Privacy Policy

Effective Date: July 31, 2026 · Version 1.2

Previous version (1.1): July 11, 2026

Key Points at a Glance

Before diving into the details, here are the most important things to know:

  • We do NOT allow third-party AI providers (Groq, Google Gemini) to use your data to train their models.
  • We do NOT sell your personal information.
  • Your notes, recordings, and meeting data are private and accessible only to you.
  • Audio recordings are stored securely and can be deleted at any time — deletion is permanent.
  • All data is encrypted at rest (AES-256) and in transit (TLS 1.3).
  • We are committed to GDPR, CCPA/CPRA, and applicable data privacy regulations.

Introduction

Grafite Labs LLC ("Grafite," "we," "our," or "us"), a New Jersey limited liability company, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our meeting notes application, website, and related services (collectively, the "Service"), including our web application, optional desktop helper application, and any associated APIs.

By using Grafite, you consent to the data practices described in this policy. If you do not agree with our policies and practices, please do not use our Service. Your use of our Service is also subject to our Terms of Service.

"Personal Data" means any information that identifies or relates to a particular individual and includes information referred to as "personally identifiable information" or "personal information" under applicable data privacy laws.

Information We Collect

Account Information

When you create an account via Google or Microsoft OAuth, we collect:

  • Email address
  • Name (from your authentication provider)
  • Profile picture (from your authentication provider)
  • Authentication tokens for connected services

Meeting and Audio Data

When you use our recording features, we collect:

  • Audio recordings of your meetings (only when you choose to record)
  • Transcriptions generated from your audio recordings
  • AI-generated summaries and notes from your meetings
  • Action items and tasks extracted from meeting content
  • Meeting metadata (title, date, duration, participants)

Calendar Data

If you connect your Google Calendar or Microsoft Outlook, we access:

  • Calendar event details (title, time, location, attendees)
  • Meeting links and conference information
  • Attendee names and email addresses

Conversational AI Data (Ask Grafi)

When you use Ask Grafi, our conversational AI feature, we process:

  • Your questions and queries
  • Conversation history within a session
  • Related notes, meetings, and data referenced to generate answers

Forms and Feedback Data

When you create or respond to forms:

  • Form structure, questions, and configurations
  • Responses submitted by you or your respondents
  • Voice recordings submitted through forms (if applicable)

People and Relationship Data

We automatically build a people directory from your meeting activity:

  • Contact names and email addresses from calendar events and meetings
  • Meeting history and interaction frequency
  • Notes and context you add about contacts

Usage and Device Information

We automatically collect:

  • Device type, operating system, and browser information
  • IP address and approximate location derived from IP
  • App usage patterns and feature interactions
  • Referring webpage or source through which you accessed the Service

Desktop Helper Application

If you use the optional Grafite desktop helper application:

  • The helper captures system audio on your device to enable recording of meeting audio output
  • Audio is processed locally and transmitted to our servers for transcription
  • The helper does not collect additional personal information beyond what is described in this policy

How We Use Your Information

We use your information for the following purposes:

  • Providing the Service: Operate, maintain, and deliver the core features including recording, transcription, summarization, and search
  • AI Processing: Process audio recordings through transcription and generate AI summaries and action items
  • Conversational AI: Power the Ask Grafi feature by querying your stored data to provide cited answers
  • Calendar Sync: Sync with your calendar to display upcoming meetings and provide relationship context
  • People Tracking: Build and maintain your personal contacts directory from meeting data
  • Communication: Send you service-related notices, updates, and support responses
  • Security: Detect, prevent, and address security issues, fraud, and technical problems
  • Improvement: Analyze usage patterns to improve and personalize the Service (using aggregated, de-identified data only)

AI Processing & Data Protection

This is important: Grafite uses third-party AI services to process your data. We want you to understand exactly how this works:

Enterprise AI Agreements

We have enterprise-grade agreements in place with all our AI providers that explicitly prohibit the use of your data for training their AI models. This means:

  • Your recordings are NOT used to train AI models
  • Your transcripts are NOT used to train AI models
  • Your meeting content remains YOUR private data
  • AI providers process your data solely to deliver the service and then discard it

