Legal

Privacy Policy

This Policy explains what personal information Grava collects, why we use it, when we disclose it, and the choices available to you.

Effective September 2, 2026

1. Scope and who we are

This Privacy Policy applies to the websites, applications, and hosted web-scraping services operated by Grava, Inc. (“Grava,” “we,” “us,” or “our”). It does not govern a third-party website that a customer directs Grava to access or another service that links to its own privacy policy.

For account, website, and business-contact information, Grava generally decides why and how the information is used. For personal information contained in target instructions or collected output, Grava generally processes that information on the customer’s behalf, and the customer is responsible for its collection and use.

2. Information we collect

We collect information you provide, information generated when you use the Services, and limited technical information collected automatically.

  • Account and identity information, such as your email address and, if you use a third-party sign-in option, the name, profile details, and authentication identifiers that provider makes available to us.
  • Service content, such as target URLs, Recipes, selectors, schedules, Checks, configuration, Run output, logs, errors, and Repair Proposals.
  • Communications, such as support requests, feedback, and other messages you send us.
  • Usage and device information, such as IP address, browser and device type, request timestamps, pages or features used, referring page, and diagnostic events.
  • Cookies and similar storage needed to authenticate you, maintain a secure session, remember settings, and operate the Services.
  • Billing and transaction information if paid features are offered. A payment processor may collect payment-card details directly; Grava does not need to store full card numbers.

3. Customer-directed collection

Customers choose the websites Grava accesses and the information a Recipe extracts. That output may include personal information available on a target site. Customers must have an appropriate legal basis and any required notices or permissions for that collection. If your information appears in customer-directed output, please contact the relevant Grava customer first; we will assist that customer as required by law and our agreement with them.

4. How we use information

We use personal information for the following purposes:

  • provide, operate, maintain, and support the Services;
  • authenticate accounts and protect the Services, users, and third parties from abuse, fraud, and security threats;
  • execute Recipes, produce and validate Run output, and prepare Repair Proposals;
  • diagnose failures, measure performance, and improve product reliability and usability;
  • communicate about the Services, respond to requests, and send important account or policy notices;
  • administer paid plans and business relationships; and
  • comply with law, enforce our agreements, and establish or defend legal claims.

5. How we disclose information

We disclose personal information only as needed for the purposes described in this Policy:

  • to infrastructure, database, authentication, email, security, support, and payment providers that process information for us under appropriate obligations;
  • to people within your organization and others you authorize;
  • to professional advisers and auditors where reasonably necessary;
  • to law enforcement, regulators, courts, or other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, and security; and
  • in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to customary safeguards.

6. Selling, advertising, and automated decisions

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use personal information to make decisions that produce legal or similarly significant effects about you. We will update this Policy and provide any required choices before materially changing those practices.

8. Retention

We keep personal information only as long as reasonably necessary for the purposes described here, including while an account is active and as needed to provide the Services, meet legal and accounting obligations, resolve disputes, and enforce agreements. Retention varies by data type and configuration. We may retain limited security logs and backups for a reasonable period after account deletion, after which they are deleted or de-identified through ordinary retention cycles.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls and encryption in transit. No system is completely secure, and we cannot guarantee absolute security. Please contact hello@grava.dev if you believe your account or information is at risk.

10. Your choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; to withdraw consent; or to appeal our response. You may also have the right to complain to your local privacy authority. We will not discriminate against you for exercising a privacy right.

To make a request, email hello@grava.dev. Tell us the right you want to exercise and the account or information involved. We may need to verify your identity and authority before acting. If Grava processes the information only for a customer, we may direct the request to that customer.

11. International transfers

Grava operates in the United States and may use providers in other countries. Your information may therefore be processed where privacy laws differ from those where you live. When required, we use recognized transfer mechanisms and contractual protections for international transfers.

12. Children

The Services are intended for business users and are not directed to children under 18. We do not knowingly collect personal information directly from children. If you believe a child provided personal information to us, contact hello@grava.dev so we can investigate and take appropriate action.

13. Changes to this Policy

We may update this Policy as the Services or law change. We will post the revised Policy with a new effective date and provide additional notice when a change is material. Earlier versions remain available to administrators through our content-management version history.

14. Contact us

For privacy questions, requests, or complaints, contact Grava at hello@grava.dev. Please do not include sensitive personal information in an unencrypted email.