Gammy Apps Privacy Policy
Release status: Gammy Family and Gammy Managed version 5 are in Internal Testing only and have not been promoted to Production. The current Production apps do not support paired connected status, Family video calling, push alerts, or caregiver remote actions. Family Premium is not publicly purchasable yet. The disclosures below also cover data handled during authorized internal testing.
This privacy policy applies to Gammy Focus com.t9messenger.launcher.focus, Gammy Full com.t9messenger.launcher, Gammy Managed com.t9messenger.launcher.managed, Gammy Family com.t9messenger.family, and the related Gammy websites and services.
Developer: Gammy Studios LLC
Privacy contact: admin@gammystudios.com
Overview
Gammy Launcher turns an Android smartphone into a simpler phone experience with large controls, calling, text messaging, contacts, photos, alarms, calendar, audio tools, simplified setup, and caregiver setup features. Gammy Focus, Gammy Full, and Gammy Managed are separate apps. Gammy Managed is a mixed-audience app for children getting a first phone and for adults or seniors using a caregiver-managed device. It includes kiosk behavior, protected setup, and child-safe defaults. Gammy Focus, Full, and Managed can provide default SMS, dialer, and alarm features when the user chooses those Android roles. Gammy Full and Managed can also act as the user's home screen. The apps may request permissions normally used by phone, messaging, camera, microphone, contacts, calendar, location, notification, Wi-Fi, Bluetooth, and device-setup apps; the Managed build delegates Bluetooth setup to Android and does not request Bluetooth scan or Nearby Devices permission.
Gammy Family is the optional caregiver companion. It uses first-party Gammy services to connect authorized caregivers with a household, provide setup and status tools, and support caregiver accounts. Gammy Family is intended for parents, caregivers, and other authorized family members rather than use by a child as the account holder.
We do not sell personal data. Gammy does not include ads or third-party advertising SDKs.
Data Gammy Accesses
Gammy may access the following data depending on which features the user or caregiver enables:
- Contacts: names, phone numbers, and contact details used for trusted contact calling and messaging, including contact edits made inside Gammy.
- SMS and MMS: text and media messages used to send, receive, display, and store conversations when Gammy is selected as the default SMS app, plus PIN-validated caregiver/admin setup messages if that managed feature is enabled.
- Phone and call data: phone state, call-log information needed for the default dialer experience, outgoing calls, incoming call display, and in-call controls when Gammy is selected as the default dialer.
- Photos, videos, and camera: photo viewing, camera capture, media messages, QR scanning screens, and related local media features.
- Calendar: calendar event titles, times, and reminders shown in the calendar tool when permission is granted.
- Microphone and audio: web calls, voice input, Beau companion features, voice recorder, saved audio files, radio, alarm, timer, and Bible read-aloud audio where enabled.
- Bible reading data: local bookmarks and last-read position for bundled public-domain Bible text.
- Medication routine data: medication names, doses, schedules, and notes that the user or caregiver enters for the local medication list. Gammy uses this for routine display only; it is not medical advice, diagnosis, treatment recommendations, clinical monitoring, or care-provider medication management.
- Location and Wi-Fi information: navigation features, Android Wi-Fi setup flows, and optional Weather. Location Tools are off by default in Gammy Managed and can be enabled only from the PIN-protected caregiver dashboard. In launcher versions that include direct Weather transport, after an admin accepts the in-app disclosure and enables Weather, Gammy rounds latitude and longitude to one decimal place and sends those approximate coordinates to Open-Meteo over HTTPS when Home or Weather refreshes. Corrective Full and Managed releases disable that direct Weather transport and send no coordinates to a weather provider. Gammy does not provide continuous or background family location tracking.
- Notifications: selected notification access if the user grants notification listener access. Gammy uses it for optional Motorola FM controls and only reads or suppresses competing SMS notifications while Gammy holds Android's default SMS role.
- App settings and local app data: admin PIN hash, setup choices, a caregiver-entered number for display as this phone's own number, home and managed-device configuration, Android setup/settings state where permission is granted, alarms, reminders, message history, contacts, and feature settings. The displayed own-number value is entered by a caregiver, remains in app-private storage, and is not read automatically from the SIM.
- Device or app identifiers: local, app-generated identifiers used for app setup. The launcher release does not transmit advertising ID, IMEI, IMSI, SIM serial, Build serial, MAC address, the device phone number, BSSID, SSID, or similar persistent device identifiers.
- Gammy Family account data: caregiver email address, display name, a one-way password hash, authentication-session records, household membership, and account-security activity.
