Effective July 25, 2026
Privacy Policy
This policy explains how GrebCo collects, uses, shares, retains, and handles personal information when you visit or use GrebKey.
1. Who operates GrebKey
GrebCo, a business registered in Seattle, Washington, United States, operates GrebKey and is responsible for the practices described in this policy. Contact support@greb.co with a privacy request or question.
2. Information GrebKey handles
The information GrebKey handles depends on how you use the site, dashboard, API, and SDKs.
- GitHub sign-in data: GitHub user ID, username, name, and an account email address. During sign-in, GitHub may return profile and verified email information so GrebKey can select the account email.
- Account and licensing data: account identifiers, plan, product names, license keys, labels, status, license metadata, activation limits, expiry dates, API key hashes and prefixes, and usage totals.
- Machine activation data: a machine fingerprint supplied by the SDK or API caller, an optional device label, the IP address observed when a machine is activated, activation time, and last-validation time.
- Billing data: Stripe customer and subscription identifiers, plan status, checkout and paid-account milestones, and related billing state. GrebCo does not receive or store full payment-card numbers.
- Acquisition attribution: a random journey identifier, page and signup event names, campaign source, medium and campaign values, referrer hostname, and event time. This attribution record does not store email, GitHub identity, raw IP address, or user agent.
- Request and diagnostic data: Cloudflare and GrebKey process network information such as IP address, request headers, route, response status, and timing to deliver, protect, rate-limit, and troubleshoot the service. A short-lived hashed request bucket is used to rate-limit public acquisition events.
- Support communications: information you include when you email or otherwise contact GrebCo.
3. Why GrebCo uses information
GrebCo uses information to:
- authenticate users and operate accounts;
- create and validate license keys, manage machine activations, and enforce plan limits;
- process subscriptions, reconcile billing status, and maintain transaction and compliance records;
- secure, rate-limit, monitor, debug, and improve GrebKey;
- measure which campaigns and onboarding steps lead to account activation or a paid subscription;
- respond to support, download, correction, and deletion requests; and
- comply with law, enforce agreements, and protect GrebCo, users, and the public.
5. Retention
Privacy-minimized acquisition event records are automatically deleted after 90 days. OAuth state normally expires after 10 minutes, one-time callback codes after 5 minutes, and dashboard sessions after 7 days.
GrebCo retains account, licensing, activation, usage, billing, and support information for as long as reasonably needed to operate and secure GrebKey, provide the service, maintain compliance and transaction records, resolve disputes, and enforce agreements.
After a deletion request, GrebCo may retain limited records when required for legal, tax, accounting, fraud-prevention, security, or compliance purposes.
6. Your choices and requests
Any user may email support@greb.co to request a download of their GrebKey account data, correct account information, or request deletion of their account and personal information. GrebCo may need to verify the request before acting on it.
A deletion request does not automatically cancel an active Stripe subscription. Cancel the subscription through the GrebKey billing controls or ask GrebCo for help. Some information may be retained for the limited reasons described in the Retention section.
You can limit campaign attribution stored in your browser by clearing site storage. You can also stop using GrebKey, revoke GrebKey's access in GitHub, or deactivate individual machine activations from the dashboard.
7. Security
GrebCo uses administrative, technical, and organizational measures intended to protect information. No system or transmission method is completely secure, so GrebCo cannot guarantee absolute security. Keep GitHub, API, and license-key credentials confidential and contact GrebCo if you suspect unauthorized access.
8. International use
GrebCo and its service providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws from your location.
9. Changes to this policy
GrebCo may update this policy as GrebKey or applicable requirements change. The effective date at the top will be updated. For a material change, GrebCo will provide reasonable notice through the service or an account contact method when practical.
10. Contact
For privacy questions, data downloads, corrections, or deletion requests, email support@greb.co. GrebCo is registered in Seattle, Washington, United States. No postal contact address is currently available.
Questions or requests
Email support@greb.co.