Privacy policy
Last updated: 10 July 2026
Controller: Matthias Bregenzer, In der Ziegelei 4, 55566 Bad Sobernheim, Germany
Contact: [email protected]
1. Overview
RemoteGuard only processes the data needed to run and operate the app: managing electronic locks and granting access rights. The app shows no ads, and no data is sold for advertising.
2. What data we process
- Account and profile data: email address, display name, role and, if you add one, profile picture.
- Lock data: name/alias, technical identifier (e.g. MAC), protocol type.
- Lock credentials: stored encrypted; processed only within authorized lock functions and never shown to keyholders in plain text.
- Shares & actions: invitations, active shares and a log of executed lock actions.
- Messages, photos and reports: contents of the in-app chat and shared photos between the parties of a share (end-to-end encrypted). We do not routinely read this content. If a user submits a report, the reported content and the information in the report are made available to authorised RemoteGuard reviewers only to assess that report and enforce our community rules.
- Technical, notification and support data: device and connection data necessary for operating the app and preventing abuse, push-notification token and settings, as well as information you provide in a support request.
- Subscription and payment status: product, billing period, store transaction identifier and subscription status. We do not process full payment details when the purchase is made through Apple or Google.
- Newsletter data: email address, consent status, double-opt-in confirmation, list membership and the technical data needed to deliver newsletters.
3. Purpose and legal basis
Processing serves to provide the app’s functions (performance of a contract, Art. 6(1)(b) GDPR). We process newsletter data on the basis of your consent (Art. 6(1)(a) GDPR); you can withdraw this consent at any time, for example through the unsubscribe link in a newsletter. For security logs, abuse prevention, handling reports, enforcing our community rules, operating the website and handling requests, we process data based on our legitimate interest (Art. 6(1)(f) GDPR); where a request relates to a contract, also Art. 6(1)(b) GDPR.
4. Processors / hosting
- Website hosting: the static website (remoteguard.app) is hosted on Cloudflare Pages (Cloudflare, Inc., USA), with which a data processing agreement (Art. 28 GDPR) is in place. When the site is accessed, Cloudflare processes technical connection data (including the IP address) in server logs to deliver the site securely and reliably. Transfers to the USA are covered by the EU-US Data Privacy Framework and EU Standard Contractual Clauses.
- App backend: the backend and database run on Supabase (Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992) under a data processing agreement. Data is hosted in a region within the EU (on Amazon Web Services (AWS) infrastructure as Supabase’s sub-processor); any international transfer is safeguarded by EU Standard Contractual Clauses.
- Subscription management: purchases and subscriptions are managed via RevenueCat (RevenueCat, Inc., USA) under a data processing agreement. This processes purchase-related data such as an in-app user identifier, device and transaction identifiers and the subscription status. Transfers to the USA are safeguarded by EU Standard Contractual Clauses.
- App stores: a subscription is purchased through the Apple App Store or Google Play. They handle the payment as independent controllers under their own privacy terms; we do not receive full payment data, only information such as the subscription status and a transaction identifier.
- Push notifications: to send push notifications we use Firebase Cloud Messaging (Google Ireland Ltd. / Google LLC, USA) under a data processing agreement. A device token is processed to deliver notifications to your device; Firebase is used solely for push delivery, not for analytics or tracking. Transfers to the USA are safeguarded by EU Standard Contractual Clauses.
- Content moderation: RemoteGuard reviewers only receive access to the content and information included in a report when a user submits that report. This is necessary to assess reports and enforce our community rules; chat content is otherwise end-to-end encrypted and not routinely accessible to us.
- Email: if you contact us at [email protected], your message is processed by our email provider mailbox.org (Heinlein Hosting GmbH, Germany) on the basis of a data processing agreement.
- Newsletter: for newsletter subscriptions and delivery, we use Brevo (Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France) as a processor. Brevo processes your email address, consent and double-opt-in status, list membership and the technical data needed to send emails on our instructions. More information is available in Brevo’s Privacy Policy.
- Spam protection for the newsletter form: we use Cloudflare Turnstile from Cloudflare, Inc., USA to protect the newsletter form against automated submissions. For this purpose, Turnstile processes technical information about the browser and device, as well as IP-related connection data, to distinguish people from bots. This is based on our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR). More information is available in Cloudflare’s Privacy Policy and the Cloudflare Turnstile Privacy Addendum.
- Website analytics: we use Umami Cloud (Umami Software, Inc., USA; EU data region selected) to understand the reach and technical performance of our website. Umami processes privacy-friendly usage and technical data, such as page path, referring host, approximate location (country, region and city), device type, browser, performance metrics and basic interactions with website sections. We do not forward IP addresses to Umami. Umami does not use cookies, cross-site tracking or individual visitor profiles. We do not use the data for advertising. Processing is based on our legitimate interest in improving the website (Art. 6(1)(f) GDPR). More information is available in Umami’s Privacy Policy.
5. Retention
Account data is stored as long as your account exists or as long as it is needed for the stated purposes. Newsletter subscription data is retained until you withdraw your consent or unsubscribe. We may retain a minimal suppression record and proof of consent for as long as necessary to prevent future mailings and establish, exercise or defend legal claims. Reports and support requests are retained only as long as needed to handle them and for any applicable legal claims. On account deletion we delete the data unless statutory retention duties require further storage; backup copies are removed during the regular backup rotation. See Delete account.
6. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection. For this, contact [email protected]. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, work, or where the alleged infringement took place.
7. App permissions
Bluetooth is needed to find and operate supported locks nearby. Camera and photos are only used if you take or send a photo in the chat yourself. No location or advertising data is collected through them.
8. Security
Connections are encrypted via TLS/HTTPS. Security-critical lock credentials are stored encrypted, the in-app chat is end-to-end encrypted, and data access is limited by row-level isolation. A detailed, plain-language explanation is at Security & privacy.
9. Website: cookies, tracking and fonts
This website is intentionally data-minimal: fonts are self-hosted and we use no advertising technologies or marketing pixels. We use cookie-free Umami Cloud in its EU data region for privacy-friendly reach and performance measurement; the processing is described in section 4. The newsletter page additionally loads functional third-party resources from Brevo and Cloudflare Turnstile. Turnstile may use technically necessary browser storage or similar technologies to protect the form from bots. Technical server logs are processed by our host (see section 4) on the basis of our legitimate interest in operating the site securely (Art. 6(1)(f) GDPR).