LocoLinkANDROID · WETO MEDIA
LocoLink · Android

Privacy on Android

How LocoLink handles your model railway, licence and support data.

Effective 14 September 2026

Who is responsible?

LocoLink for Android is provided by WETO Media, Renselweg 1, 9672 AX Winschoten, the Netherlands, Chamber of Commerce number 96618043. WETO Media is responsible for the processing described here. Contact info@locolink.io about your personal data. This policy covers the Android app distributed through Google Play.

Your railway and files

Projects, locomotives, routes and settings are stored on your device. Connections to command stations, cameras, feeds and club services exchange the information needed with the devices or services you configure. Those destinations may be outside your home network. Your railway projects are not automatically uploaded to LocoLink.

You choose which files to import, export or share. Exported and shared copies remain at their chosen destinations. Android system backup may retain projects and settings according to your device settings. The current app excludes its installation identifier and licence cache from system backup. Restoring the app creates a new installation identity and can require licence activation again.

Existing licences

Activation and validation send your licence key, activation identifier and installation information to the licence service. Depending on the service, this includes a generated device identifier, device label, operating system and version, app version, hostname, language, region and time zone. The response may contain the associated licence and customer details. The app stores a local licence cache to remember access.

The LocoLink service records activation and usage times, country information and an IP-derived code for licence administration and abuse prevention. This code is not anonymous. Older licences can be checked through Polar. Deactivating a device removes its active association; it does not automatically erase the licence or all historical records. Android supports existing licences and does not provide purchases or account registration.

Update checks

The app automatically checks for updates using the app family, platform and current version. This request does not contain a licence key. The receiving infrastructure processes connection information, including the IP address. Android app updates are offered through Google Play.

Support and bug reports

Sending the in-app bug form submits your message, timestamp and app/system version. An address for a reply is optional. Additional diagnostics are off by default. Enabling them adds technical information such as licence status, command-station configuration, project counts, support text and logs. You can preview the client report before sending. The server also adds a report identifier, User-Agent, country and IP-derived code, which are not shown in that local preview. Reports pass through Resend to our Zoho Mail support mailbox.

Known full licence keys, activation/device identifiers and the known customer email are filtered from automatically added diagnostics. This does not detect every personal detail. Check your message and diagnostic content before sharing. Other support actions prepare an editable email, copy text or open Android’s share sheet. These can contain device information, a masked licence key and, for a shared support package, an optional screenshot. Text filtering does not redact screenshots. You choose the recipient and send the prepared email yourself.

Why we process data

We process licence and necessary support information to perform our agreement with you. Our legitimate interests in operating a reliable service, fixing faults and preventing licence abuse support necessary technical and security processing; we limit this to what is needed. Optional additional diagnostics are provided with your consent. You can stop sending them and withdraw consent for further processing by contacting us. Withdrawing consent does not affect earlier lawful processing. We also retain information when a specific legal obligation requires it.

Services and international processing

Cloudflare operates the licence, update and bug-report endpoints, licence storage and infrastructure logs. Polar handles older licences. Resend delivers in-app bug reports. Zoho Mail receives and stores support correspondence. Google Play distributes the app; Android can handle system backup. Services you choose for cameras, feeds, sharing or email process the information you send to them.

The Zoho account uses the EU region. Resend sends from Ireland but stores email data in the United States. Cloudflare and other providers use international infrastructure and subprocessors. EU account or sending regions do not guarantee that every processing operation stays in the EU. Relevant provider terms describe transfer safeguards, including standard contractual clauses where applicable. You can request information about the safeguards relevant to your data from us; provider documents are linked below.

Retention and deletion

Local data remains until you delete it in the app, clear Android app data or uninstall. Manage exported copies and system backups separately. We retain licence information while the licence remains valid. Our policy limits technical licence history and residual information about deactivated devices to 90 days, except information needed for an ongoing abuse investigation.

We retain resolved support messages and bug reports for no more than 12 months after closure, deleting personal diagnostics sooner when no longer needed. WETO Media checks these periods manually each month and handles deletion requests individually. This is not a promise of automatic deletion. Information necessary for a specific legal duty or dispute is retained separately for that purpose and reviewed.

Provider copies have separate cycles: Cloudflare Workers Logs on our current plan: 3 days; Resend email/logs: 30 days, backups: 7 days; Zoho may retain mail for recovery for 30 days after deletion from Trash. A deletion from our working records does not instantly remove these recovery copies.

Security

Licence, update and in-app support requests use HTTPS. Access to the licence administration uses passkeys. Model railway protocols and destinations you configure may use unencrypted connections. Email delivery also depends on the receiving mail service; the current sending configuration permits opportunistic TLS. We therefore do not promise that every connection in every feature is encrypted.

Your choices and rights

Email info@locolink.io to request access, correction, deletion, restriction or portability, or to object to processing where applicable. You do not need to create an account or activate a licence to make a request. Describe the data or interaction concerned; do not send a password, full licence key or identity document unless a specific secure verification step has been agreed. We verify that a request concerns your information and explain any lawful exception to deletion. You may complain to the Dutch Autoriteit Persoonsgegevens or your local supervisory authority.

We update this policy when relevant processing changes. A new feature that requires an explanation or consent will also provide it in the app. The current Android release has no configured LocoLink AI gateway.