Skip to content

Privacy Policy

Grail Computer Labs Pte. Ltd.
Last updated: 5 August 2026

1. Introduction

Grail Computer ("Grail," "we," "our," or "us") is a Singapore‑based software company that provides software modernisation services and an engineering and operations platform for building, testing, deploying, and operating applications, AI capabilities, and analytics ("Services"). Your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and secure information about you when you use any of our websites, dashboards, mobile or desktop applications, APIs, browser extensions, or any other product or service that links to this Policy (collectively, the "Service").

By accessing or using the Service, you acknowledge that you have read and understood this Policy and agree to our Terms of Service. If you do not agree, please do not use the Service.

2. Scope

This Policy applies to personal information that we process as a controller. It does not apply to:

  • Data that you upload to private Grail workspaces when Grail acts as a processor on your behalf, such as source code, proprietary datasets, prompts, and outputs. That processing is governed by the applicable agreement and data processing terms.
  • Third‑party services you choose to connect to in your Grail workspace. Those services have their own privacy policies.

Workspace processing locations, approved AI providers, retention periods, and deployment boundaries may differ by engagement and are defined in the applicable order form or data processing agreement.

3. Information We Collect

3.1 Information you provide directly

  • Account Data – name, email address, password (hashed), profile photo, two‑factor authentication secrets, and organisation affiliation.
  • Billing & Payment Data – if you purchase a paid plan, our payment processor (Stripe) collects your payment‑card details. Grail only stores limited billing metadata (card type, last four digits, expiry month/year, billing country) and invoices.
  • Workspace & Project Content – source code, run‑time logs, prompts, uploaded files, database schemas, environment variables, and other artefacts you choose to store in your Grail workspace.
  • Support & Communication Data – information contained in emails, chat messages, or tickets you send to us.

3.2 Information we collect automatically

  • Usage & Device Data – IP address, device type, OS and browser version, language, screen resolution, referring URLs, click‑stream data, and the features you use.
  • Analytics & Marketing Data – where enabled and permitted, we may use PostHog, Google Ads, or Apollo to understand site use, measure campaigns, and route business enquiries. These tools receive only the data configured for their stated purpose.
  • Cookies & Similar Technologies – we use first‑party technologies for authentication and preferences. Non-essential analytics or marketing technologies are used subject to applicable consent requirements and available browser or site controls.

3.3 Data from third parties

  • Public profile data from OAuth providers (Google, X/Twitter) when you authorise Grail.

4. How We Use Information

We use your information to:

  1. Provide and maintain the Service – create accounts, authenticate users, spin up workspaces, compile and deploy code, and fulfil orders.
  2. Improve and research – diagnose crashes, benchmark agent performance, and develop new features.
  3. Communicate – send administrative messages, security alerts, and product updates. Marketing emails are sent only with your consent.
  4. Security & Abuse Prevention – detect fraud, suspicious log‑ins, or malicious code execution; enforce our Acceptable Use Policy.
  5. Legal compliance – comply with financial, tax, export‑control, and anti‑money‑laundering obligations.

We do not use customer workspace content, source code, prompts, or outputs to train shared models or improve cross-client services unless the customer gives written opt-in. Limited operational telemetry may be processed to secure, support, and operate the Service.

5. How We Share Information

We never sell your personal information. We share it only as follows:

  • Service Providers – depending on the Service and engagement, providers may include cloud hosting (Railway, AWS, Hetzner), storage (Supabase, S3-compatible), analytics and marketing tools (PostHog, Google Ads, Apollo), payments (Stripe), communications (Resend), and approved AI inference providers (OpenRouter, AWS Bedrock, Google AI). Current subprocessor details are available on request.
  • Public Content – if you set a project to "public," its code, prompts, and documentation become visible to anyone with the link. Private workspaces remain private by default.
  • Corporate Transactions – information may be transferred in connection with a merger, acquisition, or asset sale.
  • Legal & Safety – where required to comply with law, enforce our terms, or protect the rights, property, or safety of Grail, our users, or others.

6. Legal Bases for Processing (EEA/UK)

We process personal data on the following bases: (i) contract necessity; (ii) legitimate interests (product security, R&D); (iii) consent (marketing, certain cookies); and (iv) compliance with legal obligations.

7. International Data Transfers

Website, account, and support data may be processed in the United States and other jurisdictions where our subprocessors operate. Enterprise workspace data may follow a different approved processing boundary defined in the applicable order form or data processing agreement. Where required, we use Standard Contractual Clauses or another lawful transfer mechanism.

8. Data Retention

We retain personal information for as long as it is needed to: (a) deliver the Service; (b) comply with legal obligations; or (c) resolve disputes. Deleted workspaces enter a 30‑day grace‑period before permanent erasure from backups.

9. Your Rights and Choices

Subject to local law, you may have the right to access, correct, delete, or port your personal data, object to or restrict processing, and withdraw consent. You can exercise most rights from the Grail dashboard or by emailing human@grail.computer.

10. Security

Grail uses administrative, technical, and organisational safeguards appropriate to the Service and the information processed. These may include access controls, multi-factor authentication, encryption in transit and at rest, environment separation, logging, and review procedures. The exact control scope and any engagement-specific requirements are defined in the applicable agreement. Current security and subprocessor information is available on request.

11. Children's Privacy

The Service is not directed to children under 16. If we learn that we have collected personal information from a child without verified parental consent, we will delete it.

12. Cookies & Tracking Technologies

You can manage cookies and similar technologies through available site controls and your browser. Disabling essential technologies may affect core functionality. You can also contact us to ask about the analytics or marketing tools currently enabled on the website.

13. Changes to This Policy

We may update this Policy periodically. We will notify you of material changes via email or an in‑app banner and post the revised Policy with a new effective date.

14. Contact Us

If you have questions about privacy or would like to exercise your rights, please contact:

Grail Computer Labs Pte. Ltd.

Attn: Data Protection Officer

68 Circular Road, #02-01

049422, Singapore

human@grail.computer

You may also lodge a complaint with your local supervisory authority.