Privacy Policy
Last updated: 18 July 2026
This Privacy Policy explains what information Gisly collects, the legal bases and purposes for using it, who we share it with, how long we keep it, and the rights you have. Gisly is a contacts management application, so much of the data it holds is information you choose to add about other people.
1. Who we are and our role
Gisly ("we", "us", the "Service") is operated by the developer, who you can reach at nadeemzahid123123@gmail.com.
For your account information (your name, email, sign-in details), we act as the data controller. For the contact records and documents you add, you are the controller and we act as a data processor handling that data on your instructions. You are responsible for having a lawful basis to store information about the people in your contacts.
2. Information we collect
- Account information: your name, email address, and authentication details. Passwords are stored only in secure, hashed form by our authentication provider; if you use Google sign-in we receive your basic profile and profile image.
- Contact data you add: names, phone numbers, emails, employers, job history, education, notes, and any other details you enter or import about your contacts.
- Uploaded documents: business cards, resumes, and other files you upload for scanning.
- Billing information: if you buy a paid plan, billing name, contact details, and payment references (card details are handled by our payment processor, not stored by us).
- Usage and technical data: basic information needed to operate the Service securely and reliably.
3. Legal bases for processing (GDPR)
Where the EU/UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to create your account and provide the Service you asked for.
- Legitimate interests — to operate, secure, and improve the Service and prevent abuse, balanced against your rights.
- Legal obligation — to comply with laws that apply to us.
- Consent — where we ask for it. For the contacts you add, you are responsible for the lawful basis (such as your own legitimate interest or consent).
4. How we use information
- provide, maintain, and improve the Service;
- read uploaded documents and pre-fill contact details for you;
- process subscriptions and payments;
- keep the Service secure and prevent abuse;
- respond to your requests and communicate about the Service.
5. We do not sell or share your personal information
We do not sell your personal information or the contact data you store, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) and similar U.S. state laws. We have not sold or shared personal information in this sense. We do not use your data or your contacts to serve advertising.
6. Document scanning and AI processing
When you upload a business card or resume, its contents are processed to extract contact details. This involves automated text recognition and, where enabled, an AI model provided by Google (Gemini API) acting as our processor. Uploaded files and extracted text are used only to provide this feature to you, are not used to train third-party models, and this processing may occur on servers located in the United States. Automated extraction can make mistakes; please review results before relying on them.
7. Service providers (sub-processors)
We share information only with providers who help us run the Service:
- Supabase — database, hosting, and authentication (data stored in the Asia Pacific / India region).
- Vercel — application hosting and delivery.
- Google (Gemini API) — AI-assisted document extraction (United States).
- Stripe — payment processing for paid plans, if and when you purchase one.
These providers process data on our behalf under appropriate contractual obligations. We may also disclose information if required by law or to protect our rights.
8. International data transfers
Your information is stored and processed in India (our database region) and may be processed in the United States (for AI extraction and hosting). If you are in the European Economic Area, the UK, or another region with data-transfer rules, these are international transfers. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses with our providers. Contact us for more information about these safeguards.
9. About the contacts you add
The people in your contact records are "data subjects" whose information you control. You are responsible for having the right to store their data and, where the law requires, for informing them. If one of your contacts asks us to access or delete their information, we will generally direct them to you as the controller, and we will assist you in responding. Anyone who believes their data is held in Gisly may contact us at nadeemzahid123123@gmail.com and we will route the request appropriately.
10. Who added what
Within a workspace, we record which user created or last updated a contact. We use this only to manage editing permissions and accountability inside your own workspace. We do not sell this information, use it to build profiles of you, or share it for advertising.
11. Data retention and deletion
We keep your information for as long as your account is active or as needed to provide the Service. You can delete individual contacts and content at any time, and an admin can delete the entire workspace from Settings.
When an account is deleted, we permanently remove its contacts, companies, teams, files, and user logins. We retain only anonymized statistics (such as counts and coarse industry/country, with no names, emails, phone numbers, notes, or addresses), which cannot be used to identify anyone, for our own analytics. We may retain limited records where we must to comply with legal obligations (for example, billing records).
12. Security and breach notification
Your data is transmitted over encrypted connections and stored with our infrastructure providers. We take reasonable technical and organizational measures to protect it, but no method of storage or transmission is completely secure, so we cannot guarantee absolute security. If a data breach affects your personal information, we will notify you and any relevant authority where required by law.
13. Your privacy rights
Depending on where you live, you may have rights to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete your information ("right to erasure");
- restrict or object to certain processing;
- receive a copy of your data in a portable format;
- for California residents: know, delete, correct, and opt out of any sale/share (we do not sell or share), without discrimination for exercising these rights.
You can manage most of your data directly in the app. To make a formal request, or to appoint an authorized agent, contact us at nadeemzahid123123@gmail.com. EEA/UK users also have the right to complain to their local data protection authority.
14. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, please contact us so we can remove it.
15. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above. We encourage you to review this page periodically.
16. Contact
For privacy questions or to exercise your rights, contact the developer at nadeemzahid123123@gmail.com.
Contact
Questions about this page? Reach the developer at nadeemzahid123123@gmail.com.