Skip to content

Legal

Privacy Policy

Last updated: August 31, 2026

1. Overview

Ungrid.ai (“we,” “us,” or “our”) is operated by Matthew Shilts. This page explains what data we collect, why we collect it, how long we keep it, and what control you have.

Plain English summary: we collect the minimum needed to run monitoring and alerts, we do not sell your data, and we do not share it for advertising.

1.1 At a glance

  • We collect: account details, system telemetry, and delivery settings (email, verified mobile number, and SMS preferences) so alerts can work. For a Yacht connector, this may include an owner-consented Victron GPS position and a named home harbor.
  • We do not collect: full card numbers (payments are handled by Stripe).
  • We use your data for: service delivery, reliability, billing, and required legal/compliance purposes.
  • We keep poll-result history: up to 30 days.
  • You can request: access, correction, export, or deletion at [email protected].

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address — for account login, alert delivery, and communication
  • Name — for personalized communications
  • Password — handled by Firebase Authentication; Ungrid does not store it in plaintext
  • Installer enrollment details — installer company, direct phone, optional website, and permission to contact you if we need to help complete installer enrollment
  • Optional recovery phone number — for a support callback only if you lose access to your authenticator; never used for sign-in or SMS codes
  • Verified mobile number and SMS preferences — only when you choose to enroll a recipient for transactional Low Battery Alerts, Critical Battery Alerts, High Load Alerts, or Recovery Confirmations

2.2 Third-Party Monitoring Credentials

To monitor your power system, we collect login credentials for your monitoring platform (e.g., Victron VRM, EG4 Cloud). These credentials are:

  • Encrypted and stored in Google Cloud Secret Manager
  • Used solely to read your system data
  • Never stored in plaintext or logged
  • Deleted through our verified account-deletion process

2.3 System Monitoring Data

We collect energy system data including battery state of charge, solar production, load consumption, and system status. Poll results are retained for up to 30 days. Operational delivery records may be retained longer to investigate reliability and security incidents.

2.4 Yacht Location Information

For a Victron Yacht connection, you may separately consent to Ungrid processing the latest timestamped GPS position supplied by your Victron GX device through VRM. We use that position for location-sensitive weather, solar timing, the Sunrise Energy Brief, the Sunset Reserve Outlook, Dashboard Energy Insight, and location-aware Storm Watch for yachts. We also collect the named home harbor you choose during setup for labeled routine-weather and scheduled-guidance context when a fresh yacht position is unavailable.

The latest accepted position replaces the prior saved position and remains with the yacht's monitored-system record while the connector is active; connector or account deletion removes that record. A home harbor is never presented as the yacht's live position. If the last confirmed position is stale and shows the yacht offshore, Storm Watch pauses until a fresh Victron position is available.

We send the coordinates needed for a request to Visual Crossing for location-specific weather and to Open-Meteo for timezone and solar-timing data. Starlink may transport Victron data, but Ungrid does not use Starlink as a location source. Exact yacht coordinates are not sent to OpenAI.

2.5 Alert Delivery Information

We use your verified account email and any verified recipient email addresses you select to deliver alerts, briefs, and outlooks. For selected Low Battery Alerts, Critical Battery Alerts, High Load Alerts, and Recovery Confirmations, you may also choose verified recipient mobile numbers for SMS delivery.

2.6 Read-only dashboard members

When an account owner invites someone to view confirmed dashboard readings, we process the invited email address, the authenticated member identity, invitation and revocation records, and the member's access to that account's monitoring data. Access is available only after the invited person opens the one-time invitation delivered to the invited email address and signs in with that exact address. Members do not receive billing, payment, connector credentials, recipient delivery details, recovery information, or account-control access.

2.7 SMS Alerts and Mobile Messaging

SMS alerts are optional and transactional. To enroll, a recipient enters a United States mobile number in the authenticated Ungrid application, agrees to the SMS disclosure, receives a verification code, and confirms the number. After verification, the account owner chooses which eligible Low Battery Alerts, Critical Battery Alerts, High Load Alerts, and Recovery Confirmations may be sent by SMS.

SMS messages include system notifications such as Low Battery Alerts, Critical Battery Alerts, High Load Alerts, and Recovery Confirmations, plus optional read-only Ask Ungrid AI replies to battery, solar, cached-weather, and Tesla charging questions. The question is processed with the relevant confirmed system or vehicle facts to prepare the reply; Ungrid does not send control commands, change settings, wake a vehicle, or trigger a vendor reading from SMS. Frequency varies with monitored-system activity and your configured alert thresholds; Sunrise Energy Briefs and Sunset Reserve Outlooks remain email-only. Message and data rates may apply. Reply STOP to opt out of SMS alerts or HELP for help. You can also pause SMS or remove the verified number from the Recipients page.

