Skip to content

Privacy Policy

Last updated: 30 July 2026

This policy explains what personal data Gramoo collects when you use it, why, and the choices and rights you have. We aim to collect as little as we can, and we never sell your data.

Who we are

Gramoo is an online grammar-learning service, and is the controller of the personal data described here. You can reach us about privacy at any time using hello@gramoo.xyz.

What we collect

  • Account details: your email address, a password (stored only as a secure hash by our auth provider, never in plain text), and the display name you choose.
  • Learning preferences: your English variant (UK or US) and your daily goal.
  • Age confirmation: that you have confirmed you are 13 or older.
  • Learning activity: your lessons, answers, scores, XP, streaks, review schedule, hearts, and achievements. This is what powers your progress and dashboard.
  • Certificate details: if you claim your Grammar Master certificate, we store the display name printed on it, your completion date, its issue date, and a random verification identifier.
  • Purchase data: if you buy Gramoo Plus, a record that you own it plus a Stripe customer reference. Your card details go straight to Stripe and never reach our servers.
  • Technical data: basic request information (such as your IP address) used to keep the service secure and rate-limited. We do not run advertising trackers.

Why we use it, and our legal basis

  • To provide the service (accounts, lessons, saving your progress): to perform our contract with you.
  • To issue your certificate and verify a certificate link you choose to share: to perform our contract with you.
  • To process Gramoo Plus payments: to perform our contract, and to meet legal and accounting duties.
  • To keep Gramoo secure and prevent abuse (for example rate limiting and stopping reward farming): our legitimate interest in a safe, fair service.
  • To send essential account emails, such as confirming your email address: to perform our contract.

Who processes your data

We use a small number of trusted providers to run Gramoo:

  • Supabase, for authentication and the database that stores your account and progress.
  • Stripe, to process Gramoo Plus payments.
  • Vercel, to host and serve the app.
  • Upstash, if enabled, to store short-lived counters used for rate limiting.

These providers act on our instructions and only for the purposes above.

Sending data outside the UK

Some of our providers may process data outside the UK or the European Economic Area. Where they do, we rely on safeguards recognised by data protection law (such as UK adequacy decisions or standard contractual clauses) so your data keeps a similar level of protection.

How we protect your data

  • Passwords are stored only as secure hashes, never in plain text.
  • Data is encrypted in transit using HTTPS.
  • Access is restricted so each account can only ever read its own data (row-level security in the database).
  • Payments run through Stripe, so we never store your card number.

No online service can be completely secure, but we take reasonable technical and organisational measures to protect your data.

Sharing a certificate

A certificate verification page shows the name printed on the certificate, the course title, and its completion and issue dates. It is available only through a long, random link and we ask search engines not to index it. Anyone you share that link with can view those details. Deleting your account removes the certificate and makes the link stop working.

How long we keep it

We keep your account data for as long as your account exists. When you delete your account, we remove your personal data from our database. We may keep limited records where the law requires it (for example basic payment records for tax and accounting).

Your rights

Under UK and EU data protection law you can:

  • access a copy of your data (you can download it any time from your profile settings);
  • correct data that is wrong;
  • delete your account and data (you can do this yourself from your profile settings);
  • object to or restrict some processing, and ask for your data in a portable format;
  • withdraw consent where we rely on it.

To use your download or delete options, go to your profile settings. For anything else, contact us using hello@gramoo.xyz. If you are in the UK and think we have not handled your data properly, you can complain to the Information Commissioner’s Office (ico.org.uk).

Automated decisions

We do not make decisions about you by purely automated means that would have a legal or similarly significant effect on you.

If something goes wrong

If a data breach happens that is likely to risk your rights, we will report it to the Information Commissioner’s Office, and tell you where the law requires, without undue delay.

Cookies and device storage

Gramoo currently uses only essential cookies: the secure session cookies that keep you signed in. These are needed for the app to work, so they do not require a consent banner. We do not use advertising or cross-site tracking cookies. If we add optional analytics in future, we will ask for your consent first and give you an easy way to opt out.

We also save a few small settings in your browser’s own storage, such as whether sound effects are on or off. These stay on your device and are not sent to us.

Children

Gramoo is for people aged 13 and over. We do not knowingly collect data from children under 13. If you believe a child under 13 has given us their data, contact us using hello@gramoo.xyz and we will delete it. See our Terms of Service.

Changes to this policy

We may update this policy from time to time. If we make an important change we will take reasonable steps to let you know. The date at the top shows when it was last updated.

Questions? Contact us at hello@gramoo.xyz.