1. Who We Are
Graystone Security Solutions LLC is incorporated in the State of Wyoming and does business as Graystone Solutions. In this policy, "we," "us," and "our" mean Graystone Security Solutions LLC.
- Website: https://graystone.solutions
- Registered Agent: 30 N Gould St Ste R, Sheridan, WY 82801, USA
- Privacy Contact: privacy@graystone.solutions
Graystone AI Solutions is the name for the family of artificial intelligence products that we produce. Individual products are made available under their own product names. This policy applies to all of them.
2. Scope of This Policy
This policy applies to:
- The Graystone Solutions website at https://graystone.solutions
- All Graystone AI Solutions products, including our mobile applications
- The AI Services — the assistant features that process material you submit
This policy does not cover:
- Data processed under a signed Client Services agreement for IT managed services or security consulting. That data is governed by your contract.
- Content that stays in Your Storage and never reaches us. See Section 5.
3. Definitions
| Term | Meaning | |---|---| | The Assistant | The artificial intelligence assistant in a Graystone AI Solutions product | | AI Services | The processing features the Assistant performs on material you submit | | Your Storage | The container that holds your content, on hardware or in a cloud account that you control | | Submitted Item | A file, recording, or document that you knowingly send to us for a specific processing operation | | The Relay | Our hosted service that resolves identities and negotiates shares between users |
4. What We Collect
4.1 Website Visitors
When you visit our website we may collect your IP address and browser type for security and spam prevention, cookies necessary for site functions (Section 11), and information you submit through a contact form.
We do not use advertising trackers, third-party analytics platforms, or behavioral profiling tools on this website.
4.2 Account and Identity Data
When you create an account we collect:
- Your email address and an account identifier
- Your name, if you give it to us
- Login timestamps and session records
- Your subscription and entitlement status
Sign in with Apple. If you sign in with Apple, Apple gives us an account identifier and an email address. If you choose to hide your email address, that address is an Apple private relay address, and we never receive your real address. If you choose not to share your name, we do not receive it and we do not ask again. We do not require more than Apple provides.
4.3 Session Identifiers
When the Assistant performs a processing operation, we generate a session identifier. It tells our systems which request the result belongs to. It is not linked to the content of the material you submit.
4.4 Submitted Items
The AI Services are opt-in and purchased. When you use them, you choose a specific item and a specific operation — for example, a voice recording to be transcribed and summarized. We receive that item for the duration of that operation only. Section 6 describes exactly what happens to it.
We do not collect your content in the background. We receive an item only when you send it.
4.5 Assistant Memory (optional)
By default the Assistant does not remember your conversations. Memory is an optional paid feature. If you turn it on, we store the facts and preferences you choose to give the Assistant, so that it can use them in later sessions. You can view, edit, and delete these entries at any time, and you can turn the feature off. Turning it off deletes the stored entries.
4.6 Billing Data
We do not store your payment card details. Where you purchase through the Apple App Store, Apple processes the payment and we receive a purchase record. Where you purchase on our website, our payment processor handles the payment and we receive your email address, the item purchased, and the processor's transaction identifier.
4.7 What We Do Not Collect
We do not collect your address book. We do not collect your location. We do not track you across other apps or websites. We do not build advertising profiles.
5. Your Storage — Content We Never Receive
Graystone AI Solutions products are built so that your content stays under your control. This section prevails over any conflicting statement elsewhere in this policy.
5.1 You Hold the Keys
Content in Your Storage is encrypted on your device using strong, industry-standard cryptography. The encryption keys are generated on your device and stay on your device. We never receive your keys. We operate no key escrow.
5.2 We Cannot Read, Recover, or Reset It
Because we do not hold your keys, we cannot read your stored content, restore it, or reset it for you. If you lose your device and your keys and you have no backup, that content may be permanently unrecoverable. Safeguarding your keys and any recovery material is your responsibility.
5.3 Storage You Choose
Your Storage may sit on your own device, on your own hardware, or inside a container in a personal cloud account that you control. We have no access to those accounts. Only encrypted data is placed there. Your chosen provider's own privacy terms govern how it handles that encrypted data.
5.4 Sharing Between Users
When you share content with another user, the transfer runs directly between your environment and theirs over an open federation protocol. The content is not copied to us and we are not a party to the transfer. We do not process shared content.
5.5 The Relay
To help you find and reach another user, we operate the Relay. The Relay resolves identities and negotiates shares. It is designed so that:
- Identifiers are stored in blinded form
- Records carry an enforced expiry and are removed when it passes
- No single operation exposes both parties to a request
The Relay never receives file content and never receives encryption keys.
5.6 The Outer Limit of What We Can See
Across the products described in this section, the data we may hold is limited to your account record, your published public key, blinded identifiers you publish so others can find you, and minimal routing metadata for an item in transit. That is the outer limit.
