Skip to content
GRYV
Legal document

Privacy Policy

Last updated: October 4, 2026

01Introduction

This Privacy Policy applies to all mobile applications ("Apps") published by Bartosz Rzechółka, operating under the GRYV brand ("we," "us," or "Provider") on the Apple App Store, and to the gryv.dev website ("Website").

We make every effort to protect users' privacy in accordance with applicable laws, in particular Regulation (EU) 2016/679 (GDPR). Apple Inc. is not a party to this Privacy Policy.

02Scope of Data Processing

We do not require user registration or account creation. We do not collect names, email addresses, phone numbers, or any other identifying details about you, and no App asks you for them.

Most features run entirely on your device. Anything you enter while using an App - player names, scores or settings, for example - stays on your device and is removed when you delete the App.

Some Apps have a feature that needs a server - generating a text or an image with an AI model, for example. Using such a feature sends a request to a service we operate, as described in "Server-Backed Features" and "Content Sent to Third-Party AI Services" below.

Our Apps use Google services for analytics and crash reporting (Firebase), and some use Google AdMob to display ads. These are described below.

We only process data that identifies you directly when you contact us yourself - through the form on the Website or by email. This is described in "Website and Contact Form" below.

03Analytics and Crash Reporting

Our Apps use Firebase Analytics and Firebase Crashlytics, services provided by Google LLC.

These services collect technical and statistical data for the following purposes:

  • Analyzing app performance and usage patterns
  • Identifying and diagnosing crashes and technical issues
  • Improving app stability and user experience

Data collected may include:

  • Device type and model
  • Operating system version
  • App version
  • Crash logs and error reports
  • Session duration and features used
  • Installation identifiers (e.g., IDFV - Identifier for Vendor, Firebase installation ID)
  • Anonymous usage statistics

LEGAL BASIS: We process this data based on our legitimate interest (Article 6(1)(f) GDPR) in keeping our Apps stable, functional and of good quality. We do not link this data to your identity, and it does not allow us to tell who you are.

For more information about how Google processes this data, please refer to Google's Privacy Policy.

Apple may also provide us with aggregated, anonymous statistics (such as downloads or crashes), only from users who have agreed to this in iOS settings ("Share With App Developers"). You can withdraw that consent at any time in Settings → Privacy & Security → Analytics & Improvements.

04Server-Backed Features

We do not maintain a user database. There are no accounts, no profiles, and nothing that lists who our users are.

TECHNICAL LOGS: Where an App has a feature that runs on a server we operate, that server keeps a technical log of each request: which App and which feature was called, whether it succeeded, how long it took, how much of the AI provider's capacity it used, and the device type reported by the operating system. We deliberately do not record IP addresses. These servers run on infrastructure provided by Cloudflare, Inc.

ABUSE PROTECTION: To stop one device from exhausting a shared service, the log also records a per-installation identifier issued by Apple's App Attest and Firebase App Check, together with a daily request count. The identifier is specific to one installation of one App: it is not your Apple ID, a device serial number or an advertising identifier, it does not follow you between our Apps, and it is replaced when the App is reinstalled. We use it to count requests and for nothing else.

CONTENT YOU SEND: Where a feature works on something you provide - a photograph or a piece of text - that content is sent to the server and passed to the AI provider that processes it, and the answer is returned to you. We do not store what you send, and it does not appear in the logs; only its size and the amount of model capacity it used are recorded.

05Content Sent to Third-Party AI Services

Some App features use artificial intelligence models. This section says exactly what is sent, to whom, and for what.

WHAT IS SENT: Depending on the feature:

  • Text you write in the App
  • A photograph you choose from your library or take with the camera, reduced in size on your device before it is sent
  • Parameters only, without any of your content - for example the chosen category, result style or the App language

Nothing else is sent with it: no name, no contact details, no Apple ID, no location, no other photos, and no advertising identifier. Each AI feature tells you in the App what data it sends.

HOW IT IS COLLECTED: Only when you start the feature yourself. Before your content (text or a photo) is sent for the first time, the App shows a screen that explains what is sent and to whom, and sends nothing unless you agree. You can withdraw that permission at any time in the App's Settings.

WHO RECEIVES IT: The content goes to a server we operate on infrastructure provided by Cloudflare, Inc., which - depending on the feature - passes it to one of these providers: Google LLC (Gemini API), OpenAI, L.L.C. / OpenAI Ireland Ltd. (OpenAI API) or Anthropic PBC (Claude API). The model's result is returned to the App. No other party receives it.

ON-DEVICE: Some features use Apple's on-device models (Apple Foundation Models). In that case your content never leaves your device and is not sent to us or to any provider.

WHAT IT IS USED FOR: Only to generate the result you asked for. It is not used for advertising, profiling, or marketing, it is not used to identify you or anyone in a photo, it is not processed for face recognition or any other biometric identification, and it is never sold.

