Getrive

Privacy Policy

Last updated July 21, 2026

This page explains what personal data Getrive collects, why, under what legal basis, and who it's shared with — written to meet the UK/EU General Data Protection Regulation (GDPR)'s transparency requirements as well as plainly explain things. Getrive is the data controllerfor the data described below. It's currently operated by an individual founder, not yet through a registered company; contact details are at the bottom of this page.

Legal basis, at a glance

Each section below explains its own legal basis inline, next to the data it actually covers — this is just a quick index if you want the summary first:

  • Contract (Art. 6(1)(b)) — account & product data, verification/reset emails, your own product data sent to AI providers.
  • Legitimate interest (Art. 6(1)(f)) — public post content we process (see that section for the full balancing test), signal-alert/digest emails (with an opt-out).
  • Consent (Art. 6(1)(a)) — analytics cookies, the signup-attribution capture, both gated behind the cookie banner and withdrawable at any time.

Account & product data

We collect what you give us directly: your email, and, if you sign up with a password rather than Google, that password (hashed, never stored in plain text). If you sign in with Google, we receive your name, email, and profile picture from Google — nothing else from your Google account. Either way, we also collect the product details you enter (name, description, target customer, website URL, signup goal).

Legal basis:processing this is necessary to provide the account and product you've asked us to run (contract, GDPR Art. 6(1)(b)).

Public post content we process (Reddit, Hacker News & more)

To find relevant signals, Getrive fetches public post content from the channels you choose to monitor — Reddit subreddits (via Reddit's public RSS feeds), Hacker News (via its public API), IndieHackers (via a public feed), Stack Exchange sites (via the official public API), and Ask MetaFilter (via a public RSS feed). We only process publicly-visible posts — never private messages, DMs, or anything requiring a login to view.

This content was written by other people — Reddit users, Hacker News commenters, and so on — who are not Getrive account holders and haven't agreed to our terms. If that content includes personal data (a username, something identifying they chose to share publicly), we process it too, for as long as it takes to score relevance and, if you act on it, draft a reply.

Legal basis:legitimate interest (GDPR Art. 6(1)(f)) — the data was already made public by its author on a platform that itself makes it publicly accessible, we only use it for the narrow purpose of relevance scoring and reply drafting, we don't build profiles of individual authors across posts, and it isn't retained once that purpose is served. Because this content doesn't come from the author directly, GDPR Art. 14 would otherwise require notifying each one individually — we rely on the Art. 14(5)(b) exemption for cases where that would involve disproportionate effort (there's no practical way to contact every author of every post we score). If you're the author of a public post Getrive has processed and want to know what we hold or have it removed, contact us below and we'll act on it.

Third-party AI providers

Depending on what you're doing in Getrive, the following data is sent to third-party AI providers:

  • Anthropic(Claude) — your product description and target customer (to generate positioning statements and channel/subreddit suggestions), the scraped text of your own website if you use “Prefill from your website” during setup, and individual posts from any monitored channel (Reddit, Hacker News, IndieHackers, Stack Exchange, or Ask MetaFilter — to draft a suggested reply).
  • OpenAI (GPT) — individual posts from any monitored channel (Reddit, Hacker News, IndieHackers, Stack Exchange, or Ask MetaFilter), scored for relevance against your product description.

Both are US-based companies; sending data to them is an international transfer outside the UK/EEA under GDPR. Both process API data under their own published data-processing terms, which include contractual safeguards (Standard Contractual Clauses) covering exactly this kind of transfer, and neither uses API data to train their models by default. Each provider processes this data under its own API terms and privacy commitments; Getrive doesn't control their retention practices beyond what their API terms specify.

Legal basis:contract (Art. 6(1)(b)) for account holders' own product data; legitimate interest (Art. 6(1)(f)) for public post content, for the same reasons given above.

Emails we send

Account verification and password-reset emails are sent whenever you request them — necessary to run the account you asked for (contract, Art. 6(1)(b)). Instant signal alerts and the weekly digest are sent based on your own preference toggles in Settings > Notifications (“Instant signal alerts” and “Weekly digest”), on by default as part of delivering the product's core value (legitimate interest, Art. 6(1)(f)) — you can turn either off at any time from that page, and doing so takes effect immediately.

Cookies & similar technologies

On the public site, nothing beyond what's strictly necessary runs before you make a choice in the consent banner (powered by Silktide Consent Manager, an open-source tool that itself stores your choice in your browser's local storage, not a cookie). You can change your choice at any time via the “Cookie settings” link in the footer.

