Back to home

GDPR & Compliance

Gabyly is designed around European (GDPR) and US (CCPA) privacy principles from the ground up. Rather than bolting compliance on afterwards, we built the product so that data minimisation, transparency and your right to erasure are the default behaviour. This page summarises how those principles map onto how Gabyly actually works.

Lawful basis & consent

We process your personal data on two lawful bases: your consent, and the necessity of delivering the service you asked for. When consent is the basis, for example, remembering optional preferences, you give it freely and can withdraw it at any time without affecting the lawfulness of earlier processing. We never bury consent in pre-ticked boxes.

Article 17, Right to erasure

The right to be forgotten is built into the product rather than hidden in a form. Every memory carries an expiry timer you set, and a one-tap erase removes it immediately. Deleting your account removes your personal data and stored media from our systems. Because shared memories are end-to-end encrypted, expiry effectively renders any residual data unreadable as well.

Data minimisation

We collect only what is necessary to keep your shares secure and to show you how many times they were opened. We do not request a phone number, a date of birth, or any data unrelated to the service, we do not record the identity or location of the people who open your links, and we do not enrich your profile with information bought from data brokers.

Your data subject rights

You can exercise your rights of access, rectification, restriction, portability and objection directly from your account, or by contacting us. You can export your data at any time, and you always have the right to lodge a complaint with your national supervisory authority if you believe your rights have not been respected.

International transfers

EU data stays in the EU when you choose European storage. Where any limited cross-border processing is necessary, for example with a sub-processor, we apply appropriate safeguards such as standard contractual clauses to keep your data protected to European standards.

Sub-processors & security

We work with a small number of vetted sub-processors for hosting, payments and email, each bound by data-protection agreements. Combined with end-to-end encryption, encrypted connections and hashed passwords, this keeps the amount of readable personal data we ever hold to an absolute minimum.

Our sub-processors

We work with a small number of vetted providers, each bound by a data-processing agreement (and, where relevant, EU standard contractual clauses). We only ever share the minimum data required, and your shared media stays end-to-end encrypted throughout, so these providers never receive readable photos or videos.

ProviderPurposeLocation
OVHcloudEncrypted media storage & hostingEU (France / Europe)
MongoDBApplication databaseEU region
StripePayment processingEU (Ireland) · DPF
ResendTransactional emailUS · SCCs / DPF
GoogleSign-in & privacy-safe analyticsEU-US DPF
CloudflareCDN, DNS & securityGlobal · DPF

Last updated: 8/5/2026. Questions? privacy@gabyly.com

Your privacy, your choice

Gabyly uses only what it needs to work, plus optional functional storage to remember your preferences. We never use advertising or tracking cookies. Read our cookie policy