HOW LONG IT IS KEPT: We do not store what you send or the generated result on our servers; they exist only for the time it takes to answer the request. AI providers process the content as our service providers under their API terms and data processing agreements; under those terms they do not use it to train their models and may keep it for a limited period (typically up to 30 days) solely to detect abuse and meet legal obligations. The result is kept only on your device.

LEGAL BASIS: Your consent (Article 6(1)(a) GDPR), given in the App before your content is first sent, and the performance of the feature you requested (Article 6(1)(b) GDPR). Withdrawing consent does not affect processing that happened before it was withdrawn.

Do not send a photo of a person who has not agreed to it, and never send a photo of a child. The App may refuse photos that appear to show a minor.

06Device Permissions

Our Apps respect your privacy and device security:

  • Camera: most of our Apps do not access your camera. Where a feature requires it - taking a photo for an AI feature, for example - the App asks for permission first, and iOS will not grant access without it
  • Microphone: our Apps do not access your microphone
  • Location: our Apps do not track your precise location (GPS)
  • Contacts: our Apps do not access your contact list
  • Photos: our Apps do not access your photo library. Where a feature needs a photo, you choose a single photo through the system picker, which gives the App only that photo
  • Tracking (App Tracking Transparency): Apps that show ads may ask for permission to access the advertising identifier, as described in "Advertising"

We only request permissions that are strictly necessary for the feature in question. You can manage app permissions at any time through your device settings.

07Advertising

Some Apps display ads through Google AdMob, a service of Google LLC / Google Ireland Limited. Where an App offers a purchase or subscription that removes ads, ads are no longer shown once you have it.

DATA COLLECTED BY ADMOB: To show an ad, measure its performance and prevent fraud, AdMob may process:

  • The advertising identifier (IDFA) - only if you allow tracking in the App Tracking Transparency prompt
  • The identifier for vendor (IDFV) and other device identifiers
  • IP address and the general location derived from it (such as country or city)
  • Device model, operating system version, language and region settings
  • Information about the App and about ad impressions and interactions

CONSENT (EEA, UK, SWITZERLAND): Before the first ad is shown, the App displays Google's consent form (User Messaging Platform, IAB TCF compliant). There you decide whether you agree to personalized ads and to information being stored on your device. You can change your choice at any time in the App's privacy settings.

APP TRACKING TRANSPARENCY: The advertising identifier (IDFA) is only shared if you allow it in the iOS system prompt. You can withdraw that permission in Settings → Privacy & Security → Tracking.

WITHOUT CONSENT: If you do not consent, non-personalized or limited ads are shown - selected by context (such as the App and general location), not by your history. Google may still process limited data for frequency capping, aggregated reporting and fraud prevention.

LEGAL BASIS: Your consent (Article 6(1)(a) GDPR) for personalized ads and for accessing information on your device; our legitimate interest (Article 6(1)(f) GDPR) for showing non-personalized ads, security and fraud prevention.

Google processes this data as an independent controller under Google's Privacy Policy and the page "How Google uses information from sites or apps that use our services". We do not sell your data and do not give advertisers any data about you ourselves.

08In-App Purchases

All in-app purchases and payments are processed exclusively by Apple Inc. through the App Store. We do not process, store, or have access to any payment information.

The App checks the status of your purchases and subscriptions directly with Apple (StoreKit), on your device. We do not receive your name, email address or Apple ID in the process.

REFUNDS: Refunds are decided by Apple. For refund requests, billing inquiries, or payment-related issues, please contact Apple directly through the App Store or Apple Support, in accordance with Apple's policies.

We are not responsible for any payment processing, billing errors, or refund decisions made by Apple.

09Website and Contact Form

When you send an inquiry through the form on the Website, we process the data you enter: your name, email address, company (optional), the kind of work you need, your budget and your message. We process data in emails you send us in the same way.

PURPOSE AND LEGAL BASIS: To answer your inquiry and correspond with you, including preparing a quote - based on your consent (Article 6(1)(a) GDPR) and on steps taken at your request before entering into a contract (Article 6(1)(b) GDPR). You can withdraw consent at any time without affecting processing that happened before.

Form messages are delivered to our inbox through Resend. The Website is hosted by Vercel Inc., which may log technical request data (such as IP address, browser type and time of request) to keep the service secure and stable - based on our legitimate interest (Article 6(1)(f) GDPR).

COOKIES: The Website uses no tracking cookies and no analytics. It only uses your browser's session storage (sessionStorage) so the intro animation is not shown again in the same tab. That information never leaves your browser.

10Third-Party Services

Our Apps are distributed through Apple's App Store. Apple Inc. is not a party to this Privacy Policy. Apple's collection and use of data is governed by Apple's own Privacy Policy.

