Privacy Policy

This Policy explains what personal data Fliver collects, why we process it, how long we keep it, and the choices you have. Endpoint payloads you choose to publish are your responsibility.

Effective
13 August 2026
Last updated
13 August 2026
Operator
LogicByte Studios
Contact
privacy@fliver.net

This Privacy Policy ("Policy") describes how LogicByte Studios ("LogicByte", "we", "us", or "our") collects, uses, stores, and shares personal data in connection with Fliver websites, dashboards, plugins, gateways, tunnels, and related services (the "Service").

Fliver is primarily a relay platform. When your Project serves a public Endpoint, the response body is generated by systems you control. Those responses may contain personal data that you choose to expose. In that case, you determine what is published; Fliver transmits it as part of operating the relay.

By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service. Where required by law, we will request additional consents for specific processing.

1. Data Controller

Unless otherwise stated, LogicByte Studios is the controller of personal data processed to operate Fliver accounts, billing, security, and platform logs.

If you publish personal data through your Endpoints (for example player names, UUIDs, ban reasons, or chat excerpts), you are typically the controller of that publication decision. Fliver processes such traffic as a technical relay/processor to deliver your responses to requesters, and may retain limited operational logs as described below.

Contact for privacy requests: privacy@fliver.net. Legal notices: legal@fliver.net.

2. Scope

This Policy covers personal data processed when you visit fliver.net and related sites, create an account, manage teams and Projects, pair servers, use tunnels, purchase plans, contact support, or interact with abuse/legal processes.

It does not govern third-party websites, game platforms, payment processors, or services that merely consume your public Endpoints after Fliver delivers a response.

3. Personal Data We Collect

We collect the following categories, depending on how you use the Service:

3.1 Account and profile data

  • Name or display name, email address, password hashes or authentication tokens, avatar/logo where provided.
  • Organization/team names, slugs, membership roles, and project metadata.
  • Email verification status and security settings.

3.2 Billing and purchase data

  • Plan selection, subscription status, invoices/receipts references, and limited payment metadata returned by our payment provider.
  • Payment card details are typically processed by the payment provider (for example Lemon Squeezy) and are not stored in full by Fliver.

3.3 Server pairing and session data

  • Pair codes, session identifiers, client/plugin version strings, organization and project slugs, gateway association metadata.
  • Tunnel online/offline state and timestamps needed to route requests.

3.4 Technical and security logs

  • IP addresses, user-agent strings, timestamps, request paths (public API and Dashboard), approximate geolocation derived from IP where used for security, and diagnostic error logs.
  • Rate-limit counters, abuse signals, and authentication failure records.

3.5 Communications

  • Support messages, abuse reports, legal correspondence, and survey or feedback content you choose to send.

3.6 Endpoint relay traffic

To relay a public request, Fliver necessarily processes HTTP method, path, query string, selected headers, and body bytes between the public client and your paired server, then returns your response. Response bodies are User Content generated by you.

We may retain truncated or sampled request/response metadata for reliability, abuse prevention, debugging, and legal compliance. Retention windows may be configurable per Project where the product exposes that setting. Do not place secrets in public Endpoints.

3.7 Cookies and similar technologies

We use cookies and similar technologies for authentication sessions, preference storage, security, and (where enabled) analytics. Essential cookies are required for the Dashboard to function. You can control non-essential cookies through your browser settings and any consent tools we provide.

4. Sources of Data

We collect data directly from you, automatically from your devices and integrations (plugin/tunnel), from payment providers, and from security/abuse partners or publicly available sources when investigating fraud or misuse.

5. Purposes and Legal Bases

We process personal data for the following purposes. Where GDPR/UK GDPR applies, the typical legal bases are noted:

  • Provide and operate the Service (contract / legitimate interests).
  • Authenticate users, pair servers, and relay Endpoint traffic (contract).
  • Secure the platform, prevent abuse, detect fraud, and enforce Terms/Rules (legitimate interests / legal obligation).
  • Bill for paid plans and prevent payment fraud (contract / legitimate interests / legal obligation).
  • Communicate service notices, security alerts, and support replies (contract / legitimate interests).
  • Improve reliability, performance, and product features using aggregated or de-identified metrics where feasible (legitimate interests).
  • Comply with law, respond to lawful requests, and establish/defend legal claims (legal obligation / legitimate interests).
  • Send product updates or marketing only where permitted and with opt-out (consent or soft opt-in where applicable).

