What we collect, and why.
This policy explains what Groundwork collects when you visit the site, search, make an account, use the AI tools, join a team, buy a plan or write to us; why we collect it; who else handles it; how long it’s kept; and how to see, correct or delete it. Last updated October 1, 2026.
Who we are
Groundwork, a trade name of Groundworks LLC, runs this website (“Groundwork”, “we”, “us”). We decide what personal information is collected here and how it’s used, which makes us its “controller” under European and UK law and a “business” under California’s. The quickest way to reach us about anything on this page is by email, at inquiries@groundworkdemographics.com.
This policy covers the website, the site reports, the AI tools, accounts, teams and plans, and the contact form. It doesn’t cover other companies’ websites that we link to, or Stripe’s checkout and billing pages, which follow Stripe’s own privacy policy.
What we collect
What you give us
- Your email address, when you make an account or sign in. We check it’s yours by emailing it a six-digit code, or, if you sign in with Google or Microsoft, by their word that the address is yours. From them we receive that address and whether they’ve confirmed it; their answer can include your name and profile picture, which we don’t keep. We never see your Google or Microsoft password. If you change your address, we confirm the new one with a code and email the old one to say so.
- Your password, if you choose one. We keep only a one-way hash of it, never the password itself. When you set one, we check it isn’t a known leaked password by sending Have I Been Pwned the first five characters of a one-way hash of it; the password, and your email, never leave our server.
- What you do with your account. Each action: whether it was a site search or one of the AI tools, and when; and for a search, the place you searched (as you typed or picked it) and its map location, rounded to about 100 meters. We also record when you started the free trial, and when you last signed in and used the site, and keep the business type you last chose for your searches and the addresses you add as your own locations (up to 200, each with its map location), so they’re the same on every device you sign in on.
- Addresses you look up from Excel, if you use Groundwork in Excel. The add-in sends us only the addresses in the cells you point it to, and looks each one up as a search, recorded the same way. Besides the cells you point it to, it reads only what it wrote before and the cells it’s about to write to (to check they’re empty), and it doesn’t send anything else in your workbook.
- Places you ask about through Claude or ChatGPT, if you connect one of them to your account. The assistant sends us only what a report needs (the address or map location, and the business type), and each report it runs is recorded as a search, the same way. We never see your conversation with the assistant.
- What you give the AI tools: questions, descriptions of a business or of what you look for in a site, and documents you upload or paste. We don’t save these; see The AI tools and your documents.
- Other people’s email addresses, if you own a team and add them to it. Please add only people who expect to hear from us.
- Your message, if you use the contact form: your name, email address, company if you give one, and what you write.
- Payment details, which you enter on Stripe’s checkout page, not ours. Stripe tells us the plan and whether payment went through; we never receive your card number.
- Password logins. If we’ve given you a password login, we also hold your name if you gave it to us, how many searches you’ve run, and the places you looked up and AI tools you used (the most recent fifty). We store only a one-way hash of the password, never the password itself.
- The earlier demo. If you used Groundwork’s earlier free demo, we hold the email address you confirmed, how many lookups you used and the ZIP codes you looked up (the most recent fifty).
What we collect automatically
- Your IP address and browser details, which every request to a website carries. Our host keeps them in its logs for a short time, and we use IP addresses to limit how often one connection can make requests.
- Two cookies and a few notes in your browser’s session storage, all needed for the site to work; see Cookies and your browser.
- Anonymous page-view counts: which page was opened, the site you came from, and your country, browser and device type, counted without cookies and without identifying you.
What we get from others
- If a team’s owner adds you to their team, we get your email address from them.
- Stripe tells us about a team’s subscription: its plan, its status and its billing dates.
What we don’t collect
We never ask for your device’s location (the site turns browser location access off entirely). We don’t collect government ID numbers, health information or bank or card numbers, and we don’t buy information about you from anyone.
How we use it
European and UK law ask us to name the legal basis for each use, so it’s in the last column. Elsewhere, the first two columns are what matter.
| Why | What it uses | Legal basis (EU and UK) |
|---|---|---|
| To run your account, and the reports and AI tools you ask for | Your email address, your actions, what you give the AI tools | Performing our contract with you |
| To count actions against your allowance, and run the trial and plans | Your actions, trial date and plan | Performing our contract with you |
| To take payment and keep billing records | The plan and Stripe’s references for it | Performing our contract; keeping records the law requires |
| To keep the site secure and working: stopping abuse, limiting request rates, fixing errors | IP addresses, browser details, logs | Our legitimate interest in a secure, working service |
| To understand what people use Groundwork for, and improve it | Your actions and the places searched; page-view counts | Our legitimate interest in improving the product |
| To send what your account needs: codes that confirm your address or reset your password, team invitations, notice of changes to your plan or these terms | Your email address | Performing our contract with you |
| To write to you personally about your account or what you were looking at | Your email address and recent searches | Our legitimate interest in helping customers; tell us to stop and we will |
| To answer your message | What you sent through the contact form | Taking steps you asked for |
| To meet legal obligations and deal with legal claims | Whatever the obligation or claim requires | Legal obligation; our legitimate interests |
We don’t use your personal information for advertising, we don’t sell it, we don’t use it to make automated decisions with legal or similarly significant effects on you, and we don’t use it to train AI models. There are no newsletters or automated email sequences: if we write to you, it’s a person writing, and you can tell us to stop.
The AI tools and your documents
When you use an AI tool, what it needs to answer is sent to OpenAI: your question or description, the names and figures of the reports involved, and, for a document check, the document itself (the PDF, or the text you paste).
- We send it with storage turned off, so it isn’t kept in OpenAI’s response history. OpenAI may keep API data for up to 30 days to watch for abuse, and doesn’t use it to train its models, under OpenAI’s privacy policy.
