Legal

Privacy Policy

Your privacy matters to us. Here's how we protect it.

Last updated: July 2026

Privacy at a Glance

  • • We collect only what's necessary to provide our services
  • • We do not sell your personal data. Our LinkedIn advertising pixel may count as "sharing" under California law, and it is off unless you turn it on
  • • You can delete your account at any time, and ask us for a copy of your data — see section 11
  • • Analytics and advertising trackers stay off until you opt in on our Cookie Settings page
  • • Our hosting and database providers encrypt data at rest and in transit

Beta Services Notice

Gryphin is currently offered as a beta service. While we protect your data with the same safeguards described in this policy, please be aware that during the beta period:

  • Features, data models, and integrations may change, be reset, or be removed without notice.
  • We may contact you for product feedback, usability studies, or beta-related announcements.
  • Usage telemetry is collected more actively to help us identify bugs and improve the product.
  • We recommend keeping your own backups of critical content until the service reaches general availability.

1. Introduction & Who We Are

Gryphin is a product of Laika Dynamics Ltd ("Gryphin," "we," "us," or "our"), a company registered in New Zealand with its registered office at 114 Kennedy Road, Marewa, Napier 4110, New Zealand. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website at gryphin.app, our applications, and our services (collectively, the "Services").

We handle personal information in accordance with the Privacy Act 2020 (New Zealand). Where the UK and EU General Data Protection Regulation applies to you, we also comply with it, and where the California Consumer Privacy Act as amended by the CPRA applies, section 13 sets out your additional rights.

1.1 Are we a controller or a processor?

This distinction matters because it decides who is responsible for your data and who you should ask to exercise your rights. Both roles apply to us, depending on the data:

We are the controller

For account data, authentication data, billing and subscription data, support correspondence, product analytics, marketing data, and security and diagnostic logs. We decide why and how that information is processed, and this policy governs it.

We are a processor

For the customer content you and your team put into boards, cards, comments, and attachments — including any personal information about third parties you choose to put there. Your organisation is the controller of that content and decides what goes in it. We only process it on your instructions to run the Services.

If you are a member of a workspace you do not own and you want content removed from that workspace, ask the workspace owner first. If they do not respond, contact us at privacy@gryphin.app and we will help.

Please read this Privacy Policy carefully. By using our Services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

We collect information you provide directly to us, including:

Account Information

Name, email address, password, and profile picture

Payment Information

Billing address and payment method, tokenised and processed by Stripe. We never see or store your full card number

Content

Boards, cards, comments, attachments, and other content you create

Communications

Messages you send to us or other users

Waitlist & Beta Signups

Email address and any optional details you submit to join the waitlist or beta programme

Integration Data

Information you authorise us to access through connected services (e.g. Google Calendar, Google Drive)

2.2 Information Collected Automatically

When you use our Services, we automatically collect:

Device Information

Browser type, operating system, device identifiers

Usage Data

Pages visited, features used, time spent on the Services

Log Data

IP address, access times, referring URLs

Cookies

Small files stored on your device (see Cookie Policy). Non-essential cookies are off until you opt in

Push Tokens

Device push notification tokens if you install our mobile app and opt in to notifications

Product Analytics

Event data captured via PostHog. Because we identify signed-in users, this data is pseudonymous — it is linked to your account identifier and remains personal information. It is not anonymised

Analytics and advertising technologies only run if you have consented. See our Cookie Policy for a full inventory of what is set, by whom, and for how long.

2.3 AI-Powered Features

Some Gryphin features (such as task breakdown, summarisation, and AI chat) are powered by third-party large language model providers, including OpenAI and OpenRouter.

When you use these features, the content of your prompts — which may include card titles, descriptions, comments, or other information you choose to submit — is transmitted to those providers solely to generate a response.

We select providers whose API terms prohibit using your content to train their models. We do not send your data to AI providers unless you actively use an AI feature.

Please do not enter sensitive personal information — such as health, financial, or biometric details about identifiable people — into AI prompts.

3. How We Use Your Information

We use the information we collect to do the things below. Section 4 sets out the legal basis for each of them.

