Legal
GDPR & EU users
Last updated June 12, 2026
1. Controller and processor roles
- For your account and saved content, the Recl operator acts as the data controller.
- Our infrastructure and AI providers act as processors or independent controllers under their own terms — the full list is on the Subprocessors page.
- Recl processes data only on documented purposes listed in the Privacy Policy; we do not repurpose your content.
2. Legal bases
| Processing | Basis |
|---|---|
| Operating your library, summaries, search, graph, recall | Contract — Art. 6(1)(b) |
| Messaging nudges & push notifications you connected | Consent — Art. 6(1)(a), revocable any time |
| Security, anti-abuse, rate limiting, diagnostics | Legitimate interest — Art. 6(1)(f) |
| Billing and accounting records | Legal obligation — Art. 6(1)(c) |
3. Your data subject rights
| Right | How to exercise it | Timeline |
|---|---|---|
| Access (Art. 15) | Email hello@recl.app from your account email | Within 30 days |
| Rectification (Art. 16) | Edit profile data in Settings, or email us for anything not self-serve | Immediate / 30 days |
| Erasure (Art. 17) | Settings → Danger zone → Delete account (self-serve), or email us | Immediate; backups expire within 35 days |
| Portability (Art. 20) | Email hello@recl.app — we provide your saved content and metadata as JSON | Within 30 days |
| Restriction / objection (Art. 18, 21) | Email hello@recl.app describing the processing you object to | Within 30 days |
| Withdraw consent (Art. 7(3)) | Disconnect Telegram/Discord or disable push in Settings — effective immediately | Immediate |
4. International transfers
Recl's primary infrastructure is hosted in India (DigitalOcean, Bangalore region). Some subprocessors (e.g., Cloudflare, Google, OpenRouter) operate globally, including in the United States. Where personal data of EU/EEA/UK users is transferred outside the EEA, it is protected by the subprocessors' Standard Contractual Clauses (SCCs) or equivalent safeguards, as documented in their respective data-processing agreements.
5. Data breach notification
If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and affected users without undue delay, as required by Art. 33–34 GDPR.
6. Contact and complaints
- Privacy contact: hello@recl.app (we respond within 30 days).
- You have the right to lodge a complaint with your local supervisory authority (the data-protection authority of your EU member state, or the ICO in the UK).