  • Necessary(always on, no consent required) — your signed-in session, and a small preference cookie remembering which results filter tab you last had open. Legal basis: necessary to provide the service you're using (Art. 6(1)(b)); exempt from consent under the ePrivacy rules as strictly necessary.
  • Analytics (off until you accept) — PostHog, described below. Legal basis: your consent (Art. 6(1)(a)), given or withdrawn in the banner.
  • Attribution (off until you accept) — the signup-attribution capture described below. Legal basis: your consent (Art. 6(1)(a)), given or withdrawn in the banner.

Product analytics

Getrive uses PostHog(hosted on PostHog's EU Cloud, based in the EU) to understand how the product is actually used — page views, clicks, scroll depth, and session recordings of your browsing and in-app activity, across both the public site and the logged-in product. This is how we find what's confusing or broken, rather than guessing. Session recordings automatically mask password fields. We never send PostHog your email, password, or full name as event data — only your internal account id and category-level properties (e.g. which button you clicked, which onboarding step you completed).

Website tracking (optional, your choice)

If you choose to use Getrive's attribution tools on your own website, one of two things happens, depending on which option you set up:

  • No-code redirect: we log that a signup occurred, with no visitor-level data beyond the timestamp and which project it belongs to.
  • Tracking snippet:a small script you paste onto your own site stores a randomly-generated visitor token in that visitor's browser (localStorage) to connect a signup back to the specific reply that brought them there. This token isn't linked to any other identifying information we collect.

If you use the tracking snippet, you — not Getrive — are responsible for your own site's compliance obligations (for example, cookie/tracking consent requirements that may apply in your visitors' jurisdictions). Getrive provides the mechanism; how and where you deploy it on your own property is your call.

Where your data is processed

Getrive is hosted on Vercel, with a Postgres database, both of which may process data outside the UK/EEA depending on region configuration. Combined with the AI providers above and our email provider (Resend), this means your data can be processed in the US as well as the UK/EEA. Where a provider is outside the UK/EEA, we rely on their own GDPR-compliant transfer mechanism (typically Standard Contractual Clauses) rather than transferring data on terms of our own.

Data security

Passwords are hashed, never stored in plain text. Sessions are signed and encrypted (Auth.js / NextAuth). Traffic to and from Getrive is encrypted in transit (HTTPS/TLS). No system is perfectly secure, but these are concrete, real measures, not a generic promise.

What we don't do

  • We never post, comment, DM, or send anything on your behalf — on Reddit, Hacker News, IndieHackers, Stack Exchange, Ask MetaFilter, or anywhere else.
  • We don't sell your data to anyone.
  • We don't process post content beyond what's needed to score relevance and draft replies.

Data retention & deletion

We keep your account and project data until you ask us to delete it. Archiving a project from its Settings page hides it from your project list but keeps its data intact and restorable; it is not deletion.

To permanently delete a single project or your entire account, email us at senkcsani@gmail.com. This is currently a manual process — there's no self-serve delete button yet — but every request is honored. Deletion is permanent and covers everything tied to the project or account: signals, scored post history, monitored sources, tracked links, and signup/attribution records. We don't retain any of this after deletion — Getrive has no billing or invoicing system that would require keeping records for legal reasons.

Your rights

If you're in the UK or EEA, GDPR gives you the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted (see Data retention & deletion above).
  • Restriction — ask us to limit how we use your data in specific circumstances.
  • Object — object to processing based on legitimate interest, including the public-post processing described above.
  • Portability — receive your data in a portable format (see the export option in Settings).
  • Withdraw consent — for anything based on consent (analytics, attribution), at any time via “Cookie settings” in the footer, with no effect on processing before withdrawal.
  • Lodge a complaint — with a data protection supervisory authority. Getrive is based in Hungary, so the lead authority is the NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság); if you're in the UK, you can instead complain to the ICO. We'd appreciate the chance to make it right first, but you're not required to contact us before complaining to either.

To exercise any of these, contact us below. We respond within one month of a verified request, as GDPR Art. 12(3) requires — extendable by a further two months for complex or numerous requests, in which case we'll tell you within the first month and explain why. This is currently a one-person operation, so we aim to respond well inside that window rather than up against it, but the one-month figure is the actual commitment, not an estimate.

Children's privacy

Getrive isn't intended for anyone under 16. We don't knowingly collect data from children; if you believe a child has created an account, contact us and we'll delete it.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the date at the top of this page.

Contact

Questions about this policy or your data: senkcsani@gmail.com