- Gammy Family household data: household and device labels, authorized caregiver links and roles, device status and setup progress, caregiver-entered family or restore information, consent records, call and message activity, and commands requested by an authorized caregiver.
- Gammy Family app data: a random first-party app-install identifier, app registration and notification state, and camera or microphone access when the caregiver scans a pairing code or starts a call. Gammy Family does not use the advertising ID.
- Purchase and referral data: product or plan, transaction and subscription status, processor identifiers, refund or chargeback status, and an optional first-party referral code used to attribute a purchaser's qualifying sale. When Gammy's website referral route is enabled, opening an active Gammy referral link sets a secure, HttpOnly, SameSite=Lax first-party session cookie containing only that code. It expires when the browser session ends, is not used for cross-site advertising, and a later referral link does not replace the first valid code in that session. Gammy does not receive full payment-card numbers from Google Play or Stripe.
- Website and service request data: hosting and security providers may process normal network details such as IP address, request time, requested page or API route, browser or app user agent, response status, and diagnostic or abuse-prevention logs. Gammy does not add third-party advertising or behavioral analytics to the public website.
- Gammy Managed Family service traffic. A caregiver can link a Gammy Managed phone to a Gammy Family household. Until a caregiver links the phone, Gammy Managed does not send any of this information and works entirely on the device. After linking, the phone sends a Gammy-issued device identifier and device registration token with check-ins and command polls to the Gammy Family service address the caregiver provided. The service records the last device check-in time and a registration-bound poll heartbeat that is updated no more than once every 45 seconds. Check-in status can include setup/restore progress; the name, requester, result, and error state of caregiver-requested actions; call/workflow/update state; app version and edition; default-app/device-owner state; and battery or charging state. A caregiver-requested support action can also send the Android/app version, manufacturer/model/device name, available storage, locale, and time zone. When the phone requests a Family video call, it also sends the selected Family contact identifier and display name.
- What Gammy Managed check-ins do not include: message text, call logs, contact lists, calendar entries, photos, medication entries, or location. Gammy Managed does not send an advertising identifier or a permanent hardware identifier.
How Data Is Used
Gammy uses data to provide the features selected by the user or caregiver:
- Show a simple home screen and menu.
- Make and receive calls.
- Send, receive, and display SMS/MMS messages.
- Process caregiver/admin setup messages when an enabled managed feature uses them for documented setup updates.
- Show trusted contacts and photos.
- Run alarms, timer, calendar, audio, camera, navigation, Android-owned Bluetooth setup, Wi-Fi, medication-list, and setup tools. In Managed, streaming radio and the complete Bible library are off by default and can be enabled only from the PIN-protected caregiver dashboard.
- Keep protected setup and managed-device behavior reliable.
- Authenticate caregivers, connect authorized Gammy Family members to a household, deliver requested Family features, prevent abuse, and provide account recovery and deletion.
- Validate purchases and subscriptions, provide entitlements and support, and calculate referral commissions on eligible purchaser transactions.
Data Sharing And Service Providers
Gammy may share or process data with the following services only as needed for enabled features:
- Mobile carriers and Android phone/SMS services for calls, SMS, and MMS.
- Launcher versions that include direct Weather transport use Open-Meteo for an approximate-coordinate forecast request only after an admin explicitly enables Weather. Open-Meteo also receives normal network information such as the requesting IP address. Corrective Full and Managed releases do not contact Open-Meteo.
- Streaming radio providers when the user plays an internet radio stream.
- Video calling or handoff apps when the user chooses to open or hand off a call to another app.
- Cloudflare for hosting, security, storage, notifications, and enabled realtime call routing for Gammy Family.
- Netlify for the Gammy Studios website, redirects, request handling, and enabled website functions.
- Neon-hosted PostgreSQL for website account, waitlist, purchase, entitlement, and referral records when those website services are enabled.
- Google Firebase Cloud Messaging and Apple Push Notification service for generic Gammy Family notification wakeups when the applicable notification channel is enabled.
- VDO.Ninja for a standard user-started video-call session when that compatibility path is enabled. Camera and microphone media is sent only after the caregiver starts or joins a call.
- Google Play for app distribution, purchases, subscriptions, refunds, and related purchase verification.
- Stripe for purchases made on an authorized Gammy website. Stripe processes payment details under its own privacy terms; Gammy receives transaction and customer references rather than full card numbers.
- Communications providers when an authorized caregiver uses an enabled text-message or video-call feature.
