Legal

Privacy Policy

How Grabr collects, uses, stores, and shares personal data for cloud and self-hosted deployments.

Effective July 20, 2026Last updated July 20, 2026Grabr, operated by an individual in Bangladesh

1. Who we are

This Privacy Policy explains how Grabr, operated by an individual in Bangladesh (“Grabr”, “we”, “us”, or “our”) collects, uses, stores, shares, and otherwise processes personal data when you visit https://grabr-kappa.vercel.app, create an account, use the managed cloud service, connect social or messaging accounts, or contact us.

For privacy and data-protection requests, email supportgrabber@gmail.com.

Grabr is a social publishing and workflow product. Live publishing currently supports Bluesky and LinkedIn. Telegram is used as a mobile drafting and approval client. Google Drive can be connected for media import. AI generation features may use fal.ai and related model providers. Cloud billing is handled through Whop.

2. Scope: cloud vs self-host

Cloud service. If you use Grabr’s managed cloud at https://grabr-kappa.vercel.app, Grabr is the organization that determines how the service processes account and service data needed to operate the product. For content and connected-account data that you instruct the service to process (for example posts you draft or publish), Grabr typically acts as a service provider / processor on your instructions, subject to the Terms and any executed Data Processing Addendum.

Self-hosted Community deployments. If you deploy Grabr yourself using the public source and your own infrastructure (for example your own Supabase, Redis, Telegram bot token, and optional fal.ai key), you are the operator of that instance. In that case, you determine the purposes and means of processing. This Privacy Policy does not automatically govern self-hosted deployments operated by third parties.

3. Personal data we collect

Depending on how you use Grabr, we may process:

  • Account data: email address, password (handled by our authentication provider), display name, timezone, avatar URL if provided, and authentication session information.
  • Workspace and team data: workspace name, slug, plan, settings, memberships, roles (owner, admin, editor, viewer), and invitation emails for teammates who already have accounts.
  • Content data: post titles, captions, schedules, approval status, platform-specific captions, publish results, error messages, and related audit events.
  • Media: uploaded images and videos, files imported from Google Drive, media sent through Telegram, and AI-generated assets stored in our media storage.
  • Connected account credentials: connection metadata (for example handles, account IDs, display names) and encrypted OAuth tokens or Bluesky session material needed to publish or import on your behalf.
  • Telegram linkage: Telegram chat ID, pairing tokens and expiry, alert preferences, and temporary bot interaction state needed for drafting or approval flows. Message and media content you send to the bot may be stored as drafts or posts.
  • AI Studio data: prompts, selected templates, reference media identifiers or signed URLs, generation metadata, provider job identifiers, credit balances, and ledger entries.
  • Billing data: plan tier, subscription status, Whop membership/plan identifiers, billing cadence, period end, manage URL, and credit-pack events. Payment card details are processed by Whop, not stored in Grabr’s application database.
  • Operational analytics: internal publish metrics such as published, failed, and scheduled counts derived from your workspace data. We do not currently run third-party product analytics SDKs such as Google Analytics or PostHog in the application.
  • Support communications: information you send to supportgrabber@gmail.com, including attachments you choose to provide.
  • Technical data: IP address and browser metadata as processed by our hosting and security infrastructure, cookies and similar technologies described in the Cookie Policy, and server logs needed for security and reliability.

4. How we use personal data

We use personal data to:

  • create and authenticate accounts and workspaces;
  • provide scheduling, approvals, queueing, and publishing features;
  • connect and maintain social, Drive, and Telegram integrations;
  • store and deliver media required for drafts and published posts;
  • operate Content Studio and meter AI credits;
  • process subscriptions, plan changes, and credit allotments;
  • show workspace publish health and related operational metrics;
  • send in-product notifications and optional Telegram publish alerts;
  • secure the service, prevent abuse, and debug incidents;
  • respond to support, privacy, and legal requests; and
  • comply with applicable law and enforce our Terms and policies.

We do not sell personal data. We do not use personal data for third-party advertising networks.

6. How we share data

We share personal data only as needed to operate Grabr, including:

  • Infrastructure providers such as Supabase (auth, database, storage), hosting/CDN providers for the web application, and Redis for job queues.
  • Billing: Whop receives workspace and plan metadata needed for checkout, subscription status, and webhooks.
  • AI providers: fal.ai and related model routing may receive prompts, generation parameters, and temporary signed media URLs for analysis or generation.
  • Connected platforms: Bluesky, LinkedIn, Google, and Telegram receive the data needed to authenticate, import, draft, approve, or publish according to your instructions and their own terms/privacy policies.
  • Workspace members: teammates with access to your workspace can see content, approvals, and operational data according to their roles.
  • Legal and safety: we may disclose information if required by law, to protect rights and safety, or in connection with a business transfer if Grabr’s operations change ownership.

