Privacy Statement

Last updated: 29.04.2026

Who we are

Grasp It is operated by Augmented Haptics Ltd. For any questions about this statement or your data, contact us at support@grasp.it.

We are the controller responsible for the personal data described here.

What we collect

We collect only what is needed to give you an account:

  • Your email address, used as your one-time-password (OTP) sign-in identifier.

On iOS, the app can access your photo gallery if you grant permission, so that you can use your own pictures within the app. This access is optional, controlled by the iOS permission prompt, and can be revoked at any time in your device settings.

We do not currently collect usage analytics, location data, advertising identifiers, or the contents of your work in the app.

Why we collect it and our legal basis

We process your email address to create and maintain your account and to send the one-time passwords that let you sign in. The legal basis is performance of the contract between you and us (Article 6(1)(b) GDPR): without an account we cannot provide the service.

Analytics

We do not collect analytics at this time. We may in the future introduce optional analytics to understand how the app is used and to improve it. If we do, we will update this statement to describe what is collected and the legal basis before any analytics are enabled.

Who processes your data

Authentication is handled by Supabase, acting as a processor on our behalf. Supabase processes your account data only to authenticate you. Their handling of data is described in their own privacy policy: https://supabase.com/privacy.

Your account data is stored within the European Union (Frankfurt, Germany). We do not transfer your account data outside the EU or UK.

To keep you signed in, the app stores a session token locally on your device. This token stays on your device and is removed when you sign out.

We do not sell your data or share it for advertising.

How long we keep it

We keep your account data for as long as your account exists. When you delete your account, we delete the associated account data, subject to any retention period required by law.

How we protect your data

We use a reputable authentication provider and transmit your data over encrypted connections. No system can be guaranteed completely secure, but we take reasonable measures to protect your information against unauthorized access, loss, or misuse.

Your rights

Under the UK GDPR and EU GDPR you have the right to access, correct, or delete your data, to restrict or object to processing, and to data portability. You may also lodge a complaint with a supervisory authority. To exercise any of these, contact us at support@grasp.it. We aim to respond within one month, as required by the GDPR.

Children

Grasp It is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us at support@grasp.it and we will remove it.

Changes

We may update this statement. The date above reflects the most recent change.