Skip to main content

Hosted FMD Server

The FMD Team provides two hosted instances of FMD Server, available at https://server.fmd-foss.org and https://server-edge.fmd-foss.org. These instances are publicly accessible and free to use. This page describes the usage policy for these instances.

General Resources​

Ethical use​

You are only permitted to register, log in, and use accounts on the hosted instances for devices that:

  1. You are the primary user of, or
  2. The primary user has given you explicit permission.

Do not use FMD Server to attempt to control the devices of other people without their knowledge and consent.

Fair use​

Only use the hosted instances of FMD Server for their intended purpose (== locating and controlling your device). You are welcome to register multiple accounts, especially if you own multiple devices (phone, tablet, ...).

If we detect excessive use or abuse of the service, we reserve the right the block you.

Data Retention​

danger

Shorter retention limits will apply for the 0.x🠪1.x upgrade of the hosted FMD Server instances. This upgrade is planned for early 2027. Please follow the blog or the announcements channel on Matrix to receive the latest information.

Normal Usage​

The hosted instances are configured with MaxSavedLoc: 300 and MaxSavedPic: 10. This means that under normal usage conditions, they will keep the last 300 locations and last 10 pictures for each account. All previous data will automatically be deleted.

Ceased Usage​

This section describes how long we keep unused accounts before they are cleaned up and removed.

  • 365 days (1 year) without activity: We may delete stored data, such as locations and pictures. The account itself is not deleted.
  • 730 days (2 years) without activity: We may delete the account.

To put this into context, here is some background information:

  • FMD Server stores a LastSeenTime Unix seconds timestamp for each account. This value is updated every time an authenticated request is made, for example, when FMD Android downloads the list of pending commands (which might be an empty list). This allows administrators to detect that an account is unused.
  • Since the push URL of an account is stored in plaintext, administrators can send a push message to the client (FMD Android). This causes the client to request the list of pending commands. This way, the administrator can force clients to contact the server, thus refreshing the LastSeenTime. (Note that administrators cannot execute commands on clients).
  • Push servers usually cache the push message for some time (the duration varies by server). Therefore, even if the client is offline when a push message is sent, the message can still be delivered when the client comes online again a few hours or a day after.

Deleting data is done in form of a cleanup week. Cleanup weeks are irregular. They are held when administrators deem it necessary. A cleanup week works as follows:

  1. Day 1: Identify all accounts without activity for N years. Send a push message to all of these accounts.
  2. Day 4: Identify all accounts without activity for N years. Send a push message to all of these accounts.
  3. Day 7: Identify all accounts without activity for N years. Delete their data or the account itself (dependening on N).
tip

The Connectivity Check feature in FMD Android ensures that your LastSeenTime remains up-to-date (as a side-effect of checking that the server is still reachable). Every connectivity check results in an authenticated request to FMD Server.

Backups​

Backups are retained for 6 months.

If you manually and explicitly delete data (locations, pictures) or delete your entire account, these are deleted from the production database immediately. However, the data remains in backups until the backup is rotated and deleted. (Note that location/picture data is encrypted by a key only known to you, both in the production database and in the backups.)