Privacy Policy
Privacy Policy
Effective May 12, 2026
What Granular does
Granular helps people build public proof-of-work profiles from the AI tools they already use. Assistants can draft entries or profile changes, but nothing is published to a Granular profile until the account owner approves it.
Information we collect
We collect account information such as name, username, email address, sign-in identifiers, settings, and public profile fields. We store published profile content, approved entries, tags, traits, profile sections, attachments that the owner approves, and metadata needed to operate the service.
Granular Connect stores unpublished draft text and attachments in a local SQLite database on the user's own computer. The website reads those drafts directly from the local Connect app over an authenticated loopback connection. Unpublished draft content is not uploaded to our servers. The first server request containing an entry's content occurs only after the account owner explicitly presses Publish.
We may process connector and device metadata, authentication tokens, approval outcomes, and privacy-scrubbed usage counters needed to keep Connect working. Those counters do not include draft titles, bodies, summaries, attachments, prompts, or file contents.
How we use information
We use information to authenticate users, operate public profiles, publish and apply owner-approved entries, prevent abuse, debug the service, measure product usage, provide support, and maintain the integrity of public work records.
Sharing and visibility
Published profile pages and approved entries are public. Private account information, local unpublished drafts, OAuth tokens, internal identifiers, and support communications are not sold. We share data with service providers only as needed to run Granular, such as hosting, authentication, storage, analytics, email, and security services.
Google user data
When a user connects a Google account, Granular requests read-only scopes only. With Gmail (gmail.readonly) it reads message headers and bodies. With Google Calendar (calendar.readonly) it reads events and attendees. With Google Drive (drive.readonly) it reads documents and their revision history. It also reads the account address and name (userinfo.email, userinfo.profile) to attach the connection to the right person. Granular cannot send, reply to, delete, move, or modify anything in a connected Google account.
This data is used to build the firm's Company Brain: a searchable, cited memory of the firm's people, companies, deals, and documents, which the firm's own members query and which powers meeting preparation and research features inside Granular. It is stored encrypted, isolated per firm, and shown only to the people the firm's own permissions allow.
Granular's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, not used for advertising, and not used to train generalised artificial intelligence or machine learning models. No human reads it except with the user's explicit permission, where it is necessary for security purposes, to comply with applicable law, or in aggregated and anonymised form.
A connection can be removed at any time from Connectors inside Granular, or from the Google account's third-party access settings. Removing a connection stops further reading and removes that source from the firm's memory.
Retention and deletion
Public profile content remains until the owner edits, hides, deletes, or closes the account. Review records and operational logs may be kept for a limited period for security, debugging, abuse prevention, and audit integrity. Account deletion requests can be sent to hello@granular.work.
Contact
Questions about this policy can be sent to hello@granular.work.