Legal
Privacy Policy
This Privacy Policy explains how Gripho handles personal information across our website, product, integrations, meeting workflows, and customer support channels.
Last updated: July 29, 2026
1. Scope and roles
This Privacy Policy explains how Gripho collects, uses, shares, stores, and protects personal information when people visit gripho.io, use app.gripho.io, interact with our product, or communicate with us. Gripho is an AI meeting assistant that prepares users for calls, captures meeting context, drafts follow-ups, proposes CRM updates, schedules next steps, and sends approved actions to connected tools.
Gripho may act as a controller when we decide how and why we process information about visitors, prospects, customers, account administrators, billing contacts, and product users. Gripho may act as a processor or service provider when we process meeting content, CRM records, calendar information, and other workspace data on behalf of a customer.
2. Information we collect
We may collect account and profile information such as name, email address, company, role, workspace membership, authentication records, preferences, and support communications.
We may collect meeting and workflow data that customers choose to provide or connect to Gripho, including calendar events, attendees, transcripts, summaries, notes, action items, follow-up drafts, CRM records, deal or account context, tasks, approvals, and integration metadata.
We may collect technical and usage information such as IP address, device and browser data, log events, pages visited, session information, feature usage, approximate location, cookies, and diagnostics.
We may collect billing and commercial information when applicable, such as plan, subscription status, invoices, payment status, tax information, and related business records. Payment card details are handled by payment providers and are not stored by Gripho unless explicitly stated in the product.
3. How we use information
We use personal information to provide, maintain, secure, and improve Gripho, including account creation, authentication, meeting capture, AI-generated summaries, CRM update drafts, follow-up drafts, scheduling workflows, task creation, customer support, troubleshooting, abuse prevention, analytics, billing, and compliance.
We may use workspace data to generate outputs requested by users, such as meeting summaries, next steps, CRM field suggestions, email drafts, task drafts, and pre-meeting briefs. Gripho is designed so users can review and approve important actions before they are pushed to connected systems.
We may use contact information to send service messages, product updates, security notices, onboarding communications, and marketing messages where permitted by law. Users can opt out of non-essential marketing communications.
4. Legal bases
Where applicable privacy laws require a legal basis, we process personal information to perform a contract, comply with legal obligations, pursue legitimate interests, protect rights and security, or with consent. Examples include providing the service, issuing invoices, maintaining security logs, improving product reliability, responding to support requests, and sending consent-based communications.
For customer workspace data, the customer is typically responsible for determining the lawful basis for collecting and using meeting, CRM, calendar, and end-user data. Gripho processes that data according to the customer's instructions and applicable agreements.
5. Cookies and similar technologies
Gripho may use cookies, local storage, pixels, and similar technologies for authentication, session management, security, preferences, analytics, product improvement, and marketing attribution.
Users can control cookies through browser settings and, where available, through consent or preference tools. Disabling required cookies may affect sign-in, security, or core product functionality.
6. Sharing and subprocessors
We may share personal information with vendors and subprocessors that help us operate Gripho, such as cloud infrastructure providers, database and storage providers, AI and transcription providers, analytics tools, email providers, payment processors, monitoring tools, support tools, and security services. These providers are authorized to process information only as needed to provide services to Gripho and are subject to confidentiality and data protection obligations.
We may share information with connected integrations at the direction of a user or customer, including calendar, conferencing, CRM, email, project management, messaging, and automation tools.
We may disclose information when required by law, legal process, or government request; to protect the rights, safety, and security of Gripho, users, customers, or others; or in connection with a merger, acquisition, financing, reorganization, or sale of assets.
7. International transfers
Gripho and its providers may process information in countries other than the country where a user or customer is located. When required, we use appropriate safeguards for cross-border transfers, such as contractual commitments, data processing terms, standard contractual clauses, or other legally recognized mechanisms.
8. Security
We use technical and organizational safeguards designed to protect personal information, including access controls, encryption in transit, monitoring, logging, backup procedures, least-privilege access practices, and internal controls for sensitive production systems.
No internet service can be guaranteed to be completely secure. Customers and users are responsible for using strong credentials, limiting workspace access, reviewing connected integrations, and promptly reporting suspected unauthorized access.
9. Retention and deletion
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the service, maintaining security, complying with legal obligations, resolving disputes, enforcing agreements, and preserving backups.
Retention periods may vary by data type. Account, billing, and contract records may be retained for legal and tax purposes. Security logs may be retained for security and fraud prevention. Meeting artifacts, drafts, CRM context, and workspace records are generally retained according to customer settings, product functionality, deletion requests, and backup cycles.
