Your rights, by where you live
The Privacy Notice describes what Runeka collects and why, and it applies to everyone. This page adds what the law where you live gives you on top of it — the authority you can complain to, the extra consents we need, and who represents us in your country.
How to read this page
Find your region below. Everything in the Privacy Notice still applies; the section for your region adds to it, and where the two ever conflict, the one for the country you live in wins. If your country is not listed, the last section covers you.
Three things are true in every region, under every law on this page:
- We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we show no ads. There is no version of Runeka where your Diary funds the product.
- Diary and wellbeing content is treated as sensitive everywhere — not only where a statute happens to name it. It stays on your device unless you switch a cloud feature on and invoke it, and it always needs its own separate consent.
- Exercising a right is free and never costs you access to the product.
European Union and EEA
The GDPR is the base the whole Privacy Notice is written to, so there is nothing extra to add here — the legal bases, the Art. 9(2)(a) explicit consent for cloud Diary processing, retention, transfers, and your rights are all in the Privacy Notice itself.
You can complain to the data-protection authority of the country where you live, where you work, or where the problem happened.
Runeka is established in Slovenia, so you are dealing with us directly rather than through a representative.
Your consumer rights on purchases — the 14-day withdrawal right and the statutory conformity guarantee — are in the Terms of Use.
United Kingdom
We process your data under the UK GDPR and the Data Protection Act 2018. Your rights match the EU set: access, rectification, erasure, restriction, portability, and objection, answered within one month and free of charge.
Cloud Diary processing rests on your explicit consent, because Diary text can reveal health information, which UK law treats as special category data.
Where data leaves the UK, the transfer rests on the UK Extension to the EU–US Data Privacy Framework for certified US providers, or on the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
You can complain to the Information Commissioner's Office (ICO) at ico.org.uk. We would rather you told us first, but you never have to.
Switzerland
We process your data under the revised Federal Act on Data Protection (revFADP), in force since 1 September 2023. Diary and wellbeing content is sensitive personal data under Swiss law, so cloud processing of it needs your express consent — which is how the product already works.
You can request access, rectification, deletion, and the handover of your data, and you can object to processing. Transfers to the United States rest on the Swiss–US Data Privacy Framework for certified providers, recognised as adequate since 15 September 2024, or otherwise on standard contractual clauses adapted for Switzerland.
You can complain to the Federal Data Protection and Information Commissioner (FDPIC).
United States
HIPAA does not cover what you write here
This matters more than anything else in this section, so we will say it plainly: Runeka is not a healthcare provider, health plan, or healthcare clearinghouse, and we are not anyone's business associate. HIPAA therefore does not apply to your Diary entries, mood check-ins, or reflections. Many people assume any app that touches mental wellbeing is HIPAA-covered. It is not, and neither is this one. What protects your entries is that they stay on your device by default.
Consumer health data — Washington and Nevada
Washington's My Health My Data Act and Nevada's SB 370 regulate consumer health data specifically, and unlike the state privacy laws below they apply regardless of how small a company is. Washington requires that policy to be published separately rather than buried in a general notice, so it has its own page: the Consumer Health Data Privacy Policy.
State privacy laws, and where we actually stand
The CCPA/CPRA in California, and the comparable laws in Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and the other states that have them, apply above thresholds — broadly, annual revenue in the tens of millions of dollars, or handling personal information about roughly 100,000 or more consumers, or making a large share of revenue from selling personal data. Runeka currently meets none of them, so most of these laws do not yet bind us.
We would rather give you the rights than the exemption. Wherever you live in the United States, you can ask us to:
- tell you what personal information we hold about you, and give you a copy;
- correct it if it is wrong;
- delete it;
- limit how we use information you consider sensitive; and
- appeal, to a human, if we turn one of those requests down.
We will not discriminate against you for asking — no worse price, no degraded product. There is no opt-out of sale, sharing, targeted advertising, or profiling to offer you, because we do none of those things: we have never sold or shared personal information as the CCPA defines those terms, we do not process it for cross-context behavioural advertising, and we do not disclose it to third parties for their own direct marketing under California's Shine the Light law. We honour the Global Privacy Control signal, though for the same reason there is nothing for it to switch off.
Breach notification
As a health app that HIPAA does not cover, we are subject to the FTC's Health Breach Notification Rule. If identifiable health information we hold were breached, we would notify you and the Federal Trade Commission within the deadlines the rule sets, alongside any state notification duties.
Canada
We process your data under PIPEDA, which applies to us because we offer the Service commercially to people in Canada. Health-revealing Diary content is sensitive information, and Canadian law expects express consent for it — which matches the separate, explicit consent the product already asks for.
You can ask for access to what we hold, ask us to correct it, and challenge our handling of it. If a breach created a real risk of significant harm, we would report it to the Office of the Privacy Commissioner of Canada, tell you, and keep a record of it. You can complain to the OPC at any time.
