Privacy Policy

Last updated: August 13, 2026

This page describes what the software actually does. Where it states a legal position, that position is ours and has not yet been reviewed by counsel.

Two different groups of people

This policy covers two populations, and the difference matters. CUSTOMERS sign up, agree to these terms, and give us their data on purpose. AUTHORS are the people whose posts we read in the groups our customers monitor. They did not sign up and were never asked. Most of the data in GrapeWire belongs to the second group, so most of this page is about them.

1. What we hold about customers

Your name and email address, a one-way hash of your password (never the password), your interface language, the groups and rules you configured, the alert destinations you set up — including the webhook URLs and addresses you paste in, which are stored so we can deliver to them — and a log of significant actions in your workspace. If you pay us, Stripe holds your card details and we hold their customer and subscription identifiers; we never see the card.

2. What we hold about post authors

For every post we ingest: the author name as it is displayed on the platform, the text of the post, a link to it, the time it was posted, and the score our model gave it. For a short period we also keep the raw response the platform returned. We do not go looking for anything else — no email addresses, no phone numbers, no friend lists, no profile pages — and we do not combine posts into a profile of a person. If an author put a phone number in the post itself, it is in the post we stored, and it is deleted with it.

3. Why we are allowed to do that

For customers, we process data to provide a service they asked for (a contract). For post authors, we rely on legitimate interests: a business monitoring public and semi-public conversations to find people asking for the service it provides. We think that interest is real, that the data is limited to what a person chose to post in a group, and that our retention and deletion rules keep the impact proportionate. If you are an author and you disagree, section 7 tells you how to object — and objection is not a request we weigh, it is one we act on.

4. How the groups are read

Facebook groups are read by accounts that we operate, not by yours: there is no field in GrapeWire for a customer's social media login and there will not be. Those accounts join and read groups the way a member does. Reddit is read through its public interface. We do not bypass access controls, and we do not read anything a member of that group could not read.

5. Who else sees it

Post text and the author name are sent to a language model provider (OpenRouter, or Anthropic) for scoring, unless the deployment turns that off. Alerts are delivered to the destination the customer chose — Slack, Discord, Microsoft Teams, Google Chat, email, ntfy, or their own webhook — and once delivered, that data is in a system we do not control. Stripe processes payments. Our hosting provider stores the database. We do not sell data, we do not run advertising, and we do not share data with anyone else.

6. How long we keep it

Ingested posts are deleted 90 days after they were posted, automatically, whether or not anyone read them. The raw platform response is deleted after 7 days. Alerts we already delivered are not reachable by that deletion — they are in the customer's own Slack or inbox. Customer data lives as long as the workspace does: deleting a workspace deletes its users, sources, rules, posts, matches and audit log immediately. Support messages and payment records are kept beyond that because we need them to answer a dispute.

7. Your rights, and how to actually use them

Customers can export everything in their workspace as one file, and can delete the whole workspace, from inside the product — no request, no waiting. Post authors can write to hello@grapewire.co: we will delete every post of yours we hold and add you to a suppression list so that we do not ingest you again, and we will confirm when it is done. We cannot reach alerts already delivered to a customer, copies held by the model provider under their own retention, or backups until they age out — we will tell you that rather than imply otherwise. You may also ask what we hold, ask us to correct it, or complain to your data protection authority (in Türkiye, KVKK; in the EU, your national authority).

8. Security

Traffic to GrapeWire is encrypted in transit. Workspace data is separated at the application layer and every query is scoped to the workspace of the signed-in user; that separation is covered by automated tests that run on every change. Passwords are stored as bcrypt hashes. Alert destinations, including webhook URLs, are stored in the database without additional application-level encryption — anyone with database access can read them, and that access is limited to the people who operate the service. We say this plainly because a claim of 'industry-standard encryption' would be easier to write and less true.

9. Contact

Privacy questions and erasure requests: hello@grapewire.co. Everything else: hello@grapewire.co. We answer erasure requests within 30 days and usually much sooner.