Privacy Policy

Protecting your data with transparency and care.
Effective: February 1, 2026

About this Policy: This Privacy Policy describes how Grid Interface, LLC (“Grid Interface,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use the Grid Interface platform — including GridCom (AI-powered VoIP and AMS call intelligence), GridOrigin (insurance CRM with intake forms), GridIntel (AI chat and call analysis), and associated services (the “Services”). We use Google Gemini (primary AI processing), OpenAI (fallback AI processing), and Anthropic (additional AI option) as AI technology providers; and Stripe and Metronome (subscription billing) as payment technology providers. By using the Services, you agree to the practices described in this Privacy Policy.


This Privacy Policy applies to Customers (businesses and organizations subscribing to the Services) and their Authorized Users (employees, contractors, and individuals accessing the Services on the Customer’s behalf). It also applies to end users whose personal information — including call recordings, voice data, and contact information — is processed through the Services by Customers.

1. INFORMATION WE COLLECT

1.1 Information You Provide Directly

• Account Information: Name, email address, company name, phone

number, and billing address when you register.

• VoIP and AMS Configuration Data: API credentials, VoIP provider

settings, AMS connection configuration, and integration preferences submitted during onboarding and account setup.

• Call and Communication Data: Call recordings, transcripts, metadata

(call duration, timestamps, caller/callee numbers), and related communication content retrieved via your VoIP provider’s API.

• Payment Information: Subscription billing information (credit card

or ACH) collected through our third-party payment processor. We do not store full payment card numbers or bank account numbers.

• Communications: Messages, support requests, and feedback you send to

us.

1.2 Information Collected Automatically

• Usage Data: Log files, IP addresses, browser type, device

identifiers, pages visited, features used, session duration, and click patterns.

• Telemetry Data: API call patterns, feature usage metrics, error

logs, and performance data used to maintain and improve the Services.

• Cookies & Similar Technologies: Session cookies for authentication,

preference cookies, and analytics cookies. See Section 8 (Cookies).

1.3 Information Processed Through AI Features

• Call audio and transcription data submitted to Google Gemini

(primary) and OpenAI (fallback) for voice-to-text transcription; Anthropic models may also be used as an additional option;

• Transcribed call text submitted to Google Gemini (primary) and/or

OpenAI (fallback) for summarization, sentiment analysis, translation, call tagging, and vector embeddings (using Voyage AI embedding models); and

• Structured outputs (summaries, sentiment scores, action items)

pushed back to the Customer’s AMS via API.

AI Processing Notice: Call transcripts and related content — which may contain names, phone numbers, policy details, and other personal information — are transmitted to third-party AI providers via their API services. Grid Interface relies on each provider’s API data usage policies, under which API inputs and outputs are not used to train models by default. Customers are responsible for ensuring they have all required consents from call participants before submitting recordings to the Services. See Section 11 (TCPA and Recording Compliance).

1.4 Information from Third-Party Integrations

• VoIP Provider API: Call recordings, call metadata, and related

communication data retrieved via your VoIP provider’s API as authorized by your account configuration.

• AMS Integration: Data pushed to and pulled from your Agency

Management System (AMS) as part of the GridCom integration workflow, as configured by Customer.

2. HOW WE USE YOUR INFORMATION

We use personal information for the following purposes:


• To Provide the Services: Connect VoIP and AMS platforms, retrieve call recordings, process transcriptions, generate AI summaries and sentiment analyses, and push structured data to

Customer’s AMS.

• AI Features:

• Billing & Payments: Process subscription fees through our third-party payment processor.

• Account Management: Authenticate users, manage permissions,

configure integrations, and provide customer support.

• Platform Improvement: Use aggregated, de-identified Usage Data and

Derived Data to improve the Services and generate industry analytics. We do not use identifiable

Customer Data to train AI models without prior written Opt-In Consent.

• Legal Compliance: Comply with applicable laws (including TCPA,

CCPA/CPRA, California AI laws, and state recording notification requirements), respond to legal process, and enforce our terms.

