Privacy Policy
Last updated: September 26, 2026
- Your files never leave your local network — no server relay, ever.
- The app has no analytics, no crash tracking, no advertising identifiers. A bug report only leaves your device if you send it yourself (section 2f). The website counts its visits anonymously, with no cookies (section 2b).
- The app collects one single piece of personal data: your email address, and only if you create an account for your subscription. The free tier asks for none. The only other exceptions: what beta testers gave us when signing up (section 2d), the address left on this website to be told when the app is out (section 2e), and what you put in a bug report (section 2f).
- EU users have full GDPR rights — contact us any time.
1. Who we are
GreySpace is developed and published by Fabien Chauveau, independent developer.
Contact: [email protected]
For any privacy-related inquiry, write to [email protected]. We respond within 30 days.
2. Data we collect — and why
2a. Buying the subscription
When you purchase or subscribe to GreySpace Pro, your payment and email are processed by Stripe (our payment processor) — governed by their Privacy Policy. We do not store your card details or billing address.
Since September 2026, GreySpace no longer uses a license key: a subscription is tied to an account (section 2c). In practice:
- No license code is issued, entered or stored any more. The old alphanumeric code system has been removed from the product.
- To check that a subscription is active, the app sends over HTTPS to
api.getgreyspace.comyour session token and an installation identifier (a random UUID generated locally, unrelated to your identity or your hardware), used to enforce the device limit. Nothing else. On iOS, macOS and Android, subscription status is additionally checked with the store through RevenueCat (section 5), which receives neither your email nor any payment details. - Logs of those checks are retained for 30 days (Cloudflare D1), then auto-deleted.
2c. GreySpace account (optional)
Since September 2026, GreySpace offers an account so your subscription follows you from one device to the next. It is entirely optional. The free tier — including unlimited receiving, forever — works with no account, no email, and no personal data reaching us at all. An account is only created when you ask for one: when you subscribe, claim a subscription you already paid for, or ask on this website to be told when the app is out (section 2e).
If you do create an account, here is exactly what is stored on our servers (Cloudflare D1, European Union), and nothing else:
- Your email address. It is the only personal data an account requires. It serves as your account identifier and lets us send your 6-digit sign-in code. It is never sold, never shared beyond the processors listed in section 5, and we only email you about your account — unless you asked to be told when the app is out (section 2e), which states exactly which emails you will get.
- Your device names and their platform (“Office PC”,
windows). You choose that name in the app — if it contains your first name, it is stored as-is. It exists only so you can recognise your own devices in the list and disconnect one. You can change it any time in settings. - An installation identifier per device (a random UUID generated locally, unrelated to your hardware), used to enforce the 5-device limit.
- Your subscription status: active or not, plan, end date, originating store. No payment details — we never see them.
- Last-activity timestamps (when each device last checked in), to help you spot the one you no longer use.
What is never stored: your password (there is none), your 6-digit code (only a hash is kept, for 10 minutes), and your session token (only a hash is kept server-side; the token itself lives solely in your device's secure vault — Keychain, Keystore or DPAPI).
Deleting your account is done from inside the app, in two taps: Settings → your address → “Delete my account”. Everything is erased from our servers immediately and irreversibly. No email to write, no waiting period. An account created only for “Tell me when it’s out” is also erased by the unsubscribe link in every email. Note: this does not cancel your subscription, which is cancelled where you paid for it (Apple, Google or Stripe). See the dedicated account deletion page.
2b. Website (hosting and visitor statistics)
This website (getgreyspace.com) is hosted on Cloudflare Pages. Cloudflare may collect standard web server logs (IP address, browser type, referring URL) as part of their infrastructure security, subject to Cloudflare's Privacy Policy.
This website places no cookies and no identifier on your device, and uses no advertising pixels (no Google Analytics, no Mixpanel). To know how many people visit, where they come from and which download links get used, it relies on Umami Cloud (Umami Software, Inc.), a visitor statistics tool built for exactly that. That is why no cookie banner appears.
For each page view, Umami receives the page address (with its utm_ campaign tags, if any), the site you came from, your browser, operating system, device type, screen size and language. It derives your country, region and city from your IP address, without keeping that address. Page views are grouped per visitor through an anonymous hash, computed from the IP address and the browser and renewed every month: it is used to count visitors, not to know who you are. Clicks on download links, on the Discord link and on links to the pricing page are counted the same way, along with the page and the location of the button they came from (top or bottom of the page, for example), as well as the use of the “Send yourself the link” button, without the link sent or its recipient.
These statistics are used only to measure traffic on this website: they are never combined with your account, the app, or other websites. They are hosted in the European Union and kept for 6 months. To stop your visits from being counted at all, open getgreyspace.com/?notrack=1: your browser remembers that choice (repeat it on each browser and each device), and getgreyspace.com/?retrack=1 undoes it.
2d. Beta programme (only if you signed up)
Testers in the first phase signed up through a questionnaire (a Google Form). If you filled it in, here is what we keep (Cloudflare D1, European Union):
- Your email address, used to send you your beta access. That access code expired on July 31, 2026 and no longer grants anything.
- Your Discord username, if you gave it, to connect the GreySpace Discord server with the sign-ups.
- Your answers to the questionnaire: devices and software you use, how often and how large your transfers are, your current tools, your main pain point, and a link to your portfolio if you gave one. They are used to sort bug reports by platform.
Your answers also remain in the Google Form, on the developer's account, with the same retention period. None of it is sold or used for marketing.
This data is erased no later than 12 months after your last answer, or as soon as you ask at [email protected]. It rests on your consent, which you can withdraw at any time the same way.
The Android closed test goes through a Google group (greyspace-testers): Google manages your membership, and your address appears in the member list, which is used only to give you access to the test on the Play Store. Leaving the group removes you from it.
2e. “Tell me when it’s out” (only if you signed up)
On the Download page, you can leave your address to be told when the app lands on Google Play (and, before the iPhone app came out, on the App Store). You confirm it with a 6-digit code, which creates your GreySpace account (section 2c) — with no device, so nothing but your address. Here is what we keep (Cloudflare D1, European Union):
- Your email address, and the language to write to you in.
- The phones you ticked (Android, iPhone), and the dates of your sign-up and of the emails sent.
What you get, and nothing else: one email the day the app comes out in the store of each phone you ticked, then a single email introducing the Pro version, no sooner than a week later. Your address is never sold, never shared, never used for anything else.
Every email contains an unsubscribe link that erases your sign-up at once — and your account too, if that was all it was used for. Otherwise the sign-up is erased 12 months after the last email (or after signing up, if the app hasn’t come out yet), along with the account if it was never used in the app. It rests on your consent (GDPR art. 6(1)(a)), which you can withdraw at any time through that link or by writing to us.
2f. “Report a bug” (only if you send a report)
In the app, the “Report a bug” button (in Settings, and under every error message) opens a window to write to us. Nothing leaves your device until you tap “Send”, and you can read the full content first, with “See what is attached”. The report goes over HTTPS to api.getgreyspace.com, which emails it to the developer. It contains:
- Your message and, if you give it, your email address so we can reply. If you are signed in, your account address is suggested: you can clear it.
- The place in the app you report from, and the text of the error shown at that moment.
- The GreySpace version, your device model and its operating system (for example “samsung SM-A375B, Android 16”), the language, and whether an account is signed in, with its tier (free or Pro). Never the name you gave your device.
- What the app did in the last few minutes (a technical log of 400 lines at most), unless you untick the box. It lives in memory only and is never written to your device. Before sending, the app masks your account name in folder paths, email addresses and sign-in tokens. File names stay: they often help understand the bug.
Without an internet connection, the report waits in the app (three at most) and goes out on the next launch. The server keeps only each report’s random identifier, so it never receives the same report twice: the content exists only in the email the developer receives.
A report is used only to fix GreySpace and to reply to you. It is erased 12 months after it is received, or as soon as you ask at [email protected]. It rests on your consent (GDPR art. 6(1)(a)): you choose whether to send, and what.
3. What we do NOT collect
- ❌ Your files — they travel directly on your local network and never touch our servers
- ❌ Names, phone numbers, postal addresses.
The only exceptions, all explicit: your email address, if — and only if — you create an account (section 2c) or ask to be told when the app is out (section 2e), and what you gave us yourself if you signed up for the beta programme (section 2d), and what you put in a bug report (section 2f). Without an account and without a bug report, the app sends us literally no personal data about you. - ❌ Location data or GPS coordinates
- ❌ Contact lists or address books
- ❌ Advertising identifiers (IDFA, GAID)
- ❌ App usage analytics or session recordings.
The website does count its visits, anonymously and with no cookies (section 2b). A bug report you send yourself attaches the log of the last few minutes, nothing more (section 2f). - ❌ Hardware-bound device identifiers (IMEI, serial number, MAC address).
We do, however, generate an installation identifier: a random UUID created locally on your device, unrelated to your identity or to your hardware. It is transmitted only when checking a paid subscription, to enforce the device limit.
4. LAN-only transfers
File transfers in GreySpace are point-to-point on your local Wi-Fi or LAN. Data travels directly from one device to another using TCP over your network. No file content is relayed through any external server, cloud service, or GreySpace infrastructure. You are in complete control of what gets transferred.
5. Data processors
| Processor | Purpose | Data shared | Policy |
|---|---|---|---|
| Stripe | Payment & subscription management | Email, payment info (at purchase only) | stripe.com/privacy ↗ |
| Resend | Sign-in and confirmation emails (6-digit codes), beta access emails, bug reports sent to the developer (section 2f), and “Tell me when it’s out” emails | Email address and, depending on the email: 6-digit code, beta access code, message text or the content of a bug report (section 2f) | resend.com/legal/privacy-policy ↗ |
| RevenueCat | iOS and Android subscription management | Account identifier (UUID) and subscription status — never your email | revenuecat.com/privacy ↗ |
| Cloudflare | Website hosting, account API & account database | Server-level request logs, account data (section 2c), beta-tester profiles (section 2d), random identifier of bug reports (section 2f), “Tell me when it’s out” sign-ups (section 2e) | cloudflare.com/privacypolicy ↗ |
| Beta-tester questionnaire (Forms) and Android closed-test group (Groups) | Questionnaire answers, email address of group members (section 2d) | policies.google.com/privacy ↗ | |
| Umami | Website visitor statistics, no cookies | Page views, referring site, browser, OS, device, language, country and city (section 2b). IP address not kept | umami.is/privacy ↗ |
6. Your rights (GDPR — EU/EEA)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of access — request a copy of data we hold about you
- Right to rectification — correct inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
To exercise any of these rights, email [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with your national data protection authority. In France: CNIL (cnil.fr).
Legal basis for processing: contract performance (GDPR art. 6(1)(b)) — subscription checks and account management exist to deliver the service you bought. The beta programme (section 2d) and “Tell me when it’s out” (section 2e) rest instead on your consent (art. 6(1)(a)), which you can withdraw at any time by writing to us — or, for the latter, through the link in every email. A bug report (section 2f) also rests on your consent: it only leaves if you send it. For free-tier users without an account, the app processes no personal data at all as long as they send no bug report, and that is the default case. The right to erasure is exercised directly in the app (Settings → your address → “Delete my account”), with no need to write to us. Website visitor statistics (section 2b) rest on our legitimate interest (art. 6(1)(f)) in knowing how our own website is visited; you can object at any time through the link given in section 2b.
7. Children's privacy
GreySpace is not directed at children under 13. We do not knowingly collect data from children. As we collect no personal data during normal use, this is already satisfied by design.
8. Data retention summary
- Subscription check logs: 30 days (Cloudflare D1, then auto-deleted)
- Purchase data: retained by Stripe per their policy (legal requirement)
- Account data (email, devices, subscription status): kept as long as the account exists, then erased immediately on deletion from the app
- 6-digit sign-in codes: 10 minutes, stored as a hash, then deleted — a code that has been used is destroyed at once
- Sessions: a rolling 1 year, extended on each use; signing out deletes them on the spot
- Beta-tester profiles (beta programme questionnaire): erased no later than 12 months after the last answer, or as soon as you ask
- “Tell me when it’s out” sign-ups: erased on unsubscribing, otherwise 12 months after the last email sent; the account goes too if it was never used in the app
- Website visit statistics (Umami): 6 months, with no IP address
- Bug reports: 12 months after receipt, in the developer’s mailbox, or until you ask; the server keeps only their random identifier
- Everything else: not collected, not retained
9. Changes to this policy
If we materially change our data practices, we will update this page and the "Last updated" date above. We will not add tracking or analytics without updating this policy first.
10. Contact
Questions or requests about your data:
[email protected]