Privacy Policy
Last updated: 17 August 2026
This policy explains what data relocating.app collects, why, how long we keep it, and the rights you have over it. We wrote it to be read, not to be skimmed past — if anything here is unclear, contact us (see Contact).
Who we are
relocating.app is operated by the relocating.app team (the “we”, “us”, “controller”). We run a global information service about relocation and a moderated community chat. We deliberately keep the service pseudonymous and collect as little personal data as we can.
We are the data controller for the personal data described here. We do not have a physical storefront; the way to reach us is the contact channel below.
Our privacy posture
We follow the GDPR as our baseline standard for everyone, everywhere — not only for EU residents. We chose GDPR because it is strict and gives you real, enforceable rights. This service is not aimed at any single country.
We practice data minimization. You can use the whole service — including cloud backup of your relocation profile and tool progress — completely anonymously: no email, no name, no login. If you later choose to sign in (to sync across devices, or to join the community chat), the only directly identifying data we use is your email address. Inside the community you are pseudonymous — other users see a display name, not your real identity.
What we collect
By default the service is anonymous and none of the directly-identifying data below is collected — only pseudonymous backup data you create (your saved destination, tool progress) tied to a random account id. The rows below apply once you opt into email sign-in or the community chat:
| Data | Why we have it | Source |
|---|---|---|
| Email address | Account login, password reset, essential service notices | You, if you sign in |
| Display name | So you can be identified inside the community chat | You |
| Password hash | To authenticate you (we never store the plaintext password) | Derived at signup |
| Community messages | To operate the chat and let others read what you post | You, when you post |
| Moderation records | Reports, warnings, mutes, bans — to enforce the rules and keep an audit trail | You and moderators |
| Hashed IP address | Abuse prevention, rate limiting, ban evasion detection | Automatic, at request time |
| Basic technical logs | Security and debugging (timestamps, error traces, coarse request metadata) | Automatic |
We do not collect: your legal name, phone number, home or mailing address, government IDs, payment card data, precise location, or advertising identifiers. We do not run third-party advertising or behavioural tracking, and we do not sell or rent personal data to anyone.
Legal basis for processing
Under GDPR Article 6, we rely on:
- Contract (Art. 6(1)(b)) — to create and run your account and deliver the chat you signed up for. This covers your email, display name, password hash, and messages.
- Legitimate interests (Art. 6(1)(f)) — to keep the service safe: abuse prevention, moderation, rate limiting, and security logging. This covers hashed IPs, moderation records, and technical logs. We limit these interests to what safety actually requires.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with a valid legal requirement.
- Consent (Art. 6(1)(a)) — for anything optional (e.g. turning on cloud backup, or a non-essential mailing). You can withdraw consent at any time, and we will not condition the core service on it.
Processors we use
We host and run the service through a small set of vendors (“processors”). Each processes data only on our instructions, under a data processing agreement:
- Supabase (self-hosted, EU region) — database, authentication, and storage. All user data lives on infrastructure we operate in the EU.
- Moderation API provider — automated screening of chat content for prohibited material (e.g. CSAM, harassment, spam) before and after it is posted. Message text and limited metadata are sent for classification; results feed our enforcement.
- Transactional email sender — delivers account emails (verification, password reset, essential notices) if you sign in with email. Receives your email address and the message content.
We keep this list current. If a processor changes, we update this page.
Where your data is stored
Primary storage is in the European Union. Where a processor operates outside the EU, we rely on appropriate safeguards under GDPR Chapter V (such as Standard Contractual Clauses or an adequacy decision) before any transfer.
How long we keep it
We delete or anonymize data on fixed schedules, not “whenever we get around to it”:
- Community messages — retained while the community needs the context, then anonymized after 18 months: the message content is detached from your account and any identifiers, so it can no longer be traced back to you.
- Hashed IP addresses — deleted after 90 days.
- Inactive accounts — if you do not return for 24 months, we delete the account and its personal data.
- Moderation records — kept as long as needed to enforce bans and prevent evasion, then removed.
- Technical logs — rotated on a short cycle (days to weeks) unless a specific security investigation requires holding a record longer.
When you delete your account or your cloud backup, see the erasure timeline below — it overrides the schedules above for your personal data.
Your rights
Under GDPR you can, at any time:
- Access / export your data — request a machine-readable export (DSAR) of the personal data we hold about you.
- Rectify inaccurate data — or just edit it in your account.
- Erase your data — request deletion (see timeline below). If you use cloud backup, “Delete cloud data” on your account page erases it immediately.
- Restrict or object to processing based on legitimate interests.
- Withdraw consent where processing is based on consent.
- Complain to your local data protection authority.
How we handle requests:
- Data export (DSAR): we provide your export within 30 days.
- Erasure: once you request deletion (or delete your account/backup), we erase your personal data within 30 days. Content you posted publicly in the chat is either deleted or anonymized so it can no longer be linked to you; we may retain a minimal record where a legal obligation or active abuse investigation strictly requires it, and we will tell you if so.
We do not charge for these requests and we will not make you jump through hoops.
Children
The service is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has an account, contact us and we will remove it.
Security
Passwords are stored only as salted hashes. IP addresses are hashed. Data in the EU is encrypted in transit and at rest. Access to production data is limited to what operating the service requires. No system is perfectly secure, but we design for minimal blast radius: the less we hold, the less there is to lose.
Changes to this policy
If we make a material change, we will post the new version here with an updated date and, for significant changes, notify account holders. Continued use after a change means you accept the updated policy.
Contact
For any privacy question, complaint or to exercise a right, email us at [email protected]. We aim to respond to every request within 30 days.