Privacy Policy
Your privacy matters to us. Here's how we protect it.
Last updated: July 2026
Privacy at a Glance
- • We collect only what's necessary to provide our services
- • We do not sell your personal data. Our LinkedIn advertising pixel may count as "sharing" under California law, and it is off unless you turn it on
- • You can delete your account at any time, and ask us for a copy of your data — see section 11
- • Analytics and advertising trackers stay off until you opt in on our Cookie Settings page
- • Our hosting and database providers encrypt data at rest and in transit
Beta Services Notice
Gryphin is currently offered as a beta service. While we protect your data with the same safeguards described in this policy, please be aware that during the beta period:
- Features, data models, and integrations may change, be reset, or be removed without notice.
- We may contact you for product feedback, usability studies, or beta-related announcements.
- Usage telemetry is collected more actively to help us identify bugs and improve the product.
- We recommend keeping your own backups of critical content until the service reaches general availability.
1. Introduction & Who We Are
Gryphin is a product of Laika Dynamics Ltd ("Gryphin," "we," "us," or "our"), a company registered in New Zealand with its registered office at 114 Kennedy Road, Marewa, Napier 4110, New Zealand. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at gryphin.app, our applications, and our services (collectively, the "Services").
We handle personal information in accordance with the Privacy Act 2020 (New Zealand). Where the UK and EU General Data Protection Regulation applies to you, we also comply with it, and where the California Consumer Privacy Act as amended by the CPRA applies, section 13 sets out your additional rights.
1.1 Are we a controller or a processor?
This distinction matters because it decides who is responsible for your data and who you should ask to exercise your rights. Both roles apply to us, depending on the data:
We are the controller
For account data, authentication data, billing and subscription data, support correspondence, product analytics, marketing data, and security and diagnostic logs. We decide why and how that information is processed, and this policy governs it.
We are a processor
For the customer content you and your team put into boards, cards, comments, and attachments — including any personal information about third parties you choose to put there. Your organisation is the controller of that content and decides what goes in it. We only process it on your instructions to run the Services.
If you are a member of a workspace you do not own and you want content removed from that workspace, ask the workspace owner first. If they do not respond, contact us at privacy@gryphin.app and we will help.
Please read this Privacy Policy carefully. By using our Services, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
We collect information you provide directly to us, including:
Account Information
Name, email address, password, and profile picture
Payment Information
Billing address and payment method, tokenised and processed by Stripe. We never see or store your full card number
Content
Boards, cards, comments, attachments, and other content you create
Communications
Messages you send to us or other users
Waitlist & Beta Signups
Email address and any optional details you submit to join the waitlist or beta programme
Integration Data
Information you authorise us to access through connected services (e.g. Google Calendar, Google Drive)
2.2 Information Collected Automatically
When you use our Services, we automatically collect:
Device Information
Browser type, operating system, device identifiers
Usage Data
Pages visited, features used, time spent on the Services
Log Data
IP address, access times, referring URLs
Cookies
Small files stored on your device (see Cookie Policy). Non-essential cookies are off until you opt in
Push Tokens
Device push notification tokens if you install our mobile app and opt in to notifications
Product Analytics
Event data captured via PostHog. Because we identify signed-in users, this data is pseudonymous — it is linked to your account identifier and remains personal information. It is not anonymised
Analytics and advertising technologies only run if you have consented. See our Cookie Policy for a full inventory of what is set, by whom, and for how long.
2.3 AI-Powered Features
Some Gryphin features (such as task breakdown, summarisation, and AI chat) are powered by third-party large language model providers, including OpenAI and OpenRouter.
When you use these features, the content of your prompts — which may include card titles, descriptions, comments, or other information you choose to submit — is transmitted to those providers solely to generate a response.
We select providers whose API terms prohibit using your content to train their models. We do not send your data to AI providers unless you actively use an AI feature.
Please do not enter sensitive personal information — such as health, financial, or biometric details about identifiable people — into AI prompts.
3. How We Use Your Information
We use the information we collect to do the things below. Section 4 sets out the legal basis for each of them.
