POLICIES & PREFERENCES
Privacy Policy
On this page
- Effective date: August 12, 2026
- Last updated: September 23, 2026
- Applies to: grindlabs.ca, lagrind.ca, the Grind Labs web and progressive web applications, packaged mobile applications, CBSE Grind and other Grind Labs or La Grind products, and related digital services that link to this Policy (collectively, the “Service”).
Key facts
- Grind Labs Inc. is accountable for personal information under its control. The Privacy Officer is reachable at hello@grindlabs.ca.
- We collect account, profile, study, communication, file, AI, purchase, device, security, and usage information as needed for the features you use.
- Some information stays on your device; some is synchronized or stored in private server storage; some is shown to users you choose; and selected AI inputs go to our AI provider.
- Our main service providers are Supabase, Cloudflare, Resend, Stripe, Apple, Google, Anthropic, and ipwho.is. Their roles are explained below.
- We do not sell or rent personal information, disclose it to data brokers, or use it for cross-context behavioural advertising.
- You may have rights to access, correct, delete, or port information, withdraw consent, object or restrict processing, and complain to a regulator. The rights that apply depend on where you live.
- Security reduces risk but cannot eliminate it. Contact us promptly if you suspect unauthorized account access or a privacy incident.
This summary highlights important points. The complete Policy below explains the details.
1. Who is responsible
Grind Labs Inc., a Canadian corporation based in Quebec, Canada, is responsible for personal information under its control. Grind Labs is our English-facing brand, La Grind is our French-facing brand, and CBSE Grind is one of our study products.
Our Privacy Officer oversees this Policy and privacy requests. Contact:
- Email: hello@grindlabs.ca
- Subject line recommended: Privacy request
The Privacy Officer may verify identity and authority before disclosing or changing account information. This contact route also accepts privacy complaints and questions about our service providers or practices.
2. Scope and key facts
This Policy covers information handled through Service accounts, websites, progressive web and packaged applications, study tools, purchases, community and collaboration features, calls, AI tools, digital coaching surfaces, support, and security operations. It does not govern a third-party site or service that has its own policy, even when linked from the Service.
We collect, use, retain, and disclose personal information for identified purposes, with consent or another lawful basis where applicable. We aim to limit information to what is reasonably needed for those purposes, but the exact information depends on the features, account role, purchase, device, settings, and interactions you choose.
We do not sell or rent personal information, disclose it to data brokers, or use personal information for cross-context behavioural advertising. We do not run third-party advertising trackers. We may use aggregate or de-identified information that does not reasonably identify a person for research, quality measurement, security, reporting, and Service improvement.
3. Information we collect
We may collect the following categories.
| Category | Examples |
|---|---|
| Account and authentication | Email address; account identifier; password hash maintained by the authentication provider; Google or Apple sign-in identifier if chosen, and the name and email address Apple shares when you first sign in with Apple (which may be an Apple private relay address); multifactor enrolment and verification state; recovery, session, consent, and authentication records. |
| Profile, school, role, and cohort | Display name, username, avatar, language, school, discipline, graduation or cohort information, role, staff assignment, directory settings, entitlement, membership, and profile fields. |
| Study and product activity | Answers, scores, timing, confidence, notes, documents, decks, cards, question sets, calendar items, calendar subscription links you add and the events our relay retrieves from them, bookmarks, progress, grades, goals, settings, activity history, feature use, and analytics events. |
| Community and collaboration | Posts, comments, direct and group messages, friends and requests, shared study items, group membership, presence, blocks, reports, moderation status, rosters, permissions, edit history, and collaboration events. |
| Support and applications | Support correspondence, forms, feedback, applications, survey responses, complaints, attachments, troubleshooting information, and actions taken. |
| AI interactions | AI prompts, instructions, selected Service context, extracted text, selected page images, generated output, model and feature identifiers, token or usage records, GrindStone quote, debit, restoration, and technical-result information. |
