Privacy Policy
Last updated October 6, 2026
Grotto is a product of Stewardship Compute LLC (“Grotto,” “we,” “us”). This policy explains what we collect, how we use it, and the choices you have. By using Grottoyou agree to this policy.
1. Who this covers
Grotto serves two groups. Account holders are businesses and creators who sign up to build a site, shop, booking page, or send email. Site visitors are the customers of those businesses who view a published site, place an order, book an appointment, subscribe, or chat. For account data we are the controller; for the data an account holder collects from their own visitors, we act as a processor on that account holder’s behalf.
2. Information we collect
- Account information — email address, business name, business type, and (optionally) an avatar.
- Content you create — your website blocks, themes, products, pages, chatbot configuration, and uploaded images.
- Your customers’ data — when your visitors buy, book, subscribe, or contact you: their name, email, order/appointment details, and messages. This is stored so you can run your business.
- Payment information — subscriptions and shop checkout are processed by Stripe. We do not see or store full card numbers; Stripe handles payment data under its own terms. We store identifiers such as your Stripe customer and subscription IDs.
- AI inputs — instructions you give the AI site builder and assistant, and messages exchanged with the customer chatbot, are sent to our model provider to generate responses. Conversations with a site’s chatbot are stored so the business that owns the site can review them. The chatbot tells visitors it is an AI assistant.
- Voice & microphone — if you use the voice feature, we access your microphone only while you are actively recording. The captured audio is sent to our speech provider (Groq, with OpenRouter as a fallback) to transcribe your speech and generate spoken replies. We do not store the audio after it is processed, and the microphone is never accessed unless you start a recording.
- Usage data — basic logs, AI message counts, and technical data (e.g. request metadata) used to operate, secure, and improve the service.
- Local storage — we use your browser’s storage (and a service worker) to keep you signed in and enable offline/app behavior. We do not use third-party advertising cookies.
3. How we use information
- To provide and operate the service (host your site, process orders and bookings, send your email, run the AI features).
- To authenticate you and secure your account.
- To process payments and manage subscriptions.
- To send transactional email (booking confirmations, contact alerts, and campaigns you initiate).
- To enforce usage limits, prevent abuse, and comply with law.
- To support you and improve Grotto.
We do not sell your personal information, and we do not use your or your customers’ content to train AI models.
4. Service providers (subprocessors)
We share data with vendors only as needed to run Grotto:
- Supabase — database, authentication, file storage, and serverless functions.
- Netlify — hosting and delivery of the application.
- Cloudflare — DNS, CDN, and edge routing for published sites.
- Stripe — payment processing for subscriptions and shop orders.
- Resend — sending transactional and marketing email.
- OpenRouter and the model providers it routes to — currently including OpenAI, Google, and DeepSeek — with NVIDIA as a fallback. They power the AI site builder, assistant, orchestration, code editor, and the customer chatbot. We do not use your or your customers’ content to train AI models.
- Groq — speech-to-text and text-to-speech for the voice feature (OpenRouter is the fallback).
- Meta (Facebook and Instagram) — when you connect a Page or Instagram account, to publish your posts and read their engagement (see “Facebook and Instagram”).
- Cloudflare Turnstile — a bot check on sign-up and sign-in.
- Printful — print-on-demand production and shipping; receives the customer’s name and shipping address for orders you fulfill via Printful.
- Google — when you connect Google Calendar (Pro), we create calendar events and Meet links for your bookings, including the customer’s name, email, and appointment details.
- GitHub — when you connect GitHub, we read and write repository content to import or export your site code on your behalf.
- qr.io — when you generate a QR code for your site, we send your public site URL and business name to create it. No personal data is shared.
Each provider processes data under its own terms and only for the purpose of delivering its service to Grotto.
5. Facebook and Instagram
If you connect a Facebook Page or an Instagram professional account to Grotto (Marketing → Social), you sign in with Facebook and choose which Pages and accounts Grotto may use. We then receive and store:
- the IDs and names of the Pages and Instagram accounts you connected;
- an access token Meta issues for them, stored securely in our database and used only from our servers; and
- the permissions you granted — to list your Pages, publish posts you create or approve, and read your posts’ engagement (such as likes, comments, and reach) so we can show it in your dashboard.
We use this only to publish what you ask Grotto to publish and to show you how your posts are doing. We never post without your action, never read your private messages, never sell this data, and never use it for advertising. It is not shared with anyone except the service providers that host Grotto (Supabase stores it).
Disconnecting. Use Disconnect next to the account in Marketing → Social. We delete the stored token and connection immediately. You can also remove Grotto in Facebook under Settings → Business Integrations (or Apps and Websites).
Deleting your data. Delete your Grotto account in Settings, or email [email protected] with the subject “Delete my data.” We delete your Facebook and Instagram connection data with the rest of your account within 30 days and confirm by email.
6. Sharing and disclosure
We disclose information only: to the subprocessors above; to you, the account holder whose business the data belongs to; when required by law or to protect rights and safety; or in connection with a merger, acquisition, or sale of assets (with notice). We never sell personal data.
7. Data retention
We keep account and business data for as long as your account is active. When you delete your account or specific records, we delete or anonymize the associated data within a reasonable period, except where retention is required by law (e.g. tax/transaction records held by Stripe).
8. Security
Data is encrypted in transit (HTTPS) and at rest by our infrastructure providers. Access controls restrict data to your own account through database row-level security. No system is perfectly secure, but we work to protect your information and will notify affected users of a material breach as required by law.
9. Your rights
Depending on where you live (including under GDPR and the CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can manage most data directly in your dashboard, or contact us at [email protected]. If you are a site visitor, contact the business whose site you used; we will assist them as their processor.
10. Children
Grotto is not intended for anyone under 16, and we do not knowingly collect data from children.
11. International transfers
We operate in the United States; if you access Grotto from elsewhere, your data may be processed in the U.S. and other countries where our providers operate, with appropriate safeguards.
12. Changes
We may update this policy; material changes will be posted here with a new date and, where appropriate, additional notice.
13. Contact
Questions? Email [email protected]. Stewardship Compute LLC, 143 Scottwood Dr SE, Fort Walton Beach, FL 32548.