1. Who we are, and what this covers
Grail Analytics, Inc. (Grail Analytics, we, us), a Massachusetts corporation with a place of business at 28 Porazzo Road, Hull, MA 02045, measures how AI answer engines describe brands. This notice explains how we collect, use and share information in connection with grailanalytics.ai and the Grail Analytics platform (together, the Service). It applies to visitors to our site and to customers and their users.
It does not cover the Customer Data you submit through the Service for analysis — the brand facts you give us to check AI claims against. That processing is governed by our Data Processing Agreement and by the Terms of Service, where we act as your processor rather than as a controller in our own right.
2. What we collect
2.1 Account information. Your name and email address, and a cryptographic hash of your password (we never store the password itself). If you sign in with Google, we receive your email address and basic profile information from Google instead.
2.2 Information you configure. The brand you are measuring, its aliases and website, the competitors you track, the prompts you want run, and the ground-truth facts you supply about your own organisation. If you upload a file of ground-truth facts, we parse it and discard the original file — only the structured fact rows are stored.
2.3 Your website, and documents you upload. When you enter your website during onboarding, we fetch and analyse pages from that site — the homepage plus a small number of same-site pages linked from it — to pre-fill your brand name, aliases, suggested prompts, ground-truth facts, and brand colours. The fetch is restricted to the public web address you gave us.
Ground-truth documents you upload (PDF, XLSX, DOCX, CSV, TSV, TXT or Markdown) are parsed to text, and that extracted text is sent to a third-party AI model to propose structured fact rows, which you then review. As above, the original file is discarded — only the fact rows you keep are stored.
2.4 Information we generate. The responses AI models give to your prompts, the brand mentions and citations we extract from them, the accuracy verdicts we compute, and your scores over time.
2.5 Usage and analytics. We use Google Analytics via Google Tag Manager, and automatically collect device and browser information, IP address, pages viewed, referring URLs and similar usage data. On both this website and the signed-in application, all four Consent Mode v2 signals — analytics storage, advertising storage, advertising user data and ad personalisation — are declared denied before any Google tag loads. Nothing is granted until you choose to allow it in the cookie notice, and choosing to keep it off is a single click that carries the same weight. Our analytics events are designed to carry no personal data — no email addresses, names or passwords are sent in any event parameter.
2.6 Payment information. Payments are handled by Stripe. We never receive or store your card number. We store an identifier linking your account to your Stripe customer and subscription records.
3. How we use it
To provide, maintain and improve the Service; process payments and manage your subscription; respond to support requests; send administrative communications (billing notices, security alerts, Terms updates, report-ready and export-ready notifications); send product or marketing communications where permitted, which you can opt out of at any time; monitor and improve site and Service performance and security; and comply with legal obligations.
3.1 Aggregated and de-identified data. We may also generate aggregated or de-identified data from Customer Data across customers, and use it for any lawful business purpose, including improving the Service and publishing research. We only do this where the result no longer identifies you, your brand or any individual, cannot reasonably be re-identified, and draws on enough distinct customer accounts that no single customer’s data can reasonably be isolated or inferred from it. Data that does not yet meet those conditions remains personal data and continues to be handled as described in the rest of this notice. The full conditions are in Section 4.4 of the Terms of Service.
3.2 Legal bases (EEA/UK). Where the GDPR applies we rely on: performance of a contract (providing the Service you signed up for); our legitimate interests (improving and securing the Service, and direct marketing to business contacts, subject to your right to object); your consent, where we ask for it — for example analytics cookies and marketing email; and legal obligation, for example tax and accounting records.
4. Who we share it with
4.1 Processors. We use the following:
- AI model providers (OpenAI, Anthropic, Google) — running the service means sending content to these providers. Specifically: the prompts we run on your behalf (which contain your brand name, competitor names and the query text); the model answers we collect, sent on to a second model for claim extraction; your ground-truth facts — individually as evidence, and as a whole corpus — sent to a model to adjudicate accuracy claims, and their text sent to an embeddings API for matching; the pages we fetch from your website and the text of any ground-truth document you upload, sent to Anthropic for structured extraction during onboarding; and your report content, sent to a model to write the report’s prose summaries. We do not send them your account credentials or your billing details.
