Privacy Policy

Last updated 14 July 2026

Contents
  1. 1. Who we are
  2. 2. In plain terms
  3. 3. Data we collect
  4. 4. Google user data — how we access, use, store and share it
  5. 5. Why we process your data (legal bases)
  6. 6. Who we share data with
  7. 7. Your rights (if you are a Gritt user)
  8. 8. If you are an investor in our database
  9. 9. International transfers
  10. 10. How long we keep data
  11. 11. Security
  12. 12. Cookies and tracking
  13. 13. Children
  14. 14. Changes
  15. 15. Contact

1. Who we are

Gritt ("Gritt", "we", "us") operates gritt.io, a platform that helps startup founders reach investors by email.

Legal entity[LEGAL ENTITY NAME — e.g. Gritt SAS]
Registered address39 rue des vignes 75016 Paris France
Company numberRCS Paris 852 925 585
Data controllerThe entity above
Privacy contactprivacy@gritt.io

We are established in France. Where the GDPR applies, we act as data controller for the personal data described below, except where stated otherwise.

2. In plain terms

3. Data we collect

3.1 Data you give us

DataWhy
Name, email address, password (stored hashed)Your account
Company name, website, pitch, traction, stage, fundraising amount, target markets, focus areasTo match you to relevant investors and to draft your emails
Billing detailsHandled by Stripe — we never see or store your card number

3.2 Data from your Google account (see Section 4 — this is the important one)

3.3 Emails you send through Gritt

The subject and body of each message, the recipient, the time it was sent, and the Gmail message and thread identifiers Google returns to us. We keep these so you can see your own outreach history and so we don't contact the same investor twice.

3.4 Usage data

Pages viewed, features used, a randomly generated visitor and session identifier, referral source, IP address, browser and device type. We use this to understand how the product is used and to fix what's broken.

3.5 Investor data (personal data about people who are not our users)

We hold professional information about investors: name, LinkedIn public profile identifier, photograph, professional biography, city and country, publicly listed contact details (which may include an email address, telephone number or social media handle), and their investment history (companies invested in, approximate date, stage).

This data is obtained from public professional sources and from third-party data providers. It is not collected from the investors themselves. Section 8 is written for them.

4. Google user data — how we access, use, store and share it

This section exists because Google requires it, and because it is the part of this policy most people will actually care about. It is deliberately specific.

4.1 What we ask for

When you connect your Gmail, Google asks you to grant Gritt exactly three scopes:

ScopeWhat it lets us do
openidIdentify the Google account you connected
.../auth/userinfo.emailRead the email address of that account, so we can show you which inbox is connected and set the correct From address
.../auth/gmail.sendSend an email on your behalf. Nothing else.

gmail.send is send-only. It does not permit us to read, list, search, download, modify, label, delete or archive any message, draft or attachment in your mailbox. We hold no other Gmail permission, and we have not requested one.

We do not access your Google Contacts, Calendar, Drive, or any other Google service.

4.2 What we do with it

4.3 What we store, and how

StoredProtectionKept until
Google refresh tokenEncrypted at rest (AES-256-CBC, unique initialisation vector per record)You disconnect, or delete your account
Google access tokenEncrypted at rest; expires within about an hourReplaced automatically; deleted on disconnect
Google account email address and account identifierStandard database encryption at restYou disconnect, or delete your account
Granted scopesSame
Gmail message ID and thread ID of messages we sentYou delete your account

We do not store any content from your mailbox, because we cannot read it.

4.4 What we do NOT do

4.5 Limited Use

Gritt's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4.6 Revoking access — at any time

  1. In Gritt: click Disconnect on the Gmail card. We immediately delete your refresh token, your access token and your Google account identifier.
  2. In Google: go to myaccount.google.com/permissions, find Gritt, and click Remove access.

Either method stops all sending immediately. Doing the second without the first will cause our stored token to fail, and we will delete it and prompt you to reconnect.

PurposeLegal basis (GDPR Art. 6)
Providing the service you signed up forContract — Art. 6(1)(b)
Sending emails from your Gmail at your instructionContract — Art. 6(1)(b), plus your explicit Google authorisation
Billing, fraud prevention, keeping recordsLegal obligation and legitimate interests — Art. 6(1)(c), 6(1)(f)
Product analytics and improving the serviceLegitimate interests — Art. 6(1)(f)
Maintaining the investor database and matching investors to foundersLegitimate interests — Art. 6(1)(f). See Section 8, including your absolute right to object.
Marketing emails to you (our user)Consent, withdrawable at any time

6. Who we share data with

We do not sell personal data. We use the following processors:

