PRIVACY POLICY
Your journey is personal. We treat it that way.
This policy describes how Grezli handles information in the private founder preview.
Last updated: August 26, 2026
1. Information we collect
Account and private identity
We collect your email address, authentication identifiers, first and last name, and sign-in information managed by Supabase Auth. If you use Google sign-in, Google and Supabase provide the account information needed to authenticate you. Grezli does not receive your Google password.
Immigration journey and tracking data
We collect information you choose to add, such as visa category, process type, filing date, case identifier, current stage, alert preference, status observations, and I-140 planning information. We treat these records as private account data.
Community data
We collect your public Grezli name, optional visa label, posts, tags, outcomes, comments, replies, votes, saved items, and reports. Community activity is associated internally with your account so we can operate moderation and ownership controls.
Technical data
We may process session cookies and ordinary service logs such as request time, browser or device information, IP address, and error or security events. We do not use advertising cookies in the founder preview.
2. How we use information
We use information to authenticate users; create personalized dashboards and timelines; track user-added cases; display and moderate community contributions; secure, debug, and improve Grezli; communicate about account access; send case-status emails you explicitly enable; and comply with legal obligations. We do not use private immigration details to advertise to you.
3. What other users can see
Your email address, real name, case identifier, and private journey records are not displayed in community posts. Other users may see your Grezli name, any visa category you choose to display, and the posts, comments, replies, outcomes, and timestamps you publish. Avoid placing private information inside free-text community content.
4. Service providers and disclosures
Grezli uses service providers to operate the preview: Supabase for authentication, PostgreSQL, and the Data API; Google when you choose Google sign-in; Resend for authentication and opted-in case-status email delivery; and OpenAI Sites on Cloudflare-compatible infrastructure for hosting. These providers process information under their own terms and privacy commitments.
Grezli may also disclose information when reasonably necessary to comply with law, respond to valid legal process, investigate abuse, protect users, or preserve the security and integrity of the service. Grezli does not sell personal information or share it for cross-context behavioral advertising during the founder preview.
5. DOL FLAG case checks
When tracking is enabled for a PERM case, Grezli sends the case identifier needed to request its status from the U.S. Department of Labor FLAG service. Grezli records returned status observations and check times. Automated checking stops when verification or CAPTCHA is required and stops for finalized cases. FLAG may not provide the exact decision date.
6. Storage, security, and location
Product data is stored in Supabase PostgreSQL and protected through authenticated sessions, row-level security, per-user ownership controls, and server-side repository boundaries. No system can guarantee absolute security. The service providers used by Grezli may process data in the United States or other locations where they operate.
7. Retention and deletion
We generally retain account and product data while your preview account remains active. During the founder preview, access, correction, and deletion requests are handled manually. Deleting an account may require removal or de-identification of associated community contributions. Limited records may remain when necessary for security, legal compliance, dispute resolution, or backup integrity.
8. Your choices
You can edit your profile, journey, case information, and eligible community content through available product controls. You can choose whether to publish community content and whether to display a visa category with it. Case-status email is disabled by default and can be enabled or disabled at any time in notification preferences. You may stop using Google sign-in through your Google account settings. Contact the founder who invited you to request a copy, correction, or deletion of your information.
9. Children
Grezli is intended for adults and is not directed to children under 13. Do not use the service if you are under 18 during the founder preview.
10. Changes and contact
We may update this policy as Grezli’s features and practices change and will revise the “Last updated” date. For privacy questions or requests during the founder preview, contact the founder who invited you. A dedicated privacy contact and any required jurisdiction-specific notices will be added before wider access.