- Stripe — payment processing and subscription billing.
- Resend — transactional email. It receives your name and email address whenever we send you a service email (for example, a report-ready or export-ready notification).
- DigitalOcean — hosting, managed database, and object storage for your generated reports and database backups.
- Google — Analytics and Tag Manager, subject to your consent.
- Sentry — error monitoring.
4.2 Other disclosures. We also disclose information:
- to professional advisors — lawyers and auditors — as needed;
- for legal and safety purposes — to comply with law, respond to lawful requests, or protect the rights, property or safety of Grail Analytics, our customers, or others; and
- in a business transfer — if we are involved in a merger, acquisition or asset sale, information may transfer as part of that transaction, subject to this notice or a successor notice with notice to you.
5. International transfers
We are a Massachusetts, USA corporation, and information we collect may be processed in the United States and in other countries where our service providers operate. Where we transfer personal data out of the EEA, UK or Switzerland, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses, as described further in the DPA.
6. How long we keep it
We keep your data for as long as your account is active. When you request deletion, we remove your live records within 30 days and purge them from backups within 90 days. Account and billing data is retained for the life of your account plus a period afterwards to satisfy legal and accounting requirements.
One exception: our operator audit log is append-only by design, so those rows are not deleted. Instead, your identifying fields inside them are replaced with a stable opaque identifier, so the audit trail stays intact without a live link to your deleted account. Records held by Stripe remain subject to Stripe’s own retention policy.
7. Your rights
7.1 Core rights, offered to all users. Regardless of where you live, you may: access the personal information we hold about you; correct inaccurate information; delete your personal information; receive a copy of it in a portable format; object to or restrict certain processing; and withdraw consent where processing is based on consent. To exercise any of these, email hello@grailanalytics.ai. We will respond within 30 days of receiving a verifiable request. If we need more time for a complex request, we will tell you why and give you a new timeframe before the original 30 days runs out.
For an export of your data — you get a ZIP of structured JSON covering your prompts, runs, model responses, citations, accuracy verdicts, ground-truth facts, and report records, plus the rendered reports themselves.
Four things are excluded from the export by design, and the ZIP’s own README says so:
- Ground-truth source files — uploads are parsed and discarded at ingest, so only the structured fact rows exist; those are exported.
- Embedding vectors — machine-internal representations, excluded from every file.
- Operator test-lab (experimental) runs and the rows derived from them.
- Claim verdicts that are not in an approved or auto-approved review state, and operator-only debug payloads. A verdict still awaiting review is not in your export.
You can request deletion of your account and data from your account settings, subject to the timelines above.
7.2 Additional rights for specific jurisdictions.
- EEA, UK, and Switzerland residents: you also have the right to lodge a complaint with your local data protection supervisory authority, in addition to (not instead of) contacting us directly.
- California residents (and other states with similar sensitive-data provisions): you have the right to limit our use of sensitive personal information. As a practical matter this should not come up — we do not ask you to submit sensitive categories of personal information (health, precise geolocation, and similar) as part of Customer Data, and ask that you not include them.
8. Cookies
We set a session cookie and a security token that are necessary for you to stay signed in —
these cannot be switched off. Your consent choice itself is not stored in a cookie: it is kept
in your browser’s local storage, under the key
ai_vis_consent. Analytics cookies are set only after you accept them, and you can
decline without losing any product functionality.
Changing your mind is as easy as the original choice. — it takes effect immediately, with no confirmation step and no account required.
9. Security
We use technical and organisational measures designed to protect information against unauthorised access, loss or misuse. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Children’s privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children under 16.
11. Changes to this notice
We may update this notice from time to time. For material changes we will provide notice as described in Section 12 of the Terms of Service. The “Last updated” date above reflects the most recent revision.
12. Contact
Questions about this notice or your data: hello@grailanalytics.ai.
Grail Analytics, Inc.28 Porazzo Road
Hull, MA 02045