Privacy Statement

Last updated: 08.09.2026

Who we are

Grasp It is operated by Augmented Haptics Ltd. For any questions about this statement or your data, contact us at support@grasp.it.

We are the controller responsible for the personal data described here.

What we collect

We collect only what is needed to give you an account:

  • Your email address, used as your one-time-password (OTP) sign-in identifier.

On iOS, the app can access your photo gallery if you grant permission, so that you can use your own pictures within the app. This access is optional, controlled by the iOS permission prompt, and can be revoked at any time in your device settings.

We also collect anonymous usage statistics, described in the Analytics section below. They contain nothing that identifies you.

We do not collect location data, advertising identifiers, or the contents of your work in the app.

Why we collect it and our legal basis

We process your email address to create and maintain your account and to send the one-time passwords that let you sign in. The legal basis is performance of the contract between you and us (Article 6(1)(b) GDPR): without an account we cannot provide the service.

Analytics

To understand how the app is used and to find errors, the app sends us anonymous usage statistics: which actions are taken, when, and on which app version and platform. These records are not linked to your account or your device, are sent without your sign-in credentials, and contain no identifier that persists between app sessions, so they cannot be traced back to you. They are deleted after 12 months.

Who processes your data

Authentication and the storage of usage statistics are handled by Supabase, acting as a processor on our behalf. Supabase processes your account data only to authenticate you. Their handling of data is described in their own privacy policy: https://supabase.com/privacy.

Your account data and the usage statistics are stored within the European Union (Frankfurt, Germany). We do not transfer them outside the EU or UK.

To keep you signed in, the app stores a session token locally on your device. This token stays on your device and is removed when you sign out.

We do not sell your data or share it for advertising.

How long we keep it

We keep your account data for as long as your account exists. When you delete your account, we delete the associated account data, subject to any retention period required by law. Anonymous usage statistics are deleted after 12 months.

How we protect your data

We use a reputable authentication provider and transmit your data over encrypted connections. No system can be guaranteed completely secure, but we take reasonable measures to protect your information against unauthorized access, loss, or misuse.

Your rights

Under the UK GDPR and EU GDPR you have the right to access, correct, or delete your data, to restrict or object to processing, and to data portability. You may also lodge a complaint with a supervisory authority. To exercise any of these, contact us at support@grasp.it. We aim to respond within one month, as required by the GDPR.

Children

Grasp It is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us at support@grasp.it and we will remove it.

Changes

We may update this statement. The date above reflects the most recent change.