Privacy Policy

Last updated: September 5, 2026 (UTC)

Introduction

Gramms is a product of SmartCue, Inc. ("we," "our," or "us"), a Delaware corporation. Gramms is an iPhone app that parents and guardians use to make personalized bedtime stories for their children. This policy explains exactly what the app collects, which partners receive it and under what conditions, how long we keep it, and how you remove it.

We comply with the Children's Online Privacy Protection Act (COPPA), including the FTC's 2025 amendments. Children do not use Gramms directly and cannot create an account: a parent or guardian sets everything up, and a child's information is only ever provided by that adult.

This policy describes the current version of the Gramms iPhone app. If an earlier version is installed on your device, some details below may not yet apply to it.

The short version

  • A story needs very little: a child's first name, their age, and the idea you type.
  • Those three things go to OpenAI, which writes the story and reads it aloud.
  • Nothing reaches our voice partner, Cartesia, unless you choose to bring a loved one's voice into Gramms.
  • There is no advertising in Gramms, and we never sell anyone's information.
  • You can close your account inside the app to remove your account and family data, including cloned voices at our voice partner. Limited retention exceptions are explained below.

What We Collect

Account information (parent or guardian)

You sign in with Sign in with Apple. There is no password to create, and Gramms never sees one. From Apple we receive:

Child profile

With your consent, and only what a story actually needs:

We do not ask for a last name, a birth date, a photograph, a description of how the child looks, a school, a location, or a contact detail of any kind for a child.

What you write, and what the app makes

Voice recordings (optional, and treated as sensitive)

Bringing a loved one's voice into Gramms is entirely your choice, and nothing here is collected unless you do it. If you do, we collect:

Before a recording is used, it is checked automatically. Every recording is classified to confirm the speaker is an adult; Gramms will not build a voice from a child's voice. A recording made inside the app is also transcribed, to confirm the person really read the words shown on screen; a file you upload cannot be checked that way, so it rests on the adult check and on your word that the person agreed. Both checks run at OpenAI. Only then does the recording go to Cartesia to build the voice. See "Who receives your information" below.

Requested story-ready updates (optional)

If your app offers story-ready updates and you ask for one, we store an identifier for this app installation, its notification delivery token, your notification permission and app version, and the request linked to your account and story. We also keep your update preference, delivery results, and when an update is tapped or its story is opened or starts playing. Temporary waiting and playback records help us avoid interrupting an experience already in progress. Device safety records track registration order and timing, a registration revision, a hashed delivery token and whether registration is blocked. These help prevent an old sign-in from taking over a newer registration. Allowing notifications does not sign you up for updates about every story.

Each story update is your choice. You can cancel a request or pause story updates in Gramms Settings, and manage notification permission in iPhone Settings. A change needs a connection before our server can apply it. An update already submitted for delivery may still arrive.

App-health information

So we can tell whether the app is working, Gramms records events such as "a story finished" or "a screen failed to load". Each event carries:

We use this number only to understand how the app is behaving, never to identify you or your child, and never for advertising. These events are stored on our own systems, not sent to an advertising or analytics company. Before anything is written down, a filter throws away the fields that would carry a name or a story idea, blanks out anything that looks like an email address or a sign-in token, and shortens long text. Story text and narration are never part of an event. Gramms contains no advertising, no ad networks, and no third-party analytics or attribution software.

How We Use It

We use what we collect only to:

We do not use anyone's information, least of all a child's, for advertising, profiling or marketing. We do not sell or rent personal information, and we do not share it with anyone beyond the service providers named below.

Who Receives Your Information, and When

These companies process information on our behalf and under contract. Each receives only what its job needs, and several receive nothing at all unless you use a particular feature. Each acts as our service provider and handles the information under contract with us.

OpenAI: writing, narration, pictures and safety checks

Writing the story

Receives: your child's first name and age, how they should be referred to in the story, the language you chose, your story idea, and the recap of earlier chapters

When: every time a story or chapter is made

Reading it aloud

Receives: the story text, which contains your child's first name

When: every story read in the app's own narrator voice

Painting the cover

Receives: the story text, to pick one scene worth painting, and then that scene description, to paint it

When: every story that gets a cover

Read-along timings

Receives: the narration audio and the language it is in, not the story text

When: so the words can light up in time with the voice. The transcript is matched against the story on our own server

Safety checks

Receives: your story idea and the story text, and (only if you add a family voice) that voice recording

When: before a story is shown to a child, and before a recording is turned into a voice

See OpenAI's privacy policy.

Cartesia: family voices only

Nothing reaches Cartesia unless you bring a loved one's voice into Gramms. If you never use that feature, this section does not apply to you.

Making the voice

Receives: the voice recording you provided, and the name you gave it

When: once, to build the voice

Reading in that voice

Receives: the story text, which contains your child's first name

When: each time a story is read in that voice

When you remove a voice, we ask Cartesia to destroy it and then read back to confirm it is gone before we let go of anything on our side. If that confirmation does not come, we stop and tell you nothing was removed, rather than report a deletion we could not verify. See Cartesia's privacy policy.

Supabase: our database and file storage

Supabase

Holds: your account, child profiles, stories, narration audio, cover pictures, voice recordings, and app-health events

Purpose: the database, sign-in and file storage behind Gramms

Traffic is encrypted in transit, storage is encrypted at rest by the platform, and database rules restrict every row to the household that owns it. See Supabase's privacy policy.

