Privacy Policy
Version 2026-09-06 · Effective September 6, 2026 · Terms of Service · Parental Consent
ChoreDash is a household chores-and-rewards app used by parents and their children. Because children use it, we designed it around the U.S. Children's Online Privacy Protection Act (COPPA) and similar rules elsewhere (GDPR-K, UK Age-Appropriate Design Code). The short version: we collect the minimum, we never sell it, we show no ads, and parents stay in control — including the ability to export, freeze and permanently delete everything.
1. Who we are and how to reach us
ChoreDash ("we") operates choredash.info. Privacy questions, data requests and complaints: privacy@choredash.info. We answer within 10 business days and complete verified deletion requests within 30 days.
2. What we collect
From parents and other adult household members
- Account: email address, display name, a salted password hash (or a Google sign-in id).
- Household: household name, time zone, members and their roles, invite codes.
- Billing (paid plans and Family Wallet top-ups): handled by Stripe. We store Stripe customer / payment ids and amounts — never card numbers.
- Consent records: see section 4.
About children (created only by a parent)
- Profile: first name, optional nickname, age (or birth month/year), an avatar emoji and color, and optionally a profile photo that a parent has approved.
- Activity inside the household: chores assigned and completed, routines, points, XP, levels, badges, streaks, rewards requested and redeemed, savings goals, Money-Lab simulations, privilege requests, snack requests.
- Content the child creates: optional photo proof of a chore, voice clips (recorded by parents for picture-first mode), short journal entries, chore ideas, cheers for siblings, and messages to parents or siblings in the same household.
- Kid Login: a PIN hash (never the PIN), a login code, session tokens, and the time of last sign-in.
What we deliberately do NOT collect about children
- No last name, email address, phone number, street address or school.
- No precise location. GPS and other EXIF metadata are stripped from every photo before it is stored.
- No contacts, no device identifiers for advertising, no third-party tracking or analytics SDKs on kid screens.
- No persistent identifiers shared with anyone outside your household.
3. Why we collect it (and the legal basis)
- To run your household's chores, routines, rewards and messaging — the service you asked for.
- To keep kids safe: text a child writes is screened for profanity and hidden contact details; photos are screened for unsafe content before they're saved. Flags go to the parent, never to third parties.
- To generate optional AI suggestions (chore ideas, encouragement, weekly summaries). Prompts contain only first names, ages and chore data; AI providers are contractually barred from training on them.
- To send notifications a parent turned on (push, email) and to bill paid plans.
- Legal basis: performance of our contract with the parent, the parent's verifiable consent for child data, and our legitimate interest in security and abuse prevention.
We do not sell personal data. We do not show advertising. We do not use children's data for behavioral advertising, marketing profiles, or any purpose unrelated to your household.
4. Verifiable parental consent
No child profile can be created until the parent records consent. We support two methods and store which one was used so it is auditable:
- Signed affirmation (default): the parent reads the consent statement, ticks a box, and types their full name.
- Card verification (stronger): a $0 authorization of a payment card through Stripe confirms an adult payment method. Nothing is charged and card details never reach us.
Every consent record stores: the household, the child (or "whole household"), who granted it, the exact text shown, the policy version accepted, the method, a coarse network prefix (never the full IP) and browser family, and timestamps for grant and revocation. When this policy changes materially, we bump the version and ask parents to re-affirm before adding children.
5. Parents' rights and controls
Everything below is self-serve in Settings → Privacy & Data — no email required:
- Access & portability: download a complete JSON export of the household and each child's data, including a list of media references.
- Review: parents see every message, journal entry, photo and request their child creates.
- Revoke consent (freeze): stops all further collection for a child — the profile is deactivated, Kid Login is disabled and sessions end. Existing data is kept only until you export or delete it, or restore consent.
- Delete a child: permanently erases every record about that child and every photo and voice clip in our private storage, atomically.
- Delete the household or your account: removes all household data, all children, all files, and signs out every device.
Each action is written to a tamper-evident privacy activity log visible to the household's parents. Refusing or revoking consent never affects the parent's own account.
6. Who can see a child's data
- The parents/owners of the household, and other adult members with the roles a parent grants.
- Siblings in the same household see first names, avatars, points and leaderboard positions, and can exchange moderated messages and cheers.
- A child linked to two households (e.g. co-parents) has separate points and visibility per household.
- Our staff only access data to resolve a support request you open or to investigate abuse, and every access is logged.
7. Service providers
We use a small number of processors under data-processing agreements: our cloud database and private file storage, Stripe (payments and card verification), an AI gateway for optional suggestions, a push-notification relay, and an email provider for parent emails. None of them may use your family's data for their own purposes.
8. Security
- Encryption in transit (TLS) everywhere; encryption at rest for the database and storage.
- Row-level security on every table: a household's data is invisible to every other household, enforced in the database itself.
- Photos and voice clips live in private buckets and are served only through short-lived signed links.
- Secrets and payment keys live only on our servers. Kid PINs are stored as hashes with attempt limits.
- Money-moving operations require parent approval and run as atomic server-side transactions.
9. Data retention
- Household and child data: for as long as the household exists. Deleted immediately on request (section 5); backups roll off within 30 days.
- Frozen (consent-revoked) children: retained up to 90 days for the parent to export or restore, then deleted.
- Kid sessions: expire automatically; PIN attempt logs are kept 30 days.
- Photo proof: retained until the chore is deleted or the child/household is deleted.
- Consent records and the privacy activity log: kept for 3 years after deletion, as required to demonstrate compliance; they contain no child content.
- Billing records: 7 years, as required by tax law.
10. Cookies and local storage
We use only strictly-necessary storage: your sign-in session, the household you last opened, sound and install preferences. No advertising or cross-site tracking cookies.
11. International users
Data is hosted in the United States. If you use ChoreDash from the EU/UK, the parent is the person who consents on the child's behalf, and you have the rights in section 5 plus the right to complain to your data-protection authority.
12. Changes to this policy
Material changes bump the version number above, are announced in-app to parents, and require re-affirmation before new child data is collected. Older versions are available on request.