4. Legal Bases for Processing
If you are in the European Economic Area or the United Kingdom, the GDPR requires us to have a lawful basis for every purpose we process your personal data for. The table below maps each purpose to its basis under Article 6.
| What we do | Data involved | Lawful basis |
|---|---|---|
| Creating and administering your account; providing boards, cards, comments, and collaboration features | Account information, customer content, usage data | Performance of a contract — Art. 6(1)(b) |
| Taking payment, issuing invoices and receipts, and managing subscriptions | Billing details, subscription and transaction records | Performance of a contract — Art. 6(1)(b); legal obligation for tax and financial records — Art. 6(1)(c) |
| Sending service and transactional email (sign-in links, receipts, security alerts, service notices) | Email address, account and billing events | Performance of a contract — Art. 6(1)(b) |
| Providing AI-assisted features when you choose to use them | The prompt content you submit, which may include card titles, descriptions, and comments | Performance of a contract — Art. 6(1)(b) |
| Keeping the Services secure — bot protection, abuse detection, rate limiting, investigating incidents | IP address, device and log data, access records | Legitimate interests — Art. 6(1)(f): protecting our users, our systems, and our business from fraud and abuse |
| Diagnosing errors and crashes so we can fix them (Sentry) | Error reports, stack traces, browser and device information, user identifier | Legitimate interests — Art. 6(1)(f): keeping a beta product working and fixing defects |
| Responding to support requests and product feedback | Your messages to us and related account context | Performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) where you are not the account holder |
| Product analytics — understanding which features are used and where people get stuck | Pseudonymous event data linked to your account identifier | Consent — Art. 6(1)(a), given through our cookie banner or Cookie Settings page, and withdrawable at any time |
| Advertising and measuring ad performance, including the LinkedIn Insight pixel | Page views, referral information, and identifiers shared with LinkedIn | Consent — Art. 6(1)(a). Off unless you switch Marketing on |
| Sending marketing and product-announcement email | Email address, subscription status | Consent — Art. 6(1)(a). In New Zealand we also comply with the Unsolicited Electronic Messages Act 2007. Every message has an unsubscribe link |
| Contacting beta participants about usability studies and beta announcements | Email address, beta programme status | Legitimate interests — Art. 6(1)(f): improving a beta product, with an opt-out in every message |
| Complying with lawful requests, court orders, tax and accounting obligations, and enforcing our terms | Whatever the specific obligation or claim requires | Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) for establishing or defending legal claims |
| Transferring the business — a merger, acquisition, or sale of assets | Account and billing records | Legitimate interests — Art. 6(1)(f): being able to restructure or transfer the business, subject to notice to you |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms. You can object to that processing at any time — see section 11. You can ask us for a summary of the balancing assessment for any of the purposes above.
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. For cookies and trackers, use the Cookie Settings page. For marketing email, use the unsubscribe link in any message.
Under the New Zealand Privacy Act 2020 there is no equivalent "lawful basis" list. Instead, we must collect personal information for a lawful purpose connected with our activities, collect it only where it is necessary for that purpose, and use and disclose it consistently with the purpose of collection. The table above also describes those purposes for the benefit of New Zealand users.
6. AI Features & Automated Decision-Making
We do not make decisions about you by automated means alone
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, as described in Article 22 of the GDPR. We do not use AI or profiling to make decisions about credit, employment, insurance, education, or access to essential services.
6.1 AI suggestions are advisory. Gryphin's AI features — task breakdown, summarisation, drafting, and chat — produce suggestions. They do not act on your account, change your plan, remove your access, or take any step with a legal or similarly significant effect. A person always decides what to accept, edit, or ignore. AI output can be wrong or incomplete, so please check anything you rely on.
6.2 No profiling for advertising beyond your consent. We do not build behavioural profiles of you within the product. Where you have turned marketing cookies on, LinkedIn may use the information it receives for its own advertising profiling under its privacy policy — turning Marketing off on the Cookie Settings page stops that at source.
6.3 Security and abuse detection. We use automated rules — rate limiting, bot detection, and anomaly alerts — to protect the Services. These can temporarily block a request or flag an account for review. A person reviews the situation before we suspend or terminate an account, except where an immediate automated block is needed to stop an active attack. If an automated control has affected you, contact us at support@gryphin.app and a human will look at it.
