Privacy

Privacy, and how it all works

No legalese wall. Giraffe keeps what you work out with Claude, ChatGPT or Gemini, what’s true now, the decisions, the open questions and the notes, in projects you can read on your own, with no AI. Here is exactly what it stores, what it never touches, and how small a key a connected assistant actually holds.

Last updated 22 September 2026. Giraffe is made by BRBR GROUP LLC.

Who’s responsible, and who Giraffe is for

Giraffe is made and run by BRBR GROUP LLC, a company registered in Wyoming, United States. When this page says “we”, that is who it means, and that is who is answerable for everything below.

You need to be 18 or older to have a Giraffe account. Giraffe isn’t built for children and isn’t offered to them. If you believe someone under 18 has an account, write to privacy@withgiraffe.com and we’ll close it.

Giraffe is free. Not free for now, and not free until something ends. Free. There is no card field, no plan to choose and nothing to cancel, and no part of this page depends on that changing.

How a save actually happens

You’re in a chat with Claude, ChatGPT or Gemini. You say: “Save what we concluded to my Acme project.” Your assistant sends Giraffe that one piece, not the conversation, and it lands filed: something that’s true now, a decision, an open question or a note. Nothing else moves.

Weeks later you open that project in your browser and read it. Nothing has to be running, no assistant has to be involved, and nothing has to be re-explained.

What we store

The projects you explicitly save, what’s true now, the decisions, the open questions and the notes, plus the history of how each one changed, and who or what changed it. Any Documents composed from a project (a brief, a handoff, a study sheet, written for one audience at one moment) and every earlier version of each.

Your account email, so you can sign in. There’s no password on an ordinary Giraffe account: you sign in with a code we email you. Nothing to leak, and nothing you’ve reused somewhere else. The one exception is a review account we issue so an app-store reviewer can sign in without a mailbox; it holds only fictional sample projects.

Basic usage counts: how often a project was saved to or read from, which parts of the app get used. Numbers, and labels like “project opened”. Never a line of what you wrote.

How many people visit the public pages of this site, and how fast those pages load for them. Vercel, the company that runs the site, measures this for us. It records which public page was opened, which site or campaign link sent you there, your country, region and city, and what kind of device and browser you used. It doesn’t use tracking cookies and it doesn’t give you an identifier that follows you around: it works a short-lived hash out of the request itself and discards it after 24 hours.

Pages inside your account are deliberately left out of that. No project page, document, shared link or project history is ever sent for measurement, because a project’s web address contains the name you gave it. Page speed is the one exception. We do measure how fast the signed-in app is, and for that we send the shape of the address (“a project page”) instead of the address itself.

If you land on a Giraffe marketing page before you have an account, a first-party cookie remembers, for up to 30 days: a campaign label if you clicked a tagged link, which site sent you (just the site, never the page or anything after the ?), and which page you landed on first. It’s set once per browser and never overwritten by a later visit. If you never create an account, that cookie never leaves your browser. It doesn’t reach us. If you do sign up within that window, those few labels are recorded once, attached to your new account, so we can tell which channels actually bring people back. Nothing about you personally, and nothing from before you had an account.

What we don’t do

We never read your ChatGPT, Claude or Gemini conversations. You keep using them exactly as you do now. There’s no connection between Giraffe and your chat history. The only things that ever reach us are the requests your assistant makes: to save something, or to read back what you already saved.

Nothing is captured automatically. If you didn’t save it, it isn’t here, which is also why a new library is empty until you put something in it.

Whether your assistant checks with you before each save is a setting on its side, not ours. Claude calls it Tool access, and it can be set to ask every time, to let Claude decide, or never to ask. ChatGPT asks before each save today. Whichever assistant it is, nothing reaches Giraffe that it didn’t deliberately send.

We don’t sell your data, and we don’t use anything you save in Giraffe to train AI models, not ours, not anyone else’s. Your projects are not training data.

Giraffe itself carries no ads. We do buy a small number of ads for Giraffe on Meta (Facebook and Instagram), and if you click one of those and later confirm a signup, we tell Meta that happened, so we can see whether the ad is working. “Paid ads and Meta” below says exactly what that involves, what it excludes, and how to say no.

Giraffe runs on rented cloud infrastructure rather than servers we own. The companies involved are listed below by name, with what each one does.

The companies that help run Giraffe

Seven companies, and what each one is for. This is the whole list. If an eighth is ever added, it appears here before it goes live.

