Privacy Policy
In effect from 15 August 2026. This single policy covers everything we make: the managed Hoodik Cloud service, the Hoodik apps for iOS, Android and macOS, the self-hosted server software, and this website. It replaces the separate policies previously published for Hoodik Cloud and for the apps.
The short version. Your files are encrypted on your device with keys we never receive, so we cannot read them, whichever version of Hoodik you use. If you run the server yourself, we hold nothing at all. If we host it for you, we hold the little we need to run your account, mainly your email, your billing status and short-lived technical logs. The apps keep their data on your device and send us nothing. We do not sell your data, and we only give it to an authority under a valid legal order, and even then your files stay encrypted.
1. Which Hoodik you are using
Hoodik comes in more than one form, and our relationship to your data is completely different in each. Find yours here, then read that section. Section 2 applies to all of them.
| What you use | What we hold | Section |
|---|---|---|
| Hoodik Cloud, the managed service we run for you | Your account and billing status, short-lived logs, and your instance as encrypted data | 3 |
| The Hoodik apps on iOS, Android or macOS | Nothing. The apps talk only to the server you point them at | 4 |
| The server software, running on your own hardware | Nothing. We are not involved in it at all | 5 |
| This website | Aggregate traffic counts, no cookies, no personal data | 6 |
Hudik d.o.o., Kapelska 6, 31000 Osijek, Croatia (VAT ID HR15878994254), publishes all of it. Where this policy says "we", that is the company.
2. The principle that applies to every version: we cannot read your files
Hoodik is end-to-end encrypted. Your files, their names and their thumbnails are encrypted on your device, using current, well-regarded, published cryptography, before they are uploaded. Your password is never sent to the server, and the keys that decrypt your data never leave your device. Whoever runs the server stores only encrypted data and holds no key that can decrypt it, and when we are the one running it, that means us. This includes files shared through a public link, which are decrypted in the recipient's own browser. The exact algorithms are documented in our published source and security documentation, so this is a claim you can check rather than one you have to take on trust.
Encryption uses a hybrid X25519 and ML-KEM-768 key exchange with Ed25519 identities, and AEGIS-128L for content, with support for AEGIS-256, Ascon-128a and ChaCha20-Poly1305. Sign in uses OPAQUE, so your password never crosses the network.
3. Hoodik Cloud, the managed service
This section applies only if we host an instance for you. For the account and operational data below we are the data controller. For the Content you store on your instance, you are the controller and we act as your processor, on the terms of our Data Processing Agreement.
3.1 What we process
Account data (we are the controller). Your email address, your chosen data region, and your plan and subscription status. We use this to create and run your account, contact you about the service, and provide support.
Billing data (handled by our payment provider). Payment is processed by our Merchant of Record, who collects your name, billing address, tax details and payment method. They are a separate controller for that data. We receive payout and tax reports from them, not your card details.
Operational data (we are the controller). To keep the service secure and working, our systems record access logs (IP addresses, timestamps and basic request metadata) and technical information about your instance, such as the region it runs in and how much storage it uses. We keep IP-level access logs to a minimum and retain them for a short period (see 3.4).
Your instance's data (we are your processor). Your instance stores your Content as encrypted data we cannot read. Its database also holds, on your behalf, the information the application needs to work: the email addresses of the users you invite, their password verifiers, their public keys and their password-protected private keys, and metadata about your files such as their sizes, timestamps and folder structure, plus a privacy-preserving search index made of hashed word-tokens. We hold all of this as your processor. The encrypted file content is unreadable to us; the rest is protected but is still personal data, which is why we are transparent about it here. For completeness: the search index uses hashed tokens that are not individually salted, so someone who obtained the database could test whether a guessed word appears in a file name. We treat this as a known limitation.
3.2 Why we process it, and our legal basis
- To provide the service (performance of a contract): creating and running your account and instance, billing, and support.
- To keep the service secure (legitimate interests): preventing abuse, fraud and attacks, and diagnosing problems.
- To meet legal obligations: tax and accounting records, and responding to valid legal orders.
For the Content on your instance, we act only on your instructions as controller, on the basis set out in the Data Processing Agreement. A request to scan or read that Content would be a request to process it against your instructions, which we have no basis to do, and, in any case, cannot, because we hold no keys.
