Privacy Policy for Flux
Last Updated: 13.09.2026
Flux lets you write a post once and publish it to several social networks, from the iPhone and iPad app, the Android app, or the web portal at app.fluxpost.eu. Your Flux account now lives on our servers: that is what lets the apps and the web show the same connected networks, drafts and archive. This policy replaces the earlier one, which described a version of the iPhone and iPad app that kept everything on your device. Here is exactly what we keep, why, who else receives it, and how to remove it.
1. Who is responsible
Flux is operated by Kempu OÜ (Estonia), the controller of the personal data described here. Questions and requests: [email protected].
2. What we store
- Your Flux account: name, optional display name, email address, password (stored only as a one-way hash), time zone, email preferences, and composer preferences such as thread numbering, alt text defaults and your AI writing guidance.
- Connected networks: for each network you connect, the account ID, username, display name and profile picture that network gives us, and the access and refresh tokens Flux needs to post for you. Tokens are encrypted in our database and are never sent to your devices. For LinkedIn and Facebook we also keep the Pages you add. For Bluesky you sign in on Bluesky’s own page, or your own server’s if your account is hosted elsewhere, so Flux never sees your password; we also keep the address of that server and the key that ties your tokens to Flux, both encrypted. For a webhook we keep its address and, if you give one, its access token (encrypted).
- Profile pictures: a small copy (128 × 128 pixels) of each connected account’s and Page’s picture, because the links networks hand out expire. We refresh it about once a week and delete it once no connected account uses it.
- Your content: workspaces (called profiles in the app), drafts, the posts you publish with each network’s result (post ID, link or error message), contacts you save (names and handles on each network, which can be other people’s public handles), and the images and videos you attach, with their alt text, thumbnails and original file names.
- Link previews: when you add a link, our server fetches that page’s title, description and image address. The result is cached for 24 hours and saved with the draft or post that uses it.
- Plan and billing: your plan, subscription status and billing periods, how much of each monthly allowance you have used, and from Stripe a customer reference and your card’s brand and last four digits.
- Sign-in and security: the apps signed in to your account (the device name the app sends, when it was last used, when its sign-in expires), web sessions (IP address and browser) and password reset requests. Our hosting provider’s web servers keep standard access logs (IP address, time, requested address, browser), and the application logs errors, which can include your account ID and the message a network returned.
- Two-step verification: every account signs in with a password and a code from an authenticator app. We keep your authenticator’s secret key (encrypted), a one-way hash of each unused recovery code, when two-step verification was turned on, and the time step of the last code you used, so no code works twice. While a sign-in waits for its code we keep a hashed reference to it and, for an app, the device name it sends; while you add an authenticator app, its new secret key is kept encrypted until your first code confirms it. New recovery codes shown in the browser are held encrypted in your session until you confirm you have saved them. We also count wrong codes per account.
If you used Flux on an iPhone or iPad before accounts existed, the app moves the profiles, connected accounts, drafts, archive and contacts kept on that device into your Flux account when you first sign in.
3. On your device
iPhone and iPad: the app keeps a local copy of your drafts, archive and accounts list so it opens quickly and can hold edits you make offline until they sync, and it keeps your Flux sign-in in the iOS Keychain. Alt text generated with Apple Intelligence is produced on the device; the image itself is uploaded to Flux like any other attachment. The app icon and haptics stay on the device.
Android: the app keeps a local copy of your drafts, archive and accounts list, and holds drafts and attachments you add offline until they upload. It keeps them in its private storage, which Android’s backup and device-to-device transfer leave out. Your Flux sign-in is encrypted with a key held in the Android Keystore, which never leaves the phone. Photos and videos come from Android’s photo picker, which hands the app only the items you choose, so the app has no access to the rest of your storage. While posts publish in the background, Android shows a notification if you allow it. Account, plan and billing pages and network connections open in your browser through a sign-in link that works once, within 2 minutes; your browser then keeps the portal’s sign-in cookies. Signing out deletes the local copy and the offline drafts and attachments, and cancels publishing still waiting on the phone; pictures the app has shown can stay in its image cache until newer ones replace them or Android clears it. If your sign-in expires instead, the copy stays on the phone, hidden, until the same account signs in again. Your appearance and haptic feedback settings stay on the device.
Both apps: your composer preferences and the accounts you last selected in each profile are saved to your Flux account, so the apps and the web use the same ones. When you set up two-step verification, either app can pass the setup link to an authenticator app on the same device, and lets you copy the key or share your recovery codes with an app you choose. Neither app keeps the key or your recovery codes. Your authenticator app, and any app you save the codes in, keeps its own copy under its own terms, including any backup or sync it offers.
4. What we do not do
- No advertising, and no selling or renting of your data.
- No analytics or tracking cookies on fluxpost.eu or in the portal. The portal sets only the cookies signing in needs: a session cookie, a security (CSRF) cookie and a “remember me” cookie. fluxpost.eu sets none.
- No analytics, advertising or crash-reporting code in the iPhone, iPad and Android apps.
- Flux does not use your posts, images or other content to train AI models.
5. Why we use it
- To provide Flux: keep your account, connect your networks, publish what you ask us to, and show your drafts and archive (GDPR Art. 6(1)(b), performance of our contract with you).
- To bill paid plans and keep the records accounting law requires (Art. 6(1)(b) and 6(1)(c)).
- To keep Flux secure and working: two-step verification, sessions, logs, preventing abuse and fixing faults (Art. 6(1)(f), our legitimate interest in running a secure service).
- To email you about your account: verification and password reset links, a security notice whenever the second step of your sign-in changes (turned on, moved to another authenticator app, new recovery codes, or reset by an administrator), and, unless you switch them off under Settings › Preferences, a warning when a monthly allowance passes 80% and a notice when a network connection stops working (Art. 6(1)(b) and 6(1)(f)).
6. Who else receives your data
- The networks you publish to: X, Bluesky, Threads, LinkedIn, Facebook and the Mastodon servers you connect receive what you publish (text, images, video, alt text) and the requests needed to connect your account, renew access and look up people you mention. For Bluesky, your posts go to the server that hosts your account; to find it, our server looks up your handle’s domain and Bluesky’s public directory (plc.directory), and searches for people to mention go to Bluesky’s public service without your credentials. What they do with it is governed by their own privacy policies.
- Webhook endpoints you add receive each post as JSON: the text, images, alt text, link preview, and a link to any video.
- Media links: Threads and webhook endpoints download media from a signed link that stops working after one hour. Otherwise your files are served only to you.
- Websites you link to are visited by our server to build the preview, so they see our server’s address, not yours. The preview picture is the exception: the apps and your browser load it straight from where the website keeps it, so that server sees your IP address.
- Hosting: NetiServer runs our servers in Amazon Web Services’ data centre in Ireland (EU). The database, uploaded files, logs and outgoing email are all there.
- Stripe processes payments for paid plans. It receives your name, email address, billing address and card details; card numbers never reach our servers.
- AI providers: when you use Smart Descriptions or AI writing, the image you want described or the text you want rewritten (with links replaced by placeholders), together with our instructions, goes to the provider configured for that feature: OpenAI, Anthropic, Google (Gemini) or OpenRouter, which passes the request on to the model’s maker. No account details are sent, and Flux keeps no copy of the request.
- Apple distributes the iPhone and iPad app through TestFlight and the App Store, and Google distributes the Android app through Google Play, each under its own privacy policy. Depending on your device settings and their terms, they can pass us crash reports and usage statistics.
- We disclose data to authorities only when the law requires it.
Stripe, the AI providers and several of the networks are based in the United States. Where your data leaves the EU/EEA, the transfer relies on the safeguards the GDPR provides for, such as the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
7. How long we keep it
- Your account, connections, drafts, archive, contacts and files: until you delete them or your account.
