Privacy Policy
Last updated: 5 September 2026
The short version
Grafida — the app — collects nothing. No analytics, no tracking, no telemetry, no crash reporting, no account. It does not talk to us at all. We could not tell you how many articles you have written, or whether you have ever opened the app, because the app never tells us, and we run no server for it to tell.
This website is a static site. It collects nothing beyond the standard access logs.
Who we are
The data controller is:
Akeeba Ltd, Kantaras 37E, 2043 Strovolos, Nicosia, CYPRUS.
Company registration HE307966
Our Data Protection Officer can be reached by email at nicholas αt akeeba dοt cοm.
No data collection in the applications
Grafida for iPhone and iPad, Grafida for Android, and Grafida Desktop collect no information whatsoever.
The applications contain no analytics, tracking, telemetry, advertising, crash reporting, licence checks, activation calls, or any other mechanism that reports anything to us. Neither requires an account. Neither has a sign-in screen. We do not operate a server that either application communicates with.
Your articles, your drafts, your images, and your site credentials are stored on your device. Credentials are stored in the operating system's secure store. Your content itself is stored in plain text on the device and is not encrypted by us; the device's own disk encryption – if enabled – is what protects it.
Both Grafida application implementations are Free and Open Source Software. You can inspect the code yourself.
What the apps do connect to
Grafida is a tool for editing articles on a Joomla site. As a result, it makes network connections. Every one of them goes somewhere you chose:
- Your own Joomla! site. The address, and the API token, are ones you entered. This is the entire point of the application.
- An AI provider you configured, if you chose to configure one. See the AI features section below.
- huggingface.co and its content delivery hosts, but only at the moment you tap Download on a local AI model. If you never download one, the app never contacts them.
- Hosts named by your own site's content. If your site's favicon lives on a CDN, if the stylesheet Grafida borrows to preview your articles pulls a webfont, or if one of your articles contains an image hosted elsewhere, then displaying those things fetches them from wherever your site says they are. Grafida does not choose those addresses. Your site does.
AI features
The AI assistant is optional. It sits unconfigured and inactive by default. You can choose to disable it completely, in which case the feature disappears from the app – and is forcibly disallowed from making any network connections – rather than merely being hidden.
If you configure a hosted AI provider, using the assistant sends your article's text, and possibly its images, to that provider. That is a transfer to a third party you have chosen and that we have no part in. It is governed by that provider's own privacy policy and terms, not by ours. We never see it, we never receive a copy, and we have no relationship with the provider on your behalf. The API key you enter is stored in your device's secure store and is sent to nobody but that provider.
If you instead use on-device inference, nothing leaves your device using the assistant. This is the option we recommend, and it exists precisely so that confidential drafts need never be transmitted anywhere.
Marketplaces
You can obtain the app through the App Store (iPhone, iPad), or through GitHub (Windows, Linux, macOS, Android). These downloads are governed by the privacy policies and terms of service of the respective marketplace.
We do not receive your information when you download our software. Apple and Google give us only aggregate download reports — numbers by country, by day, by device type — which identify nobody. GitHub only provides the total number of downloads for each file; this identifies nobody.
This website
The grafida.app site is a static HTML site. It does not require an account and sets no cookies.
Our web server keeps logs, as every web server does. These record the IP address, the browser's User Agent string, and the addresses requested. We keep them to keep the site running and to identify abuse, and for no other purpose. We do not use them to build a profile of you, and we do not sell, rent or share them.
We do not use third-party analytics on this site.
Support requests, and who's responsible for them
We handle support through GitHub Issues, on our own two repositories. That means two different parties end up touching your data, for two different reasons:
- GitHub is responsible for your GitHub account: signing up, logging in, and whatever GitHub itself does with that on their end. That is covered by GitHub's own privacy policy, not this one. We have no data processing agreement with GitHub, no way to instruct them, and no visibility into anything beyond what you post publicly on the issue.
- We are responsible for what happens to the issue itself, once you post it: we read it, we may reply to it, and we use whatever you told us to help you. You are giving us that information for a specific reason you chose — asking for support — which is the "Consent" basis described below.
So yes, opening a GitHub issue does involve processing of personal data, split between GitHub (the account/platform side) and us (the "read your ticket and help you" side).
Whether you have to give us anything
You can read this site, download Grafida, and use either application indefinitely without ever giving us anything.
When you request support, we will need to ask you for a reasonable amount of information necessary to help you with your issue. You are free to decline providing that information, understanding we might be objectively unable to provide further assistance.
Our legal basis for processing
Neither the apps nor this website process personally identifiable information (PII). Explicitly, the IP address in the log files is not PII as it's not tied to a real or pseudonymous identity – it's completely anonymous.
The one exception is support: if you contact us, whatever you choose to tell us in that ticket is personal data, and we do process it.
When submitting GitHub issues, pull requests, or you otherwise choose to contact us, the legal basis of processing is Consent, where we ask for it explicitly, or you implicitly provide when initiating contact with a specific request which objectively requires us to process your information. You may withdraw consent at any time; doing so does not make what we did beforehand unlawful.
Who else sees your data
| Recipient | What they see | Why |
|---|---|---|
| Our hosting provider | Whatever is on the server, as any host can | To host the site |
We share your data with no other recipient. We do not sell it, rent it, trade it, or transfer it for anyone else's marketing.
GitHub isn't in this table, because we don't send them anything — you interact with GitHub directly, under GitHub's own privacy policy, whether that's downloading the app or opening a support issue. See "Support requests" above for how that responsibility is split.
Note that Apple and Google are not in this table either. Apple and Google make the app available to you; Apple and Google do not pass us anything about you, and we pass Apple and Google nothing.
Transfers outside the EEA
Your data is processed in the European Economic Area. If any processor we use is located outside it, that transfer will be covered by the safeguards required under Article 46 of the GDPR.
Automated decision-making and profiling
We don't do that.
Marketing
We do not run personalised marketing campaigns, and we do not use your personal data to target advertising. We don't even collect your personal information to begin with.
How long we keep things
| Data | Kept for |
|---|---|
| Web server and security logs | 14 months |
Your rights
Your data rights concern personally identifiable information (PII). None of that is collected by our applications or this website.
If you've contacted us for support, you can ask to see, correct, or have us delete whatever you sent us — just get in touch and tell us which issue it was.
PII held by GitHub itself — your account, your GitHub-side activity — is subject to GitHub's own privacy policy, not ours.
Complaints
If you think we have handled your data despite not collecting anything, please tell us first — most problems are a misunderstanding, and we would rather fix it than have it adjudicated.
You also have the right to complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus. You may also complain to the authority in your own country of residence.
Cookies
We do not use any cookies.
Changes to this policy
When we change this policy we will change the date at the top and add a line to the changelog below. We have no way of notifying you individually, so the changelog is the record.
Changelog
- 7 September 2026 — first version.