Privacy Policy
How Field Logic Ltd handles personal data through grith.ai and the grith product.
Last updated:
1. Who we are
This Privacy Policy is published by Field Logic Ltd ("Field Logic", "we", "us"), company number 15380264, registered in England and Wales and trading as grith. Our registered office is 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE. We are the controller for account, billing, website, and support data. For customer data submitted through team cloud features, we generally act as a processor under our Data Processing Agreement.
Contact for privacy / data-protection enquiries: privacy@grith.ai.
2. What this policy covers
This policy describes how we handle personal data when you:
- visit grith.ai or docs.grith.ai;
- create a grith account or sign in via GitHub;
- subscribe to a paid tier through Polar;
- email us, fill in the contact form, or report a vulnerability;
- run the grith product with cloud-sync features enabled.
The grith product itself runs locally on your machine. Most data processing - proxy evaluations, audit logs, supervisor traces - stays on your device unless you use a feature that sends data to our servers. Those features are described in section 3.5 Product telemetry and cloud sync; cloud analytics is on by default for paid plans.
3. What we collect and why
3.1 Website visitors
- Server logs - IP address, user-agent, requested URL, referrer, timestamp. Retained for up to 30 days for security and abuse-prevention purposes. Lawful basis: legitimate interests (operating and securing the service).
- Cloudflare Web Analytics - we count page views using Cloudflare Web Analytics, which is cookieless and storage-free: it writes nothing to your device and reads nothing from it, sets no identifier, and does not fingerprint you by IP address or user-agent. Because there is no identifier, you are not recognised between page loads or visits and no profile is built. We see aggregate counts only - page views, referring sites, country, browser and device type. Lawful basis: legitimate interests (understanding aggregate site usage). See our Cookie Policy for why this needs no consent banner.
3.2 Account holders
When you create an account:
- Email address - required for sign-in, transactional email (verification, licence delivery, billing), and support correspondence. Lawful basis: contract.
- Name and avatar - only if you sign in via GitHub OAuth. We receive your public GitHub profile (name, username, avatar URL, primary email). Lawful basis: contract.
- Authentication and device tokens - issued and managed by Better Auth, stored server-side and, for website sessions, as a secure HTTP-only cookie in your browser. Device-login and API credentials are associated with your account. Lawful basis: contract.
- Encrypted LLM provider keys - if you store OpenAI / Anthropic / OpenRouter / Ollama keys in your grith account, they are encrypted at rest with AES-256-GCM using a key derived from a server-held master secret. The Service decrypts a key only when returning it to an authorised administrator for the team that stored it; plaintext keys are not logged. Lawful basis: contract.
3.3 Paid subscribers
Payment is processed by Polar; we do not see or store your card details. From Polar we receive and store the subscription ID, tier, status, billing email, and subscription lifecycle events (created, renewed, cancelled, refunded). Lawful basis: contract.
3.4 Contact / support correspondence
If you email us or use the contact form, we hold the contents of your message together with your email address for as long as the enquiry remains open, plus a reasonable backlog period (typically 24 months). Lawful basis: legitimate interests (handling and improving customer support) or consent.
3.5 Product telemetry and cloud sync
The grith product includes features that send data to our servers:
- Cloud analytics (paid plans) - when you are signed in on a paid plan, the grith daemon sends aggregated usage and security analytics to our backend so that your team can review activity across devices. The daemon sends a heartbeat, and a snapshot whenever there is anything new to send, every 30 seconds; data is normally visible in the online dashboard within 60 seconds (95th percentile) while the device is connected. What is sent is limited to:
- decision rollups per UTC day and hour - counts of allowed, queued and denied tool calls, composite-score sums, a versioned 30-bin score histogram over the range 0 to 15, and per-filter evaluated, triggered and denied-contribution counts;
- labels identifying the session, project, profile, supervised tool and configuration;
- LLM provider and model identifiers, token counts, and cost in integer USD micros together with the price source and pricing version;
- destination rollups, keyed by a team-scoped HMAC rather than by the destination itself; a readable destination label appears only where your team owner has enabled approved labels;
- security events - queue, deny, canary and explicit data-gap events;
- device health - last contact, latest local event, dirty and archive backlog, completeness tier, and audit-database generation.
We never receive your command lines or arguments, file paths, URLs, prompts, model responses, file or source contents, payload bodies, environment values or secrets, or free-form task context and decision reasons: these have no field in the wire schema or the archive schema, so there is nowhere for them to be recorded.
