Grayson Strategies, LLC, doing business as Graytech Studio ("Graytech," "we," "us," or "our"), provides the website at https://graytech.dev and related forms, assessments, accounts, workshops, communications, and services. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through those activities.
This Policy applies to the Graytech website and related online services that link to it. A signed client agreement, statement of work, nondisclosure agreement, or data-processing addendum may provide additional or different terms for a client engagement. Third-party websites and services have their own privacy practices.
1. Information we collect
Information you provide
Depending on how you interact with Graytech, we may collect:
- Contact information, such as your name, email address, telephone number, company or organization, job role, and communication preferences.
- Business and project information, such as your goals, operational challenges, project interests, budget range, timeline, current platforms, workshop interests, and service requests.
- Account information, such as profile information, authentication identifiers, login activity, and records needed to administer access for paid users.
- Assessment information described below.
- Transaction and subscription information, such as the product or service purchased, transaction date, amount, payment status, billing contact information, and processor reference numbers.
- Communications and support records, including messages you send through forms, email, SMS, or other channels.
- Marketing preferences, such as whether you subscribed, unsubscribed, or consented to receive email or SMS marketing.
Please do not submit confidential client data, regulated data, health information, complete financial-account or payment-card information, government identification numbers, passwords, trade secrets, or other highly sensitive personal information through a general website form or assessment. If a project requires sensitive or regulated data, the scope, safeguards, and responsibilities must be addressed in a signed agreement before Graytech receives it.
AI Readiness Assessment information
The current assessment may collect:
- Full name, email address, and business name.
- An optional website URL and optional industry selection.
- Up to three optional brand-color values.
- Responses about revenue range, lead sources, follow-up practices, technology stack, content, bottlenecks, lost-revenue concerns, and automation goals.
- Free-text responses, including text fields that may allow up to 2,000 characters.
- A browser-generated record identifier and a status showing whether the assessment was started or completed.
The first step creates a record immediately. Your name, email, and business name are stored when you complete Step 1, even if you do not finish. If you leave before finishing, Graytech may retain your identity information and an incomplete status even though the later answers were not submitted. Authorized Graytech access occurs through administrative systems.
When a visitor starts or completes the Graytech AI Readiness Assessment, the browser sends the visitor's approved assessment information through secure server-side functions. Public browser clients are not permitted to directly read or update assessment records. A short-lived signed assessment session is used to authorize permitted updates to the applicable record. Assessment responses may be sent server-side to Graytech's customer relationship management provider so Graytech can create or update the contact, apply the Graytech Assessment Lead tag, route the inquiry, and follow up about the submission.
The current assessment does not calculate an automated score and does not send answers to an AI model. Raw assessment answers are generally retained for 30 days unless they are needed for active client work or requested follow-up, and the assessment result and basic contact record may generally be retained for 12 months. The customer relationship management platform processes contact and assessment-related information for lead management, workflow routing, and follow-up.
Please do not submit confidential, regulated, health, financial, legal-matter, or other sensitive personal information through the assessment. Before Graytech enables AI processing, we will update this Policy and the notice shown at the assessment, identify the relevant provider, and explain the processing before information is sent.
Information collected automatically
When you use the website, Graytech and its infrastructure providers may automatically receive technical information such as:
- Internet Protocol address and approximate or inferred location.
- Browser, device, operating system, language, locale, and user-agent information.
- The page address you visit, referring page, date and time, and interaction or session information.
- Cookie identifiers and similar technical records used for security, authentication, preferences, and limited analytics.
The current analytics script may use a first-party session-id cookie that expires after approximately 30 minutes. Cloudflare may set an essential __cf_bm cookie to distinguish legitimate traffic from automated traffic. Graytech does not currently use Google Analytics, Meta Pixel, LinkedIn Insight Tag, Hotjar, Microsoft Clarity, or advertising cookies.
Payment information
New payments may be processed by Stripe through GoHighLevel or by PayPal. Historical subscription transactions may continue to be administered through Paddle. These processors collect and process payment details under their own terms and privacy notices. Graytech receives transaction records and identifiers needed to fulfill, support, account for, and reconcile purchases, but does not intend to collect or store complete payment-card numbers through its website systems.
2. How we use information
Graytech may use personal information to:
- Operate, maintain, troubleshoot, protect, and improve the website and services.
- Receive and administer assessment submissions, service inquiries, workshop interest, and contact requests.
- Provide assessment-related follow-up, requested information, proposals, support, products, workshops, and services.
