Privacy Policy
Last updated: 5 September 2026
Controller
Mind Your Axis / GRITT
Chamber of Commerce: 99066467 - VAT ID: NL005369924B37
Visiting address: Eerste van Swindenstraat 387-1, 1093 GB Amsterdam, The Netherlands
Contact and privacy requests: service@mindyouraxis.com
1. What this statement covers
This privacy policy applies to the use of GRITT and to our related websites, accounts, paid subscriptions, support contacts, payment relationships and usage-based features such as credits, uploads, speech and web retrieval. In this policy we explain which personal data we process, why we do so, with whom we share data, how long we retain data and which rights you have.
2. Which data we process and why
- Account and authentication data: such as email address, hashed password, account status and preferences such as language or theme. Legal basis: performance of the agreement.
- Subscription and payment data: such as the selected plan, credits, invoice status, transaction references, Stripe customer and subscription IDs, promo or coupon references and administrative payment metadata. As a rule, we do not receive full card or bank account numbers. Legal basis: performance of the agreement and statutory record-keeping obligations.
- Usage, security and support data: such as IP address, timestamps, browser or device data, error messages, abuse signals, order and webhook logs and correspondence with customer service. Legal basis: performance of the agreement and our legitimate interest in security, fraud prevention, stability, troubleshooting, support and cost control.
- Content that you actively enter or upload: such as prompts, chat messages, documents, notes, transcripts and other input needed to provide the functionality you request. Legal basis: performance of the agreement.
- Personal conversation memory: GRITT may build a limited memory across chats from your own conversations, covering durably relevant topics, goals, interests, preferences, project context, self-descriptions and cautiously formulated, revisable interaction patterns. This memory is enabled by default for accounts; enabling it does not cause older conversations to be processed automatically. It helps GRITT adapt conversations and educational support and avoid unnecessary repetition. GRITT is not intended to store passwords, tokens, payment details, precise addresses, medical or psychological diagnoses, or special-category personal data such as ethnicity, political opinions, religion, health or sexual orientation in this memory. Legal basis: our legitimate interest in providing consistent, personal and useful support through an AI tutor and conversation partner.
- Vector and retrieval data: embeddings, metadata and, where needed for retrieval, text fragments of uploaded or processed content. Legal basis: performance of the agreement.
- Internal product improvement and user research: we may use usage data, error patterns and, where reasonably possible, aggregated or anonymised data for internal quality improvement, statistics, security and user research. Legal basis: our legitimate interest in improving and securing our service.
- Privacy-lean customer-value and active-time measurement: for signed-in customer accounts, we count active-use seconds only on supported GRITT web pages and native app screens while the relevant surface is visible in the foreground and has recently been operated by the user. The active clock stops after two minutes without interaction. Under a secret, one-way pseudonym, we link this measurement to the plan and to successful or refunded amounts reported by the payment provider. The content-free measurement message contains no screen name, visited URL, chat or document content, text, audio, session ID, advertising ID, name, email address or plain user ID. Only aggregated cohort results appear in the admin view and export. The pseudonymous daily records remain personal data under the GDPR. Legal basis: our legitimate interest in privacy-responsible product statistics, pricing insight and capacity planning.
- Necessary storage and cookieless analytics: strictly necessary storage for basic functionality, security, session management and preferences. For general visitor statistics, we use self-hosted Matomo without analytics cookies. Legal basis: performance of the agreement or legitimate interest in a functional, secure and improvable service.
AI processing and external AI service providers. When you use AI functionality, such as chat, Education, Study mode, document analysis, source analysis, speech-to-text or read-aloud features, we process the data needed to perform that function. This may include chat messages, prompts, selected document context, source excerpts, file contents, project or session context, audio recordings and transcripts.
These data are first sent to the secured GRITT backend operated by Mind Your Axis. To generate answers, compile limited personal conversation memory, perform analysis or embeddings, or provide speech functionality, GRITT may pass these data to external AI and speech providers. In the current production configuration, language-model processing, embedding processing and speech-to-text use Microsoft Azure services (including Azure OpenAI), and text-to-speech uses ElevenLabs. These parties process data solely to provide GRITT functionality, under contractual arrangements or their applicable processor terms.
The mobile app asks for consent for this processing before AI functionality is used. Without that consent, you cannot use AI functionality in the mobile app.
