Written to be read. Plain sections, no fine print buried at the bottom.
GYST is operated by GYST (SASU), 55 rue Saint-Louis en l'Île, 75004 Paris, France.
SIREN 939 814 182 · RCS Paris 939 814 182 · VAT FR12 939 814 182
Contact: hi@gyst.studio
GYST acts as the data controller for the personal data described in this Privacy Policy.
GYST is a visual workspace designed to help people capture, explore, organize and create from their ideas, information and digital content. It is available through its website, web application and mobile applications for iOS and Android.
This Privacy Policy explains how we collect, use, store and protect personal data when you interact with GYST.
GYST is currently in an early-stage testing and development phase. During this period we collect limited product usage information, including privacy-protected session recordings, to understand how people use the product, identify bugs and friction, and improve the experience.
Depending on how you use GYST, we may collect the following categories of information.
Name, email address, account ID, authentication provider (such as Google Sign-In) and account preferences.
We process the content you voluntarily create, save, upload or capture within GYST: notes and text, boards and canvases, pages, images, files and documents, links and bookmarks, websites and webpages, social media posts, videos and embedded content, tags, visual organization data, connections between content, and anything else you choose to add.
This content may contain personal data depending on what you choose to save. You remain responsible for the content you upload, save or create within GYST.
Payments are processed by Stripe. We may receive your billing email, billing country, subscription status and transaction or subscription identifiers. We do not store credit or debit card numbers.
For service operation, security and product improvement: IP address, browser and device type, operating system and version, app version, device identifiers, timestamps, usage logs, feature interactions, crash reports, error logs, diagnostics and performance data.
Device model, operating system version, app version, and photos, images or files you choose to upload from your device.
The mobile app only accesses your camera, photo library or files when you initiate an action that requires such access and grant the relevant permission. We do not access these features in the background unless required for a feature you have specifically enabled and permitted through your device settings.
If you sign in using Google, GYST accesses your Google account email address, basic profile name and Google account identifier through Google OAuth.
GYST does not access your Gmail content, Google Drive files, contacts or calendar data. Google account data is used solely to authenticate your account, create or link your GYST account, and provide secure login.
We use personal data only where necessary to operate, secure, understand and improve GYST: creating and maintaining accounts, providing the workspace, storing and displaying content you add, processing subscriptions, authenticating users, operating product features and providing customer support.
Also to improve functionality and usability, understand how users interact with GYST, diagnose technical problems, detect and fix bugs, monitor performance, develop and test new features, protect GYST against fraud, misuse and security threats, and comply with applicable legal obligations.
We do not sell personal data to advertisers, data brokers or other third parties.
GYST is currently in an early-stage testing phase, so understanding how people interact with the product matters a great deal to us. We use product analytics and session-recording technologies to identify usability issues and technical problems, and to improve the product.
Navigation between pages or boards, clicks and selections, scrolling, movement across the interface, opening or closing features, adding or moving elements, sequences of interactions, and technical errors or unexpected behaviour.
The purpose is to understand how users interact with GYST, not to review the substance of their private content.
We configure our session-recording tools to minimise the personal or private information visible in recordings. Where technically supported, content displayed within the workspace is masked, hidden, blurred or otherwise obscured before or during recording: text you enter or display, images and visual content, sensitive input fields, and other content that may reveal private information.
For example, a recording may show that a user added an image, moved an element or had difficulty using a feature, without requiring us to see the underlying private content. Session recordings should therefore be understood as privacy-protected recordings of interactions with the GYST interface, not recordings of your private workspace content.
Recordings and associated usage information are used only to understand product behaviour, identify usability problems, bugs and technical issues, evaluate functionality, find where users encounter friction, and improve the experience. They are never used for advertising or sold to third parties.
Recordings are retained for a maximum of 30 days, then deleted. We may keep aggregated or genuinely anonymised insights that can no longer reasonably be linked to an identifiable individual.
Access is restricted to authorised GYST team members and, where necessary, service providers acting on our behalf, limited to what is reasonably necessary. Questions or requests: hi@gyst.studio.
GYST may include features that let you interact with artificial intelligence using the context available in your workspace. When you intentionally use an AI-powered feature, we process what is necessary to provide it: the question or prompt you submit, information on the board, page or workspace you ask the AI to work with, and contextual information needed to generate the response.
Where GYST relies on third-party AI infrastructure or model providers, relevant information may be transmitted to those providers solely to process your request. We aim to limit what is shared to what is reasonably necessary, and we require appropriate contractual and data protection safeguards.
GYST does not use private workspace content to train its own general-purpose AI models.
