Privacy Policy

This Privacy Policy explains how Jedro Labs LLC (“we”, “us”), a Wyoming limited liability company, collects, uses, and protects your personal data when you use GraceDays (gracedays.app). We are the data controller for that processing. Contact us any time at hello@gracedays.app.

1. Data we collect

2. How we use your data

We use your data to provide and operate the Service, generate the insights and AI responses you ask for, authenticate you, process your subscription, keep the Service secure, respond to support requests, and comply with our legal obligations. We do not sell your personal data, and we do not use your private content to train third-party AI models.

3. Legal bases (GDPR)

Where the GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for), legitimate interests (to secure and improve the Service), consent (for non-essential cookies and marketing, where used), and legal obligation (e.g. tax and accounting).

For health and wellbeing data we rely on your explicit consent (GDPR Article 9(2)(a)), asked for separately, in plain words, before you log anything, and again for the Medical module. For sending your content to our AI providers we likewise ask for your consent. You can withdraw either at any time (section 4); withdrawal does not affect processing that already happened.

4. Health and wellbeing data (special category)

What. The health and wellbeing data listed in section 1, only ever what you choose to log or upload yourself.

Why. To keep your log, do the maths you ask for (calories, protein, targets, trends), prepare the summaries, insights and reminders you ask for, and, in the Medical module, keep your records in one place. Nothing else: we never use it for advertising, never sell it, and never use it to train anyone’s AI models.

Consent. We ask for your explicit consent on a dedicated screen before your first entry, and separately before the Medical module. Each purpose is its own unticked box, and we record the date and time, the version of the text you agreed to, and the network address and browser you agreed from, so your consent can be shown if it is ever questioned.

Withdrawal. You can withdraw your consent at any time in Settings → Security → Your consents. Withdrawing pauses the related features until you agree again; it does not delete what you already logged, which stays yours to export or delete.

Protection. Health data lives in your own isolated database schema and sensitive fields are encrypted at rest with a key derived for your account alone (section 8). Our AI providers receive only what is needed to answer the request in front of them, under contract, and may not retain or train on it.

Not medical advice. GraceDays is a companion, not a clinician. Nothing it shows you is medical advice; see the Terms of Service.

5. AI processing

To generate responses, the content of your requests — including health and financial entries you mention — is sent to our AI providers (listed below) for processing, with your consent. They act as our processors under contract and are not permitted to use your content for their own purposes or to train their models. Reading medical documents with AI is a separate switch inside the Medical module, off by default.

6. Service providers (sub-processors)

We share data only with providers that help us run the Service, under agreements that require them to protect it. Each one receives only what its job needs:

The AI model hosts act as our processors and are bound not to retain your content or use it to train models. We run one primary host with the others as fallbacks; your content reaches only a host whose service we have actually switched on. We do not send your data to any AI provider that is not listed here.

7. International transfers

Our infrastructure is hosted in the United States. Where data is transferred internationally, we rely on appropriate safeguards (such as the EU–US Data Privacy Framework and standard contractual clauses) as required by law.

8. Security

We take security seriously. Each user’s data lives in an isolated database schema; sensitive fields are encrypted at rest with a per-user key; passwords are hashed with bcrypt; and two-factor authentication is available. No system is perfectly secure, but we work to protect your data using industry-standard measures.

9. Data retention

We keep your personal data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain certain records (for example, billing records, and the record of the consents you gave, which holds only your account number, the purpose, the version and the dates) to meet legal obligations or to demonstrate compliance.

10. Your rights

Depending on where you live (including under the GDPR and the CCPA), you have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. Where processing rests on your consent, you may withdraw it at any time in Settings → Security → Your consents. You can export your data from within the app and request deletion of your account. To exercise any right, email hello@gracedays.app. We do not sell personal information, and we will not discriminate against you for exercising your rights.

11. Children

The Service is not directed to anyone under 18, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, provide additional notice where appropriate. If the wording you consented to for health data or AI processing changes materially, we will ask for your consent again before continuing.

13. Contact

Questions or requests about your privacy? Email hello@gracedays.app.