EarnJar Privacy Policy
The short version: EarnJar is a family tool, not a data business. We collect the minimum needed to run your household's job board, we never sell or share data for advertising, kids can't be contacted through EarnJar, and you can export or permanently delete everything from inside the app.
Who we are
EarnJar ("we") is a household job-and-allowance app: parents post paid jobs, kids earn, negotiate, invoice, and learn to manage money. This policy covers the EarnJar iOS app and earnjar.app.
Children's privacy (COPPA)
EarnJar is built for families and takes a deliberately minimal approach to children's data:
- Parents create every kid profile. Kids cannot sign up on their own, and a parent records their consent when creating the profile.
- We collect almost nothing about kids: a first name or nickname, an avatar color, and a pretend "business name" they pick. No email address, no birthday, no age, no photos of the child, no location.
- Kids sign in with a 4-digit PIN chosen with their parent. PINs are stored only as salted cryptographic hashes; parents can reset them at any time (resets immediately end the kid's existing sessions).
- Kids cannot be contacted through EarnJar: no messaging, no social features, no public profiles, no ads. Kids never see marketing or prices.
- Parents can delete a kid's profile and all of their data at any time from the app (Kids tab), and can delete the entire household account (see "Your rights").
What we collect, and why
- Parent account: your email address and a password (handled by our authentication provider), used to sign in and for account emails like password resets.
- Household data you create: household name, jobs, negotiations, invoices, balances, savings goals, family-loan records, and notes you write. Money amounts in EarnJar are educational bookkeeping — EarnJar never holds or moves real money.
- Proof photos (temporary): a kid may attach a photo of finished work. It is stored privately, visible only to your household, and deleted from our storage when the job is paid (or sent back for a redo, or canceled). Copies briefly held in network-edge caches expire shortly afterward, and no new links to a deleted photo can ever be created. Photos older than 30 days are deleted regardless.
- Notifications (optional): if you enable them, a device push token. Our notification rule is a product promise: at most one daily summary, only when someone in your family is actually waiting on you, never promotional.
- Usage analytics (optional, anonymous): we use our own first-party, aggregate event counts (e.g. "a job was posted") to fix confusing screens. Events use a random per-install identifier, and our servers structurally reject anything that looks like personal data — names, free text, child identifiers cannot be stored. Kid sessions send even less. You can turn this off in Settings (only crash counts remain).
- Subscription status: whether your household's subscription is active. Payment itself is handled entirely by Apple — we never see your card.
What we never do
- No selling or renting personal data. No advertising, ad SDKs, or cross-app tracking.
- No third-party analytics SDKs in the app.
- No contact with children, and no marketing to children.
Service providers
We use a small