Privacy Policy
Last updated: September 30, 2026. We are committed to protecting your privacy and your agent's data.
Information We Collect
We collect information that you provide directly to us when you create an account, use our services, or communicate with us. This includes your name, email address, and any data provided to your agents for processing.
How We Use Your Data
Your data is used to provide and maintain Gridable for your workspace. Gridable does not train or fine-tune any AI model on your data. Your agents recall earlier work because Gridable stores your conversations, the notes agents save, and search indexes built from them, and looks them up when working in your workspace. We do not share your private data with other users or with advertisers.
Data Security
Connections to Gridable use HTTPS: Railway, our hosting provider, terminates the encrypted connection, and Gridable redirects any plain-HTTP request to HTTPS. Account passwords are stored only as bcrypt hashes, and the API keys and tokens you save are encrypted with AES-256 before they are stored. Some keys saved earlier are still encrypted under an older key and still need to be re-encrypted under the current one. Workspaces share one database: every record carries its workspace ID, and every signed-in request is tied to the workspace of the account that made it. The public API roles of the database are locked out of every table, with row-level security on and their access revoked, so your data is reached only through the Gridable server.
Maps and Location in Published Apps
When an app built on Gridable shows a map, the viewer's browser loads the map background (its style, map tiles, fonts and icons) directly from OpenFreeMap (tiles.openfreemap.org), an independent map service built on OpenStreetMap data. OpenFreeMap receives the viewer's IP address, the browser's standard request headers, and which map tiles were requested, which shows the area being viewed and so roughly where the places on the map are. The map does not send OpenFreeMap the names, addresses or records behind those places. A published app may also ask for the device's current location, for example to share where a crew member is. The browser asks the person first, and nothing is shared if they decline. Gridable does not store a shared location unless the app saves it in one of its records.
AI Services That Process Your Content
Gridable sends the text of your requests, conversations and workflow steps to the AI model that answers them: Anthropic (Claude), OpenAI or Google (Gemini) directly, or another model through OpenRouter (openrouter.ai), depending on the model chosen and the AI account your workspace connected. Voice features send audio to Deepgram or Google to be transcribed and send replies to Deepgram to be spoken. Image generation sends the image request to fal (fal.run), OpenAI or Google, and building search indexes sends text to OpenAI or Google. Gridable also does its own housekeeping on your conversations: it summarises a long conversation so it fits, and keeps a short summary of each session. Gridable runs that work on the DeepSeek V4.1 Flash model through OpenRouter, pinned to three hosts, Fireworks, Together and DeepInfra, which receive the conversation text being summarised. Gridable sets OpenRouter's data collection to deny, so only hosts that do not store or train on prompts take the work, and it never sends this work to DeepSeek's own servers. This applies even when your workspace connects its own Claude subscription or AI key, because the housekeeping is Gridable's work and Gridable pays for it. By default, every other request made for your workspace through OpenRouter also carries that deny setting, so only hosts that do not store or train on prompts answer it, including requests on your workspace's own OpenRouter key. A workspace admin can turn this off in Settings; the workspace then accepts that its requests through OpenRouter may reach hosts that keep prompts and train on them. Claude and OpenAI models called directly run under Anthropic's and OpenAI's API terms, which do not use API data for training. Questions Gridable's decision model answers about your work go only to hosts that keep nothing, whatever that setting says.
Service Providers That Receive Your Data
These are the outside services Gridable sends your data to, what each one receives, and why. Each row says when it applies: always, only when you use the feature it names, or only if you connect the service. A region is stated only where we have confirmed it, so where none is shown, none is claimed.
- Railway (railway.app): Hosts the Gridable server. Everything you send to Gridable passes through it, and it terminates the encrypted connection. Always. Region: US West.
- Supabase (supabase.com): The database and file storage: your account, workspace records, conversations, workflows and uploaded files. Always. Region: us-west-2 (AWS Oregon).
- SendGrid (sendgrid.com): Sends Gridable email (password resets, invitations, workflow notifications and support messages): the recipient address and the message. Always.
- Stripe (stripe.com): Takes payment when you buy a plan: your email address and your account and workspace IDs. Card details go to Stripe directly and never reach Gridable. Only when used: buying a plan.
- GitHub (github.com): Holds support requests sent from inside the console: your name, email, account and workspace IDs and your message, as an issue in Gridable's tracker. Only when used: sending a support request.
- Pwned Passwords (api.pwnedpasswords.com): When you set a password: the first 5 characters of its SHA-1 hash, never the password, to check it against known breaches. Always.
