Privacy Policy
Last updated: 19 July 2026
Grongy (“Grongy”, “we”, “us”) is a research and writing assistant built around a simple principle: your work stays yours. This policy explains what we collect, what we deliberately do not collect, and the third parties involved when you use the app.
The short version
- Your documents, sources, library, drafts and chat history are stored locally in your browser (IndexedDB). Without an account they never leave your device.
- When you are signed in(any plan), this work is backed up to your private account so you can open it from any browser or computer (“cloud sync”). It stays private to you — protected by your login, isolated per account, encrypted in transit and at rest. We do not read it, sell it, or share it.
- Uploaded PDF filesare read and indexed entirely in your browser. When you are signed in, a copy is stored in your account's private cloud file storage (within your plan's allowance) so you can open it on other devices; signed out, files never leave your device.
- Using the app requires a free account — it keeps your work backed up, your usage fairly metered, and your files private to you. Your documents still live device-first.
- When you use an AI feature, the text needed for that request is sent to our AI provider to generate a response.
- We never sell your data, and we never fabricate or share your work.
What we store on our servers
We keep the minimum needed to run accounts and enforce plan limits:
- Account information — your email address (and, if you sign in with Google, your basic profile) via our authentication provider. Used to sign you in and associate your plan.
- Usage & plan data— a monthly count of the advanced AI actions you take, so we can apply your plan's allowance. We store which model was used and when — never the content of your prompts.
- Your synced workspace (signed-in accounts)— your projects, documents, sources, outlines, drafts and chat threads are mirrored to your private account so you can access them from other devices. Uploaded PDF files are stored in your account's private cloud file storage (Cloudflare R2), isolated per account and accessible only through your login. This content is encrypted in transit and at rest. We use it only to provide sync — we do not read it, analyse it, or share it.
- Documents you explicitly share (paid plans)— using “Share with your advisor” publishes a read-only snapshot of that document on our servers under an unguessable link. Anyone who has the link can read that snapshot until you stop sharing, which deletes it immediately. Nothing is ever shared without this explicit action.
What stays on your device
While signed out, your projects, documents, uploaded PDFs, saved sources, outlines, drafts and chat threads live only in your browser's local storage — they are never sent to us. Clearing your browser data, or using the Delete everything option in Settings, permanently removes local data from that device. When signed in, your workspace and uploaded files are also backed up to your account (see above); you can request their deletion at any time.
AI processing
AI features (autocomplete, drafting, editing, chat, review) work by sending the relevant text — your instruction, the selected passage, parts of your document, and the sources you chose — to our AI provider, OpenRouter, which routes it to the underlying model provider (e.g. Anthropic, OpenAI, Google, xAI) to generate a response. This transfer is necessary to provide the feature. We do not use your content to train models.
Source search
When you search for papers, your search terms are sent to public scholarly databases — OpenAlex and Crossref — to return real publications and their metadata. PDFs you upload are read and indexed inside your browser; the file itself is never sent to our AI provider. When signed in, a copy is stored in your private cloud file storage (see above) so you can read it on other devices.
Cookies & local storage
- A session cookie from our authentication provider keeps you signed in.
- Local preferences(your name, theme, defaults, saved prompts) are stored in your browser's localStorage, not on our servers.
We do not use advertising or third-party tracking cookies.
Service providers
- Supabase — authentication, the usage database and workspace sync.
- Cloudflare R2 — private cloud file storage (uploaded PDFs).
- OpenRouter and the underlying model providers — AI generation.
- OpenAlex & Crossref — scholarly source search and metadata.
Each processes data under its own terms and privacy policy.
Your rights
You can view and delete your locally stored work at any time from within the app. To access or delete your account data (email and usage records) held on our servers, contact us at support@grongy.co and we will action your request.
Data retention
Local data persists until you clear it. Account and usage records are retained while your account is active and deleted on request. Monthly usage counts reset at the start of each calendar month.
Children
Grongy is intended for users in higher education and is not directed at children under 16. If you believe a child has provided us personal information, contact us and we will remove it.
Changes
We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about privacy? Email support@grongy.co. See also our Terms of Service and Academic Integrity statement.