Privacy Policy
Version 3 · Last updated April 30, 2026
1. Who We Are
Relocat ("we", "us", "our") operates the Relocat platform — an end-to-end encrypted document storage and sharing service. We act as the data controller for the personal data described in this policy.
Relocat is currently operated as a pre-incorporation European initiative. Full operator identification and service-of-process details are published on the Imprint page and will be updated there when the operating entity is registered.
Contact: privacy@relocat.org
2. What Data We Collect
Account data
When you register, we collect your email address and a hashed device identifier. We do not collect your name, phone number, or postal address.
Device and session data
We store a unique device ID and its public cryptographic key to authenticate your requests. No private keys ever leave your device.
Server logs
Our servers log standard HTTP request data: IP address, timestamp, HTTP method and path, and user-agent string. These logs are used for security monitoring and abuse prevention and are retained as described in Section 6.
Encrypted files and metadata
We store the encrypted blobs you upload, along with encrypted metadata (file names, sizes). We store these as opaque binary objects — we cannot read their contents.
AI-assistant activity (optional feature)
If you enable the optional AI-assistant integration (MCP), we keep an activity log of assistant requests — which tool was invoked, when, and whether you approved it — and signed consent receipts recording each approval you grant. These records contain operational metadata only, never file contents or file names. They exist so you can audit what an assistant did on your account and so consent decisions remain provable. Retention is described in Section 6. If you never enable the AI features, none of this data exists.
Community signals (optional feature)
If you opt in to Community Sharing, the app contributes aggregate, non-identifying signals from people on similar journeys. This is off unless you enable it, and you can turn it off at any time in Settings → Privacy.
Crash and diagnostics reporting
Current releases transmit no crash reports and no diagnostics — the app keeps a local, user-viewable diagnostics log on your device only. If a future version introduces crash reporting, it will be strictly opt-in and this policy will be updated before such a version ships.
3. What We Cannot Access
Relocat is a zero-knowledge platform. All file content, file names, and metadata are encrypted on your device before being sent to our servers, using keys that never leave your device. This means:
- We cannot read your files or their names.
- We cannot read any metadata you store in your vault.
- We cannot comply with requests to disclose file contents, because we technically cannot access them.
This is not a policy choice — it is a cryptographic guarantee built into the platform architecture.
4. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Contract (Art. 6(1)(b)): Processing your email and device credentials is necessary to provide the Relocat service you have registered for.
- Legitimate interest (Art. 6(1)(f)): Retaining server logs for up to 90 days is necessary for security monitoring, abuse prevention, and incident response. We have assessed that this interest does not override your fundamental rights given the short retention period and the absence of profiling.
- Consent (Art. 6(1)(a)): The optional features described in Section 2 — AI-assistant activity and community signals — process data only after you enable them. You can withdraw consent at any time in the app's privacy settings; withdrawal stops future processing.
5. Third-Party Processors and Recipients
We use the following sub-processors to operate the Service:
- Amazon Web Services (AWS) — cloud object storage in the EU (Frankfurt) region. Only encrypted blobs are stored; the processor cannot decrypt them. Data processing agreement in place per GDPR Art. 28.
- Transactional email delivery — one-time codes and service notifications are sent to your email address through our email delivery provider, which processes the recipient address and message content solely to deliver the message on our behalf.
AI providers you connect
If you use the optional AI-assistant integration, the AI provider you connect (for example, the vendor of your chosen assistant) receives only the metadata categories you have explicitly approved — never file contents. That provider is a recipient you choose and direct, not a sub-processor acting for us; its handling of data is governed by your agreement with it. You can revoke its access at any time, and every disclosure is recorded in your activity log.
We do not share personal data with any other third parties, sell data, or use it for advertising.
6. Data Retention
- Account and device data: Retained for the duration of your account. Deleted within 30 days of account deletion.
- Encrypted vault data: Retained until you delete it or your account is deleted.
- Server logs: Retained for up to 90 days, then rotated out by our log infrastructure.
- Share and guest link access logs: Access records (IP address, country, user-agent, and result) are retained for up to 90 days for security auditing and anomaly detection, then deleted automatically.
- AI-assistant activity and consent receipts: Retained for up to 13 months from creation, then purged automatically. Deleting your account deletes both immediately, together with the rest of your data. If you ask us to delete your assistant activity log while keeping your account, the signed consent receipts are retained separately for the remainder of the 13-month window — they are the auditable proof of the approvals you granted — and they contain no vault contents.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Ask us to correct inaccurate data.
- Right to erasure (Art. 17): Ask us to delete your account and associated data.
- Right to data portability (Art. 20): Receive your account data in a machine-readable format.
- Right to restrict processing (Art. 18): Ask us to pause processing in certain circumstances.
- Right to object (Art. 21): Object to processing based on legitimate interest.
To exercise any of these rights, contact us at privacy@relocat.org. We will respond within one month.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22).
You also have the right to lodge a complaint with your local data protection supervisory authority.
8. Data Protection Inquiries
No Data Protection Officer is currently appointed. If one is appointed, their contact details will be published here and on the Imprint page. For all data-protection inquiries, contact privacy@relocat.org.
9. Cookies and Tracking
The Relocat guest file sharing page (/g/) uses no cookies, no tracking pixels, and no analytics scripts. The professional web panels (admin, moderator, partner, KG editor) use a session cookie strictly necessary for signing in — no consent is required under the ePrivacy Directive for strictly necessary cookies — and the community web app at /app/ sets no cookies at all.
We do not use advertising cookies, behavioral tracking, or third-party analytics on any page. Full details are on the Cookies and local storage page.
10. International Transfers
Encrypted data may be stored in the EU (Frankfurt) region. All transfers within the storage processor's infrastructure are covered by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c).
11. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. We will notify registered users by email of any material changes at least 14 days before they take effect. The version number and last updated date at the top of this page always reflect the current version.
Change log
- Version 3 (July 2026): Disclosed the transactional email delivery sub-processor; removed an inaccurate IP-truncation claim (request logs are retained as described in Section 6); share and guest link access records are now deleted automatically after 90 days; added an automated decision-making statement (GDPR Art. 22); aligned the rights-response window with the statutory one month.
- Version 2 (July 2026): Disclosed the optional AI-assistant activity log and signed consent receipts (13-month retention), community signals, and the current no-crash-reporting status; distinguished user-directed AI recipients from our sub-processors; moved operator identification to the Imprint page; aligned log-retention wording at 90 days everywhere.
- Version 1 (April 2026): Initial policy.
12. Contact
For any privacy-related questions or to exercise your rights: privacy@relocat.org