Privacy
What is public, what stays private, and what gets processed
Flex Your Income is built around public money stories. That makes the privacy boundary more important, not less. This notice explains what the service publishes, what it keeps private, and where moderation, voting and anti-abuse processing fit.
Last updated: 19 September 2026
The short version
- Your published amount, currency, pay basis, short story and chosen public context are visible to anyone.
- Some complete public stories are eligible for search-engine indexing, so public can mean searchable as well as shareable.
- The service does not ask for payslips, tax returns, employer names, exact dates of birth, home addresses or identity documents to publish a story.
- Public user-authored text is screened before a new or edited moderated revision can be published. Moderation is not verification of the money claim.
- Your private owner signing key is generated in your browser. The server stores the matching public key, not the reusable private key.
- Community voting uses a pseudonymous browser actor and public aggregate counts. A vote is not verification.
- Analytics is opt-in and separated from moderation, voting and anti-abuse identity.
- Advertising, tips and payments are not currently enabled.
- You can unpublish or permanently delete your own story with its private management link.
Who can use the publishing service
You must be at least 18 years old to publish or manage a money story. If you choose to provide an age bracket, Flex Your Income accepts broad adult brackets only. It does not collect your exact age or date of birth.
This is a participation and privacy rule for this service. It is not a claim that one age threshold answers every legal question in every country.
What a public money story contains
A community-submitted story contains the amount you report, its currency, an explicit pay basis such as per year, per hour, per day, per gig or one-off, a short public story, a country or broad region, and either a public display name or Anonymous status. You may also add industry, occupation, a broad adult age bracket and income-source category.
Those fields are submitted for publication. Published stories are available through an opaque public URL and can appear in site discovery. Flex Your Income does not silently convert unlike kinds of pay into an annual amount.
Community-submitted money claims are self-reported. The service may also use controlled site-created starter stories, which are tracked separately through internal provenance. Neither category is independently verified, and moderation, votes, Top or Trending do not turn a claim into verified fact.
Automated moderation of public text
New or edited public user-authored text is screened before that moderated revision can become public. The moderated text surface is the short story, a non-anonymous display name, and an occupation when one is supplied.
The service first applies local checks for material such as links or domain-like promotion, contact details, link-markup attempts and obvious repetition spam. It then uses Cloudflare Workers AI for broader automated safety plus publication-policy and relevance checks across that public-text surface.
The automated classifier input does not include the submitted money amount, currency, pay basis, location, industry, age bracket or income-source category. It also does not include your private management key, owner proofs, anti-abuse identifier, analytics identifier, Cloudflare Access identity or visitor report details.
Cloudflare currently states that customer content is not used to train Workers AI models unless the customer explicitly consents. Provider terms and retention practices can change, so this notice should be read together with the provider's current terms.
Flex Your Income keeps the publication-safety decision and revision metadata needed to apply moderation consistently. Automated moderation is a publication-safety control; it does not verify that an amount, job or story is true.
Reports and repeat moderation
Visitors can report a public story using a report category and optional details. The moderation database intentionally does not store a reporter name or email field.
A report can request another automated scan of the story's current public content. Report detail text itself is not sent to the external content classifier. Repeat reports against unchanged content can be combined rather than causing one classifier call per report.
An unsafe current revision can be hidden. If an automated provider is temporarily unavailable, an already-accepted public story is not automatically treated as newly unsafe. Exceptional cases can still receive human moderation, and an explicit human Hide or Restore for the same content revision takes precedence over ordinary repeat scans.
Edits that leave the moderated public text unchanged can reuse a matching current safety decision. Changed public text or outdated automated decisions require another check.
Private moderation decisions, report details and abuse-attribution data do not appear in public story views.
Search engines and copies outside the service
Every published story is publicly reachable and shareable. Complete stories with suitable structured context can be eligible for the production sitemap; incomplete or unavailable stories are excluded.
Raw story text can appear in the body of an indexable public page because it is the public content. It is deliberately not copied into the page title, meta description, Open Graph description, Twitter description or site-generated native-share text by default.
Search engines, social networks, archive services and other people can cache, screenshot, quote or copy public information. Unpublishing, editing, switching to Anonymous or deleting the original story does not guarantee that third parties immediately remove copies they already made.
Private owner controls and browser recovery
The browser generates an ECDSA P-256 keypair when a story is created. The server receives and stores the public verification key. The reusable private signing key remains browser-side and is carried in the private management link after the URL fragment marker (#), which browsers do not send in ordinary page requests.
To recover interrupted publishing, this site saves the pending or recently completed submission in your browser's local storage. This includes the private management key, matching public key, submitted claim and recovery information. Submission recovery is valid for up to 24 hours from the original attempt. Expired entries are removed when you next use the recovery flow; browser storage can remain on disk until then or until you clear it.
