Grixo

Privacy Policy

Last updated Jul 27, 2026

BOSQUE DE CANELA - UNIPESSOAL LDA, NIPC 519494210, Avenida Atlântico 16, escritório 2.01, 1990-019 Lisboa, Portugal ("Grixo", "we", "us") is the data controller for personal data processed through https://grixo.co (the "Service"). This Policy follows the EU GDPR and Portuguese data protection law (Lei n.º 58/2019).

1. Data we collect

●      Account: name, email, password (hashed).

●      Billing: token packs bought and transaction records (card details are handled by our payment providers, not us).

●      Content: crew configurations, prompts and files you submit (Input) and the output your runs produce.

●      Credentials: your model provider and service keys, stored encrypted.

●      Usage & technical: runs dispatched, ledger movements, tokens reserved and debited, API key activity, IP address, device and browser data.

●      Cookies: see our Cookie Policy.

Please don't submit sensitive personal data as Input.

2. Why we use it (legal bases)

●      Provide the Service, run your crews and settle usage — *contract*.

●      Process payments and keep accounting records — *contract / legal obligation*.

●      Support, security, fraud prevention, service improvement — *legitimate interests*.

●      Marketing and non-essential cookies — *your consent*.

We do not use your Input or Output to train our own AI models.

3. AI models, connectors and sharing

To execute a run, we send your Input to the model providers and connected services that run uses — either ours or the accounts you register. We also share data with hosting, analytics, support and payment providers acting for us. We do not sell your data. We may disclose data where required by law.

4. International transfers

If data is transferred outside the EEA, we use appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision.

5. Retention

We keep data only as long as needed: account data for the life of your account; ledger and billing records as required by Portuguese law (generally 10 years for accounting records); run data and logs for a limited period proportionate to support and security needs.

6. Security

We use appropriate measures including encryption in transit and at rest, AES encryption of stored credentials, hashed API keys and access controls. No system is fully secure, but we work to protect your data and to notify breaches where legally required.

7. Your rights

Under the GDPR you can access, correct, delete, restrict or port your data, object to processing, and withdraw consent. Contact [email protected] to exercise these rights; we respond within one month. You may complain to the Portuguese data protection authority, CNPD (Comissão Nacional de Proteção de Dados, https://www.cnpd.pt), or the authority in your country.

8. Children

The Service is not for under-18s and we don't knowingly collect their data.

9. Changes

We may update this Policy and will note the "Last updated" date; material changes will be notified.

Contact

BOSQUE DE CANELA - UNIPESSOAL LDA · NIPC 519494210 · Avenida Atlântico 16, escritório 2.01, 1990-019 Lisboa, Portugal · +351 923 224 438 · [email protected]