← back

Privacy Policy

LOX is designed so that we cannot see your files, even if we wanted to. This policy explains what little personal data we do process, why, and the rights you have under the EU General Data Protection Regulation (GDPR). Because birch ave is established in Germany, the policy follows the structure of a German Datenschutzerklärung.

1. Controller

The controller responsible for data processing within the meaning of the GDPR is:

Andreas Schulz
birch ave
Birkenallee 24
14621 Schönwalde-Glien
Germany
Email: andel@birch-ave.com
Phone: +49 15678 337083

2. Our approach

LOX is end-to-end encrypted. The encryption key is derived on your device from your passphrase and never leaves it. We do not hold the key, cannot recover it, and never see it. The app itself is offline: it sends no data to any server we operate, because we operate none for it. Anything you choose to back up to a cloud provider of your own is ciphertext, unreadable without your key. This is the structural reason the rest of this policy is short: there is very little personal data for us to process in the first place.

3. Data processed on this landing page

This landing page is deliberately data-minimal. We do not set cookies, we do not embed analytics, advertising, social-media plug-ins, external fonts, or third-party CDNs. All content is served directly from our hosting provider.

When you visit the site, our hosting provider records technical data in server logfiles that your browser transmits automatically:

These logs are processed solely for the purpose of operating, securing, and technically optimising the website. They are not merged with other data sources or used for marketing. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a stable and secure website). Logs are deleted or anonymised after at most 30 days.

4. Data processed in the LOX app

LOX is a native application for Android and Windows, obtained from Google Play or the Microsoft Store. It is local-first: your files, document metadata, passphrase and quick-unlock PIN live on your device only. They are not uploaded to us, and we cannot read them. The app contacts no server of ours, so no usage data, telemetry, crash reports, or analytics reach us from it.

The app stores through which LOX is distributed are independent controllers for the data they collect when you download or purchase an app — your store account, device, and transaction details. That processing is governed by their own privacy policies, not this one. From them we receive only aggregated, non-identifying statistics such as download and crash counts.

5. Data processed by cloud backup and sharing

Cloud backup is opt-in per vault and switched off by default. When you enable it for a vault, encrypted blobs from that vault are uploaded to a storage account you connect yourself — your Google Drive, Dropbox, or OneDrive. The provider sees only ciphertext; the encryption key remains on your device. We are not involved in that transfer: it runs directly between the app and your provider, under your own contract with them. Vaults you do not opt in stay strictly on your device.

6. Sharing a vault with someone else

When you share a vault, the recipient receives an encrypted copy with its own passphrase, delivered via QR code. No key material passes through us — we run no servers in that path — and we cannot read the contents of shared vaults. You are responsible for whom you share with and for revoking access when appropriate.

7. Contacting us by email

If you email us, the information you provide (your email address, optionally your name and phone number, and the content of your message) is stored and used solely to handle your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures / performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Your data is deleted once it is no longer required and no statutory retention period stands in the way.

8. Recipients and processors

To operate the service we rely on the following processors:

Two further parties process data in connection with LOX, but not as our processors:

We do not transfer personal data to other recipients beyond what is necessary to operate the service.

9. Your rights as a data subject

Where we process personal data about you, you have the following rights:

To exercise your rights, an informal message to andel@birch-ave.com is enough.

10. Right to lodge a complaint with a supervisory authority

Under Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority if you believe the processing of your personal data infringes the GDPR. The competent authority is the supervisory authority of the federal state in which the controller is established: [COMPETENT STATE SUPERVISORY AUTHORITY].

11. Validity of this privacy policy

Last updated: August 2026. We may need to adapt this policy as the service evolves or as legal requirements change. The current version is always available on this page.