Give and Grow — Privacy Policy (DRAFT)
FOR ATTORNEY REVIEW — technology / IP / privacy counsel. Not in force until reviewed and dated. Draft 2026-09-26 for app version 0.8.0. Controller: Damon Musso / Moose Woodworks, Orange Park, Florida, USA. Contact: [privacy@giveandgrow.app — to confirm].
Plain-language summary (not part of the policy): the app works offline and keeps everything on your device. There are no accounts. We do not run analytics, ads or trackers. The only thing that can leave your device is a small set of machine-setting numbers, and only after you turn that on. A Pro key contains a scrambled fingerprint of your email, never the email itself.
1. What Give and Grow is
Give and Grow is an offline-first app for makers: machine settings, translation between machines, quotes, product costs, orders, a run log, SOPs and shop planning. It runs as a website, an installable web app, and as Android, Windows and iOS apps built from the same code. It has no user accounts and no server that your data is sent to by default.
2. Data stored on your device (never sent to us)
The app stores, in your browser's or app's local database (IndexedDB) on the device you use: - your shop profile (name, shop name, email, phone, logo, theme, units, defaults) if you fill it in; - your machines, settings overrides, imported machine libraries and catalogued vendor files (name, size and hash of each file); - your run log (machine, material, settings, outcome, notes, an optional small photo); - your products, orders, customers and order notes (typed by you or imported from an Etsy CSV you choose); - your license key, trial start date, sharing switches, consent receipts and a rotating pseudonym (see 4); - preferences such as the selected machine and checklist progress. This data never leaves the device unless you export it (Backup, Export profile, Export runs, save an SOP) or turn on sharing (Section 4). We cannot see it, recover it or delete it for you; deleting the app or clearing site data removes it.
The installed web app also caches the app's own files (code and data libraries) so it opens without a signal. This cache holds no personal data.
3. Data we receive when you buy a Pro key
Purchases are handled by a payment processor (Stripe, or the Google Play / Microsoft Store billing of the store you bought from). The processor sends us your email address and the plan you bought; we do not receive your card number. We use the email to send you the key and for support and refund requests, and we keep a record of issued keys (email, plan, expiry, key id, date) for as long as the key can be valid plus our record-keeping period [COUNSEL: set, e.g. 7 years for tax records].
What the key itself contains. A Pro key is a signed text string. Its payload holds only: the product ("gag"), the plan, the first 16 hexadecimal characters of the SHA-256 hash of your lower-cased email, the expiry date and an 8-character random id. It does not contain your email, name, device or any identifier we could match to you without our own issued-key record. The app checks the key's signature on your device; entering a key sends nothing to us.
4. Optional sharing: "Help Give and Grow grow" (the rings)
The Grow → My shop card shows three switches. Everything is off until you turn it on, and turning it off stops the next send at once. - This device (ring0.local) — always on; it is simply the fact that the app stores your data locally (Section 2). - My other devices (ring1.sync) — your choice to carry your data between your own devices by backup or profile file. Nothing goes to us. - The commons (ring2.core) — the parent switch for anything that leaves the device. Under it: - Tool & setting outcomes (ring2.build) — after you log a run, the app stages one row containing only: product name, machine class, machine family (a class + power bucket, never a machine name or serial), the material's generic name as you typed it (lower-cased, trimmed), operation, power %, speed, passes, line interval, thickness and the outcome word. It never includes notes, photos, customers, products, prices, file names, your profile or free text. Rows are sent as one packet when the device is online, or when you press Send now. - Model math (ring2.model) — not in this version; it stays off.
Each packet carries an envelope: a random packet id, a pseudonym ("gag-" plus 16 random hex characters) that the app replaces every 90 days, the app version, schema and consent version, the day it was sent, which switches were on, and a hash of the rows. The pseudonym lets us drop duplicate packets and delete a shop's rows on request; because it rotates, packets from one shop cannot be linked forever. We do not receive your IP address beyond what the receiving server logs for security [COUNSEL: state retention of server logs, e.g. 30 days].
Who decided. The card records, on your device only, the name you type as "decided by" and "entered by", and how the button was pressed, and writes each decision and each send as one plain sentence in a receipt list you can read. These names are not sent.
Where it goes. Packets go to our Master Nia server at the address shown in the card (by default a local address for testing; the production address is set before launch). Rows are kept under the pseudonym to improve the starting points shown to every maker. We may publish aggregated starting points (for example "birch 3 mm, 60 W CO2: median 60 % at 12 mm/s, n = 40") that cannot identify any shop.
Legal basis (EEA/UK users). Consent (Art. 6(1)(a) GDPR), given by the switch and withdrawable at any time by turning it off. The rows are not personal data in most cases, but we treat the pseudonymised packet as such to be safe.
5. Data we do not collect
No analytics, crash reporting, advertising identifiers, cookies (other than the local database above), location, contacts, camera roll (photos you attach to a run are read once and kept only on your device), or tracking of any kind. The Android build requests no permissions beyond network access and file save/share. The web build makes network requests only to load its own files, to the sharing address in Section 4 when you turn it on, and to links you tap.
6. Third parties
- Payment: Stripe (stripe.com/privacy) or the app store you bought from. They are independent controllers for the payment itself.
- Hosting: the web app is served from Cloudflare Pages; Cloudflare sees the usual request logs (IP, user agent) as our processor [confirm at launch].
- App stores: Google Play and Microsoft Store collect install and crash statistics under their own policies; we receive aggregate counts only.
- Links in the app to vendors, guides and videos open the other party's site under its own policy. Nothing is sponsored. We do not sell personal data and do not share it for advertising.
7. Your rights
You control your device data directly (export, import, delete). For the issued-key record and any shared rows you can ask us to access, correct or delete them; for shared rows send the pseudonym shown in your receipts (Send now → Show what would be sent shows the current one). EEA/UK users also have the right to complain to their supervisory authority; California users have the rights under the CCPA/CPRA (we do not sell or share personal information). Email [privacy@giveandgrow.app].
8. Children
The app is for adults operating shop machinery. We do not knowingly collect data from children under 13 (or 16 in the EEA). Because there are no accounts, we collect no age data; a Pro key can only be bought by an adult with a payment method.
9. Security
Your data stays on your device under its own protections. Keys are verified by Ed25519 signature; the signing key lives offline on one computer. Sharing packets are sent over HTTPS to the production address. No system is perfectly secure; keep a backup of your data (Tools → Backup).
10. Changes
We will post changes here and show a note in the app on the first open after a material change. The date at the top is the version in force.
Notes for counsel (remove before publishing)
- Store forms (Google Play Data safety, Microsoft Store privacy declaration) are pre-filled in STORE_LISTING_GIVE_AND_GROW.md to match Sections 2–5; if this policy changes, those answers must change with it.
- Consider whether the pseudonymised setting rows are personal data at all; the policy treats them as such conservatively.
- Confirm entity name, contact email, log-retention periods, and whether a Data Processing Agreement is needed for the Master Nia host.
- The receipt sentences on the device double as the consent record (Art. 7(1) GDPR); they are not sent to us, so ask whether a server-side consent flag in the envelope (consent_version + consent_scopes, already present) is sufficient.
Moose Woodworks LLC · 2539 Sandlewood Circle, Orange Park, FL 32065 · dmusso89@gmail.com