Privacy policy.
Last updated
This policy explains what personal data PolyGrind collects, why we collect it, who processes it on our behalf, and the rights you have over it under the General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for processing your personal data is Tuncer Akdemir, c/o POSTFLEX PFX-930-463, Emsdettener Straße 10, 48268 Greven, Germany. You can reach us at support@polygrind.io.
We have not appointed a data protection officer. One is required under § 38 BDSG only where a controller regularly and systematically monitors people on a large scale, or processes special categories of data at scale, or has twenty or more people engaged in automated processing. None of that applies here. Write to the address above with any question a data protection officer would otherwise answer.
2. What we collect and why
Account data. When you create an account we process your email address, an authentication identifier, and — if you sign in with Google — the name and profile picture Google returns. Legal basis: Art. 6(1)(b) GDPR, performance of a contract. Without this data we cannot give you an account.
Uploaded screenshots and analysis results. Images you upload are transmitted to our AI provider for analysis, and the resulting structured output is stored against your account so you can see your history. Legal basis: Art. 6(1)(b) GDPR. Do not upload images containing personal data of other people — the service does not need it and we ask you not to provide it.
Payment data. Subscriptions are processed by Whop. We receive a customer identifier and subscription status. We never receive or store your card number. Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for the retention of invoices under German commercial and tax law.
Server logs. Our hosting provider records IP address, user agent, requested URL, referrer and timestamp for each request. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in operating the service securely and diagnosing faults.
Support correspondence. If you contact us, we process the content of your message and your contact details in order to answer it. Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR depending on the subject.
3. Cookies and similar technologies
We set strictly necessary cookies for session handling, security, and to remember that you dismissed the announcement bar. These do not require consent under § 25(2) TTDSG.
Any analytics or marketing technologies are loaded only after you consent through our cookie banner, on the basis of Art. 6(1)(a) GDPR and § 25(1) TTDSG. You can withdraw consent at any time via the cookie settings link in the footer, with effect for the future. Our cookie policy lists each cookie individually.
4. Processors and recipients
We use the following processors under Art. 28 GDPR. Each is bound by a data processing agreement, and transfers outside the EEA are covered by the European Commission’s Standard Contractual Clauses where no adequacy decision applies.
- Supabase — database, authentication and file storage. Our project is hosted in the EU (eu-central-1, Frankfurt).
- Vercel — application hosting, content delivery, and aggregate page statistics. The statistics set no cookie and store nothing on your device; they count page views and derive a country and device type, and cannot identify you. Processing may take place in the United States.
- Whop — payment processing, billing and subscription management, and — only if you consent to analytics — conversion measurement, which tells Whop that a subscription began with a visit here. The cookies involved are listed in our cookie policy. Whop acts as an independent controller for parts of this processing under its own privacy policy, and processing may take place in the United States.
- Google (Gemini API) — analysis of uploaded screenshots. Processing may take place outside the EU under Google’s own terms.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
5. Retention
- Account data: for as long as your account exists, then deleted within 30 days of closure.
- Uploaded screenshots: deleted automatically 90 days after upload, or immediately when you delete the analysis.
- Analysis results: for as long as your account exists.
- Invoices and payment records: ten years, as required by § 147 AO and § 257 HGB.
- Server logs: seven days, then deleted or anonymised.
- Support correspondence: three years from the end of the year in which the matter was closed.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Have inaccurate data corrected (Art. 16).
- Have your data erased (Art. 17).
- Restrict processing (Art. 18).
- Receive your data in a portable, machine-readable format (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)).
To exercise any of these, email support@polygrind.io. We respond within one month. You also have the right to lodge a complaint with a supervisory authority — for an operator based in Bavaria this is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), or the authority in your own country of residence.
7. Security
Data is transmitted over TLS. Database access is restricted by row-level security so that account holders can only read their own records. Passwords are never stored in plain text. No system is perfectly secure, and we will notify you and the competent supervisory authority of a personal data breach where the GDPR requires it.
8. Changes to this policy
We update this policy when our processing changes. The date at the top reflects the current version. Where a change materially affects you, we will notify you by email or in the product before it takes effect.