rekko.

English · Français · Deutsch · Español · Italiano · Português (Brasil) · 日本語 · 한국어

Privacy Policy

Last updated: June 8, 2026

Rekko is built around a simple promise: your data stays yours. What you watch, what you rate, the friends you share with — none of it lives on our servers. This page explains, in plain language, what data Rekko handles, where it goes, and how you can control or delete it at any time.


1. Who is responsible for your data?

Rekko is developed and operated by Jean-Baptiste Meyer ("we", "us"), acting as the data controller under the General Data Protection Regulation (GDPR / RGPD).

Any question about this policy or your data can be sent to jib@jibstudios.com.

2. What data Rekko handles

Rekko collects only what is strictly necessary to make the app work. Concretely:

Rekko does not collect: your contacts, your location, your microphone, your browsing history, your advertising identifier, or any third-party analytics. There is no in-app tracking SDK.

3. Where your data is stored

Personal data is stored in your own private iCloud space, via Apple's CloudKit framework. We do not have a server holding a copy. Specifically:

4. Third parties involved

5. Legal basis

All processing of personal data is based on your consent (GDPR art. 6(1)(a)) — given when you sign in and create your profile — and on the performance of a contract (art. 6(1)(b)) for the functionality you actively request (creating a circle, sending a recommendation, etc.).

6. How long we keep your data

For as long as your account exists. When you delete your account from the Rekko settings, your local database is wiped, the App Attest key tied to your installation is invalidated, your CloudKit zones (shared and private) are torn down, and your sign-in identifier is cleared from the keychain. Members of circles you owned are notified that the share is gone and the bookmark disappears from their device.

Because Rekko never stores a Sign in with Apple token (we keep only the opaque userIdentifier on your device, in your local keychain), there is no token for us to revoke server-side. If you want to additionally invalidate the Sign in with Apple authorisation on Apple's side, you can do so at any time from iOS Settings → your name → Password & Security → Apps Using Apple ID → Rekko → Stop using Apple ID.

7. Your rights under GDPR

You can exercise the following rights at any time:

To exercise any of these rights, including a manual data request when the in-app flows are not enough, write to jib@jibstudios.com. We will reply within 30 days at most.

8. Permissions Rekko may ask for

9. Children

Rekko is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has signed up, please contact us and we will delete the corresponding account.

10. Changes to this policy

We may update this policy when the app or applicable law change. We will update the "Last updated" date at the top of this page, and a meaningful change will be surfaced in-app the next time you open Settings.