Privacy Policy
Last updated: June 2025
1. Introduction
Volgrei ("we", "our", or "us") operates the Volgrei mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service. By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with its terms, please discontinue use of the Service immediately.
2. Data Controller
The data controller responsible for your personal data is Volgrei, operated as an individual business under Italian law (Partita IVA, regime forfettario). For any privacy-related inquiries, you may contact us at [email protected].
3. Data We Collect
We collect the following categories of personal data:
- Account data: email address, username, and encrypted password upon registration.
- Usage data: app interactions, feature usage, and session metadata collected for service improvement.
- User-generated content: tasks, notes, and other content you create within the Service.
- Device data: device type, operating system version, and app version for diagnostic purposes.
- Payment data: subscription and billing information processed exclusively by Apple (App Store) and RevenueCat. We do not store payment card details.
4. Legal Basis for Processing
We process your personal data on the following legal bases under the General Data Protection Regulation (GDPR) (EU) 2016/679: (a) performance of a contract, where processing is necessary to provide the Service you have requested; (b) legitimate interests, for service security, fraud prevention, and analytics; (c) consent, where you have explicitly provided it; and (d) compliance with legal obligations.
5. How We Use Your Data
We use collected data to:
- Provide, maintain, and improve the Service;
- Authenticate users and manage accounts;
- Process subscription payments via third-party processors;
- Send transactional communications (account confirmations, security alerts);
- Detect, investigate, and prevent fraudulent or unauthorized activity;
- Comply with applicable legal obligations.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
6. Third-Party Processors
We engage the following sub-processors to operate the Service. Each processor is bound by data processing agreements consistent with GDPR requirements:
- Supabase: authentication and database infrastructure.
- Anthropic: AI inference for the Grei assistant feature.
- RevenueCat: subscription and in-app purchase management.
- Cloudflare: content delivery and DDoS protection.
7. Data Retention
We retain your personal data for as long as your account remains active or as necessary to provide the Service. Upon account deletion, we will delete or anonymize your personal data within 30 days, unless retention is required to comply with legal obligations, resolve disputes, or enforce our agreements.
8. International Data Transfers
Some of our third-party processors operate outside the European Economic Area (EEA). Where personal data is transferred to countries not recognized by the European Commission as providing an adequate level of protection, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) adopted by the European Commission.
9. Your Rights
Under GDPR and applicable Italian law (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018), you have the following rights with respect to your personal data:
- Right of access: obtain confirmation of whether we process your data and receive a copy.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your data under certain conditions.
- Right to restriction: request that we limit processing of your data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali) at garanteprivacy.it.
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS), encryption at rest, access controls, and regular security assessments. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
11. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from minors. If you become aware that a minor has provided us with personal data without parental consent, please contact us at [email protected] and we will take steps to delete such data promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, where changes are material, notify you via email or in-app notification. Continued use of the Service after such changes constitutes acceptance of the updated Policy.
13. Contact
For any questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact us at [email protected].