Privacy Policy
Effective Date: August 5, 2026
Grydell, Inc. ("Grydell," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and otherwise process personal information in connection with our websites, including grydell.com, our SANTA application at santa.grydell.com, and related products, support, communications, and services that link to this Privacy Policy (collectively, the "Service").
This Privacy Policy does not apply to information processed under a separate written agreement that expressly supersedes this Privacy Policy. If you use the Service through an employer, architecture firm, school, or other organization (a "Business Customer"), additional terms, including a data processing addendum, may apply.
1. Scope and Roles
Grydell acts as a controller or business for personal information that we collect for our own purposes, such as account administration, billing, security, product analytics, marketing, and direct customer support.
When a Business Customer submits personal information to the Service and instructs us to process it on the Business Customer's behalf, Grydell may act as a processor or service provider. In that context, the Business Customer determines the purposes and means of processing, and its privacy notice and agreement with Grydell govern the processing. If you are an employee, contractor, client, or other individual whose information was submitted by a Business Customer, please direct your request to that Business Customer. We will assist the Business Customer as required by applicable law and our agreement.
2. Personal Information We Collect
We collect personal information directly from you, automatically when you use the Service, from Business Customers that provide access to the Service, and from service providers or integrations that you choose to use.
2.1 Account and Contact Information
We may collect your name, email address, password or authentication credentials, profile information, company or school affiliation, workspace membership, role, permissions, and other information you provide when creating or managing an account.
If you sign in through a third-party authentication provider, we may receive information authorized by that provider, such as your name, email address, profile image, and authentication token. We do not receive your password for the third-party service.
2.2 Billing and Transaction Information
We may collect your subscription plan, billing contact information, billing address, tax identification information, transaction identifiers, purchase history, payment status, and related records. Payment card and bank account information is processed by our payment processor. Grydell does not intentionally store complete payment card numbers or card security codes on its own systems.
2.3 Customer Content
We collect information that you or a Business Customer uploads, enters, generates, or otherwise makes available through the Service ("Customer Content"). Customer Content may include:
- Architectural photographs, sketches, drawings, plans, renderings, reference images, and other project files.
- Prompts, instructions, project and canvas names, selection and mask geometry, editing history, configuration data, and workflow inputs.
- Images and other outputs generated or edited through the Service.
- Comments, ratings, annotations, feedback, collaboration activity, and export activity.
- Screenshots, files, and descriptions that you submit to customer support or during product testing.
Customer Content may contain personal information if you or another user includes it. Please do not upload personal information that is not necessary for your use of the Service. You are responsible for having the rights and permissions needed to submit Customer Content, including any personal information relating to another person.
2.4 Usage, Device, and Log Information
We may automatically collect information about how you use the Service, including pages and features accessed, buttons or tools used, generation and editing events, session dates and times, referral information, error reports, performance data, and interactions with communications.
We may also collect device and network information, including IP address, browser type, operating system, device identifiers, language, approximate location derived from IP address, and security and diagnostic logs.
If you choose to allow optional product analytics, we collect bounded feature-use events and may use session replay to understand usability. We configure this processing to exclude information you type and to mask or block sensitive areas, user-generated media, and privileged screens. We do not enable replay capture of network request bodies or headers, console logs, or canvas content. You can decline or withdraw this choice at any time in SANTA's Privacy settings.
2.5 Communications and Feedback
We collect information you provide when you contact us, request support, participate in an interview or survey, join a waitlist, attend an event, submit product feedback, or otherwise communicate with us. This may include the content of the communication and related metadata.
Support screenshots and files are used to investigate and resolve the reported issue. We do not use support screenshots or files to train models unless we obtain separate permission or the material has been deidentified so that it is no longer personal information or identifiable Customer Content.
2.6 Marketing Information
We may collect your marketing preferences and information about your interaction with our website, newsletters, and promotional communications. We do not send marketing messages where consent is required unless we have obtained that consent.
2.7 Applicant Information
If you apply to work with Grydell, we may collect your contact information, resume, work and education history, portfolio, references, interview notes, and other information relevant to evaluating your application and meeting legal obligations.
2.8 Sensitive Information
The Service is not designed to collect government identification numbers, financial account credentials, health information, precise geolocation, biometric identifiers, or other sensitive personal information that is not necessary for architectural visualization. Please do not include such information in Customer Content or support requests. If we learn that sensitive information was submitted unintentionally, we may delete or restrict it as appropriate.
