MonteSprout Privacy Policy
The short version
MonteSprout is local-first. Your classroom records — observations, student names, photos, videos and voice notes — are stored on your device and in your own private iCloud. We run no accounts and no classroom-data servers, and we cannot read your classroom records.
There are three narrow exceptions, all described in full below. When you generate a report, the note text is sent for AI drafting with the child’s name swapped for a stand-in first, and neither we nor the AI provider keeps a copy. When you hand a colleague a join code — or ask your lead teacher to invite you — we hold a short-lived, encrypted note that lets the two of you connect, and we cannot open it. And the app can send anonymous crash and usage statistics, which you can turn off in Settings → Privacy.
1. What you put in, and where it lives
Observations, student names (the app stores a first name and an optional last initial, never a surname), curriculum records, report drafts, photos, videos and voice notes are stored in a database on your device.
If you are signed into iCloud, they sync through your private iCloud database (Apple CloudKit), which only your Apple account — and co-teachers you explicitly invite to a classroom — can reach. Mango Grove Labs has no access to this data and operates no server that stores it.
Joining a classroom by code, or asking to be invited. Apple’s invitation is a link, and a link does not always reach the right phone. So MonteSprout offers two shortcuts, and each one parks a small record on our server for up to 24 hours. A join code stores your classroom’s iCloud invitation link; a request to be invited stores the name you typed and an opaque identifier for your Apple account. In both cases the record is encrypted with a key derived from the eight-character code itself, which is spoken or messaged from one teacher to the other and never sent to us — so we hold something we cannot open, and neither can anyone who obtains the database. Each record is filed under a one-way hash of the code, cannot be listed or searched, is deleted as soon as it is used, and expires within 24 hours in any case. No observation, no child’s name and no classroom content is ever part of it, and a request grants nothing on its own: the lead teacher still chooses whether to invite you, and at what level.
2. AI report drafting — the one time note text leaves your device
When you ask MonteSprout to draft a report, the app sends the relevant observation text and curriculum or lesson names through our relay server to an AI provider (currently OpenAI). The child’s name is replaced with a stand-in before anything is sent, and the real name is restored on your device afterwards. Photos, videos and audio are never sent.
The relay does not store or log your text. The only record kept is an anonymous usage row — token counts, timing and a random install identifier — used to enforce a rate limit. Our AI-provider organization is configured not to log, share or train on your content; the provider may retain API traffic briefly for abuse monitoring, after which it is deleted.
One honest limitation: if your note text mentions other children by name, those names travel as written. The app asks your permission before your first generation and says so plainly at that moment. You can use MonteSprout fully without ever generating an AI report.
3. Anonymous analytics and crash reports (optional)
To find bugs and understand which features help, the app can send crash reports (Sentry) and anonymous usage events (PostHog) — things like “a report was exported”, never the content of your notes.
The app has no general-purpose “record anything” call: every event is one of a fixed, hand-written list, and an event property can only be a number, a flag, or a short label — never a nested object or a piece of your writing. The events that accompany observations and media are covered by tests asserting exactly that.
The only identifier is a random install ID created on your device; it is not linked to you and is replaced if you reinstall. As with any internet service, the providers receive your IP address as part of transport. Both toggles are in Settings → Privacy and take effect immediately. We do not use advertising identifiers, we do not track you across apps or websites, and we never sell data.
4. Beta (TestFlight) feedback
If you are testing a beta build, a shake-to-report tool lets you send us a message, optionally with screenshots you choose and — only if you type them — your name and email. Beta builds also share crash and usage data with us through Apple TestFlight, as described in Apple’s TestFlight privacy notice. The feedback tool does not exist in App Store builds.
5. Notifications
Reminders are scheduled locally on your device; nothing about them is sent to us. The app also receives silent background pushes from Apple’s CloudKit to know when your own iCloud data has changed — these carry no content and are not sent by us.
6. Retention and deletion — you hold the keys
Deleting is built in. Individual observations, students, classrooms and reports can be deleted, with a recovery window you choose in Settings (30 days, 90 days, or never auto-remove), after which they are permanently erased — and “Delete forever” is always available on demand. Permanently deleted items are gone from your device and from your iCloud.
You can export your records at any time from Settings → Export data, as JSON (complete and re-importable) and as Markdown (a readable document). Photos, videos and voice notes are listed in the export rather than embedded — the files themselves stay on your device and in your iCloud backup, which is where they belong.
Removing the app and its iCloud data removes your classroom records entirely. We hold no copy.
7. Children’s data
MonteSprout is a tool for teachers and is not directed to children. Observation records concern students in your care: they are entered by you, stay under your control as described above, and are never used by us for any purpose — we cannot read them.
For schools with data-processing requirements (FERPA, GDPR and similar): the practical answers are that classroom records live on the teacher’s device and in her own private iCloud with no copy held by us, and that the AI drafting path is pseudonymized, not retained, and never in our custody. Write to us for written detail.
8. Changes and contact
We will update this page when our practices change, and note the date at the top. Questions or data requests: support@mangogrovelabs.com.