Grom — Privacy Policy
Last updated: 14 July 2026
This Privacy Policy explains how Yury Moskaltsov ("Grom", "we", "us") collects and uses personal data when you use the Grom mobile application and related services (the "Service"). We are the data controller for the purposes of the UK GDPR and EU GDPR.
Contact / Data Protection point of contact: yury@gromapp.ai Postal address: 4 Whitchurch Parade, Whitchurch Lane, Edgware, HA8 6LR, United Kingdom
Note for business (team) use: where Grom is provided to you through your employer or organisation, that organisation is the controller of the content you create within their workspace, and we act as a processor on their behalf. This policy describes our own processing as controller (e.g. account and device data) and our role as processor for workspace content.
1. What data we collect
Account data. Email address, display name, and (if provided) phone number, avatar, and status text. Authentication identifiers from Sign in with Apple or Google sign-in, and a Firebase user ID.
Messages and user content ("UGC"). The messages, images, files, voice messages, tasks, checklists, and other content you send or upload. Messages are stored to deliver them and to provide search and AI features within your workspace.
Calls, recordings and transcripts. When you make a voice or video call, we process call metadata (participants, time, duration, quality). If you or another participant starts recording, we create an audio recording of the call and generate a written transcript, summary, and derived items (e.g. action items and search embeddings). See Section 4.
Contacts. If you grant permission, contact information you choose to use to find or invite people.
Device and technical data. Device identifiers, push notification tokens, app version, log and diagnostic data, and approximate technical information needed to operate the Service.
Usage data. Feature usage and interaction data used to operate and improve the Service.
We do not intentionally collect special-category data. Please do not share sensitive personal data in messages or calls unless necessary.
2. Why we use your data and our lawful bases (UK/EU GDPR)
| Purpose | Lawful basis |
|---|---|
| Create and manage your account; authenticate you | Performance of a contract |
| Deliver messages, calls, files, and core features | Performance of a contract |
| Call recording and transcription (when enabled) | Legitimate interests / performance of a contract with the workspace; see Section 4 |
| Send push notifications you've enabled | Performance of a contract / consent |
| Content moderation, safety, and abuse prevention | Legal obligation and legitimate interests |
| Security, fraud prevention, debugging (error monitoring) | Legitimate interests |
| Improve and develop the Service | Legitimate interests |
| Comply with law and respond to lawful requests | Legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights. You may object — see Section 8.
3. Messaging and user-generated content
Grom is a communication platform. Content you send is shared with the recipients and workspace members you direct it to. We provide tools to report content or users and to block users. Reported content and associated metadata are processed so we can review and act on it, including removing content and suspending accounts where appropriate. See our Terms of Service for our content rules and moderation process, and Section 9 below for how to report illegal content.
4. Call recording and transcription
Recording is not silent: when a recording is active, all participants are shown a clear on-screen "Recording" indicator. We do not require a separate consent tap; by remaining in a call after the indicator appears, participants are on notice that the call is being recorded.
When a call is recorded we process:
- the audio recording of the call (via our recording provider, Agora);
- a transcript of the recording (via our transcription provider, Deepgram);
- a summary and derived items (e.g. action items) and search embeddings, generated by our AI processing providers.
Responsibility to inform. Where Grom is used by an organisation, the organisation and the person who starts a recording are responsible for ensuring recording is lawful in their context and for informing participants as required by applicable law. We provide the indicator and notices to support this.
Retention. Recordings, transcripts, and derived items are retained for 90 days by default (configurable per workspace), after which they are automatically deleted, unless we are required to retain them longer by law or you have asked us to keep them. See Section 7.
Deletion. You can request deletion of a recording you initiated, and you can request erasure of your personal data including your recorded audio and transcript segments — see Section 8. Deleting your account removes recordings you initiated and your transcript contributions, subject to legal retention requirements.
