Features Multi-Sync Engine Security & Privacy About Company Support Center Privacy Policy Terms & Conditions
Privacy & Data Protection Standard

Privacy Policy

Last updated: August 6, 2026

1. Overview & Commitment

Graft ("we", "our", or "us") respects your privacy and is committed to protecting the personal data of our users. This Privacy Policy describes how Graft collects, uses, stores, and protects information when you use our mobile application and web workspace.

We never sell, rent, or trade your personal contact address book, interaction history, or calendar data to third-party advertisers or data brokers.


2. Data We Collect & Sync Scope

To provide personal relationship management services, Graft requests explicit user authorization to access:

  • Device & Ecosystem Contacts: Names, phone numbers, email addresses, and postal addresses from Apple Contacts, Google Contacts, and Microsoft Outlook.
  • Calendar & Interaction Events: Event titles, dates, and attendee emails from Apple Calendar, Google Calendar, and Outlook Calendar to index interaction history.
  • Account & Auth Tokens: Encrypted OAuth 2.0 tokens provided by Google and Microsoft during authorization. We never store or request your actual third-party passwords.
  • User-Generated Content: Custom tags, color categories, notes, duplicate merge decisions, and invite list statuses.

3. How We Protect Your Data

All communication between your device, provider APIs, and Graft server infrastructure is encrypted using TLS 1.3 encryption. Sensitive tokens and data stores are protected with AES-256 encryption at rest. JWT authentication tokens utilize strict refresh mechanisms to safeguard user sessions.


4. Account & Data Deletion Rights

Graft provides full self-service controls allowing users to delete their account and permanently remove all associated synced data at any time.

Option A: In-App & Web Account Deletion

  1. Log into your Graft application or Web workspace.
  2. Navigate to Settings → Account Profile.
  3. Scroll to the section labeled "Delete Account".
  4. Confirm account deletion. All synced contacts, interaction timelines, OAuth tokens, and preferences will be permanently erased.

Option B: Direct Email Data Removal Request

You may also submit a data removal request by emailing our support team at [email protected] with the subject line "Data Deletion Request". Requests are processed within 24 hours.


5. Third-Party Integrations

Graft integrates with Apple iCloud, Google Workspace APIs, and Microsoft Graph APIs. Your use of third-party connected accounts is governed by their respective privacy policies:


6. Contacting Us

If you have any questions or concerns regarding this Privacy Policy, please reach out to us:

Graft Software Technologies
Email: [email protected]
Website: graftapp.io