TL;DR
  • Your files never leave your local network — no server relay, ever.
  • The app has no analytics, no crash tracking, no advertising identifiers. A bug report only leaves your device if you send it yourself (section 2f). The website counts its visits anonymously, with no cookies (section 2b).
  • The app collects one single piece of personal data: your email address, and only if you create an account for your subscription. The free tier asks for none. The only other exceptions: what beta testers gave us when signing up (section 2d), the address left on this website to be told when the app is out (section 2e), and what you put in a bug report (section 2f).
  • EU users have full GDPR rights — contact us any time.

1. Who we are

GreySpace is developed and published by Fabien Chauveau, independent developer.
Contact: [email protected]

For any privacy-related inquiry, write to [email protected]. We respond within 30 days.

2. Data we collect — and why

2a. Buying the subscription

When you purchase or subscribe to GreySpace Pro, your payment and email are processed by Stripe (our payment processor) — governed by their Privacy Policy. We do not store your card details or billing address.

Since September 2026, GreySpace no longer uses a license key: a subscription is tied to an account (section 2c). In practice:

2c. GreySpace account (optional)

Since September 2026, GreySpace offers an account so your subscription follows you from one device to the next. It is entirely optional. The free tier — including unlimited receiving, forever — works with no account, no email, and no personal data reaching us at all. An account is only created when you ask for one: when you subscribe, claim a subscription you already paid for, or ask on this website to be told when the app is out (section 2e).

If you do create an account, here is exactly what is stored on our servers (Cloudflare D1, European Union), and nothing else:

What is never stored: your password (there is none), your 6-digit code (only a hash is kept, for 10 minutes), and your session token (only a hash is kept server-side; the token itself lives solely in your device's secure vault — Keychain, Keystore or DPAPI).

Deleting your account is done from inside the app, in two taps: Settings → your address → “Delete my account”. Everything is erased from our servers immediately and irreversibly. No email to write, no waiting period. An account created only for “Tell me when it’s out” is also erased by the unsubscribe link in every email. Note: this does not cancel your subscription, which is cancelled where you paid for it (Apple, Google or Stripe). See the dedicated account deletion page.

2b. Website (hosting and visitor statistics)

This website (getgreyspace.com) is hosted on Cloudflare Pages. Cloudflare may collect standard web server logs (IP address, browser type, referring URL) as part of their infrastructure security, subject to Cloudflare's Privacy Policy.

This website places no cookies and no identifier on your device, and uses no advertising pixels (no Google Analytics, no Mixpanel). To know how many people visit, where they come from and which download links get used, it relies on Umami Cloud (Umami Software, Inc.), a visitor statistics tool built for exactly that. That is why no cookie banner appears.

For each page view, Umami receives the page address (with its utm_ campaign tags, if any), the site you came from, your browser, operating system, device type, screen size and language. It derives your country, region and city from your IP address, without keeping that address. Page views are grouped per visitor through an anonymous hash, computed from the IP address and the browser and renewed every month: it is used to count visitors, not to know who you are. Clicks on download links, on the Discord link and on links to the pricing page are counted the same way, along with the page and the location of the button they came from (top or bottom of the page, for example), as well as the use of the “Send yourself the link” button, without the link sent or its recipient.

These statistics are used only to measure traffic on this website: they are never combined with your account, the app, or other websites. They are hosted in the European Union and kept for 6 months. To stop your visits from being counted at all, open getgreyspace.com/?notrack=1: your browser remembers that choice (repeat it on each browser and each device), and getgreyspace.com/?retrack=1 undoes it.

2d. Beta programme (only if you signed up)

Testers in the first phase signed up through a questionnaire (a Google Form). If you filled it in, here is what we keep (Cloudflare D1, European Union):

Your answers also remain in the Google Form, on the developer's account, with the same retention period. None of it is sold or used for marketing.

This data is erased no later than 12 months after your last answer, or as soon as you ask at [email protected]. It rests on your consent, which you can withdraw at any time the same way.

The Android closed test goes through a Google group (greyspace-testers): Google manages your membership, and your address appears in the member list, which is used only to give you access to the test on the Play Store. Leaving the group removes you from it.

