beta · updated 13 September 2026

Privacy Notice

This notice describes the current Groven service. The owner still needs to publish the legal operator's identity, retention periods, and the moderation-review process before the App Store release. For support and privacy questions, contact yep@groven.social.

Account and content data

Who can see your information

Your profile and shared content follow the visibility settings of the account, field, post, or community. Your email, password, login sessions, private messages, private music library, reports, and blocked-account list are not public. Audio or other content you attach to a shared post becomes available to the permitted audience of that post.

For new end-to-end encrypted direct messages, the message body is intended to be readable only on the participants' unlocked devices. Groven still processes message metadata, including the sender and recipient account identifiers, timestamps, message and key identifiers, read state, notification state, and encrypted-envelope size. This metadata is not end-to-end encrypted.

The configured site owner can see account/traffic statistics and security events to operate and protect Groven. This includes recent registrations, last activity, recorded page or API path, visit counts, estimated active time, and browser/device information. Restricted administrative access does not make this information public.

Recommendations and activity

Reports and their reasons enter a restricted owner-only moderation queue. The reviewer sees eligible public content, report details, and decision history, and can hide or restore content or suspend an account. The queue does not load private-message contents or private photo/attachment contents. A narrow public-text safety check rejects certain explicit illegal solicitations and direct violent threats; ordinary profanity is not filtered. Automated rejection records the rule identifier, not the rejected text.

Feed and people recommendations use eligible public signals such as follows, public interactions, communities, interests, and post age. You can choose Chronological or adjust Recommended in Settings. Music Match uses musical data only according to your Music Match visibility choice: Nobody, Friends only, or Everyone.

Groven records limited product events and visible-tab heartbeats to estimate activity, plus session information, browser user-agent details, and hashed IP values for security. Relationship/Grovie progression can use counts of interaction events. Private message text and private photo or attachment contents are not used for recommendation or message-content analytics.

Connected services and delivery providers

These providers process the information sent to them under their own terms and policies. Groven does not sell personal information. The owner must confirm the final list of providers and applicable international-transfer details before release.

Storage and encryption

Production connections use HTTPS, and passwords are stored as salted hashes. The current production configuration requires new direct messages to be encrypted and decrypted on participant devices before they cross Groven's message API. E2EE v2 uses P-256 key agreement, HKDF-SHA-256, and AES-256-GCM authenticated encryption. Groven stores the resulting encrypted envelope, public keys, and a private-key backup that is itself encrypted with a random recovery secret; the server does not receive that recovery secret or the new-message plaintext in the normal messaging flow.

Messages created before the E2EE v2 rollout are legacy messages. Their bodies are protected at rest with authenticated encryption under a server-held key, but the server can decrypt them for an authorised participant. They cannot be made retroactively end-to-end encrypted and remain identified separately from new E2EE messages.

Your Groven recovery code is required to unlock E2EE history on a new device or after local app/browser data is cleared. It is shown when the encryption identity is created; save it somewhere private and separate from the device. Groven support cannot retrieve or replace a lost recovery code; without it and without an already unlocked device, the encrypted history cannot be recovered. The web app can retain only a non-extractable private CryptoKey in browser storage and does not persist the recovery secret there. The prepared iOS app may store the recovery secret in the device Keychain when available, so endpoint and device security still matter.

E2EE protects new message bodies, not profile data, public content, uploads, account/message metadata, or connected-service tokens. It does not stop a recipient from copying or capturing a message, and it does not protect an unlocked, compromised, or malicious device. This implementation is not a claim of absolute security or equivalence to an independently audited messenger protocol.

The database and its backups are stored on the configured hosting storage. Authentication and server-side permission checks restrict access. No system can guarantee that all security risks have been eliminated.

Your choices and deletion

In the prepared iOS app, a separate sign-in token is held in memory and, when available, the device Keychain; it is not saved in browser storage or sent in URLs. If secure storage is unavailable, sign-in lasts only for the current app session. Spotify and Calendar connections use an explicitly confirmed, one-use browser handoff that expires after two minutes and a short-lived browser session. Password changes, session revocation, account suspension, and account deletion invalidate server-side sessions.

In Settings you can change profile visibility, manage activity and Music Match choices, control email notifications, review login sessions, change your password, enable two-factor authentication, block or unblock accounts, download account data, and permanently delete your account.

Account deletion requires your password and explicit confirmation. It signs you out and removes the account and linked records from the active database, including its messages and uploaded content. Shared communities can remain with another member as owner. Security records linked to the deleted account have their account/IP linkage and details removed.

Existing backup snapshots are not immediately rewritten by account deletion. They rotate as new backups are created; the owner must define and publish a time-bound backup-retention and restoration policy. Content already copied by another person or delivered to an email provider, Spotify, or Google is not erased by deleting a Groven account. Manage those copies and provider permissions directly with the relevant service.

You can disconnect Spotify or Google Calendar inside Groven and revoke access in the provider's account settings. Disconnecting does not automatically delete events already saved in Google Calendar. Groven is not intended for children under 13.

Contact

For privacy questions or help with your data, write to yep@groven.social. Never email passwords, sign-in codes or identity documents. See Contact Groven for guidance.