Trust & security

Trust you can verify,
not just claims.

Raki holds your most private moments. Here is exactly where your data lives, who can reach it, and how our architecture — not our promises — keeps it that way.

Request the security packRead the privacy policy

EU-only, always

Every byte is stored and processed in the European Union, on Hetzner infrastructure in Germany. Your data never leaves the EU.

Managers see nothing

Employers see only anonymized, aggregated trends — never an individual's check-ins, chats, or mood. Enforced in the database, not just in policy.

Minimum by default

We collect only what a session needs. No ad trackers, no data brokers, no selling — ever.

Your data, your control

Export or permanently delete everything, any time, from inside the app. No email, no waiting.

Where your data lives

Hosted only in the EU. It never leaves.

Raki runs entirely on Hetzner infrastructure inside the European Union (Germany). There is no US region, no cross-border replication, and no transfer of personal data outside the EU. For European users and employers, data residency isn't an add-on — it's the only option we offer.

  • Application, database, and backup storage all located in the EU
  • No personal data transferred to third countries
  • Named subprocessor list available on request, with a signed DPA

Privacy by architecture

The wall between you and your employer is in the code.

Raki's enterprise plans subsidize personal accounts — but that subsidy buys an employer zero visibility into any individual. Managers see only anonymized aggregates above a minimum group size. Individual check-ins, companion conversations, and emotional data are never exposed to anyone in your organization. This is enforced at the database layer, so it can't be switched on by a setting or a support ticket.

  • No manager access to individual data — structurally, not optionally
  • Aggregates suppressed below a minimum group size to prevent re-identification
  • We never use your conversations to train models
  • No advertising SDKs and no third-party analytics on your private content

EU AI Act

Built to stay on the right side of the AI Act.

The EU AI Act, in force since February 2025, prohibits emotion recognition in the workplace and treats emotion inference as high-risk. Raki is designed around that line rather than against it: any ambient or emotional signal is aggregated and anonymized before an employer ever sees it, and no manager can infer an individual's emotional state from anything Raki provides.

  • No workplace emotion recognition targeting individuals (Art. 5)
  • Emotion inference treated as high-risk and kept out of employer hands
  • A Data Protection Impact Assessment (DPIA) documents the design
  • Aggregate-only outputs — the manager-facing product sees no person

Security practices

The essentials, done properly.

Encrypted in transit & at rest

All traffic uses TLS 1.3. Stored data and backups are encrypted at rest.

Least-privilege access

Production access is limited, authenticated, and logged. No shared credentials.

Isolated environments

Staging and production are fully separated, with no real user data in test.

Responsible disclosure

Found something? Email security@naraki.nu and we'll respond quickly.

Your rights

GDPR rights, one tap away.

Under the GDPR you can access, correct, export, or erase your personal data. In Raki, most of that is self-service — no ticket required.

  • Export your full data from Settings → Privacy
  • Delete your account and all associated data permanently
  • Request a Data Processing Agreement (DPA) for your organization

Data protection questions: privacy@naraki.nu

Where we're honest

What's in place today — and what's next.

We'd rather show you the real state of things than a wall of logos. Here's the honest picture.

In place today

  • EU-only hosting and data residency
  • GDPR alignment, DPA on request
  • Encryption in transit and at rest
  • Non-surveillance, aggregate-only enterprise design
  • DPIA for emotional-signal processing

On the roadmap

  • SOC 2 Type II examination
  • ISO 27001 certification
  • Independent penetration-test report

Doing security due diligence?

We'll send our security pack, subprocessor list, and DPA — and answer your questionnaire.

Request the security pack

Or email us at security@naraki.nu