Privacy Policy.
What we collect, what we do with it, and what happens to the code you point the tool at.
This Privacy Policy explains how Graphify Labs ("graphify", "we") collects, uses, and protects information when you use our website, APIs, and services. By using graphify you agree to the practices described here.
Information we collect
We collect account information you provide (name, email, organization), usage and telemetry needed to operate the service, and content you choose to ingest into your graphs. We do not sell personal data.
How we use information
- To provide, maintain, and improve the service.
- To authenticate you and secure your account.
- To communicate about updates, security, and support.
- To comply with legal obligations.
Website analytics and advertising cookies
If you accept optional cookies, we use PostHog for website analytics and Meta Pixel to measure visits from Facebook and Instagram ads. Meta receives page-view information and browser information and may use cookies to connect visits with ads. Declining prevents these tools from loading. See Meta's Privacy Policy for information about how Meta handles this data.
We also use Google Ads to measure sign-ups on app.graphify.com. Google's advertising and analytics cookie consent defaults to denied in the EEA, UK, and Switzerland until you accept, and granted elsewhere until you decline. Your choice is shared between graphify.com and its app subdomain. When consent is denied, Google may receive cookieless measurement signals. See how Google uses information from partner sites.
Data you ingest
Content you ingest into graphify is processed to build your knowledge graph and is treated as confidential. On self-hosted and VPC deployments, this data never leaves your infrastructure.
The MCP connector
When you connect an AI assistant (for example Claude, Cursor, or another MCP-compatible client) to graphify over the Model Context Protocol, the assistant sends queries, such as a natural-language question or a repository identifier, to your workspace, and graphify returns results from your knowledge graph and, where you have enabled it, your stored memory. We process these queries only to answer them and operate the service. Connector access is scoped to your workspace and the repositories you have indexed; an assistant cannot reach repositories you have not added. On self-hosted and VPC deployments, connector traffic never leaves your infrastructure.
AI processing and training
We do not train models on your code. For the hosted service, code and content are sent to our LLM subprocessors (OpenAI and Anthropic) solely to produce results; under their API terms, neither we nor they train models on it. Self-hosted and on-device deployments do not send your code to these providers at all. See the full list of processors we use on our Subprocessors page.
Storage & security
Data is encrypted in transit and at rest. We maintain a SOC 2 Type II program and restrict access on a least-privilege basis. See our Security page for details.
Data retention
We keep account information while your account is active and as needed to provide the service. Content you ingest is retained until you delete it or close your account, after which it is removed from active systems within 30 days; backups expire on a rolling 90-day cycle. Operational logs and usage telemetry are kept for up to 12 months. On self-hosted deployments, retention is governed entirely by your own infrastructure. You can request deletion of your data at any time. A Data Processing Addendum (DPA) is available on request; contact our team.
Your rights
You may access, correct, export, or delete your personal data. To exercise these rights, or for any privacy question, contact our team.
Changes
We may update this policy; material changes will be announced in-product or by email. Continued use after an update constitutes acceptance.