Privacy Policy
Effective Date: July 31, 2026 · Version 1.2
Previous version (1.1): July 11, 2026
Key Points at a Glance
Before diving into the details, here are the most important things to know:
- We do NOT allow third-party AI providers (Groq, Google Gemini) to use your data to train their models.
- We do NOT sell your personal information.
- Your notes, recordings, and meeting data are private and accessible only to you.
- Audio recordings are stored securely and can be deleted at any time — deletion is permanent.
- All data is encrypted at rest (AES-256) and in transit (TLS 1.3).
- We are committed to GDPR, CCPA/CPRA, and applicable data privacy regulations.
Introduction
Grafite Labs LLC ("Grafite," "we," "our," or "us"), a New Jersey limited liability company, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our meeting notes application, website, and related services (collectively, the "Service"), including our web application, optional desktop helper application, and any associated APIs.
By using Grafite, you consent to the data practices described in this policy. If you do not agree with our policies and practices, please do not use our Service. Your use of our Service is also subject to our Terms of Service.
"Personal Data" means any information that identifies or relates to a particular individual and includes information referred to as "personally identifiable information" or "personal information" under applicable data privacy laws.
Information We Collect
Account Information
When you create an account via Google or Microsoft OAuth, we collect:
- Email address
- Name (from your authentication provider)
- Profile picture (from your authentication provider)
- Authentication tokens for connected services
Meeting and Audio Data
When you use our recording features, we collect:
- Audio recordings of your meetings (only when you choose to record)
- Transcriptions generated from your audio recordings
- AI-generated summaries and notes from your meetings
- Action items and tasks extracted from meeting content
- Meeting metadata (title, date, duration, participants)
Calendar Data
If you connect your Google Calendar or Microsoft Outlook, we access:
- Calendar event details (title, time, location, attendees)
- Meeting links and conference information
- Attendee names and email addresses
Conversational AI Data (Ask Grafi)
When you use Ask Grafi, our conversational AI feature, we process:
- Your questions and queries
- Conversation history within a session
- Related notes, meetings, and data referenced to generate answers
Forms and Feedback Data
When you create or respond to forms:
- Form structure, questions, and configurations
- Responses submitted by you or your respondents
- Voice recordings submitted through forms (if applicable)
People and Relationship Data
We automatically build a people directory from your meeting activity:
- Contact names and email addresses from calendar events and meetings
- Meeting history and interaction frequency
- Notes and context you add about contacts
Usage and Device Information
We automatically collect:
- Device type, operating system, and browser information
- IP address and approximate location derived from IP
- App usage patterns and feature interactions
- Referring webpage or source through which you accessed the Service
Desktop Helper Application
If you use the optional Grafite desktop helper application:
- The helper captures system audio on your device to enable recording of meeting audio output
- Audio is processed locally and transmitted to our servers for transcription
- The helper does not collect additional personal information beyond what is described in this policy
How We Use Your Information
We use your information for the following purposes:
- Providing the Service: Operate, maintain, and deliver the core features including recording, transcription, summarization, and search
- AI Processing: Process audio recordings through transcription and generate AI summaries and action items
- Conversational AI: Power the Ask Grafi feature by querying your stored data to provide cited answers
- Calendar Sync: Sync with your calendar to display upcoming meetings and provide relationship context
- People Tracking: Build and maintain your personal contacts directory from meeting data
- Communication: Send you service-related notices, updates, and support responses
- Security: Detect, prevent, and address security issues, fraud, and technical problems
- Improvement: Analyze usage patterns to improve and personalize the Service (using aggregated, de-identified data only)
AI Processing & Data Protection
This is important: Grafite uses third-party AI services to process your data. We want you to understand exactly how this works:
Enterprise AI Agreements
We have enterprise-grade agreements in place with all our AI providers that explicitly prohibit the use of your data for training their AI models. This means:
- Your recordings are NOT used to train AI models
- Your transcripts are NOT used to train AI models
- Your meeting content remains YOUR private data
- AI providers process your data solely to deliver the service and then discard it
How AI Processing Works
- Transcription: Audio is sent to Groq's Whisper API, transcribed, and immediately discarded by Groq after processing
- Summarization: Transcripts are sent to Google Gemini for summary generation under enterprise terms with no data retention
- Conversational AI: When you use Ask Grafi, your questions and relevant meeting data are sent to Google Gemini to generate answers, under the same enterprise terms
- Storage: Only the resulting transcripts, summaries, and AI-generated content are stored in your Grafite account
De-Identified and Aggregated Data
We may create de-identified, aggregated data from the information we collect that does not identify you personally. We may use such data for lawful business purposes, including to analyze, improve, and develop the Service. De-identified data cannot be used to re-identify you.
