grabba

privacy policy

last updated June 2026

this is the privacy policy for grabba ("grabba", "we", "us"), the professional networking application at grabba.net. grabba helps you make real-world professional connections at events and beyond. our core promise: your data is private until you choose to share it. we never sell your personal data. questions: hello@grabba.site.

what we collect

• your profile: name, role, the company you select (from a list), city, bio, and photo.
• the contact details you add and your preferred way to be reached: email, phone, LinkedIn, and a preferred channel (e.g. WhatsApp, Telegram, SMS, or email) used to route follow-ups.
• activity needed to make the product work: events you join, people you grab/match/connect with, the private notes and priority (red/yellow/green) you set on a contact, meetings you schedule, and notifications.
• basic technical data (device/browser) to operate and secure the service.

how we sign you in (LinkedIn)

you sign in with LinkedIn using "Sign In with LinkedIn using OpenID Connect". with your consent we receive your name, email address, and profile photo, which we use to create your account and your networking card (we copy the photo to our own storage so it stays available). we don't post to LinkedIn or read your connections.

AI features

some features are powered by AI — drafting a bio from text you provide, suggesting people to meet, designing your card, and summarising who you met. these run on Anthropic (the Claude API) as our data processor. we send only the specific text you've provided for that feature (e.g. your bio, role, or a URL you paste); we do not send your Google Calendar data, and Anthropic does not use this input to train its models.

one optional tool, the background check, researches publicly available professional information about a person you've connected with, or a company present at an event, using web search, and summarises it for you. it uses only that person's or company's name, role, and company together with public web results; it does not access any private LinkedIn or account data. you choose when to run it (it's limited per event).

how we use it

to show your card to people you connect with, to suggest relevant people to meet, to schedule meetings, to route follow-ups to your preferred channel, and to send you notifications. matchmaking uses the interests you provide. we don't show your email or phone to other attendees in bulk — contact details are shared only when you connect with someone or publish your card.

google user data

connecting Google is optional and used only for your calendar — your account identity comes from LinkedIn, not Google. if you connect Google Calendar, grabba accesses, uses, stores, and shares Google user data strictly as described below.

What we access. with your consent at the Google consent screen, we request:

Google Calendar — read free/busy (.../auth/calendar.readonly): your busy/free time blocks.
Google Calendar — events (.../auth/calendar.events): the ability to create and update calendar events you confirm.

these are the minimum scopes needed for the features below. you can decline calendar access and still use grabba.

How we use it. calendar read-only is used to check your free/busy availability so we can suggest meeting times that work for both you and the person you're meeting — we read availability only at the moment you schedule, and we do not read the titles, attendees, or contents of your calendar events. calendar.events is used only to create the specific meeting you confirm (with a Google Meet link). we never use Google user data for advertising or to train AI/ML models.

How we store it. to call Google on your behalf we store your Google OAuth access/refresh tokens in our database (hosted by Supabase), protected by encrypted transport and row-level access controls. we do not store a copy of your calendar; free/busy is fetched live when scheduling and not retained.

How we share it. we do not sell Google user data and do not share it with any third party, except: (a) with Google itself, to provide the feature you requested (e.g. creating your meeting); and (b) with our infrastructure provider (Supabase) acting solely as a data processor to operate grabba. we do not share Google user data with other grabba users. humans do not read your Google user data except with your consent, for security, or as required by law.

Retention & revocation. we keep your Google tokens until you disconnect Google, delete your grabba account, or revoke access in your Google account settings — any of which immediately and permanently ends our access to your Google user data and deletes the stored tokens.

Limited Use. grabba's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

sharing

we don't sell your data. people see your card only when you connect or publish it. organizers of an event you join see aggregate, non-identifying analytics — including counts by company — not your private contact details. sponsors of an event may receive aggregate metrics about their own brand's participation (e.g. how many people from their company attended and connected); individuals are named only where both parties opted in. service providers that process data solely to run grabba include Supabase (hosting), Anthropic (AI features), Google (calendar, if you connect it), and Resend (email).

changes to this policy

we may update this policy; the "last updated" date above always reflects the current version. if we materially change how grabba accesses, uses, stores, or shares Google user data, we will notify you (by email and/or in-app) and, where required, ask for your consent before the change takes effect.

your choices

you can permanently delete your account and all associated data at any time from inside the app (profile → settings → delete account), or by emailing us. deletion is immediate and irreversible. you can also disconnect Google; revoking Google access in your Google account immediately stops calendar use.

grabba participates in Google's Cross-Account Protection: if your Google account is compromised, disabled, or deleted, Google notifies us and we automatically secure or delete the linked grabba account.

retention & security

we keep your data while your account is active and delete it on request. we use industry-standard security (encrypted transport, row-level access controls) to protect it.

contact

questions or deletion requests: hello@grabba.site