Privacy Policy
Last updated: 2026-09-09
Läs policyn på svenska →This is a translation of the Swedish privacy policy. In case of any discrepancy, the Swedish version applies.
1. Introduction
This privacy policy describes how Råggywood AB ("we", "us"), registration number 556972-3884, processes personal data when you use the app Topicos ("App", "Service") on mobile and on the web (app.topicos.app), and the website topicos.app.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and supplementary Swedish legislation.
Contact:
Råggywood AB
Email: kontakt@topicos.app
Country: Sweden
2. Roles: who is responsible for what
Topicos is used by organizations, and responsibility for personal data is shared.
- Your account. For account data (phone number, name, profile picture, email, technical data about your device) Råggywood AB is the data controller.
- The organization's content. For what is created within an organization (messages, files, documents, tasks, calendar events, time reports, member lists) the organization is the data controller and Råggywood AB is the data processor. We process the content only to provide the Service according to the organization's instructions.
Organizations that need a written data processing agreement can contact us at kontakt@topicos.app.
3. What personal data we process
Data you provide
- Account data – phone number, name, profile picture, email address (optional) and bio.
- Communication – messages (text, images, video, audio, files), reactions, mentions and polls.
- Location data – your position only when you choose to share it in a chat. We never track your location in the background.
- Links – when a message contains a link, our server fetches a preview (title, description, image) from the linked page. Your device does not contact the page.
- Organization data – the organization's name, group names, topics, folders, roles and memberships. If you invite someone who does not yet have Topicos, their phone number is stored until the invitation is answered, for at most 30 days.
- Tasks, calendar and documents – titles, descriptions, notes, times, participants and attachments.
- Time tracking – if the organization uses time tracking: clock-in and clock-out times, breaks, absences with a reason code (for example sickness, care of a sick child, vacation, parental leave, leave of absence), approvals and payroll exports. Absence reasons may constitute health data. The organization is responsible for having a legal basis under employment law or collective agreements; we process this data solely as a processor.
- Calls – participants, start time, duration and whether the call was answered or missed. Audio is relayed in real time and is never recorded.
- Payment (organization administrators) – the organization's name, your phone number, the invoice recipient's email, company name and company registration number. Card details are handled directly by Stripe and never reach our systems.
Data collected automatically
- Technical data – device type and platform, operating system, app version, selected language and time zone.
- Notifications – push tokens from Apple and Google for your device (and from Expo for older app versions), plus a key used to encrypt notification content to your specific device.
- Device keys – in organizations with end-to-end encryption: the device's public encryption key, a device id and when the device was last active. The private key never leaves the device.
- Usage data – read receipts, delivery status, timestamps and when you were last active, to display message status and presence.
- Crash data – when the app crashes, a report is sent via Firebase Crashlytics with error details, device model, operating system and your account id, so that we can find and fix bugs.
- Abuse protection – to make sure requests come from the genuine Topicos app we use Firebase App Check with Play Integrity (Android), App Attest (iOS) and reCAPTCHA (web). These process technical signals about the device or browser.
Data we do NOT process
- We do not track your location in the background.
- We use no advertising networks, no analytics tools and no behavioral tracking, neither in the app nor on the website.
- We never sell personal data.
4. Purposes and legal basis
- Provide and maintain the Service – performance of contract (Art. 6.1 b).
- Send notifications about messages, tasks, calendar and calls – performance of contract (Art. 6.1 b).
- Manage accounts, authentication and payment – performance of contract (Art. 6.1 b).
- Store and display the organization's content, including time reports – on the organization's instructions as a data processor. The organization's legal basis is normally contract or a legal obligation towards its employees.
- Improve and develop the Service and fix bugs – legitimate interest (Art. 6.1 f).
- Prevent abuse and maintain security – legitimate interest (Art. 6.1 f).
- Fulfil legal obligations, such as bookkeeping – legal obligation (Art. 6.1 c).
5. End-to-end encryption
An organization's super administrator can enable end-to-end encryption (the Organization key). New messages, attachments, documents, tasks, calendar events, notifications, names of groups, topics and folders, and calls are then encrypted on the members' devices with keys that only the organization holds. We then store only encrypted content that we cannot read, together with metadata.
