Privacy Policy
Last updated: March 14, 2026
1. Information We Collect
When you create an account, we collect your name, email address, and phone number. When you use our service, we collect data about your usage including AI session counts, message counts, and token consumption for billing and service management purposes.
2. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the GrassWeb platform
- Send you account-related communications including email verification, security alerts, and service updates
- Send SMS messages to the phone number you provide (see SMS Consent below)
- Track usage for billing, cost attribution, and tier enforcement
- Improve and develop our services
3. SMS Consent
By providing your phone number during registration, you consent to receive SMS messages from GrassWeb including account notifications, security alerts, and service updates. Message and data rates may apply. Message frequency varies. This consent is a condition of using the service.
4. Data Storage and Security
Your account data is stored in a secured PostgreSQL database. Any credentials or secrets you provide to the website builder (API keys, connection strings, etc.) are encrypted at rest using AES-256-GCM and stored on isolated container filesystems — never in the database. We use industry-standard security measures to protect your data.
5. Third-Party Services
We use the following third-party services to operate GrassWeb:
- Anthropic (Claude AI) — powers the website builder. Your chat messages are sent to Anthropic's API for processing. Refer to Anthropic's privacy policy for their data handling practices.
- Microsoft Azure — hosts our infrastructure including container services, file storage, and databases.
- SendGrid — delivers transactional emails (verification, notifications).
6. Data Retention
We retain your account data for as long as your account is active. Website files are stored on persistent cloud storage and remain available until you delete your site or account. Usage records are retained for billing purposes.
7. Your Rights
You may request deletion of your account and associated data by contacting us. Deleting your account will remove your user record, all associated sites, and stored credentials.
8. Contact
For privacy-related inquiries, contact us at info@thednsgroup.com.