Grinfi OÜ — Grinfi and Telegrin
Last updated: September 2, 2026 · Version 2.0
The short version
We store what the products need to work: your account, your campaigns, and the public messages our AI flagged as leads for you. We do not sell any of it and we do not use it to train public AI models. Servers are in the EU. You can export everything, or delete everything, from your settings — without asking us.
The rest of this page is the detail.
1. Who we are, and the two roles we play
Grinfi OÜ, registry code 16546847, Vesivärava tn 50-201, Kesklinna linnaosa, Tallinn, Harju maakond, 10152, Estonia, operates Grinfi and Telegrin. This policy covers both products and the sites grinfi.io, app.grinfi.io, leadgen.grinfi.io, tg.grinfi.io, support.grinfi.io and mcp.grinfi.io.
Read this first — it decides which rules apply to what.
| Whose data | Our role | Governed by |
|---|---|---|
| Yours — your account, workspace, billing, how you use the app | We are the controller: we decide why and how it is processed | This policy |
| Your prospects' — people your campaigns find, message and store | You are the controller; we are your processor, acting on your instructions | Our DPA and section 3 below |
We do not decide who you monitor or who you contact. You do. Our job is to run the machinery and protect the data while we hold it.
2. What we collect about you
You give us:
| Category | What | Required? |
|---|---|---|
| Account | First name, last name, email, password (stored only as a bcrypt hash — never in clear text) | To sign up |
| Profile | Phone, company, position | Optional |
| Location | Country (defaulted from your IP), timezone | Optional |
| Billing | Payment details handled by Stripe — we never see or store card numbers, only a Stripe customer id and your plan | For paid plans |
| Communications | Your messages to support and sales | When you write to us |
| Connected accounts | The signed-in session for accounts you connect (LinkedIn, Telegram, Threads, Slack) — for Telegram, an encrypted session key and the phone number used for that login. We never ask for, receive or store the passwords of those accounts: you sign in on the platform itself | When you connect one |
| Content | Campaign settings, keywords, prompts, your AI-Brain (what your business sells), uploaded files | As you use the products |
We collect automatically:
- Usage — pages visited, session length, which features you use;
- Technical — request headers, browser, operating system, device;
- Network — IP address and internet provider;
- Diagnostics — error reports, with credentials and secrets stripped out before they leave our systems.
3. Data about people who are not our users
This section exists because Telegrin cannot work without processing it, and because those people deserve to know.
To find buying intent, Telegrin reads public conversations on messaging platforms, professional networks and public forums, and stores, for the customer who set up that campaign:
- the author's public display name or handle, and a link to their public profile;
- the text of the public message, where it was posted and when;
- the AI's assessment of whether it looks like buying intent;
- any later conversation between that person and our customer, where the customer replies through the product.
What we do not do. We do not read private conversations we are not entitled to see, do not access anyone's direct messages, do not de-anonymise anyone, do not build profiles beyond the customer's campaign, do not deliberately collect special categories of data (health, politics, religion, sexual orientation, biometrics), and do not sell this data to anybody.
Legal basis. Our customer relies on legitimate interest — GDPR Article 6(1)(f) — to find and contact business prospects, and our Terms require them to have weighed that interest against the rights of the people concerned. We process this data only on that customer's instructions, as their processor.
Why we did not write to you individually. We collect this data from public sources rather than from you. Contacting every author of every public post we process would take disproportionate effort, so we rely on the exemption in Article 14(5)(b) and publish this section instead — so that the processing is described in public rather than hidden.
If you are one of those people. You have every right in section 9, including the right to object. Because our customer decides what happens to your data, the quickest route is usually them. If you write to [email protected] we will identify the customer who holds your data, pass your request to them without delay, and help them act on it.
How long we keep it. For as long as our customer keeps it. They decide — they are the controller of this data, and our Terms require them not to keep it longer than their purpose needs. We delete a lead when they delete it, when they ask us to, and when their workspace closes. We run no automatic purge that would destroy a live conversation.
4. Why we use data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Running the Service, your account, your campaigns | Performance of a contract |
| Taking payment, invoicing | Contract; legal obligation |
| Support and answering you | Contract; legitimate interest |
| Keeping the Service secure, preventing fraud and abuse | Legitimate interest |
| Improving the Service and understanding how features are used | Legitimate interest |
| Marketing emails about our products | Consent, withdrawable at any time |
| Keeping accounting records | Legal obligation |
You can object to anything based on legitimate interest — see section 9.
5. Automated processing and AI
We are explicit about this because the products score people automatically.
- Telegrin's AI reads a public message and gives it a relevance score, which decides whether it becomes a lead in the customer's feed. The inputs are the customer's keywords, the description of their business, and the agent's instructions.
- In Copilot mode a human approves every message before it is sent.
- In Autopilot mode the customer has explicitly confirmed that replies go out automatically, within limits they set, and that they are responsible for what is sent in their name.
The result is a business-development contact, not a decision with legal or similarly significant effects on the individual, so Article 22 does not apply in the ordinary case. Either way a human can always intervene: the customer can review, edit or delete anything, and you can object under section 9.
