Skip to content

Legal

Privacy policy

Last updated

This policy explains what personal data GAR-AI, Inc. (“GAR AI”, “we”, “us”) collects when you use Garfunkel, why, who we share it with, how long we keep it and the choices you have. It also covers people who aren’t our customers but whose public posts or comments are analyzed. Using Garfunkel is also governed by our terms of service.

How we handle your content

  • Raw media is deleted after processing. Videos, images and audio we fetch or you upload are removed as soon as each post is done, whether it worked or not, and an hourly storage cleanup removes anything left behind. We keep the derived results and one small thumbnail per post.
  • Analyses of public posts may be reused across customers. If a public post was already analyzed with the same version of our pipeline and the same options, we may give you that analysis, after fetching the post again to check it’s still public and to get fresh numbers. The price is the same either way, and who asked for which post is never shared.
  • Uploads are never shared. Media you upload and its results are visible only to your team.
  • Training is opt-in, uploads only. We use content to train our own models only if your team opts in, and only your uploads, never posts fetched from links, because we can’t consent for their creators.
  • You can delete everything. Owners and admins can delete all of the team’s data from Settings at any time, and single results can be deleted through the API.

Who is responsible

GAR AI is responsible for the personal data described here (in European terms, the “controller”). When you upload files or submit posts, you decide what goes in, and we process it to give you results. Questions about this policy go to support@gar-ai.com.

What we collect

  • Account details. Your email address and password (our sign-in provider stores only a one-way hash of it). If you sign in with Google, the name, email address and profile picture Google shares with us; we show your name to your team. Your team’s name, your role, the email addresses you invite, and your language.
  • Billing. Stripe handles payment details; we never see full card numbers. We keep your Stripe customer ID, what you bought and when, amounts, refunds and disputes, and a card fingerprint from Stripe (a code for the card, not its number) so one card can’t earn invite rewards for itself.
  • What you submit. Links, account handles, uploaded files and the options you choose, the questions you ask in chat and the assistant, saved filters, and webhook addresses.
  • Results. Transcripts, translations, captions and on-screen text, summaries, tags, hooks, search vectors, engagement numbers over time, comment reports, and one small thumbnail per post.
  • Public data about other people. When you analyze posts, accounts or comments, we fetch public data about the creators and commenters. See people who aren’t our customers.
  • Free tries without an account. When you paste a link into a free try, we keep what you pasted, whether or not we could analyze it, with the result, how the try went and how long it took, your browser ID, your IP address and your country, for 13 months. We use this to understand and improve how people use Garfunkel and to prevent abuse. A try of a public link is analyzed like any other public post, so its analysis can enter our shared cache. We also read up to 500 of that post’s public comments and keep them with the try for 7 days (only how many there were is kept longer). For a try of an uploaded file, the file is deleted as soon as the try finishes and the file name and result within an hour; we keep only that a try happened, how it went, how long it took, your browser ID, your IP address and your country, for 13 months. If you choose to save a try of a public link, we keep the link and a one-way hash of your try session for up to 7 days, so we can add that post’s result to your library once you sign up. To enforce the free-try limits we keep one-way hashes of your IP address and a browser ID for up to 3 days, and set a cookie.
  • API, command-line and connected apps. API keys are stored only as one-way hashes. We record when each key or connected app was last used, the name and return address of each connected app, and, for each MCP tool call, the tool’s name, whether it worked, how long it took and which app made it. Each job records which app submitted it. We never log what you asked a tool or what it returned.
  • Usage analytics. Described in how we measure use of the site.
  • Security and abuse prevention. Our sign-in provider records sign-in sessions, including IP address and browser. Our hosting providers process IP addresses to deliver the site and to limit abuse. Error logs have personal details removed. To give the sign-up gift once per person, we keep a one-way hash of your email address, even after you delete your account.
  • Messages. If you write to us, we keep the conversation so we can help you.

We send email about your account and your work: sign-up confirmation, sign-in links, password resets and changes, team invites, reward notices and notices that an account count is ready. If you agreed to hear from us, we may send occasional product updates by email. Every email has an unsubscribe link, and we stop as soon as you use it.