- Create and administer paid-user accounts and authenticate authorized users.
- Process transactions, maintain subscription records, provide receipts, prevent fraud, and meet tax and accounting obligations.
- Communicate about a request, account, transaction, appointment, workshop, project, security matter, or service update.
- Send marketing email or SMS only when authorized, and maintain suppression records to honor opt-out requests.
- Analyze limited website usage and understand whether pages and forms function as intended.
- Enforce agreements, protect rights and safety, respond to legal process, and comply with applicable law.
- Establish, exercise, or defend legal claims and maintain appropriate business records.
Assessment submission authorizes Graytech to store and review the submission, provide or prepare the requested assessment-related response, and contact the submitter directly about that submission. It does not, by itself, enroll the submitter in general marketing.
3. AI processing and model training
No third-party AI provider currently receives website or assessment submissions through the live assessment. If Graytech later activates AI-assisted assessment features, the expected design is to use fixed rules for scoring and routing and Anthropic's Claude API, called from a Supabase Edge Function, for website critique, written diagnosis, or prototype content. Graytech will not activate that workflow until the assessment notice and this Policy have been updated and the data flow has been tested. Graytech will not use identifiable website, assessment, or client information to train a general-purpose Graytech model, and will not authorize a third-party AI provider to use that information for general model training, unless the affected person or client gives separate, explicit permission. Graytech may use de-identified or aggregated observations to improve its processes when the information cannot reasonably be linked to a person or business.
AI-generated outputs may be incomplete, inaccurate, or unsuitable for a particular business. If AI output is introduced, it will be presented as decision-support information that requires human review, not as legal, financial, tax, employment, security, compliance, or other professional advice.
4. Site assistants and demonstrations
Graytech Concierge
The initial Graytech Concierge is a guided site-navigation tool. It uses preset choices to direct visitors to relevant Graytech pages and does not generate open-ended AI responses. It does not persist a conversation history. Information is stored only if you deliberately open and submit a separate contact, newsletter, or assessment form, subject to that form's notice.
Hartwell Legal demonstration
The AI Receptionist Blueprint page can load a third-party demonstration widget supplied through Graytech's customer relationship management and communications provider. The provider may receive your demonstration messages or voice interaction, device and technical data, and any information you choose to enter. Please do not enter confidential, privileged, regulated, health-related, financial, or other sensitive information in the demonstration.
Hartwell Legal is fictional. The demonstration is not a law firm or legal service, does not create an attorney-client relationship, and does not give legal advice, value legal claims, transfer you to a real lawyer, send real text messages, book a real appointment, or open a legal matter.
5. How we disclose information
Graytech may disclose information to service providers that process it for a business purpose, including:
- Lovable/Lovable Cloud and related infrastructure providers for website hosting and operation.
- Supabase for database, authentication, storage, Edge Functions, and account-related email.
- Cloudflare for network delivery, bot management, and security.
- GoHighLevel for customer relationship management, forms, funnels, workshops, marketing email, and SMS when those functions are used.
- Google Workspace for direct person-to-person business email and collaboration.
- Stripe through GoHighLevel, PayPal, and Paddle for applicable payment, billing, subscription, fraud-prevention, and transaction support.
- Analytics, email, communications, security, professional-adviser, and infrastructure providers used to operate the business.
Today, Deborah Gray is the only Graytech person with administrative access to website records. If Graytech later gives employees, independent contractors, developers, virtual assistants, or implementation partners access, access will be limited to the work they perform and subject to appropriate confidentiality and data-handling obligations. Graytech may also disclose information:
- At your direction or with your consent.
- To complete a transaction or provide a service you requested.
- To comply with law, court order, subpoena, or other valid legal process.
- To investigate fraud, security incidents, misuse, or threats to rights or safety.
- In connection with a merger, financing, acquisition, reorganization, sale of assets, or similar business transaction, subject to appropriate protections and notice when required.
Graytech does not sell, rent, or trade personal information, provide leads to advertisers or referral partners, use personal information for targeted advertising, or share mobile opt-in information with third parties for their own marketing.
6. Retention
Graytech keeps personal information only for as long as reasonably needed for the purpose collected, the relationship, legal obligations, dispute resolution, and security. Subject to those considerations, Graytech's approved operating schedule is:
- Raw assessment answers: 30 days, unless the submission becomes part of an active client relationship or the submitter asks Graytech to retain it for follow-up.