• Communications: Send account notifications, security alerts, product

updates, and (with consent) marketing communications. SMS and text message communications are subject to Section 11.

Power call transcription, summarization, sentiment analysis, translation, call tagging, and vector embeddings via Google Gemini (primary), OpenAI (fallback), and Anthropic (additional option). AI inputs and outputs are transmitted via each provider’s API; providers’ default API terms do not use API data for model training.

3. HOW WE SHARE YOUR INFORMATION

We do not sell your personal information. We share information in the following circumstances:


• AI Subprocessors (LLM Providers):

• SMS Delivery Vendor: Twilio is used to deliver SMS/text message notifications to Customers and their Authorized Users; Twilio is subject to its own applicable API data processing terms.

• Payment Processor: Subscription payment information is shared with our third-party payment processor for billing. We do not store full payment credentials.

• AMS Integration: Processed outputs (summaries, sentiment data, structured call records) are pushed to your AMS via API as configured by Customer.

• Your Organization: Information may be shared among Authorized Users within your organization as controlled by your administrative settings.

• Legal Requirements: We may disclose information if required by law, court order, regulatory request, or to protect rights, safety, and property.

• Business Transfers: In connection with a merger, acquisition, or sale of assets, personal data may be transferred, subject to confidentiality protections.

• With Your Consent: In other circumstances with your explicit consent.

We share call data and related Customer Content with Google Gemini (primary), OpenAI (fallback), and Anthropic (additional option) as necessary to provide AI transcription, summarization, sentiment analysis, translation, call tagging, and vector embedding features. Voyage AI is used for embedding model services. Each provider is subject to applicable API data processing terms. CRM records and call transcripts may also be transmitted to AI providers through GridIntel AI chat features.

4. DATA RETENTION

We retain personal data only as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods are based on data sensitivity, legal requirements, and our contractual obligations to Customers.


4.1 Retention Schedule

Data Category

Retention Period

Basis / Purpose

Customer account & profile data

Duration of the Agreement, plus three (3) years thereafter

Contract / Legal Obligation

Call recordings (via VoIP API)

Two (2) years from the date of the call

Contract / Legitimate Interest

Call transcripts (via AI processing)

Two (2) years from the date of the call

Contract / Legitimate Interest

AI summaries & sentiment analyses

Two (2) years from the date of generation

Contract

AI-processed inputs to LLM APIs

Session-only; purged post-processing

Data Minimization

AMS-pushed data & integration logs

One (1) year

Contract / Legitimate Interest

Payment & billing records

7 years

Legal Obligation (tax/audit)

Usage logs & telemetry

Thirteen (13) months

Legitimate Interest

Security & access audit logs

Two (2) years

Legal Obligation / Security

Support communications

Three (3) years

Legitimate Interest

SMS / TCPA consent records

Duration of Customer relationship, plus four (4) years thereafter

Legal Obligation (TCPA)

Data breach records

Six (6) years

Legal Obligation

Aggregated / de-identified data

Indefinite (no personal data)

Legitimate Interest

4.2 Customer-Requested Deletion

Upon a Customer’s verified deletion request, we will delete or anonymize personal data within forty-five (45) calendar days, subject to legal hold obligations, regulatory requirements, active fraud investigations, or immutable disaster recovery backup schedules. Following subscription termination, Customer Data is available for manual return to Customer using commercially reasonable efforts, after which it is deleted per the schedule above.


If there is data we are unable to delete for technical reasons, we will implement appropriate measures to prevent further use. We may retain aggregated, de-identified data indefinitely for platform analytics and improvement purposes.

5. DATA SECURITY

We implement commercially reasonable technical and organizational security measures, including:

• Encryption in transit (TLS 1.2+) and at rest for stored Customer Data;

• Role-based access controls limiting data access to authorized personnel and Authorized Users only;

• Regular security assessments and vulnerability monitoring;

• Employee confidentiality obligations and need-to-know access restrictions for personnel with access to Customer Data; and

• Incident response procedures for security events affecting Customer Data.


