Privacy Policy
Last updated: 4 June 2026
Graft ("we", "us") provides a mobile app and related services that help self-employed tradespeople manage their work. This policy explains what personal data we collect, why, and your rights under UK data protection law (UK GDPR and the Data Protection Act 2018). We are the data controller for the information described here. For any question, contact hello@graft-ai.co.uk.
1. Information we collect
You give us
- Account details — your name, email address and password (passwords are stored hashed; we never see them).
- Business data you enter — your clients' details, jobs, quotes, invoices, to-dos, notes, photos, time entries and expenses.
- Business profile — company name, address, contact details and bank details you add for your invoices.
Collected automatically
- Location — only if you turn it on, to power on-site clock-in reminders, mileage tracking and directions. You can disable this any time in your device settings.
- Device & usage — a push-notification token, app version, and basic technical logs to keep the service running.
2. How we use it
- To provide the app — your diary, quotes, invoices, time tracking and customer portal.
- To send notifications you've asked for (job reminders, paid/overdue invoices, booking requests).
- To power AI features (drafting quotes, the daily brief) — see "AI features" below.
- To send invoices and quotes by email on your behalf, to recipients you choose.
- To keep the service secure, debug issues and improve the product.
Our lawful bases are: performance of our contract with you (providing the app), our legitimate interests (security and improving the service), and your consent (e.g. location and notifications, which you can withdraw at any time).
3. AI features
Some features use a third-party AI model (Anthropic's Claude) to draft quotes, write your daily brief and analyse photos you choose to add. The relevant job description, photo or business context is sent to the provider to generate that result. It is not used to train their models. You can avoid these features by not using them.
4. Who we share data with
We don't sell your data. We use a small number of trusted processors who handle data on our behalf:
- Supabase — secure database and hosting for your account and business data.
- Google Firebase — delivery of push notifications.
- Resend — sending the invoice/quote emails you ask us to send.
- Anthropic — the AI model behind quoting, briefs and photo analysis.
- Google Maps Platform — directions and travel estimates between jobs.
We also share data where you direct us to — for example, an invoice you email or a portal you share with your own customer. Some providers process data outside the UK/EEA; where they do, appropriate safeguards (such as Standard Contractual Clauses) are in place.
5. Your customers' data
When you add your clients' details, you are the controller of that information and Graft processes it on your behalf. You're responsible for having a lawful basis to store their details and for responding to their data requests. We'll help where we reasonably can.
6. Keeping your data
We keep your data for as long as your account is active. If you delete your account, we delete your personal data and business records, except where we must keep limited information to meet legal obligations (for example, financial records). You can request deletion in the app (Settings → Account) or by emailing us.
7. Your rights
Under UK GDPR you have the right to access, correct, delete or export your data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email hello@graft-ai.co.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
Data is encrypted in transit and at rest, access is restricted by row-level security so you only ever see your own business's data, and bank details and other sensitive fields are protected. No system is perfectly secure, but we take reasonable steps to protect your information.
9. Children
Graft is for working tradespeople and is not intended for anyone under 18.
10. Changes
We'll update this policy as the app evolves and post the new version here with a revised date. Significant changes will be highlighted in the app.