Privacy Policy

Effective date: September 30, 2026 · MKC KOREA CO., LTD.

Core principles

  • ✓ Business data (costing sheets, line plans) is used to improve our AI only if you opt in at signup, always in anonymized form — you can withdraw this consent anytime in Settings
  • ✓ Personal data is never sold to third parties or used for advertising
  • ✓ Saving AI conversations is opt-in (default: off)
  • ✓ On a team workspace, the workspace owner and admins can see members' usage and team activity — see sections 1, 3 and 4

1. Personal Data We Collect

ItemPurposeRetention
Email addressAccount creation, service notifications30 days after account deletion
Name / company nameService personalization30 days after account deletion
Payment identifiers (Paddle transaction / subscription ID)Subscription and credit management, accounting records5 years after payment
Service usage records (AI usage per action, amount drawn)Billing, usage display, service quality improvement1 year; on a team workspace, records of usage drawn from the team pool are kept with the owner's billing history, with the member identifier removed when the member deletes their account
Team activity log (seat, floor and approval events; which team plans and costing sheets a person opened, and when)Team administration and accountability, shown to the workspace owner and admins400 days (visible 30 / 90 / 365 days by plan)
Active-session record (session ID, sign-in time, browser user agent)Security: one active session per accountUntil the next sign-in or account deletion
Feedback posts and error reports you submitProduct improvement; shown to other users on the Feedback board (tokens and emails masked)Until you or we delete the post, or account deletion
Price history (the reason codes and notes given for each price change and price decision, who gave them and when)Negotiation record and audit trail for the plan owner; shown to users with access to the plan, and to a factory only for entries it wroteFor as long as the plan owner's account exists; kept if the style is deleted — see section 4
Device info / IPSecurity and error analysis6 months
Contacts you enter about other people (factory department contacts; factory contacts you invite): name, email, departmentSending the orders and invitations you ask us to sendUntil you remove them or delete your account; send records (recipient, time, subject) are kept with the order
Order approval records (who asked to send an order to departments, who approved it or sent it back, when, and the notes)Accountability for orders sent to departments; shown to the workspace owner and admins and to the people involvedWith the order for as long as it exists; the matching activity-log entry for 400 days

* Sensitive payment information such as card numbers is handled directly by Paddle and is not stored by the Company.

2. Purposes of Processing

  • Service delivery: account management, running AI analysis, collaboration features
  • Payment processing: credit purchases, subscription management (via Paddle), and telling the person who pays — and, on a team workspace, its admins — when a subscription payment fails
  • Service improvement: error analysis, feature improvement (excluding business data)
  • Legal obligations: compliance with applicable laws such as e-commerce regulations
  • Team administration: showing a team workspace's owner and admins each member's usage from the team pool, per-seat limits and pool alerts, and the team activity log (including which team plans and costing sheets were opened)
  • Security: signing out idle sessions after 30 minutes and keeping one active session per account
  • Price history: recording why each price changed and why a price was confirmed, countered, dropped or reopened, so the plan owner keeps a lasting negotiation record

3. Provision of Data to Third Parties

As a rule, we do not provide users' personal data to third parties. However, we share personal data with the following providers for service operation.

ProviderPurposeItems shared
Supabase Inc. (USA)Database & authenticationEmail, account info
Paddle.com (UK)Payment processingPayment-related info
Resend Inc. (USA)Email deliveryRecipient addresses and the content of emails sent or received through the Service (order details and attached files, invitations, negotiation messages, replies)
Anthropic PBC (USA)AI analysis (Claude API)Analysis request data only*
OpenAI, L.L.C. (USA)Text embeddings for reference searchFile names, product category, country; if you opted in, anonymized cost-structure patterns*
Google LLC (USA)Google sign-in, optional Google Drive syncEmail, profile name; synced files†
Vercel Inc. (USA)Website hostingIP address, access logs
Railway Corp. (USA)Application server hostingIP address, uploaded files, access logs
Functional Software, Inc. dba Sentry (USA)Error monitoringIP address, account ID, error diagnostics

* The contents of files you upload (spreadsheets, PDFs, documents, photos) and your chat messages may be sent to Anthropic to run the analysis, and a question you type into AI search in Cost Sheets is sent with the names of your buyers, seasons, categories and materials so it can be turned into a search filter; short search text may be sent to OpenAI to find comparable references. Under both providers' API terms this data is not used for training.

Emails you ask us to send: when you send an order to your departments — and when an order that was sent is later revised, cancelled or reopened — we email the contacts you listed, including the order's attached files. Invitations go to the factory addresses you enter. You are responsible for having their permission to receive these emails.

