close
Skip to content
Legal

Privacy Policy

Last updated · July 2026

This Privacy Policy explains how Graphify Labs ("graphify", "we") collects, uses, and protects information when you use our website, APIs, and services. By using graphify you agree to the practices described here.

Information we collect

We collect account information you provide (name, email, organization), usage and telemetry needed to operate the service, and content you choose to ingest into your graphs. We do not sell personal data.

How we use information

  • To provide, maintain, and improve the service.
  • To authenticate you and secure your account.
  • To communicate about updates, security, and support.
  • To comply with legal obligations.

Data you ingest

Content you ingest into graphify is processed to build your knowledge graph and is treated as confidential. On self-hosted and VPC deployments, this data never leaves your infrastructure.

The MCP connector

When you connect an AI assistant (for example Claude, Cursor, or another MCP-compatible client) to graphify over the Model Context Protocol, the assistant sends queries, such as a natural-language question or a repository identifier, to your workspace, and graphify returns results from your knowledge graph and, where you have enabled it, your stored memory. We process these queries only to answer them and operate the service. Connector access is scoped to your workspace and the repositories you have indexed; an assistant cannot reach repositories you have not added. On self-hosted and VPC deployments, connector traffic never leaves your infrastructure.

AI processing and training

We do not train models on your code. For the hosted service, code and content are sent to our LLM subprocessors (OpenAI and Anthropic) solely to produce results; under their API terms, neither we nor they train models on it. Self-hosted and on-device deployments do not send your code to these providers at all. See the full list of processors we use on our Subprocessors page.

Storage & security

Data is encrypted in transit and at rest. We maintain a SOC 2 Type II program and restrict access on a least-privilege basis. See our Security page for details.

Data retention

We keep account information while your account is active and as needed to provide the service. Content you ingest is retained until you delete it or close your account, after which it is removed from active systems within 30 days; backups expire on a rolling 90-day cycle. Operational logs and usage telemetry are kept for up to 12 months. On self-hosted deployments, retention is governed entirely by your own infrastructure. You can request deletion of your data at any time. A Data Processing Addendum (DPA) is available on request; contact our team.

Your rights

You may access, correct, export, or delete your personal data. To exercise these rights, or for any privacy question, contact our team.

Changes

We may update this policy; material changes will be announced in-product or by email. Continued use after an update constitutes acceptance.