PRIVACY, IN PLAIN LANGUAGE
What stays on your phone, and what reaches us.
The short version: no account, no ads and no advertising identifiers or third-party trackers. Griot sends a random install ID, tightly limited Usage events and crash reports. It sends your email only if you request the Sunday digest or choose to email support.
What reaches Griot
- Anonymous install ID. A random code made on first launch. It is sent with app requests and usage events, but is not linked to your name, email, phone or a device advertising ID during ordinary use. If you voluntarily email support about deletion, the draft includes an install support code so the request can be fulfilled.
- Usage events. We count whether the first-launch promise appears and is continued; which edition, card, theme, route choice, chosen answer, glossary item, method or proof page you open; whether a relevant answer is classed as changed, unchanged or unknown; whether you finish; which public instrument you starred; a share attempt; a comparison; whether you saved a checkpoint; search length and result-count buckets; and whether you turned the evening reminder on or off. We also count app-error classes, resets to the current brief date and Explore taps. These events use public item names or broad brackets. A bounded retry queue stays on your phone until the server acknowledges it, so a weak connection or restart does not erase the signal. Each event has an opaque retry ID; the server records when it arrives and may receive the device's event time so retries stay in order without being counted twice. A public edition date can identify which edition was opened. We never receive your search words, an amount, a private date from your checkpoint, a reminder threshold or free text.
- Email address. When you request the Sunday digest, we use your address to send a confirmation email. Weekly emails begin only after you confirm; existing subscribers stay subscribed. Each digest has an unsubscribe link. We count a signup request as a Usage event, but never attach your email address to analytics. The invitation state stays on your phone.
- Crash diagnostics. When the app breaks, Sentry may receive the error and stack trace plus technical app, device and OS context. Griot does not intentionally attach its install ID, name, email or precise location.
- Public proof page count. When anyone opens a public proof page, the server records the page and a broad source class such as social or search. It uses the fixed label “web”, not a reader ID, and sets no analytics cookie.
- Abuse limit. Like every internet service, the API receives a network (IP) address with a request. The Griot application immediately turns it into a one-way key using a random secret held only by that running server, uses it for request limits (one minute for browsing, ten minutes for digest signup, and ten-minute and daily limits for notification enrollment), and does not write the raw address to its database or application logs. An expired opaque bucket is removed on the next ordinary request; any remaining buckets disappear when the process restarts. Aggregate enrollment quotas contain no IP or install ID and are removed after expiry by cleanup.
- Support email. The deletion-support action opens your own mail composer with an install support code in a draft. Opening it sends nothing. If you press send, your mail service supplies the sender address or name and Griot receives whatever you choose to include, solely to handle the request. Discard the draft before sending, or ask support to remove the message after the request is resolved; mail-provider backup or security retention may still apply.
What the app keeps on your phone
Offering tracking is local: up to 20 tracked offerings and the versions you have read. Public offering facts are kept in memory for the current app session, not saved to disk; reopening the app needs a new API read that checks whether those facts are still safe to show. It does not change your basket or your chosen question. We count only generic offering opens (entry point) and track/untrack actions, without the offering identity or your tracked list.
- The public question readings you actually viewed, their answer versions and view time stay on your phone. Last-shown version hashes also stay local to avoid recounting the same opportunity. Usage events carry only the question name and broad change state, not that history or its values.
- Your full route choice and whether it is for today or kept. We count the route name and duration choice; no reason or financial profile is sent. Change or clear it in About → Your route.
- Names you starred. We count the public code when you star or unstar; a holdings amount is never requested.
- Your Since Last Check checkpoint, including the old numbers. Only an age bracket is counted when you save; the numbers stay local.
- How many editions you have finished and the last-finished date. Only completion of an edition is counted.
- Your evening reminder setting and scheduled notification ID. Only on, off or not-now is counted.
- Your digest-prompt answer, cached editions and a last-good copy of pages so Griot can open offline. Those copies are not sent back as personal data.
Deleting the app removes these local copies. It does not by itself identify and delete earlier server events; email us with the old install ID if you want those rows removed.
What we never collect
- Your name, phone number or address during ordinary app use, contacts, or your location. A support email contains only the sender details and content you choose to send.
- Any amount you send, hold or consider; bank, brokerage or portfolio data.