Replacing a management link also temporarily saves replacement credential material in local storage while the change is confirmed. Anyone with access to the same unlocked browser profile may be able to recover a private management link during that short window.
Keep the private management link private. Anyone who obtains a usable private key can exercise owner controls. Flex Your Income does not have an account, email recovery or a server-side copy of that private key to send back to you.
Security and anti-abuse processing
Cloudflare delivers and protects the service and necessarily processes network and request information such as IP addresses, headers and browser/security signals as part of that infrastructure.
Submission and report writes use Cloudflare Turnstile and rate limiting. Voting uses dedicated rate limits without a Turnstile challenge on every vote. When a protected write reaches the anti-abuse boundary, the service may set a first-party __Host-fyi_abuse cookie for up to 90 days. It is a pseudonymous abuse-correlation token, not an analytics identifier.
Ordinary public browsing does not create that abuse cookie. If a security dependency needed for a protected action is unavailable, the action is refused rather than bypassing the protection.
Community votes
Voting creates or reuses the pseudonymous abuse cookie. The database stores a derived actor hash, the story it relates to, active or removed state and the first effective vote time. It does not store your raw cookie or IP address as voter identity, and does not link votes to a private management key or analytics identity. Public pages show aggregate counts, not voter identities.
Removing a vote removes its influence from community popularity. A private inactive record remains for unchanged content so removing and re-adding a vote cannot make it look newly popular. Material changes to displayed content clear its vote history; permanently deleting the story also deletes that history. Hiding or unpublishing unchanged content preserves it.
The cookie's 90-day expiry does not itself delete server-side vote history. Clearing or losing the cookie can prevent this browser from recognising or removing its earlier vote. Checking your existing vote does not create a new cookie. Votes do not verify claims.
Optional analytics
Product analytics is opt-in. Until you choose to allow analytics, the browser does not send Flex Your Income analytics events. Your consent choice is stored locally so the site can remember it, and you can reopen Analytics preferences from the footer and withdraw consent later.
After consent, the browser creates a random session identifier. The analytics provider can group events inside that session, but Flex Your Income does not deliberately reuse a stable analytics identifier to join one browser session to another.
To distinguish new from returning consented visits without creating a persistent person ID, the browser keeps a simple analytics-specific visited-before marker. To count different stories read within one session without sending story identity to the analytics provider, the browser also keeps a bounded session-local set of one-way hashes of story paths.
If production analytics is enabled, allowed events are forwarded through the Flex Your Income server to a separate FlexYourIncome PostHog project using PostHog's EU ingestion endpoint. Analytics excludes raw money amounts, free text, display names, flex slugs, owner credentials, report text, moderation notes, Access identity and abuse/voter identifiers. Voting analytics records only coarse actions and product surfaces, not the story voted on or the actor.
Analytics can fail or be disabled without preventing publishing, sharing, reporting, voting or owner management.
Advertising, payments and tips
Advertising, tips and payments are not currently enabled. Flex Your Income therefore does not currently collect payment-card or bank details through those features.
If the service's data handling changes materially, this notice will be updated before the new handling is relied on.
Deletion, retention and recovery copies
Unpublishing makes a story unavailable to ordinary public reads but keeps it so the owner can publish it again when allowed. Permanent deletion removes the live story and linked owner-control, report, moderation, abuse-attribution and vote state.
Short-lived retry, moderation-attempt, challenge and link-replacement records have explicit expiry times and are pruned by scheduled maintenance. The browser abuse cookie has its own 90-day lifetime and is not the same thing as a particular story or vote record.
Cloudflare D1 provides point-in-time disaster recovery. Historical database states may remain recoverable for a limited provider-defined window even after a row is removed from the live database.
Deletion cannot erase screenshots, search-engine caches, social previews or other copies already held by third parties.
Where data is processed
Flex Your Income is operated in Australia, but the service uses third-party infrastructure including Cloudflare for hosting, security and automated content safety and — when you opt in and analytics is enabled — PostHog. Those providers may process or store data outside Australia. The service does not promise Australian-only data residency.
Access, correction, removal and privacy questions
If you still have your private management link, use it to edit, unpublish or permanently delete your own story. If a public story exposes someone else's information or otherwise breaks the rules, use the Report action on that story.
For privacy questions, removal requests you cannot complete through owner controls, or concerns about how information is handled, see Contact and removal or email privacy@flexyourincome.com.
Please do not send payslips, tax records, identity scans or similarly sensitive documents in an initial email. The service does not need a surprise dossier arriving in an inbox to prove that privacy matters.