Grinfi

Privacy Policy

Grinfi OÜ — Grinfi and Telegrin

Last updated: September 2, 2026 · Version 2.0

The short version

We store what the products need to work: your account, your campaigns, and the public messages our AI flagged as leads for you. We do not sell any of it and we do not use it to train public AI models. Servers are in the EU. You can export everything, or delete everything, from your settings — without asking us.

The rest of this page is the detail.

1. Who we are, and the two roles we play

Grinfi OÜ, registry code 16546847, Vesivärava tn 50-201, Kesklinna linnaosa, Tallinn, Harju maakond, 10152, Estonia, operates Grinfi and Telegrin. This policy covers both products and the sites grinfi.io, app.grinfi.io, leadgen.grinfi.io, tg.grinfi.io, support.grinfi.io and mcp.grinfi.io.

Read this first — it decides which rules apply to what.

Whose dataOur roleGoverned by
Yours — your account, workspace, billing, how you use the appWe are the controller: we decide why and how it is processedThis policy
Your prospects' — people your campaigns find, message and storeYou are the controller; we are your processor, acting on your instructionsOur DPA and section 3 below

We do not decide who you monitor or who you contact. You do. Our job is to run the machinery and protect the data while we hold it.

2. What we collect about you

You give us:

CategoryWhatRequired?
AccountFirst name, last name, email, password (stored only as a bcrypt hash — never in clear text)To sign up
ProfilePhone, company, positionOptional
LocationCountry (defaulted from your IP), timezoneOptional
BillingPayment details handled by Stripe — we never see or store card numbers, only a Stripe customer id and your planFor paid plans
CommunicationsYour messages to support and salesWhen you write to us
Connected accountsThe signed-in session for accounts you connect (LinkedIn, Telegram, Threads, Slack) — for Telegram, an encrypted session key and the phone number used for that login. We never ask for, receive or store the passwords of those accounts: you sign in on the platform itselfWhen you connect one
ContentCampaign settings, keywords, prompts, your AI-Brain (what your business sells), uploaded filesAs you use the products

We collect automatically:

  • Usage — pages visited, session length, which features you use;
  • Technical — request headers, browser, operating system, device;
  • Network — IP address and internet provider;
  • Diagnostics — error reports, with credentials and secrets stripped out before they leave our systems.

3. Data about people who are not our users

This section exists because Telegrin cannot work without processing it, and because those people deserve to know.

To find buying intent, Telegrin reads public conversations on messaging platforms, professional networks and public forums, and stores, for the customer who set up that campaign:

  • the author's public display name or handle, and a link to their public profile;
  • the text of the public message, where it was posted and when;
  • the AI's assessment of whether it looks like buying intent;
  • any later conversation between that person and our customer, where the customer replies through the product.

What we do not do. We do not read private conversations we are not entitled to see, do not access anyone's direct messages, do not de-anonymise anyone, do not build profiles beyond the customer's campaign, do not deliberately collect special categories of data (health, politics, religion, sexual orientation, biometrics), and do not sell this data to anybody.

Legal basis. Our customer relies on legitimate interest — GDPR Article 6(1)(f) — to find and contact business prospects, and our Terms require them to have weighed that interest against the rights of the people concerned. We process this data only on that customer's instructions, as their processor.

Why we did not write to you individually. We collect this data from public sources rather than from you. Contacting every author of every public post we process would take disproportionate effort, so we rely on the exemption in Article 14(5)(b) and publish this section instead — so that the processing is described in public rather than hidden.

If you are one of those people. You have every right in section 9, including the right to object. Because our customer decides what happens to your data, the quickest route is usually them. If you write to [email protected] we will identify the customer who holds your data, pass your request to them without delay, and help them act on it.

How long we keep it. For as long as our customer keeps it. They decide — they are the controller of this data, and our Terms require them not to keep it longer than their purpose needs. We delete a lead when they delete it, when they ask us to, and when their workspace closes. We run no automatic purge that would destroy a live conversation.

4. Why we use data, and on what legal basis

PurposeLegal basis
Running the Service, your account, your campaignsPerformance of a contract
Taking payment, invoicingContract; legal obligation
Support and answering youContract; legitimate interest
Keeping the Service secure, preventing fraud and abuseLegitimate interest
Improving the Service and understanding how features are usedLegitimate interest
Marketing emails about our productsConsent, withdrawable at any time
Keeping accounting recordsLegal obligation

You can object to anything based on legitimate interest — see section 9.

5. Automated processing and AI

We are explicit about this because the products score people automatically.

  • Telegrin's AI reads a public message and gives it a relevance score, which decides whether it becomes a lead in the customer's feed. The inputs are the customer's keywords, the description of their business, and the agent's instructions.
  • In Copilot mode a human approves every message before it is sent.
  • In Autopilot mode the customer has explicitly confirmed that replies go out automatically, within limits they set, and that they are responsible for what is sent in their name.

The result is a business-development contact, not a decision with legal or similarly significant effects on the individual, so Article 22 does not apply in the ordinary case. Either way a human can always intervene: the customer can review, edit or delete anything, and you can object under section 9.

