Privacy policy
Last updated: 6 August 2026
This policy explains what Graft does with personal data. Graft is a job-costing tool for construction companies: you photograph supplier invoices and receipts, and we store them and the figures taken from them against your jobs.
Who we are
The data controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For anything in this policy, including access and deletion requests, contact [CONTACT EMAIL].
What we collect
- Account data — your email address, your display name, your role in your company, and (for workers) the hourly rate your admin sets.
- Documents you capture — photographs, PDFs and emailed attachments of invoices and receipts, and the text extracted from them.
- Job and cost data — jobs, budgets, cost codes, posted costs, logged hours, variations and client invoices.
- Billing data — your subscription status and plan. Card details are handled entirely by Stripe and never reach us.
We do not use analytics, advertising or third-party tracking cookies. The only cookie this website sets keeps you signed in.
Why we process it, and on what basis
To provide the service you have contracted for (performance of a contract), to take payment and prevent misuse (legitimate interests), and to meet accounting and tax obligations (legal obligation).
Who processes it for us
- Supabase — database, authentication and file storage. The Graft project is hosted in the EU.
- Anthropic — reads captured invoice images to extract supplier, date and amounts, and receives aggregate figures about your business(job names, supplier names, totals, budgets and invoice balances) to generate the insight shown on your overview dashboard. Data is sent for processing and is not used to train models.
- Postmark — inbound email (your company's forwarding address) and outbound email (client invoices, receipts you choose to send, and overdue notifications).
- Stripe — subscription billing. Stripe is the controller of your card data; we never see it.
- Vercel — hosting for this website.
Some of these providers operate outside the EEA. Where they do, transfers rely on the European Commission's standard contractual clauses.
How long we keep it
Receipts and the cost records made from them are retained for seven years, which reflects the period businesses are generally expected to keep accounting records. Removing a receipt inside the app hides it from your lists and keeps the underlying file; it is not erased.
If you want data genuinely erased, ask us — see below. We will do it unless we are legally required to keep it.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable form. You can also export your own costs and receipts at any time from Settings in the app, without asking us.
Write to [CONTACT EMAIL]. We will respond within one month. If you are unhappy with how we handle it, you can complain to your national data protection authority — in Ireland, the Data Protection Commission.
Changes
If we change this policy we will update the date at the top, and tell you in the app if the change is significant.