Privacy Policy
LOX is designed so that we cannot see your files, even if we wanted to. This policy explains what little personal data we do process, why, and the rights you have under the EU General Data Protection Regulation (GDPR). Because birch ave is established in Germany, the policy follows the structure of a German Datenschutzerklärung.
1. Controller
The controller responsible for data processing within the meaning of the GDPR is:
Andreas Schulz
birch ave
Birkenallee 24
14621 Schönwalde-Glien
Germany
Email: andel@birch-ave.com
Phone: +49 15678 337083
2. Our approach
LOX is end-to-end encrypted. The encryption key is derived on your device from your passkey or passphrase and never leaves it. We do not hold the key, cannot recover it, and never see it. Anything that ever reaches our infrastructure — or that of any third party we use — is ciphertext, unreadable without your key. This is the structural reason the rest of this policy is short: there is very little personal data for us to process in the first place.
3. Data processed on this landing page
This landing page is deliberately data-minimal. We do not set cookies, we do not embed analytics, advertising, social-media plug-ins, external fonts, or third-party CDNs. All content is served directly from our hosting provider.
When you visit the site, our hosting provider records technical data in server logfiles that your browser transmits automatically:
- IP address of the requesting device (shortened or anonymised where technically possible)
- Date and time of the request
- Name and URL of the file retrieved
- Amount of data transferred and a success/failure code
- Browser and operating system
- Referrer URL (the page previously visited)
These logs are processed solely for the purpose of operating, securing, and technically optimising the website. They are not merged with other data sources or used for marketing. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a stable and secure website). Logs are deleted or anonymised after at most 30 days.
4. Data processed in the free LOX app
The free tier of LOX is local-first. Your files, document metadata, passkey, and recovery phrase live on your device. They are not uploaded to us and we cannot read them. The PWA host only serves the static application shell — the same files for every visitor — and generates the server logs described above.
5. Data processed in the Sync & Share add-on
The optional Sync & Share add-on is opt-in per vault. When you enable it for a vault, encrypted blobs from that vault are uploaded to storage providers. The provider sees only ciphertext; the encryption key remains on your device. Vaults you do not opt in stay strictly local.
Subscriptions for Sync & Share are handled by our payment processor, Stripe, which collects the billing email and payment token needed to process the transaction. We receive a subscription status and a customer reference but not your full payment details. Legal basis: Art. 6(1)(b) GDPR (performance of the subscription contract).
6. Sharing a vault with someone else
When you share a vault, the recipient receives an encrypted copy with its own passphrase, delivered via QR code. No shared key material transits our servers and we cannot read the contents of shared vaults. You are responsible for whom you share with and for revoking access when appropriate.
7. Contacting us by email
If you email us, the information you provide (your email address, optionally your name and phone number, and the content of your message) is stored and used solely to handle your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures / performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Your data is deleted once it is no longer required and no statutory retention period stands in the way.
8. Recipients and processors
To operate the service we rely on the following processors:
- Netlify — hosting of this landing page and the LOX web app shell.
- cloud providers (Google Drive, Dropbox) — encrypted blob storage for the Sync & Share add-on.
- Stripe — subscription billing for the Sync & Share add-on.
We do not transfer personal data to other recipients beyond what is necessary to operate the service.
9. Your rights as a data subject
Where we process personal data about you, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw a given consent (Art. 7(3) GDPR)
To exercise your rights, an informal message to andel@birch-ave.com is enough.
10. Right to lodge a complaint with a supervisory authority
Under Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority if you believe the processing of your personal data infringes the GDPR. The competent authority is the supervisory authority of the federal state in which the controller is established: [COMPETENT STATE SUPERVISORY AUTHORITY].
11. Validity of this privacy policy
Last updated: May 2026. We may need to adapt this policy as the service evolves or as legal requirements change. The current version is always available on this page.