We use the following service providers, each only for the purpose listed:

  • Apple: distribution, payments and refund decisions; on-device AI models
  • Google (Firebase): analytics, crash reporting and App Check
  • Google (AdMob): displaying ads, as described in "Advertising"
  • Google (Gemini API), OpenAI (OpenAI API), Anthropic (Claude API): generating a result from content you send to an AI feature, as described in "Content Sent to Third-Party AI Services"
  • Cloudflare: hosting the servers behind App features
  • Vercel: hosting the Website
  • Resend: delivering contact form messages

EQUAL PROTECTION: Every provider above that processes personal data on our behalf - Google as Firebase and as AI provider, OpenAI, Anthropic, Cloudflare, Vercel and Resend - is bound by data processing terms, and where data leaves the European Economic Area by Standard Contractual Clauses, that require it to protect that data to the same or an equal standard as this Privacy Policy and applicable data protection law, and to use it only to provide its service to us. Apple (for purchases) and Google (for AdMob) process data as independent controllers under their own privacy policies.

The Apps may contain links to third-party websites or services (including in ads). Those are governed by their providers' own privacy policies, and we are not responsible for them.

11International Data Transfers

Google (Firebase, AdMob, Gemini API), OpenAI, Anthropic, Cloudflare, Vercel and Resend may process data in the United States or other countries outside the European Economic Area (EEA).

For transfers of personal data outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or on an adequacy decision (EU-US Data Privacy Framework), to which these providers have committed.

12Children's Privacy

Our Apps are not directed to children. We do not knowingly collect personal information from children under 13 years of age (or under 16 in the European Economic Area).

Photos of children must not be sent to any App. Apps that send photos to an AI service may refuse photos that appear to show a minor.

If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at contact@gryv.dev.

13Age Restrictions

Age restrictions for each App are determined by the age rating assigned by Apple Inc. through the App Store. Users must comply with the age requirements specified on each App's App Store listing. Some content categories (for example those marked 18+) are intended for adults only.

Parents and guardians are responsible for monitoring their children's use of the Apps and ensuring compliance with applicable age restrictions.

14Data Retention

We hold no personal data about you in any account or profile, because none exists.

Technical request logs of server-backed features - including the per-installation identifier and daily count - are deleted automatically on a rolling basis, within 30 days.

We do not store content sent to AI features; how long AI providers keep it is described in "Content Sent to Third-Party AI Services".

Firebase data is retained according to Google's policies: Firebase Analytics data for 14 months by default, Firebase Crashlytics data for 90 days. AdMob advertising data is retained according to Google's policies.

Contact form data and correspondence are kept for as long as needed to handle your inquiry and, if we work together, for the duration of that work and the limitation period for claims or as required by law (e.g. tax law). Inquiries that did not lead to a project are deleted within 12 months at the latest.

Technical server logs of the Website are kept by Vercel according to its retention policy, typically no longer than 30 days.

15Your Rights

Under the GDPR and other applicable data protection laws, you have rights regarding your personal data, including:

  • Right of access - to obtain confirmation whether your personal data is being processed
  • Right to rectification - to have inaccurate personal data corrected
  • Right to erasure ("right to be forgotten") - to have your personal data deleted
  • Right to restriction of processing - to limit how your data is used
  • Right to data portability - to receive your data in a structured, commonly used format
  • Right to object - to object to processing based on legitimate interests
  • Right to withdraw consent - at any time, without affecting processing before the withdrawal
  • Right to lodge a complaint - with a supervisory authority, in Poland the President of the Personal Data Protection Office (UODO)

You can withdraw permission to send content to AI services in the App's Settings. You can change your personalized ads choice in the App's privacy settings, and tracking permission in iOS Settings → Privacy & Security → Tracking.

Since our Apps do not collect data that lets us identify you, we may be unable to fulfil some of these rights - we cannot link the data to a specific person. However, if you have contacted us or have any questions about your data, please contact us at contact@gryv.dev. For data Google processes as an independent controller, you can also use Google's own tools.

We may request additional information to verify your identity before fulfilling any data protection request.

16Changes to This Policy

We may modify this Privacy Policy. Changes take effect when the updated policy is posted on this page, and the "Last updated" date will change accordingly.

We encourage you to review this Privacy Policy periodically.

17Data Controller and Contact

The data controller for personal data processed in connection with our Apps and the Website is:

Bartosz Rzechółka, operating under the GRYV brand Szczecin, Poland E-mail: contact@gryv.dev

For any questions regarding this Privacy Policy or to exercise your data protection rights, contact us at the email above. We will respond within one month as required by the GDPR.

This policy applies to all mobile applications published by Bartosz Rzechółka, operating under the GRYV brand on the Apple App Store and to the gryv.dev website.

Terms of Service →