Legal
Privacy Policy
Last updated: April 24, 2025
Contents
01 Who we are
GrydBase is a business operations platform for contractors, roofers, service businesses, and similar trades. It is owned and operated by Caleb Media Studio, LLC ("we", "us", "our"), based in Central Florida. This Privacy Policy explains what data we collect, how we use it, and what rights you have over it.
"You" means anyone who creates an account, uses the platform, or accesses a client portal created through GrydBase.
02 Data we collect
Account data: When you register, we collect your name, email address, and authentication credentials. If you sign in with Google, we receive your name and email from Google but never your Google password.
Workspace and business data: Data you enter into GrydBase — customer contacts, job records, notes, invoices, contracts, and site content — is stored on your behalf. You own this data.
Email content: When you use GrydBase's business email feature, inbound and outbound message content is stored to display in your inbox and linked to CRM records. Email is processed through Resend (see Section 5).
Payment data: We do not store credit card numbers. Payment details are handled entirely by Stripe, Inc. We receive transaction IDs, billing amounts, and subscription status from Stripe's webhook events.
Technical data: We collect IP addresses, browser type, device information, and session tokens for security, authentication, and platform reliability purposes. This data is not sold or used for advertising.
AI interaction data: When you use AI features, your prompt and the relevant workspace context (contact records, site content, etc.) are sent to Anthropic's API to generate a response. See Section 6 for details.
03 How we use your data
We use your data to:
- Provide, maintain, and improve the GrydBase platform
- Authenticate your identity and secure your workspace
- Process payments and manage subscription billing
- Send transactional emails (invoices, receipts, portal invites, system alerts)
- Enable AI-powered features when you initiate them
- Comply with legal obligations and respond to valid legal requests
- Investigate and prevent fraud, abuse, and security incidents
We do not sell your personal data. We do not use your data to serve advertising.
05 Third-party services we use
GrydBase relies on the following subprocessors to operate. Each processes data only as necessary to provide its function:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, file storage, authentication | Workspace data, account credentials, session tokens |
| Stripe | Payment processing, subscription management | Billing details (no raw card numbers) |
| Resend | Transactional and business email delivery | Email content, recipient addresses |
| Vercel | Application hosting and edge delivery | Request logs, IP addresses |
| Anthropic | AI model inference (Claude) | Prompts, relevant workspace context |
| OpenSRS / Tucows | Domain name registration | Registrant contact info (ICANN required) |
| Cloudflare | DNS management and proxy | Domain DNS records |
06 AI features and data handling
GrydBase uses Anthropic's Claude API to power AI features such as email drafting, site content generation, and workflow assistance. When you initiate an AI feature:
- Your prompt and relevant workspace context (e.g., a contact's name or a site section) are sent to Anthropic
- Anthropic processes this data to generate a response and returns it to GrydBase
- Anthropic does not use API-submitted data to train its models, per their enterprise API data policy
- AI requests are never made automatically — they are always user-initiated
We do not send payment data, authentication credentials, or full email inboxes to Anthropic. AI context is limited to what is directly relevant to your request.
Each AI request consumes Credits from your workspace balance. Credits are charged at the time of the request. AI-generated content is stored in your workspace only if you choose to save it.
07 Data retention
We retain your data for as long as your account is active. If you cancel your subscription, your workspace data is retained for 30 days before being scheduled for deletion, giving you time to export anything you need.
Some data may be retained longer where required by law (e.g., billing records). Email delivery logs are retained for 90 days. IP-based security logs are retained for 30 days.
08 Exporting your data
You have the right to export your data at any time while your account is active. The following exports are available from your workspace settings:
- Contacts and CRM records — CSV export
- Invoices and contracts — PDF download per record
- Email messages — MBOX/EML format
- DNS records — Zone file export
- Site content — JSON export of page blocks
For a full bulk export of all workspace data, email hello@calebmedia.co with the subject "Data Export Request." We will deliver a complete archive within 14 business days.
09 Deleting your data
You may request deletion of your account and all associated data by emailing hello@calebmedia.co with the subject "Account Deletion Request." We will complete deletion within 30 days, except for data we are required to retain by law (such as billing records).
Domain registrations are governed by ICANN policy and cannot be deleted mid-registration period. They will expire naturally unless renewed.
10 White label and reseller use
Agency plan subscribers may configure GrydBase with custom branding. When white-label is enabled, your customers interact with your branded interface and may not be aware they are using GrydBase. In this case, you are acting as a data controller for your customers' data, and we are acting as your data processor.
You are responsible for providing your own privacy notice to your customers explaining how their data is collected and used when they access your white-labeled portal. Our Privacy Policy governs the relationship between you and us, not between you and your end customers.
11 Service availability and infrastructure
We design GrydBase for the highest possible reliability. However, GrydBase is built on top of third-party infrastructure — including Vercel (hosting), Supabase (database and authentication), Stripe (payments), and Resend (email delivery). The availability of these services is outside our direct control.
In the event of an outage or service degradation caused by a third-party provider, we will work in good faith to restore full functionality as quickly as possible and communicate status updates through your workspace or registered email address.
No system is perfectly reliable. We do not guarantee uninterrupted access to GrydBase and are not liable for data delays or loss of access caused by third-party infrastructure failures. Each provider publishes its own public status page.
12 Security
We use industry-standard security practices to protect your data, including:
- TLS encryption in transit for all data between your browser and our servers
- Encrypted storage for sensitive values (API keys, webhook secrets)
- Row-level security enforced at the database layer via Supabase
- Session tokens rotated on sign-in and invalidated on sign-out
- Service role credentials never exposed to client-side code
No system is perfectly secure. If you discover a vulnerability, please report it to hello@calebmedia.co.
13 Children
GrydBase is intended for use by adults operating or working for businesses. We do not knowingly collect data from anyone under 18 years of age. If you believe a minor has provided us data, contact us and we will delete it promptly.
14 Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by displaying a notice in your workspace at least 14 days before the changes take effect. Continued use of GrydBase after that date constitutes acceptance of the updated policy.
15 Contact
Questions, export requests, or deletion requests: hello@calebmedia.co
Caleb Media Studio, LLC · Central Florida, United States