Opening your board…
Opening your board…
Effective date:
Graiboard is operated by Zero Point Ventures LLC, a Virginia limited liability company (“Zero Point Ventures,” “Graiboard,” “we,” “us,” or “our”).
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use Graiboard, including our website, web application, integrations, plugins, connectors, MCP servers, APIs, and related services (collectively, the “Service”).
By using Graiboard, you acknowledge the practices described in this Privacy Policy.
When you create or use a Graiboard account, we collect your email address, account identifiers, authentication and verification information, session information, plan information, and account preferences. The current signup flow uses email and a password through Supabase Auth. We also receive names and other profile information if you choose to provide them, for example through billing or support.
Graiboard allows users and connected AI assistants to create and manage project information. Customer Content may include:
Customer Content may contain personal information if you or another user choose to include it. Graiboard also stores project ownership, room membership, invitations, permissions, and the identifiers, timestamps, and statuses needed to coordinate work. Graiboard does not automatically store your conversations in other AI applications.
You are responsible for deciding what information you place in Graiboard and for ensuring that you have the right to submit that information.
If you connect Graiboard to an AI provider, coding agent, application, API, plugin, MCP client, or other third-party service, we may receive information necessary to establish and operate that connection.
This includes connection and client identifiers, source labels, permissions, authorization scopes, registered callback addresses, connection status, credential lifecycle information, and information exchanged through the integration. Session polling and supported notifications also use chat or session identifiers, scheduling information, subscription details, and delivery status. These identifiers do not necessarily identify your account at the AI provider.
The current connections use Graiboard-issued credentials. Graiboard does not ask for the password or API key for your third-party AI account. A manual connection may require you to paste a Graiboard access key into the client you authorize.
When you use Graiboard, we may automatically collect technical information such as:
Paid Graiboard plans are processed through third-party payment providers such as Stripe.
Stripe collects payment details, billing information, and any requested tax information through its hosted payment and billing interfaces. Graiboard sends Stripe the account email and identifiers and the selected plan and quantity. Graiboard receives subscription and transaction notifications and stores billing identifiers, plan and status, billing-period and cancellation dates, quantity, and event-processing records. Payment amounts may be processed through those notifications or viewed in Stripe; Graiboard does not store complete payment-card credentials.
If you contact us, we may collect your name, email address, the content of your message, diagnostic information you choose to provide, and other information necessary to respond to your request.
We use information collected through Graiboard to provide and operate the Service; authenticate users and connected agents; maintain projects, tasks, Notes, handoffs, activity history, and other requested functionality; process subscriptions and payments; provide customer support; secure accounts and infrastructure; prevent fraud, abuse, and unauthorized access; diagnose failures and improve reliability; enforce our Terms of Service; comply with legal obligations; and develop and improve Graiboard.
We use public-page visit statistics to understand how people find Graiboard, and operational information such as aggregate request counts and error rates to improve reliability.
We may use aggregated or de-identified information internally to operate, secure, evaluate, and improve Graiboard. Such information must not reasonably identify an individual, account, or customer.
Graiboard does not currently provide Customer Content or de-identified Customer Content to third parties for independent research. We do not currently operate an external research-sharing pipeline.
Future external research use of aggregated or de-identified information may occur with appropriate safeguards and updated disclosure. Before such sharing, we would assess re-identification risk, limit the information and recipients, establish appropriate use restrictions, and update this Privacy Policy. This describes a possible future practice, not an existing sharing program.
Graiboard is not a zero-access or end-to-end-encrypted service. Project text is readable by the Service, authorized collaborators and integrations, and infrastructure operators with appropriate administrative access. Administrative tools and backups can allow access outside the ordinary user interface.
We limit operational access to purposes such as:
We seek to limit such access to personnel with a legitimate operational need.
Graiboard is designed to work with third-party AI assistants and services.
When you intentionally connect or direct an AI assistant or other third-party service to interact with Graiboard, information relevant to the requested interaction may be transmitted to that provider.
For example, an authorized AI assistant may read a project brief, tasks, Notes, handoffs, or other project information and may write information back to Graiboard.
Those providers are independent third parties. Their collection, retention, training, and other use of information are governed by their own terms, privacy policies, account settings, and agreements with you.
You should review the privacy and data-use settings of any provider you connect to Graiboard.
Zero Point Ventures does not use Customer Content to train its own general-purpose AI model. The current product provides project tools to services you connect; it does not run a separate Graiboard model-training program. Provider use of information remains subject to that provider's terms and your settings.
