Privacy Policy
Version 6 · Last updated September 3, 2026
1. Who We Are
Relocat ("we", "us", "our") operates the Relocat platform — an end-to-end encrypted document storage and sharing service. We act as the data controller for the personal data described in this policy.
Relocat is currently operated as a pre-incorporation European initiative. Full operator identification and service-of-process details are published on the Imprint page and will be updated there when the operating entity is registered.
Contact: privacy@relocat.org
2. What Data We Collect
Account data
When you register, we collect your email address and a hashed device identifier. We do not collect your name, phone number, or postal address.
Device and session data
We store a unique device ID and its public cryptographic key to authenticate your requests. No private keys ever leave your device.
Server logs
Our servers log standard HTTP request data: IP address, timestamp, HTTP method and path, and user-agent string. These logs are used for security monitoring and abuse prevention and are retained as described in Section 6.
Encrypted files and metadata
We store the encrypted blobs you upload, along with encrypted metadata (file names, sizes). We store these as opaque binary objects — we cannot read their contents.
AI-assistant activity (optional feature)
If you enable the optional AI-assistant integration (MCP), we keep an activity log of assistant requests — which tool was invoked, when, and whether you approved it — and signed consent receipts recording each approval you grant. These records contain operational metadata only, never file contents or file names. They exist so you can audit what an assistant did on your account and so consent decisions remain provable. Retention is described in Section 6. If you never enable the AI features, none of this data exists.
Community signals (optional feature)
If you opt in to Community Sharing, the app contributes aggregate, non-identifying signals from people on similar journeys. This is off unless you enable it, and you can turn it off at any time in Settings → Privacy.
Community Map profile (optional feature)
If you join the optional Community Map, we store a display name you choose and a city you select, and optionally a photo, in plain form. This is off unless you enable it, and you can leave the map at any time. See Section 11.
Crash and diagnostics reporting
Current releases transmit no crash reports and no diagnostics — the app keeps a local, user-viewable diagnostics log on your device only. If a future version introduces crash reporting, it will be strictly opt-in and this policy will be updated before such a version ships.
3. What We Cannot Access
Relocat is a zero-knowledge platform. All file content, file names, and metadata are encrypted on your device before being sent to our servers, using keys that never leave your device. This means:
- We cannot read your files or their names.
- We cannot read any metadata you store in your vault.
- We cannot comply with requests to disclose file contents, because we technically cannot access them.
This is not a policy choice — it is a cryptographic guarantee built into the platform architecture.
4. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Contract (Art. 6(1)(b)): Processing your email and device credentials is necessary to provide the Relocat service you have registered for.
- Legitimate interest (Art. 6(1)(f)): Retaining server logs for up to 90 days is necessary for security monitoring, abuse prevention, and incident response. We have assessed that this interest does not override your fundamental rights given the short retention period and the absence of profiling.
- Consent (Art. 6(1)(a)): The optional features described in Section 2 — AI-assistant activity, community signals, and the optional Community Map — process data only after you enable them. You can withdraw consent at any time in the app's privacy settings; withdrawal stops future processing.
5. Third-Party Processors and Recipients
We use the following sub-processors to operate the Service:
- Amazon Web Services (AWS) — cloud object storage in the EU (Frankfurt) region. Your vault content is stored there only as encrypted blobs that Amazon Web Services (AWS) cannot decrypt. If you add a photo to the optional Community Map (Section 11), that photo is stored there in plain form. Data processing agreement in place per GDPR Art. 28.
- Transactional email delivery — one-time codes and service notifications are sent to your email address through our email delivery provider, which processes the recipient address and message content solely to deliver the message on our behalf.
AI providers you connect
If you use the optional AI-assistant integration, the AI provider you connect (for example, the vendor of your chosen assistant) receives only the metadata categories you have explicitly approved — never file contents. That provider is a recipient you choose and direct, not a sub-processor acting for us; its handling of data is governed by your agreement with it. You can revoke its access at any time, and every disclosure is recorded in your activity log.
We do not share personal data with any other third parties, sell data, or use it for advertising.
6. Data Retention
- Account and device data: Retained for the duration of your account. Deleted within 30 days of account deletion.
- Encrypted vault data: Retained until you delete it or your account is deleted.
- Server logs: Retained for up to 90 days, then rotated out by our log infrastructure.
- Share and guest link access logs: Access records (IP address, country, user-agent, and result) are retained for up to 90 days for security auditing and anomaly detection, then deleted automatically.
- AI-assistant activity and consent receipts: Retained for up to 13 months from creation, then purged automatically. Deleting your account deletes both immediately, together with the rest of your data. If you ask us to delete your assistant activity log while keeping your account, the signed consent receipts are retained separately for the remainder of the 13-month window — they are the auditable proof of the approvals you granted — and they contain no vault contents.
- Community Map profile: Deleted immediately when you leave the map or delete your account. Exceptions: a photo held as evidence, and the record of that hold (Section 11).
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Ask us to correct inaccurate data.
- Right to erasure (Art. 17): Ask us to delete your account and associated data.
- Right to data portability (Art. 20): Receive your account data in a machine-readable format.
- Right to restrict processing (Art. 18): Ask us to pause processing in certain circumstances.
- Right to object (Art. 21): Object to processing based on legitimate interest.
To exercise any of these rights, contact us at privacy@relocat.org. We will respond within one month.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22).
You also have the right to lodge a complaint with your local data protection supervisory authority.
8. Data Protection Inquiries
No Data Protection Officer is currently appointed. If one is appointed, their contact details will be published here and on the Imprint page. For all data-protection inquiries, contact privacy@relocat.org.
9. Cookies and Tracking
The Relocat guest file sharing page (/g/) uses no cookies, no tracking pixels, and no analytics scripts. The professional web panels (admin, moderator, partner, KG editor) use a session cookie strictly necessary for signing in — no consent is required under the ePrivacy Directive for strictly necessary cookies — and the community web app at /app/ sets no cookies at all.
We do not use advertising cookies, behavioral tracking, or third-party analytics on any page. Full details are on the Cookies and local storage page.
10. International Transfers
Encrypted vault data, and any Community Map photo you add (stored in plain form, Section 11), may be stored in the EU (Frankfurt) region. All transfers within the storage processor's infrastructure are covered by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c).
11. Community Map (Optional Feature)
The Community Map is an optional feature that shows, to signed-in Relocat users, which cities other opted-in users have chosen to be listed in. The information you provide for it — a display name of your choosing, a city you select from a list and, if you add one, a photo — is stored in plain form on Relocat servers so that it can be shown to other users. It is not part of your encrypted vault and is not covered by Relocat's zero-knowledge guarantees. The app never requests or uses your device's location for this feature. A city is only shown once at least five opted-in users have chosen it. Profiles reported by other users may be hidden by a moderator. You can leave the map at any time; leaving deletes your community profile immediately and permanently. If a moderator has hidden your profile, a record of that decision is kept for as long as your account exists and is deleted with it. Reports you have filed about other members are kept on the same basis.
If you add a photo, it is stored unencrypted on Relocat servers and reviewed by a moderator before anyone else can see it; software produces advisory scores that a person reads, and no decision is automated. A photo that is not approved, or that you replace or remove, is deleted at that moment. A photo held as evidence of suspected illegal content is kept until the incident is closed, even after your account is deleted.
The photo itself is held for us by the storage processor named in Section 5, in plain form, in the same region as your encrypted vault data.
A record of each decision about a photo you submitted — the outcome, the reason shown to you, any advisory scores, and a digest of the image, but not the image itself — is kept while your community profile exists and is deleted when you leave the map or delete your account.
Every evidence hold carries a review date, initially 30 days after it is opened; extending it requires a recorded reason, and an overdue hold is flagged to us until it is closed or extended. When a hold is closed the photo is deleted. A record that the hold existed — including when it was opened and closed, the stated ground, the reasons for any extension, the notes our moderators made, any advisory scores recorded when the photo was reviewed, and a digest of the photo, but never the photo itself — is kept without a fixed time limit. Once your account is deleted, that record is no longer linked to you or to any account.
An upload that cannot be processed as an image — wrong format, too large, corrupt, or not matching what your app declared — is refused automatically, as is an upload that is started but never completed. These are technical checks, not decisions about you or the picture.
12. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. We will notify registered users by email of any material changes at least 14 days before they take effect. The version number and last updated date at the top of this page always reflect the current version.
Change log
- Version 6 (September 2026): Sections 5 and 10 now say that a Community Map photo is held by the storage processor in plain form — only vault content is encrypted. Section 11 says where the photo is held; that a record of each photo decision is kept while your community profile exists; that the record of an evidence hold — but not the photo — is kept without a fixed time limit and is no longer linked to you once your account is deleted; that a hold carries a 30-day review date; and which technical checks refuse an upload automatically. The photo is now listed among the data outside end-to-end encryption, and Section 6's exception names the hold record. The "last updated" date at the top of this page, which had not moved since the first version, is corrected.
- Version 5 (September 2026): Section 11 describes optional photos on the Community Map: a photo you add is stored unencrypted on Relocat servers and reviewed by a moderator before anyone else can see it; software produces advisory scores that a person reads, and no decision is automated. A photo that is not approved, or that you replace or remove, is deleted at that moment. A photo held as evidence of suspected illegal content is kept until the incident is closed, even after your account is deleted — the one exception to the Community Map profile's otherwise-immediate deletion (Section 6). Listed the optional photo in Section 2 (what we collect).
- Version 4 (August 2026): Added Section 11 describing the optional Community Map: the display name and city you provide for it are stored in plain form, are shown to signed-in Relocat users, are not part of your encrypted vault, may be hidden by a moderator if reported, and are deleted immediately when you leave the map. No device location is used. Section 11 also states that a moderator's decision to hide a profile, and any reports you file about others, are kept until your account is deleted. Listed the Community Map in Section 2 (what we collect), Section 4 (consent) and Section 6 (retention).
- Version 3 (July 2026): Disclosed the transactional email delivery sub-processor; removed an inaccurate IP-truncation claim (request logs are retained as described in Section 6); share and guest link access records are now deleted automatically after 90 days; added an automated decision-making statement (GDPR Art. 22); aligned the rights-response window with the statutory one month.
- Version 2 (July 2026): Disclosed the optional AI-assistant activity log and signed consent receipts (13-month retention), community signals, and the current no-crash-reporting status; distinguished user-directed AI recipients from our sub-processors; moved operator identification to the Imprint page; aligned log-retention wording at 90 days everywhere.
- Version 1 (April 2026): Initial policy.
13. Contact
For any privacy-related questions or to exercise your rights: privacy@relocat.org