Effective 2 August 2026

Gravify online-account Privacy Notice

This notice covers the Gravify website, account, payment, licensing, release, and support services. It does not turn Andrea Tosi into the host of the relationship content you keep on your self-hosted Personal Hub.

1. Controller

The controller is Andrea Tosi, an individual based in Milano, Italia and operating Gravify. Privacy requests: andreatosi.info@gmail.com. Address: Via Edoardo Bassini 54, Milano, Italia.

2. Data the online service processes

The account service is not designed to receive message bodies, relationship maps, private notes, avatars, local files, connector tokens, WhatsApp sessions, or assistant context. Do not send that information through support email.

3. Purposes and legal bases

4. Recipients and service providers

Data is disclosed only as needed to providers supporting account hosting, database and infrastructure operations, authentication, transactional email, error/security monitoring, and customer support. Stripe Managed Payments and Link receive and process purchase information under the roles and notices presented at checkout. We may disclose information where law requires it or to protect legal rights. Gravify does not sell your personal data.

5. International transfers

Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. Contact us for information about the safeguard relevant to a particular provider.

6. Retention

Account and licence data is kept while needed to provide the perpetual licence and account. Roadmap votes, private vote reasons, and private proposals are kept while the account remains active or until they are removed during account closure or an applicable erasure request; an approved public roadmap item is independent operator-authored product copy and contains no submitter identity or private proposal text. After closure, other data is deleted or anonymised when no longer needed, except payment, tax, contract, consent, refund, dispute, fraud-prevention, and legal-claim records retained for the applicable statutory period. Operational security logs are normally kept for up to 90 days unless an incident requires longer preservation. Ordinary support correspondence is normally kept for up to 24 months after the request closes. Backups age out under the applicable backup cycle and are not used for ordinary service access.

7. Security

We use access controls, encrypted transport, protected secrets, signed licence records, audit trails, and security updates appropriate to the online account's limited role. No internet service can promise absolute security. Report a suspected account or service incident promptly to andreatosi.info@gmail.com.

8. Your rights

Subject to applicable conditions, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent without affecting earlier lawful processing; and complain to the Italian data-protection authority (Garante per la protezione dei dati personali) or the authority where you live or work. We may need to verify your identity. Email andreatosi.info@gmail.com from your account address. Authenticated owners also have this request route in Account settings.

You can record and track closure, access, correction, portability, restriction, objection, or erasure from Account Settings, or contact us by email. If you request closure, we disable ordinary account access and delete or anonymise data that no longer has to be retained. Payment, tax, contract, fraud, dispute, and legal-claim records can remain for the applicable legal period. A separate deletion request to Link may remove related Stripe objects; Gravify must still preserve the minimum evidence it is legally required to keep and reconcile the licence safely. Neither route remotely deletes private data on an offline Personal Hub.

9. Required information and automated decisions

An email address and the information needed for payment and licensing are required to create and perform the contract. Without them, we cannot sell or activate Personal. The online account does not make solely automated decisions producing legal or similarly significant effects about you.

10. Local Personal data and connectors

You control the information kept on your Personal Hub and determine which optional connectors to enable. The WhatsApp module is dormant by default. In relationship-metadata mode it can transfer profile images, names, phone numbers, and message timestamps/frequency—but not message bodies—to your Hub. Full-history mode can additionally transfer bodies and attachments. This connector data stays within the owner-controlled Personal system unless you choose another destination.

11. Changes

We will publish an updated date here and give additional notice where a material change requires it. Contact Andrea Tosi at andreatosi.info@gmail.com with questions.