Privacy Policy
How R-ESM LLC processes personal data in the StateNull and StateNull-SecoM services. Effective 12 July 2026 · last updated 30 September 2026. Questions: media.supply@statenull.com.
Who we are (data controller)
The data controller is R-ESM LLC (Royal Enterprise Service Management), 30 N Gould St # 38144, Sheridan, WY 82801, USA (see the Impressum). For organisations that enrol their members, that organisation is the controller for its members' work data and R-ESM acts as its processor.
What we process
- Account data — your e-mail address, optional display name and @handle, and a one-way (scrypt) hash of your password. Used to create and secure your account. At account creation we derive an approximate service region (e.g. EU, US, Asia-Pacific) from your network address so your account is placed near you; the address itself is not stored — only the chosen region — and you can change the region in your account at any time.
- Subscription & billing data — your plan, trial/renewal status, and the billing details you provide at checkout (handled by Paddle — see Payments).
- Communications & files — your messages, calls and shared files are end-to-end encrypted. Our servers act as a blind relay and store only opaque ciphertext; R-ESM LLC cannot read your content (zero-knowledge). To operate the service our servers do process account, request and delivery metadata — file names, sizes, types, recipients and timestamps — never the contents.
- Captured media (StateNull-SecoM) — photos, scans, PDFs, video and voice notes are encrypted on your device and uploaded as opaque ciphertext under your own keys.
- Managed devices — on devices enrolled by an organisation (MDM), the organisation administrator can view device inventory (model, OS, battery, installed-app list, compliance) and issue management actions (e.g. lock/wipe). This is controlled by the organisation, not by R-ESM LLC.
- Sending addresses (optional) — if you add your own mail server so messages to your customers come from your address, we store its server name, port, username, sender name and address, and the password you enter, encrypted with a key held on our server outside the data volume. The server must be able to use it to send on your behalf, so this is not zero-knowledge: it protects a leaked disk or backup, not a compromised running server. It is used only to send the messages you trigger, never to read your mailbox. You can delete it at any time; revoke the password at your provider as well.
- People you ask us to notify (optional) — when you add e-mail addresses or @handles to "Notify when it's submitted", we store them on that request (and as your defaults, if you save them) and use them only to tell those people that the request was submitted, with a short delivery record (sent or failed) per person. Each e-mail is sent on its own, so an address you mark BCC is never shown to anyone else. The message names the request and your office — never the files, their names, their contents or any key.
- In-app notices — an @handle you notify receives a notice in the app and portal instead of an e-mail: the request title, your office's name, the number and total size of the files, and when it was submitted.
- Videos you send (optional) — a video you upload to send to specific people is encrypted in your browser before it leaves it; we store only the ciphertext, the title you give it, its size and type, and its key sealed to your own Review Key (we cannot open it). For each personal link we store the name you type for that person (shown in their watermark and your receipts — it is your label, not a checked identity), its limits (views, expiry, whether a code is needed — the code and the link itself are kept only as one-way hashes) and view receipts: when a view started and was last active, and how far and how long the player reported it played. Screen recording cannot be prevented by any web page, and we do not claim otherwise.
- Capture location (optional) — inside the encrypted capture; the server cannot read it.
- Job site point (optional) — stored with the job, deleted with it. If the office adopts the crew's pin as the site, that point, rounded to about 11 m, is stored with the job. The crew's pin itself is sent end-to-end encrypted; the server cannot read it.
- Address search — only when the office presses “Find from address”, the site address is sent to the OpenStreetMap Foundation's Nominatim service (UK). It is not a sub-processor; we cache the result (without the address) for 90 days.
- Customer decisions — the name the customer types when they accept or do not accept is stored readable with the job. Drawn signature (optional): encrypted on the customer's device, deleted with the job, never registered publicly.
- Counter-signature — the office's optional receipt of a customer decision. The certificate serial is kept after erasure so the signature stays checkable.
- Registered Proof Packs — when an office registers a Proof Pack, a public registry entry holds only fingerprints (hashes) and a time; the pack's details (office name, item fingerprints) are kept in a separate record that is deleted with the job or the account, after which the entry reads “details deleted at the sender's request”.
- Company domain (optional) — the domain your office adds and the DNS record value we ask it to publish; we look that record up in public DNS when you press Check now and once a day while the domain is shown. Removed when you remove the domain or close the account.
- Notification settings — which notices and e-mails you turned off (only the switches you changed are stored).
- Videos your customers send (optional) — when an office asks for a video, the customer records it in their browser or uploads one; it is encrypted in their browser before it leaves it and stored as ciphertext with the job. Sound is recorded only when the customer chooses it. We store the video's size, type and arrival time, and whether the customer's page reported it as a browser recording or an uploaded file (a report by that page, not a check we make). Videos recorded or uploaded in a browser are received files, not sealed captures.
