Privacy Policy

Grove Privacy Policy

Effective: July 25, 2026

Grove helps you grow a virtual forest using step totals read from Apple Health. This policy explains what Grove processes and why.

Information Grove Processes

Grove reads step-count data from Apple Health only after you grant permission. Health data is used to show progress and calculate in-app goals. Grove does not use Health data for advertising, sell it, or share it with data brokers. Grove does not write records to Apple Health.

Grove stores account information, goals, sessions, step ledgers, trees, preferences, and notification settings in Amazon Web Services. Apple may process sign-in information when you choose Apple sign-in. Password accounts use a username and do not collect an email address.

If notifications are enabled, Grove processes an app installation identifier, push token, timezone, reminder settings, and delivery status. If you request manual password recovery, Grove stores hashed, not raw, recovery-device and network signals, plus coarse device model, OS version, locale, timezone, app version, and timestamps. Recovery signals expire within 90 days and requests within 30 days. Grove does not collect advertising identifiers, serial numbers, contacts, or Health data for recovery.

Use and Disclosure

Information is used to provide Grove, synchronize devices, authenticate accounts, send requested reminders, prevent abuse, recover password accounts, troubleshoot failures, and protect the service. Service providers process information only to operate these functions. Privacy-safe crash reporting may receive scrubbed technical diagnostics; Grove disables default personal-information collection and does not send Health data, account identifiers, credentials, push tokens, or request bodies.

Retention and Deletion

When you delete an account, Grove removes authentication identities, provider links and credentials, device-account links, recovery records, push tokens, notification associations, and profile identifiers. Product records such as trees, goals, sessions, step ledgers, preferences, timestamps, step totals, and outcomes are retained under a newly generated random surrogate. The temporary link to the former account is deleted. These retained records are intended to be irreversibly deidentified and unlinkable at the user level; Grove does not claim that detailed datasets are mathematically anonymous in every possible context.

Your Choices

You control Health and notification access in iPhone Settings. You may disable reminders in Grove and delete your account in Settings. Apple accounts recover through Apple. Password-account recovery is handled manually through Grove support.

Security, Children, and Changes

Grove uses access controls, encryption in transit, encrypted cloud storage, limited retention, and audited administrative procedures. Grove is not directed to children under 13. Material policy changes will be posted here with a new effective date.

Contact

For privacy or support requests, visit Grove Support.