EU-only, always
Every byte is stored and processed in the European Union, on Hetzner infrastructure in Germany. Your data never leaves the EU.
Managers see nothing
Employers see only anonymized, aggregated trends — never an individual's check-ins, chats, or mood. Enforced in the database, not just in policy.
Minimum by default
We collect only what a session needs. No ad trackers, no data brokers, no selling — ever.
Your data, your control
Export or permanently delete everything, any time, from inside the app. No email, no waiting.
Where your data lives
Hosted only in the EU. It never leaves.
Raki runs entirely on Hetzner infrastructure inside the European Union (Germany). There is no US region, no cross-border replication, and no transfer of personal data outside the EU. For European users and employers, data residency isn't an add-on — it's the only option we offer.
- ✓Application, database, and backup storage all located in the EU
- ✓No personal data transferred to third countries
- ✓Named subprocessor list available on request, with a signed DPA
Privacy by architecture
The wall between you and your employer is in the code.
Raki's enterprise plans subsidize personal accounts — but that subsidy buys an employer zero visibility into any individual. Managers see only anonymized aggregates above a minimum group size. Individual check-ins, companion conversations, and emotional data are never exposed to anyone in your organization. This is enforced at the database layer, so it can't be switched on by a setting or a support ticket.
- ✓No manager access to individual data — structurally, not optionally
- ✓Aggregates suppressed below a minimum group size to prevent re-identification
- ✓We never use your conversations to train models
- ✓No advertising SDKs and no third-party analytics on your private content
EU AI Act
Built to stay on the right side of the AI Act.
The EU AI Act, in force since February 2025, prohibits emotion recognition in the workplace and treats emotion inference as high-risk. Raki is designed around that line rather than against it: any ambient or emotional signal is aggregated and anonymized before an employer ever sees it, and no manager can infer an individual's emotional state from anything Raki provides.
- ✓No workplace emotion recognition targeting individuals (Art. 5)
- ✓Emotion inference treated as high-risk and kept out of employer hands
- ✓A Data Protection Impact Assessment (DPIA) documents the design
- ✓Aggregate-only outputs — the manager-facing product sees no person
Security practices
The essentials, done properly.
Encrypted in transit & at rest
All traffic uses TLS 1.3. Stored data and backups are encrypted at rest.
Least-privilege access
Production access is limited, authenticated, and logged. No shared credentials.
Isolated environments
Staging and production are fully separated, with no real user data in test.
Responsible disclosure
Found something? Email security@naraki.nu and we'll respond quickly.
Your rights
GDPR rights, one tap away.
Under the GDPR you can access, correct, export, or erase your personal data. In Raki, most of that is self-service — no ticket required.
- ✓Export your full data from Settings → Privacy
- ✓Delete your account and all associated data permanently
- ✓Request a Data Processing Agreement (DPA) for your organization
Data protection questions: privacy@naraki.nu
Where we're honest
What's in place today — and what's next.
We'd rather show you the real state of things than a wall of logos. Here's the honest picture.
In place today
- ✓EU-only hosting and data residency
- ✓GDPR alignment, DPA on request
- ✓Encryption in transit and at rest
- ✓Non-surveillance, aggregate-only enterprise design
- ✓DPIA for emotional-signal processing
On the roadmap
- ◦SOC 2 Type II examination
- ◦ISO 27001 certification
- ◦Independent penetration-test report
Doing security due diligence?
We'll send our security pack, subprocessor list, and DPA — and answer your questionnaire.
Request the security packOr email us at security@naraki.nu