Effective 20 August 2026
Privacy Policy
This policy explains what personal data re:plyte processes, why it is needed, who receives it, how long it is kept and how you can exercise your rights.
Controller and contact
re:plyte is the controller for the re:plyte website, app and API. Send privacy questions or requests to [email protected].
What this policy covers
This policy covers replyte.com and the re:plyte mobile service. It does not cover information that Apple, Google, Firebase, Twilio, Cloudflare, Stripe or another provider processes independently under its own notice. re:plyte is not an emergency service and its messages, reports and support channels are not monitored for an immediate response.
Account, sign-in and device data
Depending on how you sign in, we process an Apple, Google or Firebase account identifier and the name, email address or phone number that the provider makes available. We also process your profile name and image, language and privacy preferences, account roles, device and push-notification token, session and security records, and the current User Content Rules acceptance. For Sign in with Apple, an encrypted provider credential is retained only when needed to revoke re:plyte access at account deletion; the one-use authorization code is not stored.
Vehicle and user-content data
A vehicle is addressed by its issuing country together with its normalised licence plate. We process claimed vehicles, optional vehicle details, co-driver access, accepted contact reasons, notification settings and QR or handover links. A claim can include a registration certificate, deed, inheritance paper, sale contract or company authorization reviewed to check authority over a vehicle. These documents can contain names, home or registered addresses, vehicle ownership and acquisition details, and a sale price. User content can include messages, photos, voice notes, attached locations, road broadcasts, updates, community and travel-group content, profile material, reactions, reports and blocks. Moderation reports contain a bounded snapshot of the reported item and available context.
Location and what other people see
When you ask for Nearby results, your current position and chosen radius are sent for that request but the query position is not written to the database. If you publish a road broadcast, its coordinates are stored for the broadcast lifecycle. A location deliberately attached to a message is stored with that message. Other users can see the issuing country and plate, the reason for contact and the content you choose to share; they do not receive your private sign-in details or phone number from re:plyte. Blocks are private and enforced in both directions.
Website and support data
If you ask to be notified about availability, Cloudflare KV stores the lower-cased email address and submission date. A salted, truncated hash derived from the request IP is used only for a short-lived rate-limit count. The site has no third-party advertising pixel, behavioural analytics script or tracking cookie. If you contact support or privacy, we process the message and contact details needed to answer; do not send passwords, one-time codes, identity tokens or vehicle-claim documents by email.
Purposes and legal bases
We process account, vehicle, message, location and device data as necessary to provide the service you request and perform our contract with you. We rely on legitimate interests, balanced against your rights, to secure the service, prevent fraud and abuse, enforce blocks, moderate reports, diagnose faults, protect users and defend legal claims. Authentication, installation, notification, transport and on-device recognition components supplied by Google can process limited device, installation, per-installation identifier, usage, latency, image-format/configuration, event and error information for app functionality, service analytics and diagnostics; re:plyte does not use that information for advertising or cross-app tracking. Camera images and the recognized plate/barcode output are processed on the device and are not sent to Google or the re:plyte API by the recognizer; only the normalized plate candidate selected by the on-device gate is sent to the existing exact plate-and-country lookup. We process the availability email on your consent, which you may withdraw. Device permissions and choices control optional location, photo, microphone and notification access. We process information when necessary to comply with a legal obligation or establish, exercise or defend legal claims.
Providers and other recipients
The current service uses Hetzner-hosted compute and PostgreSQL storage; Cloudflare for the website, DNS, email routing, edge security, KV and private R2 object storage; Apple for sign-in, App Store distribution, notification delivery and system-provided on-device Vision recognition; Google for sign-in, Google Play distribution, Firebase phone authentication, Firebase Cloud Messaging and on-device ML Kit recognition with the limited metrics described above; and Twilio for the fallback SMS verification route; Apple and Google for Premium subscription billing; and Stripe for Fleet invoicing under custom agreements. Authorized staff can review vehicle claims, support requests and moderation reports when needed. Providers act as processors or independent controllers according to the service concerned and their terms. We do not sell personal data or share it for third-party targeted advertising.
International transfers
Some providers may process data outside Romania or the European Economic Area. The lawful transfer mechanism depends on the provider, service and destination. We permit a transfer restricted by EU rules only when an applicable mechanism is available, such as an adequacy decision or contractual safeguards. You may ask us for information about the safeguard relevant to your data. Provider infrastructure and transfer routes can change, so this policy does not claim that every processing operation remains in one country.