🛠️Provide, maintain, and improve our Services
💳Process transactions and send related information
📧Send technical notices, updates, and support messages
💬Respond to your comments, questions, and requests
📊Monitor and analyse trends, usage, and activities (with your consent)
🔒Detect, investigate, and prevent security incidents and abuse
Personalise and improve your experience
📢Send promotional communications (with your consent)
⚖️Meet our legal, tax, and accounting obligations

5. Information Sharing

We may share your information in the following circumstances:

With Your Consent

When you explicitly authorise us to share your information with third parties, including advertising partners.

Team Members

With other members of your workspace who need access to collaborate.

Service Providers

With the sub-processors listed below, who help us operate the Services under contract and may only use your data on our instructions.

Legal Requirements

When required by law or to protect our rights, privacy, safety, or property. Where we are legally permitted to do so, we will tell you before responding to a request for your data.

Business Transfers

In connection with a merger, acquisition, or sale of all or part of our assets. We will notify you before your data becomes subject to a different privacy policy.

🚫 We do not sell your personal information for money, and we never sell or licence your boards, cards, or other customer content. One caveat, stated plainly: if you turn on marketing cookies, our LinkedIn advertising pixel discloses information about your visit to LinkedIn for advertising purposes. Under California law that is likely to count as "sharing" for cross-context behavioural advertising. See section 13 for how to opt out — or simply leave Marketing switched off on the Cookie Settings page, which is the default.

5.1 Sub-Processors

We use the following third parties to operate the Services. Items marked "when enabled" are optional tools configured per environment and may not be active on the site you are using.

Vercel

Application hosting, edge delivery, and web analytics

Processing location: United States / global edge

Supabase

Database, authentication, file storage, and real-time services

Processing location: United States

Cloudflare

CDN, bot protection, Turnstile challenges, and DDoS mitigation

Processing location: Global edge network

Stripe

Payment processing and subscription management

Processing location: United States / Ireland

Resend

Transactional email delivery

Processing location: United States

Sentry

Error monitoring and performance tracking

Processing location: United States

PostHog

Product analytics and feature usage insights (consent required)

Processing location: United States

OpenAI

AI model provider for certain AI-powered features

Processing location: United States

OpenRouter

AI model routing for task breakdown, chat, and suggestions

Processing location: United States

LinkedIn

LinkedIn Insight advertising pixel — measures ad performance and builds advertising audiences (marketing consent required)

Processing location: United States / Ireland

Google Analytics 4

Website traffic analysis, when enabled (consent required)

Processing location: United States

Plausible

Cookieless page-view analytics, when enabled (consent required)

Processing location: European Union

Amplitude

Product analytics, when enabled (consent required)

Processing location: United States

Google (Workspace APIs)

Optional Calendar and Drive integrations (only when you connect them)

Processing location: United States

We will update this list when we add or replace a sub-processor. If you are a business customer and want advance notice of changes, email privacy@gryphin.app and we will add you to the notification list.

6. AI Features & Automated Decision-Making

We do not make decisions about you by automated means alone

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, as described in Article 22 of the GDPR. We do not use AI or profiling to make decisions about credit, employment, insurance, education, or access to essential services.

6.1 AI suggestions are advisory. Gryphin's AI features — task breakdown, summarisation, drafting, and chat — produce suggestions. They do not act on your account, change your plan, remove your access, or take any step with a legal or similarly significant effect. A person always decides what to accept, edit, or ignore. AI output can be wrong or incomplete, so please check anything you rely on.

6.2 No profiling for advertising beyond your consent. We do not build behavioural profiles of you within the product. Where you have turned marketing cookies on, LinkedIn may use the information it receives for its own advertising profiling under its privacy policy — turning Marketing off on the Cookie Settings page stops that at source.

6.3 Security and abuse detection. We use automated rules — rate limiting, bot detection, and anomaly alerts — to protect the Services. These can temporarily block a request or flag an account for review. A person reviews the situation before we suspend or terminate an account, except where an immediate automated block is needed to stop an active attack. If an automated control has affected you, contact us at support@gryphin.app and a human will look at it.

6.4 If this changes. If we ever introduce processing that does amount to automated decision-making with legal or similarly significant effects, we will update this policy first and tell you about the logic involved, the significance, the likely consequences, and your right to obtain human intervention, express your point of view, and contest the decision.

7. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. Some of these controls are ours and some are provided by the infrastructure we build on — we have set out which is which below.

🔐

Encryption

Our hosting and database providers (Vercel and Supabase) encrypt data at rest and in transit as part of their platforms, and state that they use AES-256 and modern TLS. These are their controls, not ours, and are subject to their documentation

🛡️

Access Controls

Row-level security in the database, role-based access within workspaces, and optional multi-factor authentication on your account

🔍

Monitoring

Continuous error and access monitoring via Sentry, plus Cloudflare bot protection, with ongoing security reviews

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your password and devices safe.

Breach notification. If a privacy breach occurs that has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, as required by Part 6 of the Privacy Act 2020. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a reportable breach, and notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.

We have not certified to ISO 27001 or SOC 2 at this stage. We will say so on this page if that changes.

8. Data Retention

We keep personal information only for as long as we need it for the purpose we collected it for, or for as long as the law requires. The periods below are the ones we apply to each category.

Category of dataHow long we keep it
Account profile (name, email, avatar)For as long as your account is open, then deleted or anonymised within 30 days of account deletion
Customer content (boards, cards, comments, attachments)For as long as the account or workspace exists, then deleted within 30 days. Content you contributed to a workspace owned by someone else stays with that workspace
Billing and tax records (invoices, transaction history)Seven years from the end of the financial year to which they relate, to meet New Zealand tax record-keeping requirements. These survive account deletion
Payment card detailsNever stored on our systems. Held by Stripe under Stripe’s own retention and PCI obligations
Security and access logs (including IP address)Up to 90 days, unless a log is needed for an ongoing security or abuse investigation
Error and diagnostic data (Sentry)Up to 90 days
Product analytics events (PostHog and other enabled analytics)Up to 12 months from the event, then aggregated or deleted
Support correspondence24 months from our last exchange with you
Marketing and waitlist subscriptionsUntil you unsubscribe. We then keep a minimal suppression record indefinitely so we do not email you again by mistake
Cookie consent recordStored in your browser until you change your choices or clear your browser storage
BackupsRolling backups are overwritten or expire within 30 days, so deleted data disappears from backups within that window

Account deletion. You can delete your account from your account settings at any time. When you do, we delete or anonymise your personal data and customer content within 30 days, and it drops out of our backups within the same 30-day window as those backups expire. The only things we keep past that point are records we are legally required to hold — principally billing and tax records — and the minimal information needed to honour an unsubscribe request or resolve an open dispute.

Beta caveat. As noted at the top of this page, Gryphin is in beta and data may be reset or removed as the product changes. That is a separate matter from the retention periods above, which describe the maximum time we hold data, not a guarantee that we will hold it for that long.

9. International Data Transfers

Gryphin is operated from New Zealand, but several of our sub-processors are based in, or operate infrastructure in, other countries including the United States, the European Union, the United Kingdom, and Australia. By using the Services, you acknowledge that your personal information may be transferred to and processed in those jurisdictions.

9.1 New Zealand holds an EU adequacy decision

The European Commission has decided that New Zealand provides an adequate level of protection for personal data (Commission Implementing Decision 2013/65/EU of 19 December 2012), and New Zealand is also covered by the United Kingdom's adequacy regulations. This is helpful for you: personal data can be transferred from the EEA or the UK to us in New Zealand without needing Standard Contractual Clauses or any other additional transfer mechanism.

9.2 Onward transfers. Adequacy covers the transfer to us. Where we in turn send data to a sub-processor in a country without an adequacy decision — most commonly the United States — we rely on the appropriate safeguards those providers offer, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, certification under the EU–US Data Privacy Framework where the provider is certified, and the data processing terms in their contracts with us.

9.3 New Zealand rules. Under Information Privacy Principle 12 of the Privacy Act 2020, before disclosing personal information to an overseas recipient we satisfy ourselves that the recipient is subject to comparable safeguards, whether through binding contractual terms, privacy laws in their country that provide comparable protection, or a recognised certification.