Mobile app and App Store privacy disclosure. To operate GRITT, the iOS app sends account and contact information, account and device identifiers, subscription and transaction information, chat, search and other user content, audio, usage data and limited diagnostics to the GRITT backend and the processors described above. Content you enter may include sensitive information if you choose to provide it. A general country or region category may be derived from the network address for purposes including language, availability, security, tax and billing. Where necessary, these data are linked to your account to provide the requested service; crash, performance and other diagnostic data are not linked to your identity by default. We do not use these data to track you across apps or websites owned by other companies.
3. What we do not do
We do not provide your user data to AI or model providers for the training of their generic models. We do not sell your data and currently do not show advertisements through Google AdSense or a comparable advertising provider. Where we offer AI functionality through an external processor, this is done solely to perform the function requested by you.
4. From whom we receive data
We mainly receive personal data directly from you, for example when you create an account, take out a subscription, purchase credits, use the service, upload documents or contact us. In addition, we may receive limited data from payment service providers, such as status or reference information needed for payment, invoicing, customer service and fraud prevention.
5. Recipients, processors and changes of service providers
We share personal data only where this is necessary for the delivery, security, administration, support or improvement of GRITT. For this purpose, we may use categories of service providers such as hosting and infrastructure providers, payment processors, AI and speech providers, search or retrieval providers, vector or database providers, analytics providers and email or support providers.
Where reasonably available and suitable for the relevant function, we prefer suppliers that offer processing within the EEA and have a privacy-responsible profile. This is a best-efforts preference and not an absolute guarantee that every supplier used is established within the EEA or entirely free from any third-country nexus.
Over time, we may replace, supplement or discontinue service providers with comparable suppliers, for example for reasons of continuity, security, compliance, availability, functionality, performance or cost control. If such a change is materially relevant to the processing of personal data, we will update this privacy policy and, where appropriate, also an up-to-date supplier list or documentation page.
Service providers may themselves use subprocessors or supporting infrastructure where permitted under the applicable contractual and legal framework. Any documentation or supplier page mentioning current provider names is in principle informative and intended for transparency; such an overview is not an independent promise that exactly the same parties or subprocessors will continue to be used permanently.
- Hosting and infrastructure providers: for hosting, DNS, email hosting, server management, storage and related infrastructure functions.
- Payment processors and billing providers: for payments, subscriptions, credits or top-ups, invoicing, coupons or promotional codes, customer portals and related webhook or administrative functions.
- AI and language-processing providers: for language models, embeddings and similar AI functionality, currently including Azure OpenAI through Microsoft Azure for language-model and embedding processing.
- Speech providers: for speech-to-text, text-to-speech and related audio functionality, currently Microsoft Azure for speech-to-text and ElevenLabs for text-to-speech where such speech features are enabled.
- Vector and database providers: for embeddings, metadata and text fragments needed for retrieval functionality.
- Search or retrieval providers: for web retrieval, search results and similar search functionality. When account selection is available, you can choose Google or Mojeek; without an explicit choice, GRITT uses the product default shown at that time. GRITT does not infer this choice from your country, language, IP address or message content and does not silently replace an explicit choice with another provider.
- Analytics providers: for cookieless analytics within our own or contracted infrastructure. Our self-hosted Matomo configuration does not place analytics cookies.
- Email or support providers: for customer communications, support handling and operational messages, where applicable.
Google Search Grounding. If Google is selected, GRITT sends the formulated search request to the paid Gemini API with Google Search Grounding. Google also processes the grounded search output and associated search and source information. For paid Gemini services, Google does not use prompts and answers to improve its general products. For Google Search Grounding, however, Google retains the Grounding prompt and output for 30 days to create grounded results and search suggestions and for debugging and testing of those systems; this specific retention cannot be disabled when Grounding is used. GRITT uses the Interactions API without persistent conversation storage (store=false), but that does not remove the separate Google Search Grounding retention period.
Mojeek. If Mojeek is selected, GRITT sends the search query to Mojeek in the United Kingdom. Mojeek uses an independent British search index and publishes a no-tracking policy. Its coverage and relevance may be more limited than those of larger search engines.
Where a party processes personal data on our behalf, we conclude appropriate contractual arrangements where required, such as a data processing agreement.