6. How Processing Works — Hold, Process, Return
This section describes the AI Services. It is the core of this policy and it is short on purpose.
6.1 The Free Configuration Stores Nothing
In the default free configuration the Assistant does not retain your conversations and we do not retain your content. Nothing is kept.
6.2 A Processing Operation
When you use a paid AI Service:
- You choose an item and an operation, and you send it.
- We hold that item only while the operation runs.
- The operation runs on models that we host on infrastructure we operate.
- The result returns to your device.
- We ask whether you want to keep the original in Your Storage. Your answer decides. We do not keep it either way.
Hold, process, return. We do not retain your Submitted Item after the operation finishes, and we never claim ownership of it. Your content is yours.
6.3 No Third-Party AI Provider Receives Your Content
Every artificial intelligence model used to process a Submitted Item runs on infrastructure that we operate, inside our own environment. We do not send your Submitted Items to any third-party artificial intelligence provider. This is a design decision, not a preference, and Section 9 reflects it.
6.4 We Do Not Train on Your Content
We do not use your content, your conversations, or your Submitted Items to train, fine-tune, or evaluate any artificial intelligence model. This applies to us and to any party that operates infrastructure for us. There is no opt-out to find, because there is nothing to opt out of.
6.5 Human Review
Our staff do not read your content as a matter of routine. Access is possible only in these situations:
- We investigate a specific report of abuse or a violation of our Terms
- We respond to a security incident affecting the service
- We are required to by law, after review of the demand
Access is limited to named staff, is logged, and is limited to what the situation requires. For content in Your Storage, access is not possible at all, because we hold neither the content nor the keys.
6.6 No Automated Decisions About You
We do not make any decision that produces legal effects for you, or that affects you in a similarly significant way, by automated processing alone. The Assistant produces output for you to use. It does not decide anything about you.
7. How We Use Your Data
We use the data we collect to:
- Create your account and authenticate you
- Perform the processing operations you request
- Deliver the result to your device
- Operate the Relay so you can reach other users
- Process payments and maintain your entitlements
- Detect and prevent abuse, fraud, and security incidents
- Meet our legal and tax obligations
- Answer your support requests
We do not sell your personal data. We do not use your data to train artificial intelligence models. We do not serve advertisements.
8. Data Retention
| Data | Retention period | |---|---| | Submitted Items | Deleted when the operation finishes. In no case retained beyond 24 hours, which covers retry and failure paths | | Conversation content, free configuration | Not retained | | Assistant memory entries, if enabled | Until you delete them, turn the feature off, or delete your account | | Account and identity data | Life of the account, then deleted within 30 days of your deletion request | | Session identifiers | 90 days | | Content in Your Storage | Held by you. Not held by us | | Relay records | Enforced expiry. Removed on retrieval or when the expiry passes | | Published public keys and blinded identifiers | Until you remove them or delete your account | | Payment and tax records | 7 years, as required by law | | Security and access logs | 90 days | | Support correspondence | 24 months |
9. Who We Share Your Data With
We share data only as far as is necessary to run the service.
| Recipient | Purpose | Data shared | |---|---|---| | Cloud infrastructure provider | Hosting, compute, and the Relay | Account and session data; a Submitted Item during the operation | | Apple | Sign in with Apple; App Store purchases and subscriptions | Account identifier; purchase records | | Payment processor | Purchases made on our website | Email address; transaction data |
No third-party artificial intelligence provider appears in this table, because none receives your content. See Section 6.3.
Every processor we use is bound by contract to handle your data in line with applicable privacy law. We do not share your data with anyone else without your explicit consent, except where we are required to by law. Our current list of processors is available on request from privacy@graystone.solutions.
10. Data Security
Your data is protected by encryption in transit and at rest, authentication with multi-factor options, role-based access control that limits who can reach data, dedicated secrets management, and access logging.
For content in Your Storage, security rests on client-side encryption under keys we never hold. A full compromise of our systems would not expose that content.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at privacy@graystone.solutions.
11. Cookies and Similar Technologies
Website. We use only essential cookies, for authentication and session management. They do not track you across other websites and are not used for advertising. If you sign in, your session token is held in your browser's session storage and is cleared when you sign out or close your browser.
Applications. Our applications do not use advertising identifiers and do not track you across other apps or websites. You will not see a tracking permission request from us, because we have nothing to ask for.
12. Your Rights
12.1 Access
You may ask for a copy of the personal data we hold about you.
12.2 Rectification
You may ask us to correct data that is inaccurate or incomplete.
12.3 Erasure
You may ask us to delete your personal data. You can delete your account from inside the application at any time, without contacting us. Deletion removes your account record, your Assistant memory entries, and your published identifiers.
12.4 Portability
You may ask for your data in a structured, machine-readable format.
