GREYPILE

THE PILE OF SHAME

Privacy Policy

Last updated: July 2, 2026

GreyPile is an independent fan project. We collect only the data needed to operate the app and we never sell it to third parties.

1. Who We Are

GreyPile ("we", "us", "the app") is operated by Andrea Caserini, an independent developer based in the European Union. You can reach us at neuralsand@gmail.com.

For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the personal data processed in connection with the app.

2. What Data We Collect

2.1 Account information

2.2 Content you create

2.3 Purchase information

2.4 Diagnostic and crash data

2.5 What we do not collect

3. Why We Collect It

Legal basis under GDPR: performance of a contract (Art. 6(1)(b)) for account and content data; consent (Art. 6(1)(a)) for notifications; legitimate interest (Art. 6(1)(f)) for security and abuse prevention.

4. How and Where Data Is Stored

Your account and content are stored on infrastructure provided by Supabase (EU region) in a PostgreSQL database with row-level security: each row is accessible only to its owner. All traffic between the app and our backend uses HTTPS/TLS.

Authentication tokens are stored locally on your device by the operating system so you stay signed in between launches.

5. Third Parties We Share Data With

We only share data with service providers that help us operate the app:

None of these providers receive your data for advertising or analytics outside their role described above.

6. How Long We Keep Your Data

7. Your Rights

Under GDPR and similar laws (CCPA, UK GDPR, etc.) you have the right to:

To exercise these rights, write to neuralsand@gmail.com. We will respond within 30 days.

8. Children's Privacy

GreyPile is intended for users aged 13 or older. We do not knowingly collect data from children under 13. If you become aware that a child under 13 has provided us with personal data, please contact us so we can delete it.

In the European Economic Area, the minimum age may be higher (16 in some member states). Where required, parental consent is necessary.

9. Security

We use industry-standard measures to protect your data: HTTPS in transit, row-level security in the database, and isolation of user content. No system is perfectly secure — if a breach affecting your data occurs, we will notify you and the relevant authority as required by law.

10. International Transfers

Our infrastructure is hosted in the European Union. Some service providers (e.g. RevenueCat, Apple, Google) may process data in the United States or other jurisdictions. Where this applies, transfers are protected by Standard Contractual Clauses or equivalent safeguards.

11. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the latest revision. Material changes will be announced in the app and, where required, communicated by email.

12. Contact

Andrea Caserini
Email: neuralsand@gmail.com