We keep personal data only as long as we need it to run Fluxer, meet legal obligations, resolve disputes, and enforce our rules. Our privacy policy is the full statement. This article covers the periods people ask about most.
What we keep while your account is active
While your account is active we keep what's needed to provide Fluxer: your username, email address, password hash, date of birth, messages, uploads, Communities, and profile information. You can delete most of it yourself or close the account.
A few things people assume we keep, but don't:
- Phone numbers. We don't store your phone number on your account. A raw number goes only to Twilio, which handles SMS verification, and the other narrow boundaries described in the privacy policy. For lookup caching, reuse checks, attempt controls, and rate limiting we keep keyed cryptographic markers instead. The reuse record lasts no more than 31 days, is held only in server memory rather than a database, carries neither the phone number nor an account reference, and is used to stop the same number verifying more than twice in that period. Carrier, country, line type, validity, and risk signals are kept for up to 7 days, and attempt diagnostics for up to 90 days.
- Card numbers. Stripe processes payments. Fluxer doesn't receive or store your complete card number.
- Message content for analytics or AI. Product and business analysis uses pseudonymised event records with coarse timestamps and no sensitive context, plus aggregate request, error, and performance metrics. It never reads message or file content, and we don't train or evaluate AI models on your content.
What you can remove yourself
- Individual messages and attachments. Delete them in the app. Deleting a message also deletes its attachments.
- All your messages in bulk. Open "Privacy Dashboard" and select "Data Deletion". See the data deletion guide.
- Your whole account. Close it in account settings. See the account deletion guide. Deletion starts a 14-day grace period, and signing in during that time cancels the request.
- A specific piece of data. Email privacy@fluxer.com from your registered address for anything you can't remove in the app.
What happens when you delete something
- A message or account record normally leaves active systems within minutes. Encrypted disaster recovery copies may hold it for up to 30 days before permanent removal.
- An attachment normally leaves active storage within hours. A copy may remain for up to 24 hours solely for disaster recovery, restorable only by authorised operators, then it's permanently erased. Attachments aren't included in backups kept for longer periods.
- A Community or channel enters a 14-day grace period and disappears from normal use of the app and API, though authorised staff can view and restore it and you can ask support to restore it during the window. Existing attachment links keep working, an account export may still include messages you wrote there, and bulk message deletion skips them. After 14 days it and everything in it are permanently deleted, with no way back.
- Your account gets a 14-day grace period that you can cancel by signing in. When it ends we remove the account according to the periods above, and remaining messages are no longer linked to it.
Messages already shared with other people may stay visible unless you delete them or choose message deletion when you close the account.
What we keep longer, and why
A few kinds of data outlive your account, for narrow reasons:
- Report snapshots. When content is reported we may keep the reported item, relevant context, attachments, and report information for up to 1 year to support an investigation or appeal, even after the original is deleted. It's stored separately, isn't served to users or included in exports, and access is limited to authorised staff and recorded.
- Security and usage logs. Kept for up to 90 days under normal conditions, then deleted or anonymised. Specific records may be kept longer only for an active security investigation, a binding legal obligation, or an ongoing dispute, and are deleted once that reason ends.
- Audit logs. Records of administrative access and enforcement decisions are kept as long as accountability, appeals, and review need them.
- Payment and transaction records. Kept for at least 7 years, as Swedish bookkeeping law (Bokföringslag 1999:1078) requires, and longer where needed for legal compliance, disputes, or fraud prevention. Complete card numbers aren't stored.
- Photo IDs sent to support for an age appeal or date of birth correction: deleted within 60 days after the request is closed, whatever the outcome.
- Support correspondence. Kept for as long as we need it to handle the request and any follow-up, then deleted on review.
- Backups. Encrypted, off-site, on a rolling retention period of up to 30 days.
- Legal records. Anything else the law specifically requires us to keep, for as long as the law requires.
Information anonymised so that it can no longer identify you may be kept for service analysis.
Inactive accounts
Accounts inactive for 2 years may be scheduled for deletion. We give advance notice to the registered email address before it proceeds. See the account deletion guide for details.
Your rights
You can export your data, delete messages, and close your account through "Privacy Dashboard" and account settings. For anything you can't do in the app, email privacy@fluxer.com from your registered address.
In the EEA and UK, the GDPR gives you rights of access, rectification, erasure, restriction, portability, and objection, plus rights over automated decisions. California residents have parallel rights under the CCPA/CPRA. Section 10 and section 17 of the privacy policy explain how to use them and how to complain to your data protection authority.