Plain language about what Grey keeps, why it is needed, and what you control.
Effective 4 September 202601
Project identity and pilot scope
Grey Matter is the public project name Edgar Silva uses to operate Grey; Grey Matter is not presented as a separate registered entity. The current pilot is invite-only and is available only to invited adults who are 18 or older. For privacy, support, or verified data requests, email edgarsl1992@gmail.com.
02
What Grey saves
Grey saves the email identity supplied by the sign-in provider, the account and hashed session information needed to keep you signed in, your interface language, YouTube source links and metadata, transcript text, generated summaries, key ideas, timestamps, topics, collections, highlights, and basic account, creation, search, or deletion audit events.
03
Anonymous feedback
The feedback form works without signing in. Grey stores the message, selected category, interface language, page, time, and an optional reply email. Feedback becomes eligible for deletion after 90 days and, under the monthly pilot cleanup schedule, is expected to leave the production database within 121 days. It does not attach the message to a Grey account or private library, and feedback is available only through restricted owner console and recovery tools. Deleting a Grey account does not automatically erase separately submitted feedback because it is not linked to the account. If you supplied a reply email, contact Grey Matter from that address so a removal request can be verified and handled; without enough identifying information, an anonymous message may not be findable.
04
Anonymous product analytics
Grey records a small set of onboarding steps—such as opening the landing page, trying the fictional sample, viewing sign-in, creating a first memory, and using search—to understand where the experience is unclear. The temporary browser-session identifier is hashed before storage and is not connected to a Grey or sign-in-provider account. These events never contain video links, searches, transcripts, summaries, library content, IP addresses, browser details, or advertising identifiers. They become eligible for deletion after 90 days and are expected to leave the production database within 121 days under the monthly pilot cleanup schedule.
05
Sign-in and local YouTube history import
Google or ChatGPT provides Grey with a verified email and optional display name for sign-in. Google sign-in does not give Grey access to a YouTube account. The optional history importer reads an extracted Google Takeout JSON or HTML file only inside your browser tab. Grey does not upload the raw file, titles, channels, dates, or unselected history. Temporary session storage holds only selected canonical video links, an unreadable account marker, and an expiry time until you review, skip, or clear them; the queue is ignored after seven days. A selected link reaches Grey's servers only when you choose to create its memory.
06
What Grey does not save
Grey does not store YouTube video files, your identity-provider password, or payment-card details. Grey is currently free while it grows and does not collect payment methods.
07
How processing works
Grey runs through ChatGPT Sites and Cloudflare services and uses Google or ChatGPT for sign-in. Grey contacts YouTube to resolve source metadata and available captions. When Supadata is configured, the source link may be sent there for a transcript. When generative AI is configured, transcript content—including potentially the full transcript for shorter sources—and source metadata may be sent to Cloudflare Workers AI or OpenAI to create summaries and answer questions. Grey sends OpenAI requests with response storage disabled. Other providers handle data under their own terms, retention practices, and account settings.
08
Privacy and advertising
Grey does not sell personal data, build an advertising profile from your library, show ads inside the product, or track people across third-party sites for advertising. No third party collects cross-site activity through Grey for advertising. Browser Do Not Track signals do not change Grey's behavior because Grey does not perform that advertising tracking.
09
Security and owner support
Grey uses server-side identity and ownership checks for every private record. The allowlisted owner console does not display private memory content. During a supervised recovery window, the sole owner can create an auditable full backup containing account, session, memory, feedback, funnel, and audit data. That export must remain encrypted, access-limited, and retained only under the documented recovery policy.
10
Your controls
You can export your library, delete individual memories, delete the complete library, or permanently delete the Grey account record. Account deletion removes the active library, profile, sign-in identities and sessions, and personal audit history. A pseudonymous safety marker derived from the email by hashing may remain temporarily so an in-flight processor cannot recreate deleted data. While a video is processing, that row can also hold a random request identifier and processing time; it never stores the email, video link, title, transcript, or generated memory. Deletion invalidates any active processor's permission to save and briefly blocks a request that began around the deletion. The marker follows the retention period below. Account deletion does not delete your separate Google or ChatGPT account, and it cannot identify or erase anonymous feedback or funnel rows that were never linked to the account. Password and account recovery remain with the provider you selected.
11
Retention and backups
Active account and library data remains until you delete it or the service is closed. The restricted invitation roster and participant-level pilot notes are scheduled for deletion within 30 days after the pilot ends; aggregate results may remain. Grey-created Google sign-in sessions expire after 30 days. Feedback and anonymous funnel rows become eligible for deletion after 90 days, personal audit rows after 180 days, expired session rows 30 days after expiry, and inactive hashed deletion-safety markers after 35 days. With monthly manual cleanup, those production rows are expected to be removed within 121 days, 211 days, 61 days after session expiry, and 66 days after marker inactivity, respectively. Personal audit rows tied to an account are also removed when the account is deleted. During the pilot, encrypted owner-created logical backups and derived restores are kept for at most 35 days and used only for recovery testing or disaster recovery, so a deleted or expired record already copied into a fresh backup may remain for that additional window. Platform-managed disaster-recovery copies can follow their own expiry periods.
12
Pilot age and changes
This pilot is only for invited adults age 18 or older. Do not use the pilot if you are under 18. Material changes to this notice will be dated here and communicated before they take effect when required.
GREY MATTER · EDGAR SILVA · PROJECT CONTACT
Questions, privacy, or support?
Email the public Grey Matter support and privacy address for verified data requests or account help. Never send a password, token, recovery code, transcript, or library export.