Grace Period Privacy Policy

Last updated July 16, 2026

The short version
  • We sync invoices, client contacts, and payment status from the accounting platform you connect (or from a CSV / manual entry) — nothing more.
  • AI drafting runs through OpenRouter. We do not permit any model provider to train on your data.
  • By default, every reminder is reviewed and approved by you before it sends — you can also opt a stage into auto-send, but that's a policy you set, never a decision Grace Period makes on its own.
  • If you subscribe to a paid plan, our billing partner Polar handles your payment details as merchant of record — we never see or store your card number.
  • We don't sell your data and we don't run ads. The only cookies we set without asking are the ones that keep you signed in. For analytics we use Google Analytics — it sets a cookie, so it stays off unless you accept it.
  • You can disconnect any accounting platform, or ask us to delete your data entirely, at any time.

This summary is for orientation only — the full text below is what governs.

This is a first version of our privacy policy, written to be accurate rather than exhaustive. As Grace Period grows we'll expand it — and we'd rather you email us a question than assume.

1. Who we are

Grace Period is operated by Space Cadet d.o.o., a company registered in Croatia, European Union.

Space Cadet d.o.o. · Ulica Ivana Šibla 17, 10000 Zagreb, Croatia
OIB: 36241253193 · Commercial Court in Zagreb, MBS: 081627179
Represented by Dino Sakoman, Director

Because we're incorporated in the EU, GDPR isn't an external rulebook we comply with from a distance — it's the law our own company operates under. We are the data controller for the account information you give us directly, and typically a data processor for the invoice and client data you sync from your own accounting platform, acting on your instructions.

2. What Grace Period does, briefly

Grace Period connects to your accounting software (QuickBooks, Xero, FreshBooks, or FreeAgent) — or accepts invoices you enter by hand or import via CSV — detects overdue invoices, and drafts AI-written payment reminder emails. By default, you review and approve every draft before it sends; you can also opt a stage into auto-send once you trust the tone. When a client pays, pending reminders stop automatically.

3. Information we collect

Account information. Your name, email address, and workspace membership, handled by our authentication provider, Clerk. If you sign in via Google or another identity provider, we receive only the profile fields that provider shares.

Accounting and invoice data. When you connect an accounting platform, we read (never write) your open invoices, client contact details, amounts, due dates, and payment status via that platform's official OAuth API. If you use manual entry or CSV import instead, we store exactly what you type or upload.

Email content. The reminders drafted and sent on your behalf, and — when our reply-intelligence feature is active — the content of a client's reply, so we can detect disputes, questions, or payment promises and pause the follow-up schedule accordingly.

Usage and activity data. A per-invoice history (drafted, approved, sent, delivered, bounced, paid) that powers the activity trail you see in the product. Separately, if you accept analytics, we count page views and a few product milestones through Google Analytics, so we can tell which parts of Grace Period actually get used — never including your invoice, client, or email content (see §8).

Subscription and billing information. If you subscribe to a paid plan, our billing partner, Polar, collects and processes your payment details as the merchant of record for that purchase — we never see or store your full card number. We receive only your plan, subscription status, and renewal date from Polar so the product can reflect them.

We deliberately do not collect your clients' payment card numbers or bank details — Grace Period never processes the payments your clients send you (see §7). That's separate from the subscription billing above, which is your payment to us, not your client's payment to you.

4. How we use AI

Reminder drafting is powered by large language models accessed through OpenRouter. To draft a reminder, we send the model the facts needed to write it — client name, invoice number, amount, due date, and how many days overdue it is — plus your sender name, tone preference, and signature.

We do not permit model providers to train on this data, and we do not use your invoice or client data to train any AI model ourselves. If a model provider's own policies ever conflicted with that, we would not use them.

5. How we send and receive email

Outbound reminders, draft notifications, and the weekly digest are sent through our email provider, Resend, either from Grace Period's own domain (with your reply-to address attached) or, if you've connected one, your own verified sending domain.

When a client replies, Resend routes a copy to us for classification (dispute, question, payment promise, etc.) alongside your own inbox — you always receive the reply too. We keep only what's needed to run that classification and log it on your activity trail.