3.3 Who we share it with
We do not sell your data and we do not use it for advertising. We share data only with the service providers we need to run Hoodik Cloud, listed below, and with authorities where we are legally required to, as described in 3.5.
| Provider | What they do | Where |
|---|---|---|
| Hetzner | Servers and compute for your instance | EU or US (your choice) |
| Cloudflare | Encrypted object storage, plus DNS and network edge | EU or US (your choice) |
| Paddle (Merchant of Record) | Payment processing and invoicing | EU / UK / US |
| Scaleway | Sending transactional email (e.g. confirmations) | EU (France) |
Every provider that stores your files holds only encrypted data. They cannot read it either. The current list of sub-processors is kept in our Data Processing Agreement.
3.4 How long we keep it
- Account data: for as long as your account is active, and then as needed to close it out and to meet our legal (e.g. accounting) obligations.
- Access logs: retained for 30 days, then deleted.
- Your Content and instance data: kept while your subscription is active and during the 30-day grace period after it ends, then deleted. Residual encrypted copies in our backups age out within approximately a further 7 days.
- Legal holds: where a valid order requires us to preserve specific data, we keep that data for as long as the order requires, and no longer.
3.5 Disclosure to authorities
We disclose data to an authority only under a valid legal order, and only the categories we actually hold: your account data, operational data, and information about your instance, plus your stored data as encrypted data. We hold no keys, so we cannot disclose the readable contents of your files. Our Law Enforcement Guidelines explain this in detail.
Please note that our payment provider and other sub-processors are separate companies in their own countries, and an authority can require information directly from them under their own laws, possibly without our knowledge. Our commitment to notify you where the law allows cannot cover requests made directly to them.
3.6 Where your data is stored
You choose your data region (EU or US) when you sign up, and your instance and its backups stay in that region. Because your files are end-to-end encrypted, whatever any provider holds is encrypted data regardless of region; your choice of region is about where the data physically lives, not about who can read it. Some of our providers are companies with parent organisations outside the EU; the data they hold for us is encrypted.
3.7 Data breaches
If we ever suffer a security incident, your encrypted file content remains unreadable without your keys, which we do not hold. Where an incident could affect data that is not fully unreadable, for example the information in an instance's database, we assess it and notify affected controllers, the supervisory authority, and affected individuals where the law requires, without undue delay.
4. The Hoodik apps
The apps for iOS, Android and macOS connect to a Hoodik server. That server may be one we host for you, or one you run yourself; either way, the app itself sends us nothing.
The app stores the following locally on your device only:
- Your server URL and email address, so it can connect to your server
- Your encrypted private key, protected by your password or PIN and never stored in plaintext
- Cached encrypted file data for offline access
This data never leaves your device except when authenticating with your server. Local data sits in an app-sandboxed SQLite database, and PIN or biometric unlock protects the private key at rest with Ascon-128a.
No analytics or crash reporting. The apps contain no analytics SDKs, no crash reporting tools and no advertising frameworks. We do not track how you use them.
Legacy purchase data. Current versions of the apps are free and contain no purchase functionality, so they send nothing to any payment or subscription service. Versions before 2.1.0 offered paid subscriptions: payment was processed by Apple or Google, and RevenueCat, a third-party subscription management service, received an anonymous app user ID, purchase receipts and subscription status, and basic device information such as platform, OS version and app version. RevenueCat never received your files, your server URL, your encryption keys, or anything stored in your Hoodik instance. That data is retained by RevenueCat under their own retention policy. Apple and Google handled payment under Apple's and Google's respective privacy policies. No other third-party service is integrated into the apps.
5. The self-hosted server software
If you run the Hoodik server on your own hardware, we have no access to any of it. We build and publish the software; you provide and manage the infrastructure. File content is encrypted before it reaches your server, which stores only ciphertext, along with the account information the application needs (email addresses, password verifiers, public keys) as configured by whoever administers it. Retention and every other decision about that data belong to the administrator, which is you or the person running your server. We are not involved and hold nothing.
6. This website
We use our own self-hosted, privacy-friendly analytics to understand aggregate traffic. It sets no cookies, does not track you across other websites, and does not collect personal data. There are no third-party trackers, advertising pixels or session recorders on any page.
7. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to certain processing, and to data portability. For the Content on a Hoodik Cloud instance, your one-click encrypted export covers portability directly. To exercise any right, contact us at support@hoodik.io. You may also complain to the Croatian Personal Data Protection Agency (AZOP), or to the supervisory authority where you live.
If you run the server yourself, we hold no personal data about you to access, correct or erase, so these requests go to whoever administers that server.
8. Changes to this policy
We may update this policy from time to time. If a change is significant, we will let you know through the service or by email before it takes effect.
9. Contact
Hudik d.o.o., Kapelska 6, 31000 Osijek, Croatia · support@hoodik.io. For a Data Processing Agreement, see our standing DPA.
