This Privacy Policy describes how ChoreCrown ("we," "us," or "our") collects, uses, and protects information when you use our website and mobile app at chorecrown.com. ChoreCrown is a family chore management app that helps parents assign chores, track completion, and reward children through gamification (points, levels, and rewards).
1. Information We Collect
Parent/Guardian Information
- Email address: Used for login, password resets, email verification, and account notifications.
- Password: Hashed using bcrypt before storage. Never stored in plain text.
- Parent PIN: A numeric PIN used for quick authentication on kid-facing devices. Hashed using bcrypt before storage.
- Family name: A display name for your household (e.g., "The Smith Family").
- Consent records: Timestamp of when you accepted this Privacy Policy and Terms of Service.
Child Information
- Name: The name of each child as entered by the parent.
- Birthday: Optional. Used for age display and birthday features.
- Avatar and color: Visual profile customization chosen by the parent or child.
- Chore assignments and completion records: Which chores were assigned, completed, approved, or rejected.
- Points, levels, and XP: Gamification data earned through chore completion.
- Streak data: Consecutive chore completion streaks for motivation.
- Reward redemptions: Records of rewards redeemed by the child using accumulated points.
Device and Usage Data
- Household ID: A unique identifier stored in your browser's local storage to associate a device with your family.
- Push notification subscription: If you enable notifications, we store a browser push subscription token.
- IP address: Logged for security and troubleshooting. Not associated with individual children.
2. How We Use Your Information
- Managing your family's chores, points, rewards, and rotation schedules.
- Authenticating parents and children on their respective devices.
- Sending password reset emails and email verification links.
- Sending push notifications for chore reminders and approval updates (if enabled).
- Processing subscription payments for Pro tier (via Stripe).
- Maintaining streak data, completion history, and analytics to help parents track progress.
- Preventing fraud and unauthorized access.
3. Data Sharing and Disclosure
We do NOT sell your data. Your family's information is not provided, sold, or made available to advertisers, data brokers, or any third party for marketing purposes.
We share data only with the following service providers, who process data on our behalf to operate the service:
- Cloudflare: Website hosting, DNS, and security (processes IP addresses and web traffic).
- Stripe: Payment processing for Pro subscriptions (processes payment method data — we do not store card numbers).
- Google (Gmail SMTP): Sends transactional emails (password resets, verification links). Email addresses are shared with Google's SMTP service for the sole purpose of delivering these emails.
- Oracle Cloud: Server hosting for the backend application and database.
We may disclose information if required by law, court order, or to protect the rights, safety, or property of our users.
4. Children's Data and Parental Consent (COPPA)
ChoreCrown is designed as a parent-managed tool. We comply with the Children's Online Privacy Protection Act (COPPA) and the following principles:
- Parental consent required: Only a parent or legal guardian can create an account and add children. At signup, parents must explicitly consent to the collection of their children's data.
- No direct collection from children: Children do not provide personal information directly to us. All child data is entered and managed by the parent.
- Parental control: Parents can view, modify, export, and delete all data associated with their family at any time through the Account Settings page.
- No behavioral advertising: We do not show advertising to children or use their data for behavioral targeting.
- No third-party sharing: Children's data is never shared with third parties for any purpose other than operating the core service.
Parents can withdraw consent and delete all family data at any time by using the "Delete Account" feature in Account Settings.
5. Your Rights (GDPR, CCPA, and State Laws)
If you are located in the European Union (GDPR), California (CCPA/CPRA), or other jurisdictions with data protection laws, you have the following rights:
- Right to access: You can request a copy of all data we hold about you and your family.
- Right to rectification: You can correct inaccurate information through the app or by contacting us.
- Right to erasure ("right to be forgotten"): You can delete your account and all associated data at any time.
- Right to data portability: You can export your family's data in JSON format.
- Right to object: You can object to certain processing of your data.
- Right to withdraw consent: You can withdraw consent for data processing by deleting your account.
To exercise any of these rights, use the Account Settings page or contact us at the email below.
6. Data Retention
We retain your family's data for as long as your account is active. If you delete your account, all data is permanently removed from our database within 30 days. We do not retain backups of deleted data beyond our standard backup rotation (backups are overwritten on a rolling basis).
If a subscription is cancelled but the account is not deleted, we retain the data so the family can resubscribe without losing their chore history.
7. Data Deletion and Export
Delete your account: Parents can delete their entire family account at any time from Account Settings. This permanently removes all parent information, child profiles, chores, rewards, completion history, and tokens. This action cannot be undone.
Export your data: Parents can download all family data in JSON format from Account Settings at any time.
Email request: You can also email us at [email protected] to request deletion or export.
8. Data Security
- Passwords and PINs are hashed using bcrypt before storage. We never store plain-text passwords.
- All web traffic is encrypted using HTTPS (TLS 1.2+).
- JWT tokens are used for authentication and expire after 60 minutes (access token) or 7 days (refresh token).
- The database is hosted on a private server accessible only through the application backend.
- Payment data is handled entirely by Stripe — we never see or store credit card numbers.
While we take reasonable measures to protect your data, no method of transmission or storage is completely secure. If a data breach occurs, we will notify affected users within 72 hours as required by GDPR Article 34.
9. Payment Processing
If you subscribe to ChoreCrown Pro, payment processing is handled by Stripe. We receive only your Stripe customer ID and subscription status — we do not store, process, or transmit credit card numbers. Stripe is PCI DSS Level 1 compliant.
You can manage your subscription (cancel, update payment method, view invoices) through the Account Settings page, which redirects to the Stripe Customer Portal.
10. Cookies and Local Storage
ChoreCrown does not use tracking cookies, advertising cookies, or third-party analytics. We use your browser's local storage to:
- Store authentication tokens (JWT) so you stay logged in.
- Store your household ID so kid devices remember which family they belong to.
- Remember if you've dismissed the install prompt.
Local storage data is cleared when you log out or delete your account. No tracking or cross-site advertising is performed.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify users by email and/or through the app. The effective date at the top of this policy indicates when it was last updated. Continued use of the service after changes constitutes acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us: