GrandView™
Pricing
Sign in
GrandView

Compliance

Last updated: August 7, 2026

GrandView is designed with privacy and compliance in mind. This page summarizes the regulatory frameworks we follow and the measures we take to comply with them.

1. Regulatory Overview

FrameworkScopeStatus
GDPREU/EEA residentsCompliant
CCPA/CPRACalifornia residentsCompliant
COPPAChildren under 13Compliant (age gate at signup)
ePrivacy DirectiveEU/EEA cookie useCompliant (essential cookies only)

2. GDPR Compliance

The General Data Protection Regulation applies to our processing of EU/EEA residents' data. Our compliance measures include:

  • Lawful basis — Consent (signup) and legitimate interest (service operation)
  • Data minimization — We collect only what is necessary to provide the service
  • Purpose limitation — Data is used only for the purposes described in our Privacy Policy
  • Storage limitation — Defined retention periods for all data categories (see Privacy Policy §6)
  • Data subject rights — Full self-service for access, portability, rectification, and erasure via Your Data Rights
  • Breach notification — 72-hour notification commitment
  • Data protection by design — Privacy-first architecture with no tracking cookies, no third-party analytics, essential data collection only

3. CCPA/CPRA Compliance

The California Consumer Privacy Act and California Privacy Rights Act apply to California residents. Our compliance includes:

  • Right to know — Clear disclosure of data collection practices
  • Right to delete — Self-service account deletion that removes all data
  • No sale of data — We do not sell or share personal information with third parties for advertising or marketing
  • Non-discrimination — Equal service regardless of privacy choices

4. COPPA Compliance

The Children's Online Privacy Protection Act protects children under 13. Our compliance measures:

  • Account creation requires users to be at least 13 years old
  • Users 13–17 must have parental or guardian consent
  • We do not knowingly collect data from children under 13
  • Reports of underage accounts are investigated and deleted promptly

5. ePrivacy & Cookies

The ePrivacy Directive regulates electronic communications and cookie use in the EU/EEA:

  • GrandView uses only essential authentication cookies — no consent required under ePrivacy exemption for "strictly necessary" cookies
  • No tracking cookies, advertising cookies, or analytics cookies are used
  • No third-party scripts that set cookies (no Google Analytics, no Facebook Pixel, no advertising SDKs)
  • An informational cookie notice is displayed to inform users about our minimal cookie use

6. Third-Party Data Processing

We share data with third-party providers only as necessary to deliver the service:

ProviderPurposeData SharedTheir Compliance
AnthropicAI assistanceOutline text (no PII)SOC 2, no training on API data
DeepgramLive transcriptionAudio stream (no PII)SOC 2, mip_opt_out enabled (no retention, no training)
OpenAIAudio transcription (BYOK)Audio file (no PII)SOC 2, no training on API data
StripePaymentsEmail, planPCI DSS Level 1, SOC 2
ResendEmailEmail, nameSOC 2
Fly.ioHostingWeb trafficSOC 2

7. Data Residency

GrandView application data is hosted on Fly.io infrastructure. Primary data processing occurs in the United States. AI processing via Anthropic and audio transcription via Deepgram occur in the United States.

8. Contact

For compliance questions or concerns:

Email: contact@grandview.dev

Privacy Policy Terms of Service Your Data Rights Home
GrandView
Pricing Terms of Service Privacy Policy Your Data Rights Security Accessibility Compliance Troubleshooting

© 2026 Eitel, LLC

GrandView™ · Outline your thinking.