Privacy Policy
This page explains what GraphrAI collects when you use the platform, how it's used, who else sees it, and how you can control or remove it.
What we collect
To run your account and the reasoning sessions you create, we collect:
- Account information — your email address and a password hash. We never store your password in plain text.
- Session and conversation content — the messages you send and the outputs your agents produce, including the full reasoning graphs (DAGs) built during a session. This is the content you're actively working with, so it's stored so you can return to it.
- Usage and billing metadata — token counts, model cost, and plan tier, tracked per node in your reasoning graph. This powers the cost and analytics views in the product and is how usage-based billing is calculated.
How LLM providers see your data
GraphrAI does not generate model responses itself. Requests are routed through LiteLLM to third-party model providers such as OpenAI, Anthropic, and Google.
- If you supply your own API key for a provider, requests to that provider are made directly using your key.
- If you use platform-routed defaults instead, GraphrAI selects the provider and model on your behalf. See our routing disclosure for details — you must explicitly acknowledge this practice before using platform-routed defaults.
In either case, the content of your prompts and agent outputs is sent to the relevant provider to generate a response, subject to that provider's own data handling terms. We do not use your conversation content to train models.
Data retention & deletion
We retain your account and session data for as long as your account is active, plus whatever is needed to satisfy legal or billing record-keeping obligations.
You can delete your account at any time from account settings. Account deletion requires re-authentication to confirm it's really you, and it removes your account data from the platform.
Profile isolation
GraphrAI supports isolated profiles under a single account, so you can keep separate contexts — for example, personal and work use — scoped apart from one another. Sessions, agents, configuration, and API keys are kept separate per profile rather than pooled together.
Cookies
We use a single essential authentication cookie to keep you signed in between requests. This cookie is required for the product to function and is not used for advertising. GraphrAI does not use third-party advertising or tracking cookies.
GDPR & your rights
Before any data processing happens beyond creating your account, you go through an explicit in-app consent step covering how your data will be used, including LLM routing.
You can access, export, or request deletion of your data at any time by:
- Emailing [email protected], or
- Using the deletion option in account settings.
Children's privacy
GraphrAI is not directed at children under 13 (or the applicable minimum age in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at [email protected] and we will address it.
Changes to this policy
We may update this policy as the product changes. When we do, we'll update the "Last updated" date at the top of this page. Material changes will be communicated through the product where practical.
Governing law and jurisdiction: [Jurisdiction to be finalized].
Contact
Questions about this policy or your data can be sent to [email protected], or via our contact page.