Privacy Policy
This policy explains the information Gravity collects, how we use and share it, how we protect it, and the choices available to you.
1. Scope and contact information
Gravity is operated by Jonah Greenberger and Jay Zhang (“we”, “us”). This policy covers the Gravity website and application at https://meetgravity.ai. Questions about this policy may be sent to hello@meetgravity.ai or by post at P.O. Box 1723, Wilson, WY 83014, United States.
Gravity is in early access and available by invitation. This policy describes the current Service and will be updated if our data practices change.
2. How Gravity uses information
Members of a small trusted group each connect their own Gmail account, or several of their own accounts, read-only. Gravity processes selected conversations in which you participated and derives a private record of your correspondents and their apparent areas of knowledge or work. The Rolodex itself is visible only to you, while derived signals from it participate in the group matching described below. When another member states a goal, Gravity may identify you as someone who could facilitate a relevant introduction. For each match, the requester receives a reliable human-readable name when one is available, selected public LinkedIn profile information when Gravity has it, and a requester-safe match explanation. A match is not excluded because LinkedIn information or a reliable name is absent; in that case the match explanation stands in for public profile information. Contact details, relationship context, private notes, and source evidence remain visible only to the member who owns that relationship. Gravity does not contact that person. The requester and relationship owner decide together whether to pursue the introduction.
3. Information we collect
Account information. When you sign in with Google we receive your name, email address, and profile image from your Google account, and we store an identifier for your account. We also store whether you have disabled unread-chat email reminders.
Information you give us. The goals you state within a group, the recipient email addresses and notes you provide when sending group invitations, the context you add about how you know a contact, the name, email address, LinkedIn link, and notes you add about a contact by hand, messages you send in shared group chats or to the private Agent and the files you attach to them, a LinkedIn profile PDF if you choose to import one, and the name, email address, and description you submit if you request an invitation from our homepage.
Google Gmail data. If you connect Gmail, we request exactly one read-only scope, https://www.googleapis.com/auth/gmail.readonly, and use it as described in section 4.
Technical information. We collect ordinary web request information that reaches our hosting provider, such as an IP address, browser user agent, and timestamp. We also maintain operational logs. Our application logs record selected product actions and technical outcomes, such as error categories and processing durations. These records may include an internal member reference that authorized administrators can connect to your account to provide support and understand how the product is used. We do not write names, email addresses, chat or mailbox contents, contact details, message identifiers, or model output to application logs.
4. How we use Google user data
We request one scope, gmail.readonly, and only that scope. If Google grants anything broader, we refuse the connection until you reconnect. Gravity cannot send, modify, delete, or label anything in your mailbox, and has no ability to email your contacts.
We select conversations you have sent messages in, read their headers to determine who you exchange messages with, and process selected message text to build your private Rolodex, derive short paraphrased relationship and capability notes about people you correspond with, and build your private Gmail-derived profile about your own work. These signals may support matching and introduction proposals within groups you join, subject to the visibility and approval controls in section 6.
When you ask Gravity for help with a recent exchange with someone in your Rolodex, it searches your connected mailboxes for your latest conversation with that person’s known addresses and reads that one conversation’s message text to answer you. That text is used only for that reply and is not stored. Gravity’s reply, which may describe the conversation or quote short phrases from it, is saved in your private Agent history like any other reply. This help reads only that one conversation, and only when you ask.
Apart from the replies you ask for, we do not retain message bodies, subjects, snippets, attachments, raw headers, Gmail-processing prompts, or raw model responses after processing. We retain the connected Gmail address and connection lifecycle metadata; encrypted OAuth credentials while Gmail remains connected; private contact email mappings and Gmail-observed names; interaction counts and dates; derived relationship, capability, and self-profile summaries and claims; selected private Gmail thread identifiers; processing and coverage metadata; and dependent matching records.