Revoking a connection in Graiboard prevents future access through that connection. Removing an app in an assistant provider does not by itself confirm that its Graiboard authorization has been revoked; check your connections in Graiboard Settings. Revocation does not remove information already copied to a provider, another participant, a shared image, or an exported file.
Personal projects remain private unless you authorize access or share them. Sharing a project with a Team Room makes its existing project record available to authorized room participants. A member's AI connection requires an explicit room grant in addition to the member's room access.
We may disclose information in the following circumstances.
We may provide information to vendors that help us operate Graiboard, such as cloud infrastructure, database, hosting, authentication, payment, email, security, monitoring, and customer-support providers.
The current direct service providers include:
| Provider | Purpose and information involved |
|---|---|
| Supabase | Database, authentication, and managed backups: account information, Customer Content, membership and integration state. |
| Vercel | Website and application hosting, request processing, firewall, operational logs, and public-page Web Analytics: information processed by the application, request/security metadata, and visit statistics described below. |
| Stripe | Hosted payment and subscription management: account linkage, billing and payment information. |
| Resend | Authentication email delivery: recipient address, email contents and verification links, delivery and related operational information. |
These services may use their own infrastructure providers. AI services you independently connect are described separately above.
These providers process information on our behalf or as otherwise described in their own agreements and privacy policies.
We disclose information to AI providers and other third-party services when you connect, authorize, or direct those services to interact with Graiboard.
We may disclose information if we reasonably believe disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request; enforce our agreements; investigate fraud or security incidents; or protect the rights, property, and safety of Graiboard, our users, Zero Point Ventures, or others.
If Zero Point Ventures is involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar transaction, information may be transferred as part of that transaction subject to applicable law.
Graiboard does not sell personal information for monetary consideration.
Graiboard does not currently use Customer Content or personal information for targeted behavioral advertising.
If these practices materially change, we will update this Privacy Policy and provide any notices or choices required by applicable law.
Graiboard uses session cookies for Supabase authentication and a first-party appearance cookie to remember your theme. The appearance cookie lasts up to one year unless cleared. Temporary browser session storage may hold a room-invitation reference while you accept an invitation.
We use Vercel Web Analytics on our public landing, Privacy Policy, and Terms pages to measure visits, page views, and referral traffic. It processes page URLs, referrers, timestamps, approximate location, and browser, operating-system, and device information. Vercel derives a short-lived visitor identifier from incoming request information and discards it after 24 hours; Web Analytics does not use cookies to track visitors.
Our Web Analytics integration excludes private boards, projects, account pages, and authentication and integration authorization flows. We strip query strings and fragments from tracked page URLs and do not send Customer Content, account identifiers, or custom user events to Web Analytics.
We do not use advertising or session-replay scripts. Hosting, authentication, firewall, and security services separately process request and diagnostic information to operate and protect the Service.
We use technical and organizational safeguards intended to protect information from unauthorized access, use, alteration, or disclosure.
These measures include HTTPS for the application, authentication and authorization controls, database row-level access policies, and restricted server-side credentials. Graiboard-issued manual access keys and MCP OAuth access tokens, refresh tokens, client secrets, and authorization codes are stored as one-way hashes for validation. Some secrets needed for delivery or other operations must be recoverable and are encrypted instead. Supabase manages its own authentication credentials. These descriptions do not mean that every invitation, session artifact, project field, or secret is hash-only, or that operators cannot read Customer Content.
Application diagnostics are designed to avoid recording project text and credential values unnecessarily. Request URLs, authentication/security information, and infrastructure or database error details may still contain information associated with your activity. Do not place passwords or other secrets in project text or URLs. Email transport depends on the receiving provider and is not guaranteed to be end-to-end encrypted.
No online service can guarantee absolute security. You are responsible for maintaining the security of your account, devices, credentials, API keys, connected accounts, and authorized integrations.
If you believe your Graiboard account has been compromised, contact us promptly.
We retain account and project information to provide the Service, respond to requests, maintain security, manage billing, and comply with applicable obligations. The current product does not apply a general automatic expiry to project history.
Archive. Archiving a project keeps its content and history. It is not deletion.
Project history. Editing a task or other current item can leave earlier values in activity history. Notes and activity entries are generally append-only. Corrections do not automatically erase earlier records.
