granny by peeled banana studio
how it works the relationship privacy faq
join the waitlist already in line
← back to granny

Privacy Policy

Effective July 11, 2026

the short version

Here's the plain-language version. This policy covers both this website (askgranny.app) and the granny iPhone app. The rest of the page spells it all out, but if you only read one part, read this one.

  • When you ask granny to read a chat, your screenshots travel encrypted in transit to our backend. They are submitted to our safety pipeline and then a vision model extracts the text. We do not keep the screenshots or extracted conversation as a stored record in our own database.
  • Your notebook stays on your phone. The transcripts, granny's notes about you, your per-match memory, your journal, and your chat history with granny live on your iPhone, not on our servers.
  • On our servers we keep only your account (from Sign in with Apple) and usage records we need for billing and fair use. We do not store your conversations or your notebook.
  • We share data with a short list of providers — OpenAI's moderation service, Vercel AI Gateway and eligible model hosts, Apple, Supabase, RevenueCat, and PostHog (analytics) — only to make the app work and to understand which features actually help. We don't sell your personal information, and the granny app contains no ads and no ad trackers. The app's one analytics tool, PostHog, receives named usage events like "opened the app" — never your conversations or screenshots — and you can turn it off in the app's settings.
  • One tap starts permanent deletion. "Forget me" wipes all data on your phone after our server accepts the request. We delete your account, billing records, sign-in identity, subscription record, and analytics history; if a dependency is temporarily unavailable, a durable deletion job keeps retrying until server-side deletion is complete.
  • On this website we collect the email you give our early-access waitlist (stored with Supabase), and we use privacy-friendly, cookieless analytics (Vercel Web Analytics and Vercel Speed Insights) for visitor counts and page-load performance. While we're running ads for granny's launch, the website also uses advertising pixels from Meta and TikTok, which set cookies, to measure whether those ads work. The pixels see page visits, waitlist signups, and simple form interactions (like starting to fill in the form) — and if you type your email into the waitlist form (even if you don't finish signing up), they can also get a scrambled (hashed) version of it, which is how their ad systems recognize that you signed up (when you do sign up, our server also confirms that same event to them directly — same scrambled email, never the readable one). Never anyone's conversations. Pixel details and opt-outs are in the "advertising pixels and cookies" section below. Separately from the pixels, we use PostHog, a US-hosted analytics service that sets its own cookies, to see how visitors use the page — including session recordings in which anything you type is masked, so a recording never contains the text of your email; the details are in "the website (askgranny.app)" section below. You can ask us to remove your email anytime.
  • granny is for adults. You must be 18 or older to use it.

who we are and how to reach us

This is the privacy policy for Peeled Banana LLC ("Peeled Banana", "we", "us"). It covers both our website, askgranny.app, and our iPhone app, granny. The two handle data differently, so we cover the website first and then the app.

For anything at all — privacy questions, support, or legal — email us at hello@peeledbanana.com.

Our mailing address is 14205 N MoPac Expy, Ste 570 #300693, Austin, TX 78728. We are organized under the laws of the State of Texas.

the website (askgranny.app)

This section and the next one are about askgranny.app — the site you're on right now. Everything after them is about the granny app.

The only personal information you give the website directly is the email address you choose to give our early-access waitlist. You don't have to give it. If you do, we use it to email you when granny launches, plus the occasional update along the way. (Separately, the site's hosting and — while we're running launch ads — its advertising pixels — and, for the signup event, our server's own report to the same ad platforms — see standard technical details like your IP address, and if you type your email into the waitlist form the pixels can also get a scrambled (hashed) version of it; the rest of this section and the "advertising pixels and cookies" section below cover exactly what that means.)

We store waitlist emails with Supabase, our database provider. When you sign up, we also record how you arrived, if the link you used says so: the ad-campaign tags on it (like utm_source) or a referral/channel tag (like ?ref=friend on a shared link). These are stored with your signup and used only to measure which ads and shares actually work — they're deleted with your email when you ask to be removed. The site is hosted on Vercel, which processes standard server logs (such as IP addresses) to serve and protect the site. We use two Vercel analytics tools: Vercel Web Analytics to see how many people visit and which pages they read, and Vercel Speed Insights to measure page-load performance (such as how fast pages render) so we can keep the site fast. Both are privacy-friendly and cookieless — they don't use cookies, don't track you across other websites, and don't collect information that identifies you personally. While we're running ads for granny's launch, the website also uses advertising pixels — the next section covers exactly what they are, what they see, and how to opt out.