Why we use it

For people in the European Economic Area, the UK and Switzerland, each purpose is followed by its legal basis.

  • To run Garfunkel for you: analysis, results, search, chat, exports, accounts and teams. (Contract.)
  • To handle payments, your balance, rewards and refunds, and keep accounting records. (Contract; legal obligation.)
  • To keep Garfunkel secure and fair: preventing fraud, abuse of free offers and overload. (Our legitimate interest in a safe service.)
  • To understand and improve Garfunkel with the analytics described below. (Our legitimate interest; you can object, and Do Not Track and Global Privacy Control are honored.)
  • To build de-identified statistics that combine many customers’ tags, such as how common a format or theme is, benchmarks and trends, and use them to improve Garfunkel and in features that show only those aggregates. They never include your content itself, such as your uploads, transcripts or any result that identifies you, your team or a post. We keep them de-identified, don’t try to re-identify them, and never sell them. (Our legitimate interest in improving the service and offering benchmarks; you can object.)
  • To send the service emails listed above. (Contract.)
  • To send occasional product updates, only if you agreed to hear from us. (Consent, which you can withdraw with the unsubscribe link in any of them.)
  • To analyze public posts, accounts and comments that customers submit. (Our customers’ legitimate interest in understanding public content, and ours in providing the service.)
  • To train our own models on a team’s uploads, only if the team opts in. (Consent, which can be withdrawn at any time.)
  • To comply with the law, respond to lawful requests and enforce our terms. (Legal obligation; legitimate interest.)

We don’t sell personal data, we don’t use it for advertising, and we don’t make automated decisions that have legal or similarly significant effects on anyone.

How we measure use of the site

We want to know which parts of Garfunkel help people and where they get stuck, so we record what happens on the site and in the app. We do it ourselves, without advertising or tracking companies, and our analytics don’t use cookies.

  • Our own analytics, no cookies. Your browser keeps two random IDs in its local storage, one for the browser and one for the visit, so we can tell one visit from the next. They aren’t built from anything about you or your device, and clearing your site data removes them. We also use the browser ID to stop one browser from claiming more free tries or invite rewards than allowed. A visit ends after 30 minutes without activity.
  • What we record: the pages you open (with IDs taken out of the address), how far you scroll, which buttons and features you use (for example “searched”, “opened a post”, “downloaded a spreadsheet”, or how many posts you picked to analyze with the price and balance shown), errors you run into, how long things take to load, the site that sent you (its domain only) and any campaign tags in the link, your device type and screen size bucket, your country (from our hosting provider, not your exact location), your IP address, the language you view the site in and your browser’s preferred languages (up to three, like “es-MX, en-US”), when you switch the site’s language, and which version of the app you’re using. Once you sign in, this is connected to your account and team, including what you did earlier in the same browser, so we can see whether new features help.
  • What we never record: what you type or paste — not your searches, chat questions, file names or the links you paste (for a pasted link our analytics keep only the platform or website it’s from, like tiktok.com; links pasted into a free try are kept as described above), not your transcripts, captions or results, and not your email address. No recordings of your screen or mouse (no “session replay”), and no advertising or cross-site tracking.
  • Vercel Analytics and Speed Insights. Our hosting provider, Vercel, counts page views and measures page speed for us without cookies and without identifying you. We send it page addresses with personal parts removed, and the names of some of the actions above.
  • Newsletter links. Links in our newsletter include a code that tells us which subscriber clicked, so we can see which pages of our site they visited after the click and whether they tried Garfunkel or signed up. We don’t track whether you open our emails. You can unsubscribe from any newsletter at any time.
  • Do Not Track and Global Privacy Control are honored. If your browser sends either signal, our analytics only count what happens — no ID is stored in your browser, nothing is connected to you or your account, we don’t record where you came from or your IP address (only the site language and your browser’s first language are kept), and a free try keeps neither the link you pasted nor your IP address. Vercel still counts page views and actions, without identifying you.
  • Retention and access. Analytics events, with the IP address recorded with each, are deleted after 13 months. Only Garfunkel staff can see them. If you delete your account, your analytics are disconnected from you and the IP addresses recorded with them are deleted.

