Legal

Terms & Privacy

Last updated July 2026.

Terms of Use

FlockOff is a free tool that lets you mass-block accounts on the Atmosphere. By using it, you agree to use it responsibly and in accordance with the rules of the services you connect it to (e.g. Bluesky's Community Guidelines).

FlockOff is provided as-is, without warranty of any kind. We're not liable for blocks applied in error, accounts blocked unintentionally, or any consequences of using the tool. We encourage you to use the preview screen and relationship filters to review accounts before committing to a block.

All block and unblock actions are performed directly on your own account via the permissions you grant during sign-in. FlockOff never acts on your account without your explicit instruction.

We reserve the right to suspend access to FlockOff for accounts that misuse the tool (e.g. automated abuse, coordinated harassment campaigns).

Privacy Policy

What FlockOff accesses

When you sign in, FlockOff requests only the permissions needed for blocking:

  • atproto — read your DID and handle
  • repo:app.bsky.graph.block — create and delete block records on your behalf
  • repo:app.flockoff.blockEvent — create, read, and update FlockOff's own records in your repo (your block history)

If you use a list feature (sharing a block event as a public list, or importing and managing lists), FlockOff asks for additional permissions at that moment — you approve them on your identity provider and are brought right back:

  • repo:app.bsky.graph.list / listitem / listblock — create and delete block lists, add members, and manage list subscriptions

FlockOff does not access your posts, follows, DMs, or any other data beyond what's listed above.

What FlockOff stores server-side

FlockOff does not store your personal records or block history. The only server-side storage is:

  • An encrypted session cookie — stores your account identity and display information so you stay signed in. It expires when you sign out or after a period of inactivity and never leaves your browser in plaintext.
  • Temporary in-memory OAuth and job state — authorization credentials and active block-job progress are held in the running server process so FlockOff can perform the actions you request. This state is not written to a persistent application database and is lost if the server restarts.

Your block history, criteria, and all event data live in your own Personal Data Server (PDS)— not on FlockOff's servers. You own it and can inspect or delete it at any time.

Third parties

FlockOff reads public engagement data (likes, reposts, replies, quotes) from the configured AppView API — Bluesky's public AppView by default — and can only see content indexed there. No third-party analytics, ad networks, or tracking scripts are loaded.

How to revoke access

You can revoke FlockOff's access at any time from your identity provider's settings. On Bluesky: Settings → Privacy and Security → Connected Apps → FlockOff → Remove access. This immediately invalidates FlockOff's session and it will no longer be able to act on your account.

Contact

Questions about these policies? Email [email protected] or reach us on Bluesky at @flockoff.app.