6. Where your data lives

Application data (invoices, contacts, reminders, settings, activity logs) is stored with Convex, our database provider. The application itself runs on Vercel. OAuth tokens for connected accounting platforms are stored server-side and are never exposed to your browser or to other users.

The providers that process data on our behalf (our subprocessors) are:

  • Clerk — authentication and workspace membership
  • Convex — application database
  • Vercel — application hosting
  • OpenRouter — AI reminder drafting
  • Resend — sending and receiving email
  • Google (Google Analytics) — optional analytics that loads only if you accept it; it sets a cookie and processes data on Google's infrastructure (see §8)
  • Polar — billing and subscription management for paid plans, acting as merchant of record for that purchase (see Polar's own privacy policy for how it handles your payment details)
  • The accounting platform you choose to connect (QuickBooks/Intuit, Xero, FreshBooks, or FreeAgent) — governed by that platform's own privacy terms for the data it holds

7. Payments — what we don't do

Grace Period is not a payment processor and not a collections agency. We never hold, route, or touch your clients' money. When a reminder includes a payment link, it is always your own payment page (your Stripe link, your bank details) — never ours. Payments always go directly from your client to you. (This is separate from your own subscription payment to Grace Period, handled by Polar — see §3.)

8. Cookies and analytics

The only cookies we set without asking you are the ones required to keep the product working: a session cookie from Clerk (so you stay signed in) and a short-lived state cookie during the OAuth handshake when you connect an accounting platform (it expires in 15 minutes and exists purely to prevent cross-site request forgery). Neither is used for advertising. The one optional cookie — Google Analytics — is covered below, and it stays off until you accept it.

For analytics we use Google Analytics to understand how Grace Period is used. It sets a cookie and stores an identifier on your device, so we ask first: on your first visit a banner offers Accept or Decline, and Google Analytics does not load, set any cookie, or send anything to Google unless you accept. Its legal basis is your consent, which you can withdraw at any time by clearing this site's data in your browser. We keep Google's advertising signals switched off — here it measures traffic only and is never used for ads.

When it does run, we use it to count page views and a handful of product milestones — a workspace being created, an accounting platform being connected, a reminder being approved, a subscription starting — so we can tell which parts of Grace Period actually get used. We never send it your invoice, client, or email content, and addresses that could identify a record are stripped in your browser before anything is sent: an invoice page is recorded as /invoices/[id], never the invoice's actual id, and the one-click approval links we email you are never recorded at all.

An earlier version of this policy promised that if we ever added analytics which store data on your device, the consent banner would come first. That is exactly what we do for Google Analytics — off by default, shown a banner, loaded only on your yes.

9. Data sharing

We share data only with the subprocessors listed in §6, each acting on our instructions to run the product. We do not sell your data, rent it, or share it with data brokers or advertisers. We do not use your data for any purpose beyond operating Grace Period for you.

10. International data transfers

Some of our subprocessors are based outside the European Economic Area (notably in the United States). Where that's the case, we rely on the safeguards those providers make available for international transfers, such as Standard Contractual Clauses.

11. Data retention and deletion

We keep your data for as long as your workspace is active. If you disconnect an accounting platform, we stop syncing new data from it immediately; previously synced invoices remain until you delete them or close your account.

To request deletion of your account and associated data, email hello@graceperiod.app. We're early-stage enough that this is currently handled by a human rather than a self-serve button — we aim to complete deletion requests within 30 days.

12. Your rights

If you're in the EEA, UK, or a jurisdiction with similar protections, you have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with your local data protection authority. As our company is based in Croatia, our supervisory authority is the Croatian Personal Data Protection Agency (AZOP), though you may also contact the authority in your own country.

To exercise any of these rights, email hello@graceperiod.app.

13. Children

Grace Period is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

14. Changes to this policy

If we make material changes, we'll update the date at the top of this page and, for significant changes, email the address on your account.

Questions about this privacy policy? Write to hello@graceperiod.app. Also see our Terms of Service.

Google Analytics, only if you accept: one cookie, no ads. Privacy policy