Privacy Policy

Last updated: August 20, 2026

We do not share your data.

  • We never sell it. Not to data brokers, not to advertisers, not to anyone, under any circumstances.
  • We never train AI models on it. Your loan tapes, documents, notebooks, and queries are not used to train or fine-tune any model — ours or a third party's.
  • No other customer ever sees it. Your content is isolated per account at the storage layer, the API layer, and the database layer. Nothing you upload informs, improves, or appears in another customer's results.
  • Nothing leaves the platform except to run it. The only third parties that ever touch your content are the infrastructure and AI providers required to operate the service. Every one of them is named below, is contractually barred from using your data for their own purposes, and operates under zero-retention terms.

Graam AI, LLC ("Graam," "we," "us," or "our"), a limited liability company based in New York, NY, operates the Graam AI platform at graam.ai and is the data controller for the personal information described here. This policy describes what we collect, how we use it, and the controls you have. For the technical detail behind our security claims — encryption, tenant isolation, access control, audit logging — see our Security page.

1. Our data commitments

The commitments above are binding statements about how we operate, not aspirations. Concretely:

  • No sale, no brokerage, no advertising. We have no advertising business and no data-licensing business. We do not disclose personal information to third parties for cross-context behavioral advertising, and we have not done so in the preceding twelve months.
  • No model training. We do not train, fine-tune, or evaluate models on customer content. Our AI providers process your content only to return the response to your request, under enterprise agreements that prohibit training on it and require zero retention.
  • No cross-customer learning. Nothing derived from your uploads — no embedding, no cached result, no statistical aggregate — is used to answer another customer's question.
  • You own your content. The notebooks, tapes, documents, and models you create remain yours. We claim no license to them beyond what is required to store and process them for you.

2. Information we collect

  • Account information: Email address, name, and authentication credentials when you create an account or sign in via Google OAuth. We receive your name, email address, and profile image from Google — nothing else from your Google account.
  • Content you upload or create: Notebooks, loan tapes and other data files, documents, queries, models, and outputs. Loan-level tapes may contain borrower data; they receive the same controls as every other artifact, with no less-protected lane.
  • Technical data: Browser type, IP address, device information, and session data, collected automatically to authenticate requests, enforce rate limits, and investigate abuse.
  • Cookies: Session cookies required for authentication and basic platform function. We do not use advertising cookies, third-party trackers, or cross-site analytics.

3. How we use your information

We use your information only for the following purposes:

  • To provide the platform — running the analyses you request and returning results.
  • To authenticate your identity and manage your account.
  • To store and sync your notebooks, files, and models across sessions.
  • To communicate with you about service updates or security issues.
  • To detect and prevent fraud, abuse, or violations of our terms.
  • To maintain and improve the platform. Where this involves reviewing content, it is limited to aggregate, non-content telemetry (error rates, latency, feature usage) — or to a specific artifact you have explicitly shared with us to debug a problem you reported.

We do not use your content for any other purpose. If we ever needed to, we would ask for your opt-in consent first.

4. Who we share data with

We do not sell your personal information and we do not share it for anyone else's benefit. Your data is disclosed in exactly three circumstances:

  • To operate the platform. The sub-processors listed below process your data solely to deliver the service to you, under written agreements that bar any other use. They are not permitted to retain, sell, or train on it.
  • At your direction. When you share a notebook or invite a colleague to your organization, you are choosing to disclose that content. Shared notebooks expose the notebook's cells and outputs; they do not expose the underlying source documents or data files.
  • When compelled by law. We may disclose information if required by law, subpoena, court order, or governmental regulation. Where we are legally permitted to do so, we will notify you before disclosing your content, so that you have an opportunity to challenge the request.

If Graam is ever acquired or merged, your data may transfer as part of that transaction. The acquirer would be bound by this policy until you are notified of any change and given the opportunity to delete your account.

5. Sub-processors

This is the complete list of third parties that may process customer content. Each is bound by a data-processing agreement prohibiting use of your data for any purpose other than providing their service to us.

ProviderPurposeWhat it sees
Google Cloud PlatformStorage, database, and compute hostingEncrypted files and metadata at rest. Google cannot read content encrypted with a customer-managed key.
AnthropicAI analysis and code generationDocument-derived content and queries relevant to your request, under enterprise zero-retention terms. No training on your data.
OpenAIAI routing and response synthesisDocument-derived content and queries relevant to your request, under enterprise zero-retention terms. No training on your data.
Google Identity (OAuth)Sign-inYour name, email address, and profile image. No platform content.

We will update this list before adding a sub-processor that processes customer content. Enterprise customers can request advance notice of changes.