- We can neither read, moderate, restore nor hand over encrypted content. A request to access such content must be directed to the organization, which holds the keys.
- If the organization's recovery phrase and all approved devices are lost, the content is permanently unreadable. We cannot restore it.
- Remains in plaintext even with encryption enabled: the organization's name, member names and phone numbers, time tracking data, content from before encryption was enabled, and metadata (who is a member where, who wrote when and how much).
What is encrypted, how keys are managed and what the encryption does not protect against is described on the Security page (in Swedish).
6. Where data is processed and which subprocessors we use
The database, server code and files are located in the EU. Some services are global or US-based. The table shows each provider, what it processes and where.
| Provider and service | Data | Location |
|---|---|---|
| Google Cloud – Firestore (database) | Messages, documents, tasks, calendar, time reports, memberships, notifications | EU, multi-region eur3 (Belgium and the Netherlands) |
| Google Cloud – Cloud Functions (server code) | Processing of the above on write, notifications, payment | EU, europe-west1 (Belgium) |
| Google Cloud – Cloud Storage | Profile pictures and link preview images | EU, europe-west1 (Belgium) |
| Google – Firebase Authentication | Phone number, login session and SMS delivery of one-time codes | USA. Google states that the service runs exclusively in US data centers |
| Google – Firebase Cloud Messaging | Push token and notifications to Android. Content is encrypted to the device before sending | Global |
| Apple – Apple Push Notification service | Push token, notifications and call signaling to iPhone. Content is encrypted to the device before sending | Global (USA) |
| Google – Firebase Crashlytics | Crash reports with error details, device model, operating system and account id | Global |
| Google – Firebase App Check and reCAPTCHA | Technical signals about the device or browser to stop abuse | Global |
| Cloudflare – R2 | Attachments: images, video, audio and files. Access only via signed links valid for one hour | EU jurisdiction |
| LiveKit – voice calls | Real-time audio (never stored; encrypted between participants in organizations with end-to-end encryption) and participant ids | USA |
| Expo (650 Industries, Inc.) | Delivery of app updates; push to older app versions (push token, organization and sender name) | USA |
| Stripe | Payments: organization name, phone number, invoice recipient, company name, registration number, invoices and subscription status. Card details only at Stripe | EU/USA |
The providers process data according to our instructions and are bound by data processing agreements.
Transfers outside the EU/EEA
Some of our providers are US companies, and parts of the processing take place with them in the USA. "Processing" in the legal sense also covers storage and transport of encrypted data that the provider cannot read. We therefore distinguish here between what is readable to the provider and what is not:
- Phone number and login – stored in readable form in Google's US data centers (Firebase Authentication). This is the most sensitive item a US provider sees in plaintext, and the only one that neither you nor your organization can opt out of.
- Push notifications – push tokens pass through Google and Apple, but the content is encrypted to your device. Google and Apple cannot read it.
- Crash reports – error details, device model and an account id go to Google. No names, phone numbers or content.
- Abuse protection – technical signals about the device or browser go to Google (App Check, reCAPTCHA). No content.
- Voice calls – audio passes through LiveKit's servers in real time and is never stored. In organizations with end-to-end encryption the audio is encrypted between the participants and cannot be listened to by LiveKit. Without encryption, the audio passes through the server in readable form during the call.
- App updates – Expo sees that your device fetches updates (device data, no content). Older app versions receive their notifications via Expo; for them, the message preview may pass through Expo in readable form, in organizations with end-to-end encryption only the organization and sender name.
- Payment – the organization's administrator provides billing details to Stripe (organization name, phone number, email, company name, registration number). Stripe reads them, that is the purpose.
The content of chats, files, documents, tasks and calendar is not processed in the USA. It is stored in the EU, and with end-to-end encryption enabled it exists in readable form only on the organization's devices.
The legal basis for the transfers is the European Commission's Standard Contractual Clauses in the providers' data processing agreements and, for providers that are certified, the EU–US Data Privacy Framework.