We also use PostHog, a behavior-analytics service, to understand how visitors actually use this page. PostHog records page views, clicks, and scrolling, and makes session recordings — a replay of how someone moved through the page — which we watch to figure out what's confusing and make the page better. If you join the waitlist, PostHog also gets a simple "joined the waitlist" signal — an event, not your email address. Anything you type is masked in those recordings: if you type your email into the waitlist form, the replay shows only that a field was filled in, never the text itself, and the thank-you message that greets you after signing up is hidden from recordings too. PostHog sets cookies and receives standard technical details like your IP address and browser information, and the data is hosted in the United States. PostHog's own privacy policy is at https://posthog.com/privacy. The session recordings are website-only — the granny app makes no recordings of any kind, and what the app sends PostHog is much narrower; the "analytics in the granny app" section below covers it. And if you block the analytics script, the site works fine without it.

We keep your waitlist email until granny launches or until you ask us to remove it — whichever comes first. To be removed, use the unsubscribe link in any email we send, or email hello@peeledbanana.com and we'll delete it.

advertising pixels and cookies (website only)

While we're advertising granny's launch, this website uses two advertising pixels: the Meta pixel (for our ads on Facebook and Instagram) and the TikTok pixel. A pixel is a small piece of code from the ad platform that uses cookies and similar technologies to recognize your browser. This applies to the website only — the granny app contains no ad pixels and no ad SDKs, and it shows no ads.

Here's what the pixels receive. Both get the fact that you visited a page on askgranny.app, along with standard technical details like your IP address, browser information, and the page URL. If you join the waitlist, both get a "signed up" event. We also send the Meta pixel two simple form-interaction signals of our own: that someone started filling in the waitlist form, and that someone clicked the join button — these fire even if the signup isn't completed, and they carry no email or typed text. And through a feature the platforms call "advanced matching", both can also get a scrambled (SHA-256 hashed) version of the email you type into the waitlist form — this can happen once you've typed it, even if you don't finish signing up. The email is always scrambled before it reaches the platforms — your browser does it for the pixel's copy, and our server does it for the copy described next: the platform gets a fixed string of characters it can compare against the (also hashed) emails of its own users to recognize you — not your readable email address. On top of that, the Meta pixel automatically collects some details about how you interact with the page, such as which buttons you click. One more mechanic: when you join the waitlist, our own server also reports that same "signed up" event directly to Meta and TikTok — carrying the same scrambled email, the same technical details (IP address, browser information, the page URL), and the pixels' own cookie and ad-click identifiers — so the count still works when a content blocker stops the pixels. It's the same event through a second door, not extra data, and both copies carry a shared id so the platforms count them once.

And here's what the pixels never receive: the contents of anyone's conversations, screenshots, notebook, or anything else from the granny app. The app has no ad pixels — and this website never has that data in the first place.

We use the pixels to measure whether our ads work (did the people who tapped an ad actually sign up?) and to help the ad platforms show our ads to people more likely to want them. The hashed email is part of that measurement — it's how the platforms connect an ad someone saw to a signup that actually happened. Meta and TikTok also process this data for their own purposes, described in their own policies: Meta's privacy policy is at https://www.facebook.com/privacy/policy, and TikTok's is at https://www.tiktok.com/legal/page/us/privacy-policy/en.

You don't have to be measured. Ways to opt out or limit this:

  • adjust your ad preferences with Meta at https://www.facebook.com/adpreferences (covers Facebook and Instagram)
  • adjust your ad settings in the TikTok app under Settings and privacy → Ads
  • opt out of interest-based advertising from many companies at once at https://optout.aboutads.info
  • block or clear cookies in your browser settings, or browse with a content blocker — the site works fine without the pixels (one honest caveat: if you then sign up anyway, our server still reports that one signup event to the platforms itself — the ad-preference opt-outs above are the way to limit what the platforms do with it, or email hello@peeledbanana.com and we'll remove you)

An honest note about "Do Not Track": some browsers can send a Do Not Track signal, but there's no settled standard for how websites respond to it, and these pixels don't change what they collect when it's on. If you want out, the opt-out tools above and your browser's cookie controls are the reliable route.

the information we handle

It helps to think of your information in three buckets: what you send us, what stays on your device, and what we keep on our servers. We treat each one differently.

