Tuppence is a family money-education app operated by Mishmapps LLC (“Tuppence,” “we,” “us”). This policy explains what we collect, why, and the choices you have. It applies to the Tuppence iOS app and our website.
The short version
- Parents create and control everything. Kids can only use Tuppence through a profile their parent sets up.
- We collect the minimum needed to run the app: account info from parents, and a first name, birth month/year, avatar, chore photos, and activity history for each child profile.
- Chore photos stay private to your family. They are never public, never used for ads or AI training, and are deleted on a schedule.
- We never sell personal information, never show ads, and never share children's information with third parties for marketing. There is nothing like that in the app.
- We do measure how app features are used, in aggregate, to improve Tuppence, but we never use your child's activity to profile them or to make the app more time-consuming on purpose.
- You can see, export, or delete your family's data anytime, in the app or by emailing us.
1. Information we collect
From parents (account holders):
- Name, email address, and sign-in credentials (or your Apple ID identifier if you use Sign in with Apple)
- Subscription status and purchase history. Payments are processed by Apple, so we never see your card number.
- Family settings: allowance amounts, jar splits, interest and loan rules, charity list
- Communications you send us (feedback, support requests)
About children (entered by the parent, or generated as the child uses the app):
- First name (or nickname), birth month and year, and avatar (emoji + color), entered by you when creating the profile. Birth month and year are used only to set which age-appropriate features a child can access; we do not store the day of birth.
- Chore photos taken by your child as proof of completed chores. Photos are captured in the app and processed to remove embedded metadata, including any location data, before they reach our servers.
- In-app activity: chores completed, jar balances, transactions, wishes, badges, streaks
- Device pairing information: a pairing code, device identifier, and push notification token for the child's device
We do not collect from children: email addresses, phone numbers, precise location, contacts, browsing history, or any government identifiers. Children under 13 cannot type free-text into the app; their interactions are limited to taps and selections.
From others you invite (if applicable): If you invite another caregiver (for example, a second parent or guardian) to your family account, we collect that person's name and email to set up their access. We collect this only to enable the access you requested.
Automatically (to operate and improve the app):
- On parent-facing screens, including the sign-up screens before you create an account, we use PostHog for product analytics and error tracking: app version, device model, iOS version, feature-usage events, and crash/error reports.
- On child-facing screens, we collect feature-usage events (for example, which features are opened or completed) together with crash and error diagnostics, using a device identifier. This is done only to keep the app working and to understand, in aggregate, how features are used so we can improve them (what COPPA calls support for internal operations). We do not use this data to build a profile of your child, to show advertising, to personalize the app in order to increase your child's time in it, or for any purpose beyond running and improving the app, and we never sell it or share it for others' purposes. This child-screen event data is anonymous (tied only to a random device identifier, never to your child's name or contact information), and we keep it only as long as reasonably necessary to operate and improve the app; only the de-identified aggregate trends we derive from it are kept longer. You can have it deleted at any time by deleting the child's profile or your account, or by asking us. Session recording and indiscriminate auto-capture are turned off on child-facing screens. We record only specific, named events, never screen contents.
2. How we use information
We use information to: operate the app (sync your family's data across devices, deliver notifications, process subscriptions); review and store chore photos for your approval; provide support; understand how families use features, in aggregate, so we can improve the app; secure the Service and prevent abuse; and comply with law. We do not use personal information for third-party advertising, and we do not use children's personal information for any marketing, profiling, personalization designed to increase time in the app, or AI model training.
3. Children's Privacy Notice (COPPA)
This section is a standalone notice of our practices for children under 13, as required by the Children's Online Privacy Protection Act (COPPA). It supplements the rest of this policy; where the two overlap, this section governs for children's data. Tuppence is built for children ages 5–18 to use under a parent's supervision.
a. What we collect from children.
Parents enter a child's first name (or nickname), birth month and year, and avatar. (Birth month and year are used only to set age-appropriate features; we do not store the day of birth.) From the child's paired device, we collect: chore-proof photos the child takes (captured in-app and stripped of embedded metadata, including location, before storage); in-app activity (chores completed, jar balances, transactions, wishes, badges, streaks); and device pairing information (a pairing code, device identifier, and push notification token). We collect only what is reasonably necessary for the child to use the app, and we never condition a child's use of Tuppence on providing more than that. We do not collect from children: email, phone number, precise location, contacts, browsing history, or government identifiers. Children under 13 cannot type free-text into the app. A child profile that is never paired to a device collects nothing from the child; in that mode, every detail is entered by the parent.
b. How we use it.
Solely to run the app for your family and to improve it: saving the child's progress, syncing across your family's devices, holding chore photos for your review, sending activity notifications, and (using feature-usage and diagnostic data collected on child screens) keeping the app working and understanding in aggregate how features are used so we can make them better. This falls under COPPA's support-for-internal-operations exception. We never use a child's information to build a profile of them, for advertising, marketing, to personalize the app in order to increase their time in it, or for AI model training, and we never sell it. Child-screen event data is anonymous (tied only to a random device identifier, never to your child's name or contact information), and is kept only as long as reasonably necessary to operate and improve the app; only de-identified aggregate trends are retained longer. You can have a child's event data deleted at any time by deleting the profile, deleting your account, or asking us.
c. How we disclose it.