3. Cookies and Similar Technologies
We and our service providers may use cookies, local storage, pixels, software development kits, and similar technologies to operate and secure the Service, remember preferences, understand usage, measure performance, and improve the Service.
These technologies may include:
- Strictly necessary technologies used for authentication, security, session management, payment flows, and core functionality.
- Functional technologies used to remember settings and preferences.
- Optional analytics technologies used, with your choice where required, to understand how the Service performs and how users interact with it.
You can manage certain cookies through your browser settings. Blocking or deleting strictly necessary cookies may prevent parts of the Service from working. Browser privacy signals may be treated as opt-out requests where required by applicable law. Because there is no uniform industry standard for "Do Not Track" signals, the Service may not respond to those signals. Grydell will describe any material change in its use of advertising or tracking technologies in this Privacy Policy or a cookie notice.
4. How We Use Personal Information
We may use personal information to:
- Provide, operate, maintain, and support the Service.
- Create and administer accounts, workspaces, permissions, subscriptions, and payments.
- Process Customer Content to perform requested generation, editing, collaboration, storage, and export functions.
- Authenticate users and protect accounts, systems, Customer Content, and the Service.
- Respond to inquiries, investigate reported problems, provide customer support, and communicate about the Service.
- Monitor performance, troubleshoot errors, measure feature usage, conduct quality assurance, and improve usability.
- Evaluate and improve generation and editing quality, including by reviewing prompts, inputs, outputs, selections, ratings, and error reports where permitted by our agreement with the applicable user or Business Customer.
- Develop new features and conduct research using aggregated or deidentified information where appropriate.
- Send service announcements, administrative messages, security alerts, and updates to our terms or policies.
- Send marketing communications where permitted by law and consistent with your choices.
- Detect, investigate, prevent, and address fraud, abuse, security incidents, illegal activity, and violations of our agreements.
- Comply with law, enforce our agreements, protect legal rights, and establish, exercise, or defend legal claims.
- Evaluate candidates for employment or engagement.
4.1 Human Review and Model Development
Grydell uses Customer Content to perform the generation, editing, storage, collaboration, security, and support functions requested by the user or Business Customer. Authorized personnel may review identifiable Customer Content only when reasonably necessary to respond to a support request, investigate abuse or a security incident, comply with law, or conduct a quality evaluation that the user or Business Customer has separately authorized, including an agreed closed beta or proof of concept.
We do not use identifiable Customer Content to train a Grydell model or a third-party general-purpose or foundation model unless the applicable user has expressly opted in or the applicable Business Customer has provided written authorization. Support screenshots and files are excluded from model training unless separate permission is obtained.
We may use service telemetry, product feedback, and aggregated or deidentified information to measure and improve the Service, provided the information no longer reasonably identifies a person or reveals identifiable Customer Content. For Business Customers, any more protective restriction in the applicable customer agreement or instruction controls.
5. How We Disclose Personal Information
We may disclose personal information in the following circumstances.
5.1 Service Providers
We may disclose information to vendors that help us provide the Service, including cloud hosting and storage providers, authentication providers, AI model and inference providers, payment processors, analytics providers, communications and customer support providers, security providers, and professional advisers. Providers used for material Service functions currently include Amazon Web Services for cloud infrastructure; WorkOS for authentication and identity management; OpenAI and Google Gemini for AI-related processing; Stripe for payment processing; and PostHog for consented product analytics, feature flags, and session replay. The exact provider, data elements, processing location, and retention terms may vary by feature and customer agreement.
Service providers may process information only to perform services for Grydell or as otherwise permitted by the applicable agreement and law. We require material providers to apply contractual, technical, and organizational safeguards appropriate to the services they perform.
OpenAI API data is not used to train OpenAI models unless Grydell opts in, and abuse-monitoring data may be retained for up to 30 days unless a different approved retention control applies. For paid Gemini services, Google does not use prompts or responses to improve its products, and Grydell does not enable optional sharing for model improvement. Gemini may use limited abuse-monitoring storage and project-isolated in-memory caching under its applicable terms and configuration.
PostHog receives analytics data only after the applicable choice is granted. We limit event properties to bounded metadata, sanitize resource URLs, mask inputs and sensitive areas, and configure session replay retention for 30 days.
