gratavi
Effective October 4, 2026

Your words deserve care.

This policy describes Gratavi, operated by Jerry Crews (Nerdquad), and this website. Contact jerry@nerdquad.com with privacy questions or requests.

Personal journaling

Solo entries, drafts, and private reflections are stored on your device in an encrypted app store. No Gratavi account is needed for solo journaling. The encrypted local journal is excluded from automatic device backups because its storage key is bound to this device. Save an export before replacing or erasing your phone. Exports you choose to save or share are readable by their recipients and are no longer protected by the app’s encryption.

Optional sharing

Sign in with Apple establishes a sharing account. We store an account identifier, chosen display name, public encryption and signing keys, circle memberships, invitation records, submission dates, and encrypted shared entries. We process Apple authentication credentials to maintain and revoke access. We do not require an email address for sharing.

When you agree to the Terms and Privacy Policy for sharing, we store the policy versions and the server-recorded time of your agreement with your account. This receipt contains no journal text. An encrypted copy of the confirmed receipt is kept on your device.

Normal shared text is encrypted on your device for authorized circle members. The service stores encrypted text and key envelopes. It cannot ordinarily read that text. Your optional private reflection is never included in a shared entry. Metadata such as who belongs to a circle and when an entry was submitted remains visible to the service. Encryption does not prevent a recipient from copying what they can read.

If you enable optional iCloud Keychain sync in Settings, your sharing identity keys and recovery kit sync through Apple’s end-to-end encrypted iCloud Keychain to eligible devices using your Apple Account. This does not sync your separate local journal.

Safety reports

Safety screening runs on the device. Text is not sent to an AI service. If you explicitly report an entry, the selected plaintext and supporting evidence shown in the report preview are disclosed to the operator for review. We may restrict accounts, preserve relevant material, and disclose information when required by law or to respond to a valid legal request. Reports are not end-to-end encrypted from the operator. Report explanations, selected evidence, and operator decision notes are encrypted in server storage.

Notifications and essential operations

With permission, we use an Apple push token to send generic reminders or updates without journal text. We do not sell personal information, run ads, use tracking SDKs, or collect advertising identifiers. Essential network and security systems process IP addresses and request metadata; application logs are designed to exclude authorization tokens, invitation secrets, and entry bodies. This website uses no analytics or advertising cookies.

Service providers and location

Apple provides sign-in, notifications, and optional iCloud Keychain synchronization. Amazon Web Services hosts the sharing service and encrypted backups in the United States. Only data needed for these functions is processed. The app is initially offered in the US.

Retention and your choices

Local data remains until you delete it or remove the app. Shared account data remains while your account and entries are active, subject to operational limits. You can export your journal, delete entries, leave circles, and request account deletion in the app. Ending a circle removes its shared history for all members. Deleting your sharing account, including stopping Sign in with Apple, ends circles you own and removes your own shared entries. Your separate local journal remains on your device unless you delete it. Routine backups rotate after seven successful daily snapshots. Deletions may remain in backups until rotation; a restored service must reapply deletion records. Safety reports and their decision history are normally retained for 90 days from submission, including if an involved account is deleted. We remove deleted accounts’ direct identifiers from routine report records where possible while preserving the selected signed evidence. A documented preservation hold retains the relevant records until an operator releases it; after release, records remain until the later of their existing deadline or 30 days after release. Signed membership history and public-key metadata may remain in surviving circles to verify historical entries; it may include a former member’s display name. Previously downloaded copies held by recipients cannot be recalled.

Age and sensitive information

Gratavi is for people 13 and older and is not directed to children under 13. Do not create an account for someone under 13. Age and parental-control signals may restrict sharing. We do not request a full birth date or government ID. If you believe a child under 13 has provided data, contact us.

Security and changes

Encryption, access controls, limited content collection, and deletion tools reduce risk, but no system can guarantee absolute security. Keep your device and recovery kit safe. Material changes to this policy will be communicated in the app or on this page before they take effect when required.