7. How long we keep data
- Account data is kept as long as you have an account.
- Content is kept until deleted by you, by an administrator or by deletion of the organization. Deleted messages are removed from the database immediately; attachments are deleted when no message refers to them any more. Deleted data may remain for a limited time in backups.
- Free plan: messages older than 90 days are hidden in the app but not deleted. They become visible again if the organization upgrades.
- Groups and topics marked for deletion are deleted automatically with all their content when the grace period has passed.
- Organizations with a cancelled paid subscription: 90 days after cancellation the organization's files are deleted and the organization is deactivated. The super administrator is warned after 60 and 80 days.
- Notifications that have been read are deleted after 90 days. Unanswered invitations are deleted after 30 days.
- Call history and time reports are kept as long as the organization exists, or until the organization deletes them. Time reports are the organization's payroll records.
- Inactive accounts may be deleted after 24 months of inactivity, with prior notice.
- Payment history and invoices at Stripe are kept for up to 7 years in accordance with the Swedish Bookkeeping Act.
Delete account
You can delete your account at any time in the app: Settings → Delete account. If you are the super administrator of an organization, or an administrator of an organization with an active subscription, you first need to transfer or close it.
What is deleted:
- Your profile: name, phone number, profile picture, email and bio
- Your login and your devices' push tokens and keys
- Your memberships in groups and organizations
What remains:
- Messages and files you sent in group chats and private chats remain with the recipients as part of the organization's data, with your name as sender as it appeared when the message was sent. If you want them removed, contact the organization's administrator.
- Tasks, calendar events, documents and time reports you created within an organization remain with the organization.
- Payment history at Stripe is kept in accordance with the Bookkeeping Act.
8. Your rights
Under GDPR you have the right to:
- Access – to know what data we hold about you.
- Rectification – to have inaccurate data corrected. Name, profile picture, email and bio you change yourself in the app.
- Erasure – to have your data deleted.
- Restriction – to restrict how we process your data.
- Data portability – to receive your data in a machine-readable format.
- Objection – to object to processing based on legitimate interest.
- Withdraw consent – to withdraw consent you have given at any time.
How to exercise your rights: Contact us at kontakt@topicos.app. We respond within 30 days. If your request concerns content in an organization, contact the organization first, as it is the data controller for that content. We assist the organization in fulfilling the request. End-to-end encrypted content can only be provided in encrypted form.
Complaints: You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se, imy@imy.se.
9. Security
- All traffic is encrypted (HTTPS/TLS).
- Database, server code and files are located in the EU.
- Database security rules ensure that only members of an organization, group or chat can read its content.
- Attachments are only accessible via signed links that expire after one hour.
- Notification content is encrypted to your device and opened locally.
- Organizations can enable end-to-end encryption with keys that only the organization holds.
- Requests are verified with Firebase App Check so that only the genuine app can reach our servers.
- Login uses a phone number and a one-time code via SMS.
No external security audit of Topicos has been carried out yet. More about the protection is on the Security page (in Swedish).
10. Children
Topicos is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you are a parent or guardian and discover that your child has created an account, contact us and we will delete the data.
11. Cookies and local storage
- The mobile app stores locally on the device: login state, drafts, settings and cached messages and documents. Encryption keys are stored in the iOS Keychain and Android Keystore respectively. This storage is necessary for the Service to function and does not require separate consent.
- The web app app.topicos.app uses browser storage for the login session, abuse protection, cached data and encryption keys. At login, Google reCAPTCHA is used to stop automated abuse, and Google may then set its own cookies.
- The website topicos.app uses no cookies and no analytics tools. The billing page (topicos.app/billing) loads Firebase libraries from Google to identify you and redirects you to Stripe, which uses its own cookies on its pages.
12. Changes to this policy
We may update this policy. In case of significant changes we will notify you in the app or by email if we have your address. Continued use of the Service after a change means that you accept the updated policy.
13. Contact
Do you have questions about this policy or about how we process your personal data?
Råggywood AB
Email: kontakt@topicos.app
This privacy policy is effective from 2026-09-09 and replaces the version dated 2026-01-13.