Skip to content
Step back

Privacy Policy

Last updated: October 3, 2026

Contact us

This Privacy Policy describes how Grum (“Grum,” “we,” “us,” or “our”) collects, uses, and shares information when you use our websites, applications, and related services (the “Services”), including www.grum.so and app.grum.so.

Grum is a design consistency tool. It helps teams connect a website, webapp, or GitHub repository, analyze styles, components, copy/tone, and animation, and produce a shareable report an engineer or AI agent can act on.

1. Information we collect

Account and authentication information

When you create or sign in to an account, we may collect:

  • Name, email address, and profile photo (including from Google, Microsoft, or GitHub sign-in if you choose those options)
  • Authentication credentials and security factors you set up, such as passkeys
  • Your Grum username and profile information

If you sign in with Google, we receive basic profile information Google provides for sign-in (typically name, email address, language preference, and profile image). We use Google Sign-In only to authenticate you and create or access your Grum account. We do not request Google Drive, Gmail, Calendar, or other Google content scopes for sign-in.

If you sign in with Microsoft, we receive the profile information Microsoft provides for that sign-in flow and use it only to authenticate you and create or access your Grum account.

If you sign in with GitHub, we receive the profile information GitHub provides for that sign-in flow and use it to authenticate you, create or access your Grum account, and — if you authorize it — connect repositories you choose to scan.

Service and content data

Depending on how you use Grum, we may process:

  • Repositories, websites, or webapps you connect, including files and metadata needed to run a scan
  • Reports you generate, including findings, recommendations, version history, and visibility settings (shared or private)
  • Exported markdown files, share links, and related access tokens needed to use the Services from connected clients
  • Product activity related to browsing, scanning, or improving design consistency

Report and project content is provided by you or extracted from sources you connect. We process it to operate the Services you request (for example, storing a report so you can share it with a teammate or coding agent).

Usage and technical information

We may automatically collect:

  • Log data such as IP address, browser type, device information, and pages or features used
  • Cookies and similar technologies needed for sessions, security, and product analytics
  • Product analytics and (on the signed-in product) session recordings via PostHog — page views, clicks, and navigation so we can understand usage and fix bugs. On the public marketing site we collect anonymous page analytics only (no session recordings). In the product app, inputs and on-screen text in recordings are masked before they leave your browser; we do not use analytics or recordings for advertising. Recordings are retained for a limited period and then deleted. Contact us if you would like to be excluded from this.
  • Diagnostic information related to errors, GitHub connection, report generation, and service reliability

2. How we use information

We use the information we collect to:

  • Provide, maintain, and improve the Services
  • Authenticate users and secure accounts (including passkeys, sessions, and GitHub tokens)
  • Operate scans, reports, sharing, and connected repositories
  • Process and display content you create or connect to Grum
  • Send service-related communications (for example, security notices)
  • Monitor abuse, debug issues, and protect the Services
  • Comply with legal obligations

We do not sell your personal information. We do not use Google, Microsoft, or GitHub user data obtained through sign-in for advertising.

3. How we share information

We may share information with:

  • Service providers that help us run Grum (for example hosting, databases, authentication infrastructure, and product analytics / session replay such as PostHog), under contractual obligations to protect the data
  • Other users and the public according to your visibility and sharing settings (for example, a report you choose to share)
  • Professional advisors or authorities when required by law or to protect rights, safety, and security
  • A successor entity if we are involved in a merger, acquisition, or asset transfer, subject to this Policy or equivalent protections

4. Google user data

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. For Google Sign-In, we use the data only to provide and improve account authentication and related account features in Grum.

5. Data retention

We retain account and Service data for as long as your account is active or as needed to provide the Services. You may request deletion of your account and associated personal data by contacting us. We may retain limited information as required for legal, security, or operational purposes (for example, fraud prevention or backup integrity).

6. Security

We use administrative, technical, and organizational measures designed to protect information, including encrypted connections (HTTPS), access controls, and secure session handling. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your choices and rights

Depending on your location, you may have rights to:

  • Access, correct, or delete personal information
  • Export certain account information
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent

You can update some profile and project information in the product, including report visibility settings. To exercise other rights, email privacy@grum.so. You may also disconnect Google, Microsoft, or GitHub sign-in from your provider account permissions settings.

8. Children’s privacy

The Services are not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps.

9. International transfers

We may process information in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards for cross-border transfers.

10. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may be communicated through the Services or by email when appropriate.

11. Contact us

Questions about this Privacy Policy or our data practices:

Email: privacy@grum.so
Web: https://www.grum.so

Related: Terms of Service