5. Who we share data with (sub-processors)
We use trusted service providers ("sub-processors") who process data on our behalf under contract. We share only what is necessary.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Firebase / Google Cloud (Authentication, Realtime Database, Cloud Storage, Cloud Messaging) | Auth, message delivery & storage, file/recording storage, push | Realtime Database: EU (europe-west1). Cloud Storage (files & recordings): EU multi-region. Auth & Cloud Messaging: global (primarily US) |
| Agora | Voice/video calls and cloud recording | Global (media routed via nearest data centre); recordings written to our Google Cloud Storage bucket (see Google above) |
| Deepgram | Speech-to-text transcription | United States |
| AssemblyAI | Speech-to-text transcription | United States |
| Anthropic | AI summaries, briefings, and assistant features | United States |
| OpenAI | Search embeddings (indexing your content so it can be found) | United States |
| Google (Gemini / Google AI) | AI analysis of files and video | United States / global |
| Voyage AI | Search embeddings | United States |
| Railway | Application hosting | United States (US-West) |
| Sentry | Error and crash monitoring | United States (unless you selected Sentry's EU region) |
| Apple Push Notification service / Expo | Push notification delivery | United States / global |
We may also disclose data where required by law, to protect rights and safety, or in connection with a business transfer.
We do not sell your personal data, and we do not use it for third-party advertising.
Third-Party AI & Voice Processing
To provide AI Assistant and voice features, Grom shares certain data with third-party service providers:
- Anthropic, PBC — receives text you submit to the AI Assistant to generate AI responses, summaries, and briefings.
- Deepgram, Inc. — receives voice recordings you submit via voice input, to transcribe speech to text.
- AssemblyAI, Inc. — receives voice recordings you submit via voice input, to transcribe speech to text.
- OpenAI, L.L.C. and Voyage AI — receive text from your messages, tasks, files and search queries to generate the search index (embeddings) that lets you find your content.
- Google (Gemini / Google AI) — receives files and video you ask us to search or summarise, to analyse their content.
How we collect it: Only when you actively use an AI or voice feature, and only after you grant consent in the app.
How it's used: Solely to deliver the requested feature. These providers act as data processors, process the data only to perform the service, and do not use your content to train their models. We do not sell your personal data.
Protection: Each provider is contractually bound to protect your data with safeguards equivalent to those in this policy.
Your control: Withdraw consent and disable AI/voice features any time in the app (Settings → AI Assistant). Request deletion of your AI data in-app or by contacting yury@gromapp.ai.
6. International data transfers
Some sub-processors (including Deepgram, located in the United States) process data outside the UK/EEA. Where we transfer personal data internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum and the EU Standard Contractual Clauses, together with supplementary measures where required. You can request details using the contact above.
7. How long we keep data
We keep personal data only as long as necessary for the purposes above:
- Account data: for the life of your account, then deleted or anonymised after closure.
- Messages/UGC: until deleted by you or your workspace, or on account deletion.
- Recordings/transcripts: 90 days by default, then automatically deleted.
- Logs/diagnostics: a limited period for security and debugging.
8. Your rights
Under UK/EU GDPR you have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent where processing is based on consent. You can exercise these rights — including erasure of your recorded audio and transcripts — by contacting yury@gromapp.ai, or in-app via account deletion. We will respond within the time limits required by law (generally one month).
You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO) at ico.org.uk; in the EU, your local data protection authority.
9. Reporting illegal content (DSA / Online Safety)
If you believe content on Grom is illegal or breaches our rules, you can report it in-app (long-press a message → Report, or via a user's profile) or contact our designated point of contact:
Safety / illegal-content contact (DSA point of contact): yury@gromapp.ai
We review reports and act without undue delay, prioritising serious harms. Child sexual abuse material is removed and handled in accordance with our legal obligations.
10. Children
Grom is not intended for children. You must be at least 16 years old (or the age required in your country) to use the Service. We do not knowingly collect data from children below that age.
11. Security
We use technical and organisational measures to protect personal data, including encryption in transit, access controls, and monitoring. No system is completely secure, but we work to protect your information and to notify you and regulators of breaches where required.
12. Changes to this policy
We may update this policy. We will post the new version with an updated "Last updated" date and, where changes are significant, notify you in-app or by email.
13. Contact
Questions or requests: yury@gromapp.ai Yury Moskaltsov, 4 Whitchurch Parade, Whitchurch Lane, Edgware, HA8 6LR, United Kingdom