| Files and user material | Files that stay on the device and files sent to private server storage for an enabled feature, including user books, study documents, class rosters, Casper takes, voice notes and other recordings you make, profile photos, and other user files; metadata such as title, type, size, owner, audience, and timestamps. |
| Calls | Participant and thread identifiers, call type, status, timestamps, connection and end-reason metadata, signaling needed to establish a call, and technical relay information. Microphone and camera media is transmitted during the call but the Calling feature does not record it; the application does not retain SDP/ICE signaling after the call flow. |
| Purchases and entitlements | Product, plan, subscription, renewal state, GrindStone grant or debit, currency, amount, tax and limited billing metadata, processor/customer identifiers, receipt or transaction identifier, payment status, entitlement, refund, dispute, and restoration records. Grind Labs does not receive full card numbers from Stripe or Apple. |
| Device, network, security, and diagnostics | IP address, user agent, device or installation identifier, operating system, browser, app version, coarse sign-in location such as city/region/country, timestamps, route and request information, error and performance information, security events, and fraud or abuse signals. |
Some information may be sensitive because of its content or context. Do not submit patient records, health information about an identifiable person, government identifiers, financial-account credentials, biometric identifiers, exam-confidential content, or other highly sensitive material unless a feature expressly requests it and you have lawful authority and informed consent.
4. Where information comes from
We collect information:
- from you, when you create an account, complete a profile, study, upload, post, message, call, buy, apply, ask for support, change settings, or use an AI feature;
- from your device and Service activity, through local storage, application events, network requests, security logs, analytics, diagnostics, and feature operation;
- from another user or organization, such as when a cohort president or authorized school representative adds an email to a roster, a user sends you a message or friend request, a collaborator shares an item, or someone submits a report involving your content;
- from service providers, including identity, payment, app-store, delivery, infrastructure, AI, and approximate-location providers; and
- from lawful public or institutional sources, only where needed for verification, safety, fraud prevention, rights enforcement, or legal compliance.
When we receive information from another user, they are responsible for having authority to provide it. We may notify, verify, restrict, or delete that information as appropriate.
5. Why we use information and our legal bases
We use personal information for these purposes:
- create, authenticate, secure, recover, and administer accounts;
- provide, synchronize, personalize, and remember study tools and settings;
- deliver purchases, subscriptions, entitlements, receipts, GrindStones, and restorations;
- operate profiles, directories, cohorts, rosters, sharing, messaging, collaboration, community, moderation, and calls;
- process user-directed files, Google Drive actions, and AI generation;
- send transactional, security, account, support, purchase, and service messages;
- answer requests, troubleshoot, moderate, enforce terms, and protect users;
- detect, prevent, and investigate fraud, cheating, infringement, spam, abuse, security incidents, and unlawful activity;
- measure feature use, reliability, learning flows, and content quality and improve the Service;
- comply with tax, accounting, consumer, privacy, court, regulatory, and other legal obligations; and
- establish, exercise, or defend legal rights and support a corporate transaction subject to safeguards.
The lawful basis depends on the activity and jurisdiction. It may include your consent; performance of a contract or steps you request before a contract; compliance with law; protection of vital interests in an emergency; and our or another person's legitimate interests in providing, securing, improving, and protecting the Service where those interests are not overridden by your rights. In Canada and Quebec, we seek meaningful consent where required and rely on statutory exceptions only when applicable. In the EEA or United Kingdom, we identify the relevant basis for the processing rather than treating consent as the basis for every activity.
You can decline optional information, permissions, analytics, or marketing where the Service offers that choice. Some information is required to create an account, deliver a purchased feature, keep the Service secure, or comply with law; without it, the related feature may not work.
6. When we disclose information
We may disclose personal information:
- to people and organizations you direct, according to profile, directory, post, message, cohort, roster, collaboration, sharing, call, export, and other audience choices;
- to service providers listed in section 7, only for the services they perform for us or for the separate transaction or service you request from them;
- to authorized staff and contractors who need access for support, operations, security, moderation, finance, legal compliance, or development and who are subject to confidentiality and access controls;
- to professional advisers, auditors, insurers, financial institutions, and counterparties where reasonably necessary and protected;
- to courts, regulators, law enforcement, exam owners, schools, or other authorities when required by law, a valid legal process, or when reasonably necessary to protect rights, safety, integrity, or prevent serious abuse; and
- in a financing, reorganization, merger, acquisition, insolvency, or sale, subject to lawful notice, confidentiality, due diligence limits, and continued protection.
We may preserve and disclose content or account records to investigate a report, fraud, infringement, exam misconduct, security event, or legal claim. We assess requests and disclose only what we reasonably believe is lawful and necessary. We may challenge an overbroad request where appropriate.
Aggregate and de-identified information may be shared when it does not reasonably identify an individual. We do not attempt to re-identify information treated as de-identified except to test safeguards or as permitted by law.
7. Service providers
Our current provider categories and principal providers include:
| Provider | Role and information involved |
|---|---|
| Supabase | Authentication, database, private storage, Realtime, and related backend services; receives account, session, profile, study, social, file, security, and other Service records relevant to enabled features. |
| Cloudflare | Hosting, delivery, domain and network services, security, Workers, and encrypted call relay; processes network requests, IP address, user agent, security and diagnostic information, and call media/relay traffic when a relay is required. |
| Resend | Delivery of transactional, account, support, security, receipt, and permitted commercial email; receives recipient address, message content, delivery status, and related metadata. |
| Stripe | Eligible web checkout, payment processing, subscription and billing administration, fraud controls, refunds, and receipts; receives transaction, customer, device, network, and payment information you provide to Stripe. We receive limited transaction results and identifiers, not full card numbers. |
| Apple | Optional Sign in with Apple, app distribution, StoreKit purchases, subscriptions, receipts, refunds, restoration, and platform services; receives information according to your Apple account and Apple's terms. For Sign in with Apple, we receive an Apple account identifier and, if you choose to share them, your name and email address. We receive limited transaction and entitlement information, not full card numbers. |
| Optional Google sign-in and user-directed Google Drive features; receives identity, authorization, and file/action information required for the feature you choose. The Drive connection uses Google's per-file access (drive.file): the app can see only files you create with it or choose to open with it. | |
| Anthropic | Enabled AI generation and study-assistant requests; may receive prompts, instructions, selected context, extracted text, selected page images, and technical usage information needed to return output. |
| ipwho.is | Coarse sign-in location checks; receives an IP address and returns approximate city, region, and country information used for account security. |
When you enable device notifications, the browser or operating system selects its push provider, such as Apple, Google or Mozilla. We store the delivery endpoint, subscription keys, account association and time zone needed for delivery and quiet hours. The provider handles encrypted notification delivery and related network metadata. The current browser notifications use generic text without message or study content. You can disable this device in Profile and manage permission in your browser or device settings.
Providers may process information in countries where they or their subprocessors operate. Their own privacy notices govern information they process independently, such as an Apple, Google, or Stripe account. Provider names and roles may change; we will update this Policy or provide notice when a change is material.
8. Device storage, cookies, and similar technology
The Service uses browser local storage, session storage, IndexedDB, Cache Storage for appropriate public application assets, native application storage, and similar technology to keep sessions, preferences, security state, drafts, offline work, and feature data. The exact keys and duration depend on the application, account, and feature.
We do not use advertising cookies or cross-site advertising trackers. Our applications generally rely on token and device storage rather than a first-party advertising profile. However, required providers and external checkout, authentication, support, or linked services may use their own cookies or storage under their notices. A provider page can therefore set technology that is outside our direct control.
Some study files and drafts remain only on the device. Other enabled synchronization, sharing, collaboration, coaching, review, or storage features send files or their contents to private server storage. Clearing device storage can sign you out and delete unsynchronized local work, but it does not delete server records or copies already shared with others.
