Privacy Policy
Effective: 1 July 2026 · Operated by GrittyDigital LTD
GrittyDigital LTD ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what information we collect when you use Situo ("Service"), how we use it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
GrittyDigital LTD is the data controller for your personal data. If you have any questions or concerns, contact our privacy team at support@grittydigital.com.
2. Information We Collect
We collect the following categories of personal data:
Account information
When you sign in via Google or Apple, we receive your name, email address, and profile picture from that provider. We do not receive or store your social account password.
Usage data
We collect information about how you interact with the Service — lessons accessed, lessons completed, audio playback activity, AI chat queries, and feature usage. This helps us improve the product and personalise your experience.
User-generated content
Custom lesson requests and inputs you provide (such as situation descriptions) are stored to generate and deliver your lessons.
Subscription and billing data
Payments are processed entirely by Apple App Store or Google Play. We do not store your payment card details. We do receive confirmation of your subscription status and transaction identifiers.
Device and technical data
We collect device type, operating system, app version, IP address (used only for security and fraud prevention), and crash/error logs to maintain service quality.
Communications
If you contact us by email or in-app, we retain those communications to resolve your query and improve our support.
3. Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract performance — to provide the Service you have subscribed to, including generating and delivering lessons.
- Legitimate interests — to improve the Service, ensure security, prevent fraud, and communicate service-related updates.
- Legal obligation — where required to comply with applicable law.
- Consent — for any marketing communications (you can withdraw consent at any time).
4. How We Use Your Information
- To create and manage your account
- To generate, deliver, and personalise your lessons
- To process and manage your subscription
- To provide AI-assisted features (e.g. Lesson AI chat)
- To send service-related notifications (e.g. new lesson releases, account updates)
- To respond to your support queries
- To monitor and improve the performance and security of the Service
- To comply with legal obligations
We will never sell your personal data to third parties.
5. AI and Third-Party Processing
Some features of the Service (including lesson generation and the AI chat assistant) are powered by third-party AI providers. When you use these features, relevant input data is sent to those providers solely to generate your response. We select providers who maintain appropriate data protection standards and process data only on our instructions.
We do not use your personal data to train third-party AI models unless you explicitly consent.
6. Data Sharing
We share your data only with:
- Service providers — hosting, analytics, AI providers, and customer support tools acting as data processors under our instruction.
- Authentication providers — Apple and Google, when you use their sign-in services.
- Payment platforms — Apple App Store and Google Play, to process your subscription.
- Legal authorities — where required by law, court order, or to protect the safety of our users.
7. International Data Transfers
Some of our service providers are located outside the UK. Where we transfer data internationally, we ensure appropriate safeguards are in place (such as UK adequacy decisions or Standard Contractual Clauses) in accordance with UK GDPR.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes (typically up to 7 years for financial records).
9. Cookies and Tracking
Our website uses cookies and similar technologies for:
- Essential cookies — required for the website to function (e.g. authentication state).
- Analytics cookies — to understand how visitors use our site (e.g. page views, session duration). These are anonymised where possible.
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect your ability to use the Service.
10. Your Rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
- Restriction — ask us to restrict processing of your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, contact us at support@grittydigital.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
11. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
12. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encrypted data transmission (TLS), access controls, and regular security reviews. However, no method of transmission over the internet is 100% secure.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification before they take effect. The updated policy will always be available at this URL with the revised effective date.
14. Contact Us
For any privacy-related queries, data subject requests, or complaints, contact us at:
GrittyDigital LTD
support@grittydigital.com
