← Grek Factory

GREK FACTORY / LEGAL

Privacy Policy

Last updated 2026-09-27

Who we are

Grek Factory is operated by GrekTech LLC ("GrekTech", "we", "us"). This policy explains what information Grek Factory collects when you use the product at grekfactory.com, how it is used, and who processes it for us.

Grek Factory is in Early Access (Beta). This policy will be updated as the product changes. When we publish a new version, we ask you to acknowledge it the next time you open the builder.

Information we collect

Account and identity. If you create an account, we collect the email address you sign up with and authentication data managed by Firebase Authentication. If you use Grek Factory without an account, your browser is given an anonymous session identifier so your work can be saved; if you later create an account, that same identifier is linked to it and your projects stay with you.

Your projects and content. The app names, briefs, designs, pages, text, editor history, generated source code and exports you create are stored in our database and file storage (Google Firebase / Google Cloud).

Files and images you upload. If you attach files or images to describe your idea or a change, they are uploaded to private storage and analysed to understand your request. They are deleted after the analysis. They are not added to your app unless you ask.

Visual reference images. If you use the paid Visual AI feature to restyle your app from a reference image, the image is checked, stripped of embedded metadata, sent to our AI provider (OpenAI) for analysis, and deleted from our storage after the request, whether it succeeds or not.

AI requests. If you use the paid Advanced AI features, the text of your request and the relevant parts of your project design are sent to OpenAI to generate a response. The free assistant and the command suggestions you see while typing run inside Grek Factory without any AI provider. Please don’t include sensitive personal information in requests.

Terms acceptance and privacy acknowledgement. When you first open the builder, we show a notice. By clicking OK you agree to the Terms of Service and acknowledge this Privacy Policy; we record which versions you accepted, when, and the interface language at that time.

Voice input. If you use voice-to-text, your audio is processed by your device’s own speech-recognition service. Grek Factory receives only the resulting text.

Payment information. Subscriptions and paid exports are billed through Stripe (and, in the iOS app, through Apple). We do not receive or store your full card number. We receive limited billing information such as your Stripe customer ID and subscription or payment status so we can provide what you paid for.

Feedback and support. If you send feedback, we store your message, the page you were on, your account identifier and an optional screenshot. We send a notification of your feedback to our support inbox by email (through Resend). If your account email is verified, we include it as the reply-to address so we can answer you.

Usage information. We record product-usage events (for example which feature or editor tool was used, a design style chosen, or whether an export succeeded) as identifiers and categories. These events do not contain the text you type, your prompts, images or email content.

Security and abuse limits. To protect the service we keep counters of requests (for example project creations, uploads, AI requests and acceptance attempts). For contact forms in apps built with Grek Factory we store a one-way hash of the sender’s IP address, not the address itself, to limit abuse.

Production connections you set up

When you prepare an app for production, you can connect services that you own: your Google/Firebase project, your Stripe account (through Stripe Connect) and your email provider account (Resend). Credentials you provide for these connections are encrypted and stored on our servers only; they are never shown again, never placed in your app or its exports, and are deleted when you disconnect.

Your app’s end users and their data live in your own Firebase project and accounts. When your production app sends a transactional email (for example a contact-form notification to you), it is sent through your own email provider account.

How we use this information

To provide and operate Grek Factory, including building, storing, and delivering your projects and exports.

To process payments and manage subscriptions and purchases.

To send transactional messages needed to operate the service, such as feedback notifications to our support team. We do not send marketing email, and accepting the Terms does not subscribe you to any.

To respond to feedback and support requests.

To keep the service secure, including rate limits and preventing abuse of build, AI, upload and email infrastructure.

To diagnose problems and improve Grek Factory.

Who processes information for us

We share information only with the service providers Grek Factory is built on, and only as needed to operate it:

• Google (Firebase and Google Cloud) — hosting, authentication, database, file storage and backend functions.

• Stripe — payment processing and subscription management; Stripe Connect for stores you connect.

• OpenAI — only when you use paid Advanced AI or Visual AI features.

• Resend — delivery of our transactional email (such as feedback notifications); for your production apps, your own Resend account.

• Apple — payments made through the iOS app.

These providers may process information in countries other than yours, including the United States. We do not sell your personal information.

Cookies and browser storage

Grek Factory does not use advertising cookies. We use your browser’s storage to keep you signed in (Firebase Authentication), to remember preferences such as the interface language and whether you have seen the tutorial, and to avoid showing the Terms notice again after you have accepted the current versions.

How long we keep information

Account and project data: for as long as your account exists, or until you ask us to delete it.

Uploaded context files and Visual AI reference images: deleted after the request they were uploaded for.

Exports: an export you generate but don’t purchase is kept for 7 days and then deleted. A purchased export is kept for 30 days from the date of purchase and then deleted.

Feedback, email delivery records (which contain status information, not the email content), usage events and security counters: we do not currently delete these automatically; we keep them while they are needed to operate, support and secure the service, and you can ask us to delete information associated with your account.

Deleting your account and data: Grek Factory does not yet have a self-service account-deletion control. Send a request with the in-app Feedback tool and we will process it as promptly as we reasonably can.

Security

We use technical measures to protect your information, including access-controlled cloud storage, encryption of connected-service credentials, secret-detection that keeps API keys out of your projects and AI requests, payment handling performed by Stripe (we never see your full card details), and exports that stay locked until purchased and are delivered through short-lived links.

Grek Factory is an Early Access (Beta) product. Features, security protections, and reliability are still evolving, and we do not guarantee that the service is error-free, uninterrupted, or invulnerable to all possible security issues.

Children

Grek Factory is not directed to children, and we do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy as Grek Factory changes. When we do, we change the date at the top of this page, and the next time you open the builder we ask you to acknowledge the new version.

Contact us

For questions about this policy, or to request access to or deletion of your data, use the Feedback tool inside Grek Factory or write to info@grektech.com.