† Google sign-in and Google Drive sync are optional and off by default. If you connect Drive, costing sheets and related files are copied into a folder in your own Google Drive at your request. On a team workspace, copies of team files go to one team folder in the owner’s Google Drive instead, and that folder is shared view-only with each active seat’s sign-in email through Google (so the owner and other seats can see who it is shared with); access is removed when a seat leaves.

Within a team workspace: if you accept a seat on someone else's Team, Scale or Custom workspace, your usage drawn from the team pool (in US dollars) and your team activity log entries (including which team plans and costing sheets you opened) are shown to that workspace's owner and admins. The team plans, masters and costing archive you work on there are shared with the workspace.

Price history: reasons and notes a factory gives when it submits a new costing version are provided to the buyer who invited it and stored as part of that buyer's data. A factory sees only the entries it wrote itself, never the buyer's entries or another factory's. The name (or, if no name is set, the email) of a buyer-side user who records a reason is shown to other users with access to that plan.

3-2. Team workspaces: who decides

Where a company uses GRAINSIFT through a team workspace, the workspace owner decides who is invited and uses the usage view and activity log to administer the team. For that team data, the Company processes personal data on the workspace owner's behalf. Members may also contact the workspace owner about it. Requests sent to info@grainsift.com are handled and, where needed, coordinated with the workspace owner.

4. Retention and Destruction

  1. Upon account deletion, personally identifying information is destroyed within 30 days. If you are on another user's team workspace, the team's plans, brand and factory masters, decision reports and uploads you worked on are not deleted; they are transferred to the workspace owner. Your entries in that team's activity log remain for up to 400 days, and your usage drawn from the team pool remains in the owner's billing history with your identifier removed. If you own a team workspace, deleting your account closes it: team plans created by members become their own, and team plans you created are deleted.
  2. On a team workspace, a member or admin cannot delete their own account or leave the team alone: the request goes to the workspace owner (or an admin, for a member's request), who approves it. If nobody decides within 30 days, GRAINSIFT carries it out. Items a team seat deletes — plans, costing sheets and documents, archive files, order attachments — are first kept in the team trash, where they can be restored, and are deleted for good only when the owner or an admin deletes them or empties the trash. On a personal account these files are deleted right away, and deleted plans stay in your trash until you delete them. Everything you upload while on a team workspace — costing sheets, documents, archive files — is the team's work and stays with the team if you leave or your account is deleted; files you uploaded before joining stay yours.
  3. Team activity log entries are deleted automatically 400 days after they are recorded.
  4. Price history entries cannot be edited or deleted by users; a correction is added as a new entry. They are kept for as long as the account that owns the plan exists, including after the style is deleted. If a member of someone else's team workspace deletes their account, the entries they wrote on team plans are transferred to the workspace owner together with those plans, and the author name shown on them is kept. Entries on your own (non-team) plans are deleted with your account. Entries written by a factory are kept with the buyer's plan under the same rules.
  5. Where retention is required by applicable law, data is stored separately for the required period.
  6. Electronic files are permanently deleted in an unrecoverable manner; printed materials are shredded or incinerated.

5. Your Rights

You may exercise the following rights at any time.

  • ✓ Access: review the personal data collected
  • ✓ Rectification: correct inaccurate personal data
  • ✓ Erasure: request deletion of personal data (account withdrawal). Team data you created in someone else's team workspace is transferred to that workspace's owner rather than erased, and price history entries you wrote on a team plan stay with that plan — see section 4.
  • ✓ Restriction: temporarily suspend processing of personal data
  • ✓ Portability: export the collected data — Settings → Download all your data gives you one zip (Excel, JSON and your original files). On a team, the workspace’s data is exported by its owner or an admin; each member can export their own account records.

To exercise your rights: info@grainsift.com

6. Cookies and Tracking

The Service uses essential cookies and browser storage (local storage) to keep you signed in and secure. This includes the time of your last activity, shared across your open tabs, used to sign you out after 30 minutes without activity, and a session identifier that lets us keep one active session per account. If you arrive from a link with a campaign tag or from another website, the browser keeps where you came from (the tag or that site’s name) and sends it once with your account after you sign in, so we can see which channels bring people. We do not use third-party cookies for advertising or behavioral tracking.

7. Data Protection Officer

  • Company: MKC KOREA CO., LTD.
  • Name: KO MYUNG KYOON (Representative)
  • Email: info@grainsift.com
  • Address: Unit 804, Building 102, 18 Janggok-ro 596beon-gil, Uijeongbu-si, Gyeonggi-do, Republic of Korea

8. Changes to This Policy

This policy may be revised due to changes in law, policy, or the Service. Any change will be announced by email and in-service notice at least 7 days before its effective date.

Contact: info@grainsift.com · MKC KOREA CO., LTD. · Effective date: September 30, 2026