| Information | Stored where | Used or sent to | Kept for |
|---|---|---|---|
| Project memory, files, notes, sources, conversations, and plans | Your computer or private VPS | The AI provider you select, only when relevant to the work you request | Until you change or delete it |
| Account identity and license status | Gravity Index account services and their authentication provider | Sign-in, account security, license checks, and support | While the account is active, then only as needed for security, legal, or support records |
| Payment and subscription records | Paddle or another named payment provider; GI keeps subscription status and transaction references | Checkout, tax, receipts, billing support, and fraud prevention | The periods required for accounting, tax, disputes, and applicable law |
| Service and security records | Gravity Index services and hosting providers | Reliability, abuse prevention, security, and support | Only as long as reasonably needed for those purposes or required by law |
You own the project content and data you create, import, connect, or store in Gravity Index. Gravity Index does not claim ownership of it. Your project store lives on your computer or private VPS, not in a Gravity Index project-data database.
If you connect a local folder, GI works within the projects, folders, and permissions you select. Connecting one folder does not grant access to your whole computer. A tool may read, edit, or send a file inside the connected work area when the task you request requires it.
Because project data is stored under your control, clearing app data, deleting the local store, removing a VPS, or uninstalling without a backup can delete it. Ending a trial, cancelling a subscription, or deleting a Gravity Index account does not itself delete project data stored on your computer or VPS.
When you use an AI feature, GI sends the selected provider the prompt, relevant project context, attachments, and tool output needed for that request. Each provider connection remains separate. The provider may keep or review requests under its own retention, safety, abuse-prevention, and training rules. Check the provider's policy before sending sensitive information.
Gravity Index may use a server to carry the request, stream the result, check account access, or coordinate a user-requested background action. That transport does not turn the request into stored Gravity Index project data.
We use account and service information to authenticate you, protect the service, check licenses, support billing, diagnose failures, prevent abuse, answer support requests, and meet legal obligations. Providing account information is required to create and operate an account. Providing project content is voluntary, but an AI feature cannot use content you do not choose or authorize it to process.
We do not sell personal information. We do not share project content for third-party advertising. We do not use private project content to train Gravity Index foundation models.
Private project content at rest is not browsable by Gravity Index because Gravity Index does not keep a copy of your project store. Human-visible content is limited to material you explicitly share with us, request-level material needed for support you request, security or abuse investigations, reliability debugging, or legal obligations. We do not inspect private project stores for curiosity, training, advertising, or general product research. Operational investigations rely on metadata and logs wherever possible rather than stored project content.
Gravity Index may process and store information in Israel and may transfer information to providers or infrastructure located in other countries, including the United States, the European Economic Area, and other jurisdictions where our providers operate. Where Israeli privacy law requires transfer safeguards for databases abroad, we rely on applicable legal permissions, provider commitments, contractual safeguards, and purpose-limited processing arrangements.
Gravity Index never adopts the login, model access, or credentials of another app or command-line tool. Each supported provider connection belongs to Gravity Index and is used only for that provider. Provider subscription fees, limits, and account rules are separate from the Gravity Index subscription.
You can delete your account and the account records Gravity Index holds from Settings or by contacting us. Deleting the account does not erase project data stored on your computer or private VPS. Security logs, support records, transaction records, provider-side records, and information required for legal, fraud-prevention, tax, or accounting purposes may remain for the necessary period.
Subject to applicable law, including the Israeli Privacy Protection Law, you may ask to review personal information about you held by Gravity Index, correct information that is inaccurate, incomplete, unclear, or outdated, or delete your account records. We may need to verify your identity. Project data stored on your own computer or VPS remains under your control and must be managed there.
To exercise privacy rights or ask questions about your data, contact connect@gravityindex.ai.
We use browser and Desktop storage for sign-in state, preferences, local project data, cache data, and interface state. We do not use third-party advertising cookies.
We use access controls, encrypted provider credentials, transport security, and operational monitoring to protect the service. No system is perfectly secure. You are responsible for protecting your devices, account credentials, connected local folders, and external provider keys. If a security incident requires notice to the Israeli Privacy Protection Authority, affected users, providers, or other parties, we will handle the incident according to applicable law and the facts known at the time.
Questions or data requests: connect@gravityindex.ai
This policy may be updated. We will note the effective date at the top.