Back to Grein

Privacy

Grein is a drawing tool, not an advertising business. Everything you design is rendered on your own machine. This page says exactly what does leave it, and what happens to it.

Last updated

Who is responsible

The controller for the personal data described here is:

HMT Eskeland
Steinborgveien 44
0678 Oslo
Norway
Org. no. 922 045 259
hello@konturdesign.no

Write to that address for anything on this page, including any of the rights listed below. We answer within 30 days.

The short version

  • Your gradients are rendered and stored in your own browser. We never receive them unless you sign in and choose to save a look.
  • Without an account we collect no personal data at all, and set no cookies.
  • With an account we hold your email address, your plan, and the looks you saved.
  • There is no analytics, no tracking pixel, no advertising and no profiling.
  • We do not sell or share personal data, and we never will.

What we collect, and why

DataWhyLegal basisKept for
Email addressTo create your account and send the sign-in link. It is the only credential; there is no password.Performance of a contractUntil you delete the account
Plan and subscription statusTo know whether your exports carry a watermark and which sizes are unlocked.Performance of a contractUntil you delete the account
Saved looksOnly if you sign in and save one, so it follows you between machines.Performance of a contractUntil you delete them or the account
Server and delivery logsWritten by our hosting provider. They contain IP addresses and are used to keep the service up and to stop abuse.Legitimate interest in a working, secure serviceAbout 30 days
Purchase recordsHeld by our payment provider as the seller of record, and by us as the invoice trail behind your plan.Legal obligation (accounting)5 years, as Norwegian bookkeeping law requires

We do not ask for your name, address or card details. If you buy Pro, the card details go straight to the payment provider and never touch our servers.

Cookies

Grein sets no cookies until you sign in, and it has no analytics or advertising cookies at all. That is why there is no consent banner: the only cookies we use are the ones strictly necessary to keep you signed in, which under the ePrivacy rules do not require consent.

CookiePurposeLifetime
sb-…-auth-tokenKeeps you signed in. Set by our authentication provider, readable only by the server.Up to 1 year, refreshed while you use the site

Separately, the editor keeps your current document and your interface preferences in your browser’s own storage. That never leaves your machine, and clearing site data removes it.

Who processes it for us

We use as few providers as the service allows. Each acts as a processor under a data processing agreement, or as an independent controller where noted.

ProviderRoleWhere
SupabaseDatabase and authentication. Holds your email address, plan and saved looks, and sends the sign-in link.European Union
VercelHosting and content delivery. Processes requests and writes short-lived logs.European Union, with United States support access under standard contractual clauses
PolarPayments, as merchant of record and independent controller of the purchase. Handles card details, invoices and VAT.See Polar’s own privacy notice

Fonts are served from our own domain, so no font provider learns you visited. There is no third-party script on any page.

Your rights

Under the GDPR you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct anything that is wrong;
  • delete your account and everything attached to it;
  • export your data in a portable format;
  • restrict or object to processing based on legitimate interest.

Email hello@konturdesign.no and we will act on it. There is no charge, and we will not ask why. If you think we have handled your data badly you can complain to Datatilsynet, the Norwegian data protection authority.

Security

Everything is served over HTTPS. Sign-in tokens are stored in cookies your browser will not expose to scripts. Access to the database is restricted per row, so one account cannot read another’s data even if the application were tricked into trying.

Children

Grein is not aimed at children, and we do not knowingly create accounts for anyone under 13. If you believe a child has an account, write to us and we will remove it.

Changes

If this notice changes in a way that affects you, we will say so on this page and, where the change is significant, by email. The date at the top always reflects the current wording.

See also the terms of service.