This Privacy Notice explains how Graphify handles personal information when you visit graaph.org, use app.graaph.org, create an account, connect a repository, or use our hosted APIs and MCP integrations.
1. Who is responsible
“Graphify,” “we,” “us,” and “our” mean the operator of the Graphify service. The legal operator and postal address will be identified on an applicable order form, invoice, or other written notice. For privacy questions or requests, contact support@graphify.net.
2. Information we collect
- Account and organization data: email address, authentication-provider identifiers, profile information made available by your sign-in provider, session records, organization membership, and administrator settings.
- Repository and workspace data: connection metadata, repository identifiers and permissions, content that you authorize Graphify to access, generated graphs and artifacts, build status, and operational logs.
- Billing data: plan, seats, billing interval, Stripe customer and transaction identifiers, payment status, invoices, and tax-related records. Stripe processes card details; Graphify does not store full card numbers or card security codes.
- Support and security data: messages you send us, IP and security signals, request times, error and audit logs, and information needed to prevent abuse or investigate incidents.
- Website analytics: limited page, CTA, content, language, device-type, and coarse referrer-host events. We do not send query strings, full URLs, raw referrers, source code, repository content, account credentials, API keys, or payment information in these marketing events.
3. How we use information
We use information to provide and secure the Service; authenticate users; connect and process authorized repositories; administer organizations and subscriptions; respond to support requests; prevent fraud and abuse; comply with legal obligations; and understand high-level product use. Where applicable, we rely on contract performance, legitimate interests in operating a secure service, consent, or legal obligations as the basis for processing.
4. Providers and disclosures
We share information only as reasonably necessary to run the Service. Providers may include:
- Cloudflare, for website delivery, security, and hosted application infrastructure;
- Stripe, for checkout, subscription management, payment processing, and billing records;
- Google, GitHub, and GitLab, when you choose them for sign-in or repository authorization;
- Mixpanel, for the limited product analytics described above; and
- AI-model and development-tool providers, when you configure or authorize an integration that sends information to them.
We may also disclose information when required by law, to protect people or the Service, or in connection with a genuine business transaction subject to continuing confidentiality protections. We do not sell personal information or use repository content for cross-context behavioral advertising.
5. Repository and AI processing
Repository access is initiated by you or an authorized organization administrator. Use least-privilege provider permissions and disconnect access you no longer need. Connected-provider tokens are handled as service credentials and should never be pasted into support messages or public locations.
Graphify may create graph relationships, summaries, and other AI-assisted outputs from authorized materials. If an integration sends data to an external AI provider, that provider’s terms, privacy practices, retention, and model-use policies also apply. Do not provide secrets, financial-account data, government identifiers, or other highly sensitive information unless your organization has evaluated the Service and relevant providers for that use.
6. Cookies and analytics
We use necessary browser storage for sessions, security, and core functionality. The public site also uses a browser-local anonymous visitor identifier for daily visit measurement and limited Mixpanel events. This visitor identifier is not an account identifier or fingerprint. The measurement script respects Do Not Track and Global Privacy Control signals; Mixpanel is configured without autocapture, session recording, automatic page views, IP collection, or marketing tracking.
You can manage browser storage through your browser settings. Blocking necessary storage can prevent sign-in or core features from working.
7. Retention and security
We retain information for as long as needed to provide the Service, maintain security, meet legal or accounting duties, resolve disputes, and enforce agreements. Repository content, artifacts, logs, and backups can have different operational retention periods; we do not state a fixed retention period where the service has not committed to one. A deletion request may not remove limited records that must be retained for law, security, payment, or dispute purposes.
We use measures designed to protect information, including HTTPS, access controls, restricted credentials, encrypted or hashed secrets where appropriate, and signed payment webhooks. No online service is completely secure.
8. Your choices and rights
Depending on where you live, you may have rights to request access to, correction, deletion, restriction, objection to, or portability of personal information, and to withdraw consent where processing depends on consent. Organization members should contact their organization administrator first for workspace data. You may also contact us at support@graphify.net; we may request proportionate verification before acting on a request.
9. Changes and contact
We will update the date on this page when this Notice changes. For material changes, we will provide notice through the Service or the email associated with your account when required by law. Questions, privacy requests, and reports of a suspected security issue can be sent to support@graphify.net.