When information is deleted, it may remain in encrypted backups for a limited period before being overwritten or securely removed.
10. Privacy rights
Depending on location and applicable law, individuals may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for certain processing of personal information. Requests can be sent to thiago@gripho.io.
If Gripho processes information on behalf of a customer, we may direct the requester to the relevant customer or respond in coordination with that customer. We may need to verify identity and may decline requests where permitted by law, such as when retention is required for legal, security, or legitimate business reasons.
11. Children
Gripho is not intended for children and should not be used by individuals who are not legally able to enter into these services or whose use would require parental consent under applicable law. We do not knowingly collect personal information from children without appropriate authorization.
12. Changes to this Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the website, the product, email, or another reasonable method. Continued use of Gripho after an updated Policy becomes effective means the updated Policy applies.
13. Contact
Questions, privacy requests, or security concerns can be sent to thiago@gripho.io.
14. Gripho Chrome Extension
This section describes how the Gripho browser extension for Google Chrome — Record, Transcribe & Execute tasks for Google Meet — handles information. It supplements the sections above, which continue to apply.
14.1 Single purpose
The extension exists to let a signed-in Gripho user send the Google Meet call they are currently in to their own Gripho account, so that a Gripho agent can join the call, record and transcribe it, and track the resulting action items. All of the extension's data handling serves that single purpose.
14.2 What the extension accesses
The extension runs only on https://meet.google.com/*. Within that scope it accesses:
- The URL of the Google Meet call you are in. Read when you click the Gripho button, and sent to Gripho so the agent knows which call to join.
- Your Gripho account email and name. Retrieved from Gripho's own session endpoint using the Gripho session cookie already present in your browser, and shown in the extension so you know which account is signed in.
- Email addresses you type into the “share meeting” field. Sent to Gripho so those people can access that meeting's record. The extension does not read attendee identities from the Google Meet page and does not build or store a contact list — you type each address yourself.
- Screen-share on/off state. The extension detects when you start and stop presenting in Meet, and uses it only to hide its own on-screen widget so it does not appear in what you are presenting. It does not access, read, copy, or transmit the contents of the shared screen, and the detection stays entirely inside your browser.
- The on-screen position of Meet's own controls. Read as layout geometry so the widget does not cover them. No text, participant identity, or call content is read.
14.3 What the extension does not do
The extension does not capture, record, or transmit audio or video from your call. Recording and transcription are performed by the Gripho meeting agent, which joins the call as a visible participant only after you explicitly request it, and which is governed by the sections above.
The extension does not read the content of your meeting, including chat messages, captions, shared screens, or documents.
The extension does not track your browsing. It has no access to any site other than meet.google.com and Gripho's own API, and it collects no browsing history.
The extension contains no analytics, advertising, or third-party tracking code, and loads no remote code. All of its code ships inside the published package.
Gripho does not sell or transfer data collected by the extension to third parties, does not use it for any purpose unrelated to the single purpose above, and does not use it to determine creditworthiness or for lending purposes.
14.4 Where the data goes
The extension communicates only with Gripho's own API at https://api.gripho.io. It sends no data to any other destination. Authentication uses your existing Gripho session cookie; the extension never handles or stores your Gripho password.
14.5 What is stored on your device
The extension stores a small amount of data locally in Chrome's extension storage, on your device only. It is never transmitted anywhere by the extension, and it is deleted when you remove the extension:
| Stored value | Purpose |
|---|---|
| Your Gripho account email | To display which account is signed in |
| A signed-out flag | To keep the extension signed out until you sign in again |
| The last agent and project you used | To pre-select them on your next call |
| A “show widget while presenting” preference | To remember your display choice |
14.6 Permissions and why they are needed
| Permission | Why it is required |
|---|---|
| storage | To keep the local values listed in 14.5 on your device |
| Host access to https://meet.google.com/* | To show the Gripho button inside a Meet call and read that call's URL when you click it |
| Host access to https://api.gripho.io/* | To verify your Gripho session, send the meeting you chose to capture, display that meeting's live insights, and share it with the addresses you enter |
14.7 Your control
Nothing is sent to Gripho until you click the button in the call. You can sign out from the extension's popup at any time, which stops it from using your Gripho session. Meeting recordings, transcripts, and derived data created after the agent joins are governed by sections 9 and 10 above, including retention and your privacy rights. Removing the extension deletes everything it stored locally.
14.8 Contact
Privacy questions or requests about the extension: thiago@gripho.io.