still involves processing of location data, which could be considered sensitive under some interpretations. The policy does not clarify if this is treated as a special category or if users can opt out.
Podsumowanie dla użytkownika
Fluxer is a rare example of a modern messaging service that prioritizes privacy by default: no ads, no tracking, no AI training on your data, and strong user controls. However, because some data is stored in the US, it may be accessible to US authorities under the CLOUD Act. If this is a concern, wait for their planned regional hosting or end-to-end encryption features.
Postawa zgodności
Strong GDPR compliance posture: explicit legal bases, DPIAs for high-risk processing (e.g., explicit content classifier, regional access decisions), SCCs + TIAs for international transfers, and clear user rights. No DPO appointed (under review), but transparency and accountability measures are robust. Swedish supervisory authority (IMY) oversight applies.
Transfery UE
High-risk due to US hosting (Vultr in Piscataway, NJ) subject to CLOUD Act. Mitigations include SCCs, TIAs, encryption in transit/at rest, and access controls, but lawful US government access remains a real risk. No adequacy decision for US; reliance on contractual safeguards. Regional hosting is under consideration but not yet available.
Wykryte sygnały
Konkretne dane i praktyki zidentyfikowane w tekście
Fragmenty dowodowe
Bezpośrednie cytaty z polityki potwierdzające te ustalenia
We host most stored account information, messages, communities, files, and other content with Vultr in Piscataway, New Jersey. Call traffic may pass through Vultr locations worldwide so calls route near the participants, encrypted in transit through the relay.
Hosting data in the United States brings it within reach of lawful access requests under US law, including the Clarifying Lawful Overseas Use of Data Act, the CLOUD Act, under which a provider subject to US jurisdiction can be required to produce data in its possession, custody, or control even if stored elsewhere.
Nothing on Fluxer is currently end-to-end encrypted. Your data is encrypted in transit between your device and our servers and at rest on our servers and backups, but because the service relies on server-side processing to function, message content and call media are technically accessible to our systems while being handled.
We do not use your content for advertising, behavioral profiling, AI training, or commercial research, and we do not sell, rent, license, or broker it.
Fluxer runs no AI or LLM inference over your messages, files, or calls. For explicit content preferences we use OpenNSFW2, a small pretrained image classifier running on Fluxer-operated infrastructure. It is not a generative AI system or an LLM.
We have not appointed a formal data protection officer under GDPR Article 37 or a UK representative under UK GDPR Article 27. Both are kept under review, and this section will be updated if that changes.
Deleted messages and account data normally leave active use within minutes. Encrypted disaster recovery copies may hold them for up to 30 days, without any active processing, until scheduled deletion.
Brakujące lub niejasne
- No clarity on whether approximate location data is treated as a special category under GDPR
- No opt-out mechanism for IP-based location derivation
- No timeline for regional hosting (EU/EEA) to avoid US jurisdiction
- No confirmation of whether E2EE will cover all content types (e.g., group chats, community messages)
- No details on how TIAs are conducted or their outcomes
- No explicit mention of GDPR Article 49 derogations for transfers (e.g., explicit consent) as a fallback
- No information on whether Fluxer monitors or logs access to user data by staff (beyond audit logging)
Pytania do zadania
- When will Fluxer offer EU/EEA-based hosting to avoid CLOUD Act exposure, and what will the migration process look like for existing users?
- Can users opt out of IP-based location derivation, and if not, why is this not considered a special category of data?
- What is the timeline for implementing end-to-end encryption, and will it cover all content types (e.g., group messages, community posts)?
- Has Fluxer conducted a formal assessment of whether a Data Protection Officer (DPO) is required under GDPR Article 37, given the scale of processing?
- How does Fluxer ensure that third-party service providers (e.g., Vultr, Stripe) do not access or process user data beyond the scope of their DPAs?
- What specific measures are included in Fluxer’s Transfer Impact Assessments (TIAs) for US transfers, and how are these communicated to users?
- Does Fluxer plan to offer a 'delete all my data immediately' option that bypasses the 30-day backup retention period?
- How does Fluxer handle requests from non-US authorities (e.g., EU member states) for user data, and what legal standards are applied?
Udostępnij tę analizę
Każda osoba z tym linkiem może zobaczyć wynik powyżej.
Stworzone przez DentroChat
100% europejski czat AI dla wszystkich
Rozmawiaj z AI, pracuj z plikami, generuj obrazy i przeszukuj sieć. Dane pozostają w Europie.
Inne analizowane polityki prywatności
Zobacz wszystkiegdprchat.eu
88/100
Niskie ryzyko prywatnościGDPRchat oferuje wyjątkowo silną prywatność zorientowaną na UE, bez śledzenia i z samoobsługową kontrolą danych, ale użytkownicy powinni mieć świadomość, że podpowiedzi obrazów mogą być wykorzystywane do trenowania AI przez zewnętrznego dostawcę.
Zobacz raport →proton.me
88/100
Niskie ryzyko prywatnościProton oferuje domyślnie silną ochronę prywatności dzięki szyfrowaniu end-to-end, minimalnemu zbieraniu danych i brakowi śledzenia reklam, choć niektóre dane użytkowników trafiają do podmiotów przetwarzających w USA w celu obsługi klienta i płatności.
Zobacz raport →tuta.com
87/100
Niskie ryzyko prywatnościTuta to wysoce przyjazny dla prywatności, szyfrowany dostawca poczty e-mail, który przechowuje wszystkie dane użytkowników zaszyfrowane metodą end-to-end w Niemczech, zbiera minimalne metadane, nie używa plików cookie i udostępnia dane stronom trzecim tylko w celu przetwarzania płatności lub na podstawie nakazu sądowego.
Zobacz raport →startpage.com
90/100
Niskie ryzyko prywatnościStartpage oferuje wyjątkową prywatność z założenia, zbierając praktycznie żadnych danych osobowych i wyraźnie odrzucając śledzenie, profilowanie i rejestrowanie wyszukiwań, choć istnieją niewielkie przepływy danych do zewnętrznych dostawców reklam i analityki.
Zobacz raport →