Railway: where our server runs

Railway

Handles: whatever passes through the Gramms server while a request is being served

Purpose: hosting for the Gramms server

See Railway's privacy policy.

Apple and RevenueCat: subscriptions

Apple

Handles: the payment itself

We never see your card, your Apple ID password, or your billing details

RevenueCat

Receives: your Gramms account identifier and the purchase record Apple issues

Purpose: to tell the app whether your subscription is active

RevenueCat never receives your child's name, age, or any story content. See RevenueCat's privacy policy.

Sentry: crash reports

Sentry

Receives: crash and error reports, the device type and OS version, and the app version

Purpose: so we find out an app is broken before you have to tell us

Sentry is configured not to attach personal information automatically, and error text is filtered and shortened on the way out so a name or a story cannot travel inside an error message. See Sentry's privacy policy.

Expo: app updates

Expo (EAS Update)

Receives: your device's network address and the app version, as part of checking for an update

Purpose: to deliver app improvements between App Store releases

No account, child or story information is involved in an update check. See Expo's privacy policy.

Expo and Apple: requested story-ready updates

Expo Push Service and Apple Push Notification service

Receives: a delivery token, generic notification text and a random request identifier. The notification does not include your child's name, story title, story text or voice recording.

When: to route a story-ready update you requested to your iPhone

To register this delivery route, Expo also receives a device identifier, the app and project identifiers, the notification token type and whether the app uses a development delivery environment. Expo routes the notification through Apple. This is separate from the app-update check above. See Expo's privacy policy and Apple's privacy policy.

We and the providers above are United States companies, and your information is processed on their infrastructure. We may also disclose information if the law requires it, or to protect a child's safety.

How Long We Keep Things

Different records have different retention periods.

Your stories and your child's profile

These are the record of nights that already happened, so we keep them for as long as you want them. They stay until you remove them or close your account. We do not delete them for inactivity.

Voice recordings and voiceprints

The most sensitive thing we hold, and the one we make the fewest promises about. A voice stays for as long as you keep it, and it goes the moment you remove it, from us and from Cartesia. We will not tell you it is kept indefinitely: it is yours to keep or to take away, and we hold it only while you want us to.

Narration audio and cover pictures

These can be made again from the story text, so they are the only things we ever clear out to reclaim space. From time to time we run a clean-up by hand that removes files no story points at any more and that are at least seven days old. It is deliberately not automatic: deletion is the one thing that cannot be undone, so a person looks at what would go before any of it does.

We regularly remove notification request, delivery and response details once they are older than 30 days, and temporary waiting and playback records once they are older than one day. Device registrations and preferences remain while needed to honor your choices. Linked notification records are removed when your account is closed. An anonymous admission count remains to keep the limited pilot from expanding. We also retain device safety records, including the installation identifier, after a registration is removed. They contain no raw delivery token or account or household link, but they are not anonymous. Our regular cleanup removes them when no registration remains and they have been inactive for more than 30 days. These are Gramms retention rules; the delivery providers describe their processing in their privacy policies.

App-health events are removed for your account when you close it. We keep the records the law requires us to keep, such as tax and purchase records; those are held by Apple and by us as the seller, and are not part of your child's information.

Children's Information and Parental Consent

Gramms is used by an adult on a child's behalf. A child cannot create an account, cannot sign in, and is never asked for anything by the app.

Before you add a child, the app shows you in plain language what is collected and who receives it, and you agree to it as an identified, signed-in adult. We record which version of that wording you agreed to, so that if it ever changes materially we know who was told what. We collect only a first name and an age, because that is all a story needs.

As a parent or guardian, you may at any time:

Removing Your Information

Close your account, in the app

Open Gramms, go to Settings, and tap Close your account at the bottom. The app tells you exactly what will go before you confirm. When you do, in this order:

The anonymous pilot admission count and unlinked device safety records are excluded from account deletion. Safety records follow the 30-day cleanup rule above; they contain no child information or account or household link.

If a step cannot be completed, the app stops there and says so plainly: that it stopped partway and cannot yet tell you how much of it finished, rather than reporting a deletion that did not happen. Trying again picks up where it left off. The audio and picture files the deleted stories pointed at are removed in the hand-run clean-up described above rather than in the moment, and so is a stored recording whose removal did not succeed when its voice was destroyed. Closing your account does not cancel an App Store subscription; cancel that in your Apple subscription settings.

Remove a single voice

Remove a family voice in the app at any time. The clone is destroyed at Cartesia and the destruction confirmed, and our copy of the recording goes with it. Stories that voice already read stay in your library.

Remove one piece

To remove just a part of what we hold (one story, one name), write to robin@gramms.ai and we will take care of it. There is no in-app equivalent for a partial removal yet, so a person handles this one.

If you cannot open the app

Write to robin@gramms.ai from the email address on your account, and we will verify it is you and complete the deletion within 30 days, usually far sooner. Full instructions are on our account deletion page.

Security

No system is perfect. If we ever discover a breach affecting your information, we will tell you and the relevant authorities as the law requires.

Changes to This Policy

We may update this policy. We will change the "Last updated" date above, and for any change that materially affects what we collect or who receives it, we will tell you in the app and ask for your agreement again before that change applies to your child's information.

Contact Us

Questions about this policy, or about anything we hold: write to us and a person will answer.

SmartCue, Inc.

651 N Broad St, Ste 201

Middletown, DE 19709

Privacy and deletion requests: robin@gramms.ai

General support: support@getsmartcue.com

Website: gramms.ai