Skip to content
Core Applied systems Approach Contact
Explore Core
Core Applied systems Approach Contact
Explore Core
Privacy

Privacy Policy

Effective date: July 28, 2026 · Last updated: July 28, 2026

This Privacy Policy explains how Gradien Inc. (“Gradien,” “we,” “us,” “our”) collects, uses, and shares personal data when you visit our websites at gradien.ai, core.gradien.ai, and fincore.gradien.ai (the “Sites”) or use our products and services, including Core, FinCore, and any related applications, APIs, Model Context Protocol (MCP) endpoints, and connectors (together with the Sites, the “Services”).

Gradien Inc. is a Delaware corporation with its registered address at 251 Little Falls Drive, Wilmington, Delaware 19808, United States. For any privacy question or request, contact [email protected].

1. Our Roles

For the Sites and for account registration, billing, communications, security, and analytics, Gradien acts as the data controller (or “business” under US state privacy laws).

Where an organization uses the Services and its workspace content contains personal data, Gradien processes that content on the organization’s behalf as a processor or service provider, under the organization’s instructions. If your personal data is held in an organization’s workspace, direct privacy requests to that organization; we will support it in responding. Our Data Processing Agreement is available on request at [email protected].

2. Information We Collect

Account information. Name, email address, organization details, and authentication identifiers. Authentication is handled by Clerk; we do not store your passwords.

Billing information. Plan, transaction, and invoicing details. Payments are processed by Stripe; we do not store full payment card numbers.

Customer content. Files, notes, messages, tasks, decisions, context, and other materials you submit to the Services or that the Services ingest at your direction, including from Connected Applications. This content may include personal data you choose to include and, for FinCore, fund operations information you submit, such as investor, limited partner, or portfolio company details.

Connected application data. Data accessed from third-party applications you connect (see Section 3), limited to the OAuth scopes you approve.

Usage and device data. Log data, IP address, browser and device information, timestamps, and interactions with the Services, collected for security, operations, and abuse prevention.

Analytics data. Product analytics events collected through PostHog only after you opt in. If you do not consent, analytics events are not collected and are not backfilled if you consent later. We disable IP-based geolocation enrichment in our analytics.

Communications. Messages you send us, including support and sales correspondence.

3. Connected Applications and Google User Data

The Services let you connect third-party applications, such as Gmail, Google Calendar, Google Drive, and GitHub, through OAuth authorization. When you connect an application, we access only the data permitted by the scopes you approve, and only to provide features you request. You can disconnect an application at any time through the Services or the third party’s security settings; for Google, at myaccount.google.com/permissions.

For information received from Google APIs (“Google user data”):

  • We use Google user data only to provide and improve user-facing features of the Services that you request, such as retrieving, organizing, summarizing, and drafting your information for you and for agents acting at your direction.
  • We do not use Google user data for advertising, and we do not sell it.
  • We do not transfer Google user data to third parties except as necessary to provide features you request, for security purposes, or to comply with applicable law.
  • Google user data may be processed by the AI model providers listed in Section 5 solely to generate outputs you request. It is not used to develop, improve, or train generalized artificial intelligence or machine learning models, whether by us or by our providers.
  • Our personnel do not read Google user data except with your explicit permission, where necessary for security or abuse investigation, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

Gradien’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How We Use Information

We use personal data to:

  • Provide, operate, maintain, and support the Services, including processing customer content at your direction (legal basis: performance of a contract).
  • Authenticate accounts, secure the Services, and prevent fraud and abuse (contract; legitimate interests).
  • Process payments, manage subscriptions, and maintain business records (contract; legal obligation).
  • Communicate with you about the Services, including transactional and account messages (contract) and marketing messages, which you can opt out of at any time (consent; legitimate interests).
  • Analyze product usage through opt-in analytics to understand and improve the Services (consent).
  • Improve and develop the Services using de-identified and aggregated data that does not identify you (legitimate interests).
  • Comply with legal obligations and enforce our agreements (legal obligation; legitimate interests).

We do not use customer content or connected application data to train machine learning models. We do not sell personal data and do not use it for third-party advertising.

5. AI Model Processing

The Services use large language models operated by third-party providers to generate outputs from your inputs. Model requests are routed through OpenRouter to OpenAI (GPT models), Anthropic (Claude models), Google (Gemini models), and Moonshot AI (Kimi models), and embeddings are generated using OpenAI. Content is shared with these providers only as necessary to generate the outputs you request. We access these providers under API terms and configurations under which submitted content is not used to train their models and is retained only for limited periods for abuse and safety purposes, as described by those providers.

