Privacy at ChorePop

Privacy policy

This policy explains what ChorePop handles, why it is needed, and the choices guardians have. ChorePop is a family ledger, not a bank, and it does not hold or move real money.

Last updated: 30 August 2026

A shorter version for children

Read Privacy for children for a plain-language summary of what ChorePop remembers and how a child can ask a trusted adult for help.

Who is responsible for your data

ChorePop is operated by VEEFIVE LTD. For privacy or data-rights questions, email . For general help, email .

Data ChorePop uses

Depending on how your family uses ChorePop, this can include:

  • guardian identity and account details, such as a name, email address, user identifier, sign-in provider and security records;
  • family and child display names, guardian relationships, chores, routines, approvals, notes, allowances, buckets, goals and streaks;
  • ledger entries for money a guardian holds on a child's behalf, including deposits, withdrawals, balances and currency records;
  • subscription status and store transaction identifiers needed to verify access and prevent purchase replay; and
  • a ChorePop device identifier and app activity needed for trial binding, security, synchronisation and a guardian-visible audit trail.
  • private safety reports, including the words or item reported, the reporter's explanation, local child or guardian context, the verified guardian cloud identity used to send it, and VEEFIVE LTD's moderation record.

ChorePop does not collect payment-card or bank-account details. Apple or Google handles subscription payment. ChorePop does not ask for a child's age or birthday.

Trial data, Supabase and cloud sync

The 30-day trial ledger stays on its one device except when a child or guardian deliberately sends the private safety-report data described below. Guardian identity, trial status, subscription verification and those deliberate reports use ChorePop's Supabase cloud service. After a verified subscription, an authorised guardian can move the family ledger into secure family cloud sync so the same family can use more than one device.

ChorePop uses cloud access controls to separate each family. It sends data over encrypted HTTPS or secure WebSocket connections. Local app data is protected by the device's operating-system access controls.

Pounds, dollars and exchange rates

A family uses pounds sterling (GBP) or US dollars (USD) for its normal ledger. Other currencies are available only to record overseas gifts or holiday spending. ChorePop fetches a daily public reference-rate set through its own read-only cloud endpoint. The exchange-rate request does not contain family, child or ledger data, and ChorePop does not keep a historical rate archive.

Private safety reports and moderation

A child or guardian can use Report unsafe content to ask VEEFIVE LTD to review unsafe or unkind family-entered content. The report is not shown to family members, and ChorePop does not tell the reported person which local profile submitted it. A verified guardian cloud identity authorises delivery; local child or profile details are supporting context rather than a separate cloud identity.

Authorised VEEFIVE LTD reviewers may dismiss a report, remove or redact text, suspend an account, or lock or delete a family where reasonably necessary for safety, legal compliance or enforcement of the Terms. Moderation decisions are recorded in an operator-only audit trail.

Safety-report evidence is kept separately for up to 180 days so deleting a family cannot erase a pending safety concern. The family link is detached when the family is deleted. ChorePop then deletes or irreversibly anonymises the retained report unless a longer period is required by law or to establish, exercise or defend legal claims.

No behavioural analytics or advertising SDKs

ChorePop does not display advertising, collect behavioural analytics or sell or share app activity for targeted advertising. The production release excludes the Facebook and Meta App Events SDK, Android's advertising-ID permission and comparable in-app advertising attribution code on both Apple and Android devices.

ChorePop therefore does not send Meta app activation, session, screen, purchase or custom events, advertising identifiers, or information about names, accounts, families, children, chores, routines, balances, goals or subscriptions. Advertising campaigns may use aggregate reporting provided outside ChorePop by an app store or advertising platform; ChorePop does not add an in-app SDK or event feed for that reporting.

A future attribution-only design would be considered only if it can be proven not to collect behavioural analytics or child and family data. ChorePop would update this policy and the applicable app-store disclosures before including such a design in a production release.

Biometric sign-in stays with the operating system

Biometrics are optional and available only to one guardian selected as the main adult on each device. Face ID, Touch ID or Android fingerprint matching is performed by the operating system. ChorePop never receives or stores face or fingerprint data. The protected unlock secret remains in the device's OS keychain or keystore, and password or PIN fallback remains available.

Service providers and disclosures

ChorePop uses Supabase for cloud identity, trial and subscription state, and paid-family sync. Apple and Google provide sign-in and subscription services when selected. A reference-rate provider supplies daily exchange-rate data to ChorePop's server. ChorePop does not use an in-app advertising or behavioural-analytics provider.

ChorePop does not sell personal data or children's activity. It may disclose information where required by law, to protect users and the service, or to service providers acting on ChorePop's instructions.

Download, deletion and recovery

A signed-in guardian can use Settings → Privacy & data and choose Download my family data to save an encrypted copy of authorised family data, or choose Delete my family data. Deletion requires a fresh guardian security challenge, immediately revokes family access and starts a 30-day recovery period. A verified guardian can cancel the request during that period; permanent erasure follows when it ends, subject to the bounded safety-report retention explained above.

Trial guardians can also download or securely delete their trial data. See the account and family deletion instructionsfor the in-app steps. ChorePop does not offer a web deletion form.

Your choices and rights

Guardians can correct family records in the app, download authorised family data and request deletion. Depending on UK data-protection law, you may also ask for access, correction, restriction, portability, objection or erasure. Emailso the request can be verified safely. Safety-report access requests are handled carefully so they do not disclose another person's identity or undermine a live safeguarding review.

Children and changes to this policy

Guardians create and manage child accounts and control family data. Children do not use cloud MFA or adult biometrics. ChorePop may update this policy as the app or the law changes; the date at the top will show the latest version.