Specific retention windows
Availability-list emails and their submission dates expire after at most one year; the anonymous submission counter expires after one hour. For each exact plate lookup, a keyed, non-reversible plate digest is associated with the account in a 24-hour abuse counter and written with the account identifier to the size-rotated security log; the clear plate is not logged. Phone-verification challenges expire after 10 minutes, and uncommitted uploads are removed after 24 hours. Updates are available for exactly 24 hours and their media is removed by the scheduled post-expiry sweep. A Nearby broadcast is live for 30 minutes. Unless removed sooner, its coordinates are scheduled for deletion after another 30 minutes; its remaining row and audio are scheduled for deletion 24 hours after expiry. Messages held for an issuing-country-and-plate combination that remains unclaimed are deleted after 30 days. Vehicle-claim documents are deleted within 30 days after a decision, while a limited audit stub remains. Moderation evidence snapshots are kept for no more than 180 days; a non-content report stub may remain for accountability. Rotating refresh sessions have a maximum 30-day lifetime.
Author and moderator private-media withdrawal
When an author withdraws private media or a moderator removes content that contains it, re:plyte immediately stops authorizing new access to that media. A temporary storage-cleanup record keeps the raw storage key until a required deletion at the storage provider, attempted at or after 30 days from the removal request, succeeds. If that deletion cannot be completed, for example because of a storage-provider or network failure, the key remains while deletion is retried; there is no fixed maximum until deletion succeeds. Separately, we permanently keep a domain-separated cryptographic digest derived from the storage category and key to prevent the same object from being accepted again or receiving a new access authorization. The digest contains neither the raw key nor an account reference, but we treat it as pseudonymous, not anonymous, because it can be recomputed when the original key is available elsewhere. This withdrawal process is separate from account purge.
Other retention
Ordinary account, vehicle and conversation data is kept while the account and service need it, unless you delete content, close the account or a shorter window above applies. Limited counterparty, audit, security, moderation or legal records may remain where necessary or permitted; some are de-identified, while the permanent private-media revocation digest described above is pseudonymous rather than anonymous. We do not promise deletion where the GDPR permits or requires retention, and we review a verified request against those exceptions.
Deleting an Apple, Google or phone-based re:plyte account
You can schedule deletion in the app or use replyte.com/delete-account. The request immediately deactivates re:plyte access and revokes active sessions; a retained Sign in with Apple authorization is also revoked before deactivation completes. The same 30-day reversible grace period applies whether you signed in with Apple, Google or a phone number, and signing in during that period can cancel the request. After the grace period, a scheduled purge attempts any applicable provider-side sign-in deletion and deletion of stored private objects before local erasure. Only after those provider operations succeed does it delete or de-identify eligible account identifiers, private rows and authored content, archive claimed vehicles and revoke QR links. If a provider deletion fails, local purge is deferred and retried; eligible source records and storage keys can remain until it succeeds, with no fixed maximum while the failure continues. Account purge does not itself create the permanent object-revocation digest described above. Limited counterparty, audit, security or legal records and moderation evidence within its 180-day limit can also remain where necessary or permitted. This process deletes the re:plyte account; it does not delete your Apple or Google account.
Backups and application logs
A PostgreSQL backup is made nightly, checked as a readable archive and retained for 14 days. Data removed from the live database can therefore remain in a restricted backup until that backup rotates out; backups are not used as a live user record, and restored data remains subject to the applicable deletion process. Structured application-container events are retained by size, not by a fixed number of days: they rotate at 10 MB and are limited to three files per container. Raw HTTP request targets and query strings are not written to application access logs. Sensitive keys and recognizable phone, token, credential and payment-secret patterns are redacted before application log rendering, but no security control is absolute.
Your GDPR rights
Subject to the conditions and exceptions in law, you may request access, rectification, erasure, restriction, a portable copy, or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. Use the in-app account controls, replyte.com/delete-account or email [email protected]; we may need to verify your identity. We normally answer without undue delay and within one month, with any lawful extension explained. You may complain to the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) at dataprotection.ro, or to another competent supervisory authority.
Security, required disclosure and changes
We use access controls, private object storage, encryption in transit, protected credentials, rate limits, data minimisation and scheduled retention controls. We may disclose the minimum necessary information when required by law, a binding authority request, or to protect rights and safety. No online service can guarantee absolute security or delivery. We may update this policy when the service, providers or law change; the page will show the new effective date and we will provide additional notice where law requires it.
Effective and last updated 20 August 2026