Privacy Policy
Retonis lets you control and monitor your relay controllers from your phone or computer. This policy says exactly what data the Retonis app and service handle, why, and what never leaves your home. It is written to be read.
Who we are
Retonis is operated by DRAGOȘ HAȚEGAN PERSOANĂ FIZICĂ AUTORIZATĂ, a sole trader registered in Romania (CUI 52620811), who is the controller of the personal data described here. The registered office, trade register number and full identification are on the legal notice, which is the one place they are stated. For anything in this policy, write to support@retonis.com.
What we collect, and why
- Your account: email address, the display name you choose, and your password. The password is stored only as a salted argon2id hash — we cannot read it, ever.
- Your controllers: the identifiers of the relay controllers you claim, and the names and colours you give controllers and relays. This is what lets the app show your controllers and nobody else's.
- Controller state: relay on/off states and basic technical telemetry from your controllers (uptime, free memory). This describes the equipment, not you; it exists so the app can show live status and so an unresponsive controller can be told apart from a network problem.
- Sessions and security records: sign-in sessions (stored as token hashes), and counters of failed attempts — codes, passwords, claims — used to slow down guessing. Security events such as account creation are kept in an audit log.
- A notification address for your phone: when you sign in to the Android app, it registers a delivery address for that installation — obtained from Google — so we know which phone to reach. It is registered at sign-in whether or not you allow notifications on the phone. It belongs to that sign-in and disappears with it — by signing out, by ending every session, by resetting your password or by deleting your account — each of which removes it at once — and, when a sign-in simply expires, at the next hourly sweep. Changing your password from inside the app ends every other sign-in rather than this one, so that phone keeps its address (see How long we keep things below).
What we deliberately do not collect
- No advertising, no profiling, and no analytics or tracking of you — not in the app, not on this website. The app does carry Google's messaging library, for the notifications described below and nothing else.
- No location, no contacts, no files, no browsing data.
- We do not sell or share your data with anyone for marketing.
Your Wi-Fi password never reaches us
When you set up a controller over Bluetooth, the Wi-Fi credentials you enter travel directly from your phone to the controller in front of you. They are stored encrypted on the controller itself and are never sent to our servers.
We send only the emails the service needs: registration codes, address verification, password resets, invitations, and security notices (for example, when somebody tries to register with an address that already has an account). Delivery is handled by Postmark (ActiveCampaign, Inc.), which processes the recipient address and message for us and for no other purpose. There is no newsletter and no marketing mail.
This website
These pages are served by Cloudflare (Cloudflare, Inc.) as our processor, which also routes mail addressed to support@retonis.com onward to the operator's mailbox. Serving a page and forwarding a message mean handling the connection they arrive on — the requesting address, the browser's own description of itself, and, for mail, the message and its sender — for delivery and for protection against abuse, and for nothing else. What this site does not do is stated once, above: no analytics, no advertising, no tracking of you anywhere.
Notifications
We can tell your phone when a controller goes offline or comes back, and about members joining, leaving or being removed and controllers being claimed or released. Those two are on by default; relay switching and update notices are off until you switch them on. Each is a switch per group, in the app's Account menu. Notifications are Android-only today.
Delivery is handled by Firebase Cloud Messaging (Google Ireland Limited) as our processor. What travels through it is an identifier for the controller and for the group, which kind of alert it is and which event within that kind, the moment it happened, and — depending on the event — a relay's channel number and new state, or a controller's firmware version. No name you chose, no address of yours, and no sentence we wrote ever leaves in it: what you read is composed by the app on your phone, from names it already holds. Your phone also contacts Google directly to obtain its delivery address, which is how any Android notification works. Messages may be handled on Google infrastructure outside the EEA, under the safeguards in Google's data processing terms.
History
The same events are also written down, so that the app can answer “what happened to my controllers, and when”. A record holds an identifier for the controller and for the group, which kind of alert it is and which event within that kind, the moment it happened, and — depending on the event — a relay’s channel number and new state, or a controller’s firmware version. For a relay it also holds what moved it: whether the controller was switched from an app, over your own network, by a schedule you set, or by its own power-on policy. That is a property of the controller and not of a person — it is exactly the same word whoever was holding the phone, and it is recorded so the app can say “this came on by itself” instead of implying somebody did it. For members joining, leaving or being removed, and controllers being claimed or released, it also holds who did it. Nothing else records a person — a relay switching does not tell us who sent the command, and we do not guess.
Everyone in a group reads the same history, but only from the moment they joined it: somebody invited today cannot read backwards into a time before they had access. Your notification switches do not affect it — they decide whether your phone rings, not what is written down.
How long we keep things
- Account data: for as long as the account exists.
- Unfinished registrations: 15 minutes, then discarded.
- Sessions: until they expire or you sign out.
- Notification addresses: no longer than the sign-in that registered them. Sign out on that phone, end every session at once, reset your password or delete your account, and the address is removed with the sign-in, at once. When a sign-in simply expires nothing more is sent to it from that second, and the record itself is cleared by a sweep that runs every hour. Changing your password from inside the app ends every other sign-in, so every other phone's address goes and the one you changed it on keeps its own. Nothing has to remember to remove it; it belongs to the session. (Signing out needs to reach us to end the sign-in itself: if the phone is offline at that moment, the address goes when that sign-in expires.) If you uninstall the app, the address is dropped the first time we try to reach it and Google tells us it is gone.
- Your notification choices: while the account exists.
- Queued notifications: up to a week after they are sent or expire. They hold identifiers and the event, never a name.
- History: 90 days, then deleted. If you delete your account, your name goes from those records at once and they read as “somebody”; if a group is deleted, its history goes with it.
- To delete your account and its data, use Delete account in the app (Account menu) — it takes effect immediately. Or email support@retonis.com from the account's address — deletion is completed within 30 days. Details.
Your rights
- Ask for a copy of the data we hold about you: email support@retonis.com from the account's address — answered within a month.
- Ask us to correct anything that is wrong, the same way.
- Delete your account — see above; the in-app way is immediate.
- Object to, or ask us to restrict, a particular use of your data, and ask for a copy in a portable form — the same address.
- Complain to a supervisory authority. In Romania that is the ANSPDCP (dataprotection.ro).
We handle all of the above because you asked us to run your controllers: the data on this page is what performing that service requires, and the security records are what keeping it safe requires.
Security
All connections use TLS. Each controller authenticates with its own certificate, issued while it is being made, and controllers are isolated from one another — one can never read or command another. Passwords are hashed with argon2id; every code and token is stored only as a hash.
Children
Retonis is not directed at children under 16 and we do not knowingly collect their data.
Changes
If this policy changes, the new version is published at this address with a new effective date.