GrafterOS — Privacy Policy
Last updated: 8 August 2026 · Version 1.5
This policy explains what data GrafterOS collects, why, who it is shared with, and your rights. It's written in plain English on purpose — if anything is unclear, ask: evan@peqoy.com.
Who we are
GrafterOS runs the back office of a small trades business — quoting, scheduling, invoicing, payment chasing and email — on the owner's instruction, given in plain English. It is built on a large language model (see AI processing below). GrafterOS is operated by Evan White, a sole trader based in the United Kingdom.
For your account details and your use of the service, we are the data controller. For the records you keep about your own customers (their names, contact details, jobs and invoices), you are the controller and we act as your processor — we process that data only to run the service for you, on your instructions.
Contact for anything in this policy: evan@peqoy.com.
What we collect
- Account and business profile — your name, business name, email address, phone number, business address, trade, pricing settings (rates, price list, markup, VAT rate), working hours, and the bank/invoice details you choose to print on your documents.
- Business records — the customers, jobs, quotes, invoices, payments, costs, notes and reminders you (or the assistant, on your instruction) create in the service.
- Conversations with the assistant — everything you ask it and everything it says back, however the message reaches us, kept so it has context and you have a record. This includes the content of an email the inbox watcher acts on: it reads the thread into your conversation so it can draft your reply.
- Files — photos, receipts and documents you upload (or that arrive on emails the assistant handles for you), stored in a private bucket only your account can reach.
- Connected Google data — if you connect your Google account: email and calendar data, as described in the Google section below. Connecting is optional and separate from creating an account.
- Customer replies — if one of your customers replies to a message sent on your behalf, the reply arrives in your own email inbox. If you have connected Google and inbox monitoring is running on the service (see Inbox monitoring below), it is read there so the assistant can draft your response; nothing is ever sent back to them automatically.
- Service-improvement notes — when something notable happens in how you use the service (you turn a draft down at the approval step, or the assistant can't do something on your plan), we keep a short note that it happened, along with your trade and a pointer to the record or action it concerned. The note is written by the service from a fixed set of wordings — it is never copied from your words or your customers', and it carries no name, contact detail, address or amount of money. We keep these to find where the service gets things wrong and make it better for everyone who uses it. They are part of your account's data: they come down in your export, and they are deleted with your account.
- Service and technical data — records of what the service sent on your behalf (so there is an audit trail), usage metering (how much AI processing your account uses), error/diagnostic logs needed to keep the service running, and — if you switch notifications on — the anonymous delivery address your device registers for them.
How we use it
Only to run the service for you: drafting quotes, invoices, emails and messages for your approval; keeping your records; managing your diary; reminding and chasing; and sending you service messages (like your login code). We also use aggregate usage data to operate, secure and improve the service.
We do not sell your data. We do not use your data for advertising. And nothing is ever sent to one of your customers without your explicit approval — every outbound quote, invoice, chase, email or message requires your one-tap approval first.
AI processing
GrafterOS is built on a large language model (an AI assistant). When you use the service, your messages and the relevant parts of your business records — and, where you have connected Google, relevant email and calendar content — are processed by Anthropic's Claude models through Anthropic's API to understand your request, draft documents and messages, and carry out the tasks you ask for.
Anthropic processes this data as our sub-processor to provide the AI responses; under our commercial terms with Anthropic, data submitted through the API is not used to train Anthropic's models. AI output can be wrong — which is exactly why the service is built so you review and approve anything before it reaches a customer.
Google user data (Gmail and Calendar)
If you choose to connect your Google account, we request these permissions (scopes):
- Gmail (read and modify) — used to read the emails and threads relevant to your work, create draft replies for your approval, and send the messages and documents you have approved from your own email address.
- Calendar (read and write) — used to check your availability and to book, move or cancel the jobs and appointments you ask for.
- Basic account info (email address) — used to identify which Google account is connected to your business.
GrafterOS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In practice, that means your Google data is:
- used only to provide the user-facing features described above;
- never used for advertising, and never sold or passed to data brokers;
- never used to develop, improve or train generalised AI or machine-learning models — it is processed by our AI sub-processor solely to produce your responses, as described in the AI processing section;
- not read by humans at GrafterOS, except with your explicit permission (for example, when you ask for support on a specific message), where necessary for security or abuse investigation, or where required by law.
Inbox monitoring (the email watcher). The service includes an optional background feature that checks your connected inbox every few minutes so that a customer email gets a drafted reply waiting for you. Where this is enabled, it looks at your most recent inbox messages; automated and bulk mail (newsletters, notifications) is filtered out without AI processing; the remainder is classified by an AI step that has no ability to take any action. Only an email that looks like a customer needing a response (or a payment you should know about) is then read in full — its attachments are stored with your records so you can act on them, and any reply is only ever drafted, waiting for your approval. We keep a record of which messages have been checked so nothing is processed twice. We do not mirror your mailbox: mail that is filtered out or classified as noise leaves nothing behind but that record. A thread the assistant does act on is read into your conversation so it can draft the reply, and stays there as part of it.