No security measure is 100% effective. In the event of a data breach affecting personal information, we will notify affected individuals and applicable regulators as required by applicable law, and in any event within seventy-two (72) hours of confirming a breach as required under our Data Processing Agreement (see the Master Subscription Agreement).

6. THIRD-PARTY SERVICES

6.1 OpenAI

OpenAI serves as a fallback AI provider for transcription, summarization, and sentiment analysis features. Content submitted to OpenAI via API is processed under OpenAI’s API Data Usage Policies (platform.openai.com). OpenAI represents that it does not train its models on API inputs by default. Grid Interface is not responsible for OpenAI’s independent data practices.

6.2 Google Gemini (Primary AI Provider)

Google Gemini is Grid Interface’s primary AI provider for audio processing (using Google’s Files API), transcription, translation, sentiment analysis, summarization, vector embeddings, and call tagging. Content submitted to Gemini is processed under Google’s applicable enterprise terms (cloud.google.com/terms/gemini-enterprise/business). Grid Interface is not responsible for Google’s independent data practices.

6.3 Anthropic

Anthropic models are available as an additional AI processing option within the Services. Content submitted to Anthropic via API is processed under Anthropic’s applicable API usage policies (anthropic.com/legal/privacy). Anthropic does not use API inputs to train its models by default. Grid Interface is not responsible for Anthropic’s independent data practices.

6.4 Payment Processor

Subscription payments are processed by Stripe (stripe.com) and Metronome (metronome.com), which are linked together for subscription lifecycle and billing management. Stripe manages payment method collection and the customer billing portal for self-serve subscription management. Metronome manages subscription metering and billing infrastructure. Subscriptions are initiated via a Stripe-issued invoice; ongoing management is handled through the Stripe Customer Portal. We do not store full credit card numbers or ACH account credentials. Payment processing is governed by Stripe’s Privacy Policy (stripe.com/privacy) and Metronome’s privacy policy. Grid Interface is not responsible for the independent data practices of these payment providers.

6.5 VoIP and AMS Providers

The Grid Interface platform integrates with your chosen VoIP provider and AMS via API (GridCom module), and also collects PII directly through GridOrigin CRM intake forms (including customer contacts, addresses, and insurance opportunity data). GridIntel sends CRM records and verbatim call transcripts to AI providers for chat-based analysis. The Services also support Microsoft Teams meeting recording integrations and Calendar/To-Do integrations. All third-party platforms are operated independently and subject to their own privacy policies. Grid Interface is not responsible for data practices of your VoIP provider, AMS, or Microsoft integrations. Customers are responsible for ensuring all integrations comply with applicable laws, including recording notification requirements.

6.6 SMS Delivery Vendor

Grid Interface uses Twilio to deliver SMS and text message notifications to Customers and their Authorized Users. Content transmitted through Twilio is processed under Twilio’s applicable privacy policy and terms of service (twilio.com/legal/privacy). Grid Interface is not responsible for Twilio’s independent data practices. This is separate from, and does not include, any VoIP or SMS provider that Customer independently uses to communicate with its own end customers, which is addressed in Section 6.5.

7. YOUR PRIVACY RIGHTS

Depending on your jurisdiction, you may have the following rights regarding your personal information:

• Access: Request a copy of the personal information we hold aboutyou.

• Correction: Request correction of inaccurate personal information.

• Deletion: Request deletion of personal information, subject to legal retention obligations.

• Portability: Request your personal information in a portable format.

Data export functionality is currently in development; in the interim, portability requests may be fulfilled manually by contacting privacy@gridinterface.io.

• Opt-Out of Automated Decision-Making: Under California CPRA and applicable state laws, you may have the right to opt out of certain automated decision-making processes.

• Do Not Sell / Do Not Share: We do not sell personal information. California residents may submit a “Do Not Share” request for cross-context behavioral advertising purposes.


To exercise any rights, contact us at privacy@gridinterface.io. We will respond within forty-five (45) days as required by applicable law. We will not discriminate against you for exercising your privacy rights.

