Security and Privacy
How Grais handles your data and keeps it secure.
How does Grais handle my data?
Grais uses both local and cloud processing in normal operation. The extension keeps account, preference, conversation, draft, cache, telemetry, and runtime state in Chrome storage or IndexedDB. The iOS app keeps authentication and session state, settings, account-scoped conversation and action caches, contact bindings, and selected photo overrides on the device. Grais services process and store conversation history, AI replies, memories, plans, integrations, diagnostics, voice inputs, and enabled browser-task artifacts.
On supported communication platforms, Grais can capture the open conversation's available history and upload it to the service. This is not limited to manually selected text. Personal or sensitive data sent between the extension, website, Grais services, and providers uses encrypted network transport such as HTTPS or WSS.
What privacy controls do I have?
- You choose which supported conversations and enabled workflows you use with Grais.
- You can keep sensitive contacts in review-first mode.
- For higher-trust workflows, name the agent action scope before asking AI to inspect, suggest, or draft beyond the visible thread.
- Review, insertion, sending, automation, and browser-task behavior depend on the enabled feature and its trust or action settings.
- You can edit or delete memories and stored preferences.
- You can delete conversations and clear local extension data where the relevant control is available.
- You can request account data access, export, or deletion by email.
Does Grais use third-party AI providers?
Yes. Grais uses configured AI providers, which can include OpenAI, Anthropic, or Google, to process the prompt, conversation context, memories, and tool context needed for the requested output. Grais also uses providers for cloud hosting, authentication, storage, analytics, logging, payments, email, attribution, and integrations. See the Privacy Policy for the receiving-party categories and use limits.
For the product boundary around stronger agentic models, read the Claude Sonnet 5 follow-through note.
Does Grais read every page I visit?
No. Grais does not build or sell a general history of every site you visit. Normal conversation capture is tied to supported platform pages.
The extension also has broad host access for an enabled browser task's active visible-tab screenshot capability. A browser-task screenshot is separate from normal conversation capture and can contain anything visible in the active target tab when the task requests it.
If you do not want Grais involved in a conversation, do not use the extension in that thread. Keep browser-task capabilities disabled when you do not want Grais to inspect or act on a target tab.
Public website discovery is separate from private conversation context. Agents and crawlers can read Grais's public research, support, policy, and discovery files, but those surfaces do not grant access to account state or extension sessions. For the boundary, read Agent-Ready Websites Need Public Discovery Boundaries; for the machine-readable public map, use /llms.txt.
Can I control what gets sent?
Yes. Use review-first settings for sensitive conversations and enable higher-trust sending, automation, integration, or browser-task behavior only where you are comfortable with it. The exact controls depend on the feature.
For sensitive conversations, keep the trust level on review and avoid sending unreviewed drafts.
If a reviewed draft becomes work another person will act on, carry the decision proof before the handoff moves forward.
How can I request data deletion?
You can clear local extension data and edit or delete conversations, memories, or preferences where those controls are available. Clearing local data or removing the extension does not automatically delete remote data already held by Grais or its providers.
For account data access, correction, export, or deletion, email [email protected] from the address connected to your Grais account. Grais may verify your identity and will explain any security, legal, billing, or technical retention limits that apply.
Include the email address connected to your Grais account. Do not include passwords, payment card numbers, or sensitive third-party credentials in the deletion request.