- Deleting a draft or an archived post also deletes its files once no other draft or post uses them. It does not delete a post already published on a network; do that on the network itself.
- Disconnecting a network deletes its tokens and the accounts that used them. Flux also asks X, Bluesky, Mastodon and Facebook to revoke its access; LinkedIn and Threads give apps no way to do that, so remove Flux in their settings as well.
- Signed media links: 1 hour. Link preview cache: 24 hours. Unfinished network sign-ins: 15 minutes. Unfinished two-step sign-ins and authenticator changes, and counts of wrong codes: 15 minutes.
- Two-step verification: a recovery code is deleted as soon as it is used, and creating new codes deletes the old ones. The secret key stays until you move to another authenticator app, an administrator resets two-step verification, or you delete your account; a reset also ends every app and browser sign-in.
- Deleting your Flux account (Settings › Your data › Delete account) removes your account, connections (revoking access where the network allows), workspaces, drafts, archive, contacts, files, usage records, sign-ins and two-step verification data, and deletes your Stripe customer, which ends any subscription. Stripe keeps the payment records it is legally required to keep.
- Logs and our hosting provider’s backups can hold deleted data for a limited time until they are rotated out.
8. Security
- All traffic between the apps, the portal, the networks and our providers uses HTTPS.
- Network tokens, webhook secrets, your authenticator’s secret key and our AI provider keys are encrypted in the database; passwords and recovery codes are stored only as hashes.
- Every sign-in needs your password and a 6-digit code from your authenticator app, or a recovery code that works once. After five wrong codes, the account cannot try another for 15 minutes. Turning two-step verification on ends every sign-in made before it, and we email you whenever it changes. The setup QR code is drawn by our own server or by the app itself, so no outside service sees your secret key.
- Uploaded files sit in private storage and are served only to you, or through the signed, expiring links described above.
- Link previews and profile pictures are fetched only from public internet addresses.
9. Your rights
Under the GDPR you can access, correct, export and delete your data, and object to or restrict how we use it.
- Export: Settings › Your data › Download export gives a JSON file with your account, subscription history, usage, workspaces, connections (without tokens), contacts, drafts, archive and signed-in apps, and whether two-step verification is on with how many recovery codes are left (never the secret key or the codes). Email us for your uploaded files.
- Correct: change your details under Settings.
- Delete: Settings › Your data › Delete account, or email us.
- Lost authenticator app: sign in with a recovery code and set up a new app under Settings › Security. With no recovery codes left, email us: an administrator can reset two-step verification, which signs your account out everywhere, and you add a new authenticator app at your next sign-in.
- Emails: switch the usage and connection notices off under Settings › Preferences. Security notices about two-step verification cannot be switched off.
Write to [email protected] for anything else. You can also complain to the Estonian Data Protection Inspectorate (aki.ee) or to the data protection authority where you live.
10. Changes
When Flux changes how it handles data, we update this page and the date at the top.
13.09.2026: This policy now covers the Android app: section 3 describes what it keeps on your phone, and section 6 how Google distributes it. It also corrects two earlier statements: the accounts you last selected are saved to your Flux account, not only on your device, and the apps and your browser load link preview pictures straight from the website’s server.
13.09.2026: Every Flux account now signs in with a password and a code from an authenticator app. When this began, existing browser sessions and app sign-ins stopped working, and each account adds an authenticator app at its next sign-in. Sections 2, 7, 8 and 9 describe what is kept, for how long, and what you can do.
13.09.2026: Bluesky connects through Bluesky’s own sign-in instead of an app password. Connections made with an app password were signed out and their stored sessions deleted; your drafts and archive were not affected. Reconnect Bluesky in Flux, and delete the old app password in Bluesky’s settings.
11. Contact Us
If you have any questions about this policy, please contact us at: [email protected]