These features need to search sent conversations within a date window or conversations with a specific person, identify the participants, read selected message text, and list the account’s send-as aliases so your own addresses can be excluded. The narrower Gmail metadata scope cannot perform all four operations, while adding a Gmail settings scope would introduce write authority over mailbox settings. The read-only scope above is therefore the narrowest scope that supports the feature.
Gravity’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Automated processing and AI models
We use a large language model to derive relationship and capability information from selected conversations, to respond when a member explicitly invokes Gravity in a shared group chat or uses the private Agent, including a planning conversation opened from one of their own matches, and to learn after a member sends a message. Selected message text, profile text, authorized match context, private planning context, private notes visible only to their owner, and chat messages are submitted through the API of our current model provider, OpenAI, to produce the features described in this policy. OpenAI is also identified in the service-provider table below.
We do not use your Google user data, and we do not permit our providers to use it, to train, develop, or improve generalized artificial intelligence or machine learning models. We use model-provider APIs only to process the data needed to provide the features described in this policy.
Model output is used to produce private results, privacy-safe match explanations, and replies in chats where a member explicitly invokes Gravity. Background learning may prepare requester-authored additional goal context for the requester to review, or save or update a private note from a member’s own statements, one fact per note. These notes may describe the member, their relationships, or other people, including people without a Rolodex entry. A material goal clarification may create a deterministic suggestion, but only the requester can activate the visible context and search that one connector’s Rolodex. A positive match may separately include a reliable human-readable name and optional public-shaped LinkedIn information. This is not approval for an introduction. Model output is never used to build a shared contact database, and it is not sold or licensed to anyone.
6. Data visibility
The following restrictions govern how Gmail-derived information is made available through the Service.
- No member can browse, search, export, or enumerate another member’s relationships. There is no directory and no contact search.
- The list of people derived from your mailbox is visible only to you, in your own account.
- When another member’s stated goal matches someone you know, that member may be shown a reliable human-readable name for the person, optional public-shaped LinkedIn profile information, your name as a possible connector, a general professional description, a general statement of how the person might help, and a coarse indication of how strong the fit looks in each direction. They are not shown contact details, private Rolodex claims, relationship context, inferred private needs, source message text, or mailbox evidence. A match may include a link that opens a public web search for the displayed name and role in a new tab; Gravity sends nothing else, runs no search itself, and stores nothing from it.
- The full proposal and relationship-derived reasons become visible automatically only to you because the relationship came from your Rolodex. The requester receives only the bounded named match projection and the privacy-safe match explanation.
- A shared group chat is visible only to the goal’s requester and the member whose Rolodex supplied the relevant matches. Both members may browse the same bounded named match projection and match explanations there, while only the relationship owner opens the complete private match review. This does not share contact details or relationship evidence and does not approve an introduction. Either member may explicitly ask Gravity a question using the shared goal, bounded conversation, and only the match cards they added to discussion. Gravity receives only the shared person projection, match explanation, and coarse strengths. After the conversation pauses, background learning may save well-supported facts from the speaker’s own messages, one fact per note, into their private self notes or notes about identified people in their own Rolodex. Self notes may name other people or preserve useful context about someone without a suitable Rolodex entry. It may also propose additional goal context from the requester’s own statements. Tentative brainstorming stays in the conversation. Pending synthesized goal context is visible only to the requester; private-note changes and their in-chat confirmations are visible only to the relationship owner. If the requester accepts a material context suggestion, the visible context becomes active for matching and only that thread connector’s Rolodex is searched immediately. The search exposes no Rolodex size, rejected people, private evidence, or contact details. Gravity cannot approve an introduction, contact anyone, or authorize outreach.
- The requester may ask for a specific introduction, but only the member who owns the relationship may decide to contact that person. There is no standing consent and no opt-out default.
- A member who invites someone can include up to five people from their own Rolodex they would introduce that person to: each person’s name, the role shown in the member’s LinkedIn import, and a short reason the member approves and can reword. Gravity may draft that reason from the member’s own private search, under the same limits as a match explained to another member: it leaves out how the member knows the person, the member’s notes, and anything from email. The invitation page shows them to whoever holds that link until it is used, expires, or is withdrawn. Nothing is sent to those people, and paths through other members’ relationships are never included.
