Privacy Policy
Last updated: 23 September 2026
Grapple is a paid product, so we make money by selling software rather than by learning about you. This policy says exactly what we hold, why we hold it, who else touches it and how to get rid of it. It is short because there genuinely is not much.
The short version
- We count page views on this website, and nothing more. No cookies, no advertising tags, no session recording, no profiling, and nothing that follows you to other websites. There is no analytics of any kind in the app.
- The Free plan needs no account, and the app does not phone home about what you play.
- If you buy Pro, we hold your email address, your licence key, which Macs it is activated on, and whether your subscription is paid up. That is the lot.
- We never see your card number, we never sell or rent personal data, and we do not use it for advertising.
- There is no cookie banner because we set no cookies except the three that keep you signed in, and page-view counting uses none.
Counting page views
We use Vercel Web Analytics to count how many people visit each page, which website sent them, and roughly which country and kind of device they came from. We do it to know whether anyone is finding Grapple and which pages confuse people, which is the difference between improving the site and guessing at it.
It sets no cookies and does not identify you. It does not follow you to other websites, and it cannot: the counter is served from getgrapple.io, not from a third party's domain, so no other site ever learns that you were here. Vercel processes the data on our behalf and does not use it for its own purposes or share it with anyone. Nothing is sold, and no advertising is built on it.
The legal basis is our legitimate interest (Article 6(1)(f) GDPR) in understanding whether the website works. Because no cookie or similar device is read or written on your machine, no consent banner is required. If you block it with an extension or a privacy browser, the site works exactly the same and we simply do not count that visit.
None of this runs in the Grapple app. The app counts nothing.
Who is responsible for your data
The controller of your personal data, in the sense of the GDPR, is:
Grapple is sold by a company registered in the Netherlands with the Chamber of Commerce and registered for VAT. For our registered name, address, Chamber of Commerce (KvK) number and VAT number, email support@getgrapple.io and we will send them to you.
For anything in this policy, including access and deletion requests, write to support@getgrapple.io.
What we collect, and why
If you only use the Free plan
Nothing. The Free plan needs no account and no licence key, and with no licence key the app makes no licence request to us at all. It does not report which games you have, which ones you launch, or how they ran. Your games, your Windows environments and their settings stay on your Mac.
Two ordinary internet requests still happen, and you should know about them:
- Update checks. Once a day the app asks our server whether a newer version of Grapple exists. That request carries your IP address and the version you are running, like any web request. It does not carry anything about your Mac or your games, and we do not build a profile from it. You can switch automatic checks off in Settings → General → Updates.
- Downloads. Grapple, its engine and its graphics components are downloaded from GitHub Releases, so GitHub sees your IP address when you download them, under GitHub's own privacy statement.
If you create an account
- Your email address — required. It identifies your account and is how we send password resets and service notices.
- Your name — optional, only if you type one.
- Your password, as an Argon2id hash. We never store or see the password itself, and a hash cannot be turned back into it.
- When the account was created and last changed, and an internal counter we bump on a password reset so that old sign-ins stop working.
- Password reset requests — we store a hash of the reset link's token and the time it expires, which is one hour after you ask.
Legal basis: performing our contract with you (Article 6(1)(b) GDPR).
Your licence and the Macs you use it on
- Your licence key (the
GRPL-…code), and when it was created or last regenerated. - For each activated Mac: a random identifier the app generates on that Mac, the name of the Mac as it is set in macOS (this often contains your first name, because macOS suggests one), when it was activated, and when it last checked in. Nothing else about the machine — no serial number, no hardware details, no list of software.
We need this to enforce the 3-Mac limit that Pro is sold with, and to let you free up a slot yourself. Legal basis: performing our contract with you (Article 6(1)(b)).
Your subscription
Stripe takes the payment; we keep a mirror of the result so the app knows whether you are on Pro. That mirror holds your Stripe customer and subscription identifiers, which price you are on, whether it is monthly or yearly, the status (active, past due, cancelled and so on), the date the current period ends, whether a cancellation is scheduled, and the date any cancellation took effect.
We do not store your card number, card brand, expiry date or billing address. Those live with Stripe, which also collects the country and address details it needs to charge the right VAT, and a business VAT number if you give one. You can see and change them in Manage billing on your account page, which opens Stripe's own portal.
Legal basis: performing our contract with you (Article 6(1)(b)) and, for the invoice and tax records, our legal obligation to keep them (Article 6(1)(c)).
