Grail

Privacy Policy

Last updated: September 30, 2026

1. Overview

Grail is a personal fountain pen and ink ledger for iPhone, iPad, and Mac, developed by Orochi Systems (Can Kirsallioba, Tokyo, Japan). It is built so that your collection stays yours. Your records are stored on your device and, if you choose, in your own private iCloud. They are never sent to an Orochi Systems server, because there is none.

2. What Grail Stores

Grail keeps the records you enter: pens, nibs, inks, bottles and samples, fills, care events, ratings, notes, and any photographs you attach. All of it is stored in the App's own library on your device. If you are signed in to iCloud, the same records are mirrored to your private iCloud database (CloudKit) so they appear on your other devices. That database belongs to your Apple Account. Apple's iCloud terms apply to it; the developer has no access to its contents and no server of their own. iCloud sync is optional. If you are not signed in to iCloud, or iCloud Drive is off for Grail, your records stay only on the device where you entered them.

3. What Grail Does Not Do

- Grail does not require an account or sign-in, and there is no Orochi Systems login, cloud, or backend. - Grail does not collect analytics, usage statistics, or crash reports of its own. - Grail does not use advertising, tracking, or any third-party software development kits. - Grail makes no network calls of its own. It does not send your records anywhere except your own iCloud account, and only when iCloud sync is on. - Grail never asks for access to your photo library. When you attach a photo, the system photo picker hands Grail only the picture you chose. - Grail does not request your location, contacts, calendar, microphone, or camera. The App's privacy manifest declares no collected data and no tracking, and Grail does not ask for tracking permission because it does not track you.

4. Photographs

You can attach a photograph to a pen or to a fill as a writing sample. Photographs arrive only through the system photo picker, so Grail sees only the pictures you pick and never the rest of your library. They are stored in the App's library on your device, are mirrored to your private iCloud with the rest of your records when sync is on, and are included in exported archives.

5. Exports and Backups

Export writes a JSON archive of your library, including photographs, to a location you pick. That file is under your control; anyone you give it to can read it. Import merges an archive back into your library. Deletions are remembered inside the library and inside exported archives, so an older backup cannot resurrect a record you removed on purpose. Protect exported files after they leave the App.

6. Feedback and Contacting Us

Settings → About → Send Feedback opens your mail app with a message addressed to the developer. Sending it is your choice, and the message contains only what you write plus the App version, system version, and language shown in the draft. If you write to us, we receive your email address and whatever you choose to include, and we use it only to answer you. Support emails are kept only as long as needed to help you and to keep a record of the request.

7. Catalog, Maker, and Product Names

Grail ships with a reference catalog of pen models, nib options, and inks so you can name your own records quickly. The catalog is bundled inside the App and is looked up on your device; choosing from it sends nothing anywhere. Maker and product names appear only to identify the records you keep, the way a spreadsheet would list them. Grail is not affiliated with, sponsored by, or endorsed by any pen or ink maker.

8. App Store Privacy Label

Data Not Collected. Grail does not collect any data from this App. Apple may provide us with crash and usage information from TestFlight and the App Store under Apple's own terms, where you have agreed to share it with developers.

9. Security

Grail relies on Apple platform security, device encryption and sandboxing, and Apple's encrypted transport for iCloud. No storage or sync system can be guaranteed completely secure, but by keeping your records on your devices and in your own iCloud, Grail minimizes exposure by design. Protecting your devices with a passcode protects your Grail library too.

10. Retention and Deletion

Grail keeps your records on your devices, and in your private iCloud when sync is on, until you delete them. Deleting a record in the App removes it from your library and, through sync, from your other devices. Deleting the App from a device removes its local library on that device; records already mirrored to iCloud remain in your iCloud account until you remove them there or delete them from another device. Because Orochi Systems holds none of your App data, there is nothing for us to retain or delete on your behalf.

11. Your Rights

Because your Grail library lives on your own devices and in your own iCloud, you exercise most privacy rights directly. You can see every record in the App, take a copy with Export, correct anything you entered, and delete what you no longer want. If privacy law where you live, such as Japan's Act on the Protection of Personal Information, the GDPR, or the KVKK, gives you further rights regarding information you have emailed to us, write to grail@orochisystems.com and we will respond.

12. Children's Privacy

Grail is a general-audience app rated 4+ and collects no personal information from any user, including children. Because no data is collected, stored, or transmitted by Orochi Systems, the App poses no privacy risk to users of any age.

13. International Users

If you use Grail outside your home jurisdiction, local privacy laws may apply. Apple may process operational data such as iCloud and App Store distribution under its own infrastructure and legal obligations.

14. Changes to This Policy

Changes to this policy are published with App updates and on this page, with a revised "Last updated" date.

15. Contact

If you have privacy questions about Grail, contact us at grail@orochisystems.com, use Send Feedback in the App under Settings → About, or visit https://orochisystems.com/grail/support.