  • Vercel

    Runs the Giraffe website and app, and measures visits to its public pages and how fast they load

    United States — US East

  • Supabase

    Stores your projects, and handles signing in

    United States — US East

  • Resend

    Sends the emails Giraffe has to send you — your sign-in code, and the code that confirms you want your account deleted

    Not pinned to a region by us

  • Sentry

    Receives a report when something in Giraffe breaks, so it can be fixed

    United States

  • Cloudflare

    The sign-in page loads a bot check from Cloudflare, so opening that page sends a request to it

    The Cloudflare location nearest you

  • ImprovMX

    Receives mail sent to a @withgiraffe.com address and forwards it to the person who reads it

    Not pinned to a region by us

  • Apple

    Delivers notifications to the iPhone app — so it receives the code that identifies your phone, the name of the project that changed and, sometimes, the title of a Document, which is what you then see on your lock screen

    Not pinned to a region by us

Each of them only ever gets the part it needs to do its job. The email company gets your address, whichever fixed message we’re sending (a sign-in code, a setup email, an account notice), and, where relevant, which AI provider you’ve connected. Never anything from a project. The error-reporting company gets what broke and where in the code, never a line of what you wrote. The mail forwarder handles messages you send us, which means anything you write to one of the addresses at the bottom of this page passes through it on the way to us.

The iPhone app is worth spelling out separately. If you use it and turn notifications on, a notification has to travel through Apple to reach your phone, that is the only way any app on an iPhone can be notified, and the notification carries the name of the project that changed, sometimes the title of a Document, and the code that identifies your phone. So a name you chose can appear on your lock screen, and it passes through Apple on the way there. Never what is inside a project: the name on it, and nothing under the name. If you turn notifications off, or don’t use the iPhone app at all, none of that is sent.

Where it all is: everything you save (every project, every item, every Document, every piece of history) is stored in the United States, in a data centre on the US East coast. That is true wherever you are. If you use Giraffe from outside the United States, using it means your information is sent to and kept in the United States, under United States law, and that is worth knowing before you save anything to it.

The other five aren’t storage. They’re services Giraffe sends to. We haven’t agreed a processing region with any of them, so rather than promise you one, the list above says so.

Paid ads and Meta

If you click a Giraffe ad on Facebook or Instagram and later sign up, we may tell Meta that a signup happened, so both of us can see whether that ad is working. This only applies if you arrived that way; if you didn’t come from a Meta ad, none of this section describes anything that happens to you.

There is no Meta tracking script anywhere on Giraffe: no Meta Pixel, nothing that watches which pages you open or fires the moment you land on the site. The only thing Meta ever receives is one message, sent from our own server, and only after your signup is actually confirmed. It is never sent when you first arrive, and never just for requesting a sign-in code.

We ask first. Arriving from a Meta ad shows a small banner offering the choice before anything is recorded: Accept or Decline. Declining, or not answering at all, means nothing about that visit is ever sent to Meta. Accepting sets a first-party cookie remembering your choice for up to 30 days. That alone doesn’t reach Meta either; it only decides whether the one later message, described next, is allowed to be sent.

That message, sent at most once per account and only if you consented: that a registration happened, when it happened, the ad click id that brought you here, and, when we have them, the IP address and a broad category of browser and device (for example “desktop Chrome”), taken from the request that confirms your signup, not stored from your original visit. Never your email, hashed or otherwise; never the page you were on or its full address; never a referrer or a campaign tag beyond that one click id; never the raw text of your browser’s identification string; and never anything from inside a project or Document, a sign-in code, or an access token.

Several situations send Meta nothing at all, on purpose: signing back in to an account confirmed before you ever clicked the ad, confirming in a different browser than the one that clicked it, and using the iPhone app. Telling Meta about a signup only ever happens in the same browser that clicked the ad, for a genuine first-time signup, after you said yes.

The record of that one message is removed the same way the rest of your account is: deleting your account (see “Your control”) deletes it along with everything else. Outside of that, we don’t keep trying forever. If a qualifying message hasn’t been sent within a day of your signup being confirmed, for any reason, it never will be. That timing only affects whether the message is sent; it isn’t a promise that anything is deleted at that point.

This is default off. When it’s off, this section describes nothing that actually happens on the site: the marketing pages render as if the feature were absent, no banner appears, and nothing is ever sent to Meta.

Meta isn’t one of the companies listed above that help run Giraffe: we don’t hand it any part of the product to operate. It’s the advertiser we buy these ads from, receiving only the one signal described here, on its own terms as an advertiser, under Meta’s privacy policy.

AI assistant connections

You can connect an AI assistant to Giraffe. Nothing about your projects reaches one until you do, and connecting is always something you start and approve yourself.

Three are supported today. Each is a product of a different company, and it is that company that ends up holding whatever your assistant asks for. Any other assistant that supports this kind of connection can be connected the same way; the approval screen then shows the address your access would be sent to and says plainly when Giraffe cannot confirm who provides it.

  • Claude, provided by Anthropic

    Reads and writes your Giraffe projects when you use Giraffe from Claude.

    Handled under Anthropic’s privacy policy.