(a) What you send us. When you ask granny to read a conversation, you pick screenshots from your photo library and send them to us. Each image is submitted to our safety pipeline and then a vision model extracts the conversation text. The extracted transcript is shown to you in the app, where you can edit it.

(b) What stays on your device. We call this your notebook, and it lives on your iPhone, protected by iOS device encryption. It includes:

  • the conversation transcripts granny pulls from your screenshots
  • granny's notes about you — what she's learned about your intent, your patterns, your icks, and your style (we call this your User Model)
  • your per-match memory
  • your journal
  • your chat history with granny
  • your notification check-ins

(c) What we store on our servers. Our backend database (hosted on Supabase/Postgres) holds two things:

  • your account record, created when you sign in with Apple — an Apple user identifier, your email, an account id, and the date the account was created
  • usage and metering records for each AI call — the endpoint, the model, the provider, token counts, and cost — which we use for billing and to enforce fair use, plus your subscription and credit ledger records

To be clear: we do not store a copy of your conversations, your transcripts, or your notebook on our servers. Our backend reads your screenshots so granny can do her job, but it does not retain the conversation content.

One more stream, so the picture is complete: the app also sends usage analytics events to PostHog — which features were used, never what was in them. The "analytics in the granny app" section below covers exactly what that includes and how to turn it off.

how your screenshots are processed

Reading a chat takes a few steps, and we want you to know exactly what happens at each one.

  • Your screenshots travel to our backend encrypted in transit (HTTPS/TLS).
  • Before extraction, our safety pipeline attempts an automated check with OpenAI's moderation service. If that service is unavailable, it attempts a model-based check through Vercel AI Gateway. If both automated checks are unavailable, the current runtime may continue while sending our team a content-free operational alert. The screenshot then goes through Vercel AI Gateway to a vision model to extract the text.
  • After you confirm the transcript, coaching sends the transcript and relevant context — not the screenshot — through Vercel AI Gateway.
  • We do not use conversation content to train granny or build our own training dataset. External services process it under their API terms and our account and request configuration.

We use OpenAI's moderation service for safety screening. Model inference is routed through Vercel AI Gateway: an OpenAI model is the default for screenshot extraction, and a Claude model is the default for coaching. Vercel may route those models through eligible infrastructure providers.

The credentials used to reach Vercel AI Gateway and AI services live on our backend only. They are never shipped inside the app.

who we share data with

We keep the list of companies that touch your data short, and each one is there for a specific reason. We do not sell your personal information to anyone. Outside of the website ad pixels described above (and our server's direct signup-event reports to the same platforms) — which California law may treat as "sharing" for cross-context behavioral advertising, and which you can opt out of — we don't share your information for advertising at all. Here is everyone who receives data and why:

  • OpenAI's moderation service, Vercel AI Gateway, and eligible model hosts — OpenAI is the primary screenshot safety screen, and Vercel can handle a fallback safety check. Vercel also routes screenshot and transcript requests to the configured model or eligible hosting infrastructure for extraction and coaching. AI Gateway routing metadata uses an opaque account identifier and feature tag instead of your account name or email. The request content itself can include names and other details you provided or that appear in a screenshot when they are relevant to the feature. These services receive screenshots and/or transcript text plus relevant context to provide and secure the feature you requested.
  • Apple — handles Sign in with Apple (your account identity) and Apple In-App Purchase (payment processing). Apple receives the information needed to sign you in and to charge your subscription; we never see or store your card details.
  • Supabase — hosts our backend database and authentication. It stores your account record and the usage/billing records described above. It does not store your conversations or your notebook.
  • RevenueCat — manages your subscription. It receives a user/subscription identifier and your purchase and transaction data so we can tell whether your subscription is active.
  • Meta and TikTok (website only) — while we're running launch ads, their pixels on askgranny.app (and, for the signup event itself, our server reporting it to them directly) receive page visits, waitlist-signup events, a hashed version of the email typed into the waitlist form ("advanced matching"), and — on Meta — form-interaction signals we send (starting the waitlist form, clicking the join button) plus automatic interaction details like button clicks, so we can measure our ads. They receive nothing from the granny app. See "advertising pixels and cookies" above for details and opt-outs.
  • PostHog — our analytics provider, in two different roles. On the website it receives how visitors use the site — page views, clicks, a "joined the waitlist" event (never your email), and session recordings in which everything you type is masked (never the text of your email). In the granny app it receives named usage events (like "opened the app" or "subscribed") tied to your account id — with no session recordings and no conversation content, ever; the "analytics in the granny app" section covers it in full, including the off switch in settings and how "Forget me" deletes your analytics history. Both roles include standard technical details like IP address and device/browser information, hosted in the US. PostHog's privacy policy: https://posthog.com/privacy.

