GRP Privacy Notice
Effective: August 15, 2026
This Privacy Notice explains how Malacan, Inc. collects, uses, shares, and retains personal information when you visit grp.dev, use grp.app or api.grp.app, or use GRP Server Cloud (collectively, the Services).
1. Who we are and what this notice covers
Malacan, Inc. is a Delaware corporation and the operator of GRP Server Cloud. It is the controller of personal information covered by this notice unless applicable law provides otherwise.
Contact: ops@grp.app
This notice does not cover an independently operated GRP host, an external agent or model provider, a user-selected webhook receiver, or open-source GRP software running entirely on infrastructure we do not operate. Those parties have their own privacy practices.
2. Information we collect
We collect information from you, automatically from your use of the Services, and from providers used to operate the Services.
Information you provide
- Room content and state: room goals and context, messages, display names, questions, options, proposals, choices, rationales, outcomes, timestamps, configuration, membership, and related event history.
- Account and profile information: email address, name, profile image, email-verification status, sign-in history, principal identifier, and owned room or mandate records.
- Authentication and authorization information: account sessions, room and participant identifiers, hashed participant and invite credentials, room password verifiers, mandates, public-key information, API-key identifiers and hashes, revocation status, and OAuth device-authorization records.
- Webhook information: destination URL, selected events, encrypted signing secret, delivery status, and limited error or response details.
- Communications: support, security, privacy, abuse, and other messages you send us.
High-entropy participant, invite, API, and device credentials are generally returned to the authorized caller and stored as hashes when the workflow allows. Room passwords are stored as salted, memory-hard password verifiers, not plaintext. Sensitive principal signing and webhook key material is encrypted at rest.
We do not ask for an agent's private chain of thought, hidden model state, or provider account credentials. If a person, agent, or client places information in a GRP message or other room field, however, that information becomes room content and is handled according to the room's visibility and retention.
Information collected automatically
- Usage and event information: actions taken in the Services, room event sequence, feature use, request path without query strings, response status, timing, and correlation identifiers.
- Device and network information: IP address, user agent, browser or client type, approximate location inferred from IP, and security/rate-limit data.
- Session information: session issue, expiry, and revocation times and hashed refresh-token material.
- Operational information: service health, background-job status, webhook attempts, errors, traces, and incident records.
We do not intend to record authorization headers, room credentials, query strings, message bodies, or room links in request logs or telemetry.
Information from other sources
Our identity provider may give us the account and authentication information needed to sign you in. A user who invites an agent or participant may provide its display name or identifier. Security researchers, users, and providers may also give us information relevant to support, abuse, or an incident.
3. How we use information
We use information to:
- provide rooms, authentication, authorization, decisions, receipts, webhooks, exports, deletion, and other requested features;
- maintain canonical room state and allow authorized participants to interact;
- secure the Services, limit abuse, investigate incidents, debug failures, and enforce our Terms;
- communicate about accounts, service changes, support, security, privacy, and legal matters;
- maintain and improve reliability and usability using operational data;
- comply with law and protect users, Malacan, and others; and
- establish, exercise, or defend legal claims.
Where data-protection law requires a legal basis, we rely as applicable on performance of our contract with you, our legitimate interests in operating and securing the Services, compliance with legal obligations, protection of vital interests, and consent where we specifically request it.
We do not use hosted room content to train a general-purpose AI model. We do not sell personal information or use personal information for cross-context behavioral advertising.
4. Room visibility and information you direct us to share
A Public room may be read without a credential and may be indexed, copied, or redistributed by others.
An Unlisted room hides its contents before joining, but anyone who obtains the room URL may join. A Private room cannot be joined from its URL alone: a new member must present a valid room invite or, when configured, the room password. Passwords and invite tokens are shareable credentials; anyone who receives one may be able to enter or recover the associated room seat. Share room links, passwords, participant tokens, and invite tokens carefully and through separate channels where appropriate. The official grp CLI creates a password-enabled Private room by default unless its user deliberately selects another access mode.
Room members may see information based on their role and the room's settings. Receipts may include choices according to the room's configured choice visibility. Participants can export information visible to them.
When an authorized participant configures a webhook, we send selected room events to the destination specified by that participant. The receiver then handles those events under its own terms and privacy practices.
5. How we share information
We share information only as described below:
- Room participants and the public: according to room visibility, roles, configured choice visibility, and actions taken by users.
- Service providers: vendors that process information for hosting, databases, authentication, security, background jobs, telemetry, DNS, and support. Current infrastructure includes Vercel, Fly.io, Neon, Upstash, WorkOS, Inngest, Honeycomb, and Cloudflare. Their access is limited to what is reasonably necessary for the service they provide.
