Privacy Policy
Last updated: July 21, 2026 · Effective: May 20, 2026
Grain (web, desktop, and mobile) · Macrodeep Inc.
This privacy policy explains how Macrodeep Inc. (“we”, “us”, “our”) handles information when you use Grain — including the website at grain.sh, the application at app.grain.sh, the Grain desktop apps, and the Grain Mobile iOS app (together, the “Service”). It is written for people who care how their Personally Identifiable Information (PII) is used online: data that can identify, contact, or locate you, alone or with other data.
Please read this policy carefully. By using the Service you agree to this Privacy Policy and our Terms of Service. If you do not agree, do not use the Service.
1. Who we are
The Service is provided by Macrodeep Inc., San Francisco, California, USA. Contact: support@grain.sh · privacy@grain.sh
2. What personal information we collect
Depending on how you use Grain, we may collect:
- Account information — name, email address, password (stored hashed; we never store plaintext passwords), organization name, role, and profile details you provide.
- Billing information — when you subscribe, our payment processor collects payment details. We receive limited billing metadata (plan, status, last four digits where applicable) — not full card numbers on our servers when processed by a PCI-compliant provider.
- Workspace content — tasks, messages, agent runs, projects, knowledge, integrations config, and other content you or your agents create in Grain.
- Device and technical data — device labels, executor client IDs, IP address, browser/app version, and basic logs needed to operate and secure the Service.
- Push tokens — if you enable notifications on mobile, an APNs device token so we can deliver alerts.
- Communications — support tickets, feedback, and email you send us.
- Usage data — product analytics about features you use, limited to improving Grain (see §5).
3. When we collect information
We collect information when you:
- Register or sign in (email/password, email code, or Google OAuth)
- Create or join a workspace / organization
- Use Workrooms, agents, integrations, or other product features
- Install the desktop app or Grain Mobile and connect a device
- Subscribe, change plans, or contact support
- Visit grain.sh marketing pages (see cookies, §6)
4. How we use your information
- To provide, operate, and secure the Service
- To personalize your experience and deliver features you request
- To improve the product, documentation, and support quality
- To process subscriptions and send service-related notices
- To enforce our Terms, prevent abuse, and comply with law
- To respond to support and security inquiries
We do not sell your personal information. We do not use your workspace content to train third-party foundation models.
5. Local execution and your code
A core design of Grain is that agent execution can run on your machines (desktop companion / local executor). Source code and credentials that stay on your device are under your control. Cloud components orchestrate tasks, store workspace metadata, and deliver the web/mobile UI. You choose which projects and paths agents may access on each device.
6. Cookies and similar technologies
We use essential cookies and local storage for authentication sessions and preferences. On marketing sites we may use privacy-respecting analytics to understand traffic. You can control cookies via your browser settings. Blocking essential cookies may prevent sign-in.
7. How we protect information
- HTTPS / TLS for data in transit
- Access controls and organization isolation on multi-tenant backends
- Encrypted storage practices for production databases and backups
- Session tokens and secrets handled with industry-standard care
No method of transmission or storage is 100% secure. We work to protect your data but cannot guarantee absolute security.
8. Third parties
We use subprocessors only as needed to run Grain, for example:
- Cloud infrastructure and database hosting
- Email delivery for auth codes and product email
- Payment processors for billing
- Optional integrations you enable (e.g. Slack, Linear, Google) under their terms
- Apple Push Notification service for mobile notifications you enable
When you connect third-party services, their privacy policies apply to data you authorize them to receive.
9. Retention
We retain account and workspace data for as long as your organization is active and as needed to provide the Service, resolve disputes, and meet legal obligations. You may request deletion of your account (see §11).
10. International transfers
We may process data in the United States and other countries where we or our processors operate. By using the Service you understand that your information may be transferred to jurisdictions with different data-protection laws than your own.
11. Your rights and choices
Depending on your location, you may have rights to:
- Access, correct, or delete personal data we hold about you
- Export workspace data where the product supports it
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Opt out of non-essential marketing email
Account deletion is available in-product where offered (including Grain Mobile: More → Delete my account) or by emailing support@grain.sh. Shared workspace content may remain under your organization’s ownership so teammates’ work is not broken.
12. Children
Grain is a business product and is not directed at children under 13 (or under 16 where applicable). We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
13. California / GDPR notes
If you are a California resident or in the EEA/UK, additional rights may apply under CCPA / GDPR. We act as a controller for account data and as a processor for Customer Data you upload when processing is on your instructions under a separate DPA where applicable. Contact privacy@grain.sh for requests.
14. Changes
We may update this policy. Material changes will update the “Last updated” date and may be announced in-app or by email. Continued use after changes constitutes acceptance of the updated policy.
15. Contact
Macrodeep Inc.
San Francisco, California, USA
support@grain.sh
privacy@grain.sh
This policy is hosted at https://grain.sh/privacy and applies to the Grain product family published by Macrodeep Inc.