Privacy Policy
Effective Date: March 1, 2026
1. Introduction
Clash of Chores ("we", "our", or "the app") is a family chore tracking application. This Privacy Policy explains how we collect, use, and protect information when you use our app at clashofchores.com or through any associated mobile application.
We are committed to protecting the privacy of all our users, including children. If you have questions about this policy, contact us at support@clashofchores.com.
2. Information We Collect
Account Information
- Parent accounts: Email address and password (managed by Firebase Authentication)
- Family members: First name, avatar selection, and role (parent/kid)
- Kid login: A numeric PIN (stored as a one-way hash — we cannot see the actual PIN)
App Usage Data
- Chore names, descriptions, point values, and completion status
- Reward names and point costs
- XP (experience points) earned and activity history within your family
- Photo proof of chore completion (stored in Firebase Storage, accessible only to your family)
Device & Technical Data
- Push notification tokens (Firebase Cloud Messaging) to deliver notifications you opt into
- Browser type and basic device info for app functionality
- Local storage preferences (theme, tutorial completion status)
Payment Information
- If you subscribe to a premium plan, payment is processed by Stripe. We do not store credit card numbers. We receive only a confirmation of payment status from Stripe.
3. How We Use Your Information
We use the information collected to:
- Provide the chore tracking, XP, rewards, and leaderboard features
- Authenticate parent and kid accounts securely
- Send push notifications (chore reminders, approvals, family updates) that you opt into
- Process premium subscription payments via Stripe
- Improve the app based on usage patterns
We do not use your data for advertising. We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Children's Privacy
Clash of Chores is designed for families. Children use the app under a parent's supervision:
- Kid accounts are created and managed by a parent — kids cannot create accounts independently
- Kids log in using a family code and PIN set by their parent
- We collect only the child's first name and avatar choice — no email, phone number, or other personal contact info
- Photo proof uploads are visible only to members of the same family
- Parents can view, edit, or delete their child's data at any time from the Settings tab
- Parents can delete the entire family account, which removes all associated children's data
We comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 without parental consent. The parent account holder provides consent by creating and managing their child's profile.
5. Data Storage & Security
- All data is stored in Google Firebase (Firestore, Authentication, Cloud Storage) with encryption in transit and at rest
- Kid PINs are hashed with SHA-256 and a unique per-member salt — we cannot reverse them
- Firestore security rules restrict data access to authenticated family members only
- PIN login is rate-limited (5 attempts, then 15-minute lockout) to prevent brute force attacks
- Password reset requests are rate-limited (3 per hour per email address)
- Stripe payment webhooks use idempotency checks to prevent duplicate processing
6. Third-Party Services
We use the following third-party services:
- Firebase (Google) — Authentication, database, file storage, hosting, push notifications, and cloud functions. Firebase Privacy Policy
- Stripe — Payment processing for premium subscriptions. Stripe Privacy Policy
- Google Fonts — Font delivery (Fredoka, Nunito). Google Fonts Privacy
We do not use any analytics, advertising, or tracking SDKs.
7. Data Retention & Deletion
- Your data is retained as long as your account is active
- You can delete individual family members, chores, or rewards at any time from within the app
- You can delete your entire account from Settings, which permanently removes all your data including family, members, chores, rewards, history, and authentication records
- Account deletion is processed immediately and is irreversible
- Inactive push notification tokens are automatically cleaned up
8. Your Rights
You have the right to:
- Access your data — all your family data is visible within the app
- Correct your data — edit names, chores, rewards, and settings at any time
- Delete your data — remove individual items or delete your entire account from Settings
- Export your data — contact us and we will provide your data in a portable format
- Opt out of push notifications — disable from your device settings or the app's notification preferences
For EU/EEA users: we process data based on legitimate interest (providing the service you signed up for) and consent (push notifications, optional photo uploads). You may exercise your GDPR rights by contacting us at the email below.
9. Cookies & Local Storage
Clash of Chores uses browser local storage for session management, user preferences, and tutorial completion tracking. The app uses a service worker for offline caching of the app shell. We do not use tracking cookies or third-party advertising cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the app after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
Email: support@clashofchores.com