Privacy Policy
Last updated: July 29, 2026
Grapevine, operated by Grapevine LLC ("Grapevine," "we," "us"), is a group communication platform with two modes: an AI-generated organizational feed ("Business mode") and a private friend-group messenger and feed ("Personal mode," also called "grapes"). This policy explains what we collect, why, how it's used, and the choices and rights you have — across both modes.
The three privacy tiers
1. Group content (chat channels, feed posts, replies, reactions, polls, meet-up plans, uploaded photos/video/voice notes, memes, and — in Business mode — connected data sources): encrypted in transit (TLS) and at rest, isolated per group with database-level row security. Our AI processes this content to generate your feed, answer @mentions, and power suggestions — that is the product, and it means group content is not end-to-end encrypted. No Grapevine employee reads your content in the normal course of business; access is limited to automated processing, aggregate diagnostics, and cases where you explicitly ask for support, or where we reasonably believe it's necessary to investigate abuse, enforce our Terms of Service, or comply with law.
2. Direct messages on web: encrypted at rest and structurally excluded from AI processing — the systems that generate the feed and power the @mention AI cannot query direct-message data. We do not read them, use them, or analyze them. This applies to both one-to-one direct messages and Personal-mode friend DMs.
3. Direct messages on mobile (where available): end-to-end encrypted with keys held on your device. Neither the AI, nor group admins, nor Grapevine itself can read them — even if compelled. If you lose your device, that history is unrecoverable by design.
Media you upload, and public share links
Photos, videos, voice notes, and memes you upload are stored on our storage infrastructure at a URL that is reachable without signing in. We do not publish, index, or link these URLs anywhere, but anyone who obtains the exact URL could view the file — do not upload anything you would not want accessible this way. If you or someone in your group uses the "Share" feature on a feed post, that post's headline, body, and any meme become viewable by anyone with the generated link, without an account, until the post is removed — replies, reactions, and member identities are never included on a shared page.
What the AI sees, and how to limit it
The AI reads group channels, feed activity, and — in Business mode — data sources your group connects or uploads. It never reads direct messages. In group chat, the AI responds when addressed (by @mention or by replying under one of its own messages) and, in Business mode, group admins can mute the AI for any member: that member is never addressed or referenced by the AI, and their messages are excluded from AI processing. Reactions and votes are anonymous by design — identity is never shown to anyone, including admins.
Your data is not training data
We use your content solely to provide the Service to your group. We do not sell it, rent it, or use it to train our own or third-party foundation models. AI processing is performed via Anthropic's API under terms that do not permit training on your data.
Personal mode: friends, grapes groups & purchases
In Personal mode, we additionally collect and use: your friend list and friend-request history; your grapes-group memberships; the events you RSVP to and to-do items you claim on Plan-a-Meet posts (used to target AI reminders — a 72-hour, 24-hour, and few-hours-out nudge — to people who said yes or maybe); Secret Santa assignments and gift budgets you set; block and unfriend actions; your chosen chat bubble style, theme, and wallpaper; and records of cosmetic and subscription purchases (via our payment processor — see "Subprocessors" below). The order in which the "surprise me" feature shows its category options is personalized using a small preference counter stored only in your browser's local storage on your own device — we do not receive or store this counter on our servers, and clearing your browser data resets it. We separately log anonymous, aggregate counts of which surprise categories are picked network-wide (no account or identity attached) to keep the feature useful for everyone.
The right to burn
Group admins can permanently delete their entire group — every post, message, upload, connected-source record, and analytics row. Burning is irreversible and propagates to backups within 30 days. Individual members may delete their own account and authored content at any time.
What we collect
Account basics (email, name or handle, title/department where applicable, profile photo, bio, preferences), content you and your group create or upload, data sources your group connects in Business mode (always read-only — Grapevine never writes back to a connected system), device tokens for push notifications (if you enable them), and standard service telemetry (logins, device/browser type, IP address, diagnostics, error logs). We use cookies only for authentication and session management — no advertising trackers.
Location (zip code): if you use the "surprise me" feature for nearby suggestions, we store the zip or postal code you type in. That is the only location data we hold — we never use device geolocation, and the zip is used solely to look up nearby places and events when you ask.
