GrupyLast updated: July 30, 2026.
Grupy only processes information needed to provide its group, communication, activity and payment features. This includes account and contact details, group memberships, content users choose to share, device push tokens, optional photos and videos, and precise location only while a user actively shares their live location. Grupy does not sell personal data or use it for cross-service advertising or tracking.
Information is processed to provide and secure the service, prevent misuse, handle reports and appeals, carry out users’ payment requests and meet legal obligations. Stripe, Apple, Google and Firebase process the information required for their respective payment, sign-in, hosting, push and integrity services.
Content is generally visible to members of the relevant group or conversation. Public groups expose only an edited group summary. Reports, evidence, moderation cases and audit trails are available only to explicitly authorised roles.
Users can edit profile details and delete their account in the app. Account deletion anonymises shared history and deletes private account, membership and Firebase sign-in data. Deletion may be delayed by an active report, moderation case or legal hold. Users may request access or data portability through the support channel listed on the app’s store page.
Data is kept according to a defined deletion schedule. Live location data is deleted shortly after it expires. Rate-limit data expires automatically. Payment, audit and security data is retained longer when accounting, fraud-prevention or legal requirements make that necessary.
Grupy uses access control, server validation, App Check, encrypted transport, restricted file types, size limits, separation of roles, audit trails and legal holds. No service can guarantee absolute security; suspected misuse or security incidents should be reported through the support channel.
Material changes will be announced in the app or on this page.