You can disconnect Google at any time from Settings, or by revoking GrafterOS's access at myaccount.google.com/permissions. Stored Google credentials are deleted when your account is deleted.
Who we share data with (sub-processors)
We share data only with the service providers that run the product, each bound by their own data-processing terms, and only as needed for the purpose listed:
- Anthropic — AI model processing (the assistant itself).
- Supabase — database, file storage, and login: it holds your account and sends the sign-in code to your email address. Our database is hosted in Supabase's London (UK) region.
- Resend — delivery of our own service and alert email to you: reminders and the daily brief when a notification cannot reach you, and the links that get you back in when a connection drops. Never used to email your customers — those only ever go from your own address.
- Railway — application hosting (EU region).
- Google — Gmail and Calendar, only where you connect them and only under the consent you grant.
- Apple, Google and Mozilla push services — delivering the notifications you switch on, through whichever browser you installed the app in (Apple for Safari, Google for Chrome, Mozilla for Firefox). The notification itself is encrypted end to end, so the push service cannot read what it carries. What it does handle is the anonymous delivery address your own device generated when you turned notifications on, and the delivery details that go with passing a message to your phone.
- Xero — accounting, only where you connect your Xero organisation: we hold the connection to the one company you choose and nothing else in your Xero, and that connection covers the invoice, cost and contact records in those books. Nothing is written into them without your say-so: where you confirm it, we write a customer's contact details (name, email, phone) into your organisation as a Xero contact — exactly as you approved them, never on our own initiative. Xero owns the CIS calculation and any filing — we never work the deduction out ourselves, and we never file anything with HMRC.
- Slack — delivery of approval requests and notifications, where used for your account.
- Stripe — subscription payment, where billing applies. Payment happens on Stripe's own hosted pages: we never see or store your card details.
- Sentry — error monitoring, where enabled, so we find and fix faults; error reports are technical diagnostics, not your business records.
Beyond these providers, we disclose data only if required by law. We will tell you about material changes to this list by updating this policy.
Where your data lives, and international transfers
Your records are stored in the UK (Supabase, London region) and the application runs in the EU (Railway). Some sub-processors process data outside the UK — for example Anthropic, Resend, Slack, Stripe and the push services in the United States, and Xero, a New Zealand company, in the regions its own hosting uses. Where data leaves the UK or EEA, we rely on the safeguards recognised under UK GDPR, such as adequacy decisions and the UK International Data Transfer Addendum / EU Standard Contractual Clauses in those providers' data-processing terms.
Security
- Third-party credentials we hold for you — Google, Xero and Slack — are stored encrypted at rest (AES-256-GCM).
- All traffic to and from the service is encrypted in transit (TLS).
- Every account's data is isolated: every read and write is scoped to your business, and uploaded files live in a private bucket reachable only through your authenticated session.
- Inbound webhooks (Slack, payments) are cryptographically signature-verified before they are processed.
- We never store card details — payment runs entirely on Stripe's hosted pages.
How long we keep data, and deletion
- While your account is active, we keep your records so the service can do its job — your history is part of the product.
- If you delete your account (Settings → Account & data → Delete account), it closes immediately: the assistant stops, and the account is locked. Your data — including uploaded files and stored Google credentials — is then permanently and irreversibly erased after a 30-day window. The window exists so an accidental deletion can be reversed; after it, nothing identifiable remains.
- Anonymised, aggregated statistics (for example, typical pricing patterns across a trade) may be retained beyond deletion. These contain nothing that identifies you, your business or your customers.
- Legal retention — where the law requires us to keep specific records for longer (for example tax and accounting records relating to payments made to us), we keep only what the law requires, for as long as it requires.
Your rights
Under UK GDPR you have the right to:
- Access and portability — download a complete, machine-readable copy of your business's data at any time, self-serve, from Settings → Account & data → Export.
- Rectification — correct anything: edit it in Settings, ask the assistant to update the record, or email us.
- Erasure — delete your account as described above.
- Objection and restriction — object to or ask us to restrict processing; email us and we will respond within one month.
- Complaint — complain to the UK Information Commissioner's Office (ico.org.uk). We'd appreciate the chance to sort it out first: evan@peqoy.com.
Our lawful bases: performing our contract with you (running the service), your consent (connecting Google), our legitimate interests (security, preventing abuse, improving the service with aggregate data), and legal obligation (statutory records).
Your customers’ data
The service holds contact details and job history for your customers because you (or your connected accounts) put them there. We process that data solely as your processor: we never contact your customers except to deliver a message you approved, and we never use their details for anything else. If one of your customers wants their data corrected or deleted, that request is yours to action (the assistant can do it for you); if they contact us directly, we will refer them to you and assist as needed.
Cookies and tracking
The app stores a sign-in token on your device so you stay logged in — that's it. We use no advertising cookies, no cross-site tracking, and no third-party analytics.
Children
GrafterOS is a tool for running a business and is not directed at children. You must be at least 18 to hold an account.
Changes and contact
If we change this policy, we'll update the date and version at the top, and tell you about any material change before it takes effect. Questions, requests, or anything unclear: evan@peqoy.com.
Terms of Service