A current list of cloud subprocessors is available at /legal/subprocessors.

7. International transfers

Grabr is operated from Bangladesh, but infrastructure and integration providers may process data in other countries, including the United States and other regions where those vendors operate. By using the cloud service, you understand that personal data may be transferred to and processed outside Bangladesh.

Self-hosted operators choose their own infrastructure regions and are responsible for transfer compliance for their deployments.

8. Retention

We retain personal data for as long as needed to provide the service, maintain backups and security logs, resolve disputes, enforce agreements, and meet legal obligations. Exact retention periods vary by data type.

Practical examples based on current product behavior:

  • Account and workspace records generally remain while the account is active and for a reasonable period afterward to support support requests and legal compliance.
  • Posts, media, approvals, jobs, and audit events remain until deleted through product actions or a validated deletion request.
  • OAuth state cookies expire quickly (about 10 minutes). Session cookies persist according to the authentication provider.
  • Redis queue jobs are trimmed after completion/failure according to worker configuration.
  • Webhook event IDs may be retained for idempotency and abuse prevention.

Important limitation: disconnecting a social connection currently marks the connection as disconnected and does not automatically purge every encrypted token row. Deleting a post may not automatically delete every associated media object. If you need broader erasure, contact supportgrabber@gmail.com.

9. Your rights and choices

Subject to applicable law, you may request access, correction, deletion, restriction, or a copy of personal data we hold about you. You may also withdraw consent where processing is consent-based, and object to certain processing.

Self-service controls available today include: updating profile/workspace settings; connecting or disconnecting integrations; unpairing Telegram; deleting posts/drafts; removing some media; revoking API keys; managing Whop billing through Whop’s portal where a manage URL is available; and signing out.

Not currently self-service: one-click full account deletion, automated data-export packages, and guaranteed automatic purge of all OAuth secrets on disconnect. We will handle those requests manually where required by law and technically feasible.

To exercise rights, email supportgrabber@gmail.com with the email address on your account, the workspace(s) involved, and a clear description of the request. We may need to verify your identity before acting.

10. Security

We use administrative, technical, and organizational measures designed to protect personal data, including HTTPS in production, encrypted storage of OAuth/session secrets using AES-256-GCM with a server-held key, hashed storage of API keys and enterprise license keys, server-only service credentials, scoped OAuth permissions, signed webhook verification for billing and AI callbacks, and workspace-oriented access controls. See also our Security Overview.

No method of transmission or storage is perfectly secure. You are responsible for protecting account credentials, connected-platform tokens under your control, and access granted to workspace members.

11. Children

Grabr is intended for users aged 18 and older and for business or creator use. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.

12. Artificial intelligence

If you use Content Studio, prompts, templates, and optional reference media may be sent to fal.ai and related model providers to generate or analyze content. Generated outputs may be stored in your workspace media library and linked to generation records for billing and debugging.

Do not submit sensitive personal data in prompts unless necessary. AI outputs may be inaccurate or unsuitable; you remain responsible for reviewing content before publishing.

13. Cookies

We use cookies and similar technologies for authentication, OAuth security, and interface preferences. Details are in the Cookie Policy.

14. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top of the page will change when we do. Material changes may also be communicated through the service or by email when appropriate. Continued use after an update means you acknowledge the revised policy, except where additional consent is required by law.

15. Contact and complaints

Privacy and data requests: supportgrabber@gmail.com

Operator: Grabr, operated by an individual in Bangladesh. Website: https://grabr-kappa.vercel.app.

If you believe your rights have been violated under applicable Bangladesh privacy or cybersecurity rules, you may also have the right to raise the matter with competent authorities once the relevant complaint mechanisms are available under those laws. We encourage you to contact us first so we can try to resolve the issue.

Related documents

  • Terms and ConditionsThe rules that govern your use of the Grabr website, cloud service, and related features.
  • Cookie PolicyDetails about cookies and similar technologies used by Grabr for authentication and preferences.
  • SubprocessorsThird-party services that may process data to help operate the Grabr cloud service.
  • Data Processing Addendum OverviewAn overview of processing roles, safeguards, and enterprise DPA terms for cloud customers.
  • Security OverviewFactual security controls used by Grabr, customer responsibilities, and how to report issues.