Privacy Policy
- 1. Who we are
- 2. In plain terms
- 3. Data we collect
- 4. Google user data — how we access, use, store and share it
- 5. Why we process your data (legal bases)
- 6. Who we share data with
- 7. Your rights (if you are a Gritt user)
- 8. If you are an investor in our database
- 9. International transfers
- 10. How long we keep data
- 11. Security
- 12. Cookies and tracking
- 13. Children
- 14. Changes
- 15. Contact
1. Who we are
Gritt ("Gritt", "we", "us") operates gritt.io, a platform that helps startup founders reach investors by email.
| Legal entity | [LEGAL ENTITY NAME — e.g. Gritt SAS] |
| Registered address | 39 rue des vignes 75016 Paris France |
| Company number | RCS Paris 852 925 585 |
| Data controller | The entity above |
| Privacy contact | privacy@gritt.io |
We are established in France. Where the GDPR applies, we act as data controller for the personal data described below, except where stated otherwise.
2. In plain terms
- We send email as you, from your own Gmail. We never read your mailbox.
- We ask Google for one sending permission (
gmail.send) and nothing else. We cannot open, list, search, or download any message in your account. - We hold a database of investors — including people who did not give us their data directly. Section 8 explains their rights and how to exercise them.
- We do not sell personal data. Ever.
- We do not use Google user data to train AI models, and we do not use it for advertising.
3. Data we collect
3.1 Data you give us
| Data | Why |
|---|---|
| Name, email address, password (stored hashed) | Your account |
| Company name, website, pitch, traction, stage, fundraising amount, target markets, focus areas | To match you to relevant investors and to draft your emails |
| Billing details | Handled by Stripe — we never see or store your card number |
3.2 Data from your Google account (see Section 4 — this is the important one)
3.3 Emails you send through Gritt
The subject and body of each message, the recipient, the time it was sent, and the Gmail message and thread identifiers Google returns to us. We keep these so you can see your own outreach history and so we don't contact the same investor twice.
3.4 Usage data
Pages viewed, features used, a randomly generated visitor and session identifier, referral source, IP address, browser and device type. We use this to understand how the product is used and to fix what's broken.
3.5 Investor data (personal data about people who are not our users)
We hold professional information about investors: name, LinkedIn public profile identifier, photograph, professional biography, city and country, publicly listed contact details (which may include an email address, telephone number or social media handle), and their investment history (companies invested in, approximate date, stage).
This data is obtained from public professional sources and from third-party data providers. It is not collected from the investors themselves. Section 8 is written for them.
4. Google user data — how we access, use, store and share it
This section exists because Google requires it, and because it is the part of this policy most people will actually care about. It is deliberately specific.
4.1 What we ask for
When you connect your Gmail, Google asks you to grant Gritt exactly three scopes:
| Scope | What it lets us do |
|---|---|
openid | Identify the Google account you connected |
.../auth/userinfo.email | Read the email address of that account, so we can show you which inbox is connected and set the correct From address |
.../auth/gmail.send | Send an email on your behalf. Nothing else. |
gmail.send is send-only. It does not permit us to read, list, search, download, modify, label, delete or archive any message, draft or attachment in your mailbox. We hold no other Gmail permission, and we have not requested one.
We do not access your Google Contacts, Calendar, Drive, or any other Google service.
4.2 What we do with it
- We send emails you have chosen to send, from your address, to investors in your outreach plan.
- We display the connected email address in the app so you know which account is in use.
- That is all. There is no other purpose.
4.3 What we store, and how
| Stored | Protection | Kept until |
|---|---|---|
| Google refresh token | Encrypted at rest (AES-256-CBC, unique initialisation vector per record) | You disconnect, or delete your account |
| Google access token | Encrypted at rest; expires within about an hour | Replaced automatically; deleted on disconnect |
| Google account email address and account identifier | Standard database encryption at rest | You disconnect, or delete your account |
| Granted scopes | — | Same |
| Gmail message ID and thread ID of messages we sent | — | You delete your account |
We do not store any content from your mailbox, because we cannot read it.
4.4 What we do NOT do
- We do not read your mailbox. We are not technically able to.
- We do not sell, rent, or trade Google user data.
- We do not use Google user data for advertising, and we serve no ads.
- We do not use Google user data to train, retrain, or fine-tune any AI or machine-learning model — ours or anyone else's.
- We do not allow our staff to read your Google user data, except in the narrow circumstances Google permits: with your explicit consent, where necessary for security purposes (for example, to investigate abuse), to comply with applicable law, or where the data has been aggregated and anonymised for internal operations.
- We do not transfer Google user data to third parties, except to the infrastructure providers strictly necessary to run the service (Section 6), where required by law, or in connection with a merger or acquisition — and in that last case only after giving you notice and obtaining your consent.
4.5 Limited Use
Gritt's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.6 Revoking access — at any time
- In Gritt: click Disconnect on the Gmail card. We immediately delete your refresh token, your access token and your Google account identifier.
- In Google: go to myaccount.google.com/permissions, find Gritt, and click Remove access.
Either method stops all sending immediately. Doing the second without the first will cause our stored token to fail, and we will delete it and prompt you to reconnect.
