Legal
Privacy Policy
Effective 30 September 2026
1. Scope and controller
Effective date: 3 October 2026. Grid Heap, Inc., a Delaware corporation, is responsible for the personal information described in this Policy. Our business address is 1111B S Governors Ave Ste 51059, Dover, DE 19904, United States. Contact us about privacy at legal@gridheap.com.
This Policy applies to https://embeddings.app and Embeddings services that link to it. We provide a prepaid embedding API, model catalogue, API playground and workspace-scoped document retrieval service. Cloudflare operates infrastructure and the initial managed model; configured direct model providers process the inputs selected for them. Self-service checkout is available only when configured; access and prepaid credit may also be issued after an agreed invoice. It explains what information we process, where it comes from, why it is used, who receives it, retention criteria and available rights. A separate notice or signed data-processing agreement governs processing expressly covered by that document.
“Personal information” includes information that identifies a person or can reasonably be associated with a person, subject to definitions and exemptions in applicable law. The U.S. state and European sections below provide additional information where those laws apply. This Policy does not make every regional law applicable to every interaction.
2. Personal information we collect
- Device and request information: IP address, browser and user-agent information, requested URL, request time and basic delivery or security events processed when your browser requests a page or asset.
- Communications: your name or email if provided, the content of an enquiry, and correspondence needed to respond to support, legal or security requests. Avoid sending passwords, payment security codes or unnecessary sensitive information.
- Service inputs: API input text is sent to the selected configured provider to generate vectors. Successful vectors and input digests are persistently cached for reuse; raw embedding request text is not included in the usage ledger. Uploaded document text is stored privately in Cloudflare R2, and chunk text, vectors and source metadata are stored in Cloudflare Vectorize under a workspace namespace. API key digests, workspace name, balance, payment reference, byte counts and operational status are retained for account, metering and security purposes. Keys entered in the playground remain in tab memory and are sent only to the API. Stripe, when configured, processes hosted checkout; we receive payment status and references, not full card details.
- Website scope: ordinary reading of this website does not require an account, checkout, form submission or model request. Public model and benchmark information is content about the listed products and sources. A separate linked service may collect information under its own notice; this Policy does not claim that those services process no personal information.
We do not request government identification, health information, biometric identifiers, precise device location or other sensitive information for ordinary website browsing. Free-form communications or content you submit may contain personal or sensitive information; submit only what is necessary and what you are authorized to provide. We do not use such information to infer sensitive characteristics about you.
3. Sources of personal information
We receive information directly from you when you contact us. Your browser and our delivery providers process request information automatically when delivering pages and assets. The site does not obtain visitor profiles from data brokers or require an external account.
We may receive information from another person who is authorized to submit it, from a professional adviser or authority handling a legal matter, or in connection with a permitted transfer of the relevant business. We do not buy advertising profiles to identify website visitors.
4. How we use personal information
- Service delivery: deliver pages and assets, provide the requested feature, maintain authorized records and respond to instructions.
- Support: respond to enquiries, correct errors, investigate a reported problem and process requests for assistance or privacy rights.
- Security and integrity: prevent unauthorized access, fraud and abuse, investigate incidents and enforce applicable agreements.
- Legal and accounting requirements: comply with lawful requests, maintain required records and establish, exercise or defend legal claims.
- Operation and improvement: diagnose delivery and service problems and understand aggregate usage or performance without building advertising profiles.
We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising. We do not operate third-party advertising, visitor session-replay or cross-site analytics on this website. We do not send marketing email merely because you browsed, made a purchase or asked for support. Service and transaction messages may still be sent where needed.
5. Cookies and similar technologies
The website does not set its own advertising or analytics cookies. Delivery and security providers may process request information or use necessary security technologies. Adobe Fonts requests transmit connection metadata to Adobe. Your browser may cache delivered pages and assets. These delivery activities still involve processing even where no visitor account or tracking profile is created.