5.2 AI and Technical Service Providers
To perform a generation, editing, enhancement, or related request, we may transmit the information reasonably necessary to an AI or technical service provider. This may include prompts, selected portions of images, reference images, configuration information, or generated outputs. We limit the disclosure to information reasonably necessary for the requested function. We do not authorize a provider to use identifiable Customer Content to train a general-purpose or foundation model unless the applicable user has expressly opted in or the applicable Business Customer has provided written authorization.
5.3 Business Customers and Workspace Members
If your account is associated with a Business Customer or shared workspace, administrators may access and manage account information, permissions, projects, Customer Content, usage information, and other workspace activity. Other workspace members may access Customer Content and collaboration information according to the permissions selected by you or the workspace administrator.
If you choose to share a project, image, export, or link with another person, the information will be disclosed as directed by you. You should verify sharing settings before disclosing confidential project material.
5.4 Legal and Safety Disclosures
We may disclose information if we reasonably believe disclosure is necessary to comply with law, legal process, or a lawful government request; enforce our agreements; investigate fraud or security incidents; protect the rights, property, or safety of Grydell, our users, or others; or establish, exercise, or defend legal claims.
5.5 Corporate Transactions
We may disclose or transfer information in connection with an actual or proposed financing, merger, acquisition, reorganization, sale of assets, bankruptcy, receivership, or similar corporate transaction. Any recipient's handling of personal information will be subject to applicable law, the transaction terms, and the commitments that continue to apply after the transfer.
5.6 At Your Direction
We may disclose information to other parties when you request or authorize us to do so.
5.7 No Sale or Cross-Context Behavioral Advertising
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, as those terms are defined under applicable U.S. state privacy laws. If our practices change, we will update this Privacy Policy and provide any required notice and choice.
6. Aggregated and Deidentified Information
We may create and use aggregated or deidentified information for analytics, research, product development, security, benchmarking, and other lawful business purposes. We maintain deidentified information in deidentified form and do not attempt to reidentify it except as permitted by law to test whether our deidentification measures are effective.
7. Data Retention and Destruction
Unless a Business Customer agreement requires a different period, Grydell applies the following default retention periods or criteria:
- Account and profile information: while the account is active and for 30 days after account closure.
- Customer Content, including source images, reference images, prompts, selections, masks, generated outputs, comments, and ratings: while the account or workspace is active and for 30 days after deletion of the applicable account, workspace, project, or content.
- Product analytics: while reasonably needed to analyze product adoption, performance, and reliability, subject to periodic review and deletion or deidentification when no longer needed.
- Session replay: 30 days from collection.
- Security, authentication, and diagnostic logs: 12 months from collection.
- Customer support communications, screenshots, and files: 24 months after the support matter is closed.
- Billing, payment, tax, and transaction records: seven years after the transaction or as otherwise required by applicable financial, tax, and accounting law.
- Marketing preferences and consent records: until withdrawal, plus three years to document compliance.
- Applicant information: two years after the recruiting process ends, unless a shorter period is required or the applicant requests earlier deletion.
- Deidentified or aggregated information: for as long as it remains deidentified and useful for legitimate business purposes.
When a retention period expires, we delete, anonymize, or securely isolate the information. Deleted information may remain in encrypted or access-restricted backups for up to 90 days before being overwritten through ordinary backup processes. We may retain information longer when required by law, subject to a legal hold, necessary to resolve disputes, enforce agreements, prevent fraud, or protect legal rights. Where retention is extended, access is limited to the purpose requiring continued retention.
Users may request account or Customer Content deletion by emailing [email protected] with the subject line "Deletion Request." Grydell will begin processing a verified request without undue delay and ordinarily complete deletion from active systems within 30 days, subject to the exceptions above.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information and Customer Content against unauthorized access, loss, misuse, alteration, or destruction. These safeguards include access controls, authentication, encryption in transit, encryption at rest where supported by the applicable service, administrative access logging, separation of production and development environments, restricted administrator permissions, backup controls, vendor review, and incident response procedures. The safeguards applied depend on the sensitivity of the information, the feature involved, and the risks of processing.
No method of transmission or storage is completely secure. We cannot guarantee that unauthorized access, disclosure, alteration, or destruction will never occur. You are responsible for maintaining the confidentiality of your credentials, using appropriate access permissions, and promptly notifying us if you believe your account or Customer Content is no longer secure.