AI providers. We use Anthropic and OpenAI through commercial APIs. Both are contractually prohibited from using your data — or your prospects' data — to train their public models.
6. Cookies
We use cookies and similar technologies for:
- Strictly necessary — signing you in, keeping your session, security. These cannot be switched off.
- Analytics — Google Tag Manager, to understand how the products are used.
- Support — Chatwoot, for the in-app chat.
- Affiliate attribution — Promotekit, to credit partners for referrals.
Non-essential cookies are set only with your consent, which you give or refuse in the cookie banner and can change at any time from the same place.
7. Who we share data with
We do not sell your data and we do not share it for advertising.
We share it only with service providers who process it on our instructions, under contractual confidentiality and security obligations. By category:
| What they do | Where | What they touch |
|---|---|---|
| Hosting, databases and application backends | European Economic Area | All service data |
| Outbound delivery, campaign execution and network routing | EEA, and a routing provider in a country covered by an EU adequacy decision | Workspace configuration, campaign content, contact data, and the signed-in session used to send on your behalf — never your passwords |
| AI analysis — Anthropic and OpenAI, through commercial APIs | USA | Message text and campaign context |
| Collection of public posts | EEA / USA | Search terms and the public posts returned |
| Payments — Stripe | EEA / USA | Billing details. Card data goes only to Stripe; we never see or store it |
| Transactional email, support chat, error diagnostics, traffic protection | EEA / USA | Email addresses, your messages to support, technical data with secrets stripped |
| Analytics and affiliate attribution | USA | Usage and referral data — only with your cookie consent |
A full list naming each provider is available on request — write to [email protected]. We give it to customers who need it for their own compliance review, and we will tell you before a change to that list that materially affects you, so you have the chance to object.
Transfers outside the EEA. Where a provider is in the United States we rely on the European Commission's Standard Contractual Clauses and, where applicable, the recipient's certification under the EU–US Data Privacy Framework, together with supplementary technical measures. Other non-EEA providers we use are covered by an EU adequacy decision, which requires no additional mechanism. Ask us for a copy of the safeguards at [email protected].
Other disclosures. Where the law requires it, or to protect our rights, prevent fraud or protect someone's safety. In a merger, acquisition or asset sale, with the data staying under protections at least as strong as these.
8. How long we keep things
| Data | Kept for |
|---|---|
| Account and workspace data | While your account is active |
| After you delete your workspace | Deleted, with a 30-day window in which you can cancel the deletion |
| Backups | 30 days, then overwritten |
| Leads and conversation history | While you keep them — you decide, and you can delete any of them at any time. We delete them on your request, without undue delay, and when your workspace closes |
| Billing and accounting records | 7 years, as Estonian tax law requires |
| Support conversations | 3 years |
| Diagnostic and audit logs | Up to 90 days |
9. Your rights
Under the GDPR you can access your data, correct it, erase it, export it, restrict or object to processing based on legitimate interest, withdraw consent at any time without affecting what came before, and complain to a supervisory authority.
Two of these you can exercise yourself, right now:
- Export — Settings → Privacy → download your whole workspace as one JSON file: campaigns, chats, keywords, signals, leads and conversations.
- Delete — Settings → Privacy → delete the workspace. It is scheduled immediately and you have 30 days to cancel before it becomes permanent.
For anything else write to [email protected]. We answer within one month and will tell you if we need longer. We may need to verify your identity first.
Supervisory authority. If our answer does not satisfy you, you can complain to the Estonian Data Protection Inspectorate — Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, [email protected], aki.ee — or to the authority where you live or work.
If you are in California. You may request the categories and specific pieces of personal information we hold about you, ask us to delete it, and ask us to correct it. We do not sell personal information and do not share it for cross-context behavioural advertising. We will not discriminate against you for exercising these rights. Use the same address: [email protected].
10. Security
We do not hold the passwords to the platforms you connect. You sign in on the platform itself; what we keep is the resulting session, which you can revoke at any time by disconnecting the account in settings. That is deliberate: a password we never receive cannot leak from us.
We protect the rest with, among other measures: TLS in transit; encryption at rest for sensitive fields, including the Telegram session keys you entrust to us; bcrypt password hashing; role-based access inside a workspace and least-privilege access for our own staff; fully separated production and development environments with separate keys and data; daily automated backups with a weekly automated restore test; and stripping of credentials and secrets from logs and error reports.
No system is perfectly secure. If a breach affects personal data we will notify the supervisory authority within 72 hours where required, and tell affected people without undue delay where the risk to them is high.
11. Children
The products are for business use and are not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to [email protected] and we will delete it.
12. Changes to this policy
We may update this policy. If we make material changes to how we process your personal data, we will notify you — by email or by a prominent notice inside the Service — and the updated policy takes effect when we publish it. For minor or clarifying changes we update this page and the version number above, and encourage you to review it from time to time.
13. Contact
Grinfi OÜ, registry code 16546847 Vesivärava tn 50-201, Kesklinna linnaosa, Tallinn, Harju maakond, 10152, Estonia [email protected] — including for privacy and data-protection requests.