Privacy Policy
This Privacy Policy describes how Digital Vision Code LLC (“we”, the “Controller”) collects, uses, stores, and protects the personal data of users of the grply application, its related websites and services (collectively, the “Service”).
This notice is drafted in accordance with Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws.
1. Data controller
The data controller is Digital Vision Code LLC.
For any matter relating to this notice or to the processing of personal data, you can write to: support@grply.app.
2. Categories of data collected
2.1 Registration and account data
- e-mail address;
- phone number;
- password (stored exclusively as a cryptographic hash; never in plain text);
- display name;
- optional profile photo (also used as your marker on the group map);
- device language and app preferences.
2.2 Location data
Precise geographic location is processed only when the User voluntarily turns on location sharing inside a group.
- Location is visible only to the members of that group, on the group’s live map.
- If authorized by the User through the operating system, sharing may continue while the app is in the background, for the duration of the activity only.
- The User can pause sharing at any time (including via “ghost” mode) and revoke permissions from the operating system.
- Location data is tied to the group and is deleted when the group expires.
2.3 User-generated content
- chat messages, voice messages, and photos sent inside a group;
- audio tracks uploaded by Instructors for lessons.
Such content is visible only to the members of the group and is automatically deleted when the group or lesson expires. EXIF metadata in photos (including any capture location) is stripped server-side before distribution.
2.4 Purchase data
For subscriptions and in-app purchases we process, through our provider RevenueCat and the stores (Apple App Store, Google Play): product identifier, transaction identifier, and subscription status. We do not process or store payment card data.
2.5 Technical identifiers and usage data
- push notification tokens;
- IP addresses and technical security logs (abuse prevention, rate limiting);
- records of the consents given (version of the accepted document, date and time), retained as proof of consent.
3. Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Account creation and management, provision of the Service | Performance of a contract (Art. 6.1.b GDPR) |
| Location sharing on the group map | Consent (Art. 6.1.a GDPR), revocable at any time |
| Push notifications about groups and lessons | Consent / performance of a contract |
| Management of subscriptions and purchases | Performance of a contract |
| Security, abuse and fraud prevention | Legitimate interest (Art. 6.1.f GDPR) |
| Compliance with legal obligations | Legal obligation (Art. 6.1.c GDPR) |
| Promotional communications, if any | Consent, revocable at any time |
4. Retention periods
- Groups and content (messages, voice notes, photos, locations, audio tracks): automatically deleted when the group or lesson expires.
- Account data: retained while the account is active. The User can delete the account and all associated data at any time from the app Settings.
- Consent records and security logs: retained for as long as necessary to comply with legal obligations and defend the Controller’s rights.
- Purchase data: retained as required by tax and accounting obligations.
5. Categories of recipients
Personal data may be processed, as processors, by providers delivering technical services on our behalf:
- Cloudflare, Inc. — cloud infrastructure, storage, and content delivery;
- RevenueCat, Inc. — management of subscriptions and in-app purchases;
- Expo (650 Industries, Inc.) — delivery of push notifications;
- Apple / Google — app distribution and store payments;
- providers of communication services (e-mail/SMS) for verifications and service notifications.
The map uses cartographic tiles provided by OpenFreeMap (OpenStreetMap data): loading maps involves transmitting the IP address to the tile provider, without any account identifier.
We do not sell Users’ personal data, nor do we share it with third parties for third-party marketing purposes.
6. International transfers
Some providers are based in the United States or other non-EEA countries. In such cases, transfers take place on the basis of European Commission adequacy decisions or Standard Contractual Clauses (SCCs), together with supplementary measures where necessary.
7. Rights of data subjects
The User has the right to:
- access their personal data (Art. 15 GDPR);
- obtain rectification (Art. 16);
- obtain erasure (Art. 17);
- obtain restriction of processing (Art. 18);
- receive their data in a structured, portable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw any consent given, at any time, without affecting the lawfulness of processing carried out before the withdrawal;
- lodge a complaint with the competent supervisory authority.
8. How to exercise your rights
- Account deletion: directly in the app (Settings → Delete account); this removes the account and all associated data.
- Withdrawing location sharing: from inside the group or from the operating system settings.
- Any other request: by writing to support@grply.app. We will respond within the timeframes required by applicable law.
9. Minors
The Service is reserved for people aged 16 or older. We do not knowingly collect personal data from minors under 16; if we become aware of a registration by a minor, we will delete the account.
10. Security
We adopt appropriate technical and organizational measures, including: encryption of communications in transit (TLS), storage of passwords exclusively as hashes using modern algorithms, removal of metadata from images, access restrictions, and automatic deletion of content when groups expire.
11. Device permissions
The app requests operating-system permissions for location, microphone, camera, photo library, and notifications exclusively in relation to the features activated by the User. These permissions can be revoked at any time from the device settings; revocation may limit certain features of the Service.
12. Changes to this notice
We may update this Privacy Policy from time to time. In the event of substantial changes, Users will be informed through reasonable means (for example in-app notifications or e-mail). The applicable version is identified by the update date shown at the top of the document.