Your privacy matters
Last updated: 26 July 2026
Here's the short version
We collect the data we need to help you find activities and connect with people. We never sell it. Public parts of grac only ever show a vague area, never your exact location — precise meeting points are shared only with people who've committed to the same plan. You can see, correct, export or delete your data at any time by emailing info@grac.social. The full detail is below.
Who we are
grac (“we”, “us”) operates the website at grac.social and is the data controller for the personal data described in this notice, for the purposes of UK GDPR and the Data Protection Act 2018.
You can reach us about anything in this notice — including any request to exercise your rights — at info@grac.social. We aim to respond within one month, as the law requires.
What information do we collect?
Account and profile
- Email address (used to sign you in via a magic link)
- Name and profile picture, if you sign in with Google or add them yourself
- A phone number, only if you choose to add one to your profile
- Your interests, and the activities you say yes, maybe or no to
Location
- An approximate area you choose, or your device location if you grant the browser permission — used to show what's happening near you
- The meeting point of a plan you've committed to, shared with the other committed members of that plan
Location is handled in two stages by design. Sparks and other public surfaces store and show only a coarse grid square, not a precise coordinate. A precise location is revealed only once a plan is confirmed and only to its committed members.
Things you create
- Messages you send in group chats
- Activities, sparks and plans you create or join
- Safety reports and feedback you submit about other members
- Your reliability score, derived from attendance and peer confirmation
Technical data
- IP address, browser and operating system, and device type
- Sign-in timestamps and security events
- Error reports and page-performance measurements
Legacy (video life stories)
If you use Legacy, we additionally process the video and audio you record, transcripts of your conversations with the AI interviewer, photographs you upload, and notes the system keeps to remember what you've already told it. You are asked for explicit, itemised consent before any recording starts, and Legacy recordings are downloadable only by you — we don't offer share links.
Life stories often touch on health, religion, politics or sexuality — special category data under UK GDPR. We process it only on the basis of your explicit consent, which you can withdraw at any time by asking us to delete the recording. Please avoid including details that identify other people (children's full names, addresses, schools) without their agreement. GPS coordinates are stripped from photographs you upload before they are stored.
Why we use it, and our lawful basis
UK GDPR requires us to have a specific lawful basis for each purpose:
| What we do | Lawful basis |
|---|---|
| Run your account, form groups, run chat and plans | Performance of our contract with you |
| Show nearby activities using your location | Your consent (browser location permission) |
| Record, transcribe and edit Legacy videos | Your explicit consent, given on the Legacy consent screen |
| Keep the community safe: moderation, safety reports, reliability scores, fraud and abuse prevention | Our legitimate interests in a safe platform, and those of other members |
| Diagnose errors, measure performance, improve the product | Our legitimate interests in a working service |
| Send you optional product news | Your consent — withdraw it any time |
| Keep records we're legally required to keep, and respond to lawful requests | Compliance with a legal obligation |
Where we rely on legitimate interests, we've considered the impact on you and you can object at any time (see Your rights below).
Automated decisions
Your reliability score is calculated automatically from your attendance history. It is designed to move down only when at least one other member corroborates that you didn't show up — a single unverified report can't reduce it. The score affects how you appear to other members; it does not produce legal effects, and you can ask us to review it by email.
Who we share it with
We don't sell your data, and we don't share it for advertising. We use the following service providers, who process data on our instructions:
| Provider | What they handle |
|---|---|
| Vercel | Website hosting and file storage |
| Neon | The database holding your account and content |
| Sign-in, if you choose Google | |
| Resend | Sign-in links and service emails |
| Pusher | Real-time chat and game updates |
| Upstash | Short-lived caching and game state |
| Sentry, Axiom | Error reports and server logs |
| Stadia Maps, OpenStreetMap | Map tiles and place lookups |
| Stripe | Payments, if you buy a paid feature. Stripe handles your card details directly — we never see or store them |
| Mux, LiveKit, ElevenLabs, and our AI model providers | Legacy only: video hosting, live audio, the interviewer's voice, and generating questions and transcripts |
Beyond those providers, we share your information only with your consent, to comply with a legal obligation or lawful request, or where it's necessary to protect the rights and safety of our members or the public.
Remember that anything you post into a group chat, spark or plan is visible to the other people in it. That is ordinary use of the product rather than sharing by us, but it is worth being deliberate about what you put there.
Where your data goes
Some of the providers above are based outside the UK, mainly in the United States. Where personal data is transferred out of the UK, we rely on the safeguards UK data protection law permits — the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or a finding that the receiving country provides adequate protection. You can ask us for detail on the safeguards for a particular provider.
How long we keep it
- Account data — for as long as your account is open. If you delete your account we remove or anonymise your personal data within 30 days, apart from anything we must keep for legal reasons.
- Chat messages and plans — kept while the group exists so the history makes sense to everyone in it.
- Safety reports — kept for up to two years after they are resolved, so repeat patterns are visible.
- Technical logs and error reports — typically 90 days.
- Legacy recordings — kept until you delete them. We deliberately do not delete them on a schedule, because the point is that they outlast the conversation. You can remove a single recording, or close Legacy entirely, from the Legacy management screen; either one also deletes the stored video and audio files, not just the listing.
Cookies and local storage
We use a small number of strictly necessary cookies and similar browser storage, and no advertising or cross-site tracking cookies:
- A secure, HTTP-only session cookie that keeps you signed in, plus a short-lived token that protects sign-in forms from cross-site request forgery.
- Local storage in your browser for your own preferences — things like text size and playback settings.
Because these are strictly necessary to provide a service you've asked for, the Privacy and Electronic Communications Regulations don't require a consent banner for them. You can still block or clear cookies in your browser, but you won't be able to stay signed in.
Children
grac arranges meetings between adults and is not intended for children. You must be 18 or over to create an account. If we learn that we hold data about someone under 18, we delete the account and its data. If you believe a child is using the service, tell us at info@grac.social.
How we keep it safe
- Traffic is encrypted in transit (HTTPS), and our database is encrypted at rest
- Sign-in uses HTTP-only session cookies; we never store passwords
- Access to production data is limited to those who need it
- Location precision is reduced before storage on public surfaces
- GPS metadata is stripped from uploaded photographs
No online service can promise perfect security, but if a breach were to put your rights at risk we would tell you and the ICO as the law requires.
Your rights
Under UK GDPR you have the right to:
- Access a copy of the personal data we hold about you
- Correct data that's wrong or incomplete
- Delete your account and data (“right to erasure”)
- Restrict or object to processing we base on legitimate interests
- Portability — receive your data in a machine-readable format
- Withdraw consent at any time, where we rely on it — this doesn't affect processing already carried out
To exercise any of these, email info@grac.social. These rights are free to use and we'll respond within one month.
If you're unhappy with how we've handled your data you can complain to the UK's supervisory authority, the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113). We'd appreciate the chance to put things right first.
Questions?
Email: info@grac.social
We may update this notice as the product changes. The date at the top always reflects the current version, and if we make a change that materially affects your rights we'll tell you directly rather than relying on you re-reading this page.