Privacy Policy for Grais

Last updated: August 12, 2026

This Privacy Policy explains how Grais collects, uses, stores, and shares information when you use the Grais website, account services, Chrome extension, or iOS app, including TestFlight builds. The extension's disclosed single purpose is to help you understand and act on communication context through AI-assisted replies, planning, memory, integrations, and user-authorized browser tasks.

1. Information Grais Handles

Grais handles the following categories of information when they are needed for the features you use:

  • Account and authentication data: email address, user and account identifiers, profile details, authentication tokens, account status, plan and entitlement information, and settings tied to your account.
  • Conversation content and history: messages from supported conversation platforms, drafts, timestamps, direction and delivery state, reactions, reply references, and limited attachment or shared-content descriptors exposed by the platform.
  • Conversation and contact context: participant names or handles, platform and conversation identifiers, conversation URLs, persona or relationship context, summaries, plans, memories, instructions, and other context used to continue a conversation workflow.
  • Browser-task data: the target tab's URL, title, page state, action results, and visible-tab screenshots or derived artifacts when an enabled browser task needs them. A browser-task screenshot can contain anything visible in that tab at the time of capture.
  • Preferences and local runtime state: language, model and response preferences, feature toggles, drafts, cached conversation state, device or installation identifiers, session state, worker state, and task status.
  • Native-device data: iOS app settings and caches, contact names or photos that you select or allow the app to match on your device, contact-to-conversation bindings, microphone audio for voice features, and generated or selected audio and images used by those features.
  • Integration data: authorization status, configuration, and data returned by integrations you enable, such as Google Calendar or a user-configured MCP service.
  • Telemetry and diagnostics: feature and surface names, event times, client, session, conversation, message, turn, task, and trace identifiers, browser and extension version, operating system, performance measurements, error codes, error messages, stack traces, and bounded diagnostic context. Grais services also receive ordinary request metadata such as IP address and headers.
  • Website, billing, and attribution data: sign-up and waitlist information, subscription and billing status, referral or affiliate attribution, and support communications. Payment processors collect the payment details you submit to them; Grais receives and stores the related customer, checkout, subscription, and status identifiers needed to manage access and billing.

Grais does not need every category for every workflow. The information handled depends on the surface, account state, settings, supported platform, integrations, and tasks you use.

2. How the Chrome Extension Collects Data

On supported communication platforms, the extension uses content scripts to identify the active conversation, capture available message history and context, keep a local upload cache, and send conversation batches to Grais services. This is not limited to a snippet that you manually select. Grais may process the open conversation's available history so it can provide continuity, memory, planning, and agent replies.

The extension uses Chrome permissions for these user-facing and operational purposes:

  • activeTab, tabs, and sidePanel: identify and associate the active supported tab with the Grais side panel.
  • scripting: install or restore the Grais companion on supported pages and perform an enabled browser task in its target tab.
  • storage: retain authentication, account, preference, conversation, memory, draft, cache, telemetry, and runtime state in Chrome storage or IndexedDB.
  • alarms: run scheduled maintenance, synchronization, heartbeat, and enabled worker activity.
  • Broad host access: operate on supported messaging sites and Grais services, support local development, and capture the active visible tab for an enabled browser task. Normal conversation capture is tied to supported platform pages. Broad host access does not mean Grais creates a general-purpose record of every site you visit.

Visible-tab screenshots are separate from ordinary conversation capture. They are taken only when an enabled browser-task workflow requests a screenshot of its active target tab. Screenshots and related artifacts may be uploaded to Grais services so the task can inspect the visible page, decide the next step, record task evidence, or diagnose a failure.

3. How the iOS App Handles Data

The iOS app uses the same Grais account and services to retrieve and synchronize action-inbox items, conversation history and summaries, drafts, memories, plans, browser-task status, and other account state. It sends the approvals, edits, actions, requests, and voice inputs you submit through the app to Grais services.

The app keeps authentication and session state, settings, and account-scoped conversation and action caches on the device. If you grant Contacts access, it can read contact names, nicknames, organization names, and photos to match a Grais conversation with a local contact. Contact bindings and selected photo overrides are stored on the device; Grais does not upload the device contact book through this matching feature.

When you start a voice feature, microphone audio and generated speech text or audio can be processed by Grais services and configured AI or speech providers. The iOS app can also request and display browser-task state from Grais services, but Chrome performs the browser access described above.

4. How Grais Uses Information

Grais uses the information described above to:

  1. Authenticate your account and enforce access, plan, and security controls.
  2. Capture, store, retrieve, summarize, and display conversation history.
  3. Generate replies, plans, memories, suggestions, and other agent output.
  4. Carry out the integrations and browser tasks you enable or request.
  5. Synchronize state across the extension and Grais services.
  6. Measure feature use and service performance, diagnose errors, prevent abuse, and secure the service.
  7. Provide support, process data requests, manage subscriptions, and attribute eligible referrals.

