Grantry ("Grantry", "we", "us"), a service operated by Root Team, Inc. (株式会社ルートチーム), provides an OAuth credential broker, MCP gateway, and access-control dashboard for teams that connect business tools to AI workers. This Privacy Policy explains what information we collect, how we use it, and how users can request deletion.
Information we collect
- Account information such as email address, name, authentication session data, workspace membership, and application settings.
- Provider connection information such as provider name, selected OAuth scopes, encrypted access tokens, encrypted refresh tokens, token expiration times, credential health metadata, and connection labels.
- Operational logs such as AI worker name, provider connection used, tool name, request status, timestamps, and error summaries.
- Support information you send to us directly, including email messages and debugging context.
Google user data
When you connect a Google service, Grantry requests only the Google OAuth scopes shown on the Google consent screen for that connection. Depending on the provider you choose, this may include access to Google Analytics, Google Ads, Google Search Console, Google Drive, Gmail, Google Calendar, Google Sheets, Google Tag Manager, BigQuery, Google Cloud, or Google Admin data.
We use Google user data only to provide the features you configure: storing the connection securely, refreshing tokens, checking connection health, listing available capabilities, routing authorized AI-worker requests to the selected Google API, and showing audit history in your dashboard.
We do not sell Google user data. We do not use Google user data for advertising. We do not use Google user data to train general-purpose AI models. We do not transfer Google user data to third parties except as necessary to provide the service you requested, comply with law, prevent abuse, or with your explicit direction.
Grantry's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect information
OAuth tokens and provider credentials are encrypted at rest. Access to provider connections is controlled by workspace, connection, and AI-worker grants. Audit logs are maintained to help account owners review how workers use configured connections.
Service providers
We rely on a small number of infrastructure providers to operate Grantry, including cloud hosting and database providers that store the encrypted data described above on our behalf. These providers process data only to provide their services to us and are bound by confidentiality and data-protection obligations.
Data retention and deletion
You can disconnect provider connections in the Grantry dashboard. Disconnecting a provider removes the stored credentials for that connection and prevents future AI-worker use. We retain account information for as long as your account is active. When you request account, workspace, or connection deletion, we delete the associated stored credentials and personal data within 30 days, except where we are required to retain certain records to comply with law or resolve disputes. You may request account, workspace, or connection deletion by contacting us at [email protected].
Governing law
This Privacy Policy is governed by the laws of Japan.
Contact
Grantry is operated by Root Team, Inc. (株式会社ルートチーム). For privacy questions or deletion requests, contact [email protected].