Third Party Index

Snapshot 22242

Document
Security page
URL
https://grayn.ai/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
69590 bytes
SHA-256 (raw)
225d0073f6efb7fae92e65f8028a0523f699695e7243716d6382c10f05074fa5
SHA-256 (normalized text)
56314d95add5448d2a19964d97cc5218081068ae216e1236285337d47941a6fd

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security & Trust Center
We see your marketing data. Nobody else does.
Grayn handles sensitive performance data, creative assets, and customer segments. Security isn't a feature. It's the foundation.
S
Audited annually
G
GDPR
Compliant · DPA
O
OAuth 2.0
Read-only · Scoped
E
AES-256
Rest & transit
Principles
Six rules we build every decision around.
Principle 01
Read-only by default.
OAuth scopes are read-only. We never have write access unless you grant it for approved campaign actions — and even then, every write is gated by human approval.
Principle 02
Workspace isolation.
Every customer workspace is fully isolated at the database level. No data ever crosses customer boundaries. Not for training, not for benchmarks, not for "aggregate insights."
Principle 03
Encrypted, end to end.
AES-256 at rest. TLS 1.3 in transit. OAuth tokens use envelope encryption and rotate automatically. Keys managed in AWS KMS.
Principle 04
No training on your data.
Your campaigns, conversations, and documents only answer your team's questions. We never train foundation models on customer data. Your data improves your Grayn, not ours.
Principle 05
Every action logged.
Every question, data pull, and action is logged with user, timestamp, and reasoning. Exportable audit trail on Enterprise plans.
Principle 06
Right to delete.
Disconnect integrations and tokens revoke immediately. Delete your workspace and all data is purged within 30 days, including backups. No dark archives.
How data moves
From your ad account to your Slack.
01
OAuth connect
You grant read-only access via official OAuth from Google & Meta.
02
Encrypted fetch
Pulled over TLS 1.3, stored encrypted at rest in your isolated workspace.
03
Indexed privately
Vector embeddings in your tenant. Never shared across customers.
04
Answered in Slack
Queries route through your Slack App. No data leaves approved boundaries.
Campaign metadata & metrics
AWS us-east-1, encrypted at rest, isolated per workspace. Retained while subscription is active.
OAuth access tokens
Envelope encryption via AWS KMS. Token values never logged. Rotated on every refresh.
Uploaded brand documents
Encrypted S3. Indexed as private vector embeddings. Never shared across tenants.
Slack conversations
Messages route through Slack's infra. Grayn stores question history for memory, not Slack's full channel data.
Audit logs
All access events logged with user, IP, action. Exportable on Enterprise. Retained 7 years.
Subprocessors
The infrastructure we stand on.
Amazon Web Services
Compute, storage, KMS keys, database hosting.
US-EAST-1
Anthropic
Foundation model inference for natural language.
US · No training
OpenAI
Fallback inference & embeddings. Zero data retention.
US · No training
Slack
Messaging surface. Grayn operates as a Slack App.
US
Pinecone
Vector database for the Cortex memory. Isolated namespaces.
US · SOC 2
Datadog
Infrastructure monitoring. Metadata only, no customer data.
US
For complete subprocessor list, data flow diagrams, or to request our SOC 2 Type II report, DPA, or BAA, email security@grayn.ai.
Answers for your security team.
The eight questions we hear most from security reviews. More? Email security@grayn.ai.
No. We use foundation models routed through zero-data-retention endpoints. Your campaigns, creative, conversations, and documents only answer your team's questions.
OAuth with read-only scopes by default. We see what you authorized us to read — nothing more. For campaign launch (Scale/Enterprise), you grant scoped write permissions with spend caps and approval rules.
AWS US-EAST-1 (Northern Virginia). All data at rest encrypted with AES-256. All in transit encrypted with TLS 1.3. Each workspace is isolated at the database level.
Yes. Disconnect integrations any time and tokens revoke immediately. Delete your workspace and all data — including backups — is purged within 30 days.
