Skip to content
Accepting new batch of evaluations until 10/22
GrayPass
  • Platform
  • Research

    Research

    • The Shape of Identity
    • The Chain of Intent
  • Company
Demo | ConsoleRequest Evaluation
Request Evaluation
GrayPassGrayPass
  • Platform
  • Research
    • The Shape of Identity
    • The Chain of Intent
  • Company
Request EvaluationDemo | Console

Privacy Policy

This policy explains what personal data GrayPass collects on this website and through the GrayPass platform, why, for how long, and the rights you keep over it.

Effective September 3, 2026
Contents and legal documents

On this page

  1. Scope
  2. What we collect
  3. What we never collect
  4. Why we process it
  5. Sharing
  6. Retention
  7. Security
  8. Your rights
  9. International transfers
  10. Children
  11. Changes and contact

Other documents

  • Terms of Use
  • Privacy Policy
  • Data Privacy
  • Biometric Information Privacy
  • GDPR

Scope

This Privacy Policy explains how GrayPass, Inc. ("GrayPass," "we," "us"), handles personal data across the surfaces it operates for the public: this website, and the GrayPass platform, meaning the SDK, API, hosted console, and non-production sandbox that our customers integrate.

When a customer integrates GrayPass into their application, that customer is the controller of their end users' data and this policy applies to our role as their processor. Product-level detail lives in the Data Privacy document; region-specific detail lives in the GDPR and BIPA documents. Where those documents are more protective, they win.

What we collect

Website visitors

  • Standard server logs: IP address, user agent, requested pages, timestamps. Used for security and reliability, kept briefly.
  • This website does not load an analytics client or advertising tracker. Standard hosting logs may be used for security and reliability.
  • Evaluation requests: your name, work email, company, product description, team location, funding range, verification practices, budget acknowledgment, and any optional context you submit. We store form submissions in Supabase to review your request and follow up. When notifications are enabled, Resend delivers a copy to our founders, using your email as the reply address.

Console and sandbox users

  • Account basics: email address, organization, and API key metadata.
  • Behavioral timing signals collected under the customer's lawful basis during enrollment and sessions: keystroke intervals, pointer and touch dynamics, scroll cadence, and focus or visibility rhythm, reduced to derived features on the device.
  • Derived artifacts: the Brainprint template and decision logs with reason codes.

End users of our customers' applications

  • The same categories of timing signals and derived artifacts, processed on the instructions of the customer whose application you are using.
  • We never receive the content you type, the pages' contents, or your identity beyond the pseudonymous identifier the customer assigns.

What we never collect

  • Typed content. The SDK reads the timing between keys, never which keys.
  • Raw behavioral streams at rest. Streams are reduced to derived features on the device; the raw series is discarded.
  • Photographs, voice, fingerprints, face geometry, or any static biometric image.
  • Data from advertising brokers. We do not sell or share personal data for advertising.

Why we process it

  • To provide the platform: evaluating whether the expected person is still in control before a consequential action, and returning decisions to the applications you use.
  • To secure the service: rate limiting, abuse detection, and incident investigation.
  • To improve the service: aggregate operational statistics about coverage, decisions, challenge outcomes, and measured request timing. Research donation requires separate, explicit opt-in consent.
  • To communicate with you: transactional email about your account, replies to evaluation requests, and product updates you can opt out of.

Where GDPR applies, our lawful bases are set out in the GDPR document. Customers determine the lawful basis for their integration and must obtain any additional consent their jurisdiction requires. Research donation requires explicit consent.

Sharing

We do not sell personal data. We share it only with:

  • Amazon Web Services for hosting, database, key management, and transactional email.
  • Supabase for website evaluation-request storage, and Resend for founder notifications when enabled.
  • Twilio for SMS step-up verification when a customer enables it.
  • Our customers, for their own end users' sessions: decisions, typed assurance, and reason codes, never raw signals.
  • Authorities, if legally compelled; we will notify affected users where the law allows.
  • A successor entity in a merger or acquisition, under this policy's commitments.

Retention

  • Raw behavioral streams: not retained. Reduced on the device, then discarded.
  • Sandbox environment data: one (1) day by default.
  • Live environment data: ninety (90) days by default, configurable per environment.
  • Public demo data: twenty-four (24) hours by default, with immediate deletion available on request.
  • Brainprint templates: retained until the subject is revoked or deleted.
  • After a customer relationship ends, its environments and data are deleted within thirty (30) days.

Security

Templates and stored request material are encrypted at rest with keys held outside the database. Proof signing keys live in AWS KMS. Subject identifiers are keyed per tenant and environment, and production transport uses TLS with HSTS. For security questions or vulnerability reports, contact us.

Your rights

Wherever you are, you can ask us to access, correct, export, or delete personal data we hold about you, and you can withdraw consent for anything consent-based (including behavioral enrollment) without losing access to unrelated features.

Deletion removes the Brainprint template, terminates live sessions, clears subject metadata, and revokes outstanding proofs. A data export describes the template's presence but does not expose the template vector.

Send requests to tools@graypass.org with the subject "Data request"; we respond within thirty (30) days. If you are an end user of a customer's application, we will route your request to that customer or act on their instruction, as the law requires.

EU/EEA, UK, and Swiss users have the additional rights described in the GDPR document. Illinois residents should also read the BIPA policy.

International transfers

We are a U.S.-based service. Before EU/EEA, UK, or Swiss personal data is transferred to the United States, the customer controller and GrayPass must put the legally required transfer mechanism and data-processing terms in place. Contact tools@graypass.org before enabling that population.

Children

The Services are not directed to children under 16, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

Changes and contact

When this policy changes materially, we will post the new version here with a new effective date and notify account holders by email. We will not retroactively weaken commitments for data already collected.

Privacy questions and requests: tools@graypass.org (subject "Privacy").

Vulnerability reports: tools@graypass.org.

Protect the action that matters most.

Request Evaluation
GrayPass

Product

  • Platform
  • Research
  • Story
  • Demo | Console
  • Request Evaluation

Legal

  • Terms of Use
  • Privacy Policy
  • Data Privacy
  • BIPA
  • GDPR

Connect

  • X
  • LinkedIn
  • founders@graypass.org
© 2026 GrayPass Inc.