- Joining a group requires your affirmative action and can be withdrawn. Signing in alone does not add you to a group. You join only by accepting an invitation.
7. People who are not members
People identified from your mailbox have not signed up for Gravity and do not have accounts. We maintain a limited record associated with your account that may include an email address, a display name, interaction counts and dates, and short derived summaries. Gravity does not contact or market to these people, create public profiles about them, or provide a way for others to look them up. A member may name a few of them in an invitation they send to someone they want to help, as described above. Any introduction is sent by a member who already knows the person, not by Gravity.
If you are not a member and believe Gravity holds information derived about you, write to hello@meetgravity.ai and we will locate and delete it. Because that data lives inside individual members’ private accounts, we may need the email address you would have corresponded from in order to find it.
8. Who we share information with
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not run advertising. We disclose information to the service providers below, who process it on our behalf under contract. We may also disclose information where required by law or when necessary to investigate a security incident or suspected abuse.
| Provider | Purpose | Data handled |
|---|---|---|
| Resend, Inc. | Transactional delivery of group invitations and unread-chat reminders. | Invitation details; a member's email address and aggregate unread-conversation count for reminders; and provider delivery metadata. |
| Google LLC | Sign-in, the read-only Gmail API that is the source of relationship signal, and private queued execution of unread-chat reminders. | Account identity; with your authorization, read-only mailbox access; and opaque chat-message identifiers used to schedule reminder checks. |
| Neon, Inc. | Managed Postgres database and the authentication service behind Google sign-in. | All stored account, relationship, and derived profile data. |
| OpenAI, L.L.C. | Language models that turn selected message text into derived relationship and capability signal and respond in shared chats and the private Agent, including planning conversations opened from a match. | Selected message excerpts, profile text, match context, attached file contents, and chat messages submitted through the API for bounded processing requests; the provider is not permitted to use them for model training. |
| Vercel, Inc. | Application hosting and content delivery. | Request metadata in transit, including IP address and user agent. |
If Gravity is ever involved in a merger, acquisition, or sale of assets, we will comply with the Google API Services User Data Policy, which requires your prior consent before Google user data is transferred in such a transaction.
A small number of trusted operators can access production systems for a documented, specific support request, to investigate a security incident or suspected abuse, or to comply with law. That access can expose data derived from a member’s mailbox, but our operator tools do not display raw message bodies. We do not read member data for any other reason.
9. Data retention
Agent conversations on your homepage are saved privately to your account until you delete the conversation or your account. Starting a new Agent chat keeps earlier conversations in your history. We save your messages and Gravity’s visible replies, including partial replies when interrupted. We also retain server-side tool results and model continuation data, including encrypted reasoning, so later replies can continue the conversation. When a reply reads one of your email conversations, we keep only a record that it did, not the message text. Those items are excluded from the browser transcript and are not evidence for chat learning. Deleting Gmail data also deletes Agent conversations that used your Rolodex, including their follow-up messages.
We keep your account, derived relationship data, and stated goals for as long as your account exists. Gmail message text is not stored and exists only for the duration of the request that processes it. Shared group-chat messages are retained with their thread while the associated goal and both participant accounts exist. Retiring the goal makes the thread read-only and archived while both participants remain active group members; leaving the group makes it unavailable, and deleting the goal, group, or either participant account deletes it. A planning conversation opened from one of your own matches is an Agent conversation and is retained like any other until you delete it; deleting the match deletes it too. When Gravity saves a private note from a conversation, the conversation retains the before-and-after note receipt needed to show and undo that change. Shared-chat reflection records may retain private note receipts for the relationship owner, requester-reviewed goal-context revisions, and the status of a rerun suggestion while the associated account, goal, and thread exist. Removed notes retain their receipts so you can review or undo the change. The same background learning applies to saved Gravity Agent conversations and their files. File contents are attributed to their surrounding conversation; uploading a document does not establish that its statements describe you or are your beliefs. Deleting a conversation removes its learning checkpoints and receipts. Saved notes remain in your Profile or Rolodex, where you can remove them separately. Learning checkpoints contain identifiers and timestamps, while note receipts record changes without copying message or file contents. Unread-chat reminder state retains content-free episode, delivery, aggregate-count, and provider metadata while the associated account and chat exist; the reminder itself contains only an aggregate unread-conversation count and links back to Gravity. Google OAuth credentials are stored encrypted and are erased when you disconnect Gmail. We also ask Google to revoke those credentials.