  • ChatGPT, provided by OpenAI

    Reads and writes your Giraffe projects when you use Giraffe from ChatGPT.

    Handled under OpenAI’s privacy policy.

  • Gemini, provided by Google

    Reads and writes your Giraffe projects when you use Giraffe from Gemini Spark, after adding Giraffe as a custom app under Connected Apps in the Gemini web app.

    Handled under Google’s privacy policy and the Gemini Apps privacy notice.

When anything is shared. Only after you approve the connection on Giraffe’s own screen, which names the product, the company behind it, and the address your access will be sent to, and only then in reply to a request your assistant makes. That approval is recorded, along with the address; an assistant that later asks to send your access somewhere else is stopped and you are asked again. Giraffe has no way to start one: there is no code in Giraffe that calls OpenAI, Anthropic or Google, and no scheduled job that pushes anything outward. Your assistant asks; Giraffe answers the question it was asked and nothing more.

What can be asked for. Anything in the projects on your account: project names and overviews and the spaces they are filed in, current facts, decisions, open questions, notes, whole documents, the sources attached to them, and the history of changes, including which assistant wrote what. The access an assistant holds is for your account and carries the email address on it. There is no per-project switch: a connection reaches the whole library, which is why the approval screen says so before you approve it rather than after.

Why. Because that is the point of connecting one: so the assistant you are already talking to can pick up what you decided last month instead of you pasting it back in. Nothing is shared for advertising, for training a model on our behalf, or for any purpose of ours at all. What the provider then does with it is governed by your agreement with them, linked above, including whether it is used to train their models, which is a setting in their product, not in Giraffe.

Writing back. A connected assistant can also save into Giraffe: create projects (filed into a space you already have), rewrite a project’s overview, add, replace and remove facts, decisions, open questions and notes, attach sources, and create or rewrite documents. Whether it checks with you before each save is a setting on its side, described further up this page. It cannot delete a project, empty your trash, change your account, or manage connections. The section below lists the limits that matter most; all of them are enforced in the database rather than by the assistant behaving well.

Taking it back. Settings → Connections, on the web or in the iPhone app, has a Disconnect button for every connection. It takes effect on the next request: a token issued before you disconnected stops working, so there is no window in which an assistant keeps reading. What the provider already received is with them, under the policy or notice linked above, and their own product is where you delete it.

How they protect it. Each of the three states, in its own privacy policy or product privacy notice linked above, that it applies technical and organisational security measures to what it holds; that content it receives from a service you connect is treated as your own content under that policy; and that what you delete is removed from its systems within the period its policy names, subject to the exceptions the policy states. Those are the same categories of protection this page describes for Giraffe: kept private to your account, deleted when you delete it. The one that differs is training. Giraffe never uses what you save to train a model. Whether a provider uses what it receives to improve its models is a setting on your account with that provider, not on Giraffe. Anthropic’s policy says that use is on unless you opt out, with an exception for conversations flagged for safety review. OpenAI’s says it is your choice, made in your account’s data controls. Google ties it to Keep Activity, and Google’s own help page says Keep Activity has to be on for the Gemini feature Giraffe works through. So while Gemini is connected, what it receives from Giraffe is saved to your Google activity and can be used to improve Google’s models, with a subset read by human reviewers, on Google’s terms. We checked those policies on 2 September 2026; they are theirs to change, which is why each is linked rather than paraphrased.

The connection is between you and your own account with that provider. Giraffe has no separate agreement with any of them about your data. Giraffe’s part is to say clearly what can be requested, to require your approval before anything is returned, to record that approval and the address it was given for, and to stop returning anything the moment you disconnect.

What a connected assistant can and can’t do

Connecting Claude, ChatGPT or Gemini hands it a key to your projects, and it’s worth knowing how small that key is. What follows isn’t a policy we promise to follow. It’s what the database will accept from a connection: the limits sit underneath the app rather than in front of it, so they don’t depend on an assistant behaving well, or on us remembering to check.

What it can do

  • List your projects and open any one of them
  • Search across all of them
  • Page through a project’s history
  • Create a new project
  • Change what’s in one: add a fact, correct one that’s moved, record a decision, close an open question, leave a note

What it can’t do

  • Delete a project
  • Rename, archive or restore one
  • Create or rename a Space (the folders projects sit in) or move an existing project between them. (A new project can be filed into a Space you already have, if you name one.)
  • See your connections: it can’t add one, end one, or list the others
  • Pin a project to the top of your list
  • Hide the dot that tells you it wrote something since you last looked

That last one matters more than it sounds. Whether a project shows as changed is your view of your own library, and nothing an assistant does can tidy the dot out of the way.

