Privacy policy.
Last updated
This policy explains what personal data PolyGrind collects, why we collect it, who processes it on our behalf, and the rights you have over it under the General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for processing your personal data is {{ LEGAL NAME }}, {{ FULL POSTAL ADDRESS }}, Germany. You can reach us at {{ CONTACT EMAIL }}.
{{ DATA PROTECTION OFFICER — required only if you regularly and systematically monitor data subjects on a large scale, or process special categories of data at scale. Most early-stage operations do not need one. Delete this paragraph if it does not apply to you. }}
2. What we collect and why
Account data. When you create an account we process your email address, an authentication identifier, and — if you sign in with Google — the name and profile picture Google returns. Legal basis: Art. 6(1)(b) GDPR, performance of a contract. Without this data we cannot give you an account.
Uploaded screenshots and analysis results. Images you upload are transmitted to our AI provider for analysis, and the resulting structured output is stored against your account so you can see your history. Legal basis: Art. 6(1)(b) GDPR. Do not upload images containing personal data of other people — the service does not need it and we ask you not to provide it.
Payment data. Subscriptions are processed by Stripe. We receive a customer identifier, subscription status and the last four digits and brand of your card. We never receive or store your full card number. Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for the retention of invoices under German commercial and tax law.
Server logs. Our hosting provider records IP address, user agent, requested URL, referrer and timestamp for each request. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in operating the service securely and diagnosing faults.
Support correspondence. If you contact us, we process the content of your message and your contact details in order to answer it. Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR depending on the subject.
3. Cookies and similar technologies
We set strictly necessary cookies for session handling, security, and to remember that you dismissed the announcement bar. These do not require consent under § 25(2) TTDSG.
Any analytics or marketing technologies are loaded only after you consent through our cookie banner, on the basis of Art. 6(1)(a) GDPR and § 25(1) TTDSG. You can withdraw consent at any time via the cookie settings link in the footer, with effect for the future. Our cookie policy lists each cookie individually.
4. Processors and recipients
We use the following processors under Art. 28 GDPR. Each is bound by a data processing agreement, and transfers outside the EEA are covered by the European Commission’s Standard Contractual Clauses where no adequacy decision applies.
- Supabase — database, authentication and file storage. Our project is hosted in the EU (eu-central-1, Frankfurt).
- Vercel — application hosting and content delivery. Processing may take place in the United States.
- Stripe — payment processing. Stripe acts as an independent controller for parts of this processing under its own privacy policy.
- {{ AI PROVIDER — name the vision model vendor you actually use, and link its privacy and data retention terms. Confirm in writing that your uploads are not used to train their models, and state that here. }} — analysis of uploaded screenshots.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
5. Retention
- Account data: for as long as your account exists, then deleted within 30 days of closure.
- Uploaded screenshots: deleted automatically 90 days after upload, or immediately when you delete the analysis.
- Analysis results: for as long as your account exists.
- Invoices and payment records: ten years, as required by § 147 AO and § 257 HGB.
- Server logs: seven days, then deleted or anonymised.
- Support correspondence: three years from the end of the year in which the matter was closed.
{{ Confirm these periods match what your systems actually do. A retention policy you do not enforce is worse than none, because it documents your own breach. }}
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Have inaccurate data corrected (Art. 16).
- Have your data erased (Art. 17).
- Restrict processing (Art. 18).
- Receive your data in a portable, machine-readable format (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)).
To exercise any of these, email {{ CONTACT EMAIL }}. We respond within one month. You also have the right to lodge a complaint with a supervisory authority — for an operator based in Bavaria this is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), or the authority in your own country of residence.
7. Security
Data is transmitted over TLS. Database access is restricted by row-level security so that account holders can only read their own records. Passwords are never stored in plain text. No system is perfectly secure, and we will notify you and the competent supervisory authority of a personal data breach where the GDPR requires it.
8. Changes to this policy
We update this policy when our processing changes. The date at the top reflects the current version. Where a change materially affects you, we will notify you by email or in the product before it takes effect.