Server logs and abuse prevention
Like every web server, ours sees the IP address of each request. We use it to rate-limit sign-ins, sign-ups, password resets and licence checks so that nobody can brute-force an account. To make that work across servers we keep a counter row in our database whose key contains the IP address (or, for per-account limits, the email address or licence key being tried), a count and an expiry time. Nothing else is recorded — no page, no time of visit beyond the expiry. The counters expire within minutes and the rows are deleted about an hour later. Our hosting provider also keeps short-lived request logs for operating the service.
Legal basis: our legitimate interest in keeping accounts and systems secure (Article 6(1)(f)). We think you have the same interest.
What we deliberately do not do
- No advertising, no advertising tags, no profiling, no A/B testing, no heat-mapping and no session recording.
- No product telemetry or crash reporting in the app: Grapple does not report what you play, what you install or how often you open it. Diagnostics are only ever sent when you use Report a problem yourself, and you send that file by email.
- No third-party scripts. Even the fonts are served from our own domain, so opening a Grapple page tells Google nothing, and the page-view counter is served from getgrapple.io rather than someone else's domain.
- No advertising, no ad networks, no data brokers. We never sell, rent or share personal data for anyone else's marketing.
- No marketing emails unless you ask for them. The only email we send is about your own account.
- No automated decision-making or profiling that has legal or similarly significant effects on you.
Cookies
We set three cookies, all strictly necessary, and only once you sign in or start signing in:
- A session cookie that keeps you logged in. It is HttpOnly, SameSite=Lax, and lasts up to 30 days or until you sign out.
- A CSRF token that stops another website submitting forms as you.
- A short-lived callback cookie that remembers which page to send you back to after signing in.
None of them tracks you, none is shared, and none needs consent under the ePrivacy rules — which is why you have not been asked to click anything.
Who else processes your data
We keep the list of suppliers short on purpose. Each one is a processor acting on our instructions under a data processing agreement.
- Stripe (Stripe Payments Europe Ltd, Ireland, with Stripe, Inc. in the United States) — payments, invoicing and VAT calculation. Stripe is the controller for its own payment and fraud-prevention purposes; see its privacy policy.
- Neon — the database that holds your account, licence and subscription records. Our database runs in Neon's EU region in Frankfurt, Germany.
- Vercel — hosting and content delivery for this website and its API.
- Resend — sending transactional email such as password resets. It handles your email address and the contents of that message.
- GitHub — hosting the download files. GitHub sees your IP address when you download Grapple or its engine.
Your account data is stored in the EU. Some of these suppliers are part of United States groups, so support and operations staff there may be able to access data. Those transfers are covered by the European Commission's standard contractual clauses and, where the supplier is certified, by the EU–US Data Privacy Framework.
How long we keep it
- Account, licence and device records — for as long as your account exists. Ask us to delete the account and they go immediately; copies in our database provider's backups fall out within 30 days.
- Device activations — until you remove that Mac from your account page, or the account is deleted.
- Password reset tokens — one hour, then they are dead whether used or not.
- Invoices and payment records — 7 years. Dutch tax law requires it, so this is the one thing we cannot delete on request. They are held by Stripe.
- Server logs — a short period at our hosting provider, never longer than 30 days.
- Rate-limiting counters — the counter expires within minutes and the row is deleted about an hour later.
Your rights, and how to use them
Under the GDPR you can ask us to:
- tell you what we hold about you, and give you a copy (access);
- correct anything wrong (rectification);
- delete it (erasure) — for us that means deleting your account, which removes everything except the invoice records we are legally required to keep;
- stop using it for a while, while a dispute is sorted out (restriction);
- hand you the data you gave us in a machine-readable file, or send it to someone else (portability);
- stop processing based on our legitimate interests (objection).
How: email support@getgrapple.io from the address on your account, or from any address if you tell us which account you mean. There is no form and no fee. We reply within one month, and usually within a few days. If a request is complicated we may take up to two further months, and we will tell you if so.
If you think we have got it wrong, please tell us first — but you always have the right to complain to a supervisory authority. Ours is the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. You can also complain to the authority in the EU country where you live or work.
Security
Passwords are stored as Argon2id hashes with parameters following current OWASP guidance, never as text. Sessions use HttpOnly cookies and are invalidated everywhere when you reset your password. Sign-ins, sign-ups, resets and licence checks are rate-limited. Everything travels over HTTPS. Card data never reaches our servers.
Children
Grapple accounts are for people aged 16 and over. We do not knowingly collect data about younger children; if you believe we have, email us and we will delete it.
Changes to this policy
If we change what we collect or who processes it, we will update this page and change the date at the top. If the change matters to you, we will email account holders before it takes effect. In particular: if we ever add anything that tracks you between websites, or any analytics inside the app, we will say so here in plain words first — and we have no plans to.
See also our Terms of Service and our Refunds & withdrawal policy.