Privacy Policy
Last updated: October 3, 2026
This Privacy Policy describes how Grum (“Grum,” “we,” “us,” or “our”) collects, uses, and shares information when you use our websites, applications, and related services (the “Services”), including www.grum.so and app.grum.so.
Grum is a design consistency tool. It helps teams connect a website, webapp, or GitHub repository, analyze styles, components, copy/tone, and animation, and produce a shareable report an engineer or AI agent can act on.
1. Information we collect
Account and authentication information
When you create or sign in to an account, we may collect:
- Name, email address, and profile photo (including from Google, Microsoft, or GitHub sign-in if you choose those options)
- Authentication credentials and security factors you set up, such as passkeys
- Your Grum username and profile information
If you sign in with Google, we receive basic profile information Google provides for sign-in (typically name, email address, language preference, and profile image). We use Google Sign-In only to authenticate you and create or access your Grum account. We do not request Google Drive, Gmail, Calendar, or other Google content scopes for sign-in.
If you sign in with Microsoft, we receive the profile information Microsoft provides for that sign-in flow and use it only to authenticate you and create or access your Grum account.
If you sign in with GitHub, we receive the profile information GitHub provides for that sign-in flow and use it to authenticate you, create or access your Grum account, and — if you authorize it — connect repositories you choose to scan.
Service and content data
Depending on how you use Grum, we may process:
- Repositories, websites, or webapps you connect, including files and metadata needed to run a scan
- Reports you generate, including findings, recommendations, version history, and visibility settings (shared or private)
- Exported markdown files, share links, and related access tokens needed to use the Services from connected clients
- Product activity related to browsing, scanning, or improving design consistency
Report and project content is provided by you or extracted from sources you connect. We process it to operate the Services you request (for example, storing a report so you can share it with a teammate or coding agent).
Usage and technical information
We may automatically collect:
- Log data such as IP address, browser type, device information, and pages or features used
- Cookies and similar technologies needed for sessions, security, and product analytics
- Product analytics and (on the signed-in product) session recordings via PostHog — page views, clicks, and navigation so we can understand usage and fix bugs. On the public marketing site we collect anonymous page analytics only (no session recordings). In the product app, inputs and on-screen text in recordings are masked before they leave your browser; we do not use analytics or recordings for advertising. Recordings are retained for a limited period and then deleted. Contact us if you would like to be excluded from this.
- Diagnostic information related to errors, GitHub connection, report generation, and service reliability
2. How we use information
We use the information we collect to:
- Provide, maintain, and improve the Services
- Authenticate users and secure accounts (including passkeys, sessions, and GitHub tokens)
- Operate scans, reports, sharing, and connected repositories
- Process and display content you create or connect to Grum
- Send service-related communications (for example, security notices)
- Monitor abuse, debug issues, and protect the Services
- Comply with legal obligations
We do not sell your personal information. We do not use Google, Microsoft, or GitHub user data obtained through sign-in for advertising.
3. How we share information
We may share information with:
- Service providers that help us run Grum (for example hosting, databases, authentication infrastructure, and product analytics / session replay such as PostHog), under contractual obligations to protect the data
- Other users and the public according to your visibility and sharing settings (for example, a report you choose to share)
- Professional advisors or authorities when required by law or to protect rights, safety, and security
- A successor entity if we are involved in a merger, acquisition, or asset transfer, subject to this Policy or equivalent protections
4. Google user data
Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. For Google Sign-In, we use the data only to provide and improve account authentication and related account features in Grum.
5. Data retention
We retain account and Service data for as long as your account is active or as needed to provide the Services. You may request deletion of your account and associated personal data by contacting us. We may retain limited information as required for legal, security, or operational purposes (for example, fraud prevention or backup integrity).
6. Security
We use administrative, technical, and organizational measures designed to protect information, including encrypted connections (HTTPS), access controls, and secure session handling. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your choices and rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal information
- Export certain account information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
You can update some profile and project information in the product, including report visibility settings. To exercise other rights, email privacy@grum.so. You may also disconnect Google, Microsoft, or GitHub sign-in from your provider account permissions settings.
8. Children’s privacy
The Services are not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps.
9. International transfers
We may process information in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards for cross-border transfers.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may be communicated through the Services or by email when appropriate.
11. Contact us
Questions about this Privacy Policy or our data practices:
Email:
privacy@grum.so
Web: https://www.grum.so
Related: Terms of Service