EarnSprout ("we," "us," or "our") operates the EarnSprout mobile application and website at https://earnsprouts.com (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described here.
1. Who We Are
EarnSprout is a Christian family platform designed for parents and their children. We are committed to maintaining the privacy of every user, especially minors. Questions about this policy may be sent to privacy@earnsprouts.com.
2. Children's Privacy (COPPA)
EarnSprout is designed for use by parents on behalf of their children. Children under 13 do not create accounts directly. Parents (account holders) create child profiles within the app. We do not knowingly collect personal information directly from children under 13 without verifiable parental consent.
Child profiles contain only: a first name or nickname, an optional avatar/photo, and performance data (chore completions, points, badges). This information is tied to the parent's account and is never shared with third parties for advertising.
If you believe we have inadvertently collected personal information from a child under 13 without consent, please contact us at privacy@earnsprouts.com and we will delete it promptly.
3. Information We Collect
a) Information You Provide
- Account registration: Name, email address, password (stored hashed), optional family name.
- Child profiles: Child's first name or nickname, optional avatar photo.
- Chores & routines: Titles, descriptions, completion photos you upload.
- Faith content: Prayer entries and gratitude notes you voluntarily write.
- Payment information: Handled entirely by Stripe. We store only your Stripe customer ID and subscription status — never raw card numbers.
- Referral codes: If you share or use a referral link.
- Support correspondence: Emails you send to our support address.
b) Information Collected Automatically
- Device identifiers: Push notification token (Expo) for sending approval alerts and reminders.
- Usage data: App interactions (feature usage, screen views) to help us improve the product.
- Crash & error logs: Stack traces and error reports (may include device type, OS version) via our error monitoring service.
- Log data: IP addresses, request timestamps, and HTTP response codes retained for security and abuse prevention.
c) Media Uploads
Photos uploaded as chore proof or avatars are stored securely via Cloudinary. We do not use these images for training AI models or for any purpose other than displaying them within your family's account.
4. How We Use Your Information
- Provide and improve the EarnSprout Service.
- Process payments and manage subscriptions through Stripe.
- Send push notifications and email summaries you have opted into.
- Generate weekly family reports and analytics visible only to you.
- Detect fraud, abuse, and unauthorized access.
- Respond to support requests.
- Comply with legal obligations.
We do not sell your personal information. We do not use your data for advertising.
5. Legal Bases for Processing (GDPR)
For users in the European Economic Area, the United Kingdom, and Switzerland, our legal bases are:
- Contract performance: Processing necessary to provide the Service you signed up for.
- Legitimate interests: Security monitoring, fraud prevention, service improvement.
- Consent: Optional email summaries and push notifications (which you can withdraw at any time).
- Legal obligation: Compliance with applicable laws.
6. Sharing Your Information
We share data only as follows:
- Stripe — payment processing. Stripe's privacy policy governs data they collect.
- Cloudinary — media storage for uploaded images.
- Expo (Push Notifications) — to deliver push notifications to your devices.
- Error monitoring provider — stack traces and error logs for debugging.
- Co-parents you invite — when you invite a co-parent or grandparent, they see your family's chore, routine, and child data.
- Legal requirements — if required by law, court order, or to protect our rights and safety.
- Business transfers — in the event of a merger or acquisition, data may transfer to the successor entity.
7. Data Retention
We retain your account data for as long as your account is active. When you delete your account, we delete your personal information within 30 days, except where retention is required by law or for fraud prevention purposes (up to 7 years for financial records). Anonymized, aggregated data may be retained indefinitely for product analytics.
8. Security
We use industry-standard safeguards including HTTPS/TLS for all data in transit, hashed passwords (bcrypt), and environment-variable secrets management. Access to production databases is restricted to authorized personnel. No system is perfectly secure; if you discover a vulnerability, please disclose it responsibly to privacy@earnsprouts.com.
9. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data.
- Port your data to another service.
- Object to or restrict certain processing.
- Withdraw consent for marketing and push notifications at any time.
- Lodge a complaint with a data protection authority.
To exercise any of these rights, email privacy@earnsprouts.com. We will respond within 30 days.
10. Cookies & Tracking
The EarnSprout website uses cookies only for authentication session management (via NextAuth.js) and to remember your preferences. We do not use third-party advertising cookies or cross-site tracking technologies. The mobile app uses secure device storage (Expo SecureStore) rather than browser cookies.
11. International Data Transfers
EarnSprout is operated from the United States. If you are located outside the US, your data will be transferred to and processed in the US. For transfers from the EEA/UK, we rely on Standard Contractual Clauses or other lawful transfer mechanisms with our sub-processors.
12. Changes to This Policy
We may update this policy as our practices evolve. Material changes will be communicated by email to the address on your account or by a prominent notice in the app at least 14 days before taking effect. Continued use after the effective date constitutes acceptance.
13. Contact Us
For privacy-related questions, data requests, or concerns:
EarnSprout Privacy TeamEmail: privacy@earnsprouts.com
Website: https://earnsprouts.com