Legal
Privacy Policy
Last updated: September 21, 2026
1 · Data controller
The data controller is JOE ASSISTANT (SAS), SIREN 944 391 135, 200 rue de la Croix Nivert, 75015 Paris, France — [email protected]. This policy explains what we collect when you use GripForge (gripforge.ai), its API, and its MCP connector — why, for how long, and your rights under the EU General Data Protection Regulation (GDPR).
2 · Data we collect, purposes and legal bases
- Account data — email address, salted password hash (scrypt), plan, API key, workspace membership. Purpose: providing the Service, authentication, metering. Legal basis: performance of a contract (art. 6(1)(b)).
- Content you create or upload — prompts, 3D models, textures, VFX, HUDs, game kits and projects, together with their names, tags and thumbnails. Stored in your workspace Library so you can retrieve them later. Legal basis: performance of a contract.
- Usage and metering data — credit and attach counts, generation job records, API and MCP request logs (timestamps, HTTP status, tool name, file names, IP address, user agent). Purpose: quota enforcement, reliability, debugging, abuse and fraud prevention. Legal basis: contract and legitimate interest (art. 6(1)(f)).
- Billing data — handled entirely by our Merchant of Record, Paddle, who acts as an independent controller for the purchase (identity, payment method, invoice). We receive transaction status and credit grants, never card numbers. See Paddle’s privacy policy for their processing.
- Product analytics — page views, feature usage and front-end errors via PostHog, hosted in the European Union. Data is pseudonymous; we do not sell it or use it for advertising. Legal basis: legitimate interest in improving the product.
- Audience measurement — our own cookieless page-view counter: the page path, the referring site, utm parameters, device and browser family. Unique visitors are counted with a hash of IP address and browser salted with a random value that changes every day and is then deleted; the IP address itself is never stored. Nothing is kept in your browser, and nothing is sent when Do-Not-Track or Global Privacy Control is on. Legal basis: legitimate interest (audience statistics exempt from consent).
- Support correspondence — emails to [email protected] and messages sent through the in-app support chat. Support messages, and an alert when an account is created or a purchase is made, are relayed to our internal Slack and Discord channels so we can answer. Legal basis: legitimate interest / contract.
3 · Your prompts and your assets
Where they live. Assets you generate or upload are stored in your workspace Library until you delete them or close your account. They are private by default: no one outside your workspace can list or open them. A link to an asset is signed and time-limited.
When they become public. An asset becomes publicly visible only if you publish it — to the community showcase, or through a Game Kit project you mark as published. Publishing is always an explicit action on your side, and you can unpublish.
What leaves our servers. Generating an asset sends your prompt, and where the feature requires it a reference image or a low-resolution render of the region being worked on, to the AI provider that performs that step (listed in Section 4). Providers are bound by their API terms; we select providers that do not train on API data. We never sell your content, and we do not use your models or prompts to train our own machine-learning models.
Prompts you write to the GripForge agent. When you give the agent a request — in the GripForge CLI or in the prompt box of the site — we keep the text of that request, the model that handled it, the tokens used and its cost, for 365 days. We use this record to run and bill the service, to investigate problems you report and to improve how requests are routed. It is then deleted.
4 · Processors and recipients
Personal data and content are shared only with the providers needed to run the Service:
- Hosting: OVHcloud (servers in the European Union);
- CDN, DNS and security: Cloudflare (traffic filtering, bot protection);
- Payments & invoicing: Paddle (Merchant of Record, independent controller);
- Analytics: PostHog Cloud EU;
- Advertising measurement: Google Ads (Google Ireland Ltd), only to count sign-ups coming from our own campaigns — see Section 7;
- AI generation and analysis: Meshy and Tripo (image-to-3D and text-to-3D), OpenAI and xAI (concept images, textures, HUD and screen art), Anthropic (placement scoring and orientation checks), Replicate (specific generation models). Each receives only the prompt and the images needed for the step it performs;
- Transactional email: Resend;
- Support and operational alerts: Slack and Discord (internal channels);
- Version control export: Diversion, only when you use that export.
Where a provider processes data outside the EU/EEA, transfers rely on appropriate safeguards (adequacy decisions or Standard Contractual Clauses). We never sell personal data.
5 · The MCP connector and the API
GripForge exposes its tools to AI agents over the Model Context Protocol at https://gripforge.ai/mcp and over the REST API. A connected agent authenticates with your API key and acts strictly inside the workspace that key belongs to: it can create, read and delete assets there, and nothing outside it.
We receive what the agent sends us for a tool call — the prompt and parameters — plus the request log described in Section 2. We do not read, request or store your conversation history, your assistant’s memory, or any file on your machine we were not explicitly given. Revoking a key in your account page cuts the connector’s access immediately.
6 · Retention
- Account data: for the life of the account, then deleted within 30 days;
- Library assets and projects: until you delete them or close your account; deleting an asset removes its bytes from storage;
- Generation job records: 12 months, for billing and dispute resolution;
- API, MCP and audit logs: up to 12 months, then deleted or anonymized;
- Support conversations: 24 months;
- Billing records: kept by Paddle per statutory accounting durations;
- Analytics: per PostHog EU retention settings, capped at 12 months.
- Audience measurement: 25 months (daily salts: deleted the next day).
7 · Cookies and local storage
Strictly necessary, first-party (no consent banner required): gf_session (httpOnly, 30 days) for authentication, gf_workspace (1 year) for the workspace you last opened, and gf_signup (15 minutes) set once when an account is created. Interface preferences (language) and a support-chat identifier live in your browser’s localStorage. The Paddle checkout, when opened, sets its own cookies necessary for payment processing.
Campaign attribution, first-party: gf_attrib (30 days) remembers how you first reached the site — UTM parameters, a Google Ads click identifier, a creator code and the referring page. It is read once, when you create an account, so we know which campaign brought you; it is never shared and does not track you across other sites.
Advertising measurement (Google Ads): we run a Google Ads conversion tag that lets Google count how many sign-ups a campaign produced. In the EEA, the United Kingdom and Switzerland the tag runs in consent-denied mode: it sets no cookie, reads none, and sends only anonymous, cookieless pings that Google uses for aggregate modelling. Elsewhere it may set Google’s conversion cookies (_gcl_*, 90 days). We do not use it for personalised advertising or remarketing. Google’s privacy policy: policies.google.com/privacy. We set no other advertising or cross-site tracking cookies.
8 · Security
Passwords are stored as salted scrypt hashes; sessions are server-side with httpOnly cookies; transport is TLS-encrypted end to end; asset links are signed and expire; API keys can be regenerated at any time. Access to production systems is limited to authorized personnel. No method is 100% secure — in case of a breach affecting your data we will notify you and the CNIL as required by articles 33–34 GDPR.
9 · Your rights
You have the right of access, rectification, erasure, restriction, portability, and objection (including to legitimate-interest processing), and the right to withdraw consent where processing is based on it. Write to [email protected] — we answer within one month. Deleting your account removes your personal data and your Library within 30 days, subject to legal retention duties. You may lodge a complaint with the French supervisory authority, the CNIL (cnil.fr), or with the authority of your country of residence.
10 · Children and changes
The Service is a professional tool not directed at children under 15; we do not knowingly collect their data. We may update this policy; material changes will be announced on this page and, for account holders, by email.