Privacy Policy
Last updated: June 2026
Grip is a product of Lexenne, currently in development. Today, grip.lexenne.com is an information and waitlist site. This policy explains what the site collects and how we handle it. We will update it before the Grip app launches and begins holding your household records.
What we collect
| Data | Why | How long we keep it |
|---|---|---|
| Your email address (when you join the waitlist) | To contact you about early access and launch | Until you ask us to remove it, or the waitlist closes |
| Basic server logs (IP address, browser type) | Serving the site and protecting it from abuse | A short rolling window held by our hosting provider |
That is the whole of it. The site runs no advertising or analytics trackers, and sets no tracking cookies.
Who we share data with
We do not sell your data. We share the minimum needed to run the site:
- Loops — our email service, which stores your waitlist email so we can write to you.
- Vercel — our hosting provider, which serves the site and keeps short-lived server logs.
Your rights
You can ask us to show you, correct, or delete the information we hold about you. Email us and we will take care of it.
How AI will handle your data (when the app launches)
Grip is built to give you the "snap it and it files itself" experience without giving up control. The app is not live yet; here is how it will work, and we will publish a full policy before it launches.
- A local mode keeps everything on your device. It reads your receipts and documents on your own device (or your own AI endpoint), so nothing leaves at all. It is always available, including on the free plan.
- If you choose cloud capture, only the image you scan leaves - not your account, your household, or your other records - and only when you use it.
- Where it goes: a cloud AI provider (Google, via Google Cloud Vertex AI) reads the image to pull out the details. Under our agreement, your content is not used to train their models and is not kept beyond processing.
- We never sell your data, and we never train on it. Your records stay encrypted and are exportable at any time.
Who holds your keys (when the app launches)
Access to your records is authorized by a cryptographic key tied to your identity. The long-term design, the "sovereign" version, keeps that key on your own device, so only you can authorize access and it never leaves your hands.
The first version does not work that way yet. To get Grip running, Lexenne holds and manages your key in a secured key store and authorizes access on your behalf after you sign in. This is a deliberate first-step choice, the same pragmatic trade as the rest of V1, and a later version moves the key onto your device. We record it here openly, and we make no "your keys never leave you" claim until that move ships. The switch changes where the key lives, not how your data is protected.
Changes
If we make a material change to this policy, we will note it here and, where it affects people on the waitlist, let you know by email.
Contact
Questions, or want your data removed? Email grip@lexenne.com.
