Privacy · Draft

Privacy

Here’s how EarnSparky handles information. Each section has a short summary in plain language alongside the full explanation.

1. Who we are

EarnSparky is an app where children practise and Parents manage learning activities, screen-time rewards and Parent Reports.

Operator: [Legal operator name and registered trading name]
KVK: [Registration number]

For privacy questions, contact hello@earnsparky.app.

2. Your Family, accounts and paired devices

Family”, “Parent”, “Child” and “Device” are terms we use to describe how the app is organized, not real names. A Family account brings together the people and paired devices using EarnSparky, under the supervision of a Parent or another authorized caregiver.

Family names, Parents’ and children’s first and last names, and ages are not stored on our servers or sent to the AI provider. Any such details entered in the app stay on paired devices, protected by local encryption.

The only personal contact detail we store is the Parent’s email address, used for account authentication and responding to requests. We also store technical account and device connections, learning results and reports needed to provide the service; these records do not contain those names or ages.

3. Learning activities

When a child practises, we store their answers, activity results and learning history. We use this information to evaluate answers, provide learning activities, process screen-time rewards and give Parents insight into practice.

4. Personalized practice

EarnSparky uses learning results to adjust the difficulty of future activities. As a child answers more questions correctly, practice can become more challenging.

5. AI-generated Parent Reports

We use artificial intelligence (AI) to turn recent learning activities into short, actionable summaries for Parents. The service receives relevant learning statistics and evidence about practice questions and answers. It does not receive names, ages, email addresses or other directly identifying personal details.

The summary is saved as a Parent Report and shown to the Parent. It may contain mistakes and is not a diagnosis or a replacement for professional educational advice.

6. Screen time and device status

We process configured screen-time rules and relevant status information from paired Companion devices. This supports rewards and restrictions and helps check whether the required device settings are working.

7. Subscriptions

Apple processes App Store purchases. Through RevenueCat, we process subscription products, transaction identifiers, subscription status and access periods. This information is associated with the Family account and determines which features and how many Learning Programs are available.

We do not receive payment-card or bank-account details from Apple. RevenueCat also processes subscription information for subscription and revenue reporting.

8. Notifications

We use an installation identifier and notification token to deliver push notifications to the correct device through Firebase Cloud Messaging, for example when a new report is available.

9. Our legal bases for processing

This draft proposes the following purpose-specific bases, subject to review before the policy takes effect:

  • Parent accounts and subscriptions: performance of our agreement with the Parent, where processing is necessary to provide and manage the requested service.
  • Profile-linked learning, personalized practice and Parent Reports: our legitimate interests in providing a useful Parent-managed learning service and giving Parents insight into practice. This requires a necessity and balancing assessment that gives particular weight to children’s rights. Keeping names and ages out of server records and AI requests is one safeguard, not an exemption from data-protection law.
  • Security, device operation and support: legitimate interests in protecting accounts, operating the service reliably and responding to requests, or performance of the Parent’s agreement where the processing is necessary for that service.
  • Legally required records: compliance with applicable legal obligations, such as accounting requirements.

You can object to processing based on legitimate interests by emailing hello@earnsparky.app. We will assess your request and weigh your privacy interests against our reasons for processing, as required by applicable law. Where processing relies on your consent, you can withdraw that consent through the same email address. We will then stop the processing covered by that consent. Withdrawal does not affect the lawfulness of processing carried out before it was withdrawn. If we stop processing information that is necessary for a particular feature or for providing the service, that feature or the app may no longer work for your account. We will explain any such consequences when handling your request.

10. Our service providers

We work with specialist providers:

  • Supabase: sign-in, database and backend processing.
  • RevenueCat: subscription management and reporting.
  • Firebase Cloud Messaging: push notifications.
  • OpenAI: generating Parent Reports.
  • Cloudflare: hosting and delivering our website.
  • Apple: app distribution and App Store purchases.

Providers receive the information needed for their role. Some also process information for their own purposes, such as payment administration, security or service reporting, under their applicable terms and privacy notices.

OpenAI’s published API policy states that API inputs and outputs are not used for model training by default, unless the customer opts in. We configure report requests with response storage disabled. This is not a guarantee of zero retention: OpenAI’s standard abuse-monitoring logs may retain content for up to 30 days, with longer retention in the circumstances described in its policy.

Providers may process information outside the European Economic Area. Such transfers require applicable safeguards, such as an adequacy decision or Standard Contractual Clauses, and appropriate processing agreements where required. We do not claim that all processing takes place in the EU. Contact us for information about the arrangements applicable to your data.

Provider information: Supabase, RevenueCat, Firebase, OpenAI API data controls, Cloudflare and Apple.

11. Retention and deletion

Cancelling or downgrading a subscription does not automatically delete programs, associated learning activities or reports. Programs beyond a lower plan’s limit remain stored; a higher plan can make them available again.

Cancelling a subscription and requesting deletion of information are separate actions.

One-year inactive-account policy: we intend to retain the Family account, its program assignments, learning history and Parent Reports while the Family uses the service or has an active subscription or access grant. After that, the retention period is one year from the later of the Family’s last activity or the end of its subscription/access grant. This allows a Family to return without immediately losing its history. At the end of that period, these records are to be deleted or irreversibly anonymized. Background technical messages alone do not count as Family activity.

You can request account and associated learning-data deletion earlier by emailing hello@earnsparky.app. We may need to verify that you are the Parent authorized to act for the Family. We will explain any records that must be retained and the reason. Account deletion does not cancel an Apple subscription; manage that separately through Apple.

Notification tokens are retained while needed to deliver notifications and removed when no longer needed. Technical logs and support correspondence are retained only as necessary for security, troubleshooting and handling requests. Records required for legal obligations or a specific dispute may need to be retained longer, with use restricted to that purpose.

Deleted information may remain in restricted backups until those copies expire under the applicable backup schedule. Provider-controlled security and transaction records follow the provider’s applicable retention rules and legal obligations; the one-year rule is not a promise that every provider record is erased on the same date.

12. Security

We use technical access controls to restrict information to authorized accounts and processes. Children’s identity information is protected locally using encryption. No system can guarantee complete security.

13. Your privacy rights

Depending on the circumstances, you may request access, correction, deletion, restriction or portability of personal data. You may object to certain processing. Where we rely on consent, you can withdraw it.

We may ask for information to verify your authority to make a request. We normally respond within one month. If a permitted extension is necessary, we will explain it within that month.

You can also complain to the Dutch data-protection authority, the Autoriteit Persoonsgegevens, or another competent supervisory authority.

Email hello@earnsparky.app with your request and enough account information for us to locate the relevant Family. Tell us if you are acting on behalf of a child. Do not send passwords or identification documents unless we explain why additional verification is necessary and how to provide it safely.

14. Our website

Our static website contains no advertising, analytics scripts or forms of our own. Cloudflare processes connection information to deliver and secure the website.

Connection information can include an IP address, browser information and technical request details. Cloudflare may use security technologies, including cookies where applicable to its protections. Its processing is described in the Cloudflare Privacy Policy. We do not use this website to track visitors across other companies’ websites for advertising.

15. Changes and questions

We update this policy when our practices change and notify users of important changes where required. A policy update does not itself authorize a new use of information without an appropriate legal basis.

For questions, email hello@earnsparky.app. This version remains a draft and has no effective date until the operator details, review and implementation prerequisites are resolved.