Privacy policy

Last updated September 30, 2026.

Grounded (the "Service"), at https://groundandprotect.com, is operated by Validus Business Solutions ("we"). This page says what we collect, why, where it is kept and for how long, who can see it, and what you can do about it. It covers the Grounded portal, the Grounded gateway that your AI client connects to, and the Gmail and Google Calendar connections that use Google's APIs. Where this page and our terms of service say different things, this page governs for privacy.

1. What Grounded does

Grounded sits between the AI client a person uses (Claude, ChatGPT, Cursor, VS Code, Codex and other MCP clients) and the systems their company connects: MCP services and, optionally, the person's own Gmail and Google Calendar accounts. When the AI asks a connected system a question, Grounded fetches the result, holds any large result in memory, computes figures over it in code when the AI asks, and returns a card that shows what was computed and from what. Every call and computed answer gets a signed receipt.

Grounded is a business tool. Companies sign up, invite their people, and decide which connections those people may use.

2. What we collect and why

DataWhyWhere and how long
Account: your email address, password (held by Supabase Auth, never seen by us), second-factor enrollment, single sign-on identityTo sign you in and to know which company you belong toSupabase Auth and our PostgreSQL database, until your account or company is deleted
Company: name, members, roles, groups, invitations, settings and controlsTo run the company's workspace and enforce who may use whatPostgreSQL, until the company is deleted
Connections: names, URLs and settings of connected MCP services; API keys and Google refresh tokensTo reach the systems you connected, as youPostgreSQL. Keys and tokens are encrypted (AES-256-GCM) under a master key that exists only in the gateway's environment, bound to the connection and its owner. They are never shown, exported or returned by any API. Kept until you remove them, the connection is deleted, or you leave the company
Install tokens for AI clientsTo recognise your AI clientSHA-256 hash only, until revoked or you leave
Results from connected systems, including Gmail and Google CalendarTo answer the question your AI askedMemory of one gateway process, for up to 45 minutes or until the process stops. Never written to disk, to the database, to logs or to receipts. See section 3 for Google data
Activity log and receipts: who called which tool when, hashes of inputs and results, row counts, the derivation the AI asked for and the computed result (totals, counts, group labels), admin actionsSo your company can see what happened and prove it; so we can operate and secure the ServicePostgreSQL. Kept while the company exists. Receipts are hash-chained, so they cannot be edited or deleted one at a time; see section 8
Operational logs: request times, status codes, error messages, IP addressesTo run and secure the ServiceServer logs, rotated; no fixed retention beyond what operating the Service needs

A group label or a filter value is part of a derivation, so it appears in the log and the receipt. If someone asks for "messages per sender", the sender addresses are in the computed result and therefore in the log. That is by design (a receipt has to show what was computed), and it means the log is not free of business data.

We do not store your prompts to your AI, your AI's answers, or the credentials your AI client holds for its own provider.

3. Google user data (Gmail and Google Calendar connections)

A Gmail connection lets a person link one or more of their own Google accounts so that their AI can search and read that mail through Grounded. A Google Calendar connection does the same for calendars and events. The two are separate: an account linked to one grants nothing to the other. This section describes exactly how Grounded accesses, uses, stores and shares Google user data. Grounded's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we ask Google for

  • openid and email: to know which Google account you linked and to show you its address.
  • https://www.googleapis.com/auth/gmail.readonly, for Gmail connections only: to search and read mail, labels and attachment names in that account. This scope cannot send, delete, modify or label mail, and Grounded has no tool that tries.
  • https://www.googleapis.com/auth/calendar.readonly, for Google Calendar connections only: to list the calendars in that account and read their events (times, titles, locations, descriptions, attendees and their responses, conference links) and busy times. This scope cannot create, change, delete or respond to events, and Grounded has no tool that tries.

Each connection asks for openid, email and its own scope, nothing more. We request only read-only scopes. If Grounded adds another Google service, it will request only that service's read-only scope, this page will name it before the connection is offered, and Google will ask you for consent again.

How we access it

You link an account from a connection page in the portal. Google shows its consent screen; you may decline. If you grant access, Google gives Grounded a refresh token, which Grounded encrypts and stores as described in section 2. Grounded uses it to obtain short-lived access tokens, held in memory, only when your AI calls a Gmail or Calendar tool. Grounded never accesses your mail or calendars on a schedule, in the background, or for any purpose other than answering a request your AI made on your behalf. Every such request is recorded in your company's activity log under your name.

