Grant Auth
Privacy notice
What Grant handles when you connect accounts and delegate provider access to an agent.
Last updated July 15, 2026
What Grant handles
Grant stores account identifiers from Clerk, the provider connections you create, the agent profiles and permissions you select, and audit events for brokered requests. Connected providers may return resource metadata and operation results that Grant needs to show you or return to your authorized agent.
Provider credentials
OAuth tokens, API credentials, and refresh tokens are encrypted before storage. Grant uses them server-side to perform requests allowed by your agent profile. Grant does not intentionally return downstream provider credentials to an agent.
How data is used
Grant uses this data to authenticate you, connect providers, enforce agent permissions, execute authorized provider operations, maintain audit and revocation records, investigate failures, and protect the service. Grant does not sell connected-account data.
Service providers and connected products
Clerk provides user authentication, Vercel hosts the application, and Convex stores application state. When you use a connector, Grant sends the required request data to that product under the permissions you approved. Those services process data under their own terms and privacy notices.
Retention and control
Disconnecting a provider removes Grant's stored connection and stops agents from using it. Revoking an agent stops that Grant credential immediately. Some providers require separate upstream revocation, which Grant identifies in the connection flow. Audit records may be retained while your account is active so access can be reviewed. You may request account-data deletion by contacting support.
Security and beta status
Grant limits credential use to server-side connector code, encrypts stored provider credentials, and records broker activity. No system is perfectly secure. Grant is an open beta, so avoid connecting accounts or permissions you are not prepared to test in a beta service.
Contact
Privacy and deletion requests can be sent to support@grantauth.com. Do not include passwords, API keys, OAuth tokens, or other secrets in support email.