Privacy Policy
Who this is for
Tidiest is operated by Tidiest LLC ("we", "us"). This Privacy Policy explains what information we collect, why, and your rights as a parent or legal guardian. Tidiest is intended to be set up and controlled by a parent or legal guardian who is at least 18 years old. Children do not have their own accounts and cannot agree to this policy.
Our commitment to children's privacy (COPPA)
Tidiest is designed for households with children, including children under 13, and we comply with the U.S. Children's Online Privacy Protection Act (COPPA). Before we collect a child's nickname/profile information or enable child photo submission, a parent must review the child-data, child-photo, and AI-verification notice and give verifiable consent. Only after that consent may the parent create a child profile with a nickname and optional private non-photo display symbol, and pair the child's device. We collect the minimum information needed to run parent-managed chores, AI-assisted chore verification, parent review, and rewards.
What we collect from the parent
• Identity: Tidiest uses Sign in with Apple for parent accounts. We verify Apple's identity token server-side, store only the stable Apple subject or a protected hash plus minimal email relay metadata when Apple provides it, and issue an opaque Tidiest session token. • Subscription status: your Tidiest Family plan and verified trial, paid, grace, expiry, revocation, and recovery dates. Apple processes payments; we never see your card details. Our Cloudflare Worker verifies an App Store-signed transaction bound to your household before family data is saved or reopened. • Parent-supplied reward codes: if you create a manual-code reward, Tidiest stores the single-use code encrypted with its optional descriptive face value and currency. Tidiest does not sell, purchase, fund, validate, or track the monetary balance of gift cards. • Parent-selected room photos: only when you choose parent room planning. Those images are face-checked, downscaled, stripped of metadata on your device, and sent through our Worker to Amazon Bedrock/Nova Pro. They are discarded after suggestions by default. Before the first reference-enabled save, you can instead choose to keep the complete sanitized single-photo derivative privately linked to the chores saved from that scan so assigned children can use it as a framing reference.
What we collect about a child
• After parental notice and verifiable consent, a child profile UUID, a nickname you choose, such as "Kid 1", and an optional private non-photo display symbol the child may change. • Chore photos the child submits after parental consent, child-profile creation, and pairing. A photo of a child is personal information under COPPA, which is why the camera path stays locked until the parent consent stack is complete. • Chore results: the AI verification result, any parent review or override, and the points earned. • Chore titles, finish rules, reward values, reward menu items, and redemption history that you create for the household. We do not collect a child's real name, email, phone number, precise location, profile photo, public profile, advertising identifier, or tracking identifier. Chore details are not used to build an AI profile of a child, and the private display symbol is not sent to AI providers, public records, or evidence metadata. Photo location metadata (EXIF/GPS) is stripped on the device before a chore photo is uploaded as evidence.
How we use chore photos
A child submission uploads one sanitized evidence image to private R2-compatible object storage through a short-lived URL minted by Tidiest's Cloudflare Worker. The raw photo is never uploaded, the bucket is not public, and parent review uses short-lived authorized download URLs. Evidence metadata, such as evidence ID, opaque storage reference, status, approximate size, and deletion dates, is kept in Tidiest's backend evidence metadata store. If AI verification is enabled, /verify-chore resolves the same sanitized evidence only after household authorization, active Family access, consent, and parent-written rule-hash checks pass, then sends the image and rules transiently to Amazon Nova Pro through Amazon Bedrock only to verify chore completion. Clear passes award the chore's full configured value; clear misses award zero; ambiguous, private, unsafe, or sensitive images require parent review. Optional parent room planning is separate and processes only room photos deliberately selected by the parent.
