Gabyly is designed around European (GDPR) and US (CCPA) privacy principles from the ground up. Rather than bolting compliance on afterwards, we built the product so that data minimisation, transparency and your right to erasure are the default behaviour. This page summarises how those principles map onto how Gabyly actually works.
We process your personal data on two lawful bases: your consent, and the necessity of delivering the service you asked for. When consent is the basis, for example, remembering optional preferences, you give it freely and can withdraw it at any time without affecting the lawfulness of earlier processing. We never bury consent in pre-ticked boxes.
The right to be forgotten is built into the product rather than hidden in a form. Every memory carries an expiry timer you set, and a one-tap erase removes it immediately. Deleting your account removes your personal data and stored media from our systems. Because shared memories are end-to-end encrypted, expiry effectively renders any residual data unreadable as well.
We collect only what is necessary to keep your shares secure and to show you how many times they were opened. We do not request a phone number, a date of birth, or any data unrelated to the service, we do not record the identity or location of the people who open your links, and we do not enrich your profile with information bought from data brokers.
You can exercise your rights of access, rectification, restriction, portability and objection directly from your account, or by contacting us. You can export your data at any time, and you always have the right to lodge a complaint with your national supervisory authority if you believe your rights have not been respected.
EU data stays in the EU when you choose European storage. Where any limited cross-border processing is necessary, for example with a sub-processor, we apply appropriate safeguards such as standard contractual clauses to keep your data protected to European standards.
We work with a small number of vetted sub-processors for hosting, payments and email, each bound by data-protection agreements. Combined with end-to-end encryption, encrypted connections and hashed passwords, this keeps the amount of readable personal data we ever hold to an absolute minimum.
We work with a small number of vetted providers, each bound by a data-processing agreement (and, where relevant, EU standard contractual clauses). We only ever share the minimum data required, and your shared media stays end-to-end encrypted throughout, so these providers never receive readable photos or videos.
| Provider | Purpose | Location |
|---|---|---|
| OVHcloud | Encrypted media storage & hosting | EU (France / Europe) |
| MongoDB | Application database | EU region |
| Stripe | Payment processing | EU (Ireland) · DPF |
| Resend | Transactional email | US · SCCs / DPF |
| Sign-in & privacy-safe analytics | EU-US DPF | |
| Cloudflare | CDN, DNS & security | Global · DPF |
Last updated: 8/5/2026. Questions? privacy@gabyly.com
Gabyly uses only what it needs to work, plus optional functional storage to remember your preferences. We never use advertising or tracking cookies. Read our cookie policy