8. COOKIES & TRACKING TECHNOLOGIES

We use cookies and similar tracking technologies to maintain sessions, remember preferences, and analyze usage. You may control cookies through your browser settings. Disabling certain cookies may affect functionality. We do not currently respond to “Do Not Track” browser signals, though we honor opt-out rights under applicable state law.

9. AI MODEL PROCESSING

Grid Interface uses third-party AI models — including Google Gemini (primary: transcription, translation, summarization, sentiment analysis, call tagging, and vector embeddings via Voyage AI), OpenAI (fallback), and Anthropic (additional option) — to process call data and generate outputs within the Services.

9.1 What Is Transmitted to AI Providers

• Call audio is transmitted to Google Gemini (primary) for

voice-to-text transcription, using Google’s Files API for audio processing; OpenAI is used as a fallback;

• Transcribed call text is transmitted to OpenAI and/or Gemini for

summarization, sentiment scoring, and related outputs; and

• Call transcripts and CRM records transmitted via GridIntel may

contain names, phone numbers, policy details, and other personal information. Grid Interface relies on each provider’s API data usage policies, under which API inputs and outputs are not used to train models by default.

9.2 AI Training Restriction

Grid Interface will not use Customer Content, Inputs, or Customer-specific Outputs to train, fine-tune, or improve any AI or machine learning model without Customer’s prior written Opt-In Consent. Grid Interface may use aggregated, de-identified Usage Data and Derived Data for lawful platform improvement.

9.3 AI Output Limitations

• AI-generated transcripts, summaries, and sentiment scores may

contain inaccuracies, omissions, or errors;

• Outputs are intended to assist — not replace — human judgment. AI

outputs are informational only;

• Users are responsible for reviewing and independently verifying all

AI-generated content before relying on it for any business, legal, or compliance decision; and

• Grid Interface is not liable for decisions made based on

AI-generated outputs.

9.4 No Use in California Hiring Process

The Services cannot be used for the employee hiring process that occurs in the State of California. Customers are solely responsible for ensuring their deployment of AI Features complies with all applicable employment, anti-discrimination, and AI governance laws.

10. AI DISCLOSURES, DISCLAIMERS & GOVERNANCE

The Services use artificial intelligence technologies — including Google Gemini (primary), OpenAI (fallback), and Anthropic (additional option) — to transcribe call recordings, generate summaries, analyze CRM records, and measure consumer sentiment.


AI Systems Used in the Services:

• May produce inaccurate, incomplete, or misleading outputs;

• Rely on probabilistic models and may not reflect the most current or

accurate information;

• Should not be relied upon as professional legal, compliance, or

business advice; and

• Are intended to assist users — users remain responsible for all

decisions made based on AI-generated content.


10.1 Colorado Artificial Intelligence Act

The Colorado Artificial Intelligence Act establishes requirements for developers and deployers of high-risk AI systems used in consequential decision-making. Where applicable, Grid Interface implements reasonable governance practices, including risk management to identify and mitigate potential algorithmic bias, documentation of AI system intended uses and safeguards, consumer transparency informing users that the Services use AI and that outputs may contain inaccuracies, and human oversight ensuring AI outputs do not replace human review for consequential decisions.


10.2 California AI Transparency

Where required by applicable California law, Grid Interface discloses that the Services use artificial intelligence technologies, that users may interact with AI-generated content, and that AI outputs may not always be accurate or complete. Grid Interface does not use identifiable Customer Content to train AI models without Customer’s prior written consent.


10.3 New York AI Considerations

Grid Interface’s AI features are designed for business communication intelligence, not employment decisions. Customers are solely responsible for ensuring their use of AI Features in any employment context complies with NYC Local Law 144 and applicable New York State AI requirements, including required bias audits and disclosures.


10.4 Algorithmic Fairness

Grid Interface seeks to design AI systems consistent with widely recognized responsible AI principles including fairness, transparency, reliability, security, and human oversight. Customers are solely responsible for ensuring their deployment of AI Features complies with all applicable anti-discrimination, consumer protection, and AI governance laws.


