Privacy Policy

Last updated: September 1, 2026

Great In Nature ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why, on what legal basis, how long we keep it, and the rights you have over it. It applies to our website, our web app, and our iOS/Android app.

Who we are

MB "Giny" (operating the Great In Nature service), Roku st. 19A, LT-46136, Kaunas, Lithuania. Company code: 308115833. VAT number: Not applicable — MB "Giny" is not VAT-registered. You can reach us at support@greatinnature.com.

Data protection contact: No Data Protection Officer has been appointed. Our processing does not meet the large-scale processing thresholds that make a DPO mandatory under GDPR Article 37. Data-protection queries can be directed to our support email above.

What we collect

  • Account data — your name, email address, password (stored as a salted hash, never in plain text), and, if you sign up with Google or Facebook, the profile details that provider shares with us (see "Where your data comes from" below).
  • Practice data — your check-in answers (how your body feels, what to focus on, session length) and the practices we generate for you. Some of this — how your body feels, and anything you tell us to be gentle with — is health data under Article 9 GDPR, and is collected only with your separate, explicit consent (see "Health data" below).
  • Billing data — handled by our payment processor, Stripe, for web subscriptions, or by Apple/Google for mobile in-app purchases. We do not store your card details ourselves.
  • Usage data — product analytics, only once you consent, as described in our Cookie Policy.
  • Technical data — session identifiers and, briefly, your IP address (see "How long we keep it" below).

Health data (Article 9) — explicit consent

How your body feels and anything you ask us to be gentle with are health-related information. We only collect and use this with your explicit, separate consent, asked for the first time you open a check-in. If you decline, or later withdraw consent, you keep a fully working app — you still get a personalised practice from your focus area and available time, just without that extra layer of personalisation.

You can grant or withdraw this consent at any time from Profile → Privacy & cookies in the app. Withdrawing takes effect immediately: we stop asking for this information, and we erase it from your existing check-in history in the same action — we do not just stop collecting it going forward.

Why we process your data, and on what legal basis

  • Account and non-health practice data (focus area, session length, generated practices) — performance of our contract with you.
  • Health data (how you feel, what to be gentle with) — your explicit consent (Article 9(2)(a)), which you can withdraw at any time without affecting the lawfulness of processing before withdrawal.
  • Billing data — performance of our contract with you, and our legal obligations (invoicing, tax).
  • Analytics data — your consent, as described in our Cookie Policy.
  • Cookie-consent and health-consent decision records — our legal obligation to demonstrate accountability for the choices you made (GDPR Article 7(1)).
  • The record that your free trial was used (a one-way hash of your email address, kept even after you delete your account) — our legitimate interest in preventing the same person from claiming repeated free trials. This is the only thing we keep after account deletion, and it cannot be reversed back into your email address.

Automated personalisation

The practices we build for you are generated by rule-based software, occasionally refined by an AI language model (see the sub-processor list below), based on the check-in answers you give each time. This shapes the content of your practice — it does not decide anything about your rights, your access to the service, or your account, and produces no legal or similarly significant effect on you. You can always tell us your practice didn't fit and rebuild it differently.

Where your data comes from

Most of what we hold, you gave us directly. If you sign up or sign in with Google or Facebook, that provider shares your name, email address and profile photo with us as part of the sign-in — this is the only case where we receive personal data about you from someone other than you.

Who we share it with

We share data only with the processors needed to run the service, each bound by a data-processing agreement. For each: what they do for us, where they're located, and the safeguard that applies to any transfer outside the EEA.

  • PostHog — product analytics, only with your consent — European Union — EU hosting, no transfer outside the EEA.
  • Stripe — web subscription payments — United States / European Union — Standard Contractual Clauses.
  • OpenAI — optional AI refinement of generated practices and class summaries — United States — Standard Contractual Clauses.
  • RevenueCat — syncing mobile in-app purchase entitlements — United States — Standard Contractual Clauses.
  • Apple (App Store) / Google (Play Store) — processing mobile in-app purchases — United States — Standard Contractual Clauses.
  • Google Sign-in — optional "Continue with Google" authentication — United States — Standard Contractual Clauses.
  • Meta (Facebook Login) — optional "Continue with Facebook" authentication — United States / European Union — Standard Contractual Clauses.
  • Google / YouTube — hosting the video classes shown in the Classes library — United States / European Union — Standard Contractual Clauses; video thumbnails are proxied through our own servers, and no request reaches Google until you press play.
  • Hostinger — website/app hosting and mailbox infrastructure — European Union (Netherlands) — EU hosting, no transfer outside the EEA.

We do not sell your personal data, and we never share health data with any processor except where it is strictly necessary to generate your practice.

International transfers

Where a processor is located outside the EEA, we rely on that processor's Standard Contractual Clauses or another safeguard recognised under GDPR Chapter V.

How long we keep it

  • Account, check-ins, practices, sessions history — while your account is active. Deleting your account (Profile → Delete account) permanently and immediately erases all of it.
  • The hashed record that your free trial was used — kept indefinitely, even after account deletion — see "Why we process your data" above. It is a one-way hash and cannot identify you.
  • Cookie-consent decision records — 3 years from the date of the decision, to demonstrate compliance with Article 7(1) GDPR.
  • Health-data consent decision records — 3 years from the date of the decision, for the same reason.
  • Session records (which include your IP address) — automatically expire after 120 minutes of inactivity.
  • Analytics data — no longer than 12 months, and none at all if you have not consented.

Your rights

Under GDPR, you have the right to access, correct, delete, or export your personal data, to object to or restrict our processing of it, and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal. To exercise any of these rights, contact support@greatinnature.com, or use the account deletion option in the app for immediate self-service deletion.

You also have the right to complain to a supervisory authority. In Lithuania, this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI). You may also complain to the supervisory authority in your own EU country of residence.

Security

We use industry-standard measures to protect your data, including encryption in transit, hashed passwords, and access controls limiting who at MB "Giny" can see your data. No system is completely secure; if we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, you, without undue delay.

Children

Our service is not directed at children, and we do not knowingly collect personal data from children.

Changes to this policy

If we make material changes to this policy, we will post the update here and, where appropriate, notify you directly.