## privacy
Privacy Policy
Last updated: July 2026
This privacy policy informs you about which personal data EiraSync processes when you use our website, join the early-access waitlist, or use our service.
Vault contents are transmitted end-to-end encrypted. The sync server processes and stores encrypted data only. Decryption keys remain on your devices (zero-knowledge principle of the Obsidian LiveSync plugin).
1. Controller
Simon Mück Lechnerstraße 15/60 1030 Vienna Austria Email: hello@eirasync.app
Provider details under §5 ECG (Austrian imprint requirements) are listed in our separate legal notice.
2. Collection and processing of personal data
a) Website visit (server log files) When you access our website, your browser automatically transmits information to our server. This includes in particular:
- IP address
- Date and time of the request
- Browser type and version
- Operating system
- Referrer URL (if transmitted)
- Pages and files accessed
This data is technically required to provide the website and to ensure the security and stability of our systems.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Our legitimate interest lies in particular in providing the website, ensuring system security, detecting and defending against attacks, error analysis, and ensuring uninterrupted operation. Server log files are generally deleted after 14 days at the latest, unless they are needed longer to investigate a security incident.
b) Web analytics (Umami) For statistical analysis and reach measurement, we use the privacy-friendly analytics tool Umami. Umami does not use cookies. IP addresses are anonymised immediately upon collection, so no direct identification of you is possible. Only aggregated metadata (e.g. pages accessed, region, browser used) is processed.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Our legitimate interest lies in the ongoing optimisation and user-oriented design of our website.
c) Search engine analytics (Google Search Console) We use Google Search Console to analyse search engine performance. This involves processing aggregated data about how our website is found in search results.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Our legitimate interest lies in improving the discoverability of our website in search engines.
d) Early-access waitlist When you sign up for our waitlist, we process:
- your email address
- time of registration
- optionally your user agent and the origin of your registration (referrer)
We use this data solely to inform you about the launch of EiraSync and product-related information.
Legal basis: Art. 6(1)(a) GDPR (consent).
You may withdraw your consent at any time with effect for the future, for example by email to hello@eirasync.app.
e) User account and sync service To provide our service, we process in particular:
- email address
- authentication information (magic link)
- technical metadata for managing your synchronisation
- information about your plan and account status
Vault contents are not processed in plaintext by EiraSync.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
f) Cookies and browser storage We use only technically necessary cookies or browser storage entries (e.g. session or authentication data) required to operate our service. No consent-based tracking or marketing cookies are used.
Legal basis: § 165 para. 3 TKG 2021 (Austria) or the applicable national provisions implementing the ePrivacy Directive, as well as Art. 6(1)(f) GDPR.
g) Automated decision-making No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
h) Availability monitoring (Better Stack) We use Better Stack to monitor the availability of our services (API, sync, website). This involves periodic impersonal health checks (HTTP requests to public endpoints such as /health). Vault contents, personal API paths, and host metrics (e.g. storage or RAM) are not displayed publicly.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable operation).
3. Service providers and recipients of personal data
We use the following service providers to deliver our service:
- Hetzner Online GmbH (Germany): Hosting of the sync infrastructure (CouchDB / LiveSync). Processed data: encrypted vault data, technical metadata, server log files.
- Cloudflare, Inc. (USA): CDN, WAF, and hosting of the web application (Cloudflare Workers). Processed data: IP address, HTTP requests, technical connection data.
- Supabase (EU, Frankfurt): Authentication, account management, and storage of waitlist and control-plane metadata. Processed data: email address, account information, authentication data.
- Resend, Inc. (USA): Sending transactional emails (magic links, notifications). Processed data: email address, delivery metadata.
- Paddle (Paddle.com Market Ltd., UK / Paddle Payments Ltd., Ireland / Paddle.com Inc., USA): Processing of orders, subscriptions, and invoicing as Merchant of Record. Processed data: billing data, payment information, order information. Payment data is not processed or stored by EiraSync but is collected and processed directly by Paddle.
- Umami (EU): Cloud infrastructure for web analytics. Processed data: anonymised usage data, technical metadata.
- Google Ireland Limited (EU): Google Search Console for search engine performance analysis. Processed data: aggregated data on website discoverability (e.g. search queries, clicks, indexing status).
- Better Stack (Better Uptime): Availability monitoring and public status page (status.eirasync.app). Processed data: IP address and request metadata from health checks against public endpoints; no vault contents.
International data transfers Cloudflare, Inc. and Resend, Inc. are certified under the EU-U.S. Data Privacy Framework (DPF) according to their own statements; transfers to these providers are based on the corresponding adequacy decision of the European Commission.
For transfers to Paddle.com Market Ltd. (UK), we rely on the European Commission's adequacy decision for the United Kingdom. Where data is processed by Paddle.com Inc. (USA), this is based on the Data Privacy Framework (DPF) or appropriate guarantees under Art. 46 GDPR in the form of Standard Contractual Clauses (SCC) set out in Paddle's Data Sharing Addendum. Should any of the certifications mentioned cease to apply or become invalid, we will ensure transfers through appropriate guarantees under Art. 46 GDPR.
4. Retention
We store personal data only as long as necessary for the respective purposes or where statutory retention obligations apply. In particular:
- Server log files: generally up to 14 days
- Waitlist: until withdrawal of consent or dispatch of launch information
- Account data: until deletion of the user account
- Billing data: according to statutory retention obligations through Paddle
5. Data security
Communication between your device and our servers is encrypted exclusively using TLS (HTTPS). Vault contents are transmitted end-to-end encrypted. The keys required for this remain exclusively on your devices.
6. Minors
Our offering is not specifically directed at persons under 16 years of age. If we learn that personal data of a minor was collected without parental consent, we will delete that data immediately.
7. Your rights
You have the right at any time to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent with effect for the future (Art. 7(3) GDPR)
- Lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, a simple email to hello@eirasync.app is sufficient.
Supervisory authority in Austria: Austrian Data Protection Authority Barichgasse 40-42, 1030 Vienna www.dsb.gv.at