Skip to main content
Haptic Grove

Privacy

What we collect, which is almost nothing.

This website sets no cookies, runs no analytics, and has no forms. The apps we publish and the client work we do are covered further down.

Last updated 13 September 2026

This website

hapticgrove.com is a set of static files. There is no account system, no database, no contact form, and no comment section. We set no cookies and store nothing in your browser. We run no analytics, no advertising pixels, no session recording, and no tag manager, so we cannot tell you how many people read this page, which is the point.

Your web host's logs

Like any website, the server that delivers these files keeps standard access logs: IP address, timestamp, the file requested, referring page, and user agent. These are generated by the hosting provider for security and troubleshooting, retained for a short period, and not used to build a profile of you or combined with anything else.

Fonts

The typefaces on this site load from Google Fonts. When a page loads, your browser requests those font files from fonts.googleapis.com and fonts.gstatic.com, which discloses your IP address and user agent to Google. Those requests are governed by Google's own privacy policy. Nothing else on this site is served by a third party, and if you would rather we removed that dependency, say so: the fonts can be self-hosted and we will.

If you email us

When you write to hello@hapticgrove.com, we receive whatever you put in the message and it sits in our email provider's system. We keep correspondence as long as it is useful for the relationship and delete it on request. We do not add you to a mailing list, we do not have a mailing list, and we do not sell, rent, or share contact details with anyone.

Apps we publish

Haptic Grove LLC publishes its own applications on the Apple App Store and Google Play. This section is the company-level policy for those apps. Each app also has its own policy page linked from its store listing, and where the two differ, the app's own policy governs for that app, because what an app collects depends on what the app does.

What our apps collect

The standing rule is that an app asks for what it needs to function and nothing that merely might be useful later. Depending on the app, that can include:

  • Account information if the app has accounts: an email address, a display name, and an authentication credential. Passwords are stored only as salted hashes, or not at all where sign-in is delegated to Apple, Google, or another identity provider.
  • Content you create in the app, which is yours. We do not read it for any purpose other than operating the service, and we do not use it to train machine learning models.
  • Device and diagnostic data: crash reports, performance traces, app version, OS version, device model. This is used to fix defects.
  • Purchase records where an app sells something. Payment is processed by Apple or Google. We receive a transaction record and entitlement status; we never see your card number.

System permissions such as camera, microphone, photos, contacts, location, and notifications are requested only at the point a feature needs them, with an in-context explanation, and the app remains usable where the platform allows you to decline.

Tracking and advertising

Our apps do not serve third-party advertising, do not include advertising SDKs, and do not track you across other companies' apps or websites. We therefore do not request permission under Apple's App Tracking Transparency framework and do not use the advertising identifier. We do not sell or share personal information as those terms are defined under the CCPA as amended by the CPRA, which includes cross-context behavioral advertising.

Analytics

Where an app uses product analytics, it is limited to aggregate usage of features, it is disclosed in that app's own policy and in its store privacy disclosures, and it is not linked to advertising networks. Any app aimed at children uses no analytics at all.

Push notifications

If an app sends notifications, delivery runs through Apple Push Notification service or Firebase Cloud Messaging, which requires a device token. You can turn notifications off in the operating system at any time, and doing so does not disable the rest of the app.

Deleting your account and your data

Any app of ours that lets you create an account lets you delete it from inside the app, in line with Apple's App Store guidelines and Google Play's data deletion requirements. Deletion removes your account and associated content from production systems promptly, and from encrypted backups as those backups age out on their normal rotation, typically within 35 days. You can also request deletion by emailing hello@hapticgrove.com from the address on the account, and we will confirm when it is done. Records we are legally required to retain, such as transaction records for tax purposes, are kept for the period the law requires and nothing longer.

Service providers

Running an app means using infrastructure: cloud hosting, authentication, crash reporting, push delivery, and the app stores themselves. Each app's own policy names the providers it uses. They process data on our instructions under written terms, and none of them are permitted to use your data for their own purposes.

Children

Unless an app's store listing and its own policy say otherwise, our apps are general-audience products not directed to children under 13, and we do not knowingly collect their personal information. Any app we publish into a children's category will comply with COPPA, Apple's Kids Category rules, and Google Play's Families policy, will collect no more than the app needs to function, and will carry no advertising or third-party analytics. If you believe a child has provided us information, email us and we will delete it.

International transfers

Our infrastructure is hosted in the United States. If you use an app from outside the United States, your information is processed there. Where an app serves users in the EU or UK, the transfer safeguards and the lawful basis for processing are set out in that app's policy.

Store disclosures

Apple's privacy nutrition labels and Google Play's Data safety section are filled in per app from the same facts described here, and are updated when an app's behavior changes rather than at a release's convenience.

Client data during an engagement

Project work is a different matter from this website, and it is the part that actually deserves your attention. Our standing practice:

  • Your data stays yours. Code, data, and cloud accounts are created in your name or transferred to you at handover.
  • Least access, for the shortest time. We ask for the narrowest credentials that let the work proceed, and we ask you to revoke them when the engagement ends.
  • Production data is not a development environment. Where we need realistic data to build against, we prefer anonymized or synthetic copies.
  • AI features are scoped deliberately. When a system we build sends your content to a model provider, we tell you which provider, what leaves your environment, and what the retention terms are, before it ships. Where the work calls for it, we build against providers that contractually do not train on your data, or run models inside your own infrastructure.
  • Subprocessors are disclosed. If a project needs a third-party service that touches your data, it is named in the engagement agreement.
  • Breach notice. If we learn of a security incident affecting your data in something we host or operate, we tell you promptly and in writing.

The specifics for any given project, including confidentiality, data processing terms, and anything your regulators or funders require, go in that project's written agreement, which governs over this page.

Your rights

California residents have rights under the CCPA as amended by the CPRA, including the right to know what personal information a business has collected, to have it deleted, to correct it, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we have no behavioral advertising to opt out of. People in the EU and UK have comparable rights under the GDPR, including access, correction, erasure, portability, and objection. We will not discriminate against you for exercising any of them.

For an app account, the fastest route is the delete option inside the app. For anything else, email us. We answer within 45 days, and usually within one.

To exercise any of them, email hello@hapticgrove.com. Because we hold so little, most requests resolve in a single reply.

Children and this website

This website is aimed at businesses and nonprofit organizations and is not directed to children under 13. We do not knowingly collect information from them here. The rules for our published apps are in the apps section above.

Changes

If this policy changes, the date at the top changes with it. Material changes affecting an active engagement will be raised with you directly rather than left for you to notice here.

Contact

hello@hapticgrove.com

Haptic Grove LLC, Los Angeles, California. This is also the developer contact for our App Store and Google Play listings, and the address for privacy requests, data deletion requests, and COPPA inquiries.

A note on this document. It describes our actual practice in plain language. It is not legal advice, and we are not lawyers. Before you rely on it, have counsel review it against the jurisdictions you operate in and the contracts you have signed, particularly if you handle health, financial, or donor data.

© 2026 Haptic Grove. Software and AI tooling for businesses and nonprofits.

What we build How we work Privacy Email us