- Cloudflare Workers hosts the production HTTPS Gammy Family service that receives Gammy Managed device check-ins and command polls, records the last check-in time and rate-limited poll heartbeat, returns requested restore data, and coordinates requested Family calls. Cloudflare processes this information on Gammy's behalf as an infrastructure provider. Gammy Managed does not use Firebase, Play Billing, or any analytics service.
We do not sell personal data.
Local Storage
Most Gammy data is stored locally on the device. This can include contacts, messages, settings, a caregiver-entered number for display as this phone's own number, alarms, reminders, calendar display state, audio recordings, Bible bookmarks, medication routine data, admin setup data, and local feature data. Local data may be removed by deleting it in the app where supported, resetting the device/app data, or uninstalling Gammy.
Security
Gammy uses Android platform permissions and app-private storage to limit access to local data. App-controlled internet services use HTTPS/TLS-capable connections where supported. Carrier SMS, MMS, and phone-call transport are controlled by mobile carriers and are outside Gammy's TLS control. Users and caregivers should keep the device lock, caregiver/admin PIN, and Google account credentials secure.
Data Retention And Deletion
Gammy keeps local data for as long as needed to provide the enabled features or until the user or caregiver deletes it, resets app data, or uninstalls the app. Gammy Launcher data remains local except for the enabled network features described above.
Gammy Family keeps server-side records for accounts, households, purchases, and enabled Family services while the account or household is active. A signed-in caregiver can permanently delete a caregiver account from the account panel. Deletion removes the account email, password hash, sessions, account profile, and membership records; it unlinks the account from shared households and anonymizes its account-attributed household activity. Shared household records and purchase records may remain for other authorized caregivers, service continuity, fraud prevention, tax, accounting, dispute, or legal obligations. Subscription cancellation is separate from account deletion.
An authorized caregiver can revoke a linked Gammy Managed phone under Device Tokens in Gammy Family. This invalidates its device credential and stops future authenticated check-ins and polls. The current Archive household action deactivates the household, revokes Family links and device/app registrations, and clears Family restore data. Archive is not a hard delete. Service records may remain, including household and link metadata, device-registration metadata, the last stored device status/check-in, the registration-bound last recorded poll heartbeat, workflow and consent state, and security or household activity history. Each setup packet expires at its stated device-token expiration. Self-serve packets are valid for no more than 72 hours; operator-provisioned packets may use a longer lifetime, with the current operator default capped at 365 days. The data-deletion page provides a verified request path for eligible retained records.
Visit Gammy Data Deletion at https://gammystudios.com/data-deletion.html for in-app and local deletion steps or to request help from admin@gammystudios.com.
Children
Gammy Managed is intentionally designed for a mixed audience that includes children ages 9-12, teens, adults, and seniors. A parent or caregiver sets up a child's Managed phone. The child-accessible default experience contains no ads or analytics, starts with calls and texts limited to caregiver-managed trusted contacts, keeps location tools off, and keeps uncontrolled streaming radio and the complete Bible library off. Optional location or open-media tools can be enabled only from the PIN-protected caregiver dashboard.
A Gammy Managed phone may be used by a child. A parent or caregiver decides whether to link that phone to a household, and no Gammy Family check-in or poll leaves the phone until they do. The linked transport carries a Gammy-issued device identifier and the functional status described above, and the service records the last check-in time and rate-limited poll heartbeat. This information is never used for advertising, profiling, or sale. An authorized caregiver can revoke the phone's Device Token to stop future authenticated check-ins and polls, and can request deletion of eligible retained service records.
Gammy does not knowingly use a child's personal data for advertising, profiling, referral attribution, or sale. Referral attribution is attached only to the purchaser or caregiver transaction, never to a child's Managed profile. The launcher release does not transmit advertising ID or the persistent device identifiers listed above. A parent or caregiver controls any child-related information entered into Gammy Family and may review or remove it, delete the caregiver account, reset app data, uninstall Gammy, or contact admin@gammystudios.com for privacy help.
Financial And Health Features
Gammy includes a local medication routine management feature and declares that feature in Google Play's Health Apps form. Gammy is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. It does not provide medical advice, treatment recommendations, dose recommendations, clinical monitoring, medication-adherence monitoring, emergency monitoring, or guaranteed emergency response. Medication information should come from the user's or caregiver's existing care instructions, and users should consult a qualified healthcare professional for medical advice, diagnosis, or treatment.
Gammy Launcher does not offer a public financial product.
Changes To This Policy
We may update this policy when Gammy changes. The effective date above will be updated when the policy changes.
Contact
Questions or requests can be sent to: admin@gammystudios.com