Privacy policy
What this website and the Gridwork app collect, who else sees it, how long we keep it, and how to make us stop.
Last updated 1 September 2026
This policy is about Gridwork specifically, not about privacy in general. If a sentence here is unclear or wrong, email us and a human will answer.
Who we are
Gridwork is a product of Momentem, at Office A, Innovation Business Center, Al Rifaa, Ras Al Khaimah, United Arab Emirates. We decide what is collected and what happens to it. In data protection language that makes us the controller; in plain language it means the decisions and the responsibility are ours.
Two different things are covered here, and this policy keeps them apart because they behave differently.
- The website: the pages you are reading now, including the beta request form and the Ask Alex widget in the corner.
- The app: the Gridwork workspace, where an invited customer briefs employees, approves work and connects their own accounts.
For anything in this policy, write to hello@bygridwork.com or to the office address above.
What we collect on this website
- The request form: your name, work email, phone number, company name, company size, industry, and whatever you write in the box about what you are trying to solve. Also your two consent answers, recorded separately, and the fact that you accepted the terms of use.
- An invisible field and a timer: the form carries a field a person never sees, and a check on how quickly it was filled in. Both are there to catch automated submissions. A submission that trips either gets the same friendly answer as everyone else and is stored nowhere.
- The bot check: a Cloudflare check runs before the form will submit. Cloudflare receives your IP address, your browser fingerprint, your user-agent string and our public site key. We get back a pass or a fail and nothing else about you.
- Rate limiting: a short-lived count kept against your IP address, so one person cannot flood the form or the Ask Alex widget.
- Ask Alex: whatever you type into the widget, and the answer we give you. Its own section further down says exactly where that goes.
- Server logs: our host records what every web host records, which is the IP address, the user-agent, the page requested, the time and the response.
- Nothing else. There is no cross-site tracking and no profile of you. Two things load from another company into your browser: the bot check on the form, and the Google Ads measurement tag, which sets an advertising identifier only if you accepted the cookie banner. Both have their own sections, here and in the cookie policy.
What we collect in the app
- Account details: name, work email and company for each person in a workspace.
- Your brief and your uploads: the documents, brand notes and guardrails you give your employees.
- Connected account data: only what an integration returns, under the scopes you granted, at the moment a task needs it. Connections use scoped access tokens you can revoke at any time.
- Work and approvals: what each employee planned and produced, what you approved or rejected, when you decided, and what the work cost.
- Product usage: timings and counts. How long a page took, how long an approval waited, how often something failed.
While your access is a beta invitation nothing is charged, so there is no card on file and we hold no payment details at all.
Why we are allowed to
Different countries name the grounds for this differently, so here they are in plain English rather than in one country's vocabulary.
- Because you asked us to: the request form, a reply to your message, and running the app for a customer who signed up for it.
- Because we agreed to: everything the app does under the agreement between us.
- Because the service has to defend itself: bot checks, rate limits, logs, and looking into abuse or fraud.
- Because you said yes, separately: marketing email, and later SMS and WhatsApp. That is consent, you give it per channel, and you can take it back whenever you like without losing anything else.
We do not send marketing on the argument that we have a legitimate interest in sending it. If you did not tick the box, you do not get it.
Who else sees it
Nobody buys it and nobody rents it. These companies process it for us, each under its own published privacy notice, and this is what each one actually gets.
- Vercel hosts this website and the app. It sees every request: IP address, user-agent, page and timing.
- Supabase is the database, the sign-in and the file storage behind the app, and the store behind this website’s forms. It holds account details, briefs, uploads, work and approvals — and every answer you give the beta request form, which is written there first, before anything else is done with it.
- Klaviyo is our email list and the message that confirms a beta request. It receives your name, email, phone number, company, company size, industry, what you wrote in the free-text box, and both of your consent answers. Klaviyo stores this in the United States. Only your email address is subscribed to anything. Your phone number is stored so that a channel you have already agreed to can be honoured later, and nothing messages it today.
- Cloudflare runs the bot check on our forms and receives what the request-form section describes.
- Resend delivers one email: the note telling us a beta request arrived. It receives your name, email address, phone number, company and what you wrote in the box, because that note IS your request. It goes to one address, ours, and Resend sends nothing to you.
- Upstash holds the rate limits: a key derived from your IP address, and a counter. Nothing you typed.
