Privacy Policy
LOX is designed so that we cannot see your files, even if we wanted to. This policy explains what little personal data we do process, why, and the rights you have under the EU General Data Protection Regulation (GDPR). Because birch ave is established in Germany, the policy follows the structure of a German Datenschutzerklärung.
1. Controller
The controller responsible for data processing within the meaning of the GDPR is:
Andreas Schulz
birch ave
Birkenallee 24
14621 Schönwalde-Glien
Germany
Email: andel@birch-ave.com
Phone: +49 15678 337083
2. Our approach
LOX is end-to-end encrypted. The encryption key is derived on your device from your passphrase and never leaves it. We do not hold the key, cannot recover it, and never see it. The app itself is offline: it sends no data to any server we operate, because we operate none for it. Anything you choose to back up to a cloud provider of your own is ciphertext, unreadable without your key. This is the structural reason the rest of this policy is short: there is very little personal data for us to process in the first place.
3. Data processed on this landing page
This landing page is deliberately data-minimal. We do not set cookies, we do not embed analytics, advertising, social-media plug-ins, external fonts, or third-party CDNs. All content is served directly from our hosting provider.
When you visit the site, our hosting provider records technical data in server logfiles that your browser transmits automatically:
- IP address of the requesting device (shortened or anonymised where technically possible)
- Date and time of the request
- Name and URL of the file retrieved
- Amount of data transferred and a success/failure code
- Browser and operating system
- Referrer URL (the page previously visited)
These logs are processed solely for the purpose of operating, securing, and technically optimising the website. They are not merged with other data sources or used for marketing. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a stable and secure website). Logs are deleted or anonymised after at most 30 days.
4. Data processed in the LOX app
LOX is a native application for Android and Windows, obtained from Google Play or the Microsoft Store. It is local-first: your files, document metadata, passphrase and quick-unlock PIN live on your device only. They are not uploaded to us, and we cannot read them. The app contacts no server of ours, so no usage data, telemetry, crash reports, or analytics reach us from it.
The app stores through which LOX is distributed are independent controllers for the data they collect when you download or purchase an app — your store account, device, and transaction details. That processing is governed by their own privacy policies, not this one. From them we receive only aggregated, non-identifying statistics such as download and crash counts.
5. Data processed by cloud backup and sharing
Cloud backup is opt-in per vault and switched off by default. When you enable it for a vault, encrypted blobs from that vault are uploaded to a storage account you connect yourself — your Google Drive, Dropbox, or OneDrive. The provider sees only ciphertext; the encryption key remains on your device. We are not involved in that transfer: it runs directly between the app and your provider, under your own contract with them. Vaults you do not opt in stay strictly on your device.
6. Sharing a vault with someone else
When you share a vault, the recipient receives an encrypted copy with its own passphrase, delivered via QR code. No key material passes through us — we run no servers in that path — and we cannot read the contents of shared vaults. You are responsible for whom you share with and for revoking access when appropriate.
7. Contacting us by email
If you email us, the information you provide (your email address, optionally your name and phone number, and the content of your message) is stored and used solely to handle your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures / performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Your data is deleted once it is no longer required and no statutory retention period stands in the way.
8. Recipients and processors
To operate the service we rely on the following processors:
- Netlify — hosting of this landing page. This is the only processor acting on our behalf.
Two further parties process data in connection with LOX, but not as our processors:
- Google and Microsoft — distribution of the app through their stores, as independent controllers (see section 4).
- Your own cloud provider (Google Drive, Dropbox, or OneDrive) — storage of encrypted backups, under the account and contract you hold with them (see section 5).
We do not transfer personal data to other recipients beyond what is necessary to operate the service.
9. Your rights as a data subject
Where we process personal data about you, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw a given consent (Art. 7(3) GDPR)
To exercise your rights, an informal message to andel@birch-ave.com is enough.
10. Right to lodge a complaint with a supervisory authority
Under Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority if you believe the processing of your personal data infringes the GDPR. The competent authority is the supervisory authority of the federal state in which the controller is established: [COMPETENT STATE SUPERVISORY AUTHORITY].
11. Validity of this privacy policy
Last updated: August 2026. We may need to adapt this policy as the service evolves or as legal requirements change. The current version is always available on this page.