- Live look (optional) — a live video call between an office and its customer is end-to-end encrypted and not recorded by us. The customer's own browser records it only if the customer chooses “Join and record”, and sends that recording only when the customer presses Send. We store with the job who agreed (the office or the customer), whether recording was chosen and when, and the office's optional answer to “Saved a trip?”.
- Checking a video — “Check this video” and statenull.com/verify compute a video's fingerprint on the viewer's device; only the fingerprint is sent to us, never the video.
- Viewers confirmed by e-mail code or @handle (optional) — if you choose that a person receives a code by e-mail before watching a video you send, we store that address on the link (shown masked, deleted with the link) and e-mail it a 6-digit code — never a link or a key; the code is kept only as a one-way hash and expires after 10 minutes. If you choose an @handle, the link names that StateNull account and the viewer signs in to watch. View receipts record which way a view was opened. This shows control of a mailbox or an account, nothing more.
- Go live (optional, when available) — a live video to the people you choose is end-to-end encrypted and not recorded. We store its title, the names you type for each viewer's link, when each viewer joined and for how long (reported by our media server), and the live minutes used.
- Job conversations — messages between an office and its customer about a job are end-to-end encrypted; the people at the office who hold a Review Key can read them, and the customer is told so. We store the ciphertext, the office member's @handle and the times.
- Web passkeys (optional) — for each passkey you add we store its public key, its credential id and a hash of it, the authenticator model identifier (used to show a name such as “iCloud Keychain”), your browser's user-agent string when you added it, when it was added and last used, and a signature counter. Your fingerprint, face and the private key never reach us. A passkey saved in Google Password Manager, iCloud Keychain or another password manager can be used on every device signed in to that manager. If you let a passkey open evidence (when that option is available), we store your office key encrypted under a key only that passkey can produce; we cannot open it. We e-mail you when a passkey is added.
- Visits (optional) — the times an office proposes, the time the customer picks (or that none of them work) and the office's reminder settings are stored with the job. The Status link shows a visit only as “being arranged” or as the picked time, and hides the street while a visit is proposed or picked; the proposed times are shown only through the pick link the office sends. The calendar file holds the time, the length, the office's name and its contact line.
- Street map — the map around a job site is served by StateNull from its own servers (map data © OpenStreetMap contributors); no Google or public map server is contacted, and we do not log which map areas an account views. Street detail for a region is downloaded by us as a whole region, so the upstream host learns only which regions we chose.
- Text search in your photos (app, optional) — text in your photos is read on your phone only; the search index stays on that phone and is never sealed, uploaded or included in backups or exports.
- Organisation members — when an organisation's admin suspends a member, we store when, by whom and an optional reason with the organisation. Jobs an admin hands over move to the chosen colleague's account. When an organisation member's account is deleted, the jobs they owned for the organisation move to the organisation's owner instead of being deleted, and the member's name is removed from them.
- Support & cancellation requests — the e-mail address and message you send us.
- Operational & security logs — minimal logs needed to run the service securely and prevent abuse.
Legal bases for processing (GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)) — to create your account and provide the subscription you signed up for.
- Legal obligation (Art. 6(1)(c)) — to keep the billing and tax records required by law.
- Legitimate interests (Art. 6(1)(f)) — to secure the service, prevent fraud and abuse, and maintain reliability.
- Consent (Art. 6(1)(a)) — where we specifically ask for it (e.g. optional communications); you can withdraw consent at any time.
What we do NOT do
- We do not sell or rent your personal data.
- We do not read your end-to-end-encrypted content.
- We do not use your content for advertising or profiling.
- We do not read, list or search the mailbox of a sending address you add — it is used only to send the messages you trigger.
Security
Transport is TLS 1.3 with certificate pinning; content is encrypted with AES-256-GCM. Every photo, scan and PDF capture is signed with a hybrid of classical (RSA-PSS) and post-quantum (ML-DSA-65 / FIPS-204) signatures, so any later change to a sealed file is detectable on verification — the signature scheme is chosen to stay robust even against future quantum computers. Encryption is on by default. (Post-quantum key exchange for the transport channel — ML-KEM / FIPS-203 — is on our roadmap, not yet shipped; our post-quantum protection today is in the signatures.)
Payments
When you purchase a subscription, payment is processed by our reseller and Merchant of Record, Paddle.com Market Ltd ("Paddle"). To process your order and calculate tax, Paddle receives the billing data it needs — such as your name, e-mail, billing address and payment-method details — under Paddle's own privacy policy. R-ESM LLC does not receive or store your full payment-card number.
Sub-processors
We use a small number of vetted service providers who process data on our behalf under data-processing terms:
- Paddle.com Market Ltd (United Kingdom) — payment processing & Merchant of Record.
- Hetzner Online GmbH (European Union) — cloud hosting / infrastructure; the service and its encrypted stores are hosted in the EU. Accounts on a non-EU service region additionally use Hetzner call infrastructure in that region (calls remain end-to-end encrypted).