9. Your Choices and Privacy Rights
9.1 Account and Communication Choices
You may update certain account information through the Service or by contacting us. You may unsubscribe from marketing emails by using the unsubscribe link in the message. You may still receive transactional, security, billing, and other nonmarketing communications related to your account or use of the Service.
You may decline optional product analytics or withdraw a prior choice at any time in SANTA's Privacy settings. Withdrawal stops future optional collection and does not affect processing that was lawful before withdrawal.
9.2 Privacy Rights
Depending on your location and applicable law, you may have the right to:
- Confirm whether we process your personal information and access that information.
- Correct inaccurate or incomplete personal information.
- Delete personal information, subject to legal and operational exceptions.
- Obtain a portable copy of certain personal information.
- Restrict or object to certain processing.
- Withdraw consent where processing is based on consent, without affecting prior lawful processing.
- Opt out of the sale, sharing, targeted advertising, or certain profiling, where applicable.
- Appeal our refusal to act on a request, where applicable.
- Lodge a complaint with a competent data protection authority.
To exercise a privacy right, contact us using the information in Section 15. Please describe your request and the account or email address involved. We may ask for information reasonably necessary to verify your identity and authority. You may use an authorized agent where permitted by law, but we may require proof of authorization and identity verification. We will not discriminate against you for exercising a privacy right.
If Grydell processes your information on behalf of a Business Customer, we may direct your request to that Business Customer.
9.3 U.S. State Privacy Rights
Residents of certain U.S. states may have additional rights under state privacy law. The categories of personal information, sources, purposes, and recipients described in Sections 2 through 5 also describe our practices during the preceding 12 months. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law. We do not sell personal information or share it for cross-context behavioral advertising.
Where applicable, you may submit an appeal of a denied request by replying to our decision or contacting us with the subject line "Privacy Appeal." California residents may also request information about disclosures of personal information to third parties for their own direct-marketing purposes. We do not disclose personal information to third parties for their own direct-marketing purposes without consent.
10. Additional Information for the EEA, United Kingdom, and Switzerland
10.1 Controller
When Grydell acts as controller, Grydell, Inc. is responsible for the processing described in this Privacy Policy. Our contact details are provided in Section 15.
10.2 Legal Bases
Where European data protection law applies, we process personal information based on one or more of the following legal bases:
- Contract, when processing is necessary to provide the Service requested by you or to take steps before entering into a contract.
- Legitimate interests, including operating, securing, supporting, analyzing, and improving the Service, communicating with users and customers, and protecting legal rights, provided those interests are not overridden by your rights and interests.
- Consent, where we ask for consent for a specific purpose, such as optional product analytics, certain cookies, or marketing communications.
- Legal obligation, when processing is necessary to comply with applicable law.
10.3 International Transfers
Grydell is a United States company. We and our service providers may process personal information in the United States and other countries that may have data protection laws different from those in your country. Where required, we use recognized safeguards for restricted transfers, such as adequacy decisions, the European Commission's Standard Contractual Clauses, and the United Kingdom International Data Transfer Addendum. You may contact us to request additional information about the safeguards relevant to your personal information.
10.4 European Rights
Individuals in the EEA, United Kingdom, and Switzerland may exercise the rights listed in Section 9, subject to applicable limitations. You may also object to processing based on legitimate interests and to direct marketing at any time. If you believe our response is inadequate, you may lodge a complaint with your local supervisory authority.
10.5 Automated Decision-Making
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects concerning individuals unless we provide any notice, safeguards, and rights required by applicable law.
11. Additional Information for Users in the Republic of Korea
Where the Personal Information Protection Act of the Republic of Korea applies, you may request access, correction, deletion, suspension of processing, or withdrawal of consent as provided by law. You may also contact us regarding the handling, overseas transfer, retention, or destruction of your personal information.
11.1 Overseas Transfers
Grydell transfers personal information and Customer Content overseas as necessary to provide the Service. Transfers occur through encrypted network connections when you create an account, use a feature, make a payment, allow optional analytics, or otherwise submit information to the Service.
- Amazon Web Services, Inc., United States. Purpose: cloud hosting, storage, database, backup, security, and content delivery. Information: account data, Customer Content, usage data, and system logs. Transfer timing and method: continuously as the Service is used, through encrypted network transmission. Retention: for the periods stated in Section 7, including backups for up to 90 days after deletion.
