Privacy Policy

Last updated: 2026-09-09

Läs policyn på svenska →

This is a translation of the Swedish privacy policy. In case of any discrepancy, the Swedish version applies.

1. Introduction

This privacy policy describes how Råggywood AB ("we", "us"), registration number 556972-3884, processes personal data when you use the app Topicos ("App", "Service") on mobile and on the web (app.topicos.app), and the website topicos.app.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and supplementary Swedish legislation.

Contact:
Råggywood AB
Email: kontakt@topicos.app
Country: Sweden

2. Roles: who is responsible for what

Topicos is used by organizations, and responsibility for personal data is shared.

Organizations that need a written data processing agreement can contact us at kontakt@topicos.app.

3. What personal data we process

Data you provide

Data collected automatically

Data we do NOT process

4. Purposes and legal basis

5. End-to-end encryption

An organization's super administrator can enable end-to-end encryption (the Organization key). New messages, attachments, documents, tasks, calendar events, notifications, names of groups, topics and folders, and calls are then encrypted on the members' devices with keys that only the organization holds. We then store only encrypted content that we cannot read, together with metadata.

What is encrypted, how keys are managed and what the encryption does not protect against is described on the Security page (in Swedish).

6. Where data is processed and which subprocessors we use

The database, server code and files are located in the EU. Some services are global or US-based. The table shows each provider, what it processes and where.

Provider and serviceDataLocation
Google Cloud – Firestore (database) Messages, documents, tasks, calendar, time reports, memberships, notifications EU, multi-region eur3 (Belgium and the Netherlands)
Google Cloud – Cloud Functions (server code) Processing of the above on write, notifications, payment EU, europe-west1 (Belgium)
Google Cloud – Cloud Storage Profile pictures and link preview images EU, europe-west1 (Belgium)
Google – Firebase Authentication Phone number, login session and SMS delivery of one-time codes USA. Google states that the service runs exclusively in US data centers
Google – Firebase Cloud Messaging Push token and notifications to Android. Content is encrypted to the device before sending Global
Apple – Apple Push Notification service Push token, notifications and call signaling to iPhone. Content is encrypted to the device before sending Global (USA)
Google – Firebase Crashlytics Crash reports with error details, device model, operating system and account id Global
Google – Firebase App Check and reCAPTCHA Technical signals about the device or browser to stop abuse Global
Cloudflare – R2 Attachments: images, video, audio and files. Access only via signed links valid for one hour EU jurisdiction
LiveKit – voice calls Real-time audio (never stored; encrypted between participants in organizations with end-to-end encryption) and participant ids USA
Expo (650 Industries, Inc.) Delivery of app updates; push to older app versions (push token, organization and sender name) USA
Stripe Payments: organization name, phone number, invoice recipient, company name, registration number, invoices and subscription status. Card details only at Stripe EU/USA

The providers process data according to our instructions and are bound by data processing agreements.

Transfers outside the EU/EEA

Some of our providers are US companies, and parts of the processing take place with them in the USA. "Processing" in the legal sense also covers storage and transport of encrypted data that the provider cannot read. We therefore distinguish here between what is readable to the provider and what is not:

The content of chats, files, documents, tasks and calendar is not processed in the USA. It is stored in the EU, and with end-to-end encryption enabled it exists in readable form only on the organization's devices.

The legal basis for the transfers is the European Commission's Standard Contractual Clauses in the providers' data processing agreements and, for providers that are certified, the EU–US Data Privacy Framework.

7. How long we keep data

Delete account

You can delete your account at any time in the app: Settings → Delete account. If you are the super administrator of an organization, or an administrator of an organization with an active subscription, you first need to transfer or close it.

What is deleted:

What remains:

8. Your rights

Under GDPR you have the right to:

How to exercise your rights: Contact us at kontakt@topicos.app. We respond within 30 days. If your request concerns content in an organization, contact the organization first, as it is the data controller for that content. We assist the organization in fulfilling the request. End-to-end encrypted content can only be provided in encrypted form.

Complaints: You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se, imy@imy.se.

9. Security

No external security audit of Topicos has been carried out yet. More about the protection is on the Security page (in Swedish).

10. Children

Topicos is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you are a parent or guardian and discover that your child has created an account, contact us and we will delete the data.

11. Cookies and local storage

12. Changes to this policy

We may update this policy. In case of significant changes we will notify you in the app or by email if we have your address. Continued use of the Service after a change means that you accept the updated policy.

13. Contact

Do you have questions about this policy or about how we process your personal data?

Råggywood AB
Email: kontakt@topicos.app

This privacy policy is effective from 2026-09-09 and replaces the version dated 2026-01-13.