Privacy Policy

In effect from 8 July 2026. This policy covers Hoodik Cloud (hoodik.cloud) and is separate from the privacy policy for the Hoodik apps and the self-hosted software at hoodik.io.

The short version. Your files are encrypted on your device with keys we never receive, so we cannot read them. We hold the limited information we genuinely need to run your account and the Service, mainly your email, your billing status, and short-lived technical logs. We do not sell your data, and we only give it to an authority under a valid legal order, and even then your files remain encrypted.

1. Who is responsible for your data

Hudik d.o.o., Kapelska 6, 31000 Osijek, Croatia (VAT ID HR15878994254), runs Hoodik Cloud and is the data controller for the account and operational data described in this policy. For the Content you store on your Instance, you are the controller and we act as your processor. See section 4 and our Data Processing Agreement.

2. The core principle: we cannot read your files

Hoodik Cloud is end-to-end encrypted. Your files, their names and their thumbnails are encrypted on your device, using current, well-regarded, published cryptography, before they are uploaded. Your password is never sent to us, and the keys that decrypt your data never leave your device. We store only encrypted data and hold no key that can decrypt it. This includes files you share through a public link, which are decrypted in the recipient's own browser, not on our servers. The exact algorithms are documented in our published security documentation. Everything below is about the limited account and operational data we do process to run the Service.

3. What personal data we process

Account data (we are the controller). Your email address, your chosen data region, and your plan and subscription status. We use this to create and run your account, contact you about the Service, and provide support.

Billing data (handled by our payment provider). Payment is processed by our Merchant of Record, who collects your name, billing address, tax details and payment method. They are a separate controller for that data. We receive payout and tax reports from them, not your card details.

Operational data (we are the controller). To keep the Service secure and working, our systems record access logs (IP addresses, timestamps and basic request metadata) and technical information about your Instance, such as the region it runs in and how much storage it uses. We keep IP-level access logs to a minimum and retain them for a short period (see section 6).

Your Instance's data (we are your processor). Your Instance stores your Content as encrypted data we cannot read. Its database also holds, on your behalf, the information the application needs to work: the email addresses of the users you invite, their password verifiers, their public keys and their password-protected private keys, and metadata about your files such as their sizes, timestamps and folder structure, plus a privacy-preserving search index made of hashed word-tokens. We hold all of this as your processor. The encrypted file content is unreadable to us; the rest is protected but is still personal data, which is why we are transparent about it here. (A note for completeness: the search index uses hashed tokens that are not individually salted, so someone who obtained the database could test whether a guessed word appears in a file name; we treat this as a known limitation.)

4. Why we process it, and our legal basis

  • To provide the Service (performance of a contract): creating and running your account and Instance, billing, and support.
  • To keep the Service secure (legitimate interests): preventing abuse, fraud and attacks, and diagnosing problems.
  • To meet legal obligations: tax and accounting records, and responding to valid legal orders.

For the Content on your Instance, we act only on your instructions as controller, on the basis set out in the Data Processing Agreement. A request to scan or read that Content would be a request to process it against your instructions, which we have no basis to do, and, in any case, cannot, because we hold no keys.

5. Who we share data with

We do not sell your data and we do not use it for advertising. We share data only with the service providers we need to run Hoodik Cloud (our sub-processors, listed below), and with authorities where we are legally required to, as described in section 7.

ProviderWhat they doWhere
HetznerServers and compute for your InstanceEU or US (your choice)
CloudflareEncrypted object storage, plus DNS and network edgeEU or US (your choice)
Paddle (Merchant of Record)Payment processing and invoicingEU / UK / US
ScalewaySending transactional email (e.g. confirmations)EU (France)

Every provider that stores your files holds only encrypted data. They cannot read it either. The current list of sub-processors is kept in our Data Processing Agreement.

6. How long we keep data

  • Account data: for as long as your account is active, and then as needed to close it out and to meet our legal (e.g. accounting) obligations.
  • Access logs: retained for 30 days, then deleted.
  • Your Content and Instance data: kept while your subscription is active and during the 30-day grace period after it ends, then deleted. Residual encrypted copies in our backups age out within approximately a further 7 days.
  • Legal holds: where a valid order requires us to preserve specific data, we keep that data for as long as the order requires, and no longer.

7. Disclosure to authorities

We disclose data to an authority only under a valid legal order, and only the categories we actually hold: your account data, operational data, and information about your Instance, plus your stored data as encrypted data. We hold no keys, so we cannot disclose the readable contents of your files. Our Law Enforcement Guidelines explain this in detail.

Please note that our payment provider and other sub-processors are separate companies in their own countries, and an authority can require information directly from them under their own laws, possibly without our knowledge. Our commitment to notify you where the law allows cannot cover requests made directly to them.

8. Where your data is stored

You choose your data region (EU or US) when you sign up, and your Instance and its backups stay in that region. Because your files are end-to-end encrypted, whatever any provider holds is encrypted data regardless of region; your choice of region is about where the data physically lives, not about who can read it. Some of our providers are companies with parent organisations outside the EU; the data they hold for us is encrypted.

9. Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to certain processing, and to data portability. For the Content on your Instance, your one-click encrypted export covers portability directly. To exercise any right, contact us at support@hoodik.io. You may also complain to the Croatian Personal Data Protection Agency (AZOP), or to the supervisory authority where you live.

10. Data breaches

If we ever suffer a security incident, your encrypted file content remains unreadable without your keys, which we do not hold. Where an incident could affect data that is not fully unreadable (for example the information in an Instance's database), we assess it and notify affected controllers, the supervisory authority, and affected individuals where the law requires, without undue delay.

11. Analytics and cookies on this website

On this website we use our own self-hosted, privacy-friendly analytics to understand aggregate traffic. It sets no cookies, does not track you across other websites, and does not collect personal data.

12. Changes to this policy

We may update this policy from time to time. If a change is significant, we will let you know through the Service or by email before it takes effect.

13. Contact

Hudik d.o.o., Kapelska 6, 31000 Osijek, Croatia · support@hoodik.io. For a Data Processing Agreement, see our standing DPA.