Who we are, and what this covers
Grail Analytics measures how AI answer engines describe brands. This notice explains how we collect, use and share information in connection with grailanalytics.ai and the Grail Analytics platform (together, the Service). It applies to visitors to our site and to customers and their users.
It does not cover the Customer Data you submit through the Service for analysis — the brand facts you give us to check AI claims against. That processing is governed by our Data Processing Agreement and by theTerms of Service, where we act as your processor rather than as a controller in our own right.
[COUNSEL] — the operating legal entity name, registered address, and (if required) an EU/UK representative under GDPR Article 27 need to be stated here. Article 27 may bite once we have a meaningful volume of EU customers or process EU data at scale, so this should be revisited as EU signups grow rather than answered once.
What we collect
Account information
Your name and email address, and a cryptographic hash of your password (we never store the password itself). If you sign in with Google, we receive your email address and basic profile information from Google instead.
Information you configure
The brand you are measuring, its aliases and website, the competitors you track, the prompts you want run, and the ground-truth facts you supply about your own organisation. If you upload a file of ground-truth facts, we parse it and discard the original file — only the structured fact rows are stored.
Your website, and documents you upload
When you enter your website during onboarding, we fetch and analyse pages from that site — the homepage plus a small number of same-site pages linked from it — to pre-fill your brand name, aliases, suggested prompts, ground-truth facts, and brand colours. The fetch is restricted to the public web address you gave us.
Ground-truth documents you upload (PDF, XLSX, DOCX, CSV, TSV, TXT or Markdown) are parsed to text, and that extracted text is sent to a third-party AI model to propose structured fact rows, which you then review. As above, the original file is discarded — only the fact rows you keep are stored.
Information we generate
The responses AI models give to your prompts, the brand mentions and citations we extract from them, the accuracy verdicts we compute, and your scores over time.
Usage and analytics
We use Google Analytics via Google Tag Manager, and automatically collect device and browser information, IP address, pages viewed, referring URLs and similar usage data.On both this website and the signed-in application, all four Consent Mode v2 signals — analytics storage, advertising storage, advertising user data and ad personalisation — are declared denied before any Google tag loads. Nothing is granted until you choose to allow it in the cookie notice, and choosing to keep it off is a single click that carries the same weight. Our analytics events are designed to carry no personal data — no email addresses, names or passwords are sent in any event parameter.
Payment information
Payments are handled by Stripe. We never receive or store your card number.We store an identifier linking your account to your Stripe customer and subscription records.
How we use it
To provide, maintain and improve the Service; process payments and manage your subscription; respond to support requests; send administrative communications (billing notices, security alerts, Terms updates, report-ready and export-ready notifications); send product or marketing communications where permitted, which you can opt out of at any time; monitor and improve site and Service performance and security; and comply with legal obligations.
Legal bases (EEA/UK). Where the GDPR applies we rely on: performance of a contract (providing the Service you signed up for); our legitimate interests (improving and securing the Service, and direct marketing to business contacts, subject to your right to object); your consent, where we ask for it — for example analytics cookies and marketing email; and legal obligation, for example tax and accounting records.
Who we share it with
We use the following processors:
- AI model providers (OpenAI, Anthropic, Google, Perplexity) — running the service means sending content to these providers. Specifically: the prompts we run on your behalf (which contain your brand name, competitor names and the query text); the model answers we collect, sent on to a second model for claim extraction; yourground-truth facts — individually as evidence, and as a whole corpus — sent to a model to adjudicate accuracy claims, and their text sent to an embeddings API for matching; the pages we fetch from your website and the text of any ground-truth document you upload, sent to Anthropic for structured extraction during onboarding; and your report content, sent to a model to write the report’s prose summaries. We donot send them your account credentials or your billing details.
- Stripe — payment processing and subscription billing.
- Resend — transactional email. It receives your name and email address whenever we send you a service email (for example, a report-ready or export-ready notification).
- DigitalOcean — hosting, managed database, and object storage for your generated reports and database backups.