In the granny app, PostHog — exactly as described above and in "analytics in the granny app" below — is the only third-party analytics. There are no other analytics SDKs (no Amplitude, Mixpanel, or Firebase Analytics), no advertising SDKs, and no ad networks.

the other person in the chat

Your screenshots contain someone else's messages — the person you're talking to (your "match"). That content is processed through the same safety, routing, and model services as yours: the screenshot goes through safety screening and text extraction, and the confirmed transcript plus relevant context is used for coaching.

The other person hasn't agreed to any of this. So when you upload a screenshot, you're confirming that you have the right to share it, and you take responsibility for doing so. Please be thoughtful about what you upload.

accounts and Sign in with Apple

You sign in with Apple, handled through Supabase Auth. From that we receive an Apple user identifier and your email, which become your account record (along with an account id and the date you created it).

Your session token is stored in your iPhone's keychain so you stay signed in.

payments

granny is a paid subscription. Payments are handled by Apple In-App Purchase — Apple is the payment processor, and we never see or store your card details.

We use RevenueCat to manage subscriptions. RevenueCat receives a user/subscription identifier and your purchase and transaction data so we can tell whether your subscription is active.

The plans, pricing, billing periods, and any introductory offer available to you are shown in the app and on the App Store before you commit. The subscription auto-renews unless you cancel; you manage and cancel it in your App Store account settings. (Our Terms cover the renewal and cancellation details.)

Your subscription is not unlimited. Because every chat read and every coaching turn has a real AI cost, a weekly fair-use cap applies to your AI usage. The usage and metering records described above are how we measure that. The details of the cap are in our Terms.

analytics in the granny app

The granny app uses one analytics service: PostHog, the same US-hosted provider we use on the website — but the app sends it far less than the website does. In the app there are no session recordings, no screen capture, and no automatic collection of what you tap or type — the only things noted automatically are basic app-lifecycle moments: that the app was opened, sent to the background, installed, or updated (that's how "opened the app" gets counted). Beyond that, the app sends a short, hand-picked list of named events so we can tell which features actually help — things like "asked granny to read a chat" or "subscribed". An event says that something happened, never what was in it.

What PostHog receives from the app: those named events, tied to your account id — the same random string that identifies your account in our database, created with your account; not your name and not your email — plus standard technical details like your device model, iOS version, app version, and IP address (from which PostHog derives your approximate, city-level location). What it never receives: your screenshots, your transcripts, your notebook, your chats with granny, your matches' names, or anything anyone said. Conversation content stays out of analytics entirely, by design.

Two controls are always yours. You can turn analytics off in the app's settings — granny works exactly the same with it off (turning it off stops new events from that moment on; to erase what's already there, use "Forget me"). And "Forget me" deletes your analytics profile and event history at PostHog along with everything else — PostHog processes those erasures in scheduled batches on its side, so the underlying events disappear over the following days. PostHog's own privacy policy is at https://posthog.com/privacy.

what we do not do

  • We don't let analytics anywhere near your conversations. The granny app's one analytics service (PostHog) receives named feature-usage events with an off switch in settings — never your screenshots, transcripts, or notebook — and there's nothing else: no Amplitude, Mixpanel, or Firebase Analytics, and no session recordings in the app.
  • We don't show ads.
  • We don't sell your personal information. The one advertising caveat lives on the website: while we're running launch ads, its Meta and TikTok pixels (and our server's direct signup-event reports to the same platforms) may count as "sharing" for cross-context behavioral advertising under California law — the "advertising pixels and cookies" section explains what they see and how to opt out. The app shares nothing for advertising.
  • We don't store your conversations or your notebook on our servers. On our servers, the only usage we record is the metering we need for billing and fair use — the separate feature-usage events described in "analytics in the granny app" live at PostHog, with an off switch in settings.

data retention and where data lives

Your notebook lives on your iPhone for as long as the app is installed and you keep it there. It isn't copied to our servers.

