Grain / Docs / Data and privacy

Docs

Data and privacy

Grain keeps artifact files in the workspace and lets you pull them back through the CLI. You can use local workspaces in the Mac app or hosted cloud workspaces on E2B, then control audience access with public, password-protected or invite-only sharing.

Updated 2026-09-04Facts verified 2026-09-04By the Grain team

Deployment choices

ChoiceWhere it runsWhat remains true
Local workspaceThrough the Mac appArtifact files remain workspace files and can be exported.
Hosted cloud workspaceOn E2BArtifact files remain workspace files and can be exported.

What lives in a workspace

Artifact files live in the workspace and can be pulled through the CLI. The same file model applies to local workspaces in the Mac app and hosted cloud workspaces on E2B.

Sharing modes

ModeWho can reach itUse when
Public linkAnyone who has the linkThe artifact is intended for an open or broadly shareable audience.
Password-protected linkAnyone who has both the link and passwordYou need a simple shared secret around the artifact.
Invited people onlyPeople explicitly invitedAccess should follow a named audience rather than possession of a link.

Export artifact files

grain pull [--force]

The pull command receives remote changes into the linked local folder while preserving local work during normal reconciliation. Its only flag is --force. Expected output is pulled <n> remote change(s), deleted <n> local path(s), preserved <n> local change(s). An unknown option reports Unknown pull option: <option>. Usage: grain pull [--force]. If another sync client holds the workspace, the command reports that the workspace lease is active and tells you to stop that client or wait for its lease to expire.

Platform boundaries

Grain is Mac first and the Windows version has a waitlist. The core runs on Linux. These platform boundaries do not change where artifact files live or the three available sharing modes.

What this page does not claim

  • It does not claim that a password link is equivalent to invited-person access. They are separate sharing modes.
  • It does not say that hosted cloud workspaces are the only deployment choice. Local workspaces are available through the Mac app.
  • It does not promise a desktop platform beyond Mac today. Windows has a waitlist, while the core runs on Linux.
  • It does not treat files in the local checkout as a separate export format. The CLI pulls workspace files back into the linked folder.

Frequently asked questions

Where do Grain artifact files live?

They live in the workspace and can be pulled back through the CLI.

Can anyone open a public share made with Grain?

Anyone with the link can reach it. Use password protection or invited-person access for a narrower audience.

How do I export Grain workspace files?

Use the pull command from a linked local folder. It receives remote changes and normally preserves local work during reconciliation.

Does Grain run only in the cloud?

No. It supports local workspaces through the Mac app and hosted cloud workspaces on E2B. The core also runs on Linux.

Choose the audience before sharing

Review the sharing mode, then publish only to the people who should be able to open the artifact.

Free forever. No card. Bring your own agent.

Sources · facts verified 2026-09-04