Privacy

Privacy notice

What this website and the public demo at app.gyrator.io collect, who else handles it, and how to have it deleted. Gyrator on your own server is a different matter; see privacy in the product.

Who is responsible

Sasha Bondar runs gyrator.io and the demo at app.gyrator.io. Write to sasha@gyrator.io about anything on this page.

The website

The landing page, the docs and the licence page set no cookies and run no analytics. The method pages use Clicky to count visits; it may set a cookie to recognise a returning browser.

The demo at app.gyrator.io

The demo is there so you can try Gyrator before installing it. There is no paid hosted service.

What it stores

  • Your account: the organisation name, your name, your email and a hash of your password. The password itself is never stored.
  • What you enter: team names, the names and email addresses of the people you add, their answers, the team’s goal and the retro questions.
  • One cookie, tp_admin, that keeps you signed in for up to 30 days. It is removed when you sign out.
  • Technical logs of requests, which can include IP addresses. They are used only to keep the service running and to stop abuse, and are deleted as the log files rotate. Counters for sign-in and signup limits are kept in memory for at most an hour.

People you add answer through a personal link and have no account. Their answers are shown only as group totals, never by name. The product’s privacy rules apply in the demo as they do anywhere.

If you add other people, make sure they agree to it. They get an email only when you open a check-in and choose to email them.

Who else handles it

  • DigitalOcean hosts the server.
  • Resend delivers email: account confirmation, password reset and check-in invitations. It receives the recipient’s address and the message.
  • Cloudflare Turnstile checks that a human is opening an account or asking for a password reset. Cloudflare sees your IP address and signals from your browser for that check.
  • Anthropic drafts retro questions and simulated answers when the model is used. It receives team-level numbers and anonymised comments only, never names or email addresses.

Nothing is sold, shared for advertising or used to email you about anything else.

How long it is kept, and deleting it

The demo can be reset at any time, and a reset deletes every account and everything in it. To have your account and its teams deleted sooner, write to sasha@gyrator.io from the address you signed up with; it is done within 30 days. Deleting a team in the app removes its people, answers and links at once.

Under the GDPR you may ask for a copy of your data, have it corrected or deleted, or object to its use, and you may complain to your data protection authority. The basis for processing is providing the demo you asked for, and keeping it safe from abuse.

Changes

This notice changes when the demo changes. Last updated 11 October 2026.