Your account record and usage/billing records live in our backend database (Supabase/Postgres) for as long as you have an account, so we can run billing and enforce fair use. When you delete your data (see below), they're removed.

Your usage analytics events live with PostHog (US-hosted) until you use "Forget me", which removes your analytics profile and history there too (PostHog processes those erasures in batches on its side, so the underlying events can take a few days to disappear completely). Turning analytics off in the app's settings stops new events from that point on.

Our backend does not retain the conversation content it processes. The screenshots and extracted text aren't kept on our side as a stored record of your chats.

security

Your screenshots and transcripts travel to our backend encrypted in transit (HTTPS/TLS). The data on your phone — your notebook — is protected by iOS device encryption.

No system is perfectly secure, but we design granny to keep as little as possible on our servers and to keep your notebook on your device.

your choices and rights

You're in control of your data. You can review and edit your transcripts and your notebook right in the app. And you can delete everything.

"Forget me." Inside the app, this is a real, permanent delete. It:

  • deletes your server-side account and all your usage and ledger records (cascade)
  • deletes your Sign in with Apple identity
  • deletes your RevenueCat subscriber record
  • deletes your analytics profile and event history at PostHog (PostHog erases the underlying events in scheduled batches over the following days)
  • wipes all the data on your device

The request is durable and irreversible. We normally complete every step while you wait. If RevenueCat, PostHog, our database, or our authentication provider is temporarily unavailable, a deletion job keeps retrying the unfinished server-side work until it is complete.

Depending on where you live, you may have rights over your personal information. If you're in the EU/EEA or UK, the GDPR gives you the rights to access your data, to have it corrected (rectification), to have it deleted (erasure), to restrict or object to how we process it, to receive a copy in a portable format (portability), and to lodge a complaint with your local data protection authority. If you're in California, the CCPA/CPRA gives you the rights to know, access, correct, and delete your personal information, and to not be discriminated against for exercising them; we do not sell your personal information, and the only "sharing" we may do is through the website ad pixels described above (including our server's direct signup-event reports to the same platforms) — you can opt out with the tools in that section, or by emailing hello@peeledbanana.com.

When we process your personal information, we rely on these legal bases: performing our contract with you (running your account, billing, and delivering granny's coaching), our legitimate interests (keeping the service secure and enforcing fair use), your consent where we ask for it, and complying with our legal obligations.

The "forget me" control gives you a direct way to start permanent deletion. The notebook stored in the app on your iPhone is wiped after our server accepts the request; any unfinished server-side deletion keeps retrying as described above. To exercise any other right — access, correction, portability, or objection — email hello@peeledbanana.com and we'll help.

children

granny is for adults — you must be 18 or older to use it. It is not directed to anyone under 18, and we don't knowingly collect information from anyone under 18.

international users and data transfers

We're a US company, and our service providers operate in the United States and possibly elsewhere. If you use granny from outside the US, your information may be processed in the US or wherever our providers operate. By using granny, you understand your information may be transferred to and handled in those places.

Where your information is transferred out of the EU/EEA or UK, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (and the UK equivalents) — where those safeguards are required by law.

changes to this policy

If we change this policy, we'll update the effective date at the top and post the new version here. If the change is significant, we'll do our best to let you know.

contact

Questions about your privacy, or anything else? Email us at hello@peeledbanana.com. We read every message.

granny
a peeled banana studio product

a tiny software studio. built by hatef, in austin — every email on the list lands in a real inbox.

say hi → hello@peeledbanana.com
granny the app how it works the relationship faq
studio about contact
legal privacy terms support
early access join the waitlist →
© 2026 peeled banana llc · an independent software studio v1.9.0 · build 650c748 delete anytime · granny means it.