How AI Processing Works

  1. Transcription: Audio is sent to Groq's Whisper API, transcribed, and immediately discarded by Groq after processing
  2. Summarization: Transcripts are sent to Google Gemini for summary generation under enterprise terms with no data retention
  3. Conversational AI: When you use Ask Grafi, your questions and relevant meeting data are sent to Google Gemini to generate answers, under the same enterprise terms
  4. Storage: Only the resulting transcripts, summaries, and AI-generated content are stored in your Grafite account

De-Identified and Aggregated Data

We may create de-identified, aggregated data from the information we collect that does not identify you personally. We may use such data for lawful business purposes, including to analyze, improve, and develop the Service. De-identified data cannot be used to re-identify you.

Your Control

You can delete any recording, transcript, summary, note, or conversation at any time. Deletion is permanent and removes the data from our systems. You can also delete your entire account, which removes all associated data within 30 days.

Data Storage & Security

Where Your Data Is Stored

Your data is stored securely using Supabase (built on PostgreSQL) with servers located in the United States. Audio files are stored in encrypted cloud storage. The web application is hosted on Vercel.

Security Measures

We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • OAuth 2.0 with PKCE for secure authentication
  • Row-level security (RLS) ensuring users can only access their own data
  • Token encryption for connected services (Google Calendar, Microsoft Outlook)
  • Regular security monitoring and vulnerability assessment
  • Secure API endpoints with authentication and rate limiting

While we work to protect the security of your data, no method of transmitting or storing data is completely secure. We cannot guarantee absolute security.

Sub-Processors & Service Providers

We use the following categories of service providers to deliver the Service:

ProviderPurposeData Processed
GroqAudio transcription (Whisper)Audio recordings (discarded after processing)
Google (Gemini)AI summarization and conversational AITranscripts, meeting content, queries (not retained)
SupabaseDatabase and authenticationAccount data, notes, transcripts, all stored content
VercelApplication hosting and CDNWeb traffic, IP addresses
Google / MicrosoftOAuth and calendar integrationAuthentication tokens, calendar events

All sub-processors are bound by contractual obligations to protect your data and are prohibited from using it for their own purposes.

Data Sharing & Disclosure

We do NOT sell your Personal Data. We do NOT share your Personal Data for cross-context behavioral advertising. We disclose data only in the following circumstances:

  • Service Providers: With the sub-processors listed above, solely to provide the Service under contractual protections
  • Legal Requirements: When required by law, subpoena, court order, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others
  • Business Transfers: If Grafite is involved in a merger, acquisition, reorganization, bankruptcy, or sale of assets, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on our website before your data becomes subject to a different privacy policy
  • With Your Consent: When you explicitly authorize sharing, such as sharing a form or booking link

Data Retention

We retain your Personal Data for as long as your account is active and as needed to provide you with the Service. Specific retention practices include:

  • Account data: Retained while your account is active
  • Notes, transcripts, and summaries: Retained until you delete them or close your account
  • Audio recordings: Retained until you delete them or close your account
  • Usage analytics: Anonymized analytics data may be retained for up to 90 days
  • Account deletion: If you delete your account, all associated Personal Data will be permanently removed within 30 days, except where retention is required by law

You can delete individual notes, recordings, transcripts, people entries, and conversations at any time from within the app. Deletion is immediate and permanent.

Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve the Service. Here is what we use:

  • Essential Cookies: Required for authentication, session management, and core functionality. These cannot be disabled without breaking the Service.
  • Functional Cookies: Used to remember your preferences (such as theme selection) across sessions.
  • Analytics: We use privacy-focused, anonymized analytics on our marketing pages. We do not use third-party tracking cookies or advertising cookies. Our analytics do not track you across other websites.

You can control cookie preferences through our cookie consent banner on the marketing site. You can also manage cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.

Your Rights

Depending on your location, you may have the following rights regarding your Personal Data:

  • Access: Request a copy of the Personal Data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your Personal Data
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to certain processing activities
  • Restriction: Request restriction of processing
  • Withdrawal of Consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at privacy@grafite.io. We will respond to verified requests within 30 days (or sooner as required by applicable law).

European Union, United Kingdom & Swiss Data Rights (GDPR)

If you are located in the EU, UK, Liechtenstein, Norway, Iceland, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).

