Grind

Privacy Policy

Updated 30 September 2026

In short

Grind is desktop software for music producers. Your catalog stays on your Mac: your audio is not uploaded to us, and your contacts are kept on your Mac only. The account we hold is an email address, a subscription state and the few details listed below. When you send a pack by email, Grind can tell you whether it was opened; what that stores, and what it does not, is set out in its own section. If you choose to connect a Google account, Grind uses it only to send an email you wrote yourself, and never for advertising, profiling or training any AI model.

Who is responsible

Grind is operated by its founder, based in France, who is the data controller for the purposes of the GDPR.

Contact for any privacy question or request: contact@grindapp.io.

What we collect, and why

  • Your account. The email address and first name you sign up with, and the state of your subscription. Legal basis: performance of the contract.
  • Where you signed up from. The language of the page you used, and the country your connection came from at the moment you signed up, read from the network address by our host and not kept as an address. Used to write to you in your language and to understand where producers use Grind. Legal basis: legitimate interest.
  • Activated devices. A one-way fingerprint of your Mac’s hardware identifier, the name of the computer, and when it was last seen, so the device allowance can be applied. Legal basis: performance of the contract.
  • How the app is used. A short, fixed list of events about getting started and using the app (for example, that an import finished), carrying only numbers, yes/no values or short labels: never a file name, a contact or the content of a message. Used to see where new producers get stuck. Kept 180 days. Legal basis: legitimate interest.
  • Placements and credits (Pristine). When you look up a placement, the links and the song, release and artist identifiers involved; for the credits search, the producer name, legal name and aliases you enter; for certifications, the release titles. Legal basis: performance of the contract.
  • Your producer page (Pristine). What you choose to publish on it, which is public at grindapp.io/p/ followed by your name: your name, location, bio, links, pictures, releases, credits, audience figures and certifications. Your contact address appears only if you turn it on. Legal basis: performance of the contract.
  • Label pages (Pristine). A private page you share with a label, opened with a passcode: the collaborators you list with their roles and split percentages, your own split, the label and manager contact names you add, and the names of the documents attached (never the documents themselves). Only a hash of the passcode is stored. Legal basis: performance of the contract. You decide to share the other people named there, so you are responsible for being entitled to.
  • Bug reports. Your message, the app version, your operating system, your plan and the screen you were on, and up to three pictures or videos you choose to attach. Legal basis: legitimate interest.
  • Support messages. Whatever you write to us, kept so we can answer you. Legal basis: legitimate interest.
  • Emails we send you. Whether an email from Grind was delivered and opened, which Resend records through a small image in the message, so we know the account and sign-in emails reach you. Legal basis: legitimate interest.
  • Newsletter, only if you ask for it. Your address, your first name, your language, and a record of when you consented. Legal basis: consent, which you can withdraw at any time.

What stays on your machine

Your beats and the folders they sit in are read on your own computer and their contents are not uploaded to us. We do not receive your audio, we do not keep a copy of it, and nothing is trained on your work.

Your contacts, with their addresses, phone numbers, notes and sending preferences, and the history of what you sent to whom, are kept in a database on your Mac and are not uploaded to us.

The one time audio leaves your machine is when you build a pack and send it yourself: the files go to your own connected Dropbox, which creates a view-only link that anyone holding it can open, and the email or message carries that link.

Apart from the fixed usage events described above, there is no analytics and no crash reporting inside the desktop application.

Email open tracking

When you send a pack by email from Grind, a tiny invisible image is added to the HTML version of the message. It is on by default, and you can switch it off for any message with “Send without tracking”. It is never added to iMessage or to plain-text messages.

When the recipient’s mail program loads that image, our server records that a signal arrived for that message: a random identifier, the time, and what kind of signal it was (for example an automatic load by Apple Mail Privacy Protection, a mail provider’s image proxy or a security scanner, none of which means a person read it). It does not store the recipient’s address, name, network address, browser details or location. The network address and browser details are read in memory to classify the signal and are not saved; our host’s infrastructure may keep them in its request logs for about a day.

Matching a signal to a person happens only on your Mac, where your contacts are. Our server cannot tell who opened what.

Signals are deleted automatically after 90 days, and earlier if you delete the campaign or your account.

You decide to track the people you write to, so you are responsible for how you use it. For that data, Grind acts on your behalf.

Google account data

Connecting a Google account is optional. Grind organizes your library and keeps track of your submissions with no Google account connected at all. This section is the full description of what Grind does with Google user data; a longer version, written for Google’s reviewers, is on the Google API Services User Data Policy disclosure.

