Privacy
Privacy Policy
Grounded is designed for source-grounded work with tenant-scoped documents. This policy explains what the product needs to process and what should never be treated casually.
Data We Process
Grounded processes account details, tenant information, uploaded document content, questions, generated answers, citations, security events, and operational logs needed to run the service.
How Data Is Used
Data is used to authenticate users, isolate tenant workspaces, index documents, answer questions with citations, operate the platform, investigate abuse, and improve reliability.
Tenant Isolation
Documents and retrieval requests are scoped to the active tenant. Cross-tenant access is not an accepted product behavior and must be treated as a security defect.
Security
Authentication cookies are httpOnly and required for product access. Sensitive tokens are not exposed to browser JavaScript in the production-oriented web flow.
Retention
Retention periods depend on deployment policy. Self-hosted operators are responsible for configuring backups, logs, object storage, and database retention.