5. Why we process your data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service you signed up for | Contract — Art. 6(1)(b) |
| Sending emails from your Gmail at your instruction | Contract — Art. 6(1)(b), plus your explicit Google authorisation |
| Billing, fraud prevention, keeping records | Legal obligation and legitimate interests — Art. 6(1)(c), 6(1)(f) |
| Product analytics and improving the service | Legitimate interests — Art. 6(1)(f) |
| Maintaining the investor database and matching investors to founders | Legitimate interests — Art. 6(1)(f). See Section 8, including your absolute right to object. |
| Marketing emails to you (our user) | Consent, withdrawable at any time |
6. Who we share data with
We do not sell personal data. We use the following processors:
| Provider | What they process | Where |
|---|---|---|
| Xano | Application database and backend — all data in this policy | US / EU |
| Google (Gmail API) | Sends your emails; holds the OAuth grant | Global |
| Stripe | Payment processing. Stripe, not us, handles your card details. | US / EU |
| OpenAI | Your pitch text and the content of your public website, to suggest the investor focus areas that match your company. No Google user data, no investor contact details and no email content is sent to OpenAI. | US |
| SendGrid | Transactional emails from Gritt to you (e.g. "reconnect your Gmail") | US |
| Cloudflare | Content delivery, security, and hosting for parts of the site | Global |
| LaGrowthMachine | Outreach automation used in parts of our own operations | EU |
| WeWeb | Website hosting | EU |
We also disclose data where we are legally required to, or to establish, exercise or defend legal claims.
7. Your rights (if you are a Gritt user)
Under the GDPR you may: access your data, have it corrected, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent at any time.
Write to privacy@gritt.io. We will respond within one month.
You may also complain to your supervisory authority. In France this is the CNIL (cnil.fr).
8. If you are an investor in our database
You did not give us your data, and you are entitled to know what we hold and to make us stop. This section is your right of information under GDPR Article 14.
What we hold about you
Your name, LinkedIn public profile identifier, photograph, professional biography, city and country, professional contact details as publicly listed, and your investment history (companies, approximate dates, stage). We obtained this from public professional sources and third-party data providers.
What we do with it
- We show it to founders looking for relevant investors.
- Some profiles are published on public pages on gritt.io.
- Founders may use Gritt to send you an introductory email about their company.
Our legal basis
Legitimate interests (GDPR Art. 6(1)(f)): connecting founders with investors who are professionally active in their sector. We consider this to be within your reasonable expectations as a professional investor.
Who is responsible — us, or the founder who emailed you?
Both. And you do not have to work out which.
For most of what we do with your data — building the database, publishing profiles, matching investors to founders — Gritt alone is responsible. The founder has no say in any of it.
But when a founder emails you through Gritt, we and that founder are joint controllers under GDPR Article 26. They decide to contact you and what to say; we decide who is eligible to appear, how they are ranked, and we run the system that sends it. Neither of us is merely the other's supplier.
Article 26(2) requires us to publish the essence of our arrangement with founders. Here it is:
| Who is responsible | |
|---|---|
| Telling you your data is processed (this page) | Gritt |
| Being your point of contact | Gritt — privacy@gritt.io |
| Access, correction, erasure, restriction, objection | Gritt |
| Suppressing you across every founder on the platform | Gritt |
| What the email actually said | The founder |
| Stopping, if you object to them directly | The founder — and they are contractually required to tell us within 72 hours, so that we can suppress you everywhere, not just for them |
| Keeping the investor database and the public pages | Gritt alone |
🔴 You may come to either of us — Article 26(3)
Whatever we have agreed with the founder, you may exercise every one of your rights against either of us, at your choice. We cannot contract that away, and neither can they.
We have named ourselves as the contact point so that you only have to ask once. Write to privacy@gritt.io and we will handle it end to end — including instructing the founder who contacted you. You do not need to chase them, and you do not need to explain yourself.
🔴 Your rights — and they are stronger than most
- You have an absolute right to object to direct marketing (Art. 21(2)). If you tell us to stop, we must stop. There is no balancing test, and we will not ask you to justify it.
- You may object to any other processing, ask for a copy of what we hold, ask us to correct it, or ask us to delete it entirely.
How to make us stop — one email
Write to privacy@gritt.io — or simply reply to any email you receive and say so.
We will:
- Suppress you permanently and across every founder on the platform, not just the one who contacted you.
- Remove your public profile page from gritt.io.
- Confirm to you when it's done.
We keep a minimal record of your suppression — enough to make sure we never contact you again. That record exists for you, and we will not use it for anything else.
You may complain to the CNIL (cnil.fr) or your local supervisory authority at any time.
9. International transfers
Some providers in Section 6 are outside the EEA. Where that is so, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. You can ask us for details.
10. How long we keep data
| Account data | While your account is open, then 30 days |
| Google tokens | Until you disconnect or delete your account — deleted immediately on either |
| Emails you sent | While your account is open, then 30 days |
| Billing records | 10 years (French accounting law) |
| Investor suppression records | Indefinitely — this is the only way to guarantee we never contact you again |
| Analytics | 25 months |
11. Security
Passwords are hashed and never stored in plain text. Google refresh tokens are encrypted with AES-256-CBC using a unique initialisation vector per record. All traffic is over HTTPS. Access to production data is limited to staff who need it.
No system is perfectly secure. If a breach affects your rights, we will notify you and the CNIL as the GDPR requires.
12. Cookies and tracking
We use cookies and similar technologies to keep you signed in, to remember your preferences, and to understand how the product is used. Analytics identifiers are random and are not linked to your identity unless you are signed in.
Details and controls: [COOKIE POLICY URL].
13. Children
Gritt is for business use and is not directed at anyone under 18. We do not knowingly collect data from children.
14. Changes
We will post any change here and update the date at the top. If a change is significant, we will email you before it takes effect.
15. Contact
privacy@gritt.io · AMC SAS, 39 rue des vignes 75016 Paris France