6. Data residency and transfers

Customer content is stored in Google Cloud's us-central1 region in the United States by default. Enterprise deployments can pin storage to a specific region, including in the EU, on request. If you access the platform from outside the United States, your data will be transferred to and processed in the US; where required, we rely on Standard Contractual Clauses for those transfers.

7. Security

Your content is protected by layered controls:

  • Encryption. AES-256 at rest and TLS 1.2+ in transit. Enterprise customers can supply their own Cloud KMS key — revoking your grant on that key cryptographically locks both Graam and Google out of your data.
  • Tenant isolation. Enterprise deployments store each customer's content in a dedicated storage bucket with its own IAM scope, public-access prevention, and object versioning.
  • Verified identity on every request. Access decisions are driven by a signed, verified token — never by a parameter in a URL.
  • Ownership enforced at the database. Your account identity is part of the query itself, so a request for another customer's record returns nothing.
  • Audit logging. Every API request and every AI-initiated document read is logged with the verified caller identity and retained for at least 90 days.

No system is perfectly secure, and we do not claim to be. We publish our full control inventory, including work still on our roadmap, on the Security page. Graam is not yet SOC 2 certified; we will say so plainly rather than imply otherwise, and we share our controls inventory and gap analysis on request.

8. Retention and deletion

  • Content: retained for as long as your account is active, or until you delete it.
  • Deleted items: removed from the platform immediately on deletion and purged from backing storage within 30 days.
  • Closed accounts: all content is deleted within 30 days of your request, except where retention is required by law.
  • Audit and security logs: retained for at least 90 days for incident investigation.

Request deletion or a full export of your data at [email protected]. We acknowledge within 5 business days.

9. Your privacy rights

Whatever jurisdiction you are in, we extend the following rights to every user:

  • Access and portability — obtain a copy of your personal information and your content in a machine-readable format.
  • Correction — fix inaccurate account information.
  • Deletion — delete your account and all associated content.
  • Objection and restriction — object to or restrict specific processing.
  • Withdraw consent — where processing relies on consent, withdraw it at any time.
  • Non-discrimination — we will not degrade your service for exercising any of these rights.

Where the GDPR applies, our legal bases are performance of our contract with you (providing the platform), our legitimate interests (security, abuse prevention, service improvement), and your consent where specifically requested. Under the CCPA, we confirm that we have not sold or shared personal information in the preceding twelve months. Exercise any right by writing to [email protected]; we respond within 30 days.

10. Breach notification

If we discover a security incident affecting your data, we will notify affected customers without undue delay and within 72 hours of confirming the incident, with what we know about scope and impact, and what we are doing about it. Security researchers can report vulnerabilities to [email protected]; we acknowledge within 48 hours and operate coordinated disclosure.

11. Platform terms and disclaimers

AI accuracy

Graam AI uses artificial intelligence to analyze financial data, generate models, and produce forecasts. AI-generated outputs may contain errors, inaccuracies, or omissions. We do not guarantee the accuracy, completeness, or reliability of any data, analysis, model output, or forecast produced by the platform. All outputs are provided on an "as-is" basis. You are solely responsible for independently verifying any information before making financial, investment, or business decisions based on it.

No financial advice

Nothing on the Graam AI platform constitutes financial, investment, legal, or tax advice. The platform is a tool for analysis and research purposes only. You should consult qualified professionals before acting on any information obtained through the platform.

Permitted use

Graam AI is intended for use by individual humans for legitimate analytical and research purposes. The following uses are strictly prohibited:

  • Automated scraping or data extraction: You may not use bots, crawlers, scrapers, or any automated means to access, collect, or extract data from the platform.
  • Non-human use: Access must be by a human user. Programmatic or automated access via APIs, scripts, or agents is not permitted without explicit written authorization.
  • Redistribution: You may not resell, redistribute, or sublicense platform outputs or data to third parties.
  • Abuse: You may not use the platform to generate misleading analyses, manipulate markets, or for any unlawful purpose.

Limitation of liability

To the fullest extent permitted by law, Graam AI shall not be liable for any direct, indirect, incidental, consequential, or special damages arising from your use of the platform, reliance on any outputs or analyses, or any interruption or loss of data. You use the platform at your own risk.

Age requirement

The platform is intended for business use by individuals aged 18 or over. We do not knowingly collect personal information from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. For material changes — in particular any change to the commitments at the top of this page — we will notify account holders by email at least 30 days before the change takes effect, so that you can export your data or close your account first. Non-material changes are posted here with a revised "Last updated" date.

13. Contact

The data controller responsible for your personal information is:
Graam AI, LLC
New York, NY, United States

Privacy questions and data-rights requests: [email protected]
Security reports, questionnaires, and audit requests: [email protected]
Data processing agreements are available to enterprise customers on request.