6. Transfers outside the EEA
Personal data may be processed within the EEA, the United Kingdom and, depending on the service provider, subprocessor or functionality used, also in other countries outside the EEA. This may include suppliers established outside the EEA while the processing region chosen by us lies within the EEA, and conversely in some cases access or transfer outside the EEA cannot be fully excluded.
Where personal data are transferred outside the EEA, we rely on an appropriate transfer mechanism, such as an adequacy decision or Standard Contractual Clauses approved by the European Commission, supplemented where necessary with appropriate additional measures. Where data are transferred to the United Kingdom, we will in principle rely on the adequacy regime or other transfer mechanism applicable at that time.
7. Retention periods
We do not retain personal data longer than necessary for the purpose for which they were collected, unless a statutory retention obligation or a stronger legitimate interest requires otherwise. In practice, we generally apply the following periods:
- Account and profile data: for as long as your account remains active. After termination, we generally delete or anonymise these data within 6 months, unless longer retention is necessary for security, dispute handling or a legal obligation.
- Documents, chat content and other content stored by you: for as long as they form part of your account or project environment. After deletion by you or termination of the account, we generally delete or anonymise these data within 90 days, with an additional limited retention period for backups where technically necessary.
- Personal conversation memory: a memory is generally deleted no later than 365 days after it is recorded or substantively reconfirmed. Merely retrieving or using it does not extend that period. Deletion through the partial memory reset in Account, deletion of the source session or termination of the account may take place earlier. Technically necessary, content-free deletion records may remain temporarily to enforce deletion in connected storage systems.
- Invoices and tax administration: 7 years, or longer if required by law.
- Support correspondence: in principle up to 24 months after handling the request, unless a dispute, security incident or legal duty justifies a longer retention period.
- Security, access and error logs: in principle 90 days; in the event of incidents or abuse signals, relevant logging may be kept longer for as long as necessary for investigation, security or legal protection.
- Technical preferences: for as long as needed to remember necessary settings and preferences.
- Pseudonymous active-time records: up to 400 days. Aggregated customer-value snapshots are kept for up to 730 days. The underlying payment administration follows the statutory tax-retention period; when an account is erased, that account's separate pseudonymous measurement records are removed unless a legal retention duty requires otherwise.
- Aggregated or truly anonymised research and statistical data: may be retained longer because they are not, or no longer, traceable to a person.
8. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection, insofar as the GDPR grants you those rights. Where processing is based on consent, you may withdraw that consent at any time. In Account you can partially erase existing personal conversation memory; this does not automatically delete your chats, documents or study materials. To object to new personal conversation memory or to the customer-value and active-time measurement based on our legitimate interest, contact service@mindyouraxis.com. We assess such an objection under the GDPR; once it has been accepted, we will not create new relevant measurement records or memories for your account unless you ask us to reactivate them. We respond without undue delay and in principle within one month. To prevent misuse, we may request additional verification of your identity.
9. Cookies and analytics
We use only strictly necessary cookies or local browser storage for basic functionality, security, session management and preferences. For general visitor statistics, we use self-hosted Matomo in cookieless mode. Matomo is configured with disableCookies() and removes previously placed Matomo cookies before a page view is measured. On supported web and native app surfaces, the separate active-time measurement uses the existing signed-in session and a content-free heartbeat. It does not place an analytics cookie, use an advertising identifier or send a screen name, page URL or session ID. We do not load Google AdSense, Google Ad Manager or a consent manager and therefore do not show an analytics or advertising cookie banner.
10. Security
We take appropriate technical and organisational measures to protect personal data, including transport encryption, access restriction, logging and security monitoring. No system is entirely risk-free; please report security issues via service@mindyouraxis.com.
11. Automated decision-making and profiling
We do not take decisions based solely on automated processing that produce legal effects concerning you or otherwise significantly affect you. Personal conversation memory may qualify as profiling under the GDPR, but is used only to adapt conversations and educational support, not for admission, grading, marketing or any other decision with legal or similarly significant effects. We do not use personal data for marketing profiling without an appropriate legal basis.
12. 18+
GRITT is intended for persons aged 18 and over.
13. Complaints
You can send questions, privacy requests or complaints to service@mindyouraxis.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
14. Changes
We may amend this privacy policy, for example due to changes in GRITT, our service providers, processing purposes, security measures or applicable law. We publish the most recent version on the site. In the event of material changes, we will inform you in advance where appropriate via the website, in your account or by email.