Privacy Policy
Last updated 28 September 2026
This Policy explains what personal data Gravo processes, why, and what rights you have. Gravo is provided by Roman Erin, autónomo, NIF Z1420048X, C/ Sebastián de Belalcázar, 4, 28660 Boadilla del Monte (Madrid), Spain («we»). Contact for anything about personal data: [email protected].
1. Two roles
- We are the controller of the data of our customers' users: people who sign up, are invited to a team or pay for Gravo.
- We are a processor for the data of the people in our customers' chats and sources: the customer decides whom to look for and whom to contact, and is the controller. If you were contacted through Gravo, the business that wrote to you is responsible for it; you can also write to us and we will pass your request on and help.
2. Data about our users
| What | Why | Legal basis |
|---|---|---|
| Email, name, password (stored as a hash), language, role, organization name | Account, sign-in, team | Contract |
| Session and device tokens (stored as hashes), device names, last seen | Keeping you signed in, linking the desktop application | Contract |
| Connected accounts' own details: display name, username, phone number or email of the account | Showing which account does what, sending from the right account | Contract |
| Billing: company name, address, VAT ID, card details (kept by Stripe, we see brand, last 4 digits and expiry), invoices, payments, usage counts | Payments, invoices, tax records | Contract; legal obligation (tax records) |
| Telegram account you link to our notification bot | Notifications and approvals in Telegram | Contract (you choose to link it) |
| Your own Anthropic API key, if you add it (encrypted) | Running AI with your key | Contract |
| Terms version you accepted and when | Proof of acceptance | Legitimate interest |
3. Data in customers' chats (as a processor)
On the customer's instructions, Gravo processes:
- messages from the chats, groups, channels and feeds the customer selects: text, time, author's id, name, username, replies and threads, reactions. By default only messages that may matter to a campaign leave the customer's computer (private messages, replies and mentions, results of the customer's searches, messages that look like a request); the rest of the conversation is analysed on the computer and stays there;
- profiles: name, username, public bio;
- research on hot leads: public information found on the web about the person's work and company, with links to the sources. Research does not collect phone numbers, home addresses, personal emails, family, health, political or religious information, and does not cover people on the customer's «Clients» or «Do not contact» lists;
- lists the customer uploads (usernames, phone numbers, emails, companies); phone numbers are matched to Telegram accounts through the customer's own Telegram account;
- conversations and drafts written with the customer.
The desktop application also keeps, on the customer's computer only, numeric representations of messages for local analysis, for 30 days.
4. Who else processes data
| Recipient | What for | Where |
|---|---|---|
| Hosting provider | Servers and storage of the cloud | European Union |
| Anthropic, PBC | AI analysis of messages, drafts, research with web search. Anthropic does not use this data to train models. With your own API key, Anthropic processes it under your agreement with them. | United States (standard contractual clauses / EU–US Data Privacy Framework) |
| Stripe Payments Europe, Ltd. | Card payments, VAT calculation, invoices | Ireland; Stripe group transfers under its own safeguards |
| HUME (hume.run) | Billing records: organization id, usage counts, invoices, balance. No message content. | European Union |
| Telegram | Notifications from our bot, only if you link it | Telegram's infrastructure |
The messengers and networks you connect receive what the desktop application sends from your accounts, under their own policies. We do not sell personal data and do not use it for advertising. We disclose data to authorities only when the law requires it.
5. How long we keep data
- Account and customer data: while the account is active.
- After the account is closed: deleted within 30 days. Invoices and payment records: kept as long as tax law requires (in Spain, generally 4 to 6 years).
- Removed team members: the name stays as the author of past actions; access ends at once.
- Local analysis data on the computer: 30 days.
6. Security
Connections are encrypted. Passwords and tokens are stored as hashes, API keys encrypted. Each organization's data is kept in a separate database. Access by our staff is limited to what running and supporting the Service requires.
7. Cookies and local storage
The app sets one cookie, a session cookie that keeps you signed in (30 days). It also stores a few interface preferences in your browser (for example, whether the sidebar is collapsed). There are no analytics or advertising cookies. The landing page getgravo.com sets no cookies.
8. Your rights
You may ask to access, correct, delete or export your data, to restrict or object to its processing, and withdraw consent where processing is based on it. Write to [email protected]; we answer within one month. You may also complain to the Spanish Data Protection Agency (AEPD, www.aepd.es) or the authority of your country.
9. Changes
We will tell users about material changes to this Policy by email or in the app before they take effect. The date of the current version is at the top of the page.