Interest summaries: to make suggestions relevant, we derive a short summary of your interests (e.g. "hiking, tacos, horror movies") from the group messages and posts you yourself authored — never from your direct messages, which remain structurally excluded from all AI processing. These summaries are readable only by our servers (no user or group member can access them), are never shared or sold, and are deleted with your account.
Payment information: we do not collect or store your full card number. Payments are handled by our payment processor (Stripe), which collects and processes your payment details directly under its own privacy policy. We retain only transaction records (amount, date, product) needed for support, accounting, and fraud prevention.
Subprocessors
We rely on a small set of providers to run Grapevine. Each processes data only to provide their service to us, under their own security commitments and their own privacy policy:
- Supabase — database, authentication, and file storage. Holds essentially everything we hold: your email and profile, group chat and posts, uploads, and push registration records. Direct messages are stored as ciphertext we cannot read.
- Vercel — application hosting. As the host, it processes every request to our site and API, including your IP address, browser details, and request contents.
- Anthropic — AI processing. Receives group chat and post content, your interest summary, and event/venue details for the features that need them. Never your direct messages.
- Resend — transactional email. Receives your email address and the contents of the message we send you (for example, a meet-up reminder with the event title, place, and time). It also carries our internal safety alerts, which can include a report reference and the display names involved.
- Stripe — payment processing on the web. Receives your payment details and email directly; see "Payment information" above.
- Apple — in-app purchases on iOS (App Store transaction and receipt data) and push notification delivery. If you enable notifications, Apple receives your device's push token and the notification we send, which is deliberately generic ("New direct message") and never contains message content. If you enable notifications in a web browser instead, your browser vendor's push service performs the same role.
- Cloudflare — bot and abuse protection (Turnstile) on the web sign-in form. Receives your IP address, browser details, and Cloudflare's own signals about the browser, in order to tell a person from a script.
- GIPHY — the GIF picker on the web. We forward only the words you type into the GIF search box, from our server, so GIPHY does not receive your IP address at search time. GIFs themselves are loaded by your browser from GIPHY's servers, which does expose your IP address to GIPHY when a GIF is displayed.
- OpenStreetMap-based services (Nominatim for postal-code lookup and Overpass API mirrors, including a community-operated mirror, for nearby places) — used by "surprise me." Queried from our server using only the zip or postal code you typed and the coordinates derived from it, never your identity or IP address.
- Ticketmaster (Discovery API) — event listings. Queried using only a location and category, never your identity.
When you paste a link into Grapevine, our server — not your browser — fetches that page to build the preview, so the site you linked to sees a request from us rather than from you. If we add a subprocessor that materially changes how your data is handled, we will update this list and, for material changes, provide notice as described under "Changes" below.
Your rights
Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Write to privacy@saygrapevine.com and we will honor verified requests within 30 days. We do not discriminate against you for exercising these rights. Where required, you may also lodge a complaint with your local data protection authority.
Account deletion is permanent
You can delete your account at any time from your profile. Deletion erases everything you own — your groups you solely own, messages, posts, media, purchase-cosmetic ownership, friend list, and settings — and cannot be undone. Deletion does not, however, remove copies of your messages that remain visible in group chats you don't own, or purchase records we are required to keep for accounting, tax, or fraud-prevention purposes. To make the deletion promise real, the email address of a deleted account is permanently retired: it can never be used to create a Grapevine account again. The only data we retain after deletion is that retired email address itself and the minimum transaction/legal records described above.
Retention & security incidents
We keep data while your group is active and delete it per the burn and account-deletion rules above. If a security incident affects your data, we will notify affected group admins and, where required by law, affected individuals, without undue delay after confirmation, with what we know and what we're doing.
Children
Grapevine is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data. If we learn we have collected personal data from a child under 13 without verifiable parental consent, we will delete it.
International transfers
Grapevine is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your jurisdiction. By using the Service, you consent to this transfer.
Changes
If we materially change this policy, group admins get notice before the change takes effect. Continued use after notice is acceptance.
Disclaimer
- No method of transmission or storage is 100% secure; while we use commercially reasonable safeguards, we cannot guarantee absolute security, and you provide information at your own risk.
- This policy describes our practices for the Service; it does not apply to third-party sites, apps, or services you may reach through links, unfurled previews, or "surprise me" suggestions.
Questions: privacy@saygrapevine.com · Terms of Service · Home