Graito ← Back to graito.ai
Legal

Privacy Policy

Last updated: August 2, 2026

1. Introduction

This Privacy Policy explains how NotionAce Solutions ("Graito," "we," "us," "our") collects, uses, shares, and protects information when you use the Graito mobile application (the "App"). By using the App, you agree to the practices described here.

2. Information We Collect

2.1 Account Information

  • Name, email address, and password (or authentication via Google Sign-In, where enabled)
  • Profile details you choose to add: display name, bio, gender, activity level, working style, coach/user role
  • Profile photo, if uploaded

2.2 Wellbeing and Activity Data

This is the core data the App is built around, and deserves specific attention:

  • Goals you create, including category/theme (mind, body, spirit) and whether personal, peer, or coach-assigned
  • Daily check-ins: mood ratings, notes, completion status of activities
  • Activity streaks and completion history
  • Content of your Graito Portrait — an AI-generated reflection based on your check-in history
  • Voice recordings, if you use voice commands or voice journaling features (processed for speech recognition; see Section 4 on third parties)
We treat this category as sensitive. It may reveal information about your mental and physical wellbeing. We do not sell this data, and we limit internal access to what's needed to operate the App.

2.3 Social and Communication Data

  • Posts, comments, and reactions you make
  • Direct messages and group messages you send
  • Goal groups/peer connections you join
  • Coach interactions, including call metadata (duration, participants) — call content itself is not recorded by us unless explicitly stated otherwise

2.4 Payment Information

  • Subscription status and billing period dates
  • We do not collect or store your full payment card details. Payments are processed by Google Play (and the Apple App Store, if we expand there in future) — see Section 4.

2.5 Device and Usage Data

  • Device type, operating system, app version
  • Push notification token (to deliver reminders and alerts)
  • General usage analytics (features used, session activity) to improve the App
  • Approximate location, if you grant location permission (not currently requested by the App — kept here as a forward-looking placeholder in case a future feature requests it; remove entirely if that stays true indefinitely)

2.6 Permissions-Based Data

Based on permissions you grant, we may access:

  • Camera — to let you upload photos to posts/profile
  • Microphone — for voice commands and voice journaling
  • Biometric authentication — used only to unlock the App locally on your device; biometric data itself (fingerprint/face data) is processed by your device's operating system and is never transmitted to or stored by Graito

3. How We Use Your Information

We use collected information to:

  • Provide and operate core App features (goals, check-ins, AI Portrait, messaging, coaching)
  • Personalize AI-generated content and suggestions based on your activity
  • Process subscription payments and manage your Graito Plus status
  • Send push notifications you've opted into (reminders, social activity, subscription-related)
  • Maintain safety and moderate content
  • Improve the App through aggregated, de-identified usage analysis
  • Comply with legal obligations

4. Third Parties We Share Data With

We use the following service providers to operate the App. Each processes only the data necessary for their function:

ProviderPurposeData Involved
SupabaseDatabase, authentication, backend infrastructureAll account and app data (this is our primary data store)
Google Gemini (AI)Generating Graito Portrait, AI goal suggestions, voice command parsingCheck-in notes, goal details, voice transcripts sent for processing
RevenueCatSubscription managementPurchase events, subscription status, anonymized user identifier
Google Play / Apple App StorePayment processing for subscriptionsPayment details (held by the store, not by us), purchase records
Firebase (Google)Push notification deliveryDevice push token
ExpoApp infrastructure, crash reporting, push notification relayDevice identifiers, crash logs

We do not sell your personal information to third parties for their own marketing purposes.

5. AI Processing — Specific Disclosure

When you use features involving AI (Graito Portrait, AI-assisted goal creation, AI check-in summaries, voice commands), relevant data (such as your check-in notes, mood entries, goal descriptions, or voice audio/transcripts) is sent to our AI provider for processing. This data is used to generate a response for you and is subject to that provider's own data handling terms in addition to ours. We use Google Gemini on a paid API tier (not the free tier), which under Google's current terms means your data is not used to train their models.

6. Data Retention

We retain your data for as long as your account is active. If you delete your account:

  • Personal profile information is deleted or anonymized within 60 days.
  • Content shared with others in groups (e.g., posts, peer goal activity visible to group members) may persist in a form attributed to a deleted/anonymized user, since removing it entirely could affect other users' shared history.
  • We may retain limited data as required for legal, tax, or fraud-prevention purposes for longer, as required by law.

7. Your Rights

Depending on your location, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your account and associated data
  • Withdraw consent for optional processing (e.g., push notifications)
  • Data portability, where applicable

To exercise these rights, contact us at privacy@graito.ai. For users in India, these rights are provided consistent with the Digital Personal Data Protection Act, 2023.

8. Children's Privacy

Graito is not directed at children under 18. We do not knowingly collect data from children below this age. If we learn we have inadvertently collected such data, we will delete it.

9. Data Security

We use industry-standard measures (encryption in transit, access controls, authentication safeguards) to protect your data. No system is completely secure, and we cannot guarantee absolute security.

10. International Data Transfers

Our service providers may process data outside your country of residence, including in the United States (Google, RevenueCat) and other jurisdictions. Where required, we rely on appropriate safeguards for such transfers.

11. Health Data — Additional Notice

Some information you provide (mood check-ins, wellbeing goals) may be considered sensitive personal data in certain jurisdictions, even though Graito is not a medical or healthcare provider and this data is not clinical health information. We apply additional care to this category as described in Section 2.2, but you should be aware this data exists in the App and make your own judgment about what you choose to share.

12. Changes to This Policy

We may update this Privacy Policy at our sole discretion, at any time, to reflect changes in our practices, technology, legal requirements, or business operations. Updates take effect once posted in the App or on our website, and we are not required to obtain prior approval from users before making changes — your continued use of the App after an update takes effect constitutes your acceptance of it. Where a change is significant, we'll make reasonable efforts to notify you (e.g., via the App or email) around the time it takes effect, but that notice is a courtesy, not a precondition to the change applying.

13. Contact Us

Questions about this Privacy Policy or your data: privacy@graito.ai