The student account controls separate three optional purposes: feature usage (app areas and completed actions), learning trends (session totals, duration and recall outcomes), and diagnostics (app version, fixed error codes and performance measurements). Each is off by default and requires a separate affirmative choice under Profile → Your data. These measurements exclude search terms, message bodies, notes, files, card text, written answers, recordings and raw error stacks. They are linked to your account and a temporary session identifier; they are not anonymous. Consent records include the choice, time and notice version. Withdrawing a choice stops future collection for that purpose and drops unsent measurements. Previously received data remains subject to the retention and deletion rules below. Required account, transaction, security, fraud, synchronization and operational records remain separate.
9. Visibility and choices
Information visibility depends on the feature and your role or settings:
- profile and directory fields may be private, visible to friends, visible to a cohort or school, or visible more broadly as indicated;
- posts, comments, group content, rosters, and shared study items are shown to the intended audience identified by the feature;
- direct messages are intended for participants, while reported material may also be reviewed by authorized moderators or staff;
- collaboration permissions determine who may view, comment, edit, or review an item;
- call participants receive the identity and call state needed to communicate; and
- an administrator, coach, cohort representative, or school role receives only the information authorized for that role and feature.
Check the intended audience before submitting. Privacy settings reduce visibility but cannot retract a message or copy another person already received, exported, photographed, or recorded outside the Service. Blocking limits future interactions through supported features; it does not erase lawful records or guarantee that another person cannot encounter public content.
Your choices may include language and theme, profile visibility, analytics, notification and marketing preferences, sharing permissions, camera and microphone permissions, Google authorization, and subscription cancellation. Withdrawing a permission or consent applies prospectively and may disable the feature that needs it. Use in-app controls where available or contact the Privacy Officer.
10. AI and uploaded files
Files follow different paths depending on the feature:
- a local viewer, draft, or offline feature may keep a file on the device;
- an enabled synchronization, sharing, collaboration, coaching, roster, Casper, review, or storage feature may upload the file or its contents to private server storage;
- a Google Drive feature sends the user-directed file or action to Google; and
- an AI feature may send extracted text, selected context, or selected page images to Anthropic to generate output.
The feature interface and this Policy should be read together. Do not assume that every file stays local or that deleting the device copy deletes server, provider, recipient, or backup copies.
AI interactions may include prompts, instructions, selected content, outputs, safety and technical metadata, usage, and GrindStone transaction records. We use them to return the requested output, operate and secure the feature, troubleshoot, account for use, and enforce the Terms. Provider processing is also subject to its contractual and legal obligations. Do not submit patient-identifying, exam-confidential, credential, biometric, financial-account, trade-secret, or other highly sensitive information without express feature support, lawful authority, and informed consent.
11. Retention and deletion
We retain information only for as long as reasonably needed for the purposes described, a valid business or security need, a legal obligation, or the establishment, exercise, or defence of claims. Current verified rules include:
- account, entitlement, and active study information is generally retained while the account or related feature is active and afterward only as needed for deletion processing, security, disputes, law, or backups;
- raw first-party analytics events are scheduled for deletion after 90 days, while aggregate or de-identified statistics may be retained longer;
- visible global or class chat may be purged after 90 days, and visible direct messages after one year, when the applicable retention job is active; removed, reported, audit, abuse, legal-hold, or dispute material may be retained longer;
- a handled review-queue report may be purged after 48 hours when its scheduled job is active, while associated moderation evidence may follow a different retention rule;
- purchase, subscription, receipt, tax, accounting, fraud, consent, security, and dispute records may be retained for the period required or permitted by law;
- support, application, roster, file, and collaboration records are retained while needed for the feature, relationship, issue, or a lawful exception; and
- encrypted backups, provider systems, recipient copies, and technical logs expire according to their operational cycles and cannot always be removed immediately from every copy.
Where available, Profile → Your data → Delete your account starts an authenticated account-deletion flow with confirmation and a result explaining incomplete cleanup, if any. Eligible web billing is closed through that flow. Google Drive copies remain in your Drive, and Apple subscriptions must be managed with Apple.