6.4 If this changes. If we ever introduce processing that does amount to automated decision-making with legal or similarly significant effects, we will update this policy first and tell you about the logic involved, the significance, the likely consequences, and your right to obtain human intervention, express your point of view, and contest the decision.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. Some of these controls are ours and some are provided by the infrastructure we build on — we have set out which is which below.
Encryption
Our hosting and database providers (Vercel and Supabase) encrypt data at rest and in transit as part of their platforms, and state that they use AES-256 and modern TLS. These are their controls, not ours, and are subject to their documentation
Access Controls
Row-level security in the database, role-based access within workspaces, and optional multi-factor authentication on your account
Monitoring
Continuous error and access monitoring via Sentry, plus Cloudflare bot protection, with ongoing security reviews
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your password and devices safe.
Breach notification. If a privacy breach occurs that has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, as required by Part 6 of the Privacy Act 2020. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a reportable breach, and notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
We have not certified to ISO 27001 or SOC 2 at this stage. We will say so on this page if that changes.
8. Data Retention
We keep personal information only for as long as we need it for the purpose we collected it for, or for as long as the law requires. The periods below are the ones we apply to each category.
| Category of data | How long we keep it |
|---|---|
| Account profile (name, email, avatar) | For as long as your account is open, then deleted or anonymised within 30 days of account deletion |
| Customer content (boards, cards, comments, attachments) | For as long as the account or workspace exists, then deleted within 30 days. Content you contributed to a workspace owned by someone else stays with that workspace |
| Billing and tax records (invoices, transaction history) | Seven years from the end of the financial year to which they relate, to meet New Zealand tax record-keeping requirements. These survive account deletion |
| Payment card details | Never stored on our systems. Held by Stripe under Stripe’s own retention and PCI obligations |
| Security and access logs (including IP address) | Up to 90 days, unless a log is needed for an ongoing security or abuse investigation |
| Error and diagnostic data (Sentry) | Up to 90 days |
| Product analytics events (PostHog and other enabled analytics) | Up to 12 months from the event, then aggregated or deleted |
| Support correspondence | 24 months from our last exchange with you |
| Marketing and waitlist subscriptions | Until you unsubscribe. We then keep a minimal suppression record indefinitely so we do not email you again by mistake |
| Cookie consent record | Stored in your browser until you change your choices or clear your browser storage |
| Backups | Rolling backups are overwritten or expire within 30 days, so deleted data disappears from backups within that window |
Account deletion. You can delete your account from your account settings at any time. When you do, we delete or anonymise your personal data and customer content within 30 days, and it drops out of our backups within the same 30-day window as those backups expire. The only things we keep past that point are records we are legally required to hold — principally billing and tax records — and the minimal information needed to honour an unsubscribe request or resolve an open dispute.
Beta caveat. As noted at the top of this page, Gryphin is in beta and data may be reset or removed as the product changes. That is a separate matter from the retention periods above, which describe the maximum time we hold data, not a guarantee that we will hold it for that long.
9. International Data Transfers
Gryphin is operated from New Zealand, but several of our sub-processors are based in, or operate infrastructure in, other countries including the United States, the European Union, the United Kingdom, and Australia. By using the Services, you acknowledge that your personal information may be transferred to and processed in those jurisdictions.
9.1 New Zealand holds an EU adequacy decision
The European Commission has decided that New Zealand provides an adequate level of protection for personal data (Commission Implementing Decision 2013/65/EU of 19 December 2012), and New Zealand is also covered by the United Kingdom's adequacy regulations. This is helpful for you: personal data can be transferred from the EEA or the UK to us in New Zealand without needing Standard Contractual Clauses or any other additional transfer mechanism.
9.2 Onward transfers. Adequacy covers the transfer to us. Where we in turn send data to a sub-processor in a country without an adequacy decision — most commonly the United States — we rely on the appropriate safeguards those providers offer, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, certification under the EU–US Data Privacy Framework where the provider is certified, and the data processing terms in their contracts with us.
9.3 New Zealand rules. Under Information Privacy Principle 12 of the Privacy Act 2020, before disclosing personal information to an overseas recipient we satisfy ourselves that the recipient is subject to comparable safeguards, whether through binding contractual terms, privacy laws in their country that provide comparable protection, or a recognised certification.
