Effective date: 9 August 2026
Last updated: 9 August 2026
This policy explains what GPA Babel (“the app”) does with your information. It covers the app on Android and iOS.
Who is responsible
GPA Babel is provided by Grid and Garden (“we”, “us”), of 116 AGNES RD STE 200 KNOXVILLE TN 37919. For the purposes of the UK/EU GDPR we are the data controller. Contact us at contact@gridandgarden.com.
The short version
Everything you create in GPA Babel, your categories, items, words, photos and audio recordings, is stored on your device. There is no account and no sign-up, and we run no server that receives your learning content, so we cannot see it. The only things that leave your device are crash reports, and, only if you choose to enter your own Pexels API key, image searches. We show no advertising, we use no analytics, and we sell nothing.
What the app stores and collects
| What | Where it is held | Why |
|---|---|---|
| Categories, learning items and the words you enter for them | On your device | The core function of the app |
| Photos you take or choose for an item | On your device | To illustrate items you are learning |
| Audio you record for an item | On your device | To practise pronunciation |
| Practice statistics, XP, level and streak | On your device | To track your progress |
| Settings — interface language, practice languages, reminder schedule | On your device | To remember your preferences |
| Your Pexels API key, if you enter one | On your device | To authenticate your own image searches |
| Crash and error reports | Google (Firebase Crashlytics) | To find and fix crashes |
| Image search terms, and images you select | Pexels — only if you enter an API key | To search for and download pictures |
We do not collect your name, email address, contacts, location, advertising identifier or any other identifier.
Crash reporting
When the app crashes or hits an unexpected error, a report is sent to Google’s Firebase Crashlytics so we can fix it. A report contains the error, a stack trace, and basic technical information about the device: model, operating system version, app version, and the state of the app at the moment of the crash.
It does not contain your learning content, your photos, or your audio recordings.
Crashlytics is operated by Google, which processes the data under its own terms and may process it outside the UK/EU under its transfer safeguards. See the Firebase privacy documentation.
Image search (optional)
The app can search Pexels for pictures to use on your learning items. This feature is off until you enter your own Pexels API key in Settings. If you never enter a key, the app never contacts Pexels.
When you do use it, your search term is sent to the Pexels API to fetch results, and any image you choose is downloaded to your device. Pexels processes that request under its own terms — see the Pexels privacy policy.
Companion sessions on your local network
Companion mode lets several nearby devices share one learning table for a class or a group session.
- The devices talk directly to each other over your Wi-Fi network. Session data does not pass through any server of ours, or anyone else’s.
- While you are hosting, your device advertises the session on the local network using Bonjour/mDNS so nearby devices can find it. The advertisement contains the session name, a port number and an internal session identifier. It never contains the pairing code, so discovering a session is not enough to join it.
- Joining requires the six-character pairing code shown on the host’s screen. A device that does not present the correct code is refused before any connection is established.
- While a session is running, the host shares the items on the table — including their pictures and audio — with the devices that have joined.
- The advertisement and the session both stop when you end the session.
The connection is local and is not encrypted. Use companion sessions only on networks you trust.
Permissions and why they are needed
| Permission | Why | What happens if you refuse |
|---|---|---|
| Camera | To photograph objects for your learning items, and to scan a host’s QR code to join a companion session | You can still choose photos from your library, or join by typing the codes |
| Microphone | To record pronunciations for your learning items | Items work without audio |
| Photos | To choose existing pictures, and to save pictures you capture | You can still use the camera, or search Pexels |
| Notifications | To send the practice reminders you turn on in Settings | No reminders; everything else works |
| Local network (iOS) / Wi-Fi multicast (Android) | To find, host and join companion sessions on nearby devices | Companion mode is unavailable; the rest of the app works |
Each permission is requested only when you first use the feature that needs it, and every one of these features is optional.
Backups
This differs by platform, and it is worth knowing which one you are on:
- Android: the app opts out of Android’s automatic cloud backup (
android:allowBackup="false"). Your learning content is not copied to Google’s servers, and it will not reappear automatically on a new device. - iOS: app data is included in iCloud and encrypted local backups in the normal way, because nothing is excluded from backup. If you back your device up, your learning content is in that backup, held under Apple’s terms.
On either platform, use Settings → Import / Export to make a backup you control and move it to another device yourself.
Legal basis for processing (UK/EU)
- Storing your learning content on your device — performance of a contract: it is the service you asked for. It never reaches us.
- Crash reporting — legitimate interests, namely keeping the app working and fixing defects that would otherwise affect you.
- Camera, microphone, photos, notifications and local network access — consent, given through the operating system’s permission prompt and withdrawable at any time in system settings.
- Image search — consent, given by choosing to enter a Pexels API key.
Where we rely on consent, you can withdraw it at any time by revoking the permission in system settings, or by clearing the Pexels API key in Settings, with no effect on the lawfulness of processing carried out beforehand.
Retention and deletion
- On your device — your content stays until you delete it in the app or uninstall the app. Uninstalling removes all of it. Because we never receive it, there is nothing for us to delete on request.
- Crash reports — retained by Google under the Firebase Crashlytics retention schedule. To request deletion of crash data associated with your device, contact us at contact@gridandgarden.com and we will act on it.
- Pexels searches — retained by Pexels under its own policy. We receive nothing.
Export your data at any time from Settings → Import / Export.
Your rights
Under the UK/EU GDPR you have rights to access, correct, erase, restrict, object to and port your personal data. Under the California Consumer Privacy Act you have rights to know, delete, correct, and opt out of sale or sharing.
In practice, most of these you exercise directly: the data is on your device, so you can view, change, export and delete it yourself at any time. For anything concerning crash reports, email contact@gridandgarden.com and we will respond within 30 days.
We do not sell or share personal information, and we do not use it for cross-context behavioural advertising.
You may also complain to your data protection authority — in the UK, the Information Commissioner’s Office.
Security
- Your content is held in the app’s private storage, protected by the operating system’s app sandbox and by your device’s own encryption and screen lock.
- Crash reports and image searches travel over HTTPS.
- Companion sessions are protected by a pairing code that is checked before any connection is accepted, and the pairing code is deliberately kept out of the network advertisement. Those sessions are not encrypted, so use them only on networks you trust.
No method of storage or transmission is perfectly secure.
Children
The app is not directed at children under 13 and we do not knowingly collect their data. It requires no account and collects no personal details. If you believe a child has provided us with personal information, contact contact@gridandgarden.com and we will delete it.
Changes to this policy
If this policy changes, the updated version is published at this URL with a new effective date. Material changes will also be noted in the app’s release notes.
Contact
contact@gridandgarden.com
Grid and Garden, 116 AGNES RD STE 200 KNOXVILLE TN 37919