6. How We Share Data

We do not sell personal data. We share data only as needed with:

  • Infrastructure providers (hosting, databases, object storage, CDN/DNS, email delivery) acting as processors under contracts.
  • Payment processors for subscriptions and invoices.
  • Security, anti-abuse, and analytics vendors where enabled.
  • Professional advisors (legal, accounting) under confidentiality.
  • Authorities or rights holders when required by law or necessary to protect users, the public, or LogicByte.
  • A successor entity in a merger, acquisition, or asset transfer, subject to appropriate protections.

6.1 Public Endpoint consumers

Anyone on the internet who can reach your public Endpoint URL may receive the response your server generates. That disclosure is initiated by your Project configuration and scripts, not by Fliver inventing the payload. Treat public Endpoints as public.

7. International Transfers

We may process data in countries other than your own. Where required, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms for transfers from the EEA/UK to third countries.

8. Retention

We retain personal data only as long as needed for the purposes above, including:

  • Account data: for the life of the account and a reasonable period afterward for security, billing disputes, and legal claims.
  • Tunnel/session metadata: for active routing needs plus short operational history.
  • Security and abuse logs: typically longer than routine access logs, as needed to investigate incidents.
  • Billing records: as required by tax and accounting laws.
  • Relay/debug logs: according to product defaults or Project retention settings, then deletion or aggregation.

8.1 Deletion requests

When you delete an account or Project, we delete or anonymize associated personal data within a reasonable period, except where retention is required by law, needed for dispute resolution, or stored in encrypted backups until rotation completes.

9. Security

We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS) where configured, access controls, least-privilege practices, and monitoring. No method of transmission or storage is perfectly secure. You must protect pair codes, session tokens, and Dashboard access, and avoid placing secrets in public responses.

10. Children

The Service is not directed to children under 13 (or the higher age required in your jurisdiction for digital consent without parental authorization). We do not knowingly collect personal data from children in violation of law. If you believe we have, contact privacy@fliver.net and we will take appropriate steps.

11. Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, to data portability, and to withdraw consent where processing is consent-based. You may also lodge a complaint with a supervisory authority.

To exercise rights, email privacy@fliver.net with enough information to verify your request. We may decline or limit requests where permitted (for example, if identity cannot be verified, or where an exception applies).

If your request concerns personal data that appears only inside Endpoint payloads you publish, you may need to modify your scripts or Project configuration; we can assist with disabling the Project where appropriate.

12. US State Privacy Disclosures

If you are a resident of a US state with consumer privacy laws (for example California), you may have rights to know, delete, correct, and opt out of certain sharing. Fliver does not sell personal information as "sale" is commonly defined. We process data to provide the Service and for security. Submit requests to privacy@fliver.net. We will not discriminate against you for exercising privacy rights.

13. Responsibilities of Customers Who Publish Data

If you expose player or user personal data via Endpoints, you must ensure you have a lawful basis, provide required notices to data subjects, honor applicable rights requests relating to that publication, minimize data, and avoid publishing special-category or sensitive data unless you have a clear lawful basis and safeguards.

Fliver’s relay role does not transfer your compliance obligations to LogicByte for content you choose to make public.

14. Changes to this Policy

We may update this Policy by revising the JSON source and updating the version and lastUpdated fields. Material changes will be highlighted where practicable via Dashboard or email. Continued use after the effective date constitutes acknowledgment of the updated Policy, subject to mandatory law.

15. Contact

Privacy requests: privacy@fliver.net

Abuse reports: abuse@fliver.net

Legal: legal@fliver.net

Operator: LogicByte Studios — https://logicbyte.org

This Policy is maintained as structured JSON so product and compliance updates can ship without rewriting page code. It is a general notice, not legal advice for your specific jurisdiction or Project.