Cookies and browser storage

We use no advertising or tracking cookies. These are the cookies and browser storage Garfunkel sets, and why:

  • Sign-in cookies (names starting with “sb-”) keep you signed in. Without them you can’t use the app.
  • gf_locale remembers your language, for a year. gf_locale_hint (a cookie and the same key in local storage) remembers that you closed the “view this page in your language?” bar, for a year. gf_nextremembers where to take you after signing in, for an hour.
  • gf_ref remembers the invite link you arrived from, for 30 days, so the reward reaches the friend who invited you.
  • gf_try identifies your free-try session so the limits work, for a year.
  • Google and Cloudflare. If you use Sign in with Google, Google may set its own cookies on the sign-in pages. When a bot check is shown, Cloudflare may too.
  • Local storage holds the analytics IDs above and your display choices, such as theme, layout, columns, the sidebar, dismissed notices and the assistant’s open conversation. A file you drop on the home page before signing up is kept in your browser until it’s uploaded to your new account.

Service providers

We use these companies to run Garfunkel. They process data only for us, under contracts that limit what they can do with it.

  • Vercel hosts the website, app and API and provides page-view and speed analytics. It handles every request, including your IP address. United States.
  • Supabase provides our database, sign-in and file storage, so it holds everything we store. United States.
  • Amazon Web Services runs the servers that fetch and process media, and keeps their logs for 14 days. United States.
  • RunPod runs the GPU servers that transcribe speech. It receives the audio of posts and uploads through links that expire within an hour. United States, Canada or Europe.
  • OpenAI provides models for analysis, tags, translation, comment analysis, chat and the assistant. It receives captions, transcripts, video frames and images, comments, your questions and the results needed to answer them. United States.
  • TikHub is the data provider we use to fetch public TikTok, Instagram and X posts, accounts and comments. It receives the links and handles you submit, never your account details.
  • Stripe processes payments. It receives what you enter at checkout, your team’s name and our internal IDs for your team and account. United States.
  • Google sends our email through Google Workspace, and provides Sign in with Google. United States.
  • Cloudflare carries search requests between our servers and, when switched on, runs the bot check on sign-up and free tries, which receives your IP address.

We also download public media directly from TikTok, Instagram and X servers, and we send job updates to any webhook address you set.

Who else sees your data

  • The members of your team see the team’s posts, results, uploads, chats and balance.
  • Other customers may receive the same analysis of a public post you analyzed, never who asked for it. Uploads and comment reports are never shared.
  • Other customers may see aggregate statistics, such as benchmarks and trends, that combine many teams’ tags and can’t identify you, your team or a post.
  • The service providers above, only to run Garfunkel for us.
  • Authorities or others when the law requires it, or when needed to protect people’s safety or our rights.
  • A buyer or successor if GAR AI is involved in a merger, acquisition or sale, under this policy.
  • Anyone else only with your permission.

We don’t sell personal data and we don’t share it for cross-context behavioral advertising, as California law defines those terms, and we haven’t in the past 12 months.

Where data is processed

GAR AI is based in the United States, and most of our providers process data there. If you’re in the European Economic Area, the UK or Switzerland, your data is transferred to the United States and the other countries listed above. Where the law requires it, we rely on the European Commission’s standard contractual clauses (with the UK addendum) or another lawful transfer mechanism in our agreements with providers.