9.4 EU / UK representative under Article 27

To be straightforward with you: Laika Dynamics Ltd has not yet appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR. We are currently assessing whether our processing brings us within the scope of Article 3(2) and therefore whether a representative is required. If one is required, we will appoint it and publish its name and contact details here. In the meantime, EU and UK users can reach us directly at privacy@gryphin.app, and you retain your right to complain to your local supervisory authority (see section 12).

We have not appointed a statutory Data Protection Officer. The Privacy Act 2020 requires us to have a privacy officer, and enquiries to privacy@gryphin.app reach them.

10. Children's Privacy

Gryphin is not directed to children under the age of 16, and we do not knowingly collect personal information from anyone under that age. If you believe a child has provided us with personal information, please contact us at privacy@gryphin.app and we will take steps to delete it.

11. Your Rights

Depending on your location, you may have the following rights:

Access

Request a copy of the personal data we hold about you

Correction

Request correction of inaccurate or incomplete data

Deletion

Delete your account yourself in account settings, or ask us to delete your personal information

Portability

Ask us for a copy of the data you gave us in a structured, commonly used, machine-readable format — we produce this manually on request, see 11.1

Restriction

Ask us to pause processing while a dispute about accuracy or legitimate interests is resolved

Objection

Object to processing based on our legitimate interests, and to direct marketing at any time

Withdraw Consent

Withdraw consent at any time where processing is based on consent, without affecting earlier processing

Complain

Lodge a complaint with a privacy regulator — see section 12

11.1 Getting a copy of your data

We want to be accurate about this rather than promise something we do not yet have. Gryphin does not currently offer a self-service export button. There is no "download my data" feature in the product today, and we are not going to pretend otherwise.

What we do instead: email privacy@gryphin.app from the address on your account and ask for an export. We compile it manually and send you your account data and your boards, cards, and comments in a structured, machine-readable format — JSON, or CSV if you prefer. There is no charge for a reasonable request.

How long it takes: we acknowledge your request within 5 working days and provide the export within the response times in section 11.2. If a request is unusually large or complex we may extend that period, and we will tell you why before the original deadline runs out.

Deletion, by contrast, is self-service and works today. You can delete your account from your account settings at any time, and section 8 sets out what happens next.

We are building a self-service export. When it ships we will update this section — until then, treat the manual process above as the way portability works.

11.2 How to ask, and how long we take

Email privacy@gryphin.app from the address on your account. We may ask you to verify your identity before we act, so that we do not hand your data to someone else. Different laws set different deadlines, and we apply whichever is shortest for you:

  • New Zealand (Privacy Act 2020): within 20 working days of receiving your request, we will tell you our decision, and provide the information as soon as reasonably practicable afterwards.
  • EU / UK (GDPR Arts. 12 and 15): within one month, extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month.
  • California (CCPA/CPRA): within 45 calendar days, extendable once by a further 45 days with notice to you.

If we refuse a request, we will tell you why and explain how to complain (section 12).

If you are a member of someone else's workspace: for content inside that workspace we act as a processor (section 1.1), so we will normally refer your request to the workspace owner and help them respond.

12. Complaints

Please contact us first at privacy@gryphin.app — we would like the chance to put things right. But you do not have to come to us first, and you can complain to a regulator at any time.

New Zealand

You can complain to the Office of the Privacy Commissioner (Te Mana Mātāpono Matatapu), PO Box 10094, Wellington 6143, New Zealand.

Phone 0800 803 909 · privacy.org.nz

European Union & United Kingdom

If you are in the EEA or the UK you may complain to the supervisory authority in the country where you live, where you work, or where you think the problem happened. In the UK that is the Information Commissioner's Office (ico.org.uk). A list of EEA authorities is published by the European Data Protection Board at edpb.europa.eu.

California residents can also contact the California Privacy Protection Agency or the California Attorney General. Wherever you are, you keep any right you have to take a matter to a court or tribunal.

13. California Privacy Rights (CCPA/CPRA)

This section applies to California residents and supplements the rest of this policy. It is our notice at collection under the California Consumer Privacy Act as amended by the California Privacy Rights Act. Terms such as "personal information," "sell," "share," and "service provider" have the meanings given in that Act.

