Lox — Privacy Policy

Last updated: 25 September 2026

Lox is built so that as little of your data as possible ever leaves your device. This page says exactly what does, and why.

1. Who is responsible

The data controller is [OWNER: registered legal entity name], [OWNER: registered address], Croatia. Contact: [OWNER: contact email].

2. What stays on your device

3. What we process on our servers

We do not sell your data, do not show ads, and do not use third-party tracking or analytics SDKs.

4. Legal bases

We process account and subscription data to perform our contract with you (GDPR art. 6(1)(b)); technical logs and abuse prevention under our legitimate interest in running a secure service (art. 6(1)(f)); anything based on consent only after asking.

5. Who receives data

RecipientRoleWhat
Microsoft AzureDatabase hostingAccount data, entitlement state, usage counters
netcup GmbH (Germany)Server hostingEverything our API processes, transiently; server logs
RevenueCat, Inc. (USA)Subscription managementPurchase/entitlement events from Google Play, linked to your account id
Google (Play, Sign-In; Gemini API)Billing; optional sign-in; Premium answersPlay handles payment; Gemini receives questions + excerpts, sent under our key without your identity
OpenAI (USA)Premium book indexingBook excerpts for embedding, sent under our key without your identity
SMTP2GOEmail deliveryYour email address and the content of verification/reset emails

AI providers receive the text needed to answer — never your name, email or account identity; our servers make those calls under our own provider accounts. Where a recipient processes data outside the EEA, the transfer rests on the European Commission's standard contractual clauses or an adequacy decision.

6. Retention

Account data is kept until you delete your account, then removed. Usage counters are kept per billing month. Logs are kept for [OWNER: log retention, e.g. 30 days]. Backups age out on a fixed schedule.

7. Your rights

Under the GDPR you can ask for access, correction, deletion, restriction, portability, and object to legitimate-interest processing. Delete your account directly in the app's settings or at api.loxreader.app/account/delete. For anything else, email [OWNER: contact email]. You can complain to your data-protection authority; in Croatia that is AZOP (azop.hr).

8. Security

All traffic uses TLS. Passwords are stored only as salted hashes. Secrets and provider keys are held in server-side configuration with restricted access. The database is encrypted at rest by Azure.

9. Children

Lox is not directed at children under 16, and we do not knowingly process their data.

10. Changes

We will announce material changes to this policy in the app or by email before they take effect.