- Anthropic provides the model behind Ask Alex and behind every Gridwork employee. The next section is entirely about that.
- PostHog measures product usage inside the app and is not present on this website at all. It receives event names, workspace and employee identifiers, page templates, durations and counts. It is deliberately configured to capture no clicks, no automatic page views, no session recordings and no personal profiles.
- Google Ads runs the advertising measurement tag on this website, and only there — it is not in the app. Before you accept the cookie banner it receives your IP address, your user-agent and the page you are on, with no identifier attached and nothing stored on your device. If you accept, it also sets its own cookies and can join your visit to the ad you clicked. The cookie policy names the account and the cookies.
- Trigger.dev runs the scheduled and background work behind employees, so the instructions for a job pass through it.
- Sentry receives error reports from the app, configured not to send personal information by default.
Beyond those, we hand something over only if a court or a regulator with authority over us requires it, and we will tell you when we are allowed to.
Ask Alex, and the model behind him
Ask Alex is the chat widget on this website. A model answers it, and this is exactly what happens.
Your question goes to our server and from there to Anthropic, together with a fixed set of instructions and some content from these pages. The answer comes back and we show it to you.
Under Anthropic's commercial terms, inputs and outputs are deleted within 30 days and are not used to train models. Content flagged for a policy violation is kept longer, and Anthropic's own privacy notice says how long.
What we keep is a record that a call happened, which model answered, how much work it was and what it cost. Your question and the answer are not in that record. We do not store the conversation, we do not attach it to you, and we do not build a profile from it. Close the tab and it is gone from our side.
Please do not type anything confidential into it. It is a public widget on a public page with a model on the other end. If you need to tell us something sensitive, email us instead.
If the model is unavailable, or the day's spending limit has been reached, Alex answers from a short set of written answers and no question is sent to a model at all.
Where it lives
The app's data sits in Supabase and both the site and the app run on Vercel. Every workspace is isolated in the database itself: a row belongs to one workspace and the database refuses to hand it to another, rather than the application politely declining to ask.
Traffic is served over HTTPS and both providers encrypt what they store. Access by us is limited to the people who need it to run the service, and what happens inside a workspace is written to a record that only ever appends, so it cannot be quietly rewritten.
Both providers publish their own security credentials. We hold none of our own yet, and this page will not imply that we do until we do.
How long we keep it
- A request from this website is kept in our email tool while the beta list is open and while we are still in touch with you about it. Ask us to delete it and we will, within 30 days.
- A workspace is kept while your account is active. When one is deleted, every employee stops immediately, every connection is disconnected, the workspace disappears from every screen except a restore notice, and an export is offered. Thirty days later everything is purged: the rows, the stored files and the session records. That window exists so that a mistake, or somebody else getting into your account, is recoverable. After it, the data is gone and we cannot bring it back.
- Ask Alex questions are not stored by us. Anthropic deletes them on the schedule described above.
- Rate limiting counters last minutes.
- Server logs are kept by our host on its own schedule.
- The spending record, which holds identifiers, counts and costs and never the content of a message, is kept for as long as we need it for our accounts.
Your choices, and how to use them
- Ask for a copy of what we hold about you.
- Tell us something is wrong and we will correct it.
- Ask us to delete it. Data deletion is the step-by-step version of this, one route per thing you want gone.
- Take back a consent. Every marketing email carries an unsubscribe link and it works straight away. If SMS or WhatsApp ever launches, only the people who gave that separate consent will be messaged, and it can be withdrawn the same way. Withdrawing marketing consent changes nothing about your account or the emails we have to send to run it.
- Disconnect an integration from inside the app at any time. Your employees lose that access immediately.
- Ask for an export of your workspace.
- Ask about a data processing agreement. If your legal team needs one, tell us what it has to cover and we will come back to you.
To do any of these, email hello@bygridwork.com from the address you gave us, or write to the office. We aim to answer within 30 days and we will tell you if something needs longer.
If you think we have got this wrong, tell us first. We would rather fix it than have you find out from somebody else. You can also complain to the data protection authority where you live.
If we change this policy in a way that matters, the date at the top changes and we email everyone on our list and everyone with an account.
The terms of use say what you and we each agree to, and the cookie policy lists exactly what this site puts in your browser. Data deletion tells you which button to press to undo any of it.