- Google LLC — Google Workspace for transactional and support e-mail; Google Cloud Storage for the encrypted file store of accounts on a non-EU service region (US regions: Northern Virginia, USA; Singapore region: Singapore) — content remains end-to-end encrypted; the buckets are zero-knowledge.
We will update this list as our providers change.
Other recipients — OpenStreetMap Foundation (United Kingdom): its Nominatim service receives a job's site address only when an office presses “Find from address”, under the Foundation's own privacy policy. Offices can switch address search off (on-premise) and place the site by hand.
International data transfers
The service and your encrypted data are hosted in the EU by default. If your account uses a non-EU service region (detected at signup or chosen by you), calls connect through infrastructure in that region and, where regional storage is offered, new files are stored there — always end-to-end encrypted either way. R-ESM LLC is established in the United States, and some sub-processors are outside the EEA (e.g. the USA and the UK). Where personal data is transferred outside the EEA, we rely on an appropriate safeguard — an adequacy decision (the UK benefits from EU adequacy) or the EU Standard Contractual Clauses — or on your explicit consent.
Cookies & analytics
Our website and portal use only essential / session cookies needed to sign you in and keep the service secure. We do not use advertising, cross-site tracking, or third-party analytics cookies. Because there are no non-essential trackers, no cookie-consent banner is required.
Retention
- Account data — kept while your account is active. A verified deletion request runs a fixed erasure inventory across every server-side store: the account record, sessions and tokens, encrypted content and backups, support tickets, proof-request jobs and guest uploads, messages, shares, meetings, certificates metadata, agent workspaces and avatars; device records are pseudonymised and the organisation record is scrubbed. Completed within about 30 days of the request, unless a longer period is legally required.
- What remains after deletion, and why — only records with an explicit rule: billing rows referenced by opaque Paddle identifiers with the e-mail address blanked (statutory bookkeeping), issued certificates and public-key history (so records you sealed and signatures you made before deletion remain independently verifiable), and the deletion entry in the tamper-evident audit log (the retained fact that an erasure happened).
- Encrypted content — kept per your storage settings; removed when you delete it or close the account. A large file whose upload was abandoned is removed after 48 hours.
- People you ask us to notify & in-app notices — recipients stay with the request until you change them, delete the request or close the account; saved defaults until you change them; in-app notices for up to 90 days (at most the latest 200). All of it is removed when the account is deleted.
- Videos you send, their links and receipts — kept until you delete the video (which stops every link to it at once and removes the video, its links, the names you typed and the receipts) or close the account; a stopped or expired link keeps its receipts until then (at most the latest 200 per link). A video upload you abandon is removed after 48 hours.
- Job site points, crew pins, customer decisions and drawn signatures — kept with the job and deleted with it. When the crew member who pinned a site closes their account, the pin (and a site point taken from it) is removed from the job. Address-search results are cached for 90 days (a “no result” for 24 hours), keyed without the address, and removed with the account that asked.
- Registered Proof Packs — the pack's details are deleted with the job or the account; the public registry entry (fingerprints and a time only) stays, so a person holding a copy can still see that a pack was registered and when. The registry's lookup index holds the same fingerprints and goes with its tenant.
- Company domain — until you remove it or close the account. A request whose DNS record never appears expires after 7 days.
- Customer videos, Live look recordings and job conversations — kept with the job and deleted with it.
- Viewer e-mail addresses on video links — until the link or its video is deleted, or the account is closed; an e-mail code expires after 10 minutes.
- Passkeys — until you remove them, reset your password (which removes them) or close the account.
- Visits — with the job; the job's archive record keeps only the picked time.
- Go live records — removed when the account is deleted.
- Support & cancellation records — kept for up to about 24 months.
- Billing & tax records — retained by Paddle (and by us where required) for the period required by tax law, typically up to 6–10 years in the EU/UK.
- Security logs — minimal and rotated, typically within about 90 days.
Your rights
Subject to applicable law (including the EU/UK GDPR), you have the right to access, rectify, erase (be forgotten), restrict, and port your personal data, to object to certain processing, and to withdraw consent at any time. To exercise any of these, contact media.supply@statenull.com; we respond within the statutory time limits. You also have the right to lodge a complaint with a supervisory authority — for EU/EEA residents this is your local Data Protection Authority (in Germany, the DPA of your federal state), and in the UK the Information Commissioner's Office (ICO).
Age requirement (18+)
StateNull is for adults: you must be 18 or older to create an account or use the services. The services are not directed to anyone under 18, we do not knowingly collect personal data from anyone under 18, and if we learn that we have, we delete it. The same 18+ rule is stated in our Terms of Service and User Policy.
Changes & contact
We may update this policy; we will change the "last updated" date above and, for material changes, provide reasonable notice. Contact: media.supply@statenull.com · R-ESM LLC, 30 N Gould St # 38144, Sheridan, WY 82801, USA.