Privacy Policy
Who this is for
Tidiest is operated by Tidiest LLC ("we", "us"). This Privacy Policy explains what information we collect, why, and your rights as a parent or legal guardian. Tidiest is intended to be set up and controlled by a parent or legal guardian who is at least 18 years old. Children do not have their own accounts and cannot agree to this policy.
Our commitment to children's privacy (COPPA)
Tidiest is designed for households with children, including children under 13, and we comply with the U.S. Children's Online Privacy Protection Act (COPPA). Before we collect a child's nickname/profile information or enable child photo submission, a parent must review the child-data, child-photo, and AI-verification notice and give verifiable consent. Only after that consent may the parent create a child profile with a nickname and optional private non-photo display symbol, and pair the child's device. During an active trial, paid subscription, or Billing Grace Period, Auto Mode requires the additional blocking notice version 2026-07-30-auto-mode-v1 and a separate verifiable parent authorization before a child may send a before photo for chore suggestions. Free households cannot enable Auto Mode. We collect the minimum information needed to run parent-managed chores, bounded Auto suggestions, AI-assisted chore verification, parent review, and rewards.
Adult Tidiest Composer
An adult may choose a separate solo workspace under notice 2026-08-30-composer-v1. Composer creates no child profile or credential and has no points, rewards, review queue, public profile, social sharing, or child data. The first sanitized camera capture remains only in app memory until Sign in with Apple, the adult notice, and verified Composer paid access succeed. Full sanitized before and after evidence is private and short-lived after a batch resolves. Reduced private before/after Activity thumbnails are retained for up to 90 days unless the adult deletes the item, deletes all Activity, converts the workspace, or deletes the account sooner. Text Activity metadata remains until its item, workspace, or account is deleted. Optional unfinished-batch reminders are local iOS notifications and are cancelled when the batch resolves.
What we collect from the parent
• Identity: Tidiest uses Sign in with Apple for parent accounts. We verify Apple's identity token server-side, store only the stable Apple subject or a protected hash plus minimal email relay metadata when Apple provides it, and issue an opaque Tidiest session token.
• Family access status: whether your household is in the consent-gated Free tier or has verified trial, paid, grace, expiry, or revocation metadata. Apple processes payments; we never see your card details. Free activates after consent and parental confirmation; our Cloudflare Worker verifies an App Store-signed transaction before applying paid access.
• Parent-supplied reward codes: if you create a manual-code reward, Tidiest stores the single-use code encrypted with its optional descriptive face value and currency. Tidiest does not sell, purchase, fund, validate, or track the monetary balance of gift cards.
• Parent-captured room photos: Manual and AI captures are sanitized on device, downscaled to a 1024-pixel JPEG, stripped of metadata, and the raw original is immediately released. Local Vision may report a face-like candidate or bounded diagnostic error, but it is not an upload gate. AI captures are sent through our Worker to Amazon Nova Pro through AWS Bedrock or GPT-5.6 Luna through OpenAI's global API. New parents accept room-photo notice 2026-08-30-before-after-verification-v3 during onboarding; existing parents review it before their next photo-backed save. After consent, the exact sanitized derivative is privately linked to chores saved from that capture so the parent and children assigned an active linked chore can view it. When AI verification is enabled, a linked room photo may be compared with that chore's completion photo.
What we collect about a child
• After parental notice and verifiable consent, a child profile UUID, a nickname you choose, such as "Kid 1", and an optional private non-photo display symbol the child may change. • Chore photos the child submits after parental consent, child-profile creation, and pairing. For separately authorized Auto Mode, this can include one sanitized before photo shared by up to three chores and one separate sanitized after photo for each completed chore. A photo of a child is personal information under COPPA, which is why the camera path stays locked until the parent consent stack is complete. Local Vision status, confidence, normalized regions, and bounded errors are diagnostic evidence only; they do not reject a photo merely because an object looks face-like. • Chore results: the AI verification result, any parent review or override, and the points earned. • Chore titles, finish rules, reward values, reward menu items, and redemption history that you create for the household. We do not collect a child's real name, email, phone number, precise location, profile photo, public profile, advertising identifier, or tracking identifier. Chore details are not used to build an AI profile of a child, and the private display symbol is not sent to AI providers, public records, or evidence metadata. Photo location metadata (EXIF/GPS) is stripped on the device before a chore photo is uploaded as evidence.
