Privacy Policy
How Grego AI collects, uses, shares, secures, and retains personal information and customer code.
This Privacy Policy explains how Grego AI (“Grego AI,” “we,” “us,” and “our”) collects, uses, shares, and retains personal information when you visit our websites, request access, create an account, connect a repository, or use our security scanning services (collectively, the “Service”).
This policy applies globally as a baseline. Local law may provide additional rights. If your organization has a separate written agreement with Grego AI, that agreement may include additional privacy or data-processing terms.
1. Information we collect
We may collect the following categories of information:
- Contact and access-request data, such as name, work email, company or project, repository URL, and any message you submit.
- Account data, such as email address, display name, authentication events, access status, role, and account settings.
- Repository and integration data, such as repository owner and name, visibility, branch or pull-request references, installation identifiers, and integration status.
- Customer Content, including selected source code, repository files, scan scope, instructions, findings, reports, and exported results.
- Billing and usage data, such as credit balance, transactions, scan estimates, scan status, and feature activity.
- Website analytics data, when Vercel Web Analytics is enabled, such as the generalized page or route viewed, referrer, approximate location, device, browser, operating system, and selected public-site actions with limited context such as a call-to-action location, public report slug or evidence label, or social network. We do not send names, email addresses, account or organization identifiers, source code, repository or file paths, search terms, or the bodies of findings or comments through website analytics.
- Technical and security data, such as IP address, user agent, request timestamps, device or browser information, logs, rate-limit events, abuse-prevention signals, and error diagnostics.
- Communications you send to us, including support, sales, legal, and account-deletion requests.
2. How we collect information
We collect information directly from you, automatically when you use the Service, from an organization that manages your access, and from services you connect, such as a source-code hosting provider. We may also receive limited information from vendors that help us operate, secure, and communicate about the Service.
3. How we use information
We use information to:
- review access requests and create, authenticate, and administer accounts;
- connect authorized repositories, estimate scans, process selected code, and produce findings and reports;
- provide support, service communications, run-status notices, and security alerts;
- operate credits, billing records, exports, and account-deletion workflows;
- protect the Service, enforce limits, prevent spam and abuse, and investigate incidents;
- monitor reliability, understand aggregate product usage, and improve Service operation;
- comply with law, resolve disputes, and enforce agreements; and
- carry out another purpose that we disclose when collecting information or that you authorize.
4. Source code and AI processing
We process only the repository content and scope made available through your authorized use of the Service. Private code may be processed by infrastructure, security-analysis, and AI service providers acting on our behalf and subject to contractual or technical restrictions appropriate to their role.
We do not use Customer Content or customer-specific reports to train general-purpose models, and we do not share one customer’s private code or reports with another customer.
5. How we share information
We do not sell personal information, and we do not use personal information for third-party behavioral advertising. We may disclose information to the following categories of recipients when reasonably necessary:
- cloud hosting, database, storage, authentication, and infrastructure providers;
- source-code hosting and integration providers you choose to connect;
- security, abuse-prevention, observability, and incident-response providers;
- email, support, and operational communications providers;
- AI and security-analysis providers used to deliver scan functionality;
- professional advisers, auditors, insurers, regulators, or law-enforcement authorities when legally appropriate; and
- a buyer, investor, successor, or other party involved in a merger, financing, reorganization, or sale of all or part of our business, subject to appropriate safeguards.
6. Cookies, local storage, and website analytics
We use cookies and similar browser storage that are necessary for authentication, session continuity, security, abuse prevention, and user preferences such as theme or sidebar state. On the public website, we use Vercel Web Analytics to measure anonymous, aggregated page views and selected interactions. Vercel processes these measurements to provide Web Analytics and does not set analytics cookies. Website analytics are not associated with a name, email address, or account identifier. We remove query strings and fragments from the viewed or event URL before analytics events are sent, and custom event context is limited to the public values described in Section 1. We do not use third-party advertising cookies.
7. Retention
We generally retain account data, Customer Content, scans, reports, and transaction history while your account is active so that we can provide the Service, support you, and maintain a usable history. Access requests and operational or security logs may be kept for as long as reasonably necessary for business, security, anti-abuse, and legal purposes.
Following a verified account-deletion request, we aim to remove active account data and Customer Content within 30 days, except where we must retain information to comply with law, complete legitimate transactions, prevent fraud or abuse, resolve disputes, or enforce agreements. Residual copies may remain temporarily in backups until those backups rotate.
8. International processing
Grego AI and its providers may process information in countries other than where you live or work. Those countries may have different data-protection laws. Where required, we use contractual or other recognized safeguards for international transfers.
9. Security
We use administrative, technical, and organizational measures designed to protect information, including access controls, scoped integrations, short-lived credentials where supported, encryption in transit, and monitoring. No method of transmission, processing, or storage is completely secure, and we cannot guarantee absolute security.
You are responsible for protecting your account, controlling repository permissions, and promptly reporting suspected unauthorized access to hello@grego.ai.
10. Your choices and rights
Depending on where you are located, you may have rights to access, correct, export, delete, restrict, or object to certain processing of your personal information, or to withdraw consent where processing relies on consent. You may update available account information, export account data, or request account deletion through Settings.
You may also submit a privacy request to hello@grego.ai. We may need to verify your identity and authority before completing a request. We will not discriminate against you for exercising a privacy right. You may have the right to complain to a local data-protection authority.
11. Children
The Service is intended for businesses and professionals and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information to us, contact hello@grego.ai.
12. Changes to this policy
We may update this Privacy Policy as the Service or applicable requirements change. We will post the updated policy and change the effective date. If a change is material, we will provide reasonable notice through the Service or by email when practicable.
13. Contact
For privacy questions, data requests, or complaints, contact hello@grego.ai.