AI providers. We use Anthropic and OpenAI through commercial APIs. Both are contractually prohibited from using your data — or your prospects' data — to train their public models.

6. Cookies

We use cookies and similar technologies for:

  • Strictly necessary — signing you in, keeping your session, security. These cannot be switched off.
  • Analytics — Google Tag Manager, to understand how the products are used.
  • Support — Chatwoot, for the in-app chat.
  • Affiliate attribution — Promotekit, to credit partners for referrals.

Non-essential cookies are set only with your consent, which you give or refuse in the cookie banner and can change at any time from the same place.

7. Who we share data with

We do not sell your data and we do not share it for advertising.

We share it only with service providers who process it on our instructions, under contractual confidentiality and security obligations. By category:

What they doWhereWhat they touch
Hosting, databases and application backendsEuropean Economic AreaAll service data
Outbound delivery, campaign execution and network routingEEA, and a routing provider in a country covered by an EU adequacy decisionWorkspace configuration, campaign content, contact data, and the signed-in session used to send on your behalf — never your passwords
AI analysis — Anthropic and OpenAI, through commercial APIsUSAMessage text and campaign context
Collection of public postsEEA / USASearch terms and the public posts returned
Payments — StripeEEA / USABilling details. Card data goes only to Stripe; we never see or store it
Transactional email, support chat, error diagnostics, traffic protectionEEA / USAEmail addresses, your messages to support, technical data with secrets stripped
Analytics and affiliate attributionUSAUsage and referral data — only with your cookie consent

A full list naming each provider is available on request — write to [email protected]. We give it to customers who need it for their own compliance review, and we will tell you before a change to that list that materially affects you, so you have the chance to object.

Transfers outside the EEA. Where a provider is in the United States we rely on the European Commission's Standard Contractual Clauses and, where applicable, the recipient's certification under the EU–US Data Privacy Framework, together with supplementary technical measures. Other non-EEA providers we use are covered by an EU adequacy decision, which requires no additional mechanism. Ask us for a copy of the safeguards at [email protected].

Other disclosures. Where the law requires it, or to protect our rights, prevent fraud or protect someone's safety. In a merger, acquisition or asset sale, with the data staying under protections at least as strong as these.

8. How long we keep things

DataKept for
Account and workspace dataWhile your account is active
After you delete your workspaceDeleted, with a 30-day window in which you can cancel the deletion
Backups30 days, then overwritten
Leads and conversation historyWhile you keep them — you decide, and you can delete any of them at any time. We delete them on your request, without undue delay, and when your workspace closes
Billing and accounting records7 years, as Estonian tax law requires
Support conversations3 years
Diagnostic and audit logsUp to 90 days

9. Your rights

Under the GDPR you can access your data, correct it, erase it, export it, restrict or object to processing based on legitimate interest, withdraw consent at any time without affecting what came before, and complain to a supervisory authority.

Two of these you can exercise yourself, right now:

  • Export — Settings → Privacy → download your whole workspace as one JSON file: campaigns, chats, keywords, signals, leads and conversations.
  • Delete — Settings → Privacy → delete the workspace. It is scheduled immediately and you have 30 days to cancel before it becomes permanent.

For anything else write to [email protected]. We answer within one month and will tell you if we need longer. We may need to verify your identity first.

Supervisory authority. If our answer does not satisfy you, you can complain to the Estonian Data Protection Inspectorate — Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, [email protected], aki.ee — or to the authority where you live or work.

If you are in California. You may request the categories and specific pieces of personal information we hold about you, ask us to delete it, and ask us to correct it. We do not sell personal information and do not share it for cross-context behavioural advertising. We will not discriminate against you for exercising these rights. Use the same address: [email protected].

10. Security

We do not hold the passwords to the platforms you connect. You sign in on the platform itself; what we keep is the resulting session, which you can revoke at any time by disconnecting the account in settings. That is deliberate: a password we never receive cannot leak from us.

We protect the rest with, among other measures: TLS in transit; encryption at rest for sensitive fields, including the Telegram session keys you entrust to us; bcrypt password hashing; role-based access inside a workspace and least-privilege access for our own staff; fully separated production and development environments with separate keys and data; daily automated backups with a weekly automated restore test; and stripping of credentials and secrets from logs and error reports.

No system is perfectly secure. If a breach affects personal data we will notify the supervisory authority within 72 hours where required, and tell affected people without undue delay where the risk to them is high.

11. Children

The products are for business use and are not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to [email protected] and we will delete it.

12. Changes to this policy

We may update this policy. If we make material changes to how we process your personal data, we will notify you — by email or by a prominent notice inside the Service — and the updated policy takes effect when we publish it. For minor or clarifying changes we update this page and the version number above, and encourage you to review it from time to time.

13. Contact

Grinfi OÜ, registry code 16546847 Vesivärava tn 50-201, Kesklinna linnaosa, Tallinn, Harju maakond, 10152, Estonia [email protected] — including for privacy and data-protection requests.