Privacy Policy – Remtio Mobile App
1. Controller
Velletti Consulting
Munich, Bavaria, Germany
Email: vel-consulting@ame.velletti.de
Further details: Legal notice (Impressum)
[PLACEHOLDER: Data protection officer yes/no – add contact details if yes]
2. Overview
The Remtio app (Android and iOS) is an AI shopping assistant for refurbished tech. It offers free-text search across an offer catalog, a swipe deck for discovering offers, and a locally stored watchlist. This policy describes which personal data the app processes.
3. Data that stays on your device
Your watchlist and the list of skipped offers are stored exclusively on your device (Android: SharedPreferences, iOS: UserDefaults). This data is never sent to our servers and is deleted when you uninstall the app.
4. Data sent to our servers
Search queries
Your free-text search queries are sent to our backend and stored there to provide search results and improve search quality. For AI-assisted processing, queries are passed to AWS Bedrock (Amazon Web Services). Legal basis: Art. 6(1)(b) and (f) GDPR. Retention: [PLACEHOLDER: define retention period for search queries].
Click and interaction data
When you tap an offer, we record the offer ID and the source ("mobile") to analyse catalog relevance. This data is not linked to your identity. Legal basis: Art. 6(1)(f) GDPR. Retention: [PLACEHOLDER: define retention period for click data].
Advisory chat
If you use the AI advisory chat, your messages are transmitted to AWS Bedrock to generate responses. Raw dialogues are deleted automatically after 30 days; structured requirements and outcomes are stored for up to 12 months. Legal basis: Art. 6(1)(b) GDPR.
5. Sign-in (Android only)
Sign-in is optional and handled by Auth0 (Okta, Inc.), which processes your email address and name. Our backend receives your identity only as a pseudonymised hash (HMAC-SHA256) – your email address and name are never transmitted to our servers. The session is not persisted on the device. Legal basis: Art. 6(1)(b) GDPR. Auth0 privacy policy: okta.com/privacy-policy.
6. Server logs and telemetry
Each request to our backend involves processing of technically necessary data (IP address, user agent, request headers) in server logs (AWS CloudWatch, retained for approx. 30 days) and in observability traces at our provider Dash0 [PLACEHOLDER: Dash0 company address, DPA status, storage location and retention]. Traces may contain search queries as part of URLs. Legal basis: Art. 6(1)(f) GDPR (operational security and troubleshooting).
7. Recipients and international transfers
Processors: Amazon Web Services (hosting, database, AI services via Bedrock), Auth0/Okta (sign-in), Dash0 (telemetry). [PLACEHOLDER: AWS processing region incl. Bedrock region; transfer mechanism (e.g. EU Standard Contractual Clauses / EU-US Data Privacy Framework) for AWS, Auth0 and Dash0]
8. No analytics or advertising SDKs
The app contains no third-party analytics, advertising, or crash-reporting SDKs, and its only permission is internet access.
9. Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (Art. 15–21 GDPR). To exercise them, email vel-consulting@ame.velletti.de. You also have the right to lodge a complaint with a data protection supervisory authority.
Last updated: 2026-07-12