We meter water, not people.
Grifo records how much water came out of a hydrant and which account authorized it. That record belongs to your utility. This page explains what the device captures, where it goes, and what we will never do with it.
Last updated: August 9, 2026
The short version
- The device records a draw event: hydrant, timestamp, gallons, and the account that authorized it. That's the product.
- Draw records are the utility's data. We process them on the utility's behalf and hand them to the systems it already runs.
- No cameras, no microphones, no GPS on the crew. The device knows its own hydrant's location, not where anyone went.
- We never sell or rent data, and we don't use it for advertising.
- This website sets no cookies and runs no third-party analytics or trackers.
What we collect
Draw records
Each authorized draw produces a record: the hydrant identifier, the device serial, the start and end time, the volume in gallons, and the contractor account whose credential opened the valve. This is the metering data the whole system exists to produce.
Credential data
To authorize a draw, we hold what the utility provisions: the contractor company, the account or permit it maps to, and a credential identifier tied to a crew member's device. The NFC handshake is offline and happens on contact — the phone powers the exchange, and we do not read the contents of the phone, its contacts, its photos, or its location history.
Device telemetry
The unit reports its own health over LoRa: battery and turbine state, valve position, firmware version, signal quality, and tamper or impact events. Telemetry describes the hardware, not the person standing next to it.
People who contact us
If you email hello@grifowater.com, we keep your message, your address, and whatever you chose to include so we can answer and follow up. We don't add you to a marketing list off the back of a support request.
This website
The site you're reading is static. It sets no cookies, embeds no third-party scripts, and runs no analytics or advertising trackers. There is nothing here to opt out of.
Every contact route on the site is a plain mailto: link — there are no forms, so nothing is submitted to us until you deliberately send an email from your own client. Our hosting provider processes standard web request data (such as IP address and user agent) to serve pages and protect against abuse, as any web host does.
How we use it
- Authorize draws — verify that a credential is valid for that hydrant before the clutch engages.
- Meter and bill — turn gallons into a line item that posts to the utility's billing system.
- Flag tampering and loss — surface impact events, unauthorized attempts, and unexplained draws to the utility.
- Keep hardware alive — diagnose faults, schedule replacements, and ship firmware updates.
- Answer support requests — reconcile a disputed reading, fix a failed handshake, replace a damaged unit.
- Report in aggregate — corridor and program totals for the utility's own conservation and revenue reporting.
What we never do
- Sell, rent, or trade draw records, credential data, or contact details — to anyone, at any price.
- Advertise. None of this data feeds ad targeting, profiling, or lookalike audiences.
- Track crews. The device knows where it is bolted. It does not follow a phone between hydrants or off the job.
- Watch or listen. There is no camera and no microphone in the unit.
- Gate fire flow. The 4.5″ steamer is unmodified and override is mechanical — no record is created, and no authorization is consulted, when a fire crew opens a hydrant.
How long we keep it
Draw and billing records are kept for as long as the utility's own records schedule requires — these are financial records for water that was sold, and utilities generally must retain them for a set number of years. The retention period is set in the utility agreement, not by us.
Device telemetry is kept on a shorter operational window, long enough to diagnose faults and spot tamper patterns. Support email is kept as long as it's useful for the account, then deleted.
When an agreement ends, we return or delete the utility's data at its direction, apart from anything we're legally required to keep.
Security
Credentials are verified cryptographically, and the valve is fail-secure: at rest the nut free-spins and only the electronics can engage the clutch, so a damaged or compromised device withholds water rather than releasing it. Destroying the unit bricks the auxiliary valve — it does not open it.
Data is encrypted in transit, access is limited to staff who need it to run the service, and tamper events are logged. No system is perfect; if a breach affects your data, we will notify the utility and any other parties required by law without undue delay.
Your choices and rights
Depending on where you live, you may have the right to access, correct, or delete personal data about you, or to object to certain processing. Texas residents have these rights under the Texas Data Privacy and Security Act; other states and countries grant comparable ones.
Contractors and crew members: your credential is provisioned by the utility, so start with them — they control who is authorized on which hydrants. If it's easier, write to us and we'll route it.
Utility staff: requests about draw records generally belong to you as the controller of that data. We will help you fulfil them.
To make a request, email hello@grifowater.com. We'll verify who you are before acting, and we will not discriminate against anyone for exercising a privacy right.
Public records
Data held by or on behalf of a city may be subject to public-records law — in Texas, the Public Information Act. If someone requests hydrant draw data from your utility, the utility decides what must be released. That determination is theirs to make, and this policy does not override it.
Changes to this policy
If we change how we handle data in a way that matters, we'll update this page and move the date at the top. For material changes affecting a deployed utility, we notify our contacts there directly rather than relying on you to re-read a web page.
This policy does not describe children's data: Grifo is deployed on municipal infrastructure and is not directed to children under 13, and we don't knowingly collect their information.
Privacy questions
hello@grifowater.comSame inbox as everything else. Write to us about a data request, a records question from your city attorney, or anything on this page that isn't clear enough.