9.4 EU / UK representative under Article 27
To be straightforward with you: Laika Dynamics Ltd has not yet appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR. We are currently assessing whether our processing brings us within the scope of Article 3(2) and therefore whether a representative is required. If one is required, we will appoint it and publish its name and contact details here. In the meantime, EU and UK users can reach us directly at privacy@gryphin.app, and you retain your right to complain to your local supervisory authority (see section 12).
We have not appointed a statutory Data Protection Officer. The Privacy Act 2020 requires us to have a privacy officer, and enquiries to privacy@gryphin.app reach them.
10. Children's Privacy
Gryphin is not directed to children under the age of 16, and we do not knowingly collect personal information from anyone under that age. If you believe a child has provided us with personal information, please contact us at privacy@gryphin.app and we will take steps to delete it.
11. Your Rights
Depending on your location, you may have the following rights:
Access
Request a copy of the personal data we hold about you
Correction
Request correction of inaccurate or incomplete data
Deletion
Delete your account yourself in account settings, or ask us to delete your personal information
Portability
Ask us for a copy of the data you gave us in a structured, commonly used, machine-readable format — we produce this manually on request, see 11.1
Restriction
Ask us to pause processing while a dispute about accuracy or legitimate interests is resolved
Objection
Object to processing based on our legitimate interests, and to direct marketing at any time
Withdraw Consent
Withdraw consent at any time where processing is based on consent, without affecting earlier processing
Complain
Lodge a complaint with a privacy regulator — see section 12
11.1 Getting a copy of your data
We want to be accurate about this rather than promise something we do not yet have. Gryphin does not currently offer a self-service export button. There is no "download my data" feature in the product today, and we are not going to pretend otherwise.
What we do instead: email privacy@gryphin.app from the address on your account and ask for an export. We compile it manually and send you your account data and your boards, cards, and comments in a structured, machine-readable format — JSON, or CSV if you prefer. There is no charge for a reasonable request.
How long it takes: we acknowledge your request within 5 working days and provide the export within the response times in section 11.2. If a request is unusually large or complex we may extend that period, and we will tell you why before the original deadline runs out.
Deletion, by contrast, is self-service and works today. You can delete your account from your account settings at any time, and section 8 sets out what happens next.
We are building a self-service export. When it ships we will update this section — until then, treat the manual process above as the way portability works.
11.2 How to ask, and how long we take
Email privacy@gryphin.app from the address on your account. We may ask you to verify your identity before we act, so that we do not hand your data to someone else. Different laws set different deadlines, and we apply whichever is shortest for you:
- New Zealand (Privacy Act 2020): within 20 working days of receiving your request, we will tell you our decision, and provide the information as soon as reasonably practicable afterwards.
- EU / UK (GDPR Arts. 12 and 15): within one month, extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month.
- California (CCPA/CPRA): within 45 calendar days, extendable once by a further 45 days with notice to you.
If we refuse a request, we will tell you why and explain how to complain (section 12).
If you are a member of someone else's workspace: for content inside that workspace we act as a processor (section 1.1), so we will normally refer your request to the workspace owner and help them respond.
12. Complaints
Please contact us first at privacy@gryphin.app — we would like the chance to put things right. But you do not have to come to us first, and you can complain to a regulator at any time.
New Zealand
You can complain to the Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu), PO Box 10094, Wellington 6143, New Zealand.
Phone 0800 803 909 · privacy.org.nz
European Union & United Kingdom
If you are in the EEA or the UK you may complain to the supervisory authority in the country where you live, where you work, or where you think the problem happened. In the UK that is the Information Commissioner's Office (ico.org.uk). A list of EEA authorities is published by the European Data Protection Board at edpb.europa.eu.
California residents can also contact the California Privacy Protection Agency or the California Attorney General. Wherever you are, you keep any right you have to take a matter to a court or tribunal.
13. California Privacy Rights (CCPA/CPRA)
This section applies to California residents and supplements the rest of this policy. It is our notice at collection under the California Consumer Privacy Act as amended by the California Privacy Rights Act. Terms such as "personal information," "sell," "share," and "service provider" have the meanings given in that Act.