Legal Basis for Processing

We process your Personal Data under the following legal bases:

  • Contractual Necessity: Processing necessary to provide you with the Service, including account management, recording, transcription, and AI features (GDPR Art. 6(1)(b))
  • Legitimate Interest: Processing necessary for our legitimate interests, such as improving the Service, ensuring security, and preventing fraud, where those interests are not overridden by your rights (GDPR Art. 6(1)(f))
  • Consent: Where you have given explicit consent, such as connecting calendar integrations or opting into analytics (GDPR Art. 6(1)(a))
  • Legal Obligation: Where processing is necessary to comply with applicable law (GDPR Art. 6(1)(c))

Data Controller

Grafite Labs LLC is the data controller for Personal Data processed in connection with the Service. For questions about your data, contact privacy@grafite.io.

Data Processing Agreement

If your use of Grafite involves processing Personal Data of others (such as meeting participants), you act as the data controller and Grafite acts as the data processor. We offer a Data Processing Agreement (DPA) incorporating EU and UK Standard Contractual Clauses. To request a DPA, contact legal@grafite.io.

Right to Lodge a Complaint

You have the right to lodge a complaint with your local supervisory authority if you believe our processing of your Personal Data violates the GDPR.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).

Your California Rights

  • Right to Know: You can request the categories and specific pieces of Personal Data we have collected about you, the sources of collection, the purposes, and the categories of third parties with whom we share it
  • Right to Delete: You can request deletion of your Personal Data, subject to certain exceptions
  • Right to Correct: You can request correction of inaccurate Personal Data
  • Right to Opt-Out of Sale or Sharing: We do not sell your Personal Data or share it for cross-context behavioral advertising, so there is no need to opt out
  • Right to Limit Use of Sensitive Personal Information: You can request that we limit our use of sensitive Personal Data to what is necessary to provide the Service
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

Categories of Personal Data Collected

In the preceding 12 months, we may have collected the following categories of Personal Data:

  • Identifiers (name, email address, IP address, account ID)
  • Internet or electronic network activity (usage data, browser type, interactions with the Service)
  • Audio information (meeting recordings, voice notes)
  • Professional information (meeting attendees, calendar data)
  • Inferences drawn from the above (AI-generated summaries, relationship insights)

How to Exercise Your Rights

Submit requests to privacy@grafite.io with the subject line "CCPA Request." We will verify your identity before processing your request. You may also designate an authorized agent to submit requests on your behalf. We will respond within 45 days.

Other U.S. State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and port their Personal Data, as well as the right to opt out of certain processing activities. We do not sell personal data or engage in targeted advertising as defined by these laws.

Nevada residents: We do not sell your Personal Data as defined by Nevada Revised Statutes Chapter 603A. You may submit an opt-out request to privacy@grafite.io.

To exercise rights under any applicable state law, contact privacy@grafite.io.

International Data Transfers

Our Service is hosted in the United States. If you access Grafite from outside the United States, your Personal Data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers from the EU, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms as appropriate. By using our Service, you consent to the transfer of your data to the United States.

Children's Privacy

Grafite is not intended for children under 16 years of age. We do not knowingly collect or solicit Personal Data from children under 16. If we learn that we have collected Personal Data from a child under 16, we will delete that information as quickly as possible. If you believe a child under 16 has provided us with Personal Data, please contact us immediately at privacy@grafite.io.

Do Not Track Signals

Our Service does not respond to "Do Not Track" browser signals. However, we do not engage in cross-site tracking, and our analytics are privacy-focused and anonymized as described in the Cookies section above.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:

  • Updating the "Effective Date" and version number at the top of this page
  • Displaying an in-app consent prompt requiring re-acceptance
  • Sending an email notification for significant changes (where we have your email)

We encourage you to review this policy periodically. Previous versions are referenced at the top of this page for transparency.

Contact Us

If you have questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us:

Grafite Labs LLC
2 University Plaza Dr, Suite 100R
Hackensack, NJ 07601
United States

Privacy Inquiries: privacy@grafite.io
Legal & DPA Requests: legal@grafite.io
Website: https://grafite.io