How long we keep it

  • Raw media: deleted as soon as each post is done, whether it worked or not. An hourly cleanup removes anything left after a day. An upload on a job that’s waiting for payment or was canceled is kept for up to 8 days, and an upload never added to a job is deleted after 24 hours.
  • Results, transcripts, thumbnails, comment reports and chats: until you delete them or your team’s data. When a post is analyzed again, the earlier result is kept with it.
  • Shared analyses of public posts: kept in our shared cache without any link to who asked for them, and removed when a later check finds the post gone. Their thumbnails stay at addresses that can’t be guessed or listed.
  • Public account profiles in our shared catalog: kept, and refreshed whenever the account is checked again.
  • Free tries: links you try, their results, your browser ID and IP address, for 13 months; tries of uploaded files, the file as soon as the try finishes and the file name and result within an hour; the hashes for the limits for up to 3 days; a try you chose to save, for up to 7 days.
  • Analytics: 13 months, including IP addresses.
  • Training frames (only if your team opted in): until your team opts out or deletes its data. Opting out deletes the frames already kept.
  • Billing records: purchases and the history of your balance are kept as long as tax and accounting rules require, including after you delete your account. Stripe keeps its own records.
  • Your account: until you delete it. Your login is deleted at once. If you were the only member of your team, the team’s data is deleted and the team is closed; otherwise the team keeps its data. We keep the one-way hash of your email address that stops a second sign-up gift.
  • Server logs: up to 14 days on our processing servers; our hosting and sign-in providers keep their own logs for limited periods.

Your choices and rights

  • Delete. Owners and admins can delete all of the team’s data from Settings, and single results through the API. Anyone can delete their own account from Settings.
  • Export. Download your results as a spreadsheet or data file from the Posts and job pages, or through the API. For a copy of anything else we hold about you, write to us.
  • Correct. Change your email address, password, language and team name in Settings, or ask us to correct anything else.
  • Object or withdraw consent. Turn on Do Not Track or Global Privacy Control to keep analytics from being connected to you, opt your team out of training at any time, or object to any other use based on our legitimate interests.
  • Your legal rights. Depending on where you live, including the EEA, the UK and US states such as California, you may have the right to access, correct, delete, export or restrict your personal data, object to its use, and opt out of its sale or sharing (we don’t sell or share it). We won’t treat you differently for using these rights. You can also complain to your local data protection authority.
  • How to ask. Write to support@gar-ai.com from your account’s email address. We may need to confirm it’s you, and we’ll answer within a month (45 days for California requests). Someone acting for you needs your written permission. Requests about content a team holds may need its owner or an admin.

For California residents: in the past 12 months we collected identifiers (such as email address, account IDs and IP address), commercial information (purchases), internet activity (the analytics above), approximate location (country), the audio and visual content you submit, and professional information (your team). We collected them from you, your browser and, for public posts, from the platforms through our data provider, for the purposes above, and disclosed them only to the service providers above.

People who aren’t our customers

When customers analyze public posts, accounts or comments on TikTok, Instagram or X, we process public data about the people who made them: creators’ handles, display names, profile pictures, follower and post counts and their posts’ captions, media and engagement numbers, and commenters’ handles, display names, verified status, comment text, likes and times. We get it from our data provider and the platforms’ public servers. We use it only to give our customers analysis of public content.

Analyses of public posts and public account profiles are kept in a shared cache that any customer analyzing the same post or account can receive. Thumbnails and profile pictures are stored at public addresses that can’t be guessed or listed. Comments are fetched fresh for each customer and kept only in that customer’s account. Raw media is deleted after processing.

If you’re one of these people and want us to delete what we hold about you, or object to us processing it, write to support@gar-ai.com with your handle and platform. We’ll delete it from our shared cache and take reasonable steps to keep it from being added again. If you appear in a file a customer uploaded, that customer decides about it; tell us and we’ll pass your request on.

Children

Garfunkel is for people aged 18 and over and isn’t directed to children. We don’t knowingly collect personal data from children under 13, or under 16 in the EEA and UK. Public posts and comments we analyze may have been made by young people, and we can’t tell their age. If you think we hold data about a child, write to us and we’ll delete it.

Security

Data travels encrypted. Media and uploads sit in private storage that’s reached only through short-lived links. API keys, connected-app tokens and invite links are stored only as one-way hashes. Access rules keep each team’s data visible only to that team, and only a few staff can reach production systems. No system is perfectly secure, so if a breach affects your personal data, we’ll tell you as the law requires.

Changes to this policy

When we change this policy, we update the date at the top. For changes that matter, we’ll tell you by email or in the app before they take effect.

Contact

GAR-AI, Inc., a Delaware corporation. Email support@gar-ai.com.