TRUST AND DATA

What we do with your data

A relocation project holds personal information. This page explains, point by point, how it is protected and what leaves RelocDesk. Every statement matches what the service does today. We do not claim any security certification.

Code and configuration last checked: 9 October 2026.

Where your data is hosted

The database, accounts and photos are hosted by Supabase in the Frankfurt region (Germany), inside the European Union.

The website is served by Cloudflare, a global network. RelocDesk pages and server code therefore run on points of presence around the world, close to each visitor, not only in Europe. Your account data stays in the Frankfurt database.

Some providers are located outside the European Union, notably Google for the AI features (see the dedicated section). The full list is in the privacy policy.

Each account only sees its own data

Row Level Security (RLS) is enabled on all of the application data tables. For your projects, places, tasks and expenses, the rules only give access to rows linked to your account.

Place photos are kept in a private storage space, in a folder named after your user ID. The storage rules only allow reading, uploading and deleting inside your own folder.

Vault documents are not stored on our servers. If you connect Google Drive, they are sent from your browser to your own Drive, in a folder created by RelocDesk. The access requested is limited to files created by the application (drive.file scope). The connection token is encrypted before it is saved and is never sent back to the browser.

A project is only visible to someone else if you create a sharing link yourself. That link is read-only, can be revoked, and exposes neither your notes nor the phone numbers and emails of your places.

You can enable two-factor authentication (authenticator app) in Settings, then Account. Once enabled, sensitive server actions (export, account deletion, AI, payment, Drive connection) also require the second factor, and so do the database rules.

Secrets and encryption

The keys of external services (Google AI, Google Places, payment, email) are never sent to the browser. They stay on the server, and calls go through server routes that check your session.

Traffic between your browser and RelocDesk is encrypted with HTTPS. The site also sends the HSTS header (one year) so that browsers enforce HTTPS.

At rest, data is encrypted by the database host, Supabase, which states in its public documentation that it uses AES-256. This is encryption managed by the host, not end-to-end encryption: RelocDesk can technically access the database content to run the service. Passwords are handled by the Supabase authentication service.

Supabase security (public documentation)

Export or delete your data

In Settings, then Account, you can download your data as JSON: profile, projects, places, tasks, budget, comparators, price tracking, subscriptions and activity history.

In the same place, you can delete your account. Deletion removes your projects and their data, your uploaded place photos, your profile, your subscriptions and the related history, then your sign-in account. It is permanent.

Documents stored in your Google Drive remain under your control: RelocDesk does not delete them for you.

Artificial intelligence: what goes to Google

The AI features use Google Gemini and Google Places. Calls go through our servers: your browser does not contact Google directly for this.

What is sent, depending on the feature. Place search: your request, the project city and country, the category and the search area. Task generation: your request, the city, the country and the names of the places already saved in the project. Route proposal: your request, the city, the country, and the name, address, category and coordinates of the candidate places, plus the chosen start and end points. Receipt scan: the image of the receipt. Comparators: your request. Google Places receives the search text and area, then a place identifier to get its details and photos.

What is not sent: RelocDesk does not add your email, your account ID or your password to these requests. Vault documents, the photos you upload and budget expenses are not part of them. What you type in a request is sent as is, however: avoid entering sensitive information.

RelocDesk uses the paid quota of the Gemini API. According to Google public terms for paid services, Google does not use these prompts and responses to improve its products, and keeps them for a limited time to detect abuse. With Google Search enabled (grounding), prompts are stored for 30 days. These terms are Google’s and may change: the link below is authoritative.

Gemini API terms, paid services section

Payment

Payments are handled by Polar, which acts as Merchant of Record, meaning the official seller of the transaction, according to Polar documentation. Payment takes place on the checkout page hosted by Polar: RelocDesk neither receives nor stores your card numbers.

To create the order, we send Polar your email address and your account ID.

Polar: Merchant of Record

Cookies and audience measurement

Audience measurement uses PostHog, hosted in the European Union (eu.i.posthog.com). It only starts after you agree in the banner. Until you accept, the measurement service is neither initialised nor contacted.

Settings in place: no automatic click capture, no session recording, IP address not collected and geolocation disabled. URL parameters are removed before sending, and fields such as email, name, notes or amounts are filtered out.

You can refuse, or withdraw your consent at any time, with the Cookie preferences button at the bottom of the page. Refusing does not limit the service.

A question about your data?

Write to us, we answer ourselves. The legal detail (legal basis, rights, retention periods) is in the privacy policy.

Write to [email protected]