ProviderWhat they processWhere
XanoApplication database and backend — all data in this policyUS / EU
Google (Gmail API)Sends your emails; holds the OAuth grantGlobal
StripePayment processing. Stripe, not us, handles your card details.US / EU
OpenAIYour pitch text and the content of your public website, to suggest the investor focus areas that match your company. No Google user data, no investor contact details and no email content is sent to OpenAI.US
SendGridTransactional emails from Gritt to you (e.g. "reconnect your Gmail")US
CloudflareContent delivery, security, and hosting for parts of the siteGlobal
LaGrowthMachineOutreach automation used in parts of our own operationsEU
WeWebWebsite hostingEU

We also disclose data where we are legally required to, or to establish, exercise or defend legal claims.

7. Your rights (if you are a Gritt user)

Under the GDPR you may: access your data, have it corrected, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent at any time.

Write to privacy@gritt.io. We will respond within one month.

You may also complain to your supervisory authority. In France this is the CNIL (cnil.fr).

8. If you are an investor in our database

You did not give us your data, and you are entitled to know what we hold and to make us stop. This section is your right of information under GDPR Article 14.

What we hold about you

Your name, LinkedIn public profile identifier, photograph, professional biography, city and country, professional contact details as publicly listed, and your investment history (companies, approximate dates, stage). We obtained this from public professional sources and third-party data providers.

What we do with it

Legitimate interests (GDPR Art. 6(1)(f)): connecting founders with investors who are professionally active in their sector. We consider this to be within your reasonable expectations as a professional investor.

Who is responsible — us, or the founder who emailed you?

Both. And you do not have to work out which.

For most of what we do with your data — building the database, publishing profiles, matching investors to founders — Gritt alone is responsible. The founder has no say in any of it.

But when a founder emails you through Gritt, we and that founder are joint controllers under GDPR Article 26. They decide to contact you and what to say; we decide who is eligible to appear, how they are ranked, and we run the system that sends it. Neither of us is merely the other's supplier.

Article 26(2) requires us to publish the essence of our arrangement with founders. Here it is:

Who is responsible
Telling you your data is processed (this page)Gritt
Being your point of contactGritt — privacy@gritt.io
Access, correction, erasure, restriction, objectionGritt
Suppressing you across every founder on the platformGritt
What the email actually saidThe founder
Stopping, if you object to them directlyThe founder — and they are contractually required to tell us within 72 hours, so that we can suppress you everywhere, not just for them
Keeping the investor database and the public pagesGritt alone

🔴 You may come to either of us — Article 26(3)

Whatever we have agreed with the founder, you may exercise every one of your rights against either of us, at your choice. We cannot contract that away, and neither can they.

We have named ourselves as the contact point so that you only have to ask once. Write to privacy@gritt.io and we will handle it end to end — including instructing the founder who contacted you. You do not need to chase them, and you do not need to explain yourself.

🔴 Your rights — and they are stronger than most

How to make us stop — one email

Write to privacy@gritt.io — or simply reply to any email you receive and say so.

We will:

  1. Suppress you permanently and across every founder on the platform, not just the one who contacted you.
  2. Remove your public profile page from gritt.io.
  3. Confirm to you when it's done.

We keep a minimal record of your suppression — enough to make sure we never contact you again. That record exists for you, and we will not use it for anything else.

You may complain to the CNIL (cnil.fr) or your local supervisory authority at any time.

9. International transfers

Some providers in Section 6 are outside the EEA. Where that is so, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. You can ask us for details.

10. How long we keep data

Account dataWhile your account is open, then 30 days
Google tokensUntil you disconnect or delete your account — deleted immediately on either
Emails you sentWhile your account is open, then 30 days
Billing records10 years (French accounting law)
Investor suppression recordsIndefinitely — this is the only way to guarantee we never contact you again
Analytics25 months

11. Security

Passwords are hashed and never stored in plain text. Google refresh tokens are encrypted with AES-256-CBC using a unique initialisation vector per record. All traffic is over HTTPS. Access to production data is limited to staff who need it.

No system is perfectly secure. If a breach affects your rights, we will notify you and the CNIL as the GDPR requires.

12. Cookies and tracking

We use cookies and similar technologies to keep you signed in, to remember your preferences, and to understand how the product is used. Analytics identifiers are random and are not linked to your identity unless you are signed in.

Details and controls: [COOKIE POLICY URL].

13. Children

Gritt is for business use and is not directed at anyone under 18. We do not knowingly collect data from children.

14. Changes

We will post any change here and update the date at the top. If a change is significant, we will email you before it takes effect.

15. Contact

privacy@gritt.io · AMC SAS, 39 rue des vignes 75016 Paris France