Privacy Policy

Last updated: September 10, 2026

How RonikCloud processes account, billing, storage, support, security, and diagnostics data.

Optional website analytics and device storage

Essential browser and device storage supports authentication, encryption, security and your settings. The website also offers optional Google Analytics, disabled until you enable it using Privacy & cookies. Google Analytics can store _ga cookies and receive technical connection information. Our analytics configuration does not intentionally send account identifiers, file names, folder paths, query strings or URL fragments, and advertising personalization is disabled.

Your optional analytics choice is stored on this browser for 180 days. You can accept, reject or customize it, and withdraw it later using Privacy & cookies. Withdrawal disables collection and removes accessible Google Analytics cookies on this site; it does not erase information already received by Google. This optional website integration does not add a Google Analytics SDK to native desktop or mobile apps. Optional website marketing-source measurement and its session storage follow this same consent choice. Essential service and security processing is separate.

1. Scope and Controller

This Privacy Policy applies to RonikCloud accounts, apps, websites, billing, storage, backups, support, diagnostics, and security operations. The data controller is Tomáš Názler, 24. dubna 145, Zeleice 664 43, Czech Republic.

2. Data We Process

3. Why We Process Data

4. Providers and Transfers

RonikCloud uses providers including Firebase/Google Cloud, Wasabi, Stripe, Resend for permitted product updates and necessary service, privacy, security, or support operational notifications, GitHub for release operations, and infrastructure providers needed to host or secure the service.

Our production Firestore database is located in the United States multi-region (nam5), verified on 10 September 2026. Running Cloud Functions in Europe does not mean all account and file metadata stays in Europe. Ask support@ronikcloud.com for information about applicable transfer safeguards and how to obtain a copy. We do not promise EU-only storage.

Providers may process data in more than one country. Stripe documentation requires merchants to disclose that payment data may be transferred, processed, and stored outside a customer location where applicable.

Legal Bases and Your Choices

5. Your Rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of personal data. Where GDPR applies, we respond without undue delay and within one month of receiving a request. If its complexity or number permits an extension, we notify you within the first month with the reasons; the extension cannot exceed two further months. Requests are normally free of charge.

Send privacy requests to support@ronikcloud.com. We may need to verify your identity before acting on a request.

You can complain to a data-protection supervisory authority, particularly in your country of habitual residence, place of work or the alleged infringement. In the Czech Republic, contact the Úřad pro ochranu osobních údajů at https://uoou.gov.cz/. You do not have to complain to us first, and judicial remedies remain available.

You may object to direct marketing at any time, free of charge. Where consent is the legal basis, you may withdraw it at any time. If a request is refused, we explain the reason and your complaint and judicial-remedy options within the applicable deadline.

6. Retention and Deletion

Retention rules are described in the Data Retention Policy. A pending account-closure request remains until automated processing or support resolves it; it has no automatic expiry because deleting an unhandled request could defeat the user's request. After audited resolution, the request record is assigned an expiry 90 days after resolution. Scheduled maintenance may remove it after that expiry time. Completing account closure requests deletion of linked Stripe customer profiles and their reusable payment details. App-store payment credentials remain controlled by the store account. Some transaction records, logs, invoices, fraud records, provider backups, organization-owned workspace data, or records required for accounting, security, dispute resolution, or legal compliance may remain for a limited period after account deletion. After deletion succeeds, the pseudonymous long-lived deletion guard is assigned an expiry 400 days after completion solely to suppress delayed billing activity. The minimal Firebase-user-ID-addressed profile and rule-enforcement tombstones are assigned a 48-hour expiry. If closure is incomplete and authentication remains, closing-state deletion and enforcement records remain until the user retries or support safely resolves the deletion; removing them sooner could allow already-issued sign-in tokens to recreate data. Scheduled maintenance removes completed-deletion records after expiry, and a delayed maintenance run may complete removal after the expiry time.

7. Contact

Privacy questions or requests can be sent to support@ronikcloud.com or by post to Tomáš Názler, 24. dubna 145, Zeleice 664 43, Czech Republic.