← Back to GRAVILS

GRAVILS / Legal

Privacy Policy

How we handle your data and the choices you have.

Last updated: September 28, 2026

1. Who is responsible

SIA “GRAVILS VK” is the controller of personal data described in this Policy: registration number 40003374644; VAT LV40003374644; Krišjāņa Valdemāra iela 18–7, Rīga, LV-1010, Latvia. Contact us at support@gravils.app. This Policy covers the GRAVILS website and apps that link to it. The data involved depends on the app and features you use.

2. Photos stay on your device

Photo editing and image processing take place on your device. We do not store your photos on our servers, upload them to our Firebase database, or send them to an external AI provider for processing. Any image analysis needed for these features also takes place locally.

You control access to your camera and photo library through your device permissions. Photos or results that you save on your device or share through another service are subject to your device, backup, and sharing settings. If you voluntarily send an image to our support email, it becomes part of that support correspondence; it is not part of the app’s image-processing workflow.

3. Data other than photos

Our apps do not require GRAVILS account registration. This does not mean that all use is anonymous: technical identifiers may distinguish an installation or device.

  • Technical and usage data: app and operating-system version, device characteristics, app-instance or installation identifiers, feature interactions, session information, language, and approximate regional information provided by analytics services.
  • Diagnostics: crash reports, stack traces, diagnostic logs, and device or app state associated with an error.
  • App service data: non-photo application records and settings processed through Firebase database services to support the relevant app features.
  • Notifications: push registration tokens and related delivery data when push services are used.
  • Purchases: product and transaction identifiers, purchase or renewal dates, subscription status, entitlement information, and identifiers used to associate an installation with a purchase. Apple or Google handles payment credentials; we do not receive your full payment-card details through their in-app purchase systems.
  • Support: your email address, optional name, subject, message, and any information you voluntarily provide.
  • Website security and delivery: request information such as IP address, browser information, timestamps, and anti-abuse verification results processed by hosting and security providers.

4. Why we process data and the legal grounds

Under the GDPR, where it applies, we rely on the following grounds:

  • Performing a contract or taking steps at your request: providing requested features, checking purchases and entitlements, and dealing with service or purchase inquiries.
  • Legitimate interests: protecting the Services, investigating errors, preventing abuse, and managing business correspondence, where those interests are not overridden by your rights.
  • Consent: non-essential analytics, device tracking or access, and notifications where applicable law requires consent. A device permission does not replace any separate consent required by law.
  • Legal obligations: retaining required business records and responding to lawful requests.

If data is necessary to answer an inquiry or verify an entitlement and you do not provide it, we may be unable to complete that request. Where we rely on consent, you can withdraw it without affecting the lawfulness of earlier processing.

5. Service providers

We use the following services for the purposes described here. They receive the data necessary for the functions they perform, not photos from the app’s on-device processing:

  • Google Firebase database services: storage and delivery of non-photo app service data.
  • Google Analytics for Firebase: app usage measurement and analytics.
  • Firebase Crashlytics: crash reporting and diagnostics.
  • Firebase Cloud Messaging: push notification infrastructure.
  • Adapty: in-app purchase and subscription management, entitlement verification, and related subscription analytics.
  • Apple App Store and Google Play: purchase processing and store-account services, under their own privacy terms.
  • Cloudflare: website and form infrastructure, request security, and Turnstile anti-spam checks when you use the contact page.
  • Resend: delivery of contact-form messages to our support mailbox. Our mailbox provider also processes support correspondence.

Provider information: Firebase privacy and security, Google Privacy Policy, Adapty Privacy Policy, Apple Privacy Policy, Cloudflare Privacy Policy, and Resend Privacy Policy.

Data may also be disclosed where required by law, to protect legal rights, or in a business reorganization subject to applicable privacy safeguards. We do not send app photos to these providers for remote image processing.

6. Analytics, permissions, and your choices

You can manage photo and camera access and notification permissions in your device settings. Notification preferences do not automatically change analytics settings. Where consent is required for non-essential analytics or tracking, collection must depend on that consent, which you can withdraw through the privacy controls provided in the app or by contacting us.

This website does not embed Google Analytics or advertising scripts. The contact page uses Cloudflare Turnstile for security when configured. Hosting and security services may process request information and use technologies needed to deliver and protect the site. App SDKs are separate from the website and may use installation identifiers and local storage.

7. International transfers

Our providers may process data in the European Economic Area and other countries. When personal data is transferred outside the EEA, we rely on a valid legal transfer mechanism, such as an applicable adequacy decision or European Commission standard contractual clauses, with supplementary safeguards where required. Contact us for information about the safeguards relevant to your data. No single server location is promised for every provider.

8. How long data is kept

App photos are not stored on our servers. Non-photo data is kept only for as long as necessary for the purpose described, subject to legal requirements. The relevant period depends on the type of record, the feature, active service needs, provider settings, and any legal claim or statutory retention requirement.

Support correspondence is retained while handling the inquiry and for a proportionate period needed for follow-up or disputes. Purchase records may need to be kept beyond cancellation to reconcile transactions, resolve disputes, or comply with law. Diagnostic and analytics data is governed by the retention settings of the relevant services. Data is deleted or anonymized when no longer needed, subject to any lawful retention obligation. Contact us for the retention information applicable to a specific record or app.

9. Your privacy rights

Depending on your location and applicable law, you may have rights to access, correct, erase, restrict processing of, or obtain a portable copy of your personal data, and to object to processing based on legitimate interests. You may withdraw consent at any time. Some requests are subject to exceptions, including legal recordkeeping obligations.

Write to support@gravils.app with the app name and your request. Because there is no GRAVILS login, we may need an app-installation or transaction identifier to locate the relevant records and verify your request. Do not send passwords or full payment-card details. We respond within the time required by applicable law; under the GDPR this is normally one month, with permitted extensions explained to you.

You can remove local photos and app data using your device controls. Uninstalling an app does not automatically erase provider records or cancel a store subscription. To stop billing, cancel through Apple or Google.

You may complain to your local supervisory authority or the Latvian Data State Inspectorate (Datu valsts inspekcija). You do not have to contact us first.

10. Children and security

Follow the age requirements and rating of the relevant app. Where a child’s data is involved and parental authorization is required, the applicable requirements must be met before processing. A parent or guardian who believes a child’s data has been processed unlawfully can contact us for investigation and deletion where appropriate.

We use appropriate technical and organizational safeguards for the data we handle. No system or transmission method can guarantee absolute security. Please avoid sending sensitive information or photographs through support unless necessary for your inquiry.

11. Updates and contact

We may update this Policy to reflect changes to the Services or legal requirements. The revision date appears above; material changes will be communicated as required by law. Contact support@gravils.app with questions about this Policy or your data.