How we use it

  • To return search results, messages, threads and labels, or calendars, events and busy times, to your own AI client, in response to a question you asked it.
  • To compute over those results in code when your AI asks (for example, count messages per account or per sender, or add up meeting hours per calendar) and to return the computed figures.
  • Nothing else. We do not use Google user data for advertising, for profiling, to train or improve machine-learning or AI models, to build or sell datasets, or for any purpose unrelated to the feature you are using.

Where it goes (sharing)

  • Your AI client and its model provider. Mail or calendar data that answers your question, or a small sample of a large result, is returned to the AI client you installed Grounded in. That client sends it to its model provider (for example Anthropic or OpenAI) under that provider's terms. You choose the client; Grounded sends Google data nowhere else. This is the only transfer of Google user data Grounded makes, and it exists solely to provide the feature you asked for.
  • Your company's activity log. Only what section 2 describes: hashes, row counts, the derivation and the computed result. Never message bodies or event details, and never the raw result rows. Company admins and managers can see the log for the whole company; users see only their own.
  • Our infrastructure providers (section 5) process data on our behalf as described there. Google user data held in gateway memory is on a server we rent; the refresh token is in the database in encrypted form.
  • We do not sell Google user data, and we do not share it with anyone else, except if the law requires it or to investigate abuse or a security incident.

How long we keep it

  • Mail and calendar content: in the memory of one gateway process, for up to 45 minutes after it was fetched, or until the process stops, whichever is first. It is never written to disk, the database, logs or receipts.
  • Refresh token, account email and Google account id: until you remove the account, the connection is deleted, or you leave the company.
  • Access tokens: in memory, until they expire (about an hour).

Human access

No person at Validus Business Solutions reads your mail or calendars. We do not have a tool that displays Google user data, and refresh tokens are unreadable without the gateway's master key. We will only read Google user data with your explicit consent (for example, to help with a problem you report), when necessary for security or to investigate abuse, to comply with law, or after it has been aggregated so it does not identify anyone.

Removing access

  • On the connection page, remove a Google account. Grounded deletes the stored token immediately and asks Google to revoke its grant.
  • Or revoke Grounded at myaccount.google.com/permissions. Grounded will then fail to reach that account and will tell you to reconnect or remove it.
  • Leaving a company removes every Google account you linked under it.

4. How companies are kept apart

Every dataset, log row, receipt, connection and control is owned by one company. The portal's tables are under row level security and the gateway checks the company on every request, so no company can read another's data. Companies share our gateway processes and one database; the separation is logical and tested, not physical. Our security page, in the project documentation, describes this in more detail.

5. Who processes data for us

  • Supabase: authentication (passwords, second factors, single sign-on) and the PostgreSQL database that holds companies, connections, encrypted keys and tokens, the activity log and receipts.
  • Our hosting provider: the virtual server that runs the portal and the gateway, where results are held in memory.
  • Google: when you link a Google account to a Gmail or Calendar connection, Grounded calls Google's APIs as you. Google's own privacy policy applies to that account.
  • Your AI client's provider: chosen and installed by you; receives what Grounded returns to that client.

We do not use advertising or analytics trackers on the portal.

6. Cookies

The portal sets only the cookies Supabase Auth needs to keep you signed in. There are no advertising, analytics or third-party cookies.

7. Security

Connections to Grounded use TLS. Keys and Google tokens are encrypted at rest with AES-256-GCM under a master key kept only in the gateway's environment, bound to their owner so a sealed value cannot be moved to another connection or person. Fetched results never leave process memory. Two-step sign-in is available to everyone and a company admin can require it. Every administrative action is recorded before it takes effect. No outside security review has been completed yet; we say so plainly in our security documentation.

8. Your choices and rights

  • See and export: your company's activity and receipts are available in the portal to your company's admins and, for your own activity, to you.
  • Remove: remove a Google account or an API key at any time from the connection page. Leave a company from your company's People page (an admin can also remove you). A company admin can delete connections and the company.
  • Delete your account: email us at matt@techvalidus.com from the address on the account. We delete the account, its memberships and every key and Google token it held within 30 days, and we revoke Google grants when we delete their tokens.
  • Receipts: log rows and receipts your actions created are part of a hash chain your company relies on for evidence, so we do not edit or delete individual entries. They contain no message or event content; they contain your user id, the tool names, hashes, and the derivations and computed results described in section 2.
  • Access, correction, portability and objection: where the law gives you these rights, write to us and we will respond within 30 days.

9. Children

Grounded is for businesses and is not directed at anyone under 16. We do not knowingly collect data from children.

10. Changes to this policy

If we change how we handle Google user data or anything else material, we will update this page, change the date at the top, and tell company admins by email before the change takes effect. Continued use after that date means you accept the updated policy.

11. Contact

Validus Business Solutions, operator of Grounded. Privacy and security questions: matt@techvalidus.com.