Grant AuthBack to home

Grant Auth

Privacy notice

What Grant handles when you connect accounts and delegate provider access to an agent.

Last updated July 15, 2026

What Grant handles

Grant stores account identifiers from Clerk, the provider connections you create, the agent profiles and permissions you select, and audit events for brokered requests. Connected providers may return resource metadata and operation results that Grant needs to show you or return to your authorized agent.

Provider credentials

OAuth tokens, API credentials, and refresh tokens are encrypted before storage. Grant uses them server-side to perform requests allowed by your agent profile. Grant does not intentionally return downstream provider credentials to an agent.

How data is used

Grant uses this data to authenticate you, connect providers, enforce agent permissions, execute authorized provider operations, maintain audit and revocation records, investigate failures, and protect the service. Grant does not sell connected-account data.

Service providers and connected products

Clerk provides user authentication, Vercel hosts the application, and Convex stores application state. When you use a connector, Grant sends the required request data to that product under the permissions you approved. Those services process data under their own terms and privacy notices.

Retention and control

Disconnecting a provider removes Grant's stored connection and stops agents from using it. Revoking an agent stops that Grant credential immediately. Some providers require separate upstream revocation, which Grant identifies in the connection flow. Audit records may be retained while your account is active so access can be reviewed. You may request account-data deletion by contacting support.

Security and beta status

Grant limits credential use to server-side connector code, encrypts stored provider credentials, and records broker activity. No system is perfectly secure. Grant is an open beta, so avoid connecting accounts or permissions you are not prepared to test in a beta service.

Contact

Privacy and deletion requests can be sent to support@grantauth.com. Do not include passwords, API keys, OAuth tokens, or other secrets in support email.