Privacy policy
The full text below is the policy shipped with the app.
Brainy Grid Privacy Policy
Last updated: 2026-08-13
Brainy Grid is a graphic-dictation app for children. It is built so that a child’s data stays on the child’s device. This policy explains, in plain language, what is stored locally, what leaves the device and when, and how to delete it.
Summary
- Without an account the app works fully offline. In that mode we collect nothing about you or your child.
- Photos of drawings, the child’s exact age, and the local attempt history never leave the device — in any mode.
- An account is optional, is created by an adult behind a parental gate, and exists for exactly two purposes: carrying the subscription to another device and syncing progress across the family’s devices.
- We show no ads, use no advertising identifiers (IDFA/AAID), do no tracking, and share no data with third parties for their own purposes.
- The app is built to the rules that apply to children’s apps: COPPA (US), the GDPR including Art. 8 (EU/EEA), the Apple Kids Category Guidelines and the Google Play Families Policy.
1. Data that stays on the device only
Stored in app storage on your device and never sent to us:
- photos of the child’s drawings and images derived from them (overlays, recognition output);
- exact date of birth / exact age of the child;
- local attempt history;
- app settings, language, selected theme.
Recognition of the drawing runs entirely on the device: the captured photo is processed locally, is never uploaded to our servers — not even temporarily — and is not sent to any external recognition service.
This data is deleted when you delete the child’s profile in the app, when you use “Erase all data” (see section 5), or when you uninstall the app.
2. Data collected when an adult creates a family account
A family account is created only behind the parental gate (an arithmetic challenge) and only after the adult explicitly ticks “I’m over 18 and agree to the Privacy Policy and the Terms of Use”. With no account, none of the following is collected.
| Data | Purpose | Stored with |
|---|---|---|
| Parent’s email | Sign-in, password reset | Supabase (EU) |
| User ID | Links the family’s data and the subscription | Supabase (EU) |
| Child’s name (nickname) | Shows whose progress it is | Supabase (EU) |
| Child’s age band (“4–5”, “6–7”, “8+”) | Difficulty selection | Supabase (EU) |
| Profile avatar and theme | Appearance on other devices | Supabase (EU) |
| Numeric practice metrics (dictations completed, time, match percentages) | Progress sync and the parent report | Supabase (EU) |
| Subscription status and expiry | Premium access on all family devices | Supabase (EU), RevenueCat |
When a child’s name is entered, the app explicitly recommends a nickname or a made-up name. We do not verify whether the name is real and never ask for a surname.
We do not collect: photos, exact date of birth, address, phone number, location, contacts, clipboard contents, advertising identifiers.
3. Who we share data with
We do not sell data and do not share it for advertising or profiling. It is processed only by our processors, acting on our instructions:
- Supabase — database and authentication. The project is hosted in the European Union (Frankfurt); EU parents’ data does not leave the region.
- RevenueCat — subscription management on top of App Store and Google Play. Receives the user ID and purchase history; we do not pass device advertising identifiers to it.
- Apple / Google — payment processing and, if you use them, Sign in with Apple or Google sign-in. Payments are handled by them; we never see card details.
We may disclose data where required by law.
4. Retention
- Practice events (numeric attempt metrics) are kept for no longer than 12 months and are then deleted automatically by a daily server job.
- Child profiles, aggregate statistics and account data are kept for as long as the account exists: they are current state, not a log.
- A child profile deleted in the app disappears from the device immediately and stops syncing. On the server it is marked as deleted: the name, age band and appearance settings are erased, leaving only the deletion marker (so the profile cannot come back from another family device) and the numeric practice metrics — which are removed by the retention period above or by deleting the account.
- After account deletion, all data associated with it is removed from the server immediately and irreversibly.
5. How to delete your data
- A child’s profile: in the app → gear icon → parental gate → “Children” → trash icon on the profile.
- Everything on the device: in the app → gear icon → parental gate → “Erase all data”. This permanently removes all child profiles, drawing photos and images derived from them (from disk), the attempt history, statistics and app settings; the app returns to its first-launch state. The interface language is kept. If you signed in, your cloud data stays — the next item removes that.
- The whole account: in the app → gear icon → parental gate → “Family account” → delete account. All server-side data tied to the account is removed, including profiles, statistics and practice events. To wipe both the server and the device in one action, a signed-in parent gets an “Erase and delete account” button in the “Erase all data” dialog.
- If you cannot sign in, write to privacy@brainygrid.com and we will delete it on request.
6. Children and parental consent
The app is directed to children of roughly 4–8 years old, therefore:
- everything involving the account, purchases and external links sits behind a parental gate — a randomly generated arithmetic challenge;
- only an adult creates the account, and only after explicitly confirming they are over 18 and agree to this policy and to the Terms of Use;
- in the child-facing part of the app nothing can be sent outward: there is no share sheet, no saving to the photo library, no links to a browser or mail client;
- the child’s personal information under COPPA (US) and the GDPR (Art. 8, EU) — above all drawings and exact age — stays on the device, so no “collection” of it takes place in the COPPA sense.
If you believe a child created an account without your knowledge, write to privacy@brainygrid.com and we will delete the account and its data.
7. Your rights
If you are in the EU/EEA or the UK, you have the rights of access, rectification, erasure, restriction and portability, and the right to lodge a complaint with a supervisory authority. Legal bases: performance of a contract (operating the account and subscription) and your consent (creating the account), which you may withdraw by deleting the account.
If you are in California, you have CCPA/CPRA rights; we do not sell or “share” personal information.
Requests: privacy@brainygrid.com.
8. Security
Traffic to the server uses TLS. Family data is isolated at the database level (row-level security): one account’s queries cannot read another account’s rows. The sign-in session is kept in secure device storage (Keychain on iOS, Keystore on Android).
9. Changes to this policy
When this policy changes we update the date at the top of this page. The current version is always reachable from the app via the “Privacy Policy” link — on the purchase screen and on the family-account screen.