Privacy at ChorePop
Privacy policy
This policy explains what ChorePop handles, why it is needed, and the choices guardians have. ChorePop is a family ledger, not a bank, and it does not hold or move real money.
Last updated: 6 September 2026
A shorter version for children
Read Privacy for children for a plain-language summary of what ChorePop remembers and how a child can ask a trusted adult for help.
Who is responsible for your data
ChorePop is operated by VEEFIVE LTD. For privacy or data-rights questions, email privacy@chorepop.com. For general help, email support@chorepop.com.
Data ChorePop uses
Depending on how your family uses ChorePop, this can include:
- guardian identity and account details, such as a name, email address, user identifier, sign-in provider and security records;
- family and child display names, guardian relationships, chores, routines, approvals, notes, allowances, buckets, goals and streaks;
- ledger entries for money a guardian holds on a child's behalf, including deposits, withdrawals, balances and currency records;
- subscription status and store transaction identifiers needed to verify access and prevent purchase replay; and
- a ChorePop device identifier, a guardian-chosen device name, cloud session identifiers, approval/revocation times and security checks needed for trial binding, device access, synchronisation and a guardian-visible audit trail;
- non-reversible password and PIN verification records used to let an authorised family sign in on another device without replacing existing sign-in details. Cloud credential records do not contain readable passwords or PINs.
- private safety reports, including the words or item reported, the reporter's explanation, local child or guardian context, the verified guardian cloud identity used to send it, and VEEFIVE LTD's moderation record.
ChorePop does not collect payment-card or bank-account details. Apple or Google handles subscription payment. ChorePop does not ask for a child's age or birthday.
Trial data, Supabase and cloud sync
The 30-day trial ledger stays on its one device except when a child or guardian deliberately sends the private safety-report data described below. Guardian identity, trial status, subscription verification and those deliberate reports use ChorePop's Supabase cloud service. After a verified subscription, an authorised guardian can move the family ledger into secure family cloud sync so the same family can use more than one device.
ChorePop uses cloud access controls to separate each family. It sends data over encrypted HTTPS or secure WebSocket connections. Local app data is protected by the device's operating-system access controls.
Adding a new device requires a code sent to the guardian's verified email address. The code is short-lived, bound to that device and cloud session, and subject to attempt and resend limits. The service stores a one-way proof of the code, not the readable code.
After email approval, the app asks for an existing ChorePop password or PIN. A private server-only verifier checks it and returns only success, failure or temporary lockout; the verifier itself is never downloaded. The new device then derives its own independently salted one-way local verifier from the value entered. Internet is required at every unlock, including during the trial; a local verifier does not provide an offline bypass. Face or fingerprint data and the adult selected for biometric sign-in stay only on that physical device.
Guardians can use Settings → Authorized devices to revoke a device or sign out of all devices, including the current one. The service checks that authorization and the cloud session remain live. The open app also rechecks device access periodically and locks if the check fails. Revocation preserves family data; it does not remotely erase files already stored on a lost device.
Pounds, dollars and exchange rates
A family uses pounds sterling (GBP) or US dollars (USD) for its normal ledger. Other currencies are available only to record overseas gifts or holiday spending. ChorePop fetches a daily public reference-rate set through its own read-only cloud endpoint. The exchange-rate request does not contain family, child or ledger data, and ChorePop does not keep a historical rate archive.
Private safety reports and moderation
A child or guardian can use Report unsafe content to ask VEEFIVE LTD to review unsafe or unkind family-entered content. The report is not shown to family members, and ChorePop does not tell the reported person which local profile submitted it. A verified guardian cloud identity authorises delivery; local child or profile details are supporting context rather than a separate cloud identity.
Authorised VEEFIVE LTD reviewers may dismiss a report, remove or redact text, suspend an account, or lock or delete a family where reasonably necessary for safety, legal compliance or enforcement of the Terms. Moderation decisions are recorded in an operator-only audit trail.
Safety-report evidence is kept separately for up to 180 days so deleting a family cannot erase a pending safety concern. The family link is detached when the family is deleted. ChorePop then deletes or irreversibly anonymises the retained report unless a longer period is required by law or to establish, exercise or defend legal claims.
No behavioural analytics or advertising SDKs
ChorePop does not display advertising, collect behavioural analytics or sell or share app activity for targeted advertising. The production release excludes the Facebook and Meta App Events SDK, Android's advertising-ID permission and comparable in-app advertising attribution code on both Apple and Android devices.
ChorePop therefore does not send Meta app activation, session, screen, purchase or custom events, advertising identifiers, or information about names, accounts, families, children, chores, routines, balances, goals or subscriptions. Advertising campaigns may use aggregate reporting provided outside ChorePop by an app store or advertising platform; ChorePop does not add an in-app SDK or event feed for that reporting.
A future attribution-only design would be considered only if it can be proven not to collect behavioural analytics or child and family data. ChorePop would update this policy and the applicable app-store disclosures before including such a design in a production release.
Biometric sign-in stays with the operating system
Biometrics are optional and available only to one guardian selected as the main adult on each device. Face ID, Touch ID or Android fingerprint matching is performed by the operating system. ChorePop never receives or stores face or fingerprint data. The protected unlock secret remains in the device's OS keychain or keystore, and password or PIN fallback remains available.
Service providers and disclosures
ChorePop uses Supabase for cloud identity, trial and subscription state, and paid-family sync. Apple and Google provide sign-in and subscription services when selected. A transactional email provider delivers device-approval messages to the guardian's verified email address. A reference-rate provider supplies daily exchange-rate data to ChorePop's server. ChorePop does not use an in-app advertising or behavioural-analytics provider.
ChorePop does not sell personal data or children's activity. It may disclose information where required by law, to protect users and the service, or to service providers acting on ChorePop's instructions.
Download, deletion and recovery
A signed-in guardian can use Settings → Privacy & data and choose Download my family data to save an encrypted copy of authorised family data, or choose Delete my family data. Deletion requires a fresh guardian security challenge, immediately revokes family access and starts a 30-day recovery period. A verified guardian can cancel the request during that period; permanent erasure follows when it ends, subject to the bounded safety-report retention explained above.
Trial guardians can also download or securely delete their trial data. See the account and family deletion instructionsfor the in-app steps. ChorePop does not offer a web deletion form.
Your choices and rights
Guardians can correct family records in the app, download authorised family data and request deletion. Depending on UK data-protection law, you may also ask for access, correction, restriction, portability, objection or erasure. Email privacy@chorepop.comso the request can be verified safely. Safety-report access requests are handled carefully so they do not disclose another person's identity or undermine a live safeguarding review.
Children and changes to this policy
Guardians create and manage child accounts and control family data. Children do not use cloud MFA or adult biometrics. ChorePop may update this policy as the app or the law changes; the date at the top will show the latest version.