Privacy Policy
This Privacy Policy describes how Grift (“we”, “us”, “the app”) collects, uses, and shares information when you use the Grift mobile application.
By using Grift you agree to the practices described below. If you do not agree, do not use the app.
1. Information we collect
1.1 Information you give us
- Sign-in identity. When you create an account via Sign in with Apple or Sign in with Google, we receive a stable provider-issued user identifier and, if you choose to share them, your name and an email address (Apple may generate a private relay address on your behalf; Google provides the email associated with your Google account). We store these to identify your account and contact you about your account.
- Profile information. Display name, handle, bio, and avatar image you set in the app.
- Posts and reactions. Photos and videos you post, comments you write, reactions (likes, dislikes, reports), follow relationships, and block relationships.
1.2 Information collected automatically
- Device & diagnostic data. Crash reports, performance traces, and basic device information (OS version, device model) used to keep the app working. These reports are not linked to your identity.
- Authentication tokens. Firebase Authentication stores a token on your device so you stay signed in between launches. The token is removed when you sign out.
1.3 What we do not collect
- We do not use IDFA, fingerprinting, or any other cross-app tracking identifier.
- We do not access your address book, contacts, calendar, location, health data, or precise advertising identifiers.
- We do not sell, rent, or share your personal information with third-party advertisers.
2. How we use your information
We use the information we collect to:
- Run the core features of the app (signing you in, displaying posts, sending notifications you opt into).
- Enforce the post-per-day limit and 3-day post expiration.
- Detect and respond to abuse (spam, harassment, content that violates our Community Guidelines).
- Diagnose and fix bugs and crashes.
3. How we share your information
We share information with the following third parties strictly to operate the service:
- Apple, for Sign in with Apple identity verification.
- Google, for Sign in with Google identity verification (separate from Firebase, below).
- Google Firebase, which provides our authentication, database (Firestore), file storage, push notifications, and abuse-prevention (App Check) infrastructure. Firebase processes data on our behalf under Google’s data-processing terms.
We may disclose information if required by law (subpoena, court order, or similar legal process), or to protect the rights, property, or safety of Grift, our users, or the public.
4. Your rights and choices
- View and edit your profile. Use the “Edit profile” sheet in the Me tab.
- Block another user. Use the “Block @handle” action in any user’s profile. Blocking is reversible.
- Delete your account. Use the “Delete account” action in the Me tab’s settings menu. This permanently deletes your Firebase Auth account, your posts, comments, reactions, and follow/block edges. This action cannot be undone.
- Sign out. Use the “Sign out” action in the Me tab’s settings menu.
If you are in a jurisdiction with data-protection laws that grant additional rights (e.g. GDPR, CCPA), email us at the address below to exercise them.
5. Children
Grift is not directed to children under 13 (or under 16 in the EEA), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us so we can delete it.
6. Data retention
We retain your account data for as long as your account is active. When you delete your account, we delete your account data within 30 days, except where we are legally required to keep specific records longer.
7. Security
We use industry-standard measures (TLS in transit, encrypted Firebase storage at rest, App Check on backend requests) to protect your information. No system is perfect, however, and we cannot guarantee absolute security.
8. Changes to this policy
If we materially change this policy we will update the date above and notify users in the app. Continued use after a change constitutes acceptance of the revised policy.
9. Contact
Questions or requests? Email privacy@grift.app.