Legal

Privacy Policy

Last updated: September 2026

Overview

Grove treats privacy as a core design requirement, not an add-on. We believe children's data deserves the highest level of protection. This policy explains what we collect, why, and how we protect it.

Data Isolation

Every school on Grove operates on its own completely isolated database. No data is shared between schools. This isolation is enforced at the infrastructure level, not the application level.

GroveHQ staff use server-side credentials to reach each school's isolated project for platform operations — such as school directory details and aggregate health metrics (counts and status, not individual records). That access does not include child content: Grove staff cannot view child names, dates of birth, parent emails, safeguarding contacts, observation content, photos, or any per-child or per-family record. Operational checks stay at the infrastructure and directory level; child and family data remains visible only to the school's authorized staff and parents through the Grove app.

Data Storage

School data — child profiles, observations, photos, documents, and messages — is stored on Canadian servers, governed by the Personal Information Protection and Electronic Documents Act (PIPEDA).

Crash and error reports from the mobile app are handled differently. They go to Sentry, a company in the United States, so those reports are stored outside Canada. While a report is held there, United States courts, law enforcement, and national security authorities can seek access to it under United States law. The next section says what a crash report contains and what is stripped out of it first.

What We Collect

Crash and Error Reports

When the Grove app hits a fault, it sends a report so we can find the cause and fix it. A report holds the name and wording of the error, the lines of code that failed, your device model and operating system, the version of Grove you are running, the reference code shown on the error screen, and a trail of the steps taken in the app before the fault — with the content of those steps removed.

Before a report leaves the device, Grove strips out the data the app was handling and keeps only a note of its shape — “an object with 4 fields”, never the fields themselves. Children's names, photos, observations, and message contents are not part of a crash report, and no screenshot is ever attached.

One part cannot be filtered automatically: the wording of the error itself, which Grove's own code writes. We write those messages to describe the fault and not the family. No machine checks every one.

Reports go to Sentry, our crash-reporting provider, and are stored in the United States. We use them to diagnose faults in the app — not to measure or profile how anyone uses Grove.

What We Never Do

Data Retention

Casual content (photos, community posts, routine messages) is automatically deleted after a school-configured retention period. Formal records (consent forms, medical notes, incident reports) are retained for a minimum of 7 years as required by regulatory obligations.

Your Rights

You can export your child's complete learning portfolio at any time. You can request deletion of your account and personal data. Your keepsakes belong to you — even after leaving the school.

Contact

Questions about privacy? Contact us at privacy@getgrove.ca