Privacy Policy
How Grayy treats what it learns about you.
Effective 5 October 2026
Grayy makes long-form reads shaped around what you want to understand. To do that it keeps a profile of how you like to read, and it sends parts of that profile to AI models. This page says plainly what we collect, what the models see, who else handles your data, how long we keep it, and how you delete it. Questions go to hello@grayy.io.
What we collect
- Account. Your email address, your name and profile photo if you sign in with Google, and how you signed in. Sign-in is handled by Clerk; Grayy never sees or stores a password.
- Your reading profile. The answers you give during onboarding and edit on your Profile page: your role and field, what you already know, how you like to think, what you are curious about, and your reading preferences.
- Reading activity. Which reads you open, finish or set aside, the chapter you are on, and bookmarks. Individual reading events are kept for 30 days.
- What you write. Notes and highlights, your side of the Discover conversation, and any topic you type.
- The reads Grayy makes for you, and the record of what it cost to make them.
- Technical data collected by the providers that run Grayy: IP address, browser and device type, and request logs used for security and reliability.
- Product analytics. Anonymous events such as “a page was opened”. They carry no account identifier, no free text and no precise location; IP-based location lookup is switched off.
How we use it
- To plan, write, check and personalise your reads.
- To remember where you are, what you saved, and what you have already covered.
- To keep Grayy secure, enforce the monthly limits on a plan, and fix what breaks.
- To understand, in aggregate, which parts of Grayy are used.
- To meet legal obligations and respond to lawful requests.
We do not sell your data, and we do not share it for advertising. Where a law asks for a legal basis, ours is the contract with you for the service itself, our legitimate interest in keeping it secure and improving it, and your consent for anything optional.
How Grayy uses AI
Every read in Grayy is written by AI models from the sources in Grayy’s library, with the passages it drew on cited inline. A second model, from a different provider, reviews each chapter and then the whole read before it is published. It can still be wrong; check anything you would act on against the source it cites.
To shape and write your reads, Grayy sends the models:
- a bounded summary of your reading profile, limited to the fields that shape a read;
- the topic you chose and your Discover conversation;
- passages from Grayy’s library.
Your notes, highlights and email address are never sent to a model. The models are provided by OpenAI and Anthropic, and search is powered by Voyage AI; they are named below. Grayy reaches them through their developer APIs, not their consumer apps. Grayy also keeps fixed safety checks in front of the models, including one that recognises when a reader may be in crisis and answers with real help instead of a read.
Who processes your data
Grayy is built on a small number of providers. Each one receives only what it needs for its job.
| Provider | What it does for Grayy | What reaches it |
|---|---|---|
| Clerk | Signs you in and keeps your session. Grayy never sees or stores your password. | Email address, name, sign-in method, and security logs such as IP address and device. |
| Offers “Continue with Google” sign-in when you choose it, and runs Grayy’s generation service on Google Cloud. | Your Google account email and name if you sign in with Google; the data the generation service handles while it runs. | |
| OpenAI | Provides the model that writes your reads. | The prompts described under “How Grayy uses AI”. |
| Anthropic | Provides the Claude models that plan reads, review them before they are published, and hold the Discover conversation. | The prompts described under “How Grayy uses AI”. |
| Voyage AI | Turns search queries into embeddings and reranks passages from Grayy’s source library. | Topic and section queries derived from your request. Never your profile, notes or conversation. |
| Vercel | Hosts the web application and serves it from its edge network. | Standard request logs: IP address, browser, pages requested. |
| Cloudflare | Stores your generated reads in private object storage (R2) and protects sign-up from bots (Turnstile). | The reads Grayy generates for you; browser signals used only to tell people from bots. |
| Resend | Delivers the email that tells you a read is ready, when that notification is switched on. | Your email address and the title of the read. |
| PostHog | Anonymous product analytics that tell us which parts of Grayy are used. | Event names and coarse properties only. No account identifier, no free text, and IP-based location lookup is disabled. |
| Managed Redis provider | Holds the short-lived counters that rate-limit requests. | Request counts keyed by an opaque account id. No content. |
| Managed PostgreSQL providers | Host Grayy’s databases. | Everything Grayy stores about your account, as described under “What we collect”. |
| Zilliz Cloud | Hosts the search index of Grayy’s source library. | None of your data. The index holds the books, papers and case studies reads are built from. |
Some of these providers operate in the United States and other countries, so your data may be processed outside the country you live in. Each handles it under its own terms and published security commitments.
How long we keep it
- Your account, profile, reads, notes and progress: for as long as you keep your account.
- Individual reading events: 30 days.
- An in-progress Discover conversation: in your own browser tab only, for up to 24 hours or until you start a new one. It is sent to a model to be answered, and it is not stored on our servers until you ask for the read.
- Provider logs (sign-in, hosting): on each provider’s standard short-term schedule.
Deleting your account
Write to hello@grayy.io from the email address on your account and ask for it to be deleted. Within 30 days we remove your sign-in record, everything in Grayy’s databases about you (profile, reads, notes, highlights and progress) and the stored copies of your generated reads. Backup copies held by our database providers expire on their normal rotation. Anonymous analytics cannot be traced back to you and are not affected.
Your rights
You can see and correct your profile on the Profile page, delete individual notes and highlights, and have your account deleted entirely. Where you live may also give you rights to a copy of your data, to object to certain processing, or to complain to a supervisory authority. Write to hello@grayy.io for any of these and we will answer within 30 days.
Security
Everything travels over HTTPS. Your generated reads live in private storage that is never exposed to the public internet, every request is checked against the account that owns the data, and Grayy holds no passwords. No system is perfect; if we learn of a breach that affects you, we will tell you.
Age
Grayy is for people aged 16 or older. If you believe a younger person has created an account, tell us and we will delete it.
Changes
When this policy changes in a way that matters, we will update the date above and say so inside Grayy before the change takes effect.