Privacy Policy
Last updated: 18 July 2026
1. Who We Are (Data Controller)
This Privacy Policy explains how 4 BEES D.O.O. ("grappes", "we", "us"), a company registered in the Republic of Serbia (registration number / matični broj 21379450, PIB 110720700, registered office Kronštatska 5, 11000 Beograd (Savski Venac), Serbia), collects and processes personal data in connection with grappes.ai (the "Service").
For the purposes of the EU General Data Protection Regulation (GDPR) and the Serbian Law on Personal Data Protection, grappes is the data controller for personal data processed about your use of the Service.
Data Protection Contact: [email protected]
2. What Data We Collect
Account data. Email address, name (if provided), password (stored hashed), and authentication identifiers (including Google OAuth identifiers if you sign in with Google).
Content data. The prompts, files, and other inputs you submit ("Inputs"), and the AI-generated outputs ("Outputs"), together with associated session, project, and conversation data.
Voice and audio data. If you use voice dictation, the audio you record is captured and sent to our transcription provider to convert it into text; the resulting text is then processed like any other Input. See Section 4.
Memory and preferences. Preferences and patterns we store at the profile and project level to personalize the Service (see Section 8).
Usage and technical data. Logs of requests, models used, token usage, timestamps, latency, device and browser information, IP address, and similar diagnostic data.
Payment-related data. Subscriptions and payments are handled by our Merchant of Record (see Section 6). We receive limited billing-related information (such as plan, status, and country) but we do not collect or store your full payment card details.
Cookies and similar technologies. As described in our Cookie Policy.
3. How We Use Your Data and Legal Bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide and operate the Service (process your Inputs, return Outputs, manage sessions/projects) | Performance of a contract |
| Authenticate you and secure accounts | Performance of a contract / legitimate interests |
| Process subscriptions and enforce plan limits | Performance of a contract |
| Personalize via memory and preferences | Performance of a contract / consent where required |
| Prevent abuse, fraud, and prohibited content; enforce our policies | Legitimate interests / legal obligation |
| Improve and develop the Service | Legitimate interests (we minimize and, where required, seek consent) |
| Communicate with you (service messages, support) | Performance of a contract / legitimate interests |
| Marketing communications (if any) | Consent |
| Comply with legal obligations | Legal obligation |
We do not sell your personal data.
4. AI Providers and How Your Inputs Are Processed
To deliver the Service, we transmit your Inputs (and necessary context) to third-party AI providers that generate Outputs. These providers act as processors or independent controllers depending on their role and terms. The providers may include, among others, Anthropic, OpenAI, Google, xAI, and Moonshot AI (Kimi), as well as image and video generation providers (see the full list in Section 5). In particular, when you use voice dictation, the audio you record is sent to OpenAI (Whisper) for transcription; when you use image or video generation, your prompt is sent to the relevant image or video provider. We share only what is needed to fulfill your request. We endeavor to use providers that offer appropriate data-protection terms, including not training on your data where such options are available, but their handling is also governed by their own privacy terms.
5. Sub-processors
We use the third-party service providers below ("sub-processors") to operate the Service. Depending on the features you use, your data — which may include your Inputs and, where noted, your account email — is shared with them for the purposes described. This list is current as of the "Last updated" date and we will update it as our providers change.
- 4 BEES D.O.O. (our server) — application hosting and data storage; the primary server is located in Serbia.
- Anthropic — AI text generation and the context/orchestration model (United States).
- OpenAI — AI text and image generation, and voice-audio transcription (Whisper) (United States).
- Google — AI text and image generation, and Google sign-in (OAuth) (United States / EU).
- xAI — AI text generation and web retrieval for Deep Web Inspect (United States).
- Moonshot AI (Kimi) — context/intent processing and app/site build generation (processing may occur internationally, including in China).
- Recraft — logo and vector-graphics generation (United States).
- Runway — video generation (United States).
- Seedance (BytePlus) — video generation (processing may occur internationally, in the Asia-Pacific region).
- Polar (Polar Software, Inc.) — payments and Merchant of Record (European Union; checkout hosted off our domain).
- Cloudflare — DNS, content delivery, and reverse-proxy / security for the Service and hosted sites; processes traffic metadata including IP addresses (United States / global).
- DigitalOcean Spaces — object storage for generated media and published static sites (Amsterdam, EU).
- Porkbun — domain registration, only if you search for or purchase a domain through the Service (United States).
- Slack (Slack Technologies) — internal operational notifications, see below (United States).
Operational notifications. When you create an account, and when a subscription, top-up, or refund occurs, we send a short internal notification to our team via Slack that includes your email address and, for billing events, the plan and amount. This helps us operate and support the Service and relies on our legitimate interests.
Because several of these providers are located outside Serbia and the EEA, using the Service involves international transfers of personal data — see Section 7.
6. Payments (Merchant of Record)
Purchases (subscriptions, credit top-ups, and pay-as-you-go charges) are processed by Polar (Polar Software, Inc., polar.sh), which acts as Merchant of Record and as an independent controller of the payment data it collects from you through its hosted checkout. Their processing is governed by their own privacy policy. We recommend you review it.
7. International Transfers
The Service's primary server is located in Serbia, which is outside the European Economic Area (EEA). In addition, your data may be processed outside Serbia and the EEA — in particular by AI, storage, and infrastructure providers located in the United States and other countries (see Section 5). Where we transfer personal data internationally, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable. You may request more information about these safeguards using the contact details above.
8. Memory, Profiles, and Projects
The Service can store information at two levels to personalize your experience:
- Profile memory — preferences and patterns associated with you as a user (for example, tone, language, and working-style preferences).
- Project memory — context associated with a specific project you create.
You can view, edit, and delete what is stored in memory, and you can disable memory, through your account settings. Deleting memory removes the associated stored personalization data, subject to backups and legal-retention requirements described in Section 10.
9. How We Protect Data
We implement appropriate technical and organizational measures, including encryption in transit, access controls, hashed passwords, and monitoring. No system is perfectly secure; we cannot guarantee absolute security but we work to protect your data and to notify you and regulators of breaches as required by law.
10. Data Retention
We retain personal data for as long as needed to provide the Service and for legitimate or legal purposes:
- Account data — for the life of your account and a reasonable period after closure.
- Content data (Inputs/Outputs, sessions, projects) — until you delete it or close your account, subject to backup cycles (typically removed from backups within 30 days).
- Usage/technical logs — up to 12 months for security and diagnostics.
- Records required by law (e.g. accounting/tax via the Merchant of Record relationship) — for the legally required period.
When data is no longer needed, we delete or anonymize it.
11. Your Rights
Subject to applicable law, you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with a supervisory authority — in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection, and, if you are in the EEA, your local data-protection authority.
To exercise your rights, contact [email protected]. We will respond within the timeframes required by law.
12. Children
The Service is not directed to children under 18, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to This Policy
We may update this Policy. We will post the updated version with a new "Last updated" date and, for material changes, provide reasonable notice.
14. Contact
[email protected] — 4 BEES D.O.O., Kronštatska 5, 11000 Beograd (Savski Venac), Serbia.