Privacy Policy

Last Updated: 4 May 2026

Our Commitment

At Grainium we believe your privacy matters as much as your photography. This Privacy Policy explains what we collect, how we use it, who we share it with, and how to exercise your rights, across the Grainium mobile applications (iOS and Android), our website, and our AI-powered tools. We are committed to transparency and to complying with global standards including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and Apple's and Google's developer policies.

Information We Collect

We collect only what is necessary to operate the Service. Specifically: • Account & Contact Info: email address (via Apple Sign In or Google Sign In), display name, profile photo, date of birth (used solely to enforce our 16+ age requirement; only your year of birth is stored after verification). • User Content: photographs, captions, comments, ratings, reviews, store contributions, and event RSVPs that you choose to upload or post. • Location Data: approximate or precise device location, used in real time for the Discover / Near Me / Events features. Precise location is never retained on our servers unless you explicitly tag it to a public post. • Camera & Photo Library Access: used only when you actively choose to take a photo, upload a scan, or extract metadata. Photos are not read in the background. • AI Interactions: the prompts you send to Grainium AI, the responses returned, and the images you submit for inversion / identification. • Tool Usage Metrics: anonymized counts of how often the Light Meter, Dev Timer, and other tools are used, to prioritise improvements. • Device & Diagnostic Data: device model, OS version, app version, language, time zone, crash logs, and performance metrics. • Subscription Status: whether you have an active Grainium Pro entitlement (received from Apple App Store, Google Play, or RevenueCat). We never see your payment card or bank details.

How We Use Your Data

We use your information to: • Operate core Service features (discovery, gallery, events, AI assistance, professional tools). • Verify that you meet the 16+ age requirement at signup. • Personalise the community feed and recommendations. • Provide customer support and respond to your help requests. • Detect, prevent, and respond to abuse, fraud, security incidents, and Terms violations. • Comply with legal obligations and respond to lawful requests. • Improve the Service, including training and refining our AI models on anonymized prompts. You may opt out of AI training contributions in Settings. We NEVER sell your personal data. We do not run cross-app or cross-site behavioural advertising tracking. If we ever enable advertising features, we will request your permission via Apple's App Tracking Transparency prompt and Android's equivalent first.

Third Parties & Sub-Processors

To run Grainium reliably we rely on a small, vetted set of service providers. They process data only on our instructions and under contracts that meet GDPR Article 28 standards. • Supabase (database, authentication, storage) — hosts your account, profile, posts, and uploaded media. • Apple Sign In and Google Sign In — authenticate your account; only your email and (if you allow) name are shared with us. • RevenueCat — manages subscription entitlements; receives your anonymous app user ID and the Apple/Google purchase receipt only. • Apple App Store and Google Play — process all subscription payments; we never see card details. • Google Maps Platform — renders maps and resolves addresses for Discover / Near Me; receives query strings and approximate location. • Google Firebase Crashlytics — captures app crashes and non-fatal errors so we can fix them. Receives stack traces, breadcrumbs, app and device metadata, and a one-way hash of your user identifier. Never receives your raw account ID, email, photos, or AI prompts. • Google Firebase Analytics — counts which features are used so we can prioritise improvements. IDFA collection is explicitly disabled in our configuration. Receives event names (e.g., 'opened gallery', 'used light meter'), a hashed user identifier, and your subscription tier. • Google AdMob — serves non-personalized banner and interstitial advertising. Configured to never request the advertising identifier (IDFA) so personalized ad targeting is impossible regardless of your ATT response. • Google Generative AI (Gemini) — powers AI Assist features; processes your prompts and the images you submit. Conversations are not used to train Google's foundation models. A complete and current sub-processor list is available on request at privacy@grainium.tech.

Tracking & Advertising (ATT)

Grainium does not currently display third-party advertising. If and when we enable ad-supported features in a future release: • On iOS, we will present Apple's App Tracking Transparency prompt before any tracking SDK initialises. You can decline; declining does not reduce app functionality. • On Android, we will request Advertising ID access via the platform-standard permission flow. • You can revoke consent at any time from your device's system settings, and Grainium will honour the choice on the next app launch. We do not use your photos, your location, or your AI interactions to target advertising.

Data Retention & Security

We retain your data only for as long as needed to provide the Service or to meet legal obligations. • Account, profile, posts, and uploads: kept until you delete them or close your account. • Crash logs and diagnostics: retained for 90 days, then deleted. • AI chat history: associated with your account until you delete it, anonymized in aggregate after 90 days. • Backups: rolling 30-day encrypted backups; deleted accounts are purged from backups within 30 days. Data is stored in encrypted form at rest (AES-256) and in transit (TLS 1.3). Access by Grainium staff is limited, audited, and bound by confidentiality.

Your Rights

Regardless of where you live, you can: • Access and download the personal data we hold about you. • Correct inaccurate data. • Withdraw consent for non-essential processing (e.g., AI training contributions). • Object to processing or restrict it. • Port your data to another service. • Lodge a complaint with your local data protection authority. Residents of the European Economic Area, the United Kingdom, and Switzerland additionally have rights under GDPR / UK GDPR. The legal bases on which we process your data are: contractual necessity (to provide the Service), legitimate interests (safety, fraud prevention, product improvement), legal obligation, and consent (for optional features such as AI training contributions).

California Privacy Rights (CCPA / CPRA)

California residents have additional rights under the CCPA, as amended by the CPRA: • Right to know what personal information we have collected about you, including categories, sources, purposes, and third parties with whom we share it. • Right to delete the personal information we have collected. • Right to correct inaccurate personal information. • Right to opt out of sale or sharing of personal information. Grainium does not sell personal information and does not share it for cross-context behavioural advertising. • Right to limit the use of sensitive personal information. • Right not to be discriminated against for exercising any of these rights. To exercise any of these rights, email privacy@grainium.tech. We will respond within 45 days as required by law.

Account Deletion

You can permanently delete your Grainium account at any time from inside the mobile app: Profile → Account Settings → Delete Account. Deletion is immediate and irreversible. All of your profile data, uploads, comments, AI history, and follower relationships are removed from production systems within 24 hours and purged from backups within 30 days. No grace period applies. If you cannot access the app and need help deleting your account, email privacy@grainium.tech with the email address tied to your account.

Children & Age Requirement

Grainium is intended for users aged 16 and over. We do not knowingly collect personal information from children under 16. We verify age at signup by requesting your date of birth; accounts that fail this check are blocked. If we learn that we have inadvertently collected information from someone under 16, we will delete that data without delay. Parents or guardians who believe their child has created an account should contact privacy@grainium.tech.

International Transfers

Grainium is operated from the European Union. If you access the Service from outside the EU, your data is transferred to and processed in jurisdictions whose data protection laws may differ from your own. Where we transfer personal data outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

Changes & Contact

We may update this Privacy Policy from time to time. Material changes will be communicated in-app and via a notice at the top of this page. The 'Last Updated' date above always reflects the current version. Questions, requests, or complaints? • General privacy: privacy@grainium.tech • Data Protection / GDPR: privacy@grainium.tech • Copyright (DMCA): copyright.grainium@nicoleslittlebrother.tech • General contact: grainium@nicoleslittlebrother.tech