Privacy document

Privacy policy

This policy explains what Gracer Works stores, how it is used, and how organizations are separated.

Last corrected 30 September 2026
01

What is stored

  • Account data: email, display name and profile picture, from the identity provider you chose
  • Work data: projects, tasks, status, owners, comments, attachments and change history
  • Sign-in data: time and origin of each sign-in, to keep the account secure
02

Cookies we use

This site sets a single cookie and has no advertising or cross-site tracking cookies.

  • gw — The sign-in session, stored HttpOnly and Secure so JavaScript cannot read it
03

Separation between organizations

Each organization's data is separated at the database level by Row Level Security Not even application code can bypass this. A request from one organization cannot see another's.

04

AI processing

When you connect an AI agent, it can read and write only what you allow Every action is recorded in the activity log so it can be checked later

05

API key

When you create an API key we store only its hash. The key itself is not kept in the database.If you lose a key before saving it you must create a new one, and revoke anything you stop using immediately

06

Retention and deletion

Data is kept for as long as your organization uses it. An organization admin can delete projects and tasks Tasks from a deleted project move to a holding project rather than disappearing quietly

A Google sign-in account can be deleted through Firebase, which is its data holder
07

Your access

You can ask to see, correct or delete your own data by contacting your organization administrator