Privacy Policy
Effective date: October 8, 2026
This Privacy Policy explains what we collect, why we collect it, and the choices you have when you use the Grail sold-comps API and website (the “Service”).
1. What we collect
- Account data: email address and authentication identifiers when you sign up.
- API usage data: API key identifiers, request timestamps, endpoints, keywords, request counts, and response times — used for quotas, billing, abuse prevention, and reliability.
- Billing data: handled by Stripe; we do not store your full card number.
- Basic technical data: IP address and user agent for security and rate limiting.
2. How we use it
To provide and operate the Service, meter usage and bill for paid plans, enforce quotas and prevent abuse, maintain reliability, and communicate with you about your account.
3. Sharing
We use service providers (for example Stripe for payments, Supabase for authentication, and cloud hosting) that process data on our behalf. We do not sell your personal data.
4. Cookies
We use minimal cookies/local storage for session and authentication. We do not use third-party advertising trackers.
5. Retention
Account data is kept while your account is active and for a reasonable period afterward, as needed for legal and billing purposes. API usage records are retained for billing and reliability.
6. Security
We use encryption in transit, hashed API keys, and access controls. No system is perfectly secure — use strong credentials and keep your keys secret.
7. Your rights
You may request access to, correction of, or deletion of your account data by emailing support@grail.solutions. You can delete or rotate API keys from your dashboard at any time.
8. Children
The Service is not directed to children under 13.
9. Changes
We may update this policy; material changes will be posted here with a new effective date.