1. Scope
This Privacy Policy explains how Grella collects, uses, shares, and protects information when law firms, legal teams, and other business users use Grella.
- Business name: Grella
- Operated from: Australia
- Privacy and security contact: [email protected]
This policy applies to Grella's website, application, APIs, support channels, and related services. It covers personal information and customer content processed through Grella.
2. Information We Collect
2.1 Account and Organization Information
When you create or use an account, we may collect:
- Name
- Email address
- Organization name
- Role, permissions, and organization membership
- Authentication identifiers and login events
- Support and administrative contact details
2.2 Customer Content
"Customer content" means the files, data, text, and outputs that you or your users upload, create, or process in Grella. This may include:
- Uploaded documents and files
- Document text, OCR text, extracted content, and document chunks
- Chat messages, prompts, questions, and AI responses
- Generated work product, summaries, facts, chronologies, citations, and notes
- Matter, workspace, and permission data
- Metadata needed to provide search, retrieval, citation, and collaboration features
2.3 Usage and Technical Information
We may collect technical and usage information such as:
- Browser, device, and operating system information
- IP address and approximate location derived from it
- Login timestamps and session information
- Feature usage and product events
- Error reports, diagnostics, and performance data
- Security, authentication, and system logs
2.4 Billing Information
Payment details may be processed by a payment provider. Grella does not store full credit card numbers on its own servers.
2.5 How We Collect and Hold Information
We collect information:
- Directly from you when you contact us, create an account, upload content, or use Grella
- From your organization when an administrator invites you or manages your access
- Automatically through cookies, service logs, and analytics when you use our website or service
- From services or integrations that you or your organization connect to Grella
- From customer content where personal information appears in uploaded files, prompts, messages, or work product
We hold information in Grella's systems and in systems operated for us by hosting, database, storage, identity, analytics, communications, and product-service providers.
You can view most of Grella's public website without creating an account. The authenticated service requires an identified account so Grella can control access to organization and matter data.
3. How We Use Information
We use information to:
- Create and administer accounts and organizations
- Authenticate users and manage access permissions
- Provide document upload, processing, search, chat, citation, and work-product features
- Process customer content through AI, OCR, embedding, reranking, and related services
- Store, retrieve, display, and export customer content at your direction
- Provide support and respond to customer requests
- Process billing and subscriptions
- Improve service reliability, performance, and product quality
- Detect, investigate, and prevent misuse, security issues, and service abuse
- Comply with legal obligations and enforce our agreements
4. Customer Content and AI Processing
4.1 How Grella Processes Customer Content
Grella processes customer content to provide the service to your organization. This includes ingesting and indexing documents, running search and retrieval, generating summaries and answers, creating draft work product, extracting facts, surfacing citations, and maintaining relevant matter context.
Grella does not use customer content to train a Grella-owned foundation model or build a model for another customer.
4.2 Use of AI and Document-Processing Providers
Grella uses third-party providers to deliver AI and document-processing features, including large language model APIs, OCR and file extraction, embeddings, reranking, and related processing.
AI providers process document text, queries, and outputs to provide Grella's AI features. Provider retention, model-use, and location terms vary by provider and by the service configuration in use.
These providers may process customer content as needed to provide their services to Grella, subject to their applicable terms and safeguards. Ask us for the current provider details if your firm has specific requirements.
4.3 Connected AI Clients and MCP
Grella may let users connect authorized third-party AI clients, including ChatGPT and Codex, through the Model Context Protocol (MCP). When a user enables and uses a connection, Grella authenticates the user and organization and returns only the Grella data requested through available tools that the user is already permitted to access. Returned data may include matter metadata, document text or excerpts, facts, chronologies, work product, chat content, citations, and links back to Grella.
The connected client and its provider process and display returned data under their own terms and privacy policy. Users and organizations are responsible for deciding whether to connect an external client and for configuring access appropriately. Disconnecting a client prevents future authorized access but does not control copies or outputs already retained by that provider.
Grella records privacy-preserving MCP telemetry for authentication, security, reliability, rate limiting, and support. This may include pseudonymous user and organization identifiers, OAuth client identifiers, tool or operation names, status, timing, and request correlation identifiers. Grella does not intentionally include bearer tokens, raw document text, excerpts, raw queries, or work-product content in MCP analytics events.
4.4 Human Review and Access
Grella personnel do not routinely review customer content. Access to customer content is limited to what is necessary to operate the service, resolve support issues that you raise, investigate security or abuse issues, comply with legal obligations, or maintain service reliability.
Where feasible, access is controlled through role-based permissions, least-privilege practices, and logging.
4.5 Legal Review Responsibility
Grella's AI features assist legal professionals by searching, summarizing, extracting, and drafting from customer-provided material. Your organization remains responsible for reviewing outputs and making legal judgments.
5. Service Providers
We use third-party service providers to help deliver, support, secure, and improve Grella. These providers may process personal information and customer content on our behalf where needed for their role.
The types of service providers we use include:
- Hosting and infrastructure: Application hosting, databases, storage, and networking. These providers may process account data, customer content, logs, and metadata.
- AI and document processing: Language models, OCR, embeddings, reranking, and file conversion. These providers may process document text, extracted content, prompts, queries, and outputs.
- Authentication and identity: Login, user identity, and organization membership. These providers may process names, email addresses, authentication identifiers, and login events.
- User-authorized integrations: Connected AI clients and similar integrations. These providers may process account identity and customer content requested through authorized tools.