13.1 Notice at collection
| Category collected | Examples | Business purpose | Retention |
|---|---|---|---|
| Identifiers | Name, email address, account ID, IP address, device identifiers | Providing and securing the Services, support, billing | Life of account + 30 days; logs up to 90 days |
| Customer records / commercial information | Billing address, subscription plan, transaction and invoice history | Taking payment, managing subscriptions, tax records | 7 years for tax and billing records |
| Internet or network activity | Pages viewed, features used, referring URLs, analytics events | Product analytics and improvement (consent-gated), security | Up to 12 months for analytics |
| Content you create | Boards, cards, comments, attachments, AI prompts | Providing the Services you asked for | Life of account or workspace + 30 days |
| Geolocation (approximate) | Coarse city or country inferred from IP address | Security, fraud prevention, tax determination | Up to 90 days in logs |
| Inferences | Feature preferences inferred from usage | Improving the product | Up to 12 months |
We do not collect biometric information, precise geolocation, government identifiers, or information about your health, and we do not knowingly collect personal information from anyone under 16. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit its use under the CPRA.
13.2 Sources and disclosures
Where it comes from
Directly from you when you sign up or use the Services; automatically from your device and browser; from our service providers (for example Stripe confirming a payment); and from integrations you choose to connect.
Who we disclose it to
The sub-processors listed in section 5.1, acting as service providers or contractors under written terms; other members of your workspace; and regulators or law enforcement where legally required. We disclose identifiers and internet activity information for these business purposes.
13.3 Do Not Sell or Share My Personal Information
We do not sell your personal information for money, and we have not done so in the preceding twelve months.
We do, however, need to flag one thing. If you turn on marketing cookies, our LinkedIn Insight pixel discloses information about your visit — such as your IP address, the page you viewed, and LinkedIn identifiers — to LinkedIn so it can measure our advertising and build advertising audiences. We take the view that this is likely to constitute "sharing" for cross-context behavioural advertising under the CPRA, and we are telling you so rather than relying on a narrow reading.
How to exercise your right to opt out:
- Go to our Cookie Settings page and make sure Marketing is switched off, or press "Essential only." This is our "Do Not Sell or Share My Personal Information" mechanism.
- Marketing is off by default. If you have never opted in, nothing is being shared and no further action is needed from you.
- You can also email privacy@gryphin.app with the subject "Do Not Sell or Share" and we will action it.
Note on Global Privacy Control: we have not yet implemented automatic recognition of GPC browser signals. Until we do, please use the Cookie Settings page. We will update this paragraph when GPC support ships.
13.4 Your California rights
- Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we disclosed it to.
- Delete personal information we have collected from you, subject to legal exceptions such as our tax record-keeping obligations.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information — see 13.3.
- Limit the use of sensitive personal information. We do not process sensitive personal information in a way that triggers this right, but you may still ask.
- Portability — receive the information in a portable format. See section 11.1 for how this works in practice.
- Non-discrimination — see 13.5.
To exercise any of these, email privacy@gryphin.app. We respond within 45 days, extendable once by a further 45 days with notice. We will verify your identity by confirming you control the email address on the account, and may ask for additional information for a request covering specific pieces of personal information.
13.5 Non-discrimination
We will not discriminate against you for exercising any of these rights. We will not deny you the Services, charge you a different price, give you a lower quality of service, or suggest that we might. We do not offer financial incentives in exchange for personal information.
13.6 Authorised agents
You can use an authorised agent to make a request on your behalf. The agent should email privacy@gryphin.app with written permission signed by you, or a power of attorney. Unless there is a power of attorney, we may also contact you directly to confirm you gave permission and to verify your identity.
Shine the Light. California Civil Code section 1798.83 lets California residents ask about personal information shared with third parties for their own direct marketing. We do not share personal information for that purpose.
14. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Laika Dynamics Ltd
114 Kennedy Road, Marewa
Napier 4110
New Zealand
Laika Dynamics Ltd is the controller and, for customer content, the processor described in section 1.1.
Get in Touch
privacy@gryphin.appPrivacy requests, data access and deletion, and complaints. Our privacy officer reads this inbox.
support@gryphin.appGeneral product support. For legal notices, use legal@gryphin.app.
We may update this Privacy Policy from time to time. We will post the updated version on this page and change the "Last updated" date. Where a change materially affects how we use your personal information, we will tell you by email or in-product before it takes effect.