Legal

GDPR & EU users

Last updated June 12, 2026

This page explains how Recl handles the rights of users in the European Union, European Economic Area, and the United Kingdom under the General Data Protection Regulation (GDPR / UK GDPR). It supplements the Privacy Policy.

1. Controller and processor roles

  • For your account and saved content, the Recl operator acts as the data controller.
  • Our infrastructure and AI providers act as processors or independent controllers under their own terms — the full list is on the Subprocessors page.
  • Recl processes data only on documented purposes listed in the Privacy Policy; we do not repurpose your content.

3. Your data subject rights

RightHow to exercise itTimeline
Access (Art. 15)Email hello@recl.app from your account emailWithin 30 days
Rectification (Art. 16)Edit profile data in Settings, or email us for anything not self-serveImmediate / 30 days
Erasure (Art. 17)Settings → Danger zone → Delete account (self-serve), or email usImmediate; backups expire within 35 days
Portability (Art. 20)Email hello@recl.app — we provide your saved content and metadata as JSONWithin 30 days
Restriction / objection (Art. 18, 21)Email hello@recl.app describing the processing you object toWithin 30 days
Withdraw consent (Art. 7(3))Disconnect Telegram/Discord or disable push in Settings — effective immediatelyImmediate
We verify every request against the email address on the account. We will never ask for your password (there are none — Recl uses Google or Apple sign-in only).

4. International transfers

Recl's primary infrastructure is hosted in India (DigitalOcean, Bangalore region). Some subprocessors (e.g., Cloudflare, Google, OpenRouter) operate globally, including in the United States. Where personal data of EU/EEA/UK users is transferred outside the EEA, it is protected by the subprocessors' Standard Contractual Clauses (SCCs) or equivalent safeguards, as documented in their respective data-processing agreements.

5. Data breach notification

If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and affected users without undue delay, as required by Art. 33–34 GDPR.

6. Contact and complaints

  • Privacy contact: hello@recl.app (we respond within 30 days).
  • You have the right to lodge a complaint with your local supervisory authority (the data-protection authority of your EU member state, or the ICO in the UK).

Questions? Email hello@recl.appwe read every message.