Flotilla — Privacy Policy

Flotilla collects no data — by default, none. The one optional exception is Flotilla Push, described below; it ships starting in Flotilla 1.1, off unless you turn it on, and isn't present at all in Flotilla 1.0.

Flotilla is a client for your own self-hosted servers. The app connects directly from your device to the Unraid and Proxmox VE machines you configure, and that direct connection is the whole app — no server of ours is involved. There is no account system, no analytics, no crash reporting, no advertising, and no third-party SDKs, anywhere in Flotilla, whether or not you use Push.

What stays on your device

Server addresses, API tokens (stored in the iOS Keychain), pinned certificate fingerprints, and cached fleet status for the widget. Nothing leaves your device except the requests the app makes to your own servers.

Optional network access

"Load container icons" (off by default) fetches container icon images from the URLs your server's templates reference. Purchases are processed by Apple; Flotilla never sees payment details.

Flotilla Push (optional — Flotilla 1.1 and later)

Flotilla 1.0 has no Push feature: it makes no connection to any server of ours and collects no data at all. Starting in Flotilla 1.1, Flotilla Push sends alerts from your Unraid or Proxmox VE server to your iPhone when the app isn't open. It's off by default, requires Flotilla Pro, and is the only feature that isn't a direct device-to-server connection — turning it on registers an Apple Push token for your device with a relay server we operate, so it can hand your alerts to Apple's Push Notification service on your server's behalf.

Notification content is end-to-end encrypted with a key that never leaves your network except inside the pairing QR code — the relay only ever forwards ciphertext it cannot read. The one exception is the beacon-less Proxmox VE setup, where the server's webhook posts its alert text to the relay in plaintext because that path has no local encryption step. Full detail on exactly what the relay can and cannot see: Flotilla Push.

There is still no account and no analytics: enabling Push creates a random pairing ID and stores your device's Push token against it — nothing that identifies you. Unpairing in the app removes that device's Push token from the relay. "Reset pairing" on the server goes further: it revokes the whole pairing at the relay — every paired device's token and all of that pairing's stored state (heartbeat and rate-limit bookkeeping) — not just one token.

Contact

livinmathew99@gmail.com

Effective 2026 — this policy changes only if the app's behavior does, and the app's behavior is: collect nothing beyond what Flotilla Push, described above, discloses if and when you turn it on.