Privacy

ChoreStar Privacy Policy

Last updated: July 13, 2026

ChoreStar is a family chore and points tracker. It is designed for families and is a child-directed service, so we keep what we collect to the minimum needed to run the app — and we never sell your data or your children's data.

This policy explains, in plain language, what information ChoreStar collects, how we use it, who we share it with, and the choices you have. If anything here is unclear, email us at accounts@cloudmigrationconsulting.net.

📋 Information we collect

Parent account

When a parent creates an account, we collect:

  • Your email address — used to sign in, verify your account, and contact you about your account.
  • Your name — shown in the app.
  • Your password, which we store only as a one-way salted hash (PBKDF2). We never store your password in plain text and cannot see it.
  • A short email verification code we email you at sign-up to confirm your address. It is deleted once used.

Children's profiles

Children do not create their own accounts and do not provide any email address or password. A parent sets up each child's profile inside their family. For each child, the parent may enter:

  • A name (or nickname) the parent chooses.
  • An optional age.
  • An avatar (an emoji picture).

A child signs in by scanning a QR code generated by the app. The QR code contains a login token tied to that child's profile — there is no email or password for a child.

Family activity

To make the app work, we store the things you create and do inside it:

  • Your family (name, points icon).
  • Chores (titles, descriptions, point values, schedules, who they're assigned to).
  • Chore completions and approvals, and the points earned from them.
  • Rewards you create and the redemptions kids make.
  • Chore suggestions kids propose for a parent to approve.
  • The points history (the record of points earned and spent).

Technical

  • Session tokens that keep you (or a child) signed in. Sessions last about 30 days and can be revoked.

ChoreStar does not use any third-party analytics. The free tier shows non-personalized, child-safe ads — see "Advertising" below. We do not collect location, contacts, or photos. The ad service may use a device advertising identifier solely to deliver and measure non-personalized ads, never to build a profile of you or your child.

⚙️ How we use your information

We use the information above only to provide and operate ChoreStar:

  • To sign you in and keep your account secure (authentication and session management).
  • To verify your email address at sign-up.
  • To run the core features: chores, approvals, points, rewards, redemptions, history, and chore suggestions.
  • To respond to you when you contact us for support or to request deletion.

We do not sell your data, and we do not sell children's data. We do not use your or your children's information for behavioral or targeted advertising.

🧒 Children's privacy (COPPA)

ChoreStar is a child-directed service, and we take children's privacy seriously.

  • Parent-managed accounts. Only a parent creates an account, sets up the family, and adds each child's profile. Children cannot sign up on their own.
  • Parental consent. By creating the family and adding a child's profile, the parent provides consent for the limited information described above (a name/nickname, optional age, and avatar the parent enters).
  • Minimal data from children. Children do not enter an email, password, or other personal contact information. They sign in by scanning a QR code.
  • Parental control. Parents can review, edit, or delete their children's profiles and data at any time, and can delete the entire family and account (see "Data retention and deletion").

If you believe a child has provided us information without a parent's involvement, contact us at accounts@cloudmigrationconsulting.net and we will delete it.

🤝 How we share information

We do not sell or rent your information. We share it only with a small set of service providers that are essential to running the app, and only so they can perform their function for us:

  • Neon — database hosting (stores your account and family data; hosted in the United States).
  • Render — application/server hosting that runs the ChoreStar service.
  • Resend — email delivery, used to send the email verification code at sign-up.

We may also disclose information if required by law, or to protect the rights, safety, and security of ChoreStar and its users.

📣 Advertising

The free tier of ChoreStar shows ads, served through Google AdMob (in the app) and Google AdSense (on the web app, where enabled). Because ChoreStar is child-directed, every ad request is tagged child-directed and for users under the age of consent, capped at a maximum content rating of "G", and served as non-personalized — no interest-based targeting, profiling, or remarketing of you or your children. A family with a paid/premium upgrade sees no ads at all, for every member including kids.

Ad delivery may involve the ad network briefly accessing a device advertising identifier purely to serve and measure the (non-personalized) ad and to prevent fraud — never to build a behavioral profile. We do not otherwise use any third-party analytics.

🗑️ Data retention and deletion

We keep your information for as long as your account is active so the app works for you. You can have your account and all associated data permanently deleted at any time, in either of these ways:

  • In the app (self-serve): go to Settings → Delete my account. We email a 6-digit confirmation code to your account email; entering it in the app completes the deletion immediately.
  • By email: email accounts@cloudmigrationconsulting.net from (or referencing) the account email and we will delete it for you.

Either way, deletion is permanent and removes everything tied to the account, including:

  • The parent account and your hashed password.
  • Your family and every child profile in it.
  • All chores, completions, rewards, redemptions, and points history.
  • Kid chore suggestions, login sessions, and any pending email verification code.

Once deleted, this data cannot be recovered.

🔒 Security

We protect your information with industry-standard safeguards:

  • Passwords are stored only as one-way salted hashes (PBKDF2) — never in plain text.
  • All traffic between the app and our servers is encrypted in transit over HTTPS.
  • Sign-in uses bearer-token sessions that expire and can be revoked on our servers.

No method of storage or transmission is 100% secure, but we work to protect your information and limit what we collect.

🔄 Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above. Please review this page periodically.

✉️ Contact us

Questions about this policy or your data? Email us at accounts@cloudmigrationconsulting.net and we'll be glad to help.