6. How We Share Information

We share personal data only:

  • With the subprocessors listed in Section 7, to operate the Services.
  • With Connected Applications, at your direction.
  • With professional advisors, such as lawyers, accountants, and auditors, under confidentiality obligations.
  • To comply with law, enforce our agreements, or protect the rights, safety, and security of Gradien, our users, or others.
  • In connection with a merger, acquisition, financing, or sale of assets, with notice where required by law.
  • With your consent or at your direction.

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.

7. Subprocessors

SubprocessorPurposeLocation
Fly.ioApplication hosting, compute, and data storage; our PostgreSQL, Redis, LibSQL, and vector index workloads run on this infrastructureUnited States
CloudflareDNS, content delivery, network security, and static site hostingUnited States (global edge network)
ClerkAuthentication and user account managementUnited States
StripePayment processing, billing, and invoicingUnited States
ComposioIntegration infrastructure for Connected ApplicationsUnited States
OpenRouterAI model routing and inference gatewayUnited States
OpenAIModel inference (GPT) and embeddingsUnited States
AnthropicModel inference (Claude)United States
GoogleModel inference (Gemini)United States
Moonshot AIModel inference (Kimi), accessed through OpenRouterUnited States
PostHogProduct analytics, opt-in onlyEuropean Union
LoopsTransactional and product email deliveryUnited States
Google WorkspaceInternal business operations, support, and emailUnited States

We may update this list as the Services evolve; the current list is maintained on this page.

8. Cookies and Analytics

We use a limited set of cookies and similar technologies:

  • Essential. Required for the Services to function: authentication and session management (Clerk), payment processing and fraud prevention (Stripe), and network security (Cloudflare). These cannot be disabled.
  • Analytics. PostHog analytics runs only after you opt in through our consent controls. Without consent, no analytics events are collected.

We do not use advertising cookies or third-party ad tracking. You can manage cookies through our consent controls and your browser settings, and we honor applicable opt-out preference signals, such as Global Privacy Control, where required by law.

9. Data Retention

  • Account data and customer content: retained while your account is active and deleted within 30 days of account closure.
  • Backups: residual copies in encrypted backups are purged within 90 days of deletion.
  • Billing and tax records: retained as required by law, generally up to 7 years.
  • Support communications: retained as needed to manage the relationship and protect our legal interests.
  • Analytics data: collected only with consent; if you withdraw consent, collection stops going forward.

10. Security

We use administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit and at rest, workspace and tenant isolation, permissioned access to context through Core’s permission engine, least-privilege internal access controls, and logging. No system can be guaranteed secure against every threat. Report suspected vulnerabilities or incidents to [email protected].

11. International Data Transfers

We are based in the United States and process data primarily on infrastructure located in US regions; product analytics is hosted by PostHog in the European Union. Where we transfer personal data originating in the European Economic Area, the United Kingdom, or Switzerland to countries not recognized as providing adequate protection, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK Addendum, with our subprocessors. Details are available on request at [email protected].

12. Your Rights and Choices

European Economic Area, United Kingdom, and Switzerland. You may have the right to access, rectify, erase, restrict, or object to our processing of your personal data, the right to data portability, and the right to withdraw consent at any time without affecting the lawfulness of prior processing. You may also lodge a complaint with your data protection supervisory authority; in the UK, the Information Commissioner’s Office.

California. You have the right to know and access the personal information we collect, to delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell personal information and have not done so in the preceding 12 months, and we do not share personal information for cross-context behavioral advertising, so no sale or sharing opt-out is required. You may use an authorized agent to submit requests with proof of authorization.

Other jurisdictions. Where similar rights apply under your local law, we will honor them as required.

Exercising your rights. Submit requests to [email protected] from the email address associated with your account, or through in-product controls where available. We will verify your identity, typically through your account email, and respond within the timelines required by applicable law. If your personal data is held in an organization’s workspace for which we act as a processor, we will refer your request to that organization.

Marketing. You can opt out of marketing email at any time using the unsubscribe link in the message or by contacting [email protected]. We will continue to send transactional and account messages needed to operate the Services.

13. Children

The Services are not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact [email protected] and we will delete it.

14. Changes to This Policy

We may update this Policy from time to time. We will post the updated version on this page with a revised effective date and, for material changes, provide additional notice by email or within the Services.

15. Contact

Gradien Inc.
251 Little Falls Drive, Wilmington, Delaware 19808, United States
[email protected]

Gradien is a technology company building products and applied AI systems for high-context work.

Gradien

Core Applied systems Approach Contact

Legal

Privacy Terms
© 2026 Gradien Inc.

Analytics

We use optional analytics to understand how visitors use our website and improve Gradien.

Privacy details