Effective 2 August 2026
Gravify online-account Privacy Notice
This notice covers the Gravify website, account, payment, licensing, release, and support services. It does not turn Andrea Tosi into the host of the relationship content you keep on your self-hosted Personal Hub.
1. Controller
The controller is Andrea Tosi, an individual based in Milano, Italia and operating Gravify. Privacy requests: andreatosi.info@gmail.com. Address: Via Edoardo Bassini 54, Milano, Italia.
2. Data the online service processes
- Account and authentication: email address, verification state, password hash or external sign-in identifier, MFA state, session and recovery information.
- Purchase and licence: Stripe customer, Checkout, payment, refund, dispute, and event identifiers; offer and licence state; legal acceptance receipt; Hub public key and activation history. Gravify does not receive or store complete payment-card numbers.
- Release access: entitled downloads and licence-check receipts.
- Security and operation: request metadata such as IP address, device or browser information, timestamps, audit events, and error diagnostics.
- Support: your correspondence and the diagnostic information you choose to provide.
- Roadmap feedback: the roadmap items you vote for, any private reason you choose to add, and private feature proposals you submit for editorial review.
The account service is not designed to receive message bodies, relationship maps, private notes, avatars, local files, connector tokens, WhatsApp sessions, or assistant context. Do not send that information through support email.
3. Purposes and legal bases
- To create the account, deliver the paid licence, activate one Hub, provide downloads and support, and manage cancellation or refunds: performance of the contract and steps you request before entering it.
- To keep invoices, legal acceptance, payment, and consumer-remedy records: compliance with legal obligations.
- To prevent account abuse, secure the service, investigate failures, maintain audit trails, and establish or defend legal claims: our legitimate interests in a safe and accountable service.
- To send product marketing: only with any consent required by law; you may withdraw it at any time. Transactional, security, payment, and contractual notices are not marketing.
- To understand demand, review private proposals, and decide what to build: our legitimate interest in improving Gravify with accountable community input. Votes are advisory and do not make automated product or account decisions.
4. Recipients and service providers
Data is disclosed only as needed to providers supporting account hosting, database and infrastructure operations, authentication, transactional email, error/security monitoring, and customer support. Stripe Managed Payments and Link receive and process purchase information under the roles and notices presented at checkout. We may disclose information where law requires it or to protect legal rights. Gravify does not sell your personal data.
5. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. Contact us for information about the safeguard relevant to a particular provider.
6. Retention
Account and licence data is kept while needed to provide the perpetual licence and account. Roadmap votes, private vote reasons, and private proposals are kept while the account remains active or until they are removed during account closure or an applicable erasure request; an approved public roadmap item is independent operator-authored product copy and contains no submitter identity or private proposal text. After closure, other data is deleted or anonymised when no longer needed, except payment, tax, contract, consent, refund, dispute, fraud-prevention, and legal-claim records retained for the applicable statutory period. Operational security logs are normally kept for up to 90 days unless an incident requires longer preservation. Ordinary support correspondence is normally kept for up to 24 months after the request closes. Backups age out under the applicable backup cycle and are not used for ordinary service access.
7. Security
We use access controls, encrypted transport, protected secrets, signed licence records, audit trails, and security updates appropriate to the online account's limited role. No internet service can promise absolute security. Report a suspected account or service incident promptly to andreatosi.info@gmail.com.
8. Your rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent without affecting earlier lawful processing; and complain to the Italian data-protection authority (Garante per la protezione dei dati personali) or the authority where you live or work. We may need to verify your identity. Email andreatosi.info@gmail.com from your account address. Authenticated owners also have this request route in Account settings.
You can record and track closure, access, correction, portability, restriction, objection, or erasure from Account Settings, or contact us by email. If you request closure, we disable ordinary account access and delete or anonymise data that no longer has to be retained. Payment, tax, contract, fraud, dispute, and legal-claim records can remain for the applicable legal period. A separate deletion request to Link may remove related Stripe objects; Gravify must still preserve the minimum evidence it is legally required to keep and reconcile the licence safely. Neither route remotely deletes private data on an offline Personal Hub.
9. Required information and automated decisions
An email address and the information needed for payment and licensing are required to create and perform the contract. Without them, we cannot sell or activate Personal. The online account does not make solely automated decisions producing legal or similarly significant effects about you.
10. Local Personal data and connectors
You control the information kept on your Personal Hub and determine which optional connectors to enable. The WhatsApp module is dormant by default. In relationship-metadata mode it can transfer profile images, names, phone numbers, and message timestamps/frequency—but not message bodies—to your Hub. Full-history mode can additionally transfer bodies and attachments. This connector data stays within the owner-controlled Personal system unless you choose another destination.
11. Changes
We will publish an updated date here and give additional notice where a material change requires it. Contact Andrea Tosi at andreatosi.info@gmail.com with questions.