- Free text you type — search text is counted as a length and result bucket only.
- Advertising identifiers or third-party trackers. We do not sell reader data.
Sources and advice
Griot identifies the source and as-of date beside its figures. Sources may include CBN, DMO, FMDQ, SEC Nigeria, NBS, NUPRC, the U.S. Treasury and the World Bank. Where NGX market data is shown, it is supplied through the credited Mansa Professional feed while a direct NGX arrangement remains the preferred long-term path. An observed peer-to-peer dollar price is always marked unofficial and unverified. Griot explains public financial facts; it is not investment advice and does not execute a trade or transfer.
Retention and deletion
Offering notifications, when available, need separate consent. Tracking alone does not enable them. The delivery service uses a separate installation credential, encrypted Expo push token, subscriptions, consent text version and confirmation time, timezone and quiet hours—not the analytics install ID. Expo receives the token and generic update payload. Turning notifications off removes subscriptions; erasing the delivery registration removes its active token, subscriptions, jobs and consent metadata. Inactive registrations expire after 90 days. Device-confirmation challenges expire after five minutes and are purged within the following hour. Job state is removed no later than one day after event expiry. A minimal erasure marker lasts 35 days to prevent restoration from reactivating a deleted registration. Native secure storage, consent and backup-restoration checks must pass before this feature is activated.
Our private engagement report reads Usage events only as counts over groups of installs, on our own server, to see which parts of Griot people use—never as one install's history. Small groups are shown in bands; the report does not list starred instruments, comparison pairs or individual activity histories.
New usage events carry a broad platform label: iOS, Android or unknown. We do not infer it from your IP address, device model or browsing history. Older unlabelled events remain unknown. The label follows the same event retention and deletion rules.
To keep our own testing out of audience reports, an operator can exclude an installation using its install ID. Settings can reveal your installation support code on request; you may copy and share it privately. Showing the code sends no request and does not itself exclude anything. An exclusion removes that installation's past and future events from audience reports without deleting the events or stopping collection. Historical figures are recalculated using current exclusions, and a reinstall needs a new exclusion. Support can remove an exclusion; it is retained separately while needed to prevent restored records being counted again. Usage-data deletion remains a separate request.
Acknowledged events leave the phone's retry queue; deleting the app removes any unsent queue. Raw server usage-event rows are purged after 24 months by a daily retention task. Ask support@griotmarkets.com to delete events tied to an install ID. Digest confirmation links expire after 24 hours. Unconfirmed addresses and their encrypted confirmation email are removed on a later signup request or the next daily cleanup. Confirmed digest email records are deleted when you unsubscribe. The Sentry project retention setting must be verified before store submission; no longer period should be claimed until that setting is recorded.
Web edition counts
When the web edition's approved aggregate measurement is switched on, we count approximate page views and store-link clicks by Nigeria calendar day, a fixed page family, broad device class and broad referral class. These are requests, not unique people or installations. No cookie, local storage, browser identifier or individual reading history is created. Known bots, preview pages, prefetch and HEAD requests are excluded where recognisable. Raw URLs, query text, addresses, user-agent strings and referrer URLs are not kept by this measurement system. Small groups are protected in private reports.
Daily totals last 13 months. Unsent aggregate totals are bounded to 24 hours and 8 MiB; a process restart can lose them. Aggregate delivery receipts prevent retries being counted twice and last seven days. Fixed-label aggregate failure counts last 13 months. Daily cleanup runs even with counting turned off. We cannot identify a browser to delete its counts or exclude the founder's browser. Historical proof page events use a fixed 'web' label, not a reader identity, and retain the existing 24-month retention. The measurement cutover uses one writer per proof request.
Android tester requests
If you choose to request closed-test access by email, we use your Google Play account address, sender details and chosen message to add your account to the Play tester list and reply. Opening the email draft sends nothing. There is no additional enrolment database or spreadsheet, newsletter enrolment or connection to app analytics. Do not send a password, payment detail or device identifier.
Junk or uncompleted requests are removed within 30 days. Ask support for removal; Griot-controlled messages and tester-list entries are removed on request, public store launch or test closure as applicable. Continuing tester access is reviewed every 90 days. Mail/Google providers, backups and your own outbox may keep independently controlled copies that Griot cannot erase.
Changes
Material changes will be explained in the app before they take effect.