Privacy Policy

Last updated 28 September 2026

This Policy explains what personal data Gravo processes, why, and what rights you have. Gravo is provided by Roman Erin, autónomo, NIF Z1420048X, C/ Sebastián de Belalcázar, 4, 28660 Boadilla del Monte (Madrid), Spain («we»). Contact for anything about personal data: privacy@getgravo.com.

1. Two roles

2. Data about our users

WhatWhyLegal basis
Email, name, password (stored as a hash), language, role, organization nameAccount, sign-in, teamContract
Session and device tokens (stored as hashes), device names, last seenKeeping you signed in, linking the desktop applicationContract
Connected accounts' own details: display name, username, phone number or email of the accountShowing which account does what, sending from the right accountContract
Billing: company name, address, VAT ID, card details (kept by Stripe, we see brand, last 4 digits and expiry), invoices, payments, usage countsPayments, invoices, tax recordsContract; legal obligation (tax records)
Telegram account you link to our notification botNotifications and approvals in TelegramContract (you choose to link it)
Your own Anthropic API key, if you add it (encrypted)Running AI with your keyContract
Terms version you accepted and whenProof of acceptanceLegitimate interest

3. Data in customers' chats (as a processor)

On the customer's instructions, Gravo processes:

The desktop application also keeps, on the customer's computer only, numeric representations of messages for local analysis, for 30 days.

4. Who else processes data

RecipientWhat forWhere
Hosting providerServers and storage of the cloudEuropean Union
Anthropic, PBCAI analysis of messages, drafts, research with web search. Anthropic does not use this data to train models. With your own API key, Anthropic processes it under your agreement with them.United States (standard contractual clauses / EU–US Data Privacy Framework)
Stripe Payments Europe, Ltd.Card payments, VAT calculation, invoicesIreland; Stripe group transfers under its own safeguards
HUME (hume.run)Billing records: organization id, usage counts, invoices, balance. No message content.European Union
TelegramNotifications from our bot, only if you link itTelegram's infrastructure

The messengers and networks you connect receive what the desktop application sends from your accounts, under their own policies. We do not sell personal data and do not use it for advertising. We disclose data to authorities only when the law requires it.

5. How long we keep data

6. Security

Connections are encrypted. Passwords and tokens are stored as hashes, API keys encrypted. Each organization's data is kept in a separate database. Access by our staff is limited to what running and supporting the Service requires.

7. Cookies and local storage

The app sets one cookie, a session cookie that keeps you signed in (30 days). It also stores a few interface preferences in your browser (for example, whether the sidebar is collapsed). There are no analytics or advertising cookies. The landing page getgravo.com sets no cookies.

8. Your rights

You may ask to access, correct, delete or export your data, to restrict or object to its processing, and withdraw consent where processing is based on it. Write to privacy@getgravo.com; we answer within one month. You may also complain to the Spanish Data Protection Agency (AEPD, www.aepd.es) or the authority of your country.

9. Changes

We will tell users about material changes to this Policy by email or in the app before they take effect. The date of the current version is at the top of the page.