Disconnecting Gmail stops further access but does not delete previously derived relationship data. If you delete your Gmail data as described in section 10, we remove it from our live systems. Our database provider retains backups on a rolling basis, and deleted records are removed as those backups expire.
10. Your choices and controls
- Turn off unread-chat email reminders. Reminders are enabled by default. From Profile → Notifications you can turn them off or back on. A reminder is sent only for member-authored activity in active shared chats that remains unread for two hours, and it does not contain participant names or message content.
- Do not connect Gmail. Gmail is optional. You can join a group, state a goal, and receive matches without connecting it.
- Disconnect any connected Gmail account at any time from your account, which erases our stored credentials for it and stops all further reading of it, or revoke our access directly at your Google Account permissions page.
- Delete Gmail data. From Profile → Sources, choose Delete Gmail data to permanently remove your Gmail connection, private Rolodex, Gmail-derived profile, retained Gmail identifiers and workflow state, and matches sourced from your private Rolodex. Saved Agent conversations that used your Rolodex are also removed, including their follow-up messages. Matches sourced from another member’s Rolodex remain. You can use this control whether Gmail is connected or previously disconnected. We attempt to revoke any remaining Google authorization before deleting the live data.
- Deleting Gmail data does not delete messages or settings inside Gmail, your Google account, or your Gravity account. Your Gravity identity, group memberships, goals, and imported LinkedIn profile remain. It removes only data sourced from your Gmail, not another member’s independently sourced data about the same person. Reconnecting Gmail later starts with a new, empty Gmail-derived state.
- Leave a group to withdraw your data from that group’s matching.
- Delete your Gravity account. Email hello@meetgravity.ai from the address you sign in with. We use that address to verify the request, complete account-deletion requests within 30 days, and confirm by reply. Full-account deletion removes your account and profile, Gmail-derived data, imported profile, memberships, goals, invitations, matches, and proposals. Account deletion does not affect introductions or communications that occurred outside Gravity, and content independently authored by another member remains theirs.
- Remove information about you as a non-member. If you believe Gravity holds a record derived about you inside a member’s private account, email hello@meetgravity.ai with the address you would have corresponded from so we can locate and delete it.
- Access or correct your data. Write to hello@meetgravity.ai. Depending on where you live you may have rights to access, correct, delete, or obtain a copy of your personal information, and to be free from discrimination for exercising them. We honour these requests regardless of where you live, and we do not charge for them. We will ask you to verify control of the account.
11. Security
Our security measures include encrypted transport; application-layer authenticated encryption of Google OAuth credentials with a key held outside the database; managed database encryption at rest for stored account and derived data; database queries that scope member-owned Gmail-derived records to the applicable member; and operational logs restricted to values that cannot carry user content.
No system can be guaranteed to be completely secure. If you believe you have found a vulnerability, report it to hello@meetgravity.ai. We will acknowledge your report and we will not pursue good-faith security research.
12. Children, location, and changes
Gravity is not directed to anyone under 18 and we do not knowingly collect their information. We operate in the United States, and information we hold is processed there; if you use Gravity from elsewhere, you are sending your information to the United States.
We will update this policy as the product changes. When a change is material we will update the effective date above and, for changes that affect how we use Google user data, tell members before the change takes effect.