- Google — Analytics and Tag Manager, subject to your consent.
- Sentry — error monitoring.
We also disclose information:
- to professional advisors — lawyers and auditors — as needed;
- for legal and safety purposes — to comply with law, respond to lawful requests, or protect the rights, property or safety of Grail Analytics, our customers, or others; and
- in a business transfer — if we are involved in a merger, acquisition or asset sale, information may transfer as part of that transaction, subject to this notice or a successor notice with notice to you.
[COUNSEL] — this processor list needs confirming against the signed contracts, together with the legal basis for any transfer outside your jurisdiction and the applicable standard contractual clauses. The transfer mechanics for Customer Data specifically are in theDPA; this marker covers our own controller-side processing.
[COUNSEL] — whether we can state that we do not “sell” or “share” personal information needs deciding, not asserting, and the supplied draft asserted it. Under the CPRA those words have statutory definitions that reach cross-context behavioural advertising, and the product both runs Google Tag Manager and emitsad_storage, ad_user_data and ad_personalization consent signals. Any statement here — and any accompanying opt-out mechanism — has to be written against the regimes we actually fall under. Until it is, this notice makes no such statement.
International transfers
We are a Massachusetts, USA company, and information we collect may be processed in the United States and in other countries where our service providers operate. Where we transfer personal data out of the EEA, UK or Switzerland, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses, as described further in theDPA.
How long we keep it
We keep your data for as long as your account is active. When you request deletion, we remove your live records within 30 days and purge them from backupswithin 90 days. Account and billing data is retained for the life of your account plus a period afterwards to satisfy legal and accounting requirements.
One exception: our operator audit log is append-only by design, so those rows are not deleted. Instead, your identifying fields inside them are replaced with a stable opaque identifier, so the audit trail stays intact without a live link to your deleted account. Records held by Stripe remain subject to Stripe’s own retention policy.
Your rights
You can export your data at any time from your account — you get a ZIP of structured JSON covering your prompts, runs, model responses, citations, accuracy verdicts, ground-truth facts, and report records, plus the rendered reports themselves.
Four things are excluded from the export by design, and the ZIP’s own README says so:
- Ground-truth source files — uploads are parsed and discarded at ingest, so only the structured fact rows exist; those are exported.
- Embedding vectors — machine-internal representations, excluded from every file.
- Operator test-lab (experimental) runs and the rows derived from them.
- Claim verdicts that are not in an approved or auto-approved review state, and operator-only debug payloads. A verdict still awaiting review is not in your export.
You can request deletion of your account and data from your account settings, subject to the timelines above.
Depending on where you live, you may also have rights to access, correct, restrict or object to certain processing, and to withdraw consent where processing is based on consent. To exercise these rights, email hello@grailanalytics.ai. If you are in the EEA or UK you also have the right to lodge a complaint with your local data protection supervisory authority.
[COUNSEL] — the statutory rights list needs writing to the regimes we actually fall under rather than enumerated generically, along with our response-time commitment. The export and deletion mechanisms above are built and their timelines are real; what is open is which statutory rights we are asserting and how fast we promise to answer.
Cookies
We set a session cookie and a security token that are necessary for you to stay signed in — these cannot be switched off. Your consent choice itself is not stored in a cookie: it is kept in your browser’s local storage, under the keyai_vis_consent. Analytics cookies are set only after you accept them, and you can decline without losing any product functionality.
Changing your mind is as easy as the original choice. — it takes effect immediately, with no confirmation step and no account required.
Security
We use technical and organisational measures designed to protect information against unauthorised access, loss or misuse. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Children’s privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children under 16.
Changes to this notice
We may update this notice from time to time. For material changes we will provide notice as described in Section 12 of the Terms of Service. The “Last updated” date above reflects the most recent revision.
Contact
Questions about this notice or your data: hello@grailanalytics.ai.[COUNSEL] — a dedicated privacy contact and, if required, a Data Protection Officer should be named here.