Grej — Privacy Policy

Early Access · Effective 29 July 2026

This Privacy Policy explains how we handle your personal data when you use the Grej application and services (the "Service"). It forms part of, and should be read together with, our Terms of Use.

1. Who we are (Controller)

Humeko Oy, business ID 2081131-0 (VAT FI20811310), Matbackantie 8, 04130 Sipoo, Finland, which operates the Grej service, is the data controller for the personal data processed through the Service. Contact: privacy@grej.app.

2. What data we process

  • Account & identity: email, authentication identifiers (Google/Apple sign-in), account settings.
  • Asset data (Digital Twins): the products you register and their details (brand, model, serial, purchase, warranty, location if you provide it), hierarchy and status.
  • Uploaded content: photos, videos and documents you upload (e.g. manuals, receipts, warranties), and information derived from them by AI (extracted fields, document sections/chunks). We keep your files as you provide them, including any metadata they carry (for example a photo's date, camera details, or GPS location). This metadata stays private to your account, is never shared with other users, and is included when you export or delete your data.
  • AI usage & metering: records of AI operations (type, model, tokens, cost) used to enforce the Daily AI Limit and understand cost — kept at the account level.
  • Device & technical data: app version, platform, and operational logs necessary for security, abuse prevention and running the Service.

During Early Access we do not run a separate product-analytics or user-tracking system: we do not use a third-party analytics SDK, and we do not place an analytics identifier on your device.

During Early Access the Service is free and we do not process payment data. If paid plans are introduced, payments will be handled by a payment provider and this policy will be updated first.

3. Purposes and legal bases (GDPR Art. 6)

Purpose Data Legal basis
Provide the Service (Digital Twins, AI assistant, storage) Account, asset, uploaded content Contract (Art. 6(1)(b))
AI processing of your uploads to deliver features to you Uploaded content, derived data Contract (Art. 6(1)(b))
Metering and enforcing the Daily AI Limit AI usage Contract; legitimate interest (Art. 6(1)(f))
Security, abuse prevention and running the Service Technical, operational logs Legitimate interest (Art. 6(1)(f))
Contribution to cross-owner/fleet intelligence De-identified signals Explicit, revocable consent (Art. 6(1)(a))
Optional service communications Contact Consent

4. How AI processes your content

To provide AI features, your uploaded content and asset data are processed by our AI sub-processor (Google — Gemini/Vertex AI). Key points:

  • Your uploaded documents and everything derived from them (extracted fields, document chunks) are scoped to your account and are never shared with other, unrelated users.
  • We do not use your content to train general-purpose/foundation AI models.
  • Google processes this content on Vertex AI. Depending on model availability and capacity, this processing may take place outside the EU/EEA. Google acts as our processor under the Cloud Data Processing Addendum, which incorporates the EU Standard Contractual Clauses; those clauses are the safeguard we rely on for any processing outside the EU/EEA. Your uploaded files and asset data remain stored in the EU (see §12) — it is the model call itself that may be served elsewhere.

5. Sub-processors

We use sub-processors to run the Service, including: Google Cloud (hosting; region europe-north1, EU) and Google Gemini/Vertex AI (AI processing). Our full, current sub-processor list is published at grej.app/subprocessors. Hosting and storage take place within the EU/EEA; where a sub-processor processes data outside the EU/EEA — this can include AI processing, and also push-notification delivery and transactional email — we rely on EU Standard Contractual Clauses.

6. Sharing your data

We share your data only: with the household members and collaborators you designate; with sub-processors under contract (§5); and where required by law. We do not sell your personal data, and we do not use it for behavioural advertising.

7. Retention

We retain personal data for as long as your account is active and as needed to provide the Service. AI inputs are read by the model provider (Vertex AI) directly from our EU storage at request time and processed only transiently to generate a response; the durable copy remains your own upload in our EU storage, and Google does not use these inputs to train its models.

On account deletion we immediately and permanently delete your content: your items, documents, photos, timeline, onboarding sessions, device tokens and account record.

We retain operational records of the requests your account made and the AI processing it consumed — technical metadata such as the model used, tokens, cost, timestamps, routes and response codes. These contain none of your content. We keep them to detect and investigate abuse, fraud and security incidents, and as our own financial records, on the basis of our legitimate interests (Art. 6(1)(f) — see §4). They are keyed to a random account identifier, never to your name or email.

These operational records remain linkable to you only for as long as a database backup containing your account still exists — at most 30 days after deletion. We never use backups to re-identify deleted accounts, and if a backup is ever restored we re-apply deletions made after it was taken. After that window the records are anonymous, and we may keep them indefinitely.

Security logs are retained for up to 180 days. They contain no name or email address.

8. Your rights

Subject to applicable law, you may: access your data; correct it; delete it; obtain a portable copy; restrict or object to certain processing; and withdraw consent at any time (including for fleet contribution). To exercise these rights, use the in-app data controls or contact privacy@grej.app. You may also lodge a complaint with your supervisory authority — in Finland the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), and in Sweden the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).

9. Fleet / community-intelligence contribution

Contribution of de-identified lifecycle signals to any cross-owner intelligence layer is off by default and requires your explicit consent, which you can withdraw at any time. These signals are de-identified by construction and do not include your identity or your copyrighted materials.

10. Children

Our launch markets are Sweden and Finland, where the age of digital consent is 13. The Service is not directed at children under 13, and you must be at least 13 to create an account. For users aged 13–17, a parent or guardian should be involved (see the Terms of Use). We give children's personal data specific protection: we apply data minimisation and privacy by default, we do not profile users or use personal data for behavioural advertising, and we keep this policy in plain language. Within a Family workspace, accounts for younger members are managed by the adult account Owner.

11. Security

We apply technical and organisational measures appropriate to the risk (GDPR Art. 32), including encryption in transit, access controls, tenant isolation, and the principle that uploads and derived data stay scoped to their owner.

12. Data location

Primary hosting and storage are in the EU (europe-north1): your account data, uploaded files, and everything derived from them are stored in the EU and do not leave it.

AI processing is different. When an AI feature runs, the relevant content is sent to Google's Vertex AI to be processed by a model. That model call may be served from a Google region outside the EU/EEA, depending on where the model we use is available and has capacity. Google processes it on our instructions as our processor, does not use it to train general-purpose models, and does not retain it for its own purposes; transfers outside the EU/EEA are covered by the EU Standard Contractual Clauses incorporated into the Cloud Data Processing Addendum.

13. Changes and contact

We will update this policy as needed and notify you of material changes. Questions: privacy@grej.app.


Privacy Policy — Early Access · Version 2026-07-29 · Humeko Oy.