- Email, support, and communications: Transactional email, customer support, and service notices. These providers may process contact details, support messages, and notification content.
- Analytics and telemetry: Product performance, reliability, and usage analysis. These providers may process usage events, device data, and diagnostics.
- Billing and payment: Subscriptions, invoices, and payment processing. These providers may process billing contacts, payment metadata, and transaction data.
Service providers are permitted to process information only as needed to provide their services to Grella or as otherwise allowed by applicable law and their agreements with us.
6. Security and Access Controls
6.1 Current Protection
Grella uses HTTPS for public web and API traffic. Grella does not currently claim app-level field or column encryption for stored legal content. Ask us about the current hosting, database, storage, and key controls during your security review.
6.2 Organization Isolation and Access Control
Grella separates customer data by organization and uses access controls to limit who can view or manage organization content. Organization administrators control membership and access within their organization.
6.3 Logging
Grella logs certain product and system actions for security, reliability, and operations. This includes selected account, authentication, administrative, and work-product events.
Grella does not currently claim full logging of every file access or every search event. Broader file and search access logging is planned as the platform matures.
6.4 Testing and Security Program
Grella uses internal testing and security review practices for security-relevant components. Independent security validation is not yet complete.
We do not currently claim SOC 2 or ISO 27001 certification. Grella is also still completing its privileged-data readiness work. Your organization should complete its own security review before using Grella for confidential or privileged client material.
7. Data Sharing
We may share information:
- With service providers described in this policy
- With your organization and authorized organization users
- With connected AI clients or integrations that you authorize, for requests initiated through that connection
- When you direct us to share or export information
- To provide support or respond to requests you initiate
- To comply with valid legal process, court orders, subpoenas, government requests, or applicable law
- To protect Grella, our users, customers, or the public from fraud, abuse, security threats, or legal harm
- In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate notice or safeguards where required
We do not sell customer content.
8. Data Retention and Deletion
We retain information for as long as needed to provide Grella, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support business records.
8.1 Customer Content
Customer content is generally retained while your organization maintains an active account or as otherwise agreed with your organization.
Organization administrators may request export or deletion of organization content, subject to legal, security, backup, billing, and operational retention requirements.
8.2 User Accounts
If an individual user account is removed, related organization content may remain available to the organization for legal, regulatory, business, or continuity reasons.
8.3 Backups and Logs
Deleted information may persist in backups, logs, and security records for a limited period before being overwritten or deleted according to our operational processes.
9. Overseas Disclosure and Processing
Grella is operated from Australia. We are likely to disclose personal information and customer content to service providers in the United States and member states of the European Union. These providers support hosting, identity, analytics, AI, document processing, communications, and related service functions.
An integration chosen by you or your organization may disclose information to a provider in another country. Provider routes and subprocessors may change. Contact [email protected] for the current provider and location details before use if your firm has specific data-location requirements.
10. Cookies and Tracking
We use cookies and similar technologies for:
- Essential functionality, including login and session management
- Preferences and user settings
- Analytics, diagnostics, and product improvement
Our website analytics may collect page views, interactions, device information, and masked session recordings. Form inputs are masked in session recordings. You can control cookies through your browser settings. Disabling essential cookies may prevent parts of Grella from working correctly.
11. Your Privacy Rights
Depending on your location and applicable law, you may have rights to:
- Access personal information we hold about you
- Correct inaccurate or outdated personal information
- Request deletion of personal information
- Object to or restrict certain processing
- Request portability of certain information
- Opt out of marketing communications
- Lodge a complaint with a privacy or data protection authority
To exercise privacy rights, contact us at [email protected]. Tell us what you want to access, correct, delete, or question. We may need to verify your identity and, for organization-managed accounts, coordinate with your organization administrator.
11.1 Privacy Complaints
To make a privacy complaint, email [email protected] with enough detail for us to understand the issue. We will acknowledge the complaint, investigate it, and tell you the outcome and any action we will take. We aim to respond within 30 days. If we need more time, we will tell you why and when to expect a response. If you are not satisfied, you may contact the Office of the Australian Information Commissioner or another authority available to you.
12. Children's Privacy
Grella is a business service and is not directed to children. We do not knowingly collect personal information from children.
If you believe a child has provided personal information to Grella, contact us at [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, security practices, or business operations.
When we make material changes, we will update the "Last Updated" date and provide notice where required by law or our customer agreements.
14. Contact Us
For privacy questions, complaints, or data requests, contact us at:
Email: [email protected]
We aim to acknowledge privacy inquiries promptly and respond within the period required by applicable law.
You may also have the right to contact your local privacy or data protection authority, including:
Australia: Office of the Australian Information Commissioner (OAIC) Website: https://www.oaic.gov.au Phone: 1300 363 992
EU: Your local data protection authority Directory: https://edpb.europa.eu/about-edpb/board/members_en
15. Definitions
Customer content: Documents, files, text, prompts, queries, messages, outputs, metadata, and other content uploaded, created, or processed by your organization in Grella.
Connected AI client: A third-party AI product or integration that a user authorizes to access Grella, including through MCP.
Organization: A company, firm, or entity that creates or manages a Grella workspace.
Organization administrator: A user authorized to manage an organization's Grella account, users, permissions, and settings.
Personal information / personal data: Information relating to an identified or identifiable individual.
Service provider: A third party that processes information to help Grella provide, support, secure, or improve the service.