How we use chore photos
A child submission uploads only sanitized evidence to private R2-compatible object storage through a short-lived URL minted by Tidiest's Cloudflare Worker. The raw photo is never uploaded; metadata is stripped, images are downscaled, and local Vision diagnostics are recorded without making a face-like candidate an upload rejection. The bucket is not public, and parent review uses short-lived authorized download URLs. Evidence metadata, such as evidence ID, purpose role, opaque storage reference, status, approximate size, and deletion dates, is kept in Tidiest's backend evidence metadata store. If AI verification is enabled, /verify-chore resolves the evidence only after household authorization, active Free or paid access, consent, and the applicable locked chore rules pass. Free jobs return metadata-only queue status and never persist image bytes or provider bodies. Amazon Nova Pro through AWS Bedrock or GPT-5.6 Luna through OpenAI's global API may then process the sanitized evidence only for bounded Auto suggestions or chore-completion verification. An ordinary chore linked to a retained room photo under the current notice compares that sanitized before photo with its new completion photo; a chore without a reference uses only the completion photo. After the child commits Auto suggestions, each Auto chore uses its locked before photo and its own exclusive after photo for completion verification. Clearly unsafe or malformed provider results cannot become chores or rewards; ambiguous, private, or unclear results remain parent-review states. Auto rewards are disabled per child by default.
Third parties we share with
• Apple: Sign in with Apple supports parent identity, and Apple processes App Store subscriptions. Children do not use Sign in with Apple. • Cloudflare Worker, D1, Durable Objects, Queues, R2, and evidence metadata storage: Cloudflare hosts Tidiest's service code for parent room planning, AI chore verification, purchase verification, household authorization, QR/code pairing, evidence signed URLs, redemption, bonus, and ledger signing. D1 stores canonical app rows and Durable Objects serialize household mutations. Sanitized child chore evidence is stored briefly in private R2-compatible object storage. Enabled room references are stored separately in a dedicated private R2 bucket with household-scoped metadata and chore links in D1. Neither bucket has public object URLs, and the Worker never returns object keys. • Amazon Bedrock / Amazon Nova Pro: receives sanitized parent room photos for optional chore planning and, after the applicable parental consent and authorization, sanitized child chore evidence for the limited purposes of bounded Auto suggestions or chore-completion verification. It does not receive a child's nickname, public profile, or real name from Tidiest. Tidiest does not permit child evidence to be used for model training, model improvement, child profiling, personalization, or unrelated AI use. AWS states that neither AWS nor third-party model providers use Amazon Bedrock inputs or outputs to train Amazon Nova, Amazon Titan, or third-party models, and that inputs and outputs are not shared with model providers. • OpenAI / GPT-5.6 Luna: may receive the same sanitized photos through OpenAI's global API for the same limited purposes. Tidiest does not opt API inputs or outputs into training or model improvement and sends a keyed, non-identifying safety identifier instead of names, emails, or raw internal IDs. At launch, OpenAI abuse-monitoring logs may contain ordinary inputs and outputs for up to 30 days, and longer where legally required or necessary to prevent harm. Images classified as potential child sexual abuse material may be scanned and retained for manual review and legally required reporting. Global processing is not limited to the United States. We do not sell personal information, share it for advertising, or use third-party advertising or tracking SDKs.
Features Tidiest does not provide
Tidiest has no public child profiles, profile pictures, open chat, child messaging, public leaderboards, advertising, behavioral tracking, sale of personal information, face recognition, biometric identification, or child-facing AI/paywall surface. A private display symbol is not a profile picture and is never public.