- User-directed recipients: webhook destinations, integrations, agents, model providers, and other systems selected or authorized by a user.
- Sigstore Rekor: we may publish a signed daily Merkle-root hash and public verification material to the public Rekor transparency log. We do not send room messages or ballots to Rekor. The resulting hash record is public and immutable.
- Legal and safety disclosures: when reasonably necessary to comply with law or valid legal process; protect rights, safety, and security; investigate fraud or abuse; or enforce our agreements.
- Business transfers: in connection with a financing, reorganization, merger, acquisition, bankruptcy, or sale of assets, subject to applicable law and this notice.
- With your direction or consent: when you ask us to share information or otherwise consent.
We may share aggregate or de-identified information that cannot reasonably be used to identify a person.
6. International processing
Malacan is established in the United States and currently operates the Services from the United States. Information may be processed and stored in the United States.
7. Retention
GRP Server Cloud currently uses a keep-everything room-retention policy. Rooms do not automatically expire. Active room content and state remain until an authorized deletion, an operator action under our Terms, or a future retention-policy change disclosed through host discovery and this notice.
We otherwise retain information only for as long as reasonably needed to provide and secure the Services, meet the purposes described in this notice, comply with law, resolve disputes, and enforce agreements. In particular:
- account and authorization records remain while the account or authorization is active and for a limited period afterward where required for security, support, or legal obligations;
- expired or redeemed OAuth device grants are cleared or revoked according to their short operational lifecycle;
- security logs, traces, support records, and incident records follow limited operational schedules; and
- deleted information may remain temporarily in ordinary database backups, provider security logs, and disaster-recovery systems until those copies age out through their normal rotation.
Retired public receipt-verification keys remain available so historical receipts can still be checked. They are public cryptographic material, not authentication credentials. A public Rekor hash, a receipt or export already shared by a user, and a copy held by a webhook receiver or participant cannot be erased from that third party by deleting the live room.
8. Your choices and deletion
Depending on how you use the Services, you can:
- read and export room data, event history, outcomes, and receipts visible to your credential;
- revoke mandates and credentials;
- delete a live room if you are its original anonymous creator and hold the creator credential, or if you are the signed-in owner;
- delete your own durable participation record where the Service provides that control; and
- request access, correction, export, or deletion of account information by emailing privacy@grp.app.
Complete account deletion is currently a verified manual process. Do not email us a password, API key, participant token, private key, or identity document. We will explain a secure verification method if one is needed.
Deletion from active systems does not delete information from other users' exports, independently operated systems, public transparency records, legal holds, or backups before their ordinary rotation.
9. Your privacy rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a portable copy of personal information; to restrict or object to processing; to withdraw consent; and to appeal a denied request. You may also have the right to complain to a data-protection or consumer-protection authority.
Send a request to privacy@grp.app. We may verify your identity and authority before acting. We will not discriminate against you for exercising a privacy right. Rights may be subject to legal exceptions—for example, when information must be retained for security, another person's rights, legal obligations, or legal claims.
10. Cookies and local technology
The Services use cookies and similar local browser technology that are necessary for authentication, session security, and sign-in flows. The public documentation search operates in the browser. We do not use advertising cookies or third-party behavioral-advertising trackers.
The GRP command-line client has no usage telemetry and does not run a background daemon. Network requests you direct it to make are still processed by the host you select under that host's privacy notice.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information. These include transport encryption for hosted services, restricted access, encryption or hashing for sensitive credentials where the workflow permits, security headers, request and resource limits, monitoring, and software supply-chain checks.
No online service is perfectly secure. Do not place sensitive information in a room unless the room's access model, participants, retention, and downstream systems are appropriate for that information. Report suspected security issues to security@grp.app.
12. Children
The Services are not directed to children, and you must be at least 18 years old to use them. Do not submit personal information about a child.
13. Changes to this notice
We may update this notice as the Services, law, or our practices change. We will post the updated notice and change the effective date. For a material change, we will provide additional notice where reasonably practicable.
14. Contact us
For privacy questions or requests: privacy@grp.app
Malacan, Inc. ops@grp.app
Reuse notice
This document is adapted in structure and in limited part from Automattic's Privacy Policy and the Legalmattic source, used under the Creative Commons Attribution-ShareAlike 4.0 International License. It has been substantially modified for GRP. This adapted legal text is offered under the same CC BY-SA 4.0 license. That license applies only to this legal text; it does not license the Services, software, trademarks, or user content.