If you follow a link to a third-party website, sign in there or complete an external checkout, that destination may set its own cookies and process information under its own notice. Blocking necessary storage or requests may prevent a feature from working. We do not treat use of the website as consent to unrelated advertising technologies.
6. How we disclose personal information
- Infrastructure and delivery providers: hosting, database, storage, network-security and email providers receive information needed to deliver pages, operate the service, store authorized records or send requested communications. Cloudflare is used for website delivery and infrastructure; other infrastructure is used where a product feature requires it.
- Adobe Fonts: your browser requests the configured font stylesheet and font files from Adobe. Adobe receives connection information, including IP address and browser request metadata. These requests support typography rather than advertising. Adobe’s own privacy notice applies to its processing.
We may also disclose relevant information to professional advisers, law enforcement or other authorities when reasonably necessary to comply with law, protect rights or safety, investigate fraud, or establish or defend a claim. We assess the request and disclose only information appropriate to the purpose.
Information may be disclosed to a prospective or completed business transferee and advisers in a merger, financing, acquisition, reorganization, sale or insolvency involving the relevant business, subject to appropriate confidentiality and applicable law. We may disclose information to a recipient you expressly designate or authorize. These purposes do not authorize advertising sales of your personal information.
7. Retention
We retain personal information only for the period reasonably necessary for the purpose for which it was collected, including service delivery, security, accounting, legal obligations and resolution of disputes. We consider the nature and sensitivity of the information, the active service or account relationship, applicable retention requirements, outstanding claims and whether the purpose can be met with less information.
Request and security records may be retained by infrastructure providers according to the operational requirements applicable to their services. Correspondence may be kept to respond to an enquiry and document its resolution. Cached vectors remain available while their model contract is supported; private documents, indexed chunks and workspace records remain while the account is active or required for an agreed service. Request deletion or account closure at legal@gridheap.com; we remove applicable documents, indexes and cached entries after verifying authority, subject to necessary accounting, security and legal retention. Shared cache entries may require isolation or invalidation when fulfilling a deletion request.
When information is no longer needed, it is deleted, anonymized or isolated from further use pending deletion, subject to lawful exceptions. Backup copies are removed under their applicable lifecycle and are not used for ordinary active processing. Contact us to ask about retention for a particular category or exercise a deletion right.
8. Your choices
You can decline to provide information, but a feature that needs it may not work. You may contact legal@gridheap.com to request access, correction, deletion or other rights described below.
Browser settings can remove or reject cookies and local storage and limit third-party requests. Blocking essential authentication or security technologies may prevent sign-in or a transaction. Do Not Track signals do not change the service’s essential processing; we do not use the website for cross-site behavioural tracking.
We do not conduct sale, sharing for cross-context behavioural advertising, or targeted advertising that requires an advertising opt-out. Where an opt-out preference signal such as Global Privacy Control applies, we respect the applicable legal right; the signal does not prevent essential delivery, security or an operation you request. If you receive an optional marketing message from us, use its unsubscribe control or contact us; necessary service messages may continue.
9. U.S. state privacy rights
This section applies where a U.S. state privacy law governs our processing of your information. Subject to that law’s conditions, exemptions and limitations, you may have rights to confirm processing; obtain information about categories, sources, purposes and recipients; access a copy; correct inaccuracies; delete information; obtain a portable copy; opt out of sale, sharing, targeted advertising or certain profiling; and limit specified uses of sensitive information.
For notice-at-collection purposes, the categories we collect, purposes and recipient categories are stated in sections 2–6; retention criteria are in section 7. Categories may include identifiers and contact data, internet or network request data, account information where offered, commercial or transaction information where relevant, and content voluntarily submitted for a service or enquiry. We do not sell or share these categories for cross-context behavioural advertising. We do not use sensitive information to infer characteristics or perform profiling that produces legal or similarly significant effects on you.
Submit a request to legal@gridheap.com or by mail to our business address. Identify the right you wish to exercise and enough information to locate the relevant records. We may verify identity using information already associated with the request or account and ask for additional information proportionate to the risk. Do not send government identification unless we specifically request it through an appropriate method. An authorized agent may submit a request with evidence of authority; we may also seek your confirmation where law permits.
We respond within the period required by the law that applies. If we deny a request, we explain the reason subject to legal restrictions and, where the law provides an appeal, how to appeal. You may appeal by writing to the same legal address and identifying the request and why you believe the decision should change. We will provide the appeal result and any applicable route to complain to the relevant state authority. We do not unlawfully discriminate against you for exercising privacy rights.
California residents may also make a “Shine the Light” enquiry about applicable disclosures for third-party direct marketing at legal@gridheap.com. We do not disclose personal information for another company’s own direct marketing. Nevada residents may direct an applicable sale opt-out request to the same address, although we do not sell information for monetary consideration.
10. Notice to European users
Grid Heap, Inc. is the controller for the website, account, transaction and operational personal data described here where the GDPR or UK GDPR applies. Where we process customer-controlled data under a separate processor agreement, that agreement and the customer’s notices govern that processing. Contact the controller at legal@gridheap.com or the business address above.
Legal bases. Processing needed to provide a requested service or take steps at your request before a contract relies on performance of a contract. Delivery, security, abuse prevention, administration and proportionate service improvement rely on legitimate interests where those interests are not overridden by your rights. Accounting and lawful disclosure obligations rely on legal obligation. Processing that requires consent relies on the specific consent requested for it; you may withdraw that consent without affecting prior lawful processing.
Rights. Subject to legal conditions, you may request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interests. You may withdraw consent at any time where consent is the basis. You may object to direct marketing. We do not use personal data to make solely automated decisions about you with legal or similarly significant effects.
To exercise a right, contact legal@gridheap.com. We may request proportionate information to verify identity and identify records, and will respond within the applicable legal period. If we cannot comply, we explain the legal grounds and available remedies. You may complain to the supervisory authority in your habitual residence, place of work or alleged infringement. EEA authority contacts are listed by the European Data Protection Board; UK users may contact the Information Commissioner’s Office.
11. International data transfers
Company is based in the United States. Infrastructure providers and the third parties involved in a selected service may process information in the United States or other countries. A model, connected tool or merchant may be located in a different country from you. These countries may have different privacy laws.
Where a transfer is subject to GDPR, UK GDPR or another transfer restriction, it must use a mechanism permitted by the applicable law, such as an applicable adequacy decision, approved contractual safeguards, or a legally available exception. The mechanism depends on the recipient and transfer.
Contact legal@gridheap.com for information about the safeguards applicable to a particular transfer and, where required by law, a copy or description of them, subject to appropriate redaction. Choosing an external service should take its location and processing requirements into account.
12. Security
We use technical and organizational safeguards appropriate to the information processed, including encrypted transport and access controls for private records and credentials. You should protect your own devices and credentials and configure connected services and application permissions carefully. No internet service can guarantee complete security.
Report a suspected vulnerability, unauthorized account access or disclosure through security@gridheap.com. Do not send usable credentials, card security codes or unnecessary personal information in the initial report. Privacy rights requests should be sent to legal@gridheap.com.
13. Children
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect children’s information contrary to applicable law. If you believe a child has supplied personal information, contact legal@gridheap.com with enough information to identify the relevant interaction. We will investigate and take deletion or other measures required by applicable law.
14. Changes and contact
We may update this Policy as practices or legal requirements change. The effective date identifies the version. A material change will be notified through a prominent notice on the Service or another appropriate method, such as the account email where available. Any consent newly required by law will be requested separately.
Grid Heap, Inc., a Delaware corporation
Business address: 1111B S Governors Ave Ste 51059, Dover, DE 19904, United States
Privacy, data-subject requests and legal matters: legal@gridheap.com
Product support: support@gridheap.com