13.1 Notice at collection

Category collectedExamplesBusiness purposeRetention
IdentifiersName, email address, account ID, IP address, device identifiersProviding and securing the Services, support, billingLife of account + 30 days; logs up to 90 days
Customer records / commercial informationBilling address, subscription plan, transaction and invoice historyTaking payment, managing subscriptions, tax records7 years for tax and billing records
Internet or network activityPages viewed, features used, referring URLs, analytics eventsProduct analytics and improvement (consent-gated), securityUp to 12 months for analytics
Content you createBoards, cards, comments, attachments, AI promptsProviding the Services you asked forLife of account or workspace + 30 days
Geolocation (approximate)Coarse city or country inferred from IP addressSecurity, fraud prevention, tax determinationUp to 90 days in logs
InferencesFeature preferences inferred from usageImproving the productUp to 12 months

We do not collect biometric information, precise geolocation, government identifiers, or information about your health, and we do not knowingly collect personal information from anyone under 16. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit its use under the CPRA.

13.2 Sources and disclosures

Where it comes from

Directly from you when you sign up or use the Services; automatically from your device and browser; from our service providers (for example Stripe confirming a payment); and from integrations you choose to connect.

Who we disclose it to

The sub-processors listed in section 5.1, acting as service providers or contractors under written terms; other members of your workspace; and regulators or law enforcement where legally required. We disclose identifiers and internet activity information for these business purposes.

13.3 Do Not Sell or Share My Personal Information

We do not sell your personal information for money, and we have not done so in the preceding twelve months.

We do, however, need to flag one thing. If you turn on marketing cookies, our LinkedIn Insight pixel discloses information about your visit — such as your IP address, the page you viewed, and LinkedIn identifiers — to LinkedIn so it can measure our advertising and build advertising audiences. We take the view that this is likely to constitute "sharing" for cross-context behavioural advertising under the CPRA, and we are telling you so rather than relying on a narrow reading.

How to exercise your right to opt out:

  • Go to our Cookie Settings page and make sure Marketing is switched off, or press "Essential only." This is our "Do Not Sell or Share My Personal Information" mechanism.
  • Marketing is off by default. If you have never opted in, nothing is being shared and no further action is needed from you.
  • You can also email privacy@gryphin.app with the subject "Do Not Sell or Share" and we will action it.

Note on Global Privacy Control: we have not yet implemented automatic recognition of GPC browser signals. Until we do, please use the Cookie Settings page. We will update this paragraph when GPC support ships.

13.4 Your California rights

  • Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we disclosed it to.
  • Delete personal information we have collected from you, subject to legal exceptions such as our tax record-keeping obligations.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information — see 13.3.
  • Limit the use of sensitive personal information. We do not process sensitive personal information in a way that triggers this right, but you may still ask.
  • Portability — receive the information in a portable format. See section 11.1 for how this works in practice.
  • Non-discrimination — see 13.5.

To exercise any of these, email privacy@gryphin.app. We respond within 45 days, extendable once by a further 45 days with notice. We will verify your identity by confirming you control the email address on the account, and may ask for additional information for a request covering specific pieces of personal information.

13.5 Non-discrimination

We will not discriminate against you for exercising any of these rights. We will not deny you the Services, charge you a different price, give you a lower quality of service, or suggest that we might. We do not offer financial incentives in exchange for personal information.

13.6 Authorised agents

You can use an authorised agent to make a request on your behalf. The agent should email privacy@gryphin.app with written permission signed by you, or a power of attorney. Unless there is a power of attorney, we may also contact you directly to confirm you gave permission and to verify your identity.

Shine the Light. California Civil Code section 1798.83 lets California residents ask about personal information shared with third parties for their own direct marketing. We do not share personal information for that purpose.

14. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Laika Dynamics Ltd

114 Kennedy Road, Marewa

Napier 4110

New Zealand

Laika Dynamics Ltd is the controller and, for customer content, the processor described in section 1.1.

Get in Touch

privacy@gryphin.app

Privacy requests, data access and deletion, and complaints. Our privacy officer reads this inbox.

support@gryphin.app

General product support. For legal notices, use legal@gryphin.app.

We may update this Privacy Policy from time to time. We will post the updated version on this page and change the "Last updated" date. Where a change materially affects how we use your personal information, we will tell you by email or in-product before it takes effect.