Third parties we share with
• Apple: Sign in with Apple supports parent identity, and Apple processes App Store subscriptions. Children do not use Sign in with Apple. • Cloudflare Worker, D1, Durable Objects, Queues, R2, and evidence metadata storage: Cloudflare hosts Tidiest's service code for parent room planning, AI chore verification, purchase verification, household authorization, QR/code pairing, evidence signed URLs, redemption, bonus, and ledger signing. D1 stores canonical app rows and Durable Objects serialize household mutations. Sanitized child chore evidence is stored briefly in private R2-compatible object storage. Enabled room references are stored separately in a dedicated private R2 bucket with household-scoped metadata and chore links in D1. Neither bucket has public object URLs, and the Worker never returns object keys. • Amazon Bedrock / Amazon Nova Pro: receives sanitized parent room photos for optional chore planning and, if AI verification is enabled after parental consent, sanitized child chore photos plus parent-authored rules for the limited purpose of chore-completion verification. It does not receive a child's nickname, public profile, or real name from Tidiest. We do not permit Tidiest data to be used for model training, model improvement, child profiling, or unrelated AI use. AWS states that Amazon Bedrock customer prompts and outputs are not used to train the underlying Amazon foundation models unless the AWS customer consents; Bedrock may process inputs and outputs with automated abuse-detection systems. • Resend: sends privacy-minimized 30-day and 7-day recovery warnings. Recovery warnings contain only the deletion date and a recovery/support link, never child names, chores, balances, tracking, or marketing. We do not sell personal information, share it for advertising, or use third-party advertising or tracking SDKs.
Features Tidiest does not provide
Tidiest has no public child profiles, profile pictures, open chat, child messaging, public leaderboards, advertising, behavioral tracking, sale of personal information, face recognition, biometric identification, or child-facing AI/paywall surface. A private display symbol is not a profile picture and is never public.
How long we keep information
We keep each kind of information only as long as it is reasonably necessary, never indefinitely, then delete it. This is our data-retention policy; the same policy is also published in full as a standalone Data Retention Policy. • Chore photos (the review copy): approved evidence is deleted after roughly 72 hours. Rejected or disputed evidence may be retained for up to 30 days unless you delete it sooner. Abandoned or unconfirmed uploads are deleted after 24 hours. That window is deliberate - long enough for you to review a child's work, and no longer. Photos are stored only as private R2-compatible evidence objects and parent review uses short-lived authorized URLs. If AI verification is enabled, the Worker and Bedrock process verification images only transiently and do not store them outside the evidence-retention window. • Parent-selected room photos: held only while the room-planning request is running, then discarded when chore suggestions return by default. Opted-in room-reference objects and metadata are queued for deletion as soon as Family access expires or is revoked and are not restored. They are also deleted after their final chore link is removed, when their child or household is deleted, or after 24 hours if an upload is never linked. • Structured household data—including child profiles, chores, ledgers, balances, rewards, pairing credentials, and consent records—remains recoverable for 12 calendar months after expiry or revocation. Resubscription before deletion begins cancels structured deletion and pending warnings. Immediate child or account deletion removes the applicable data without that recovery window. • Device pairing codes become unusable 24 hours after creation. The stable paired-device credential follows the structured-data recovery window unless the parent revokes pairing or deletes the child or account. • Your version-stamped consent record follows the structured-data recovery window as proof that consent was given; renewed consent is required before restored child data reopens. • The age-verification signal at setup: never stored - reduced to a yes/no result and immediately discarded. A child's nickname and private display symbol follow the structured-data recovery window and are deleted when recovery ends or when the child or account is deleted sooner.
Your rights as a parent
You can review every child photo and decision, correct a rejection to approval, disable AI chore verification, disable future room-reference attachment, remove a reference from an individual chore, remove a child and related app rows and private objects, delete child data, or revoke child-photo consent to disable future photo submission. Contact [email protected] for assistance.
Security
Your family's household data lives in Cloudflare D1, with household mutations serialized by Durable Objects, while sanitized chore evidence and opted-in room references live in separate private R2-compatible buckets. A child's session can read only references linked to that child's active chores; reads stream through the authenticated Worker with private, no-store caching. A child's session can submit evidence but cannot alter its own points balance or mint parent review URLs. Points are authoritative because only our Worker can issue signed ledger records: every entry is cryptographically signed, and the app trusts only signed balances. Child-visible records contain only opaque reference IDs, never object keys or public image URLs. Parent-supplied reward codes are encrypted in the dedicated rewards database and revealed only to the authenticated child after parent approval. No system is perfectly secure, but we apply reasonable measures appropriate to the sensitivity of children's data. The full set of safeguards is published as our Information Security Program.
Changes & contact
If we make a material change to how we handle children's information, we will ask the parent to review and consent again before the change applies to your household. Questions or requests, or to reach the operator: Tidiest LLC, 12851 Tilden Dr., Rancho Cucamonga, CA, United States · +1 (909) 646-2488 · [email protected]. This policy is governed by the laws of the State of California, United States.