2e. “Tell me when it’s out” (only if you signed up)

On the Download page, you can leave your address to be told when the app lands on Google Play (and, before the iPhone app came out, on the App Store). You confirm it with a 6-digit code, which creates your GreySpace account (section 2c) — with no device, so nothing but your address. Here is what we keep (Cloudflare D1, European Union):

What you get, and nothing else: one email the day the app comes out in the store of each phone you ticked, then a single email introducing the Pro version, no sooner than a week later. Your address is never sold, never shared, never used for anything else.

Every email contains an unsubscribe link that erases your sign-up at once — and your account too, if that was all it was used for. Otherwise the sign-up is erased 12 months after the last email (or after signing up, if the app hasn’t come out yet), along with the account if it was never used in the app. It rests on your consent (GDPR art. 6(1)(a)), which you can withdraw at any time through that link or by writing to us.

2f. “Report a bug” (only if you send a report)

In the app, the “Report a bug” button (in Settings, and under every error message) opens a window to write to us. Nothing leaves your device until you tap “Send”, and you can read the full content first, with “See what is attached”. The report goes over HTTPS to api.getgreyspace.com, which emails it to the developer. It contains:

Without an internet connection, the report waits in the app (three at most) and goes out on the next launch. The server keeps only each report’s random identifier, so it never receives the same report twice: the content exists only in the email the developer receives.

A report is used only to fix GreySpace and to reply to you. It is erased 12 months after it is received, or as soon as you ask at [email protected]. It rests on your consent (GDPR art. 6(1)(a)): you choose whether to send, and what.

3. What we do NOT collect

4. LAN-only transfers

File transfers in GreySpace are point-to-point on your local Wi-Fi or LAN. Data travels directly from one device to another using TCP over your network. No file content is relayed through any external server, cloud service, or GreySpace infrastructure. You are in complete control of what gets transferred.

5. Data processors

Processor Purpose Data shared Policy
Stripe Payment & subscription management Email, payment info (at purchase only) stripe.com/privacy ↗
Resend Sign-in and confirmation emails (6-digit codes), beta access emails, bug reports sent to the developer (section 2f), and “Tell me when it’s out” emails Email address and, depending on the email: 6-digit code, beta access code, message text or the content of a bug report (section 2f) resend.com/legal/privacy-policy ↗
RevenueCat iOS and Android subscription management Account identifier (UUID) and subscription status — never your email revenuecat.com/privacy ↗
Cloudflare Website hosting, account API & account database Server-level request logs, account data (section 2c), beta-tester profiles (section 2d), random identifier of bug reports (section 2f), “Tell me when it’s out” sign-ups (section 2e) cloudflare.com/privacypolicy ↗
Google Beta-tester questionnaire (Forms) and Android closed-test group (Groups) Questionnaire answers, email address of group members (section 2d) policies.google.com/privacy ↗
Umami Website visitor statistics, no cookies Page views, referring site, browser, OS, device, language, country and city (section 2b). IP address not kept umami.is/privacy ↗

6. Your rights (GDPR — EU/EEA)

If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):

To exercise any of these rights, email [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with your national data protection authority. In France: CNIL (cnil.fr).

Legal basis for processing: contract performance (GDPR art. 6(1)(b)) — subscription checks and account management exist to deliver the service you bought. The beta programme (section 2d) and “Tell me when it’s out” (section 2e) rest instead on your consent (art. 6(1)(a)), which you can withdraw at any time by writing to us — or, for the latter, through the link in every email. A bug report (section 2f) also rests on your consent: it only leaves if you send it. For free-tier users without an account, the app processes no personal data at all as long as they send no bug report, and that is the default case. The right to erasure is exercised directly in the app (Settings → your address → “Delete my account”), with no need to write to us. Website visitor statistics (section 2b) rest on our legitimate interest (art. 6(1)(f)) in knowing how our own website is visited; you can object at any time through the link given in section 2b.

7. Children's privacy

GreySpace is not directed at children under 13. We do not knowingly collect data from children. As we collect no personal data during normal use, this is already satisfied by design.

8. Data retention summary

9. Changes to this policy

If we materially change our data practices, we will update this page and the "Last updated" date above. We will not add tracking or analytics without updating this policy first.

10. Contact

Questions or requests about your data:
[email protected]