Your data, plainly.
What Grape keeps, what it never does, and how to delete it.
- Your files stay yours, and we never send them to an AI provider.
- No ads, no tracking, no selling or sharing your data.
- Passwords and sessions are stored as hashes.
- Delete your account and everything goes at once.
What we keep
- Your email, an Argon2 hash of your password, and your first and last name if you add them.
- The files you upload, the text we read from them, and their search index. For a GitHub repository, the text of each file and its search index; we delete the clone and its git history.
- A fingerprint (SHA-256) of each sign-in session, never the session itself.
- Your API key, so the app can show your MCP URL at any time. Only you can see it, after you sign in.
- Search counts and timings for your Usage page, and an audit log of sign-ins and changes, with the time and IP address.
What we do not do
- No ads, no tracking scripts, no analytics cookies, and we do not sell or share your data.
- We do not send your files to any AI provider. Audio is turned into text on our own server.
- When you connect Claude, ChatGPT or another app through MCP, that app sees the passages it searches for you, under its own terms.
Where it lives
- On a server we run, reached only over HTTPS. Your browser keeps your sign-in token in local storage until you sign out.
Deleting
- Settings, Delete account removes your account, projects, files, indexes, API key and audit log at once. Backups age out within 7 days.
- Deleting a file or project removes it and its index at once.
Questions or a deletion request? Write to grape.retrieval@gmail.com. Last updated 30 September 2026.