The in-app “Delete local data” control removes data from that device only. In Profile, this device-only action is called Clear this device. It is not a request to delete the server account. A server deletion request for the account and personal information can be sent to hello@grindlabs.ca. We verify the requester and ordinarily target completion within 30 days, or within the period required by applicable law. We may retain or de-identify information where required for transactions, tax, security, fraud prevention, rights of others, legal claims, valid legal holds, or another lawful exception. We will explain a material refusal where law requires it.
Deleting content may remove it from active views without erasing a copy already received by another person. Account deletion does not automatically cancel an App Store subscription; cancel it through the platform that sold it.
12. International processing
Grind Labs is based in Quebec, but providers and their subprocessors may process or store information outside Quebec and outside Canada. Exact locations vary by provider, feature, routing, account, and provider configuration. Information in another country may be subject to that country's laws and lawful access by courts, law enforcement, or national-security authorities.
Where required, we assess privacy risks before communicating information outside Quebec or introducing a qualifying information system, use contractual and technical safeguards, limit access and purposes, and consider the sensitivity, destination, legal framework, and provider practices. No cross-border safeguard eliminates every risk. You may contact the Privacy Officer for available information about relevant provider categories and processing locations.
13. Security and incidents
We use safeguards appropriate to the sensitivity and context of information. Depending on the feature, these include encryption in transit, access controls, authenticated sessions, role and row-level authorization, private storage, short-lived credentials, provider security controls, logging, monitoring, backups, staff-access restrictions, and incident procedures.
No system is perfectly secure, and we cannot guarantee that loss, misuse, unauthorized access, disclosure, alteration, or interruption will never occur. The Service does not promise universal end-to-end encryption. Protect credentials and recovery codes, use multifactor authentication when offered, secure your device, review recipients and permissions, and report suspected misuse promptly.
We assess suspected privacy breaches, contain and remediate them where possible, maintain required records, and notify affected people and regulators when applicable law requires it, including where a breach creates a real risk of significant harm under Canadian law or a risk of serious injury under Quebec law.
14. Your privacy rights
Depending on where you live and subject to lawful exceptions, you may have the right to:
- request access to personal information and information about its use and disclosure;
- request correction of inaccurate or incomplete information;
- request deletion, erasure, or de-identification;
- withdraw consent prospectively, where processing is based on consent;
- request a structured, commonly used copy or portability where applicable;
- request de-indexation or re-indexation where Quebec law applies;
- object to or restrict processing where applicable, including certain legitimate-interest processing;
- receive information about, submit observations concerning, or request available human review of a decision based exclusively on automated processing where applicable;
- unsubscribe from commercial electronic messages while continuing to receive necessary service, security, and transaction messages;
- complain to us, request review of a refusal, and receive the reason and available recourse where required; and
- complain to the regulator where you live.
Submit a request to hello@grindlabs.ca with enough detail to identify the account and right. Do not email passwords or recovery codes. We may verify identity, authority, jurisdiction, and request scope. We ordinarily aim to respond within 30 days, subject to the applicable legal period, extensions, fees permitted by law, and exceptions protecting another person's rights, security, privilege, investigations, and records we must retain.
Canadian regulators include the Office of the Privacy Commissioner of Canada and, in Quebec, the Commission d'accès à l'information. You may also contact another competent privacy or data-protection authority where you live.
15. Children, changes, and contact
The Service is designed primarily for post-secondary and professional learners and is not directed to children. A minor may use only a feature expressly made available to minors with the legally valid authorization and supervision described for that feature. If you believe a child provided personal information without valid authorization, contact the Privacy Officer so we can investigate and take appropriate action.
We may update this Policy as the Service, providers, practices, or law change. We will post the updated version and date. For a material change, we will give reasonable notice and obtain renewed consent where required before using information for a materially different purpose.
Questions, requests, complaints, or incident reports: Privacy Officer, Grind Labs Inc. — hello@grindlabs.ca. The current Policy is available at grindlabs.ca/privacy and lagrind.ca/privacy.