10.5 AI Governance Framework

• Evaluation and monitoring of third-party AI providers (Google

Gemini, OpenAI, Anthropic) and their applicable terms, policies, and safety practices;

• Monitoring AI outputs for quality, accuracy, and potential misuse;

• Internal policies governing AI deployment, data handling, and

responsible AI use; and

• Annual review of AI governance practices to reflect changes in

applicable law and technology.

11. TCPA, SMS, AND CALL RECORDING COMPLIANCE

11.1 Call Recording Notice

GridCom processes call recordings retrieved via your VoIP provider’s API. Customers are solely responsible for:

• Complying with all federal and state laws governing the recording of

telephone conversations, including one-party and two-party (all-party) consent requirements applicable in the jurisdictions where calls occur;

• Providing all required notifications to call participants that calls

are being recorded before or at the time of recording; and

• Ensuring they have all rights, consents, and permissions necessary

to upload, submit, and process call recordings through the Services.

Grid Interface is not responsible for Customers’ failure to comply with applicable call recording laws.

11.2 TCPA and SMS Compliance

To the extent Customers use the Services to send text messages or make automated calls, Customers represent, warrant, and agree that:

• They will not send text messages or place automated calls without

first obtaining the recipient’s prior express written consent as required by the Telephone Consumer Protection Act (TCPA) and applicable state laws;

• They will provide clear disclosures of the messages to be received

and maintain opt-out mechanisms (STOP instructions) and help information (HELP instructions);

• They will comply with all applicable TCPA requirements, including

permitted calling times, do-not-call list registration, and required message content; and

• They maintain a privacy policy on their public-facing website that

includes a Text/SMS policy as required by applicable law.

Grid Interface is not responsible for Customers’ TCPA compliance. Customers indemnify Grid Interface for claims arising from their failure to comply. See the Master Subscription Agreement.

12. CHILDREN’S PRIVACY

The Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you become aware that a child has provided us personal information, contact us at privacy@gridinterface.io and we will delete it.

13. CALIFORNIA PRIVACY DISCLOSURES (CCPA/CPRA)

California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):


• Know: The right to know what personal information is collected, how it is used, and whether it is

disclosed or sold.

• Delete: The right to request deletion, subject to certain exceptions.

• Correct: The right to request correction of inaccurate personal information.

• Opt Out of Sale/Sharing: We do not sell personal information. We do not share personal

information for cross-context behavioral advertising.

• Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

• Limit Sensitive Personal Information: You may request that we limit use of sensitive personal

information to that necessary to provide the Services.


Categories of Personal Information Collected

• Identifiers: Name, email address, IP address, account username, phone number, and similar identifiers.

• Commercial Information: Subscription plan details, billing history, and transaction records.

• Professional / Business Information: Company name, job title, VoIP provider configuration, AMS configuration, and call management preferences.

• Communication Content: Call recordings, transcripts, AI summaries, sentiment analyses, and

AMS-integrated call data.

• Internet or Network Activity: Pages visited, features used, session duration, and usage logs.

• Inferences: Insights drawn from usage and call data to understand platform performance

and improve Services.


Categories of Third Parties with Whom We Share Personal Information

• OpenAI, L.L.C. (fallback AI transcription, summarization, and call

intelligence)

• Anthropic (additional AI processing option)

• Google LLC / Gemini (primary AI provider: transcription,

translation, summarization, sentiment analysis, call tagging, and vector embeddings via Google Files API)

• Stripe, Inc. (payment processing and customer billing portal) and

Metronome (subscription metering and billing infrastructure)

• Your AMS provider (structured output delivery via API integration)

• Twilio Inc. (SMS/text message delivery)

• Law enforcement or regulatory authorities when required by law

To exercise your California privacy rights, contact us at privacy@gridinterface.io. We will respond within forty-five (45) days of receiving a verifiable consumer request.

14. DO NOT TRACK SIGNALS

Grid Interface does not currently respond to browser “Do Not Track” (DNT) signals. Because there is no industry standard for recognizing DNT signals, we do not respond to them at this time. California residents may exercise their CCPA/CPRA opt-out rights as described in Section 13.

