Privacy

We meter water, not people.

Grifo records how much water came out of a hydrant and which account authorized it. That record belongs to your utility. This page explains what the device captures, where it goes, and what we will never do with it.

Last updated: August 9, 2026

The short version

What we collect

Draw records

Each authorized draw produces a record: the hydrant identifier, the device serial, the start and end time, the volume in gallons, and the contractor account whose credential opened the valve. This is the metering data the whole system exists to produce.

Credential data

To authorize a draw, we hold what the utility provisions: the contractor company, the account or permit it maps to, and a credential identifier tied to a crew member's device. The NFC handshake is offline and happens on contact — the phone powers the exchange, and we do not read the contents of the phone, its contacts, its photos, or its location history.

Device telemetry

The unit reports its own health over LoRa: battery and turbine state, valve position, firmware version, signal quality, and tamper or impact events. Telemetry describes the hardware, not the person standing next to it.

People who contact us

If you email hello@grifowater.com, we keep your message, your address, and whatever you chose to include so we can answer and follow up. We don't add you to a marketing list off the back of a support request.

This website

The site you're reading is static. It sets no cookies, embeds no third-party scripts, and runs no analytics or advertising trackers. There is nothing here to opt out of.

Every contact route on the site is a plain mailto: link — there are no forms, so nothing is submitted to us until you deliberately send an email from your own client. Our hosting provider processes standard web request data (such as IP address and user agent) to serve pages and protect against abuse, as any web host does.

How we use it

What we never do

Who we share with

Your utility

The city or utility that deploys Grifo receives the draw records for its own hydrants. In practice we are a processor acting on the utility's instructions — the records are its data, held under its retention and public-records rules.

The systems you already run

Records flow into the tools the utility already licenses — billing in Tyler, draw maps in Esri ArcGIS, tamper work orders in Cityworks. Once data lands there, it is governed by the utility's agreements with those vendors, not by this page.

Service providers

We use a small number of vendors for hosting, network connectivity, and email. They may process data only to provide those services to us, under contract, and may not use it for their own purposes.

Legal requests

We disclose data when a valid legal process requires it, or to protect against fraud, tampering, or a threat to safety. Where we are permitted to, we tell the affected utility first.

How long we keep it

Draw and billing records are kept for as long as the utility's own records schedule requires — these are financial records for water that was sold, and utilities generally must retain them for a set number of years. The retention period is set in the utility agreement, not by us.

Device telemetry is kept on a shorter operational window, long enough to diagnose faults and spot tamper patterns. Support email is kept as long as it's useful for the account, then deleted.

When an agreement ends, we return or delete the utility's data at its direction, apart from anything we're legally required to keep.

Security

Credentials are verified cryptographically, and the valve is fail-secure: at rest the nut free-spins and only the electronics can engage the clutch, so a damaged or compromised device withholds water rather than releasing it. Destroying the unit bricks the auxiliary valve — it does not open it.

Data is encrypted in transit, access is limited to staff who need it to run the service, and tamper events are logged. No system is perfect; if a breach affects your data, we will notify the utility and any other parties required by law without undue delay.

Your choices and rights

Depending on where you live, you may have the right to access, correct, or delete personal data about you, or to object to certain processing. Texas residents have these rights under the Texas Data Privacy and Security Act; other states and countries grant comparable ones.

Contractors and crew members: your credential is provisioned by the utility, so start with them — they control who is authorized on which hydrants. If it's easier, write to us and we'll route it.

Utility staff: requests about draw records generally belong to you as the controller of that data. We will help you fulfil them.

To make a request, email hello@grifowater.com. We'll verify who you are before acting, and we will not discriminate against anyone for exercising a privacy right.

Public records

Data held by or on behalf of a city may be subject to public-records law — in Texas, the Public Information Act. If someone requests hydrant draw data from your utility, the utility decides what must be released. That determination is theirs to make, and this policy does not override it.

Changes to this policy

If we change how we handle data in a way that matters, we'll update this page and move the date at the top. For material changes affecting a deployed utility, we notify our contacts there directly rather than relying on you to re-read a web page.

This policy does not describe children's data: Grifo is deployed on municipal infrastructure and is not directed to children under 13, and we don't knowingly collect their information.

Privacy questions

hello@grifowater.com

Same inbox as everything else. Write to us about a data request, a records question from your city attorney, or anything on this page that isn't clear enough.