Quebec. Law 25 adds more: your right to receive your data in a structured, commonly used technological format, your right to ask that a search-engine link to your information be de-indexed, and confirmation that we make no automated decision about you with a significant effect — licensing, quota, and fraud checks apply simple rules and support can review any disputed outcome. Requests go to support@runeka.com, which reaches the person accountable for privacy at Runeka.
For completeness: the federal privacy bill that would have replaced PIPEDA did not become law, so PIPEDA is what governs here.
Australia
We handle your data under the Privacy Act 1988 and the Australian Privacy Principles. There is a small-business exemption in that Act, and we want to be direct about it: it is narrow, it does not extend to organisations holding health information, and Diary and wellbeing content is health information. We therefore do not rely on the exemption, and we apply the APPs whatever our size.
You can request access to your personal information (APP 12) and ask us to correct it (APP 13). When we disclose data to a provider overseas, we stay accountable for how they handle it (APP 8). If an eligible data breach occurred, we would notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. You can complain to the OAIC.
Australia's statutory tort for serious invasions of privacy commenced in 2025, and nothing in our terms limits it. Your non-excludable rights under the Australian Consumer Law are in the Terms of Use.
Brazil
We process your data under the LGPD (Lei nº 13.709/2018), which applies because we offer the Service to people in Brazil. Diary and wellbeing content that concerns health is sensitive personal data under Art. 5, II, so cloud processing of it rests on the specific, highlighted consent Art. 11 requires — asked separately and refusable without losing the rest of Runeka.
Under Art. 18 you can ask us to confirm we process your data, give you access to it, correct it, anonymise, block, or delete it, hand it over in portable form, tell you who we share it with, and withdraw a consent you gave. International transfers rest on the ANPD's standard contractual clauses or another basis Art. 33 allows. You can complain to the Autoridade Nacional de Proteção de Dados (ANPD).
Our communication channel for data subjects is the privacy address at the end of this page.
Japan
We handle personal information under the Act on the Protection of Personal Information (APPI), which reaches us because we supply the Service to people in Japan. Diary content that concerns medical history is special care-required personal information, so we take your opt-in consent before any cloud processing of it.
Providing personal data to a third party outside Japan needs your consent together with information about the destination country and its data-protection regime, or equivalent safeguards — the Privacy Notice lists our providers and where they process. You can request disclosure of what we hold, correction of it, and suspension of its use. You can raise concerns with the Personal Information Protection Commission (PPC).
You can reach us at the privacy address at the end of this page. We answer in English.
South Korea
We process personal information under the Personal Information Protection Act (PIPA). Health-related Diary content is sensitive information, which PIPA requires us to ask about separately from every other consent — not bundled into a single "I agree". Transferring personal information abroad needs its own consent too, and we tell you the recipient, the country, the purpose, and how long it is kept before you give it.
You can access your personal information, correct it, delete it, and demand that processing stop. You can complain to the Personal Information Protection Commission (PIPC).
Write to support@runeka.com and you reach us directly.
India
We process digital personal data under the Digital Personal Data Protection Act, 2023, whose obligations are phasing in under its rules. It applies to us because we offer the Service to people in India. We give notice of what we collect and why in plain language before asking for consent, and you can withdraw that consent as easily as you gave it.
You can ask for a summary of the data we process and who we share it with, ask us to correct or complete it, ask us to erase it, nominate someone to exercise your rights if you cannot, and raise a grievance with us before going to the Data Protection Board of India. The heightened obligations for Significant Data Fiduciaries apply above thresholds we do not meet.
Grievances go to the privacy address at the end of this page, which reaches the person accountable for privacy at Runeka.
South Africa
We process personal information under POPIA (Protection of Personal Information Act 4 of 2013). Diary and wellbeing content concerning health is special personal information under section 26, so we process it only with your consent or another ground section 27 allows.
You can ask what we hold, ask us to correct or delete it, and object to processing. You can complain to the Information Regulator (South Africa).
You can reach our Information Officer at the privacy address at the end of this page.
Everywhere else
If you live somewhere this page does not name, the Privacy Notice still describes how we handle your data, and we apply the same practices to everyone: local by default, opt-in for anything that leaves your device, no sale, no ads. Where your national law gives you rights we have not listed, write to us and we will honour them where they apply. Nothing on this page asks you to give up a right your law says you cannot waive.
How to exercise any of these rights
One address for all of it: support@runeka.com. Tell us what you want and roughly where you live, so we apply the right rules. We answer within one month where the GDPR, UK GDPR, or a comparable law sets that deadline, and sooner where your law requires it. We may need to check that the request is really from you, and we will not ask for more information than that check needs. It is free, and turning you down without a route to appeal is not something we do.
Read this page alongside the Privacy Notice, the Terms of Use, and the AI & wellbeing disclaimer.
Last updated: August 18, 2026.
