Privacy Policy

Retonis · effective 25 August 2026

Retonis lets you control and monitor your relay controllers from your phone or computer. This policy says exactly what data the Retonis app and service handle, why, and what never leaves your home. It is written to be read.

Who we are

Retonis is operated by DRAGOȘ HAȚEGAN PERSOANĂ FIZICĂ AUTORIZATĂ, a sole trader registered in Romania (CUI 52620811), who is the controller of the personal data described here. The registered office, trade register number and full identification are on the legal notice, which is the one place they are stated. For anything in this policy, write to support@retonis.com.

What we collect, and why

What we deliberately do not collect

Your Wi-Fi password never reaches us

When you set up a controller over Bluetooth, the Wi-Fi credentials you enter travel directly from your phone to the controller in front of you. They are stored encrypted on the controller itself and are never sent to our servers.

Email

We send only the emails the service needs: registration codes, address verification, password resets, invitations, and security notices (for example, when somebody tries to register with an address that already has an account). Delivery is handled by Postmark (ActiveCampaign, Inc.), which processes the recipient address and message for us and for no other purpose. There is no newsletter and no marketing mail.

This website

These pages are served by Cloudflare (Cloudflare, Inc.) as our processor, which also routes mail addressed to support@retonis.com onward to the operator's mailbox. Serving a page and forwarding a message mean handling the connection they arrive on — the requesting address, the browser's own description of itself, and, for mail, the message and its sender — for delivery and for protection against abuse, and for nothing else. What this site does not do is stated once, above: no analytics, no advertising, no tracking of you anywhere.

Notifications

We can tell your phone when a controller goes offline or comes back, and about members joining, leaving or being removed and controllers being claimed or released. Those two are on by default; relay switching and update notices are off until you switch them on. Each is a switch per group, in the app's Account menu. Notifications are Android-only today.

Delivery is handled by Firebase Cloud Messaging (Google Ireland Limited) as our processor. What travels through it is an identifier for the controller and for the group, which kind of alert it is and which event within that kind, the moment it happened, and — depending on the event — a relay's channel number and new state, or a controller's firmware version. No name you chose, no address of yours, and no sentence we wrote ever leaves in it: what you read is composed by the app on your phone, from names it already holds. Your phone also contacts Google directly to obtain its delivery address, which is how any Android notification works. Messages may be handled on Google infrastructure outside the EEA, under the safeguards in Google's data processing terms.

History

The same events are also written down, so that the app can answer “what happened to my controllers, and when”. A record holds an identifier for the controller and for the group, which kind of alert it is and which event within that kind, the moment it happened, and — depending on the event — a relay’s channel number and new state, or a controller’s firmware version. For a relay it also holds what moved it: whether the controller was switched from an app, over your own network, by a schedule you set, or by its own power-on policy. That is a property of the controller and not of a person — it is exactly the same word whoever was holding the phone, and it is recorded so the app can say “this came on by itself” instead of implying somebody did it. For members joining, leaving or being removed, and controllers being claimed or released, it also holds who did it. Nothing else records a person — a relay switching does not tell us who sent the command, and we do not guess.

Everyone in a group reads the same history, but only from the moment they joined it: somebody invited today cannot read backwards into a time before they had access. Your notification switches do not affect it — they decide whether your phone rings, not what is written down.

How long we keep things

Your rights

We handle all of the above because you asked us to run your controllers: the data on this page is what performing that service requires, and the security records are what keeping it safe requires.

Security

All connections use TLS. Each controller authenticates with its own certificate, issued while it is being made, and controllers are isolated from one another — one can never read or command another. Passwords are hashed with argon2id; every code and token is stored only as a hash.

Children

Retonis is not directed at children under 16 and we do not knowingly collect their data.

Changes

If this policy changes, the new version is published at this address with a new effective date.


Retonis · support@retonis.com · Legal notice