- WorkOS, Inc., United States. Purpose: authentication, identity management, organization membership, invitations, and account security. Information: name, email address, profile and authentication data, organization and membership data, and security metadata. Transfer timing and method: when you create an account, authenticate, manage membership, or accept an invitation, through encrypted network transmission. Retention: for the account relationship and thereafter as required by applicable agreement, security, and legal obligations.
- OpenAI, L.L.C., United States. Purpose: AI-based analysis, prompt processing, generation, editing, and related technical functions. Information: prompts, selected image regions, reference images, configuration data, and outputs required for the requested function. Transfer timing and method: when an applicable AI feature is used, through encrypted API transmission. Retention: up to 30 days for abuse monitoring unless a shorter or zero-retention control applies, and longer only when legally required.
- Google LLC, United States and other countries in which Google or its subprocessors operate. Purpose: Gemini-based image and prompt processing, generation, editing, and related technical functions. Information: prompts, selected image regions, reference images, configuration data, and outputs required for the requested function. Transfer timing and method: when an applicable Gemini feature is used, through encrypted API transmission. Retention: limited abuse-monitoring storage under Google's applicable terms and project-isolated in-memory caching for up to 24 hours; optional sharing for Google model improvement is not enabled by Grydell.
- Stripe, Inc. and its affiliates, United States and countries in which Stripe, payment methods, or financial partners operate. Purpose: payment processing, subscription management, billing, tax, fraud prevention, and financial compliance. Information: name, email address, billing address, payment-method information, tax information, transaction details, and subscription information. Transfer timing and method: when a payment, subscription, refund, or billing event occurs, through encrypted network transmission. Retention: for the payment relationship and thereafter as required for tax, accounting, anti-money-laundering, fraud-prevention, dispute, and other financial-compliance obligations, generally up to seven years.
- PostHog, Inc., United States. Purpose: optional product analytics, feature flags, and session replay. Information: a Grydell analytics identifier, account and internal-user status, organization and project identifiers, bounded feature-use metadata, sanitized page routes, device and browser information, and masked interaction data. Transfer timing and method: only after the applicable analytics choice is granted and while the Service is used, through encrypted network transmission. Retention: session replay for 30 days; other analytics data according to the criteria in Section 7.
You may refuse or withdraw consent to an overseas transfer where consent is the applicable legal basis. Because some overseas processing described above is necessary to provide core Service functions, refusal may prevent account creation, AI generation or editing, storage, or payment functionality. Optional analytics may be declined without preventing use of the Service. Contact us before withdrawing consent from necessary processing so that we can explain the effect on your account and process any deletion request.
11.2 Destruction and Privacy Contact
When a retention period expires, electronic records are deleted using methods designed to prevent ordinary recovery, and paper records, if any, are shredded or otherwise securely destroyed. Backup copies are isolated from routine access and overwritten within the period stated in Section 7.
Grydell Operations handles privacy inquiries for users in the Republic of Korea. Requests and complaints may be submitted to [email protected] with the subject line "Korea Privacy Request." We will verify identity where necessary and respond in accordance with applicable law.
12. Children's Privacy
The Service is intended only for individuals who are at least 18 years old and is not directed to children or minors. Individuals under 18 may not create an account, access, or use the Service. We do not knowingly collect personal information directly from individuals under 18.
If you believe that an individual under 18 has provided personal information to us, please contact us at [email protected]. We will take reasonable steps to investigate, restrict or close the account, and delete the information where required. A school, business, or other organization may authorize only individuals who are at least 18 years old to use the Service.
13. Third-Party Services and Links
The Service may contain links to third-party websites or allow you to interact with third-party services. Their privacy practices are governed by their own policies. Grydell is not responsible for the privacy practices of third parties that are not acting as our service providers. We encourage you to review their policies before providing personal information.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or the Service. We will revise the Effective Date when we update the policy. If a change materially affects how we use personal information, we will provide notice through the Service, by email, or by another method required by law. Where consent is required for a new use, we will request consent.
15. Contact Us
If you have questions, concerns, complaints, or requests regarding this Privacy Policy or our privacy practices, contact us at:
Grydell, Inc.
2810 North Church Street, Suite 88079
Wilmington, Delaware 19802
United States
Email: [email protected]
Website: grydell.com
Please use the subject line "Privacy Request" when exercising a privacy right.