Your Control
You can delete any recording, transcript, summary, note, or conversation at any time. Deletion is permanent and removes the data from our systems. You can also delete your entire account, which removes all associated data within 30 days.
Data Storage & Security
Where Your Data Is Stored
Your data is stored securely using Supabase (built on PostgreSQL) with servers located in the United States. Audio files are stored in encrypted cloud storage. The web application is hosted on Vercel.
Security Measures
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- OAuth 2.0 with PKCE for secure authentication
- Row-level security (RLS) ensuring users can only access their own data
- Token encryption for connected services (Google Calendar, Microsoft Outlook)
- Regular security monitoring and vulnerability assessment
- Secure API endpoints with authentication and rate limiting
While we work to protect the security of your data, no method of transmitting or storing data is completely secure. We cannot guarantee absolute security.
Sub-Processors & Service Providers
We use the following categories of service providers to deliver the Service:
| Provider | Purpose | Data Processed |
|---|---|---|
| Groq | Audio transcription (Whisper) | Audio recordings (discarded after processing) |
| Google (Gemini) | AI summarization and conversational AI | Transcripts, meeting content, queries (not retained) |
| Supabase | Database and authentication | Account data, notes, transcripts, all stored content |
| Vercel | Application hosting and CDN | Web traffic, IP addresses |
| Google / Microsoft | OAuth and calendar integration | Authentication tokens, calendar events |
All sub-processors are bound by contractual obligations to protect your data and are prohibited from using it for their own purposes.
Data Sharing & Disclosure
We do NOT sell your Personal Data. We do NOT share your Personal Data for cross-context behavioral advertising. We disclose data only in the following circumstances:
- Service Providers: With the sub-processors listed above, solely to provide the Service under contractual protections
- Legal Requirements: When required by law, subpoena, court order, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others
- Business Transfers: If Grafite is involved in a merger, acquisition, reorganization, bankruptcy, or sale of assets, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on our website before your data becomes subject to a different privacy policy
- With Your Consent: When you explicitly authorize sharing, such as sharing a form or booking link
Data Retention
We retain your Personal Data for as long as your account is active and as needed to provide you with the Service. Specific retention practices include:
- Account data: Retained while your account is active
- Notes, transcripts, and summaries: Retained until you delete them or close your account
- Audio recordings: Retained until you delete them or close your account
- Usage analytics: Anonymized analytics data may be retained for up to 90 days
- Account deletion: If you delete your account, all associated Personal Data will be permanently removed within 30 days, except where retention is required by law
You can delete individual notes, recordings, transcripts, people entries, and conversations at any time from within the app. Deletion is immediate and permanent.
Cookies & Tracking Technologies
We use cookies and similar technologies to operate and improve the Service. Here is what we use:
- Essential Cookies: Required for authentication, session management, and core functionality. These cannot be disabled without breaking the Service.
- Functional Cookies: Used to remember your preferences (such as theme selection) across sessions.
- Analytics: We use privacy-focused, anonymized analytics on our marketing pages. We do not use third-party tracking cookies or advertising cookies. Our analytics do not track you across other websites.
You can control cookie preferences through our cookie consent banner on the marketing site. You can also manage cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.
Your Rights
Depending on your location, you may have the following rights regarding your Personal Data:
- Access: Request a copy of the Personal Data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your Personal Data
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to certain processing activities
- Restriction: Request restriction of processing
- Withdrawal of Consent: Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at privacy@grafite.io. We will respond to verified requests within 30 days (or sooner as required by applicable law).