Under the GDPR, we process personal data only where we have an appropriate legal basis.
Creating and maintaining your account, providing the service, storing and displaying your workspace content, processing subscriptions, providing features you request.
Securing GYST, preventing fraud and abuse, diagnosing bugs, monitoring performance, understanding how users interact with GYST, improving functionality and usability. We weigh the impact on users' rights and freedoms and implement safeguards to minimise it.
Where consent is required under applicable law for a particular technology or processing activity, we request it. You may withdraw your consent at any time.
Where necessary to comply with legal, accounting, tax or regulatory obligations.
GYST may use cookies, local storage and similar technologies to maintain sessions, authenticate users, remember preferences, secure the service, understand product performance and run product analytics.
Technologies strictly necessary for providing GYST may be used without consent where permitted by law. Where consent is legally required for analytics, session recording or other non-essential technologies, we request it before activating them. You can manage your preferences through the consent controls we make available.
We share personal data only where necessary to operate GYST or where required by law.
Payments are handled by Stripe, which processes the billing information needed to manage subscriptions and transactions.
Hosting and infrastructure rely on third-party providers. Where possible, user data is hosted within France or the European Union.
Product and technical services may include cloud infrastructure, databases and storage, authentication, product analytics, session recording, error monitoring, email communications, AI infrastructure and security. These providers may process data only as far as necessary to provide their services to GYST, under appropriate contractual and data protection obligations.
We may disclose personal data where required by law, a court order or a competent regulatory authority. We do not sell personal data to advertisers or data brokers.
We implement appropriate technical and organisational measures designed to protect personal data: encrypted connections using HTTPS, secure authentication, infrastructure access controls, restricted internal access, monitoring for suspicious activity, security and error monitoring, and appropriate safeguards for service providers.
No digital service can guarantee absolute security, but we work to maintain safeguards appropriate to the nature of the information we process and the associated risks.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected.
Where information must be retained for legal, accounting, security or dispute-resolution purposes, it may be kept for the period required by applicable law.
You may request deletion of your data at any time. Depending on the functionality available, you can delete individual content from GYST, delete your account through your account settings, or contact us at hi@gyst.studio.
Deleting your account removes the associated workspace content, uploaded files and personal information from our active systems within a reasonable timeframe, except where retention is legally required. Residual copies may temporarily remain in secure backups until those backups are automatically overwritten or deleted under our backup retention procedures.
Some of our service providers may process personal data outside the European Economic Area. Where that happens, we use appropriate safeguards as required by European data protection law.
Depending on the destination and provider, these may include an adequacy decision adopted by the European Commission, the EU-U.S. Data Privacy Framework where applicable, European Commission Standard Contractual Clauses, supplementary technical and organisational safeguards, or another lawful transfer mechanism recognised under the GDPR.
If the GDPR applies to you, you may have the right to:
Exercise these rights by contacting hi@gyst.studio. We may need to verify your identity before processing certain requests, and we handle them within the time limits set by applicable data protection law.
If you have concerns about how GYST processes your personal data, we encourage you to contact us first at hi@gyst.studio.
You also have the right to lodge a complaint with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), or with another competent European data protection authority where applicable.
GYST is not intended for children under the age of 16 unless a different minimum age applies under the laws of the relevant European Union Member State. We do not knowingly collect personal data from children who are not legally permitted to provide their own consent.
If you believe a child has provided personal data to GYST contrary to applicable law, contact us at hi@gyst.studio.
GYST is an evolving product, and our privacy practices may change as the service develops. We may update this policy to reflect changes to GYST, new product functionality, changes to our service providers or data-processing practices, and legal or regulatory requirements.
Where changes materially affect how we process personal data, we will take reasonable steps to inform users. The date at the top of this page indicates when the policy was most recently updated. The latest version is always available at gyst.studio/legal/privacy-policy.
For questions about this policy, GYST's privacy practices or your personal data:
GYST (SASU)
55 rue Saint-Louis en l'Île
75004 Paris, France
SIREN 939 814 182 · RCS Paris 939 814 182 · VAT FR12 939 814 182
hi@gyst.studio
Pick up your canvas where you left it.
New to GYST?
Start building your visual second brain.
Already have an account?
Each purpose is off unless you turn it on. No cookie is set before you save.
Session, security and load balancing. Required for GYST to work — exempt from consent under the ePrivacy directive.
Anonymised usage statistics so we can see which parts of GYST help and which get in the way.
Remembers your workspace layout, language and the tips you have already dismissed.
Measures which campaigns bring people to GYST. Never used to build advertising profiles.