Cloud analytics is on by default for a signed-in paid account, and the daemon records a consent receipt on your device the first time it turns itself on. Run
grith analytics statusto see the current state andgrith analytics disableto turn it off; settinggeneral.audit_sync = falsein your configuration also stops it entirely.Each machine registers as a device, identified by a server-issued device ID and a one-time secret stored on that machine with owner-only permissions. A paid plan allows two active devices per seat, capped at 50 per team. The cap is enforced only when a device registers with our servers and never degrades local security or supervision. Devices can be revoked from the team dashboard.
After a UTC day closes and we have accepted its rollups, your device exports that day's row-level analytics projection as a Parquet object and uploads it to private Amazon S3 storage. The object contains the same fields as the rollups, one row per event, and never the content excluded above. Objects are content-addressed, encrypted at rest under a KMS key that we manage, and the bucket blocks public access and requires TLS. Before an object is activated we verify its size, SHA-256 checksum, encryption and key identity: archives are checksum-verified, not signed.
- Update checks - the daemon may query the public GitHub Releases API to check for new versions. This reveals your IP and user-agent to GitHub; we receive no data from this call.
- Licence validation (Pro / Enterprise) - periodic signed-licence checks against our backend. We log your account ID and the timestamp.
Where features are explicitly opt-in or opt-out, the lawful basis is contract (delivering the feature you chose to use); where they support security and abuse prevention the basis is legitimate interests. Local-only usage of the open-source product never sends data to our servers.
4. Sub-processors
We rely on the following processors to deliver the service. Each is bound by a data-processing agreement and operates within the regions stated.
| Processor | Purpose | Region |
|---|---|---|
| Amazon Web Services (Amplify, RDS, S3, KMS, SES) | Hosting, database, email delivery | us-east-1 (N. Virginia, USA) |
| Polar | Payment processing and subscription management | EU / US (per Polar's sub-processor list) |
| GitHub (Microsoft) | OAuth identity provider; source-hosting | US |
| Cloudflare | CDN / DDoS mitigation in front of grith.ai; cookieless web analytics | Global edge |
We will give at least 30 days' notice before introducing a new sub-processor that materially changes how personal data is handled.
5. International transfers
Our primary hosting, database, and email infrastructure runs on Amazon Web Services in the United States (us-east-1, N. Virginia). Personal data of UK / EEA users is therefore transferred to and processed in the US. Other processors that handle data outside the UK / EEA include GitHub and Polar's US infrastructure. These transfers are covered by an adequacy decision where one applies (the EU-US Data Privacy Framework and its UK extension) and otherwise by the UK International Data Transfer Addendum / EU Standard Contractual Clauses with appropriate supplementary measures.
6. How long we keep your data
- Server logs: up to 30 days.
- Cloudflare Web Analytics: aggregate counts only, retained by Cloudflare for up to 6 months. No personal data is stored.
- Account and team data: while your account is active. Following a verified deletion request, we delete or anonymise it unless we must retain specific records for legal, security, or dispute purposes.
- Billing records: 7 years (UK tax / VAT requirement).
- Support correspondence: 24 months.
- Cloud analytics rollups and security events (paid plans): 90 days in our database.
- Daily analytics archive objects: 90 days for the active revision of a day; 7 days for a superseded revision of the same day.
- On your own device: the local analytics projection is kept for 90 days and the active forensic database for 30 days. Cold forensic archives have no automatic expiry and are managed by you.
When a paid entitlement expires, cloud analytics data becomes inaccessible immediately and is deleted after a 30-day reactivation window. Deleting a team removes both the database rows and the stored archive objects; object deletion runs as a separate job, and deletion is not complete until that job succeeds.
7. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data (subject to legal-retention exceptions);
- restrict or object to processing;
- data portability (receive a copy in a machine-readable format);
- withdraw consent at any time, where consent is the lawful basis;
- lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority.
Email privacy@grith.ai to exercise any of these rights. We normally respond within one month, subject to any extension permitted by data-protection law. We do not use the data covered by this policy for solely automated decisions that produce legal or similarly significant effects.
8. How we protect your data
Technical and organisational measures we take:
- TLS in transit for all public endpoints.
- Encryption at rest for stored secrets (provider keys, license signing key).
- Hashed-and-salted passwords (where used); session tokens issued and rotated by Better Auth.
- Secret material kept in a managed password vault, not on developer disks.
- Audit logging on production database access.
- Annual review of sub-processors and contracts.
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where the risk is high, notify affected users without undue delay.
9. Children
The grith service is not directed at children under 16. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this policy when our practices change or when legal requirements evolve. Material changes will be announced on this page and (for account holders) by email at least 30 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.
11. Contact
Field Logic Ltd, company number 15380264, registered in England and Wales. Registered office: 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE. Privacy enquiries: privacy@grith.ai. Other legal matters: legal@grith.ai. Security vulnerabilities - please follow our Security Policy rather than emailing privacy@.