Privacy Policy
GRID is a private AI workspace for organizations. Each organization (a “tenant”) runs its own isolated GRID that matures on that organization’s own data. This policy explains what data GRID accesses, why, how it is stored and protected, and the choices you have — with particular attention to data accessed through Google APIs.
In this policy, “GRID”, “we”, and “us” refer to the operator of GRID at thegrid.live. “You” means a person who connects an account to GRID on behalf of their organization.
GRID only accesses data you explicitly connect, and only for the scopes you approve on Google’s consent screen. When you link a Google account, GRID may request the following:
| Google scope | What it allows | Why GRID needs it |
|---|---|---|
userinfo.email |
Read the email address of the connected account. | To label the connection so you know which account is linked. |
gmail.compose |
Create and send drafts / messages on your behalf. | So a skill you enable (e.g. a job-application assistant) can draft and send messages you direct it to. |
gmail.readonly |
Read messages and metadata in the connected mailbox. | So a skill can read replies and confirmations relevant to a task you asked it to complete. |
GRID does not request access to your contacts, calendar, files, or any Google data beyond the scopes listed above. You are shown the exact scopes on Google’s consent screen before any access is granted, and you may decline.
Data obtained through Google APIs is used only to provide and improve the specific feature you connected it for — reading and composing messages at your direction inside your organization’s GRID. We do not use Gmail data for advertising, we do not sell it, and we do not use it to train generalized machine-learning or AI models.
Google Limited Use disclosure
GRID’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. GRID does not transfer or sell Google user data to third parties, does not use it for advertising, and does not allow humans to read it except (a) with your explicit consent (e.g. to debug or resolve an issue you report), (b) where required for security or to comply with applicable law, or (c) where the data has been aggregated and anonymized. Any AI/ML models are not developed, trained, or improved using your Gmail data.
GRID is multi-tenant by design, but tenant data is not pooled. Each organization’s connections, OAuth tokens, and content live in that organization’s own isolated database project — not in GRID’s shared infrastructure. Concretely:
We do not sell your data. We share it only with the infrastructure sub-processors required to run GRID (for example, our database and hosting providers), and only to the extent necessary to operate the service on your behalf. We may disclose data if required by law or to protect the security and integrity of the service.
You remain in control of any connection you make:
Access to tenant projects is restricted to privileged server-side credentials. Tokens and secrets are never returned to client code. Every change GRID makes on your behalf is logged and, where it affects your configuration, gated behind explicit human approval.
GRID is a workplace tool intended for organizations and is not directed to children under 13. We do not knowingly collect data from children.
We may update this policy as GRID evolves. Material changes will be reflected by updating the “Last updated” date at the top of this page.
Questions about this policy or requests regarding your data can be sent to team@thegrid.live.