How long we keep information
We keep each kind of information only as long as it is reasonably necessary, never indefinitely, then delete it. This is our data-retention policy; the same policy is also published in full as a standalone Data Retention Policy. • Chore photos (the review copy): approved evidence is deleted after roughly 72 hours. Rejected or disputed evidence may be retained for up to 30 days unless you delete it sooner. Abandoned or unconfirmed uploads are deleted after 24 hours. That window is deliberate - long enough for you to review a child's work, and no longer. Photos are stored only as private R2-compatible evidence objects and parent review uses short-lived authorized URLs. Auto Mode before evidence remains locked only while an issued set or linked chore needs it for verification or parent review, then follows the same 24-hour, roughly 72-hour, or up-to-30-day rule. This Tidiest evidence-retention policy is separate from the provider abuse-monitoring disclosure above. • Parent-captured room photos: retained after a consented photo-backed save as private room-reference objects and metadata. Paid expiry or revocation downgrades the household to Free and does not delete retained references. They are deleted after their final chore link is removed, when their child or household is deleted, or after 24 hours if an upload is never linked. Unsaved captures stay only in parent-shell memory until discarded, sign-out, or final shell teardown. • Structured household data—including child profiles, chores, ledgers, balances, rewards, pairing credentials, and consent records—remains available while the household has Free or paid access and is deleted only through the applicable child/household/account deletion path. Immediate child or account deletion removes the applicable data without a recovery window. Account deletion requires fresh Sign in with Apple authentication, revokes every session, and lets that same verified Apple identity start again with an empty workspace while private-media cleanup finishes. When Apple is still billing compatible active access, Tidiest retains only a hashed-identity-to-original-transaction continuity claim until that same identity restores the subscription; no prior workspace data is transferred. • Device pairing codes become unusable 24 hours after creation. The stable paired-device credential remains while the child is paired unless the parent revokes pairing or deletes the child or account. • Your version-stamped consent record remains while the household exists as proof that consent was given and is deleted with the applicable child or account data. • The age-verification signal at setup: never stored - reduced to a yes/no result and immediately discarded. A child's nickname and private display symbol remain while the child profile exists and are deleted when the child or account is deleted.
Your rights as a parent
You can review every child photo and decision, correct decisions subject to the displayed spent-points limitation, choose Off, Auto, or Auto-trusted separately for each child, keep Auto rewards off, disable AI chore verification, or revoke Auto Mode authorization. Revocation turns every child's Auto policy off and blocks new Auto capture, suggestions, commits, and verification. Room-photo retention is always on after its separate notice, but you can remove a reference from an individual chore. You can also remove a child and related app rows and private objects, delete child data, or revoke child-photo consent to disable future child photo submission. Contact [email protected] for assistance.
Parents may opt each child into one routine reminder using selected weekdays and a half-hour local-time choice after confirming the household timezone. Child-device reminder text is generic. Parent notifications may include child nicknames and item titles for reviews, rewards, and Auto Mode activity, plus parent-only subscription status. The parent app badge counts pending reviews and requested rewards up to 99; child sessions clear it. Tidiest uses iOS Notification Center and does not maintain an in-app notification inbox. Notification delivery metadata is operational data and does not introduce a new child-data or AI-processing purpose.
Security
Your family's household data lives in Cloudflare D1, with household mutations serialized by Durable Objects, while sanitized chore evidence and retained room references live in separate private R2-compatible buckets. A child's session can read only references linked to that child's active chores; reads stream through the authenticated Worker with private, no-store caching. A child's session can submit evidence but cannot alter its own points balance or mint parent review URLs. Points are authoritative because only our Worker can issue signed ledger records: every entry is cryptographically signed, and the app trusts only signed balances. Child-visible records contain only opaque reference IDs, never object keys or public image URLs. Parent-supplied reward codes are encrypted in the dedicated rewards database and revealed only to the authenticated child after parent approval. No system is perfectly secure, but we apply reasonable measures appropriate to the sensitivity of children's data. The full set of safeguards is published as our Information Security Program.
Changes & contact
If we make a material change to how we handle children's information, we will ask the parent to review and consent again before the change applies to your household. Questions or requests, or to reach the operator: Tidiest LLC, 12851 Tilden Dr., Rancho Cucamonga, CA, United States · +1 (909) 646-2488 · [email protected]. This policy is governed by the laws of the State of California, United States.