We do not sell, rent, or share mobile phone numbers, SMS opt-in data, or SMS consent records with third parties or affiliates for their own marketing or promotional purposes. We share this information only with service providers acting on our behalf, such as Twilio and OpenAI, as needed to verify numbers, deliver transactional SMS alerts, prepare Ask Ungrid AI replies, process STOP/HELP requests, and maintain delivery and security records.

2.8 Payment Information

Payment processing is handled by Stripe. We do not collect or store your card number. We receive only subscription status, last four digits (for display), and billing history.

2.9 Usage Data

We may collect basic usage data such as pages visited, alert delivery timestamps, and account activity logs. If you create an account from one of our market guides, we may store one predefined campaign code with your account and map it to an allowlisted market, landing page, channel, and campaign. We do not store raw URLs, raw referrers, arbitrary query parameters, advertising click identifiers, search terms, or IP addresses in the acquisition record.

2.10 Public Ask Ungrid AI

On public marketing, Independence, sign-in, and sign-up pages, Ask Ungrid AI can answer general questions about Ungrid products or the Installer Channel. The current question and a short, browser-session conversation context are sent to OpenAI to prepare a response. We do not retain public chat transcripts in Ungrid account records, and the feature is not a place to submit credentials, payment details, contact information, or installer-application information.

We use limited pseudonymous operational metadata, such as persona, page surface, response status, latency, and approved call-to-action selection, to protect the service from abuse and evaluate reliability. Approved campaign links may include first-party query parameters to preserve the selected offering through sign-up and billing; we do not use public chat text, IP addresses, or form fields for advertising profiles.

The predefined account-acquisition code described above is processed separately from public chat.

3. How We Use Your Information

  • Provide and maintain monitoring, alerts, Sunrise Energy Briefs, and Sunset Reserve Outlooks
  • Authenticate your account and apply notification preferences
  • Process subscriptions and billing events through Stripe
  • Troubleshoot outages, failed alerts, and integration issues
  • Improve reliability using aggregated or de-identified usage patterns
  • Comply with legal obligations

3.1 Data Sharing

We share limited data with service providers needed to run Ungrid.ai, including cloud hosting, billing, message composition, email delivery, SMS verification, and transactional SMS delivery. Those providers process data on our behalf. We do not sell personal data, share mobile information for third-party marketing or promotional purposes, or share data with ad networks.

4. What We Do NOT Do

  • We never sell your personal or energy data to third parties
  • We never share your data for advertising or marketing by third parties
  • We do not share mobile phone numbers or SMS consent records with third parties or affiliates for their own marketing or promotional purposes
  • We never monetize your energy usage patterns
  • We never use your data to train machine learning models for sale
  • We do not use third-party tracking cookies or advertising pixels

5. Data Storage and Security

Your data is stored on Google Cloud Platform. Connections to Ungrid use TLS/HTTPS, Google Cloud-managed encryption protects data stored at rest, and monitoring credentials are isolated in Secret Manager. Access to service data is limited to authorized personnel and automated services under the principle of least privilege.

6. Data Retention

  • Account data — retained while your account is active
  • Installer enrollment contact details — retained with the installer account while it is active so we can complete enrollment or provide account support
  • Poll-result history — retained for up to 30 days
  • Operational records — retained as needed for delivery, reliability, security, and compliance
  • Credentials — deleted through the verified disconnection or account-deletion process
  • Recipient and SMS data — retained while your account and alert configuration are active, then deleted through the verified account-deletion process; limited operational suppression and delivery records may be retained as needed for compliance, reliability, and security
  • Payment records — retained as required by financial regulations (typically 7 years)

After we verify an account-deletion request, we disable monitoring and delete tenant-scoped account, system, recipient, operational, and credential records. Short-lived hashed rate-limit records expire automatically, and financial records may remain where law requires.

7. Third-Party Services

  • Google Cloud Platform — infrastructure and data storage
  • OpenAI — message composition using selected energy readings, recipient name, and saved communication preferences; monitoring credentials, recipient email addresses, and exact yacht coordinates are excluded
  • Visual Crossing — location-specific weather forecasts using the coordinates needed for the request
  • Open-Meteo — timezone and solar-timing data using the coordinates needed for the request
  • Google Workspace Gmail API — email delivery
  • Twilio — SMS number verification, transactional SMS delivery, and STOP/HELP processing
  • Stripe — payment processing
  • Victron VRM / EG4 Cloud — system data reading (using your credentials)

8. Your Rights

Email [email protected] from your account email to exercise any of the following rights:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your data upon request
  • Withdraw consent by cancelling your account
  • Stop SMS alerts by replying STOP, pausing SMS on the Recipients page, or removing the verified mobile number

We aim to acknowledge requests within 5 business days and complete most requests within 30 days.

9. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes, we will also notify you via email.

11. Contact

Questions about this Privacy Policy: [email protected]