Privacy · Last updated 15 August 2026
What this service stores about you, and why.
This is a private, non-commercial service run for a small invited group. There is no company behind it and nothing here is monetised, so this policy is short and describes only what actually happens.
Who runs this
This service is operated by a private individual, on their own hardware, as a personal service for family and friends. It is not a product and is not offered to the public.
grivit.cloud and grivit.com are the same service, run by the same person for the same group. grivit.cloud is the infrastructure; grivit.com is where the applications members use run. Everything in this policy applies to both.
For anything in this policy, including requests about your own data, write to abuse@grivit.cloud.
What is collected
- If you have an account
- Your email address and display name, the files, photos, feeds and settings you create or upload, and server access logs containing timestamps and IP addresses.
- If you do not have an account
- When a member shares a file with you, your email address is stored so the invitation can be delivered and so the share can be revoked later. Nothing else about you is collected.
How email addresses are obtained
Every address on this system arrived one of two ways: the operator entered it when creating an account, or a signed-in member typed it while sharing a file with a specific person.
Addresses are never bought, never harvested from the web, and never imported from a mailing list or any third-party dataset. There is no signup form, so no address can arrive here without someone deliberately entering it.
Who the data is shared with
Two companies are involved, and no others. Outgoing mail is delivered through Amazon SES, so recipient addresses and message contents pass through Amazon Web Services.
AWS acts strictly as a delivery provider: it processes that mail on the operator's instructions and does not use it for its own purposes. That is processing, not sharing — nobody receives these addresses to use as their own. Nothing is sold, rented, or passed to advertisers, analytics providers or data brokers.
Backups are stored with Backblaze B2. Everything sent there is encrypted before it leaves the operator's hardware, using a key Backblaze never receives. Backblaze stores encrypted blocks it cannot read, cannot identify, and cannot open. It acts purely as storage.
Where the data is processed
Accounts, files and photos live on hardware the operator owns and runs directly, in the EU. Mail delivery is processed by Amazon SES in the eu-central-1 region, also in the EU.
Encrypted backups are stored by Backblaze in the United States. They are encrypted before upload with a key that never leaves the operator's hardware, so what crosses the border is unreadable data that Backblaze cannot open and no third party can decrypt. No readable personal data is processed outside the EU.
How long it is kept
Account data is kept until the account is closed, and is deleted with it. A share recipient's address is kept until that share expires or is revoked. Server access logs are rotated after 30 days.
Backups are taken daily and the last 30 days are kept, on the operator's own hardware and mirrored in encrypted form to Backblaze. Older backups are removed automatically as they age out, from both copies.
Backups are never edited selectively. Data deleted from the live system is absent from every backup taken afterwards, but remains inside backups taken before the deletion until those age out — so it is fully gone within 30 days. Nothing is ever restored from a backup to recover data someone asked to have deleted.
Addresses kept on purpose
There is one deliberate exception to the retention rules above. If an address bounces, or if someone reports a message from these domains as spam, that address is added to a suppression list and kept there indefinitely.
That entry is the mechanism guaranteeing the address is never mailed again. Deleting it would remove the protection, so the suppression list outlives the account or share it came from.
Stopping mail, and your rights
Reply to any message, or write to abuse@grivit.cloud. The address is suppressed permanently. You do not need an account to ask, and you do not have to say why.
You can also ask what is stored about you, ask for it to be corrected, or ask for it to be deleted. Requests to that same address are answered within 30 days.
Legal basis
Running the service — accounts, storage, sharing, and the transactional mail that makes those work — rests on legitimate interest under the GDPR.
Anything optional rests on consent, which you can withdraw at any time.
Cookies and tracking
These public pages set no cookies, load nothing from other servers, and run no analytics or tracking of any kind.
The applications behind the login set a session cookie, used only to keep you signed in.
Complaints
If you believe your data has been handled improperly, you can complain to your national data protection supervisory authority.