Last updated: September 21, 2026
Gunimi ("we", "our", "us") operates an AI-first workspace for business teams. This Privacy Policy explains what personal data we collect, how we use it, and your rights. By creating an account you agree to the practices described here.
We process your personal data under GDPR Article 6 on the following legal bases:
Account Information
When you register, we collect your email address, full name, and any profile information you choose to provide (job title, avatar).
Workspace Data
All content you create inside Gunimi — companies, contacts, deals, notes, tasks, and activity records — is stored in your workspace and associated with your account.
Usage Activity
We record workspace activity events (e.g. "deal created", "task completed") to power your activity feed and workspace analytics.
Technical Data
Standard server logs including IP addresses, browser type, and request timestamps for security and debugging purposes.
Your data is stored in Supabase on infrastructure in North EU (Stockholm, Sweden). We do not store primary workspace data outside the European Union. Row-level security (RLS) is enforced at the database layer — workspace data is only accessible to authenticated members of that workspace.
Authentication is handled by Supabase Auth using email and password. Passwords are never stored in plain text. All connections are encrypted via TLS 1.3.
Under the General Data Protection Regulation, you have the following rights:
To exercise any of these rights, email support@gunimi.com. We will respond within 30 days.
OpenAI (AI features)
When you use AI features, relevant content is sent to OpenAI's API. OpenAI's API Terms contractually prohibit use of API-submitted data to train models. We have a data processing agreement with OpenAI. As a US company, data transfer is governed by Standard Contractual Clauses (SCCs).
Supabase (database & auth)
Database, authentication, and real-time features. Data stored in North EU (Stockholm, Sweden). Supabase is SOC 2 Type II certified.
Postmark (transactional email)
Transactional emails (verification, invites, notifications). Email addresses shared only for delivery purposes.
PostHog (analytics)
Usage analytics via PostHog EU cloud. Data stored in the EU. No personal content from your workspace is sent to PostHog.
Sentry (error monitoring)
Application error monitoring and crash reporting. Configured to exclude personally identifiable information from error payloads.
Upstash Redis (rate limiting)
User IDs stored temporarily for rate limiting. No personal data beyond user ID is stored.
Most data is processed within the European Union. The exception is OpenAI (United States), used exclusively for AI features. This transfer is governed by Standard Contractual Clauses (SCCs) as required under GDPR Chapter V. OpenAI is also certified under the EU–US Data Privacy Framework.
We retain your account and workspace data for as long as your account is active. If you request deletion, we will remove your personal data within 30 days, except where retention is required by law.
Gunimi uses session cookies provided by Supabase Auth to keep you logged in. These are strictly necessary for the service to function and do not track you across third-party websites. Cookie Policy
You have the right to lodge a complaint with your national data protection authority. Slovakia: Úrad na ochranu osobných údajov SR (dataprotection.gov.sk). Czech Republic: Úřad pro ochranu osobních údajů (uoou.cz). Other EU countries: contact your local data protection authority.
Limited Use Disclosure
Gunimi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google API Services User Data Policy
When you connect a Google account, we may access the following data depending on the integrations you enable:
Google user data is used exclusively for features you request within your workspace. We do not:
For privacy questions, data requests, or concerns, contact us at support@gunimi.com.