Grais does not sell or rent user data, use personal content for personalized advertising, transfer user data to data brokers, or use it to determine creditworthiness or for lending.

5. Local and Remote Processing

Grais is not a local-only product. It uses both device storage and remote services in normal operation.

On your device, the Chrome extension stores or caches authentication state, account data, preferences, conversation and participant identifiers, messages awaiting upload, conversation-history caches, drafts, plans, telemetry identifiers, and runtime state. The iOS app stores authentication and session state, settings, account-scoped conversation and action caches, contact bindings, and selected photo overrides. Some state is session-only; other state persists in Chrome storage, IndexedDB, the iOS app's local storage, or the device keychain until it is cleared, replaced, or removed with the app, extension, or browser profile.

On Grais systems, conversation history, agent messages, memories, plans, account records, integration state, telemetry, diagnostics, and browser-task artifacts may be processed or stored to provide the service. Grais uses managed cloud, database, authentication, storage, and logging infrastructure for this work.

6. Service Providers and Other Recipients

Grais shares data only when needed to provide, improve, secure, support, or legally operate the service. Depending on the feature, recipients include:

  • AI model and speech providers, including OpenAI, Anthropic, Google, ElevenLabs, or another provider configured for the requested workflow. They receive the prompts, conversation context, memories, tool context, text, audio, and other inputs needed to produce the requested output.
  • Cloud, database, authentication, storage, and logging providers, including Google Cloud and Supabase, which process account, conversation, memory, artifact, telemetry, diagnostic, and operational data for Grais.
  • Product analytics and observability providers, including PostHog, Google Analytics or Tag Manager, and configured tracing or logging services, which receive the identifiers, events, measurements, and redacted diagnostic context needed to understand reliability and use.
  • Integration providers and user-configured services, such as Google Workspace or MCP services you enable, which receive requests and context needed to perform the integration action.
  • Payment, email, and attribution providers, including Stripe, email-delivery providers, and FirstPromoter, which receive the account, transaction, delivery, or referral data needed for those services.
  • Professional advisers or authorities when disclosure is required by law or needed to protect users or the service.

Grais does not authorize these recipients to use Grais user data for their own personalized advertising.

7. Retention, Deletion, and Export

Retention depends on the type of information and why it is needed:

  • Session state can end when the browser or app session ends. Local Chrome storage, IndexedDB data, iOS caches, contact bindings, and selected photo overrides can remain until they are cleared, replaced, or removed with the app, extension, or browser profile.
  • Remote account, conversation, memory, task, integration, and operational records are retained while needed to provide and secure the service, maintain continuity, resolve support or abuse cases, and meet applicable obligations. Grais does not apply one fixed retention period to every data category.
  • Provider logs, security records, and backup copies can follow separate operational or legal retention requirements.

You can delete individual conversations, memories, preferences, or local extension data where the relevant control is available. Removing the extension, removing the iOS app, or clearing local app or browser storage removes device-held copies but does not by itself delete data already stored by Grais services.

To request account data access, correction, export, or deletion, email [email protected] from the address associated with your Grais account. Grais may need to verify your identity. A request applies to data Grais controls; Grais will identify any data it cannot delete or export because it must be retained for security, legal, billing, or technical reasons.

You can also revoke an enabled third-party integration through the relevant provider. Revocation stops future access but does not automatically remove information already processed by Grais or the provider.

You can reopen Cookie preferences on the website and select Reject Non-Essential to withdraw optional analytics and advertising consent. The website clears the supported legacy browser identifiers and reloads without the optional loaders when they were active. This cleanup includes supported Google Analytics, PostHog, and FirstPromoter browser identity or attribution state. The website also applies this cleanup when no cookie choice is stored, so identifiers from an earlier website version or a removed choice are not reused.

8. Human Access and Support

Grais personnel do not routinely read private conversation content. Human access is limited to authorized cases, such as when you ask for support and consent to review specific data, when access is needed to investigate security or abuse, when aggregated and de-identified data is used for internal operations, or when access is required by law. Access is limited to people and systems with an operational need.

Do not send passwords, payment card numbers, or third-party credentials in support requests.

9. Security

Grais uses access controls, service authentication, monitoring, and encrypted network transport such as HTTPS or WSS for personal or sensitive data sent between the extension, iOS app, website, Grais services, and providers. No system is completely secure, and Grais cannot guarantee that unauthorized access or loss will never occur.

10. Chrome Web Store Limited Use

Grais's use and transfer of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

This means Grais limits use of Chrome extension user data to the extension's disclosed single purpose and related operations such as maintaining, securing, and measuring the performance and reliability of those features. Grais limits collection and use of browsing activity to user-facing features, limits transfers to parties needed to provide or improve those features or for permitted security and legal purposes, restricts human access as described above, and prohibits personalized-advertising, data-broker, creditworthiness, and lending uses.

11. Changes and Contact

Grais may update this policy when its products, providers, or data practices change. The date at the top shows the latest material update.

For questions or privacy requests, contact: