ChoreScroll Privacy Policy
This policy covers the ChoreScroll iOS app and chorescroll.com (the “Service”), operated by ChoreScroll, LLC (“ChoreScroll,” “we,” “us”). ChoreScroll helps parents set chores for their children, verify completion with photos or an optional audio check, and manage app access on a child’s device using Apple’s Screen Time technology. Because children under 13 use part of the Service, this policy is written to comply with the Children’s Online Privacy Protection Act (“COPPA”) as amended, and Section 3 applies specifically to children’s information.
Contact: ChoreScroll, LLC, 5900 Balcones Drive, Ste 100, Austin, TX 78731, USA · privacy@chorescroll.com · (737) 227-6100.
1. The short version
- We collect only what the Service needs to work: a parent account, child profiles a parent creates, chore photos, and app-function data.
- We never sell personal information, never use it for advertising, and never allow it to be used to train AI models.
- Chore photos are reviewed by an AI service (Anthropic) solely to check whether a chore looks done, then the parent has final say. Photos that appear to contain a person are blocked on the device and never uploaded.
- Parents control everything: they can review, delete, or stop collection of their child’s information at any time.
- Photos and other data are kept only as long as needed, on defined schedules (Section 6), never indefinitely.
2. Information we collect
From parents and solo (18+) users
- Account data: email address and password (stored as a secure hash) — or, if you choose Sign in with Apple instead, the identifier and relay email Apple provides — plus your family name.
- Subscription data: subscription status and receipt validation via Apple and RevenueCat. We never see or store card numbers; billing runs through your Apple account.
- Content: chore definitions and optional “training photos” showing what a completed chore should look like. Training photos may show your home interior; do not include people in them.
- Sign-in and session data: nothing beyond what’s needed to keep you signed in. ChoreScroll does not currently send push notifications and does not collect hardware device identifiers, advertising identifiers, or location data.
From children (child profiles created by a parent)
- Profile data the parent enters: a first name or nickname and an avatar. We do not ask children for this information, and we do not collect a child’s age, birthdate, or any other identifying detail beyond what’s listed here.
- Chore proof photos: photos the child takes in-app (live camera capture only) to show a chore is done, with the date and time of submission.
- App-function data: chore completion history, streaks, and unlock status, tied to an anonymous session identifier for the child’s paired device — not a hardware device ID or advertising identifier, and not used for push notifications, which ChoreScroll does not currently send.
- Microphone data for the optional “audio check” (e.g., confirming a sound machine or TV is off): a live loudness reading only, used in the moment to pass or flag the check. No audio is ever recorded, stored, or transmitted — not to us, not to any service provider, not even temporarily on the device.
We do not collect: geolocation, contacts, browsing history, or the identity of the apps a parent chooses to block. App selections made through Apple’s Screen Time feature are opaque tokens that stay on the device — neither ChoreScroll nor anyone else can read which apps were selected.
3. Children’s privacy (COPPA notice)
A child can only use ChoreScroll after their parent creates the child’s profile and gives verifiable parental consent, and the app enforces this in order. First, you cannot add a child at all until your card-backed subscription or free trial is active — starting one requires a payment method on file with your Apple account, and Apple confirms that transaction to you directly. That payment-card transaction verifies consent is being given by an adult with authority over the account’s payment method. Second, before any child profile is created, the app shows you a Direct Notice — in the app itself, not buried in this policy — describing exactly what we collect from your child and why, and you must affirmatively agree. Only after both steps does the child’s profile get created, and it stays on your device until you choose to pair your child’s device. We record which account, which family, when, and which version of the notice you agreed to, as our consent record. Before consent, we collect no personal information from a child.
What we collect from children and why
| Information | Why we collect it | Disclosed to |
|---|---|---|
| Chore proof photos + timestamp | To verify a chore is complete: an automated AI review, then parent approval | Anthropic (AI review), Supabase (storage) — service providers only |
| Completion history, streaks, unlock status | To run the daily chore/unlock cycle and show parents progress | Supabase (hosting) only |
| Anonymous device session identifier | To let a paired kid device sync its own chores and photos without a password | Supabase (hosting) only |
| First name or nickname, avatar (entered by parent) | So parent and child see the right chore board | Supabase (hosting) only |
| Microphone loudness reading (audio check chores only) | To verify a device is on or off without a photo | Nobody — never recorded, stored, or transmitted |
How the AI photo review works
Before a photo ever leaves the device, ChoreScroll checks it on-device — using Apple’s built-in Vision framework, never sent to us — for a visible face, and blocks submission of any photo that appears to contain a person; chores cannot be verified with a photo of a person. Photos that pass this check are sent to Anthropic, PBC, our AI service provider, which returns a confidence score on whether the chore appears complete. Anthropic processes photos under commercial terms that prohibit using them to train AI models, and deletes them from its systems within 30 days. Photos are used for chore verification only. We do not use children’s personal information to train or develop AI, and we do not permit any service provider to do so. If that were ever to change, we would first obtain separate verifiable parental consent as required by COPPA.
How the audio check works
Some chores can be verified with a brief audio check instead of a photo — for example, confirming a sound machine or TV is off. The app measures how loud the room is for a few seconds; it does not record, store, or transmit any audio, to us or to anyone, at any point, on-device or off. A live camera preview may be shown during the check so a child can see themselves, purely as a visual aid — nothing from that preview is captured or saved either. If the check can’t confirm the chore after a few tries, it’s sent to the parent for manual approval instead.
What we never do with children’s information
- No sale of personal information, no advertising or marketing use, no behavioral profiling.
- No third-party analytics or advertising SDKs in the child experience.
- No disclosure to third parties except the service providers named in Section 5, who may use the information only to provide their service to us.
- We do not condition a child’s use of the Service on collecting more information than is reasonably necessary to provide it.
Parents’ rights
At any time, a parent may: (a) review the personal information we hold about their child; (b) direct us to delete it; and (c) refuse to permit further collection or use, which will disable the child’s profile. Use the in-app controls (Family & Account, from the parent dashboard — swipe to remove a specific child, or delete the whole account) or contact privacy@chorescroll.com. We will verify you are the child’s parent before acting. Deleting a child’s profile removes that child’s chores, photos, and history on the schedule in Section 6; it does not affect any other child on the same family.
4. How we use information (all users)
- Provide and operate the Service: accounts, chore boards, photo verification, app unlocking.
- Process subscriptions and trials through Apple and RevenueCat.
- Service integrity and security: authentication, fraud and abuse prevention, debugging.
- First-party product analytics on aggregate usage (e.g., chores completed, active families). We do not use third-party analytics on children’s data.
We do not repurpose data collected for one purpose for an unrelated purpose without consent.
5. Service providers
We share personal information only with service providers acting on our instructions, each bound by terms requiring protection at least equal to this policy:
| Provider | Role | Data handled |
|---|---|---|
| Supabase | Hosting: database, authentication, photo storage | Account data, child profiles, photos, app-function data |
| Anthropic, PBC | AI photo verification (inference only; no training; ≤30-day retention) | Chore proof photos, training photos |
| RevenueCat | Subscription management (parent accounts only) | Subscription status, Apple receipt data |
| Apple | App distribution, billing, and (if you choose it) Sign in with Apple | Transaction data and, for Sign in with Apple, an identity token (under Apple’s own policies) |
We may also disclose information if required by law, to protect safety, or as part of a merger or acquisition — in which case children’s information would remain subject to commitments at least as protective as this policy, and parents would be notified.
6. Retention and deletion
We keep personal information only as long as reasonably necessary for the purpose it was collected, then delete it. Highlights (full schedule in our written Retention Policy, available on request):
- Chore proof photos: deleted 30 days after final approval/rejection; Anthropic’s copy is deleted within 30 days of processing automatically.
- Training photos: these show a completed-chore example (an empty countertop, folded laundry, etc.), not a child, so they aren’t personal information about a child under COPPA. Kept for as long as the related chore or your account exists; removed if you delete the chore or delete your account.
- Child profiles and history: kept while the profile is active. Deleting a child’s profile, or deleting your entire account, removes it from our live systems immediately; residual copies may persist in backups or logs for up to 30 days before being purged.
- Parent accounts: removed from our live systems immediately upon deletion; residual copies may persist in backups or logs for up to 30 days, minus records we must keep for tax, legal, or fraud-prevention purposes.
- Verifiable parental consent records: kept for the life of your account plus 3 years afterward, as required compliance evidence — these are not deleted when a child’s profile or your account is removed.
You can delete your account, including all child profiles, directly in the app (Family & Account → Delete account, from the parent dashboard) or by emailing privacy@chorescroll.com.
7. Security
Data is encrypted in transit and at rest. Photos are stored in access-controlled storage reachable only through authenticated requests scoped to your family. AI verification runs through our server — no API keys or third-party access ship in the app. No system is perfectly secure; we will notify affected users and regulators of a breach as required by law.
8. Your choices and rights (all users)
- Access, correct, or delete your data in-app or via privacy@chorescroll.com.
- Withdraw consent to collection at any time (this may disable the Service).
- Camera access is requested only when taking a chore photo; microphone access is requested only during an optional audio-based chore check, and, as described in Section 3, no audio is ever recorded, stored, or transmitted.
Depending on where you live (e.g., California and other U.S. states), you may have additional rights, including to know, delete, and opt out of sale/sharing. We do not sell or share personal information as those terms are defined in the CCPA, and we do not knowingly sell any minor’s data.
9. Changes to this policy
We will post changes here and update the date above. If a change materially affects how we handle children’s personal information, we will notify parents directly and obtain new verifiable parental consent where COPPA requires it.