This Privacy Policy describes how GrepLink collects, uses, and shares information about you when you use our desktop application, marketing site, and cloud sync services (collectively, the “Service”).
1. What We Collect
- Account data: email address and password hash, held by Supabase Auth.
- Your Content: the bookmarks, snippets, folders, tags, and notes you save — synced to our Supabase database under row-level security scoped to your account.
- Consent records: when you create an account, we record that you accepted our Terms of Service and Privacy Policy, including the document version and timestamp. We keep this as proof of consent, as required by data-protection law. We do not store your IP address or device details with it.
- Subscription data: plan, status, renewal date, license key. Received from LemonSqueezy via webhook.
- Error telemetry (opt-in): the desktop app can send anonymized exception reports to Sentry when you opt in to error reporting. PII (emails, IP, Authorization headers) is scrubbed client-side before sending.
2. What We Don't Collect
- We do not collect analytics on which bookmarks you open.
- We do not read the content of pages you bookmark.
- We do not track your cursor, scroll, or keystrokes outside the app.
- We do not sell your data. Period.
3. Processors
We rely on a small set of sub-processors to deliver the Service:
- Supabase — database, authentication, realtime, edge-function hosting. Data residency: EU (Frankfurt).
- LemonSqueezy— payments & merchant of record. They receive your billing information directly; we never see your card details.
- Resend — transactional email delivery (welcome, receipts, cancellation notices).
- Sentry (opt-in only) — error telemetry when enabled in the desktop app.
4. Legal Basis (EU/EEA)
Where GDPR applies, we process your personal data on these legal bases:
- Providing the Service — account data, Your Content, sync, and subscription management — on the basis of performing our contract with you (Art. 6(1)(b)).
- Keeping consent and invoice records — to meet our legal obligations (Art. 6(1)(c)).
- Optional error telemetry (Sentry) — only with your consent (Art. 6(1)(a)), which you can withdraw at any time.
5. International Transfers
Your data is primarily stored in the European Union (Supabase, Frankfurt). Some limited data is processed by US-based sub-processors (LemonSqueezy, Resend, Sentry). These transfers are covered by the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, so your data keeps an equivalent level of protection.
6. Your Rights
Under GDPR (EU), CCPA (California), and similar laws, you have the right to:
- Request a copy of all data we hold about you (data portability).
- Request correction of inaccurate data.
- Request deletion of your account and all associated data.
- Request that we restrict processing of your data in certain circumstances.
- Object to processing of your data.
- Withdraw consent at any time where processing is based on consent (e.g., error telemetry), without affecting prior lawful processing.
EU/EEA users also have the right to lodge a complaint with their local data protection authority.
Email hello@greplink.app to exercise any of these rights. We respond within 30 days.
7. California Residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request its deletion or correction, and to non-discrimination for exercising these rights. We do not sell or share your personal information, so no “Do Not Sell or Share My Personal Information” action is needed. To exercise any right, email hello@greplink.app.
8. Data Retention
We retain your data for as long as your account is active. When you delete your account, we delete your data within 30 days (subject to invoice records held by LemonSqueezy for their statutory retention period, typically 7 years).
Consent records are deleted together with your account. (If we are ever legally required to retain proof of consent for a limitation period after account deletion, we will retain only the minimal record — document type, version, and timestamp — and nothing else.)
9. Cookies
The marketing site uses a Supabase session cookie for authentication on /pricing, /account, and checkout flows. No third-party analytics or advertising cookies.
10. Children
GrepLink is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact hello@greplink.app and we will delete it.
11. Changes
Material changes to this Policy will be notified via email at least 14 days in advance.
12. Contact
Privacy questions: hello@greplink.app.