GraduallyBeta
← Back to Gradually

Privacy notice

Effective 09/28/2026

Gradually (the "service") is operated by Launchby.ai LLC ("we", "us"). This notice describes the personal data the service collects, the purposes for which it is processed, the third parties that process it, and the rights available to you.

Invest529 credentials

  • Invest529 credentials are never written to our database or to our log files. They are held in memory only for the duration of a synchronization, and are discarded when it completes.
  • If you select "remember on this device", the credentials are stored in your browser on that device only, encrypted with a key that cannot be extracted from the browser. They are sent to the service only for a synchronization, used to contact Invest529, and then discarded from server memory. A synchronization occurs when you initiate one, and each time you open the service on that device while "Sync when the app opens" is enabled in Settings. That setting is enabled by default and may be disabled at any time.
  • The service uses the read-only aggregator credential that you generate on invest529.com. That credential permits the reading of balances only. It cannot be used to transfer funds.

Personal data we collect

  • Email address. Used to authenticate you. Access is by emailed sign-in link, so the service stores no password of its own.
  • Beneficiary details. The name or nickname you enter and the expected year of enrollment. You may also provide a birth year to quickly fill an estimated college start year. Birth year is optional; no feature requires it or uses it for another purpose. A birth month and day are not collected.
  • Account balances, account names, and allocations. Retrieved from Invest529 when you initiate a synchronization, extracted from a statement you upload, or entered by you. An account you enter manually may represent any college savings plan or other account and may include a name you choose and a stocks, bonds, and cash allocation. Each synchronization and each entered balance is retained as a dated record in order to display change over time.
  • Planning inputs. Monthly contribution, selected glidepath, school type, years of attendance, current cost, inflation rate, and market scenario.
  • Feature suggestions and votes. A suggestion includes the title and problem description you provide. It is visible only to you and service administrators while awaiting review, and may become visible to everyone if it is published. Your attribution is not shown publicly. A vote is associated internally with your account to enforce one vote per feature; other users and administrators see only aggregate vote counts, not voter identities.
  • Usage events. Recorded to monitor service availability and use. When you are signed in, an event is associated with your user ID. Events are limited to a fixed set of action names and operational details such as page names, counts, status categories, and true-or-false values. They do not include balances, names, email addresses, or credentials, and are deleted after 180 days.

An uploaded statement file is processed in memory and is not retained. Only the dated balances extracted from it are stored.

Uses we do not make of your data

  • Your personal data is not sold, rented, or used for advertising.
  • The service uses no third-party analytics and no tracking scripts. Usage events are recorded in our own database.
  • The service makes no third-party requests from the browser. Fonts and images are served by the service itself.
  • The service performs no credit checks and initiates no transfer of funds.

Processors

The following third parties process data on our behalf:

  • Supabase. Database and authentication. Personal data is stored here, in the United States, and is encrypted at rest. Beneficiary names and nicknames, account names, login nicknames, and the names of custom glidepaths and scenarios are also encrypted by the service before they are stored.
  • Vercel. Application hosting and delivery.
  • Resend. Delivery of sign-in email. Receives your email address. Resend also delivers an email to service administrators when there are new feature suggestions or votes in our product roadmap. That email lists the titles of new suggestions and the number of new votes for each. It does not say who submitted or voted.
  • Cloudflare. Domain services and inbound mail forwarding.
  • UptimeRobot. Availability monitoring. Receives no personal data.
  • Invest529. Your plan provider, contacted only during a synchronization. We are not affiliated with Virginia529, Invest529, or Commonwealth Savers. See the terms of use.

Retention and deletion

You may delete your account at any time from Settings. Deletion removes the account together with beneficiaries, balances, planning settings, saved glidepaths, feature votes, and feature suggestions that are still awaiting review. If a suggestion was published before deletion, its title and description may remain on the public roadmap, but its internal attribution to your account is removed. Deletion is immediate and irreversible.

Credentials remembered on a device may be removed from the Accounts screen by disabling "remember on this device", or by clearing that browser's site data. Usage events are deleted after 180 days. When you delete your account, usage events already recorded are no longer associated with it, and are deleted on the same schedule. Demo visit records are retained for 90 days, and a demo account is deleted when the demo is exited.

Your rights

Depending on where you live, privacy law may give you rights to confirm whether we process your personal data, access it, correct inaccuracies, request deletion, obtain a copy in a portable format, and appeal a refusal of a request. We make these request options available to every user, regardless of location.

Access, correction, and deletion are available directly within the service. To obtain a copy of your data, or to exercise any right not available in the service, contact hello@gradually.io. If a request is refused, you may appeal by replying to that response, and we will provide a written explanation of our decision.

Children

The service is intended for use by adults and is not directed to children. We do not knowingly create accounts for children. An adult user may enter a beneficiary's name or nickname, expected college start year, and account information as described above. A birth year is optional and is used only to quickly fill an estimated college start year; charts and projections do not require it. The service does not ask a beneficiary to create an account or provide information directly.

Changes to this notice

We may update this notice from time to time. The current version takes effect on the date shown above. Continued use of the service after that date constitutes acceptance of the updated notice.

Contact

Questions regarding this notice may be directed to hello@gradually.io.

← Back to Gradually