Privacy Policy
This policy covers the Proud Jar app for parents, the Proud Jar Kids app for children, and the Proud Jar service that keeps them in sync. Proud Jar is operated by AppXLab, an independent software studio run by Said Aazzou, Casablanca, Morocco (“we”). Contact us about privacy at privacy@appxlab.io.
What we collect and why
| Data | Where it comes from | Why |
|---|---|---|
| Parent email address, and your name if you give it (or Apple / Google share it) | Sign in with email code, Apple or Google | To sign you in and identify your account |
| Children’s first names and birth years | Entered by a parent | To show each child their own tasks and suggest age-appropriate ones |
| Household membership and roles | Created when you set up or join a household | To decide who can see and change what |
| Tasks, notes, rewards, decisions, tokens and ledger history | Created by parents and children in the apps | The core service |
| Screen-time sessions: minutes bought with tokens, when, and the number of apps behind the gate | Proud Jar Kids on iPhone | To run the token-for-screen-time economy on supported iPhones. We never learn which apps are shielded or used; Apple gives the app only sealed references. |
| Photo proofs (optional, with parent consent) | Proud Jar Kids camera | So a parent can check a task. Encrypted on the child’s phone before upload; only your approved devices hold the keys. |
| Device and installation identifiers, push notification tokens, device public keys | Each app | Pairing, device trust, sync notifications and parent alerts |
| Free-trial check: on iPhone, a one-time Apple DeviceCheck token (Apple keeps a single “trial used” flag for the phone; we store nothing about the device); on Android, a one-way hash of the app’s device identifier, kept only as a further keyed hash | The parent app, once, when a new family starts its free trial | To give each family one free Household trial and prevent repeated trials. Never used for advertising, tracking or anything else. |
| Plan status, free-trial dates and App Store transaction identifiers | Our service, and Apple when a parent subscribes on iPhone | To give your household the Household plan. We never receive your payment card details. |
| Optional parent-app usage statistics (off unless you turn them on) | Proud Jar parent app on iOS only | Which screens are used and whether a task was approved, never names, photos or balances, and not linked to your account |
| Security and operations logs (request time, path, error codes; IP addresses only as a keyed hash for rate limiting) | Our servers | Keeping the service secure and working |
We do not collect location, contacts, messages, browsing history or advertising identifiers, and we do not sell or share personal data for advertising. The kids’ apps contain no analytics or advertising code. Android Kids includes Firebase Cloud Messaging for authenticated family synchronization. Android does not collect installed-app inventory or app-usage measurements and does not provide app blocking in this version. Timed task proofs are included.
Our website
proudjar.com and proudjar.app count page views and taps on the download buttons, with the page, the store button, your browser’s language and a random session number held only in memory for the visit. This goes to the same self-hosted Aptabase server. There are no cookies, no advertising, no fingerprinting and nothing stored on your device, and it is turned off when your browser sends Do Not Track.
Children
Proud Jar Kids is set up by a parent, who pairs the child’s phone with the household. Children use an anonymous installation session connected by a parent, not an email or social sign-in account. They have no subscription checkout. External help links and connection settings are behind a parent check. A parent can see and delete their children’s information at any time. A child’s information is added by, and stays under the control of, a parent: we only collect it after a parent has created the household and paired the child’s phone. In the European Economic Area and the UK we process it to provide the service the parent asked for, and optional photo proofs only after the parent turns them on. In the United States, Proud Jar relies on the parent setting up and controlling every child profile, and a parent can review, change or delete their child’s information at any time, or ask us to.
Photos
Photo proofs are encrypted on the child’s phone and can be opened only on devices the household has approved. Photos expire after the period your household chooses (7, 14, 30, 90 or 365 days; 30 by default). Connected viewers recheck access and clear it on expiry, revocation or backgrounding. Previously downloaded information on an offline device cannot be remotely recalled; screenshots or other copies cannot be recalled. After expiry, new server access is refused; erasing the stored copy is retried until it succeeds, which can take longer if storage is briefly unavailable. Photos are never added to a photo library. If every approved device and your recovery kit are lost, earlier photos cannot be opened by anyone, including us.
Who processes data for us
| Provider | Purpose |
|---|---|
| OVHcloud, Roubaix, France (EU) | Runs the Proud Jar API and database |
| Amazon Web Services (Amazon S3), Frankfurt, Germany (EU) | Stores encrypted photo proofs and encrypted backups |
| Resend, which sends through Amazon Simple Email Service | Sends sign-in codes |
| Apple | Sign in with Apple, push notifications, App Store purchases, Screen Time on the child’s device |
| Sign in with Google if you choose it; Firebase Cloud Messaging for Android synchronization and optional parent alerts | |
| Aptabase analytics, self-hosted by AppXLab at insights.appxlab.link | Optional iOS parent-app usage statistics, and anonymous statistics for this website; neither Android app includes this SDK |
How long we keep it
- Photo proofs: until the household’s retention period ends, then erased.
- Household records: while the household exists. Deleting the household erases its records, photos and pairing codes.
- Accounts: until you delete your account. Deleting it also revokes a linked Sign in with Apple authorisation.
- Encrypted backups: kept for 30 days to recover from failures; a restored backup re-applies deletions made after it was taken before the service reopens.
- Free-trial records: one keyed hash per parent account and per Android phone, with no email, device identifier or family data, kept after household or account deletion so the same phone or account cannot start another free trial.
- Subscription records: minimal transaction identifiers and opaque purchase-binding records may be kept after household deletion to prevent a subscription being attached twice. They are kept only while needed for that, and for up to 7 years where tax or accounting law requires it.
Your choices and rights
You can review your family’s data in the app, ask us for a copy of it, turn off analytics and notifications, shorten photo retention, remove devices and co-parents, and delete your household (Household → Our Family) or your account (Household → Account & permissions) in the app or as described on Delete your account. Depending on where you live you may have further rights, for example to access, correct or object to processing, and to complain to a data protection authority. Contact privacy@appxlab.io.
Security
Traffic is encrypted in transit. iPhone sign-in credentials use Keychain. Android local credentials and records are encrypted using Android Keystore; Android app backups are disabled. Photo-device private keys require supported secure hardware. Photos are end-to-end encrypted between approved family devices. No system is perfectly secure; tell us about any concern at support@appxlab.io.
Changes
We will post changes here and, for significant changes, tell you in the app before they apply.