Grom — Privacy Policy

Last updated: 14 July 2026

This Privacy Policy explains how Yury Moskaltsov ("Grom", "we", "us") collects and uses personal data when you use the Grom mobile application and related services (the "Service"). We are the data controller for the purposes of the UK GDPR and EU GDPR.

Contact / Data Protection point of contact: yury@gromapp.ai Postal address: 4 Whitchurch Parade, Whitchurch Lane, Edgware, HA8 6LR, United Kingdom

Note for business (team) use: where Grom is provided to you through your employer or organisation, that organisation is the controller of the content you create within their workspace, and we act as a processor on their behalf. This policy describes our own processing as controller (e.g. account and device data) and our role as processor for workspace content.


1. What data we collect

Account data. Email address, display name, and (if provided) phone number, avatar, and status text. Authentication identifiers from Sign in with Apple or Google sign-in, and a Firebase user ID.

Messages and user content ("UGC"). The messages, images, files, voice messages, tasks, checklists, and other content you send or upload. Messages are stored to deliver them and to provide search and AI features within your workspace.

Calls, recordings and transcripts. When you make a voice or video call, we process call metadata (participants, time, duration, quality). If you or another participant starts recording, we create an audio recording of the call and generate a written transcript, summary, and derived items (e.g. action items and search embeddings). See Section 4.

Contacts. If you grant permission, contact information you choose to use to find or invite people.

Device and technical data. Device identifiers, push notification tokens, app version, log and diagnostic data, and approximate technical information needed to operate the Service.

Usage data. Feature usage and interaction data used to operate and improve the Service.

We do not intentionally collect special-category data. Please do not share sensitive personal data in messages or calls unless necessary.


2. Why we use your data and our lawful bases (UK/EU GDPR)

Purpose Lawful basis
Create and manage your account; authenticate you Performance of a contract
Deliver messages, calls, files, and core features Performance of a contract
Call recording and transcription (when enabled) Legitimate interests / performance of a contract with the workspace; see Section 4
Send push notifications you've enabled Performance of a contract / consent
Content moderation, safety, and abuse prevention Legal obligation and legitimate interests
Security, fraud prevention, debugging (error monitoring) Legitimate interests
Improve and develop the Service Legitimate interests
Comply with law and respond to lawful requests Legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights. You may object — see Section 8.


3. Messaging and user-generated content

Grom is a communication platform. Content you send is shared with the recipients and workspace members you direct it to. We provide tools to report content or users and to block users. Reported content and associated metadata are processed so we can review and act on it, including removing content and suspending accounts where appropriate. See our Terms of Service for our content rules and moderation process, and Section 9 below for how to report illegal content.


4. Call recording and transcription

Recording is not silent: when a recording is active, all participants are shown a clear on-screen "Recording" indicator. We do not require a separate consent tap; by remaining in a call after the indicator appears, participants are on notice that the call is being recorded.

When a call is recorded we process:

Responsibility to inform. Where Grom is used by an organisation, the organisation and the person who starts a recording are responsible for ensuring recording is lawful in their context and for informing participants as required by applicable law. We provide the indicator and notices to support this.

Retention. Recordings, transcripts, and derived items are retained for 90 days by default (configurable per workspace), after which they are automatically deleted, unless we are required to retain them longer by law or you have asked us to keep them. See Section 7.

Deletion. You can request deletion of a recording you initiated, and you can request erasure of your personal data including your recorded audio and transcript segments — see Section 8. Deleting your account removes recordings you initiated and your transcript contributions, subject to legal retention requirements.


5. Who we share data with (sub-processors)

We use trusted service providers ("sub-processors") who process data on our behalf under contract. We share only what is necessary.

Sub-processor Purpose Location
Google Firebase / Google Cloud (Authentication, Realtime Database, Cloud Storage, Cloud Messaging) Auth, message delivery & storage, file/recording storage, push Realtime Database: EU (europe-west1). Cloud Storage (files & recordings): EU multi-region. Auth & Cloud Messaging: global (primarily US)
Agora Voice/video calls and cloud recording Global (media routed via nearest data centre); recordings written to our Google Cloud Storage bucket (see Google above)
Deepgram Speech-to-text transcription United States
AssemblyAI Speech-to-text transcription United States
Anthropic AI summaries, briefings, and assistant features United States
OpenAI Search embeddings (indexing your content so it can be found) United States
Google (Gemini / Google AI) AI analysis of files and video United States / global
Voyage AI Search embeddings United States
Railway Application hosting United States (US-West)
Sentry Error and crash monitoring United States (unless you selected Sentry's EU region)
Apple Push Notification service / Expo Push notification delivery United States / global

We may also disclose data where required by law, to protect rights and safety, or in connection with a business transfer.

We do not sell your personal data, and we do not use it for third-party advertising.


Third-Party AI & Voice Processing

To provide AI Assistant and voice features, Grom shares certain data with third-party service providers:

How we collect it: Only when you actively use an AI or voice feature, and only after you grant consent in the app.

How it's used: Solely to deliver the requested feature. These providers act as data processors, process the data only to perform the service, and do not use your content to train their models. We do not sell your personal data.

Protection: Each provider is contractually bound to protect your data with safeguards equivalent to those in this policy.

Your control: Withdraw consent and disable AI/voice features any time in the app (Settings → AI Assistant). Request deletion of your AI data in-app or by contacting yury@gromapp.ai.


6. International data transfers

Some sub-processors (including Deepgram, located in the United States) process data outside the UK/EEA. Where we transfer personal data internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum and the EU Standard Contractual Clauses, together with supplementary measures where required. You can request details using the contact above.


7. How long we keep data

We keep personal data only as long as necessary for the purposes above:


8. Your rights

Under UK/EU GDPR you have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent where processing is based on consent. You can exercise these rights — including erasure of your recorded audio and transcripts — by contacting yury@gromapp.ai, or in-app via account deletion. We will respond within the time limits required by law (generally one month).

You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO) at ico.org.uk; in the EU, your local data protection authority.


9. Reporting illegal content (DSA / Online Safety)

If you believe content on Grom is illegal or breaches our rules, you can report it in-app (long-press a message → Report, or via a user's profile) or contact our designated point of contact:

Safety / illegal-content contact (DSA point of contact): yury@gromapp.ai

We review reports and act without undue delay, prioritising serious harms. Child sexual abuse material is removed and handled in accordance with our legal obligations.


10. Children

Grom is not intended for children. You must be at least 16 years old (or the age required in your country) to use the Service. We do not knowingly collect data from children below that age.


11. Security

We use technical and organisational measures to protect personal data, including encryption in transit, access controls, and monitoring. No system is completely secure, but we work to protect your information and to notify you and regulators of breaches where required.


12. Changes to this policy

We may update this policy. We will post the new version with an updated "Last updated" date and, where changes are significant, notify you in-app or by email.


13. Contact

Questions or requests: yury@gromapp.ai Yury Moskaltsov, 4 Whitchurch Parade, Whitchurch Lane, Edgware, HA8 6LR, United Kingdom