Legal
Privacy policy
What data GRaaS collects, what it does with content you push, how long it keeps things, and who it shares them with.
Last updated 15 August 2026.
What we collect
Three categories, and it is worth separating them because they are treated differently.
- Account data. Name, work email and organisation, supplied when you sign up or are invited. Identity is handled by our authentication provider; we hold the identifiers it returns.
- Content you push. The document text, titles and identifiers you send to the ingest endpoint, plus everything derived from them — chunks, embeddings, entities, assertions and provenance records.
- Operational data. Search queries with their per-step timings and the answers produced, API key usage, and standard request logs.
What we do with content you push
We index it, extract entities and relationships from it, and use it to answer searches within the workspace it belongs to. That is the entire purpose.
We do not train or fine-tune any model on your content, and the model providers we use operate under terms that exclude training on API inputs. Your content is not used to improve answers for any other customer.
Where it lives
A single cloud region, on infrastructure we operate. There is no regional residency option today. Model inference is performed by third-party providers, which means document text is transmitted to them at ingest and at search time.
Retention
| Data | Retention |
|---|---|
| Content you push | Until you delete the document or the workspace |
| Derived data — chunks, entities, assertions | Deleted with the document that produced it |
| Search logs | Retained for the life of the workspace |
| Account data | Until the account is removed |
| Request logs | A rolling operational window |
Deleting a document removes it and its support for every fact it asserted. Any fact that loses its last supporting document as a result is retracted.
Who else sees it
- Our model and infrastructure providers, as processors. The subprocessor list names them.
- Our engineers, when operating the platform. We do not currently expose a customer-data access log, which we note on the security page rather than omitting.
- Nobody else. We do not sell data and we run no advertising integrations.
Your rights
You can export your account data, delete documents individually or delete a workspace entirely, and ask us to remove your account and everything associated with it. Note that the extracted graph is not currently exportable — your source content is yours because you sent it, but the derived structure cannot be taken with you today.
Cookies
The console uses a session cookie for authentication. This marketing site sets no analytics or advertising cookies.
Contact
Privacy questions, data processing agreements and deletion requests all go to the same address as everything else. We answer them.