Legal
Privacy
Your business data is the reason Grove exists. Here is exactly what we hold, why we hold it, and how to get it back.
Last updated July 27, 2026The short version
- We collect what the product needs to work, and nothing for advertising.
- Your business data is never sold, and never used to train a model.
- One workspace cannot read another — the database enforces that, not our code.
- Ask us for a copy or for deletion, and you get it.
01
What we collect
- Your account: a name, an email address, and which workspace you belong to.
- Your business data: whatever you and your team put into Grove — contacts, products, orders, invoices, notes.
- Technical logs: IP address, browser, and the time of each request, kept so we can fix faults and spot abuse.
- Nothing else. There are no advertising pixels and no third-party analytics on this site.
02
What we use it for
- Running the product you signed up for.
- Answering you when you write to support.
- Keeping the service up, and catching people trying to break it.
- Sending the mail you asked for: invitations, password resets, and the occasional service notice.
03
What we never do
- We do not sell your data, and we do not share it for advertising.
- We do not use your business data to train AI models.
- We do not look inside your workspace unless you ask us to, or a fault leaves us no other way to fix it.
04
How the assistant sees your data
- When you ask a question, your wording and the shape of your tables go to OpenAI, which turns them into SQL.
- The query runs on our database, not theirs.
- Rows travel onward only when they are needed to phrase the answer you asked for.
- OpenAI does not train on data sent through its API.
05
Who else touches it
- Supabase — the database, sign-in, and file storage.
- Amazon Web Services — where the API and the assistant run.
- Vercel — hosting for the web app.
- OpenAI — the model behind the assistant.
- Resend — invitations and other transactional email.
- That is the entire list. If it grows, this page changes first.
06
How it is kept
- Every table carries a tenant, and Postgres row-level security enforces it on every query — one workspace cannot read another.
- Encrypted in transit and at rest.
- Every change is written to an append-only audit log: what changed, who changed it, when.
- Access to production data is limited to the people who need it, and every use of it is recorded.
07
What you can ask us for
- A copy of your data, in a format you can open somewhere else.
- A correction — though most of it you can edit yourself.
- Deletion of your account and its data. We remove it within 30 days, minus anything the law obliges us to keep.
- An explanation of anything above. Write to us and you get a person.
08
Cookies
- One cookie, and its job is keeping you signed in.
- No advertising cookies, and no cross-site tracking.
09
The demo workspace
- The demo is a shared sandbox that resets itself before every run.
- Treat anything typed into it as public, and never put real customer data there.
10
When this changes
- Every version is dated, and the current one is always here.
- If a change matters to you, we email before it takes effect.
- Continuing to use Grove after that means the newer version applies.
Something here unclear?
Ask, and a person will answer. If a plain-language version of any clause would help, we will write one.
grove@zimblefy.com