Last updated: August 20, 2026
We do not share your data.
Graam AI, LLC ("Graam," "we," "us," or "our"), a limited liability company based in New York, NY, operates the Graam AI platform at graam.ai and is the data controller for the personal information described here. This policy describes what we collect, how we use it, and the controls you have. For the technical detail behind our security claims — encryption, tenant isolation, access control, audit logging — see our Security page.
The commitments above are binding statements about how we operate, not aspirations. Concretely:
We use your information only for the following purposes:
We do not use your content for any other purpose. If we ever needed to, we would ask for your opt-in consent first.
This is the complete list of third parties that may process customer content. Each is bound by a data-processing agreement prohibiting use of your data for any purpose other than providing their service to us.
| Provider | Purpose | What it sees |
|---|---|---|
| Google Cloud Platform | Storage, database, and compute hosting | Encrypted files and metadata at rest. Google cannot read content encrypted with a customer-managed key. |
| Anthropic | AI analysis and code generation | Document-derived content and queries relevant to your request, under enterprise zero-retention terms. No training on your data. |
| OpenAI | AI routing and response synthesis | Document-derived content and queries relevant to your request, under enterprise zero-retention terms. No training on your data. |
| Google Identity (OAuth) | Sign-in | Your name, email address, and profile image. No platform content. |
We will update this list before adding a sub-processor that processes customer content. Enterprise customers can request advance notice of changes.
Customer content is stored in Google Cloud's us-central1 region in the United States by default. Enterprise deployments can pin storage to a specific region, including in the EU, on request. If you access the platform from outside the United States, your data will be transferred to and processed in the US; where required, we rely on Standard Contractual Clauses for those transfers.
Your content is protected by layered controls:
No system is perfectly secure, and we do not claim to be. We publish our full control inventory, including work still on our roadmap, on the Security page. Graam is not yet SOC 2 certified; we will say so plainly rather than imply otherwise, and we share our controls inventory and gap analysis on request.
Request deletion or a full export of your data at [email protected]. We acknowledge within 5 business days.
Whatever jurisdiction you are in, we extend the following rights to every user:
Where the GDPR applies, our legal bases are performance of our contract with you (providing the platform), our legitimate interests (security, abuse prevention, service improvement), and your consent where specifically requested. Under the CCPA, we confirm that we have not sold or shared personal information in the preceding twelve months. Exercise any right by writing to [email protected]; we respond within 30 days.
If we discover a security incident affecting your data, we will notify affected customers without undue delay and within 72 hours of confirming the incident, with what we know about scope and impact, and what we are doing about it. Security researchers can report vulnerabilities to [email protected]; we acknowledge within 48 hours and operate coordinated disclosure.
Graam AI uses artificial intelligence to analyze financial data, generate models, and produce forecasts. AI-generated outputs may contain errors, inaccuracies, or omissions. We do not guarantee the accuracy, completeness, or reliability of any data, analysis, model output, or forecast produced by the platform. All outputs are provided on an "as-is" basis. You are solely responsible for independently verifying any information before making financial, investment, or business decisions based on it.
Nothing on the Graam AI platform constitutes financial, investment, legal, or tax advice. The platform is a tool for analysis and research purposes only. You should consult qualified professionals before acting on any information obtained through the platform.
Graam AI is intended for use by individual humans for legitimate analytical and research purposes. The following uses are strictly prohibited:
To the fullest extent permitted by law, Graam AI shall not be liable for any direct, indirect, incidental, consequential, or special damages arising from your use of the platform, reliance on any outputs or analyses, or any interruption or loss of data. You use the platform at your own risk.
The platform is intended for business use by individuals aged 18 or over. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. For material changes — in particular any change to the commitments at the top of this page — we will notify account holders by email at least 30 days before the change takes effect, so that you can export your data or close your account first. Non-material changes are posted here with a revised "Last updated" date.
The data controller responsible for your personal information is:
Graam AI, LLC
New York, NY, United States
Privacy questions and data-rights requests: [email protected]
Security reports, questionnaires, and audit requests: [email protected]
Data processing agreements are available to enterprise customers on request.