SAML/SSO (Okta, Google Workspace) on Enterprise. Role-based access (Admin, Member, Viewer) on all plans, with granular permissions per integration.
Standard DPA available to all customers. BAA, custom MSA, and negotiated terms on Enterprise. Email security@grayn.ai.
SOC 2 Type II report available under NDA. Email security@grayn.ai — sent within 1 business day.
Customers notified within 24 hours of any confirmed incident affecting their workspace. Full incident response plan tested quarterly. Post-mortem shared publicly within 14 days.
We'll send the SOC 2 report.
You decide.
Most security reviews close in under a week. We move at your pace.
Request SOC 2 report Talk to security
Contact Support
Get help from our team
Need help? Reach out to our support team and we'll get back to you as soon as possible.
support@grayn.ai
Privacy Policy
Effective 11 March 2026 · Last Updated 11 March 2026
1. Introduction
Grayn.ai ("we", "us", or "our") operates Grayn.ai. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
Account Information: Name, email address, and authentication credentials when you create an account.
Advertising Platform Data: Data retrieved from connected advertising platforms (Meta, Google, TikTok) via OAuth, including campaign metrics, spend data, and performance analytics.
Usage Data: Information about how you interact with our service, including queries, feature usage, and session data.
Communication Data: Slack workspace information when you connect our Slack integration.
Technical Data: IP address, browser type, device information, and cookies.
3. How We Use Your Information
To provide, maintain, and improve our advertising analytics service.
To process and respond to your natural language queries about ad performance.
To deliver alerts and scheduled reports via Slack or email.
To communicate with you about service updates and support.
To ensure security and prevent fraud.
4. Data Sharing
We do not sell your personal data. We may share information with:
Service providers who assist in operating our platform (hosting, analytics).
Advertising platforms solely for retrieving your campaign data via authorized OAuth connections.
Law enforcement when required by applicable law.
5. Data Security
We implement industry-standard security measures including encryption in transit and at rest, secure OAuth token storage, and regular security audits. However, no method of transmission over the Internet is 100% secure.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. You may request deletion of your data at any time by contacting us or using our data deletion process.
7. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data. To exercise these rights, please contact us at the email below.
8. Cookies
We use essential cookies for authentication and session management. We may also use analytics cookies to understand usage patterns. You can control cookie preferences through your browser settings.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the Last Updated date.
10. Contact Us
Grayn.ai · hello@grayn.ai
Terms of Service — Slack App Edition
Effective 20 March 2026 · Last Updated 20 March 2026
1. Welcome to Grayn
Agreement between user and Y77 Limited trading as Grayn. Governs access to the Grayn app via Slack Marketplace, grayn.ai, and app.grayn.ai. Grayn is a Slack-native AI agent for marketing teams: campaign analysis, reporting, budget pacing, competitor research, and creative ideation. By installing or using Grayn, you agree to these Terms.
2. Eligibility
Must be at least 16 years of age.
Must be an authorised user of the Slack workspace where Grayn is installed.
If installing for an organisation, you must have authority to accept these Terms on behalf of that organisation.
3. Installation & Accounts
Installed via Slack Marketplace using OAuth scopes displayed during install.
You are responsible for ensuring workspace admin has approved the install.
You are responsible for all activity that occurs through Grayn in your workspace.
You must provide accurate information when setting up your account.
4. Free Trial
Duration: typically 14 days, stated at sign-up.
Core features included; some advanced features reserved for paid plans.
No charge during trial. Billing starts after trial ends if not cancelled.
Auto-converts to paid subscription if not cancelled before trial ends.
One trial per organisation or Slack workspace.
Trial data deleted within 30 days of trial expiry if not converted.
5. Subscription & Billing
Subscription basis, fees in USD, excludes taxes unless stated.
Auto-renews monthly or annually unless cancelled before renewal date.
Upgrades take effect immediately with prorated billing.
Downgrades take effect at the start of the next billing cycle.
Failed payments may result in suspended access.
Fees are generally non-refundable. Contact support@grayn.ai for billing issues.
6. Acceptable Use
You must not:
Use Grayn for any illegal, harmful, or unlawful purpose.