We do not sell, rent, or share children's personal information with third parties for their own purposes. The only entities that touch it are the service providers in Section 4, who process it strictly on our instructions to operate the app and may not use it for anything else. We do not disclose children's information for advertising, and we will not share it with any third party for an independent purpose without first obtaining your separate consent, as the amended COPPA Rule requires.
d. Parental consent, review, and revocation.
Only a verified parent account holder can create a child profile. Before the first child profile is created, we give you a direct notice of these practices and obtain your verifiable consent (through the subscription transaction confirmed by Apple, together with a consent step and a copy of this notice emailed to you). You may at any time: review everything collected about your child (it is all visible in your parent dashboard), delete it (remove a photo, a child profile, or your whole account in Settings), and refuse further collection (unpair the child's device or delete the profile). You can also exercise any of these rights by emailing legal@tuppenceapp.com; we will verify you are the account parent before acting. If we ever materially change how we handle children's information, we will notify you and obtain new consent before the change applies to your child's data.
e. Operator.
All children's data described here is collected and maintained by Mishmapps LLC (contact details in Section 9). We do not permit any third-party operator to collect personal information from children through Tuppence.
4. Service providers
We share personal information only with service providers who process it for us, under contracts limiting their use to providing services to Tuppence:
- Supabase: database and file hosting (U.S. data centers). All family data, including chore photos, is stored here.
- Apple: payment processing, Sign in with Apple, and push notification delivery (APNs). Push notifications sent to a parent's device may include the child's first name and a short activity description (for example, “Sara wants $3.50 from Spend,” or “Sara finished all her quests today!”) so the parent can act without opening the app; Apple processes these only to deliver the notification. These payloads never include a last name, photo, contact information, precise location, or financial-account data.
- RevenueCat: subscription management, tied to your (the parent's) account. If you request a refund from Apple, RevenueCat shares limited information about your subscription's delivery and use with Apple to help resolve the request, as described in our Terms of Service.
- PostHog: analytics and error tracking, scoped as described in Section 1.
- Resend: email delivery (U.S.). Sends account email on our behalf: sign-in codes, address-change confirmations and security receipts, the children's privacy notice, and family invitations. These messages may include a parent's name and email address, and in one setup reminder a child's first name. Resend processes them only to deliver the message.
We may also disclose information if required by law or to protect rights and safety, and in a merger or acquisition (in which case this policy's protections would continue to apply to previously collected children's data, or we would obtain new consent).
We do not sell personal information, and we have not sold it. No third-party advertising or cross-app tracking technologies are present in the app.
5. Data retention
- Chore photos: deleted from our servers when you review them (approve or send back). If a photo is never reviewed, it is automatically deleted after 7 days. Photos are also deleted immediately when you delete the photo, the child profile, or your account.
- Child profiles: when you remove a child profile, it is recoverable for 90 days, then permanently deleted, including all associated photos, transactions, and activity history.
- Family accounts: when you delete your account, all family data is permanently deleted within 90 days, except minimal records we must keep for legal or accounting purposes (which never include children's personal information beyond what the law requires).
- Inactive accounts: if your family stops using Tuppence entirely, we delete the account and all family data after 12 months of inactivity. We email you a notice at least 30 days before that happens, and simply opening the app resets the clock. Families with an active subscription are never treated as inactive.
- Backups: secure backups may briefly retain copies of deleted data, which roll off on a fixed schedule (within 30 days) and are subject to the same protections as live data. We don't restore deleted data from backups except to recover from a system failure.
- We retain children's personal information only as long as reasonably necessary to provide the Service, and never indefinitely. Our internal written retention policy governs all categories of data we hold.
6. Security
Data is encrypted in transit and at rest. Access to family data is restricted by row-level security so each family can only reach its own records. Changing your sign-in email requires confirmation from both your current and new addresses, and we send a security notice to the old address, which protects your account against takeover. Chore photo storage is access-controlled, so photos are not publicly addressable. We maintain a written information security program covering risk assessment, access controls, and incident response. No system is perfectly secure, but we design for the sensitivity of the data we hold. In the event of a data breach affecting your family's personal information, we will notify you and any authorities required by law without undue delay.
7. Your choices and rights
- Access and portability: your parent dashboard shows your family's data; you can request an export at legal@tuppenceapp.com.
- Correction and deletion: edit or delete profiles, photos, and settings in the app, or delete your entire account in Settings → Account.
- Push notifications: controlled in iOS Settings or in-app.
- Account security: change your sign-in email or add a backup sign-in method (Sign in with Apple) anytime in Settings.
- Response time: we aim to respond to privacy requests within 30 days. If we need longer because a request is complex, we'll let you know.
- State rights: depending on where you live, you may have additional rights under state privacy laws (e.g., Texas, California). We honor access, deletion, and correction requests from all U.S. users regardless of state. We do not sell or share personal information as those terms are defined under California law.
8. Changes
If we make material changes, especially any change to how we handle children's information, we will notify parents directly (in-app and by email) and obtain new consent where COPPA requires it before the change applies to children's data.
9. Contact us
415-448-6868 · legal@tuppenceapp.com