Google user data: accessed, used, shared, protected, retained

  • What Google user data Grind accesses. The email address of the connected Google account, and the ability to submit an email you have written. Grind does not access the contents of your mailbox, your contacts, your calendar, your Drive files or any other Google user data.
  • How Grind uses Google user data. The address is used to show you which mailbox is connected and to set the From header. The send permission is used only to deliver an email you composed and triggered yourself inside the app. Google user data is never used for advertising, ad targeting, personalisation or profiling, and never to develop, improve or train any generalised artificial intelligence or machine learning model.
  • With whom Grind shares, transfers or discloses Google user data. With nobody. Google user data is not sold, and is not transferred to any third party, except as necessary to provide the sending feature you asked for, to comply with applicable law, or as part of a merger or acquisition after prior notice to you.
  • How Grind protects Google user data. The OAuth refresh token is stored on your own Mac in the operating system’s encrypted storage (the macOS Keychain). If that encrypted storage is unavailable, Grind refuses to connect rather than write the token to disk unprotected. The token stays in the application’s background process and is never exposed to the part of the app that draws the screens. All traffic to Google is over TLS. No Google user data is stored on our servers.
  • How long Grind retains Google user data, and how it is deleted. The address of the connected account and the refresh token are retained on your own machine for as long as the connection exists. Disconnecting from Settings deletes the stored token immediately, and revoking Grind from your Google account permissions has the same effect at the next refresh. Deleting your Grind account removes the account record entirely. No copy of any Google user data is retained after that.

The permissions requested, and what each is for

https://www.googleapis.com/auth/gmail.sendSend an email that you composed and you triggered. This permission is send-only: it cannot read, list, label, archive or delete any message.
https://www.googleapis.com/auth/userinfo.emailRead the address of the connected account, so Grind can show you which mailbox is linked and set the correct From header.
openidRequired for the address lookup above to answer. It grants no other access.

Bounce detection

Detecting that a message bounced would require gmail.readonly, which Google classes as a restricted permission. Grind does not request it. Bounce information is derived only from what the sending server reports at the moment of sending: a rejected address, a dead domain, a message refused as too large.

If this ever changes, this page is updated before it does, the permission is asked for separately, and declining it costs bounce detection and nothing else.

Grind does not modify, label, archive or delete anything in your mailbox, and does not request any permission that would allow it to.

Limited Use

Grind’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google user data is used only to provide the features described above.
  • It is not transferred to anyone else, except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition after prior notice to you.
  • It is never used for advertising, ad targeting, personalisation or profiling.
  • It is never sold.
  • No human reads your Google user data, except with your explicit consent for a specific problem you have reported, where necessary for security purposes such as investigating abuse, to comply with applicable law, or on aggregated and anonymised data for internal operations.
  • It is never used to develop, improve or train any generalised artificial intelligence or machine learning model.

How the Google connection is stored, and how to end it

  • The refresh token is stored on your own Mac, in the operating system’s encrypted storage. If that encrypted storage is unavailable, Grind refuses to connect rather than writing the token to disk unprotected.
  • The token stays in the application’s background process and is never handed to the part of the app that draws the screens, which can only ask whether an account is connected and under what address.
  • The content of your mailbox is not copied or stored. Grind records on your Mac that a submission happened, to whom, and when; that record is not uploaded to us.
  • Disconnecting from Grind’s settings clears the stored credential. You can also revoke Grind at any time from your Google account permissions, which Grind detects at its next refresh.

Measurement on this website

No analytics tool is active at the time of writing and no non-essential cookie is set. If one is ever added, this page is updated before it goes live and your consent is asked for first. See the cookie page.

Who processes data on our behalf

SupabaseAccounts, sign-in, subscription state, activated devices, usage events, email open signals, producer and label pages, bug reports.
ResendSends the emails Grind writes to you (account, sign-in, and the newsletter if you asked for it), and keeps the list those go to.
NetlifyHosts this website, including the producer and label pages served from it.
CloudflareChecks for bots when you sign in from the app, and delivers app updates.
SoundchartsAnswers placement, streams and credits lookups (Pristine).

Services that act on their own account

Lemon Squeezy sells the subscription as merchant of record: it runs the checkout, collects your payment details, handles tax and issues invoices, as a separate data controller under its own privacy policy. Grind never sees your card, and receives only what it needs to switch your plan on: your customer and subscription identifiers and your email address.

When you send from your own Gmail or Dropbox, those services process the message and the files under your own agreement with them. Certification lookups query the public registries of SNEP, RIAA, BPI and BVMI with release titles.

Transfers outside the European Union

The providers listed above may process data outside the European Union. Where they do, the transfer relies on the safeguards each provider sets out in its own data processing terms. We do not transfer your data to any recipient beyond those providers.

How long it is kept

  • Account data, activated devices, producer and label pages: for as long as the account exists, and removed when you delete it. A label page stops opening at its expiry date (30 days by default, at most a year) and you can delete it sooner.
  • Email open signals: 90 days at most, then deleted automatically.
  • Usage events: 180 days, then deleted automatically.
  • Bug reports and support messages: for as long as they remain useful as support history.
  • Newsletter: until you unsubscribe.
  • Invoices are retained by Lemon Squeezy under its own legal obligations, which are not ours to erase.

Your rights

You can ask for access to your data, correction, deletion, a portable copy, restriction of processing, or to object to it, and you can withdraw consent at any time without affecting processing that already happened. Write to contact@grindapp.io and you will receive an answer within one month. Your account page also has a button to request deletion from the address on the account.

If you are not satisfied with how a request was handled, you may lodge a complaint with your supervisory authority. In France that is the CNIL.

Changes to this policy

If this policy changes, the date at the top changes with it. A change that affects how Google user data is used, or that requires your consent, is not applied before you are asked.