- We don’t save your questions, descriptions or documents: they’re held in our server’s memory only while they’re needed to answer you. What we record is the action: that you used the tool, and when.
- One exception: when you ask the Excel add-in for a figure we don’t have, our server’s logs note the figure asked for (not who asked), so we know what data to add next. Logs are kept for a short time.
- A memo is written from a report’s public figures and the site’s name or address. We keep each memo for up to 30 days, so a memo for the same report and business type is shown again instead of being written twice.
- Upload only documents you’re allowed to share. If a document contains other people’s personal information (tenants’ or employees’ names, for example), you’re responsible for having the right to share it.
Teams
- A team’s owner can see the email addresses on their team, when each was added and whether each person has signed in yet. They can’t see anyone else’s searches, AI requests or how many actions they’ve used.
- Everyone on a team can see who owns it and which plan it’s on.
- Leaving a team, or being taken off one, doesn’t delete your account: it goes back to a free account, with its history.
- If you’ve been added to a team you didn’t expect, leave it from your account page, or write to us.
How long we keep it
| What | How long we keep it |
|---|---|
| Your account, its actions and your team membership | While the account exists. Deleting it from your account page removes it straight away; if you ask us to delete it, we do so within 30 days. |
| Emailed codes | Only a one-way hash, deleted as soon as the code is used. An unused code stops working after 15 minutes, and its hash is cleared out afterwards. |
| Your password | Only a one-way hash, while your account exists. Changing the password replaces it; deleting the account deletes it. |
| A connection to Claude or ChatGPT | Nothing is stored for it. The assistant holds its own key, which works for an hour and is renewed while the connection is used at least every 60 days. Removing Groundwork from the assistant, using Sign out everywhere or deleting your account ends it. |
| Rate-limit and daily counters | A day at most |
| Contact form messages | Until we no longer need them for the conversation, or you ask us to delete them |
| Billing records | As long as tax and accounting law requires, usually up to seven years. Stripe keeps its own records under its policy. |
| Server logs | A short time, set by our host: days, not months |
| What you give the AI tools | Not kept by us. Up to 30 days at OpenAI, as described above. |
| AI memos | Up to 30 days |
| Drive-time outlines around a site searched | Up to 30 days, with nothing about who searched it |
Deleted information can remain in database backups for a short time until they’re replaced. If you ask us not to contact you, we keep a note of that, so we go on honoring it.
How we protect it
- The whole site is served over an encrypted connection (HTTPS).
- Passwords and emailed codes are stored only as one-way hashes; passwords with scrypt, which is slow to work through on purpose, so a stolen copy can’t be guessed quickly. Sign-in cookies are signed, can’t be read by the page’s scripts, and stop working after 30 days.
- Our database can be reached only by our own server, with a secret key; public access is switched off for every table.
- How often codes and passwords can be tried is limited, per connection and per email address.
- Card details never touch our servers.
No system is perfectly secure. If a breach affects your personal information, we’ll tell you, and the authorities where required, as the law requires.
Your rights and choices
Whoever and wherever you are, you can ask us to:
- tell you what personal information we hold about you, and give you a copy in a form you can reuse;
- correct anything that’s wrong;
- delete it (we keep only what the law requires, such as billing records; an account that owns a team with a plan running needs the plan cancelled first);
- stop writing to you personally;
- stop or limit a particular use, or object to one based on our legitimate interests.
You can also do some of this yourself, under Settings on your account page: change the email address your account uses, and delete your account.
Some of these are legal rights where you live, in the EU, the UK, California and a growing number of U.S. states. We’d rather honor them for everyone.
How to ask
Write to inquiries@groundworkdemographics.com from the email address on your account, saying what you’d like. We’ll confirm the request is yours, usually just by replying to that address, and answer within 30 days; if a request needs longer, as the law allows, we’ll tell you why. There’s no charge. Someone else can ask on your behalf with your signed permission, and we may still check with you directly.
If we say no
We’ll explain why. You can ask us to reconsider by replying, and we’ll answer within 45 days. If you’re still not satisfied, you can complain to your state’s attorney general or, in the EU or UK, to your data protection authority (in the UK, the Information Commissioner’s Office).
We won’t treat you differently, charge you more or give you a worse service for using any of these rights.
For California residents
In the past twelve months we’ve collected these categories of personal information, from the sources and for the purposes described above, and kept each for as long as How long we keep it says:
| Category | Examples | Disclosed, for a business purpose, to |
|---|---|---|
| Identifiers | Email address, IP address, name (contact form and password logins) | Our hosting, database, email and payment providers |
| Commercial information | Your plan, its billing period and payment status | Our database and payment providers |
| Internet or other electronic network activity | Your searches and AI requests, page views, request logs | Our hosting and database providers; OpenAI, for AI requests |
| Professional information | The company you name in the contact form | Our database and email providers |
The only sensitive personal information we handle is what signs you in (the code we email, or a password we issued), and we use it only for that. We don’t sell or share personal information, including that of anyone under 16. Under California’s “Shine the Light” law: we don’t disclose personal information to anyone for their own direct marketing.
Visitors outside the United States
Groundwork is run from the United States and made for U.S. sites. Your information may be stored and processed in the United States and in the other countries where our service providers work. Where European or UK law applies to a transfer, we rely on the safeguards our providers offer for it, such as the European Commission’s standard contractual clauses or the EU–U.S. Data Privacy Framework.
Children
Groundwork is a tool for businesses, not for children. We don’t knowingly collect personal information from anyone under 16. If you think a child has given us information, tell us and we’ll delete it.
Changes to this policy
When we change this policy, we update the date at the top. If a change affects how we use your information, we’ll email account holders before it takes effect. The current version is always the one on this page.
How to reach us
For anything about your privacy, or to use any of the rights above: