FlyControl: privacy and terms of use

The privacy policy covers what the app collects, who else receives it and how to delete it. The terms of use cover what is free, what is paid and what you may do with the app.

Privacy policy

Last updated

FlyControl is an unofficial Fly.io client. It has no FlyControl account and no server of its own. The only thing it keeps is the Fly.io token you give it, and that token goes from your phone straight to Fly.io and nowhere else.

I, Tiago Danin, am the developer and the controller of this data under the LGPD (Lei 13.709/2018). If you are in the EU, the GDPR gives you the same rights and I answer them the same way. Write to TiagoDanin@outlook.com about any of it. FlyControl is not affiliated with, endorsed by or supported by Fly.io.

What you give the app

Your Fly.io token

To connect, you paste a Fly.io token, usually an organization token from fly tokens create org, or the output of fly auth token. Before saving it, the app checks with Fly.io that the token works and lists its organizations.

The token is stored in the phone's encrypted storage, the Android Keystore or the iOS Keychain, together with the label you give the account and the slugs and names of its organizations. On iOS it is kept for this device only and is not restored to another one. You can connect more than one account; each is stored the same way.

The token is sent only to Fly.io's API, at api.machines.dev and api.fly.io, in the authorization header of each request. I never receive it.

What the app loads from Fly.io

With your token, the app asks Fly.io for your apps, machines, regions, logs, metrics and deployment history. The deployment history includes the email of whoever made each release, shown in the deployment details. All of this is kept in memory while the app runs and is not written to disk. When you start, stop, restart or destroy a machine, that command goes to Fly.io the same way.

Fly.io processes those requests under its own privacy policy.

What else stays on your phone

The app saves your appearance setting (light, dark or system), the selected organization and whether you are in demo mode. It reads the clipboard only when you tap Paste on the connect screen, and writes to it only when you copy a log line or a value.

There are no analytics, no crash reporting, no ads, no notifications and no third-party SDK that collects data. I do not sell data, rent it or share it with anyone.

Why it is used

Only to show you your own Fly.io resources and to run the commands you choose, which is the service you asked for.

Deleting it

In the app, remove one account, or disconnect every account, and the stored tokens are deleted from the device. Uninstalling the app deletes them too. The token itself still exists at Fly.io until you revoke it there, with fly tokens revoke or in the Fly.io dashboard. Do that if you lose the phone.

Since I hold no data about you, there is nothing for me to access, correct or delete on my side. You can still write to me with any question about your rights, and I answer within 15 days. You may also complain to the ANPD, Brazil's data protection authority.

Security

Requests to Fly.io are encrypted in transit, and the token is kept in the system's encrypted storage. No system is completely secure. Use a token with the narrowest scope that works for you.

Children

FlyControl is meant for adults who run infrastructure on Fly.io. It is not directed at children, and I do not knowingly collect data from anyone under 18.

Changes

If this policy changes, the date at the top changes with it. A change that affects what is collected or where it goes will be described here before the version that makes it is published.

Contact

Tiago Danin, TiagoDanin@outlook.com.

Terms of use

Last updated

These terms apply to anyone who installs or uses FlyControl on Android or iOS. Connecting an account means you accept them. If you do not, uninstall the app.

Who provides the app

Tiago Danin, a private individual in Brazil, who develops and publishes FlyControl. "I" and "me" below mean him. "You" means the person using the app.

What FlyControl is

An independent client for the Fly.io API. It lists your apps and machines, shows logs, metrics and deployments, and lets you start, stop, restart or destroy a machine.

FlyControl is not affiliated with, endorsed by or supported by Fly.io. Fly.io is a trademark of its owner. For problems with your Fly.io account, billing or infrastructure, contact Fly.io, not me.

Price

Free, with no ads and no purchases.

You act on real infrastructure

Every command runs on your actual Fly.io resources. Stopping a machine takes your service down. Destroying a machine is permanent and cannot be undone from the app or by me. The app asks you to confirm before destroying, and it is still your decision.

You are responsible for the token you connect, the permissions it carries and anything done with it through the app, including costs Fly.io charges you. Use a token with the narrowest scope that works, and revoke it at Fly.io if your phone is lost.

Fly.io can change

FlyControl depends on Fly.io's API, its limits and its terms. Some of what it uses, such as the logs endpoint, is not officially documented. If Fly.io changes or limits its API, features can stop working until I adapt the app, or for good. Your use of Fly.io itself is governed by Fly.io's own terms.

What you may do with it

I give you a personal, free, non-exclusive and revocable licence to use FlyControl on your devices. You may not resell or redistribute it, or use it against accounts you are not authorised to manage. The name, the icon and the design are mine.

Liability

FlyControl is provided as it is. Data shown in the app comes from Fly.io and can be delayed or incomplete. To the extent Brazilian law allows, I am not liable for downtime, data loss, destroyed machines, charges from Fly.io or any other damage caused by commands you send or by relying on what the app shows. Nothing here removes a right that the law gives you and that a contract cannot take away, such as those in the Código de Defesa do Consumidor.

Privacy

What the app stores and where it goes is described in the privacy policy on this same page.

Changes

I may update these terms. The date at the top changes when I do. Continuing to use FlyControl after that means you accept the new version.

Law

Brazilian law governs these terms. Anything an email cannot settle goes to the courts of Belém, Pará, without prejudice to your right as a consumer to sue where you live.

Contact

Tiago Danin, TiagoDanin@outlook.com.

This site has its own documents, separate from the app's: privacy and terms of the site.