Legal
Privacy Policy
Last updated: September 2026
Overview
Grove treats privacy as a core design requirement, not an add-on. We believe children's data deserves the highest level of protection. This policy explains what we collect, why, and how we protect it.
Data Isolation
Every school on Grove operates on its own completely isolated database. No data is shared between schools. This isolation is enforced at the infrastructure level, not the application level.
GroveHQ staff use server-side credentials to reach each school's isolated project for platform operations — such as school directory details and aggregate health metrics (counts and status, not individual records). That access does not include child content: Grove staff cannot view child names, dates of birth, parent emails, safeguarding contacts, observation content, photos, or any per-child or per-family record. Operational checks stay at the infrastructure and directory level; child and family data remains visible only to the school's authorized staff and parents through the Grove app.
Data Storage
School data — child profiles, observations, photos, documents, and messages — is stored on Canadian servers, governed by the Personal Information Protection and Electronic Documents Act (PIPEDA).
Crash and error reports from the mobile app are handled differently. They go to Sentry, a company in the United States, so those reports are stored outside Canada. While a report is held there, United States courts, law enforcement, and national security authorities can seek access to it under United States law. The next section says what a crash report contains and what is stripped out of it first.
What We Collect
- Account information (name, email) for school staff and parents
- Child profiles created by the school (name, class, age group)
- Observations, photos, and learning documentation
- Messages between staff and parents within the platform
- Consent and permission form records
- Crash and error reports from the mobile app, to find and fix faults
Crash and Error Reports
When the Grove app hits a fault, it sends a report so we can find the cause and fix it. A report holds the name and wording of the error, the lines of code that failed, your device model and operating system, the version of Grove you are running, the reference code shown on the error screen, and a trail of the steps taken in the app before the fault — with the content of those steps removed.
Before a report leaves the device, Grove strips out the data the app was handling and keeps only a note of its shape — “an object with 4 fields”, never the fields themselves. Children's names, photos, observations, and message contents are not part of a crash report, and no screenshot is ever attached.
One part cannot be filtered automatically: the wording of the error itself, which Grove's own code writes. We write those messages to describe the fault and not the family. No machine checks every one.
Reports go to Sentry, our crash-reporting provider, and are stored in the United States. We use them to diagnose faults in the app — not to measure or profile how anyone uses Grove.
What We Never Do
- Sell data to third parties
- Use data for advertising
- Send children's photos to external AI services
- Track user behaviour for analytics beyond basic usage
- Share data across schools
Data Retention
Casual content (photos, community posts, routine messages) is automatically deleted after a school-configured retention period. Formal records (consent forms, medical notes, incident reports) are retained for a minimum of 7 years as required by regulatory obligations.
Your Rights
You can export your child's complete learning portfolio at any time. You can request deletion of your account and personal data. Your keepsakes belong to you — even after leaving the school.
Contact
Questions about privacy? Contact us at privacy@getgrove.ca