15. CLOUD INFRASTRUCTURE AND HOSTING

Grid Interface hosts the Services on cloud infrastructure in the United States. Customer data is stored and processed in secure cloud environments. We implement access controls, encryption in transit (TLS 1.2+), and encryption at rest as core infrastructure security safeguards. Our hosting providers may process data as part of hosting and system operations under their applicable data processing terms.

16. INDEPENDENT PLATFORM POLICIES

Third-party services integrated into Grid Interface — including Google Gemini, OpenAI, Anthropic, Stripe, Metronome, Voyage AI (embeddings), PostHog (analytics), Twilio (SMS delivery), and your VoIP and AMS providers — operate under their own independent privacy policies and terms of service. Grid Interface is not responsible for the independent privacy practices of these providers. We encourage you to review:


• OpenAI Privacy Policy: openai.com/policies/privacy-policy

• Google / Gemini: cloud.google.com/terms/gemini-enterprise/business

• Stripe Privacy Policy: stripe.com/privacy

• Metronome Privacy Policy: metronome.com/legal/privacy

• PostHog Privacy Policy: posthog.com/privacy (web analytics)

• Twilio Privacy Policy: twilio.com/legal/privacy (SMS delivery)

• Your VoIP provider’s, AMS provider’s, and Microsoft’s applicable

privacy policies

17. SUBPROCESSOR UPDATES

We may update our list of subprocessors from time to time. When we make material changes to our subprocessors that may affect how your personal information is processed, we will provide at least thirty (30) days’ advance written notice. Continued use of the Services following notice of a subprocessor update constitutes your acceptance of the updated subprocessor list. You may request our current subprocessor list at any time by contacting privacy@gridinterface.io.

18. INTERNATIONAL TRANSFERS

The Services are intended for use within the United States. Customer data is stored and processed on U.S.-based infrastructure. If you access the Services from outside the United States, you acknowledge that your information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Services, you consent to such transfer as described in this Privacy Policy.

19. AI AND AUTOMATED PROCESSING DISCLOSURE

Grid Interface uses automated systems, including AI, to transcribe call recordings, generate call summaries, and measure consumer sentiment.

• Final decisions are not made solely by AI without human review. AI

outputs are assistive tools designed to support — not replace — human judgment by Customers and their teams.

• Users retain full responsibility for reviewing, verifying, and

acting on any AI-generated content before it is used in any business, legal, or compliance context.

• Grid Interface does not use AI outputs to make legally determinative

decisions about individuals without independent human review.

20. ACCOUNT DELETION AND DATA DELETION REQUESTS

Customers and Authorized Users may request account deactivation and deletion of stored data by contacting support@gridinterface.io or privacy@gridinterface.io. Upon receiving a verified deletion request, we will:


• Deactivate the account and remove access to the Services;

• Delete or anonymize personal data stored within the Grid Interface platform, subject to the exceptions below; and

• Confirm completion of the deletion within thirty (30) days of the verified request.


Exceptions — Required Retention

We may retain certain data where necessary to:

• Comply with applicable legal obligations, including tax, record keeping, and TCPA consent record requirements;

• Resolve disputes or enforce our agreements;

• Maintain aggregated, de-identified data for platform analytics and improvement purposes; or

• Fulfill other legitimate business purposes as permitted by applicable law.

21. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify registered account administrators by email and post the updated policy at gridinterface.io/privacy-policy at least thirty (30) days before material changes take effect. Continued use of the Services after the effective date constitutes acceptance of the updated policy.

22. CONTACT US

If you have questions, requests, or concerns regarding this Privacy Policy or Grid Interface’s data practices, please contact us:


Grid Interface, LLC

42717 Hawthorn Street, Murrieta, CA 92562

• Privacy: privacy@gridinterface.io

• Support: support@gridinterface.io

• Website: www.gridinterface.io/privacy-policy


Effective Date: June 1, 2026



Grid Interface, LLC • GridCom | GridOrigin | GridIntel • Murrieta, CA

© 2026 Grid Interface, LLC. All Rights Reserved.