European Union, United Kingdom & Swiss Data Rights (GDPR)
If you are located in the EU, UK, Liechtenstein, Norway, Iceland, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).
Legal Basis for Processing
We process your Personal Data under the following legal bases:
- Contractual Necessity: Processing necessary to provide you with the Service, including account management, recording, transcription, and AI features (GDPR Art. 6(1)(b))
- Legitimate Interest: Processing necessary for our legitimate interests, such as improving the Service, ensuring security, and preventing fraud, where those interests are not overridden by your rights (GDPR Art. 6(1)(f))
- Consent: Where you have given explicit consent, such as connecting calendar integrations or opting into analytics (GDPR Art. 6(1)(a))
- Legal Obligation: Where processing is necessary to comply with applicable law (GDPR Art. 6(1)(c))
Data Controller
Grafite Labs LLC is the data controller for Personal Data processed in connection with the Service. For questions about your data, contact privacy@grafite.io.
Data Processing Agreement
If your use of Grafite involves processing Personal Data of others (such as meeting participants), you act as the data controller and Grafite acts as the data processor. We offer a Data Processing Agreement (DPA) incorporating EU and UK Standard Contractual Clauses. To request a DPA, contact legal@grafite.io.
Right to Lodge a Complaint
You have the right to lodge a complaint with your local supervisory authority if you believe our processing of your Personal Data violates the GDPR.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
Your California Rights
- Right to Know: You can request the categories and specific pieces of Personal Data we have collected about you, the sources of collection, the purposes, and the categories of third parties with whom we share it
- Right to Delete: You can request deletion of your Personal Data, subject to certain exceptions
- Right to Correct: You can request correction of inaccurate Personal Data
- Right to Opt-Out of Sale or Sharing: We do not sell your Personal Data or share it for cross-context behavioral advertising, so there is no need to opt out
- Right to Limit Use of Sensitive Personal Information: You can request that we limit our use of sensitive Personal Data to what is necessary to provide the Service
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Categories of Personal Data Collected
In the preceding 12 months, we may have collected the following categories of Personal Data:
- Identifiers (name, email address, IP address, account ID)
- Internet or electronic network activity (usage data, browser type, interactions with the Service)
- Audio information (meeting recordings, voice notes)
- Professional information (meeting attendees, calendar data)
- Inferences drawn from the above (AI-generated summaries, relationship insights)
How to Exercise Your Rights
Submit requests to privacy@grafite.io with the subject line "CCPA Request." We will verify your identity before processing your request. You may also designate an authorized agent to submit requests on your behalf. We will respond within 45 days.
Other U.S. State Privacy Rights
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and port their Personal Data, as well as the right to opt out of certain processing activities. We do not sell personal data or engage in targeted advertising as defined by these laws.
Nevada residents: We do not sell your Personal Data as defined by Nevada Revised Statutes Chapter 603A. You may submit an opt-out request to privacy@grafite.io.
To exercise rights under any applicable state law, contact privacy@grafite.io.
International Data Transfers
Our Service is hosted in the United States. If you access Grafite from outside the United States, your Personal Data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
For transfers from the EU, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms as appropriate. By using our Service, you consent to the transfer of your data to the United States.
Children's Privacy
Grafite is not intended for children under 16 years of age. We do not knowingly collect or solicit Personal Data from children under 16. If we learn that we have collected Personal Data from a child under 16, we will delete that information as quickly as possible. If you believe a child under 16 has provided us with Personal Data, please contact us immediately at privacy@grafite.io.
Do Not Track Signals
Our Service does not respond to "Do Not Track" browser signals. However, we do not engage in cross-site tracking, and our analytics are privacy-focused and anonymized as described in the Cookies section above.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Updating the "Effective Date" and version number at the top of this page
- Displaying an in-app consent prompt requiring re-acceptance
- Sending an email notification for significant changes (where we have your email)
We encourage you to review this policy periodically. Previous versions are referenced at the top of this page for transparency.
Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us:
Grafite Labs LLC
2 University Plaza Dr, Suite 100R
Hackensack, NJ 07601
United States
Privacy Inquiries: privacy@grafite.io
Legal & DPA Requests: legal@grafite.io
Website: https://grafite.io