- Assessment result, score if later implemented, and basic contact record: 12 months after the last meaningful interaction.
- Service inquiries and contact-form records: 12 months after the last meaningful contact.
- Active-account information: for the life of the account.
- Closed or canceled account profile information: generally 90 days after closure, except for records that must be retained.
- Workshop and newsletter contact records: until unsubscribe or deletion, subject to suppression records.
- Unsubscribe and suppression records: as long as reasonably necessary to honor the opt-out.
- Contracts and project records: generally for the contract term and seven years afterward.
- Payment, tax, and accounting records: generally seven years or the period required by law and legitimate accounting needs.
- Security and system logs: according to the relevant system configuration and security need.
Deletion from active systems may not immediately remove data from backups. Backup copies may remain until overwritten through the service provider's ordinary backup cycle and will not be restored for ordinary business use after a valid deletion request except where necessary for recovery, security, or legal compliance.
These periods may be shortened or extended when reasonably necessary to comply with law, resolve a dispute, prevent fraud or abuse, enforce an agreement, protect security, or follow a written client agreement. Graytech must implement and verify the deletion routines supporting this schedule before promising that a deletion has been completed.
7. Cookies and similar technologies
Graytech uses limited cookies and similar technologies for:
- Security and bot management.
- Authentication and continuity for authorized paid-user accounts.
- Limited first-party session analytics.
- Remembering technical preferences where applicable.
See the Cookie Notice for current cookie details. Browser settings may allow you to block or delete cookies, but blocking essential security or authentication technologies may prevent parts of the site from working. Graytech does not currently use advertising cookies or cross-site behavioral advertising.
8. Email and SMS choices
Service, account, transaction, and request-related communications are sent as needed to respond to you or provide a requested service. Marketing communications are optional.
You may unsubscribe from marketing email by using the unsubscribe link or contacting support@graytech.dev. You may opt out of marketing SMS by replying STOP. Reply HELP for help.
Message frequency varies, and message and data rates may apply. Opting out of marketing does not prevent Graytech from sending a non-marketing message that is necessary for an active transaction, account, appointment, security matter, or service you requested.
Graytech may keep a minimal suppression record after an unsubscribe or STOP request so that it can continue honoring the choice.
9. Security
Graytech uses administrative, technical, and service-provider measures intended to protect personal information, including access controls and database rules designed to prevent public reading of assessment submissions. No website, transmission method, or storage system is completely secure. Graytech therefore cannot guarantee absolute security, privacy, confidentiality, availability, or error-free operation.
You are responsible for using a strong, unique password, protecting account credentials, and notifying Graytech promptly if you suspect unauthorized account access.
10. Your choices and requests
You may ask Graytech to:
- Confirm whether Graytech maintains personal information about you.
- Provide access to or a copy of information reasonably associated with you.
- Correct inaccurate information.
- Delete information, subject to legal, contractual, security, suppression-list, accounting, backup, and dispute-related exceptions.
- Withdraw optional marketing consent or object to certain uses.
- Close an account.
Send requests to support@graytech.dev. Graytech may need to verify your identity and authority before acting. Graytech will respond within a reasonable period and as required by applicable law. These voluntary request options do not waive or limit any rights provided by law, and a request may be denied or limited when an exception applies.
Paid-user accounts do not currently include automatic self-service deletion. Graytech will provide a visible account-deletion request link that opens a request to support@graytech.dev.
11. Children and eligibility
The website, assessment, workshops, and services are intended for business users age 18 or older. They are not directed to children, and Graytech does not knowingly collect personal information from children under 13. If you believe a child provided personal information, contact support@graytech.dev so Graytech can review and delete it where appropriate.
12. United States processing
Graytech currently offers its services intentionally to customers in the United States. Graytech and its providers may process information in the United States and other locations where they operate, subject to their agreements and applicable law.
13. Third-party services and links
The website may link to or integrate with third-party services. Graytech does not control those services' independent privacy, security, or content practices. Review their terms and privacy notices before providing information to them.
14. Changes to this Policy
Graytech may update this Policy as practices, services, providers, or law change. The revised version will show a new "Last updated" date and will be posted at https://graytech.dev/privacy. Graytech will provide additional notice when required or when a change materially affects how previously collected information is used.
15. Contact
Grayson Strategies, LLC, doing business as Graytech Studio
601 S. Service Road, #1510
Moore, Oklahoma 73160
Email: support@graytech.dev
Business contact: deborah.graytech@zmail.com · 405-233-4092