Permanent project deletion. An authorized owner or room administrator can permanently delete an archived project after confirmation. This removes the project and its associated tasks, Notes, activity history, and handoffs from active project storage. Graiboard retains limited deletion identifiers and request records to prevent retried actions from recreating a deleted project. Separate account, credential, room-administration, billing, and security records may remain. Some administrative request records contain submitted request fields and returned results, including names, email addresses, or other content. Deletion cannot be undone through the application.
Account deletion. You can request deletion in Settings → Account by confirming your password and typing DELETE. Eligible personal accounts and their owned project content are deleted directly. Accounts with billing history, owned Team Rooms, or platform-administrator access require operator review before deletion. A review request leaves your account, content, and billing in place until it is completed; you can cancel a pending request. Submitting a deletion request does not itself cancel a subscription.
Deletion removes your account and its owned project data, connections, and authorization grants from active storage. Your contributions to projects owned by someone else may remain in their shared project history. Billing, request/retry, audit, and deletion records, backups, and copies already held by others may remain as described below. Contact contact@zpventures.io for help with account deletion or another privacy request. We verify identity before completing requests.
We use the following criteria to decide how long to retain information under Graiboard's control. Retention includes operator review and manual processes; the current release does not apply a general automatic expiry to all stored records.
Specific legal or security holds can require longer preservation. We document the reason and affected records, review the continuing need, and end the hold when its reason no longer applies. A hold does not justify retaining unrelated records.
Provider-held copies, logs, and backups. Supabase holds managed database and authentication records and backups; Vercel holds hosting, analytics, and security records; Stripe holds payment and accounting records; and Resend holds email-delivery records. Retention for these provider-held records is governed by the applicable provider agreements, policies, and configured service settings. These are distinct from Graiboard-controlled copies and are not all subject to direct deletion by Graiboard. Deleting active project or account data does not promise immediate erasure of provider backups or records.
Provider privacy information is available from Supabase, Vercel, Stripe, and Resend. Copies already held by independently connected AI services, other users, exported files, or shared images are also outside a Graiboard deletion action and remain subject to the recipient's own arrangements.
Depending on where you live and applicable law, you may have rights concerning your personal information, including rights to request access to personal information, correct inaccurate information, delete information, obtain a portable copy of certain information, and opt out of certain processing.
Graiboard does not currently sell personal information or process personal information for targeted advertising.
We may need to verify your identity before completing a privacy request. Where permitted by law, an authorized agent may submit a request on your behalf.
To submit a privacy request, contact us at:
Privacy requests do not require a paid subscription. The paid Project Notes export feature is not a substitute for a request for access to personal information.
We will respond within the period required by applicable law.
If applicable law gives you the right to appeal a decision we make concerning a privacy request, you may submit an appeal by replying to our decision or contacting:
with the subject line “Privacy Appeal.”
We will review the appeal and respond as required by applicable law.
Where the Virginia Consumer Data Protection Act applies, eligible Virginia consumers may have rights to confirm whether personal data is being processed, access personal data, correct inaccuracies, request deletion, obtain certain data in portable form, and opt out of certain targeted advertising, sale, or profiling activities.
Graiboard does not currently sell personal data or use personal data for targeted advertising.
Statutory rights and exceptions depend on the circumstances and applicability of the law.
Graiboard is operated from the United States. If you access the Service from another country, information may be transferred to and processed in the United States and other jurisdictions where our service providers operate.
Those jurisdictions may have data-protection laws different from those in your country.
Where applicable law requires a particular mechanism for international data transfers, we will use an appropriate lawful mechanism.
Graiboard provides productivity and collaboration features appropriate for general audiences. It is not directed to children under 13.
Our Terms of Service require users to meet the minimum age stated there. We do not knowingly collect personal information from children under 13.
If we learn that we have collected personal information from a child in circumstances prohibited by applicable law, we will take appropriate steps to delete or otherwise address that information.
If you believe a child has provided personal information to Graiboard improperly, contact us at contact@zpventures.io.
We may update this Privacy Policy from time to time.
If we make material changes, we may provide notice through Graiboard, by email, on our website, or through another reasonable method.
The “Effective Date” at the top of this Policy indicates when the current version became effective.
Your continued use of Graiboard after an updated Privacy Policy becomes effective is subject to applicable law.
For privacy questions, requests, or concerns, contact:
Zero Point Ventures LLC
Graiboard
Email: contact@zpventures.io
Mailing address: 8401 MAYLAND DR
STE A
RICHMOND, VA 23294
USA