Privacy Policy
1. Who We Are
CocoBucks ("we", "our", "us") is a family productivity application. The app is operated by the CocoBucks development team. For privacy questions, contact us at privacy@cocobucks.app.
2. Who This Policy Covers
This policy applies to:
- Guardians — adults who create and manage a CocoBucks family account.
- Children — minors added to a family by a guardian. Guardians are responsible for any data entered on behalf of a child.
CocoBucks is not directed to children under 13 as independent users. Guardians must be 18 or older to create an account.
3. Data We Collect
| Data | Who It Belongs To | Why We Collect It | Linked to Identity |
|---|---|---|---|
| Email address | Guardian | Account authentication (Firebase Auth) | Yes |
| User ID (Firebase UID) | Guardian | Identifies your account in our database | Yes |
| Family name (optional) | Guardian | Personalise the family dashboard | Yes |
| Child profile names / nicknames | Child (entered by guardian) | Display name on dashboards and notifications | Yes |
| Child profile avatars (emoji or image) | Child (chosen by guardian) | Visual identification on dashboards | Yes |
| Task-proof photographs | Child (uploaded via app) | Evidence that a task was completed; reviewed by guardian | Yes |
| Task history & completion records | Child | Core feature — track chores and progress over time | Yes |
| CocoBucks point balances | Child | Core feature — reward and spending system | Yes |
| Reward redemption history | Child | Track rewards earned and redeemed | Yes |
| Device push token (FCM) | Device | Push notifications for approvals and awards | Yes |
| Crash diagnostic logs & performance metrics | Device | App stability and bug diagnosis (Firebase Crashlytics) | No |
Diagnostic and Crash Data
We collect anonymous crash diagnostic logs and performance metrics (such as device model, iOS version, and stack traces at the point of an unexpected termination) via Firebase Crashlytics to monitor stability and resolve bugs. This diagnostic information uses an anonymous installation ID and is not linked to your account, family data, or user identity.
Data We Do Not Collect
- Precise or approximate location data
- Contacts, calendars, or health data
- Browsing history or cross-app activity
- Payment or financial information (there are no in-app purchases)
- Biometric data
Tracking
CocoBucks does not track users across third-party apps or websites. We do not use advertising IDs (IDFA/GAID) and do not share data with ad networks.
4. How We Use Your Data
Data is used exclusively to provide the CocoBucks service:
- Authenticate guardians and manage family accounts
- Display tasks, balances, and history to the correct family members
- Deliver push notifications for task approvals and CocoBucks awards
- Allow guardians to review task-proof photographs
- Personalise dashboards with names and avatars
We do not use your data for advertising, profiling, or sale to third parties.
5. Children's Privacy (COPPA)
CocoBucks stores data about children as part of its core function. We handle this data in accordance with COPPA:
- Only a parent or guardian (18+) may create a CocoBucks account and add child profiles.
- Children do not create their own accounts or provide their own data independently.
- Task-proof photographs uploaded by children are stored in Firebase Storage with access restricted to the family account; they are not publicly accessible.
- We do not share children's data with third parties for advertising or analytics.
- Guardians may delete any child profile and all associated data at any time from the app.
Inactive Accounts & Data Deletion
Inactive child sign-in credentials are removed after 90 days of inactivity. Guardians may delete a child profile and all associated data (tasks, points, photos, history) at any time from the app or by contacting privacy@cocobucks.app.
6. Where We Store Your Data
Data is stored in Google Cloud services (Firebase/Firestore/Cloud Storage) in the United States. All data in transit is encrypted using TLS. Firebase Storage and Firestore data is encrypted at rest by Google.
Our security rules deny all direct client access to Firestore — all reads and writes go through our backend API, which enforces Firebase Auth token validation on every request.
7. Data Sharing
We do not sell, rent, or share your personal data with third parties for their own purposes. Data is shared only with:
- Google Firebase — for hosting, authentication, storage, push notifications, and anonymous crash diagnostic collection (Firebase Crashlytics) (as a data processor on our behalf).
- Google Cloud Run — the server infrastructure that runs our API.
Both are governed by Google's privacy policy and Data Processing Addendum.
8. Your Rights and Choices
As a guardian, you may:
- Access all data stored for your family by using the app.
- Correct any information by editing profiles or task records.
- Delete individual child profiles (and all associated data) from the app at any time.
- Delete your account and all family data from the app: open Settings → Danger Zone to remove your own guardian account or delete the entire family and all its data. Deletion is immediate and cannot be undone. If you cannot access the app, contact privacy@cocobucks.app and we will process the request within 30 days.
9. Data Retention
- Guardian accounts: retained until you request deletion.
- Child sign-in credentials: removed after 90 days of inactivity.
- Child profiles & associated data: retained until guardian deletion from the app or upon account deletion request.
- Task-proof photographs: retained as part of the task record; deleted when the task or profile is deleted.
10. Changes to This Policy
We may update this policy as the app evolves. Material changes will be communicated via the app or by email to the guardian account's registered address. The "Last updated" date at the top reflects the most recent revision.
11. Contact
Questions or deletion requests: privacy@cocobucks.app