Skip to content

Legal

Privacy policy

What data GRaaS collects, what it does with content you push, how long it keeps things, and who it shares them with.

Last updated 15 August 2026.

What we collect

Three categories, and it is worth separating them because they are treated differently.

  • Account data. Name, work email and organisation, supplied when you sign up or are invited. Identity is handled by our authentication provider; we hold the identifiers it returns.
  • Content you push. The document text, titles and identifiers you send to the ingest endpoint, plus everything derived from them — chunks, embeddings, entities, assertions and provenance records.
  • Operational data. Search queries with their per-step timings and the answers produced, API key usage, and standard request logs.

What we do with content you push

We index it, extract entities and relationships from it, and use it to answer searches within the workspace it belongs to. That is the entire purpose.

We do not train or fine-tune any model on your content, and the model providers we use operate under terms that exclude training on API inputs. Your content is not used to improve answers for any other customer.

Where it lives

A single cloud region, on infrastructure we operate. There is no regional residency option today. Model inference is performed by third-party providers, which means document text is transmitted to them at ingest and at search time.

Retention

What we keep and for how long
DataRetention
Content you pushUntil you delete the document or the workspace
Derived data — chunks, entities, assertionsDeleted with the document that produced it
Search logsRetained for the life of the workspace
Account dataUntil the account is removed
Request logsA rolling operational window

Deleting a document removes it and its support for every fact it asserted. Any fact that loses its last supporting document as a result is retracted.

Who else sees it

  • Our model and infrastructure providers, as processors. The subprocessor list names them.
  • Our engineers, when operating the platform. We do not currently expose a customer-data access log, which we note on the security page rather than omitting.
  • Nobody else. We do not sell data and we run no advertising integrations.

Your rights

You can export your account data, delete documents individually or delete a workspace entirely, and ask us to remove your account and everything associated with it. Note that the extracted graph is not currently exportable — your source content is yours because you sent it, but the derived structure cannot be taken with you today.

Cookies

The console uses a session cookie for authentication. This marketing site sets no analytics or advertising cookies.

Contact

Privacy questions, data processing agreements and deletion requests all go to the same address as everything else. We answer them.