12.5 Restriction and Objection
You may ask us to restrict processing, or object to processing that we carry out on the basis of our legitimate interests.
12.6 Withdrawing Consent
Where we rely on your consent, you may withdraw it at any time. Turning off Assistant memory is one example. Withdrawal does not affect processing that already took place.
12.7 California Residents (CCPA and CPRA)
If you live in California you have the right to know what personal information we collect and why, the right to delete it, the right to correct it, and the right to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA. We will not discriminate against you for exercising any of these rights.
12.8 Your Rights and Your Storage
Because we do not hold your keys or your stored content, a request for access, portability, or erasure can only reach the limited data we actually hold — see Section 5.6. Your stored content is already under your sole control. You access, export, and delete it directly, through the application and through the storage you chose.
12.9 How to Exercise Your Rights
Use the controls in the application first. They are immediate. To make a manual request, email privacy@graystone.solutions with your name, the email address on your account, and a description of what you want. We may ask you to verify your identity before we act, to make sure we do not disclose your data to somebody else.
We answer within 30 days. For a complex request we may extend this by up to two further months, and we will tell you if we do. Removal from encrypted backup archives may take up to 90 days, in line with our backup rotation. Payment records that we must keep by law are excluded from erasure.
13. EEA and UK Users — GDPR
This section applies if you are in the European Economic Area or the United Kingdom. It adds to the rest of this policy.
13.1 Our Role
Our role changes with the data, and the third case below is the one worth reading.
- We are the controller for your account, identity, session, and billing data, and for a Submitted Item during the processing operation you request.
- Content in Your Storage is outside this policy. It never reaches us. For that content we are neither a controller nor a processor.
- For a share between two users' own environments, we are not a party. The transfer runs directly between you and the other user. We do not process the shared content and we are not a controller or processor for it.
13.2 Legal Basis for Processing
| What we process | Legal basis (Article 6) | |---|---| | Account creation and authentication | Performance of a contract | | A processing operation you request | Performance of a contract | | Payments and subscription management | Performance of a contract | | Assistant memory | Your consent, which you may withdraw | | In-app update notices and marketing email | Your consent, which you may withdraw | | Security, abuse prevention, service integrity | Our legitimate interests | | Payment and tax records | Compliance with a legal obligation |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and we will explain that assessment on request.
13.3 International Transfers
We are established in the United States. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum, and we apply additional technical measures — principally encryption and the fact that content in Your Storage never leaves your control.
Where our infrastructure provider offers processing regions inside the EEA, we select them for EEA users, so that personal data stays in the region.
13.4 Our Representatives in the EEA and the UK
[EDITORIAL MARKER — MUST BE COMPLETED BEFORE THE SERVICE IS OFFERED IN THE EEA OR THE UK. DO NOT PUBLISH THIS PAGE WITH THIS BLOCK IN PLACE.]
Under Article 27 of the GDPR and Article 27 of the UK GDPR, we appoint a representative in the European Union and a representative in the United Kingdom. Insert the name, postal address, and contact email of each representative here. If the service is not offered in these territories at launch, replace this section with a statement to that effect and restrict App Store availability accordingly.
13.5 Personal Data Breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we notify you directly and without undue delay, and we tell you what happened and what to do about it.
13.6 Complaints
If you believe we have processed your data unlawfully, you may complain to your supervisory authority — in the EEA, your national Data Protection Authority (https://edpb.europa.eu); in the UK, the Information Commissioner's Office (https://ico.org.uk). In the United States you may contact the Federal Trade Commission (https://ftc.gov). We ask you to contact us first at privacy@graystone.solutions, so that we have the chance to put it right.
14. Age Requirement
Graystone AI Solutions products are for adults. You must be at least 18 years old to create an account. We do not offer the service to anyone under 18 and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact privacy@graystone.solutions and we will delete it.
15. Changes to This Policy
We will update this policy as the law, our services, and our data practices change. Where a change is material we will tell you, by a notice in the application or by email to the address on your account. The version number and effective date at the top of this page always show which version is current, and Section 17 records the history.
16. Contact
Email: privacy@graystone.solutions
Mail: Graystone Security Solutions LLC 30 N Gould St Ste R Sheridan WY 82801 USA
17. Version History
| Version | Effective | Change | |---|---|---| | 3.0 | August 2026 | Rewritten for the public product launch. Added the hold-process-return description of AI processing, the statement that no third-party AI provider receives content, human review conditions, automated decision-making, a full GDPR section with legal bases and transfer mechanism, and Apple sign-in and in-app deletion disclosures. Age requirement set at 18. | | 2.1 | August 2026 | Added the end-to-end encrypted services article. | | 2.0 | May 2026 | First published version. |
This policy was last updated August 2026. It does not constitute legal advice. You should seek independent legal counsel to confirm compliance with the privacy law that applies in your jurisdiction.