Grid Collab

Privacy Policy

Privacy Policy

Effective date: 26 July 2026
Last updated: 26 July 2026

This Privacy Policy explains how Grid Collab (“Grid Collab,” “we,” “us,” or “our”) collects, uses, stores, shares, and deletes personal information when you use our services.

Grid Collab is a collaborative Instagram feed planning product available through:

(together, the “Service”).

Grid Collab is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc., Instagram, or Facebook. Instagram and Facebook are trademarks of their respective owners.

By creating an account or otherwise using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service.

Contact: support@gridcollab.app


1. Scope

This Policy applies to personal information we process in connection with the Service, including account registration, feed planning, collaboration features, safety tools, support requests, and related technical operations.

It does not apply to:

  • websites, apps, or services operated by third parties that we do not control (including Meta, Instagram, Facebook, Apple, Google, Expo, Convex, or Vercel), even if you reach them through the Service; or
  • information you share directly with other users outside Grid Collab.

Third-party services have their own privacy practices. You should review those policies separately.


2. Who we are and how to contact us

The Service is operated under the Grid Collab brand. For privacy questions, access or deletion requests, safety concerns, or complaints, contact:

We aim to respond to privacy requests within a reasonable period.


3. Information we collect

We collect information in three main ways: (a) you provide it; (b) it is generated through your use of the Service; and (c) it is received from connected platforms or infrastructure providers when you authorize those connections.

3.1 Account and identity information

Depending on how you sign up or sign in, we may collect:

Category Examples
App account credentials Grid Collab username (appUsername), password (stored only as a one-way hash; we do not store plaintext passwords)
Profile identifiers Display name, profile image URL (if provided by a connected provider)
Contact identifiers Email address, when provided by a connected identity provider
Instagram handle you supply Instagram username entered at sign-up for username/password accounts
Connected account identifiers Instagram user ID and username associated with OAuth sign-in

Username/password accounts are authenticated through Convex Auth. Passwords are protected with industry-standard hashing (Scrypt). We may store a synthetic internal account identifier derived from your username for authentication purposes; that identifier is used to operate sign-in and is not used as a public marketing email address unless you separately provide a contact email for support.

3.2 Instagram connection data

If you connect Instagram through official OAuth / Instagram Business Login (or related Meta authorization flows), we may collect and store:

  • Instagram user ID and username;
  • OAuth access tokens and token expiry metadata;
  • profile metadata returned by Meta’s official Graph APIs (for example biography, profile picture URL, follower/following/media counts where available); and
  • media metadata and media URLs needed to display and plan your feed grid (for example media IDs, media type, captions, thumbnail/media URLs).

Important limitation: In the production App Store release, Grid Collab does not scrape unofficial Instagram private APIs or public HTML endpoints to obtain feed data. Grid media for connected profiles is obtained through official, user-authorized APIs (or from content you upload yourself). Schema fields that historically contemplated a “public” cache source are not used to scrape Instagram in the shipping App Store product.

3.3 User-generated content and planner data

When you use planning and collaboration features, we process:

  • Custom photos you upload to a profile workspace (stored in our backend file storage);
  • Gradient placeholders and other non-image planner tiles;
  • Feed layout / ordered slot data describing how Instagram posts, uploads, and placeholders are arranged;
  • Comments on feed tiles;
  • Emoji reactions on feed tiles;
  • Profile share / invitation relationships (which users may view or collaborate on a profile workspace); and
  • Slot focus state used to reduce redundant push notifications when a collaborator is already viewing a tile.

Uploaded images are subject to technical limits (for example supported image types such as JPEG, PNG, WebP, HEIC/HEIF, and a maximum file size). Do not upload content you are not allowed to share.

3.4 Safety, moderation, and trust & safety data

We collect information when you use safety tools, including:

  • Content reports (reporter, target type, target identifiers, reason text, status, and timestamps); and
  • Blocks (who blocked whom, and when).

Reports may include information about other users or content. We use this data to review abuse, protect users, and meet legal or platform obligations.

3.5 Device, notification, and client technical data

Depending on platform and permissions you grant, we may process:

  • Expo push notification tokens for devices where notifications are enabled;
  • app version / client environment information needed to operate auth redirects and deep links (for example gridcollab:// mobile redirects);
  • authentication session tokens and related security state managed by our auth stack; and
  • server logs, error diagnostics, and operational telemetry needed to keep the Service available and secure (for example request failures, rate-limit or validation errors).

On mobile, the app may request OS permissions such as:

  • Photo library access — to add images to the planner;
  • Save to library — if you choose to save an image from the planner to your device; and
  • Notifications — to deliver activity alerts about shared feeds.

We do not request camera access for the shipping product configuration described in our mobile app settings. You can deny or later revoke permissions in your device settings; some features will not work without them.

3.6 Information we do not intentionally collect

We do not intentionally collect:

  • government ID numbers;
  • precise GPS location for advertising;
  • payment card details through Grid Collab at this time (paid plans shown on the website are informational until in-app purchase / billing is enabled); or
  • special-category sensitive data unless you voluntarily include it in content you upload or write (which we ask you not to do unless necessary).

If you choose to put sensitive personal information in captions, comments, photos, or report text, that information will be processed as part of that content.

3.7 Information from children

The Service is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children under that age. If you believe a child has provided personal information, contact support@gridcollab.app and we will take appropriate steps to delete it.


4. How we use information

We use personal information to:

  1. Provide the Service — create and authenticate accounts, save planner state, display grids, enable collaboration, and sync data across devices and clients.
  2. Connect authorized Instagram data — retrieve and cache authorized media and profile metadata so the planner can load reliably without repeatedly calling upstream APIs.
  3. Enable collaboration — honor profile shares, show invited collaborators the relevant workspace, and support comments, reactions, uploads, and layout changes within permitted relationships.
  4. Send notifications — deliver push notifications about feed activity (for example rearrangements, comments, or reactions), and suppress noisy notifications where focus state indicates a user is already viewing a tile.
  5. Protect safety and integrity — process reports and blocks; investigate abuse; remove or restrict content; suspend or delete accounts; prevent spam, fraud, and unauthorized access.
  6. Operate, secure, and improve infrastructure — maintain backups and storage as needed for reliability, debug failures, enforce technical limits, and protect against attacks.
  7. Communicate with you — respond to support requests, account deletion issues, privacy inquiries, and important service notices.
  8. Comply with law — meet legal, regulatory, tax, law-enforcement, or App Store / Play Store policy obligations.

We do not sell your personal information.

We do not use your content to train third-party generative AI models as a product feature of Grid Collab.


5. Legal bases (where applicable)

If you are in a jurisdiction that requires a legal basis for processing (for example the EEA, UK, or similar regimes), we generally process information on the basis of:

  • Contract — to provide the Service you request (account, planner, collaboration);
  • Legitimate interests — to secure the Service, prevent abuse, improve reliability, and communicate about the Service, balanced against your rights;
  • Consent — where required for optional permissions (for example push notifications or photo library access), or for certain marketing communications if we introduce them; and
  • Legal obligation — where we must retain or disclose information to comply with law.

You may withdraw consent for optional permissions in device settings or by contacting us. Withdrawal does not affect processing already completed lawfully.


6. How we share information

We share personal information only as described below.

6.1 Other users you collaborate with

If you invite collaborators or accept access to a shared profile workspace, those users can see content and activity within that shared context, which may include:

  • your app username and associated profile display information;
  • planned feed layout and tiles;
  • uploaded photos and placeholders on that workspace;
  • comments and reactions; and
  • Instagram grid media/metadata that the Service is authorized to show for that workspace.

Do not invite people you do not trust with that content. Profile owners control sharing relationships; blocking can remove mutual share access.

6.2 Service providers and infrastructure

We use third-party processors to run the Service, including:

Provider / category Typical role
Convex Application backend, database, file storage, authentication session infrastructure
Vercel Hosting for the marketing site and web planner
Expo / Expo push service Mobile build/distribution tooling and push notification delivery
Apple App Store / Google Play App distribution, review, and platform policy enforcement
Meta (Instagram / Facebook) Identity and media APIs when you connect those accounts

These providers process data on our behalf or as independent controllers for their own platform functions. Their processing is governed by their terms and privacy policies in addition to this Policy.

6.3 Legal, safety, and business transfers

We may disclose information if we reasonably believe disclosure is necessary to:

  • comply with law, regulation, legal process, or governmental request;
  • enforce our Terms of Service;
  • detect, prevent, or address fraud, security, or technical issues;
  • protect the rights, property, or safety of Grid Collab, our users, or the public; or
  • complete a merger, acquisition, financing, reorganization, or sale of assets (in which case we will require appropriate confidentiality and continue to protect personal information as described here, or provide notice of material changes).

6.4 Aggregated or de-identified data

We may create aggregated or de-identified statistics about Service usage (for example feature adoption counts) that do not reasonably identify you, and use or share those statistics for analytics, planning, or reporting.


7. Caching, storage, and international transfers

7.1 Caching of Instagram media

To improve performance and reduce timeouts, we may cache authorized Instagram media metadata and copy thumbnail/image bytes into our storage. Cached copies exist to operate the planner and may become stale until refreshed. Disconnecting Instagram or deleting your account is intended to remove associated active cache data as described in Section 9.

7.2 Where data is stored

Our primary application data is hosted through Convex and related cloud infrastructure. Web assets are hosted through Vercel. Push delivery uses Expo’s push infrastructure. These providers may process data in data centers located in the United States or other countries.

If you access the Service from outside those countries, your information may be transferred internationally. Where required, we rely on appropriate safeguards offered by our providers and applicable law.

7.3 Retention

We retain personal information only as long as needed for the purposes described in this Policy, including:

  • for as long as your account remains active;
  • for cached media while needed to provide planner functionality;
  • for safety/moderation records as needed to investigate abuse and protect users; and
  • for longer periods when required by law, dispute resolution, security, or fraud prevention.

When account deletion completes, we remove associated active service data as described below, subject to residual backups and legal holds.


8. Security

We implement technical and organizational measures appropriate to the nature of the Service, including:

  • hashed password storage for username/password accounts;
  • authenticated access controls for planner mutations and shared profile viewing;
  • scoped storage of Instagram access tokens on the server side (tokens are not returned in ordinary client “viewer” profile responses);
  • validation and size limits on uploads; and
  • access controls around share, block, and report relationships.

No method of transmission or storage is completely secure. You are responsible for keeping your password confidential and for using device-level protections (passcode, biometrics, OS updates). Notify us promptly at support@gridcollab.app if you suspect unauthorized access to your account.


9. Your choices and rights

9.1 In-product controls

Depending on the client you use, you may be able to:

  • update or disconnect connected accounts where supported;
  • manage collaborators and revoke profile shares;
  • delete comments, reactions, uploads, or placeholders you control;
  • block users;
  • report content or users;
  • disable notifications in device settings; and
  • delete your account from the Account tab / Account screen.

9.2 Account deletion

You can delete your account in the Account area of the app. Deletion is designed to remove from active Service tables:

  • your user profile record;
  • Instagram grid cache rows and associated cached image blobs for your owned profiles;
  • custom photos you own or uploaded (and their storage objects, best-effort);
  • placeholders and feed layouts you own;
  • comments and reactions you authored or that belong to profiles you own;
  • slot-focus and push-token records for your account;
  • profile share relationships to or from you;
  • content reports you filed or that target you (as indexed for deletion); and
  • block relationships involving you.

Some residual copies may remain temporarily in encrypted backups, logs, or legal holds until those systems rotate or retention periods expire. We may also retain limited information if required to resolve disputes, prevent abuse, or comply with law.

If in-app deletion fails, email support@gridcollab.app with the subject line “Account deletion request.”

9.3 Privacy rights requests

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection to certain processing, and to lodge a complaint with a supervisory authority.

To exercise rights, email support@gridcollab.app. We may need to verify your identity before fulfilling a request.

If you are in Australia, you may also contact the Office of the Australian Information Commissioner (OAIC) regarding privacy concerns. If you are in the EEA/UK, you may contact your local data protection authority.


10. Cookies and similar technologies

The marketing site and web planner may use cookies or local storage that are strictly necessary to:

  • maintain authentication sessions;
  • remember client preferences; and
  • operate security features.

We do not currently operate a third-party advertising cookie program on the Grid Collab sites. Browser settings can block some cookies; blocking essential storage may break sign-in or planner functionality.


11. Push notifications

If you enable notifications on a supported device, we store a push token associated with your account and may send messages about feed collaboration activity. Tokens may be rotated or pruned. You can disable notifications in your device or OS settings at any time. Disabling notifications does not delete your account.


12. Third-party platform data and disclaimers

  • Grid Collab’s use of Instagram or Facebook APIs is subject to Meta’s terms, policies, and your authorization.
  • Meta may change, limit, or revoke API access. That can affect which profile or media fields we can show.
  • Content you publish on Instagram remains governed by Instagram’s terms; Grid Collab is a planning and collaboration layer and does not replace Instagram’s publishing controls unless a specific publishing integration is separately enabled and disclosed.
  • Public-looking profile metadata shown in the Service is still obtained through authorized API flows or your own uploads in the production App Store configuration—not unofficial scraping.

13. Changes to this Policy

We may update this Privacy Policy from time to time. The “Effective date” / “Last updated” line at the top will change when we do. Material changes may also be communicated in-app, on the website, or by email where appropriate. Continued use of the Service after an update means you accept the revised Policy, to the extent permitted by law.


14. Additional notices for specific regions

Australia. We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) where applicable. Pricing for planned paid tiers is shown in Australian dollars (A$). Contact us first so we can attempt to resolve concerns.

EEA / UK / similar. Where GDPR or UK GDPR applies, Sections 5 and 9 describe legal bases and rights. Our processors may be located outside your country; see Section 7.

California / US state privacy laws. We do not sell personal information as “sale” is commonly defined. We also do not knowingly “share” personal information for cross-context behavioral advertising. You may request access or deletion as described in Section 9.


15. Contact

For any privacy question or request:

support@gridcollab.app

Grid Collab
https://gridcollab.app