One thing about the labels, because two different things are being named. Who you are approving is established on the approval screen, from where the access is sent: the company is named only when that address is one of the exact callback addresses Claude, ChatGPT and Gemini actually use, and otherwise the screen says it cannot confirm the provider and shows you where the access would be sent. That is the identity the AI-connections section above describes, and it is recorded with the approval.

The label beside a change in a project’s history is a different thing. Every change is stamped with whether you made it or a connection did, and which connection: those two we can prove, from the signed token the request arrives with. The product name shown next to it (Claude, ChatGPT, Gemini) is the label recorded for that connection: from the approval screen when the address was one Giraffe recognised, and otherwise from what the connection reported about itself when it first called. So a connection can’t pretend to be you, and a history label is a record of which connection wrote, not a second check of who operates it.

Disconnecting is the end of it. Every connection is listed in your settings with its own Disconnect, and one control that ends all of them at once.

It stays ended until you let that connection back in yourself, signed in to Giraffe. An assistant can’t lift its own block, and it can’t come back under a different name: the block is tied to the connection, not to what it calls itself.

One thing to expect: the assistant’s own settings may still show Giraffe installed on its side until you remove it there too. It just can’t reach anything.

The guides for Claude, ChatGPT and Gemini show every click, dated against each provider’s own documentation, before you decide.

How it’s protected

Your data is encrypted at rest and in transit, on established cloud infrastructure: the same kind of providers most modern apps run on.

To be direct: this is not end-to-end encryption. Giraffe staff with database access could technically read stored content. We don’t use that access for anything beyond running and supporting the product, and we’d rather say this plainly than let you assume otherwise.

Access to your projects is enforced by the database itself: your account can only ever read or write your own rows, whether the request comes from you or from an AI you’ve connected.

Nothing can rewrite the record. There’s no button in the product that edits or deletes a past change, and no way to ask for one. The answer you replace stops being the current one; it doesn’t stop being part of the record.

Before the beta we attacked our own permission system, and had outside AI reviewers attack it too. Five serious findings came out of that, and all five were reproduced and closed before anyone was invited in. That’s a red-team pass, not a certificate. Giraffe holds no security certification and has not been audited by an outside firm. If that changes, this page will say so.

The longer version, how sign-in works, how the database keeps one account’s rows away from another’s, and how to report something you find, is on Security.

Your control

Browse, write, edit and delete every item yourself, in the browser, with no AI involved: one fact, one decision, or a whole project. Your own edits land in the same history an assistant’s do.

Download the whole account yourself, any time: a zip with one folder per project. It’s a button, not a request.

Each folder holds the project as a readable document (project.md), the same thing machine-readable (project.json), every change ever made (history.jsonl), and where each piece came from (sources.json). There’s a single JSON file of the whole account too, if you’d rather have one file than a folder tree. Plain formats, readable by anything, including whatever you’d rather use instead of us one day. Documents you’ve written are in there too (artifacts.json, plus one readable file per Document). The archive isn’t only your projects anymore. It doesn’t include your share links; the next paragraph is about those.

You can also publish one Document as a read-only link: “View with link,” a control on the Document itself, and only you can turn it on; a connected AI can’t. Anyone holding that link can open and read that one Document, not the project it came from, not who wrote it, nothing else in your account. Turning the link off is immediate: the same link then shows nothing, exactly like a link that never existed. And a shared link always shows the Document as it stands today, not as it was the moment you shared it. Edit the Document later and anyone with the link sees the edit.

Delete your account and everything in it whenever you like, from Settings → Account. Nothing to ask us for, and nothing to wait for. If you no longer have the app or cannot sign in, the account deletion page is the way to ask from the web.

Because it can’t be undone, deleting asks for two things at once: a code we email to your account address, and the word DELETE typed out. The typed word is there so a mis-click can’t do it; the emailed code is there so someone who got hold of your open browser can’t either.

Then the live record goes immediately: every project, every item, every Document, every piece of history, and the sign-in account itself.

One thing that isn’t instant: backups. A copy of the database is taken once a day, and each copy is kept for about a week before it is destroyed. So for up to about a week after you delete, rows that were yours still exist inside those daily copies. Nothing is ever read out of them except to bring the service back after a failure, and each one goes on its own schedule without anyone touching it.

What outlives all of that is our own usage counts (event names and totals, with your account id removed, so they are no longer linked to you) and any message you sent us through the support form, which we keep as you wrote it, including the address you gave. Neither ever contained anything you saved in Giraffe.

Questions

Anything about your data, this page, or a correction to it: privacy@withgiraffe.com. If something here is wrong, that is the address for that too.

Anything about using Giraffe. Signing in, a connection that stopped working, something broken. Write to support@withgiraffe.com, or the form on Support.

If you have found a way to reach data that isn’t yours, that one goes straight to security@withgiraffe.com. Security says what to send and what happens next.

← Back to Giraffe

Still working out what it does day to day? That’s the other page.