Reverse-engineer, decompile, or extract source code of Grayn's AI or platform.
Circumvent usage limits, rate limits, or security measures.
Resell, sublicense, or redistribute access without written consent.
Generate misleading, fraudulent, or deceptive content.
Transmit malware, spam, or harmful code through the Service.
Degrade or compromise the performance of Slack's services.
Display advertising within the Slack platform using Grayn.
Use Grayn for surveillance or user profiling unrelated to its function.
7. Data Processing & Privacy
Processes only messages directed to or mentioning Grayn — not all workspace messages.
Processes marketing data from connected platforms (Meta, Google, AppsFlyer) via authorised OAuth.
Never trains LLMs or generative AI models with Slack Data.
Never sells, rents, or shares Slack Data with third parties.
Never uses Slack Data for advertising or unrelated user profiling.
Slack Data deleted within 14 business days of uninstallation.
GDPR: Grayn acts as data processor; you remain data controller. DPA available on request.
8. AI-Generated Outputs
Outputs may not be 100% accurate, complete, or free from errors.
Always review critical business decisions independently.
You are solely responsible for how you use AI-generated outputs.
Grayn does not provide financial, legal, or regulatory advice.
Results depend on the quality and completeness of data you provide.
9. Service Level Agreement
99.9% uptime target, measured monthly. Excludes scheduled maintenance, Slack outages, third-party API issues, and force majeure.
99.0%–99.9% uptime: 5% credit of monthly fee
95.0%–99.0% uptime: 15% credit of monthly fee
Below 95.0% uptime: 30% credit of monthly fee
Support: Critical within 2 hours, Major within 8 hours, General within 1 business day.
10. Intellectual Property
Grayn platform, AI models, and brand owned by Y77 Limited.
You own your data. No ownership is transferred.
Limited licence granted to process your data solely to provide the Service.
Feedback you provide may be used to improve Grayn without compensation.
11. Limitation of Liability
Total liability capped at fees paid in the 12 months preceding the claim.
Not liable for indirect, incidental, consequential, or punitive damages.
Not liable for decisions made based on AI-generated outputs.
Not liable for outages or changes to third-party services including Slack.
12. Termination
You can cancel anytime via account settings or by uninstalling from Slack.
Cancellation takes effect at end of current billing period.
We may terminate for breach of Terms, non-payment, or service discontinuation.
All Slack Data deleted within 14 business days of termination.
Non-Slack data available for export for 30 days, then permanently deleted.
13. Governing Law
These Terms are governed by the laws of England and Wales. Disputes subject to exclusive jurisdiction of the courts of England and Wales.
14. Contact
Y77 Limited (trading as Grayn) · 353 High Street North, London, England, E12 6PQ · support@grayn.ai
Data Deletion Policy
Effective 11 March 2026 · Last Updated 11 March 2026
1. Your Right to Data Deletion
At Grayn.ai, we respect your right to control your personal data. You may request deletion of your data at any time.
2. How to Request
Email: hello@grayn.ai with subject line "Data Deletion Request"
In-App: Settings → Account → Delete Account
3. What Data Will Be Deleted
Account profile and authentication credentials
Connected advertising platform OAuth tokens and cached campaign data
Slack integration tokens and configuration
Query history and saved reports
Alert configurations and notification preferences
Any other personal data associated with your account
4. Data We May Retain
Billing and transaction records as required by financial regulations
Anonymised, aggregated analytics data that cannot identify you
Data required to comply with legal obligations or resolve disputes
5. Processing Timeline
We will acknowledge your deletion request within 2 business days and complete deletion within 30 days. In some cases, up to 90 days for all backups and cached copies to be fully purged.
6. Verification
To protect your privacy, we may verify your identity before processing a deletion request. This may include confirming your email address or providing additional identifying information.
7. Consequences
Data deletion is permanent and irreversible. Once deleted, you will no longer be able to access your Grayn.ai account, historical analytics, or saved configurations. You are welcome to create a new account at any time.
8. Contact
Grayn.ai · hello@grayn.ai