- Twilio (twilio.com): Text messages (workflow SMS steps and invitations to a published app) and calls to a Gridable voice line: the phone number, the message and the call. Only when used: text messages and the voice line.
- Logto: The sign-in service for published apps: open-source software, and Gridable runs it itself on Railway (listed above). When an app turns on sign-in, the people using it sign in through Logto, which tells Gridable their email address. Only when used: sign-in for a published app.
- Nango (nango.gridable.store): The connection broker: open-source software, and Gridable runs it itself on Railway (listed above). When you connect an app such as QuickBooks, Google or Shopify, it holds that connection's tokens and relays requests to it, so it carries the data they read and write. Only if you connect it.
- Intuit QuickBooks (intuit.com): When you connect QuickBooks: your workflows read your company's records and create invoices in it. Only if you connect it.
- Shopify (myshopify.com): When you connect a Shopify store: your workflows read and update its products, inventory and orders. Only if you connect it.
- Google Workspace (googleapis.com): When you connect a Google account: the Sheets, Drive files, Gmail messages and Calendar events your workflows read or write. Only if you connect it.
- Telegram (api.telegram.org): When you connect a Telegram bot: the messages sent to and from your workspace's bot. Only if you connect it.
- Web search (Brave, Serper, Bing, DuckDuckGo) (search.brave.com, serper.dev, bing.com, duckduckgo.com): When an agent searches the web: the search words. Only when used: an agent searching the web.
- Firecrawl (firecrawl.dev): When a workflow reads a web page through Firecrawl: the page address and what to read from it. Only when used: reading a web page through Firecrawl.
- Weather (Open-Meteo, OpenWeatherMap) (open-meteo.com, openweathermap.org): When an agent looks up the weather: the place name. Only when used: an agent looking up the weather.
- OpenFreeMap (tiles.openfreemap.org): Maps in published apps: the viewer's IP address and which map area is shown (see Maps and Location above). Only when used: a map in a published app.
- Anthropic (anthropic.com): Requests, conversations and workflow steps answered by a Claude model. Only when used: a Claude model answering.
- OpenAI (openai.com): Requests answered by an OpenAI model, image requests, and text for search indexes. Only when used: an OpenAI model, image generation or a search index.
- Google Gemini (generativelanguage.googleapis.com): Requests answered by a Gemini model, voice audio to transcribe, image requests, and text for search indexes. Only when used: a Gemini model, voice transcription, image generation or a search index.
- OpenRouter (openrouter.ai): Requests answered by models from other makers (DeepSeek, Moonshot AI's Kimi, Z.ai's GLM, StepFun and OpenAI models), and Gridable's housekeeping summaries (run by Fireworks, Together or DeepInfra). Always.
- Model hosts behind OpenRouter (Fireworks, Together, DeepInfra and others): Run the models OpenRouter routes to. Gridable's housekeeping summaries of your conversations always go to Fireworks, Together or DeepInfra, which OpenRouter lists as zero-data-retention hosts for that model (read 2026-09-29). Other requests go to the host OpenRouter picks, and by default only hosts that do not store or train on prompts are used. Always.
- Typesafe (Jev decision model): Judges a tool call or a coworker decision through OpenRouter: the task text, the call's arguments and, for a coworker decision, workspace content. Every request asks for zero data retention. Only when used: the tool judge and coworker decisions.
- Deepgram (deepgram.com): Voice features: audio to transcribe and replies to speak. Only when used: voice.
- fal (fal.run): Image generation requests. Only when used: image generation.
- Google Stitch: When an agent designs a screen with the design tool: the design topic, the details and style the agent writes, and an optional reference it names. Only when used: the design tool.
Services you connect yourself, such as your own GitHub, Linear (linear.app), Vercel (vercel.com), Railway, Stripe or Supabase account, a web address a workflow calls, or a tool server you add, receive what your workflows send them. You choose those services, and their own terms apply.
Your Choices
A workspace admin decides in Settings whether AI providers may train on this workspace's data. It is off unless an admin turns it on, and each change is recorded with who made it and when. The workspace owner can download the workspace's data, or delete the workspace and everything in it, under Settings, Your data. The download lists the files stored in the workspace but does not contain the files themselves. A workspace with an active paid plan cannot be deleted until the plan is cancelled under Subscription & billing. After a delete, Gridable keeps a record of who deleted the workspace and when.
Questions about our privacy practices? Contact us at privacy@gridable.ai