Security & privacy

Encrypted on device.
EU-hosted in the cloud.

Encryption by default. No ad-tech. EU-hosted. Full export. Privacy is a design constraint, not a compliance task.

01

Encryption

Every Fluera notebook is encrypted at rest on your device with AES-256 via SQLCipher, and exported .fluera files are encrypted with AES-256-GCM. Traffic is TLS 1.3 in transit. Cloud sync is not end-to-end encrypted: synced notebooks are stored on EU infrastructure (Supabase, eu-north-1), encrypted in transit and at rest at the infrastructure level. As data controller we can technically access synced content — but we never sell it and never use it for advertising.

02

Data ownership

Every byte you write is exportable in a single click: PNG, JPEG, WebP, SVG, PDF, and our open .fluera format. Your notebooks live on your devices first. The cloud is a convenience, not a prison — lock-in is a business model we chose against.

03

GDPR, natively

Fluera is EU-hosted and GDPR-native. A Data Processing Agreement is available to any educational institution on request. Full data export and right-to-be-forgotten requests are honoured within 30 days (usually within 48 hours).

04

Local-first, always

You can run Fluera fully offline. Sync is opt-in per notebook, not account-wide. If you turn sync off, your data never leaves the device — including telemetry, which is consent-based and anonymous.

05

Audit log (Education)

For Education accounts, every access to shared notebooks is logged in an immutable audit trail, exportable for compliance reviews. Administrators can enforce SSO (SAML, OIDC) and MDM-managed deployments.

06

What we don't do

We will not run ads. We will not sell your data. We will not train our models on your notebooks. We will not track you across the web. We will not hand data to third parties beyond named sub-processors (Supabase, Vercel, RevenueCat) — all under DPA.

Responsible disclosure

Found something?

Security researchers are welcome here. Report vulnerabilities to lorenco@fluera.dev. We acknowledge within 24 hours, patch critical issues within 72, and credit reporters in our hall of fame unless you'd rather stay anonymous.

A PGP key for encrypted submissions is published on our GitHub.

Compliance & deployment

Deploying Fluera at your institution?

Universities, schools and research labs: we can walk you through our DPA, sub-processor list, SSO setup and the audit log model. Pilots typically start with one class, one semester, no charge.

Talk to us about deployment →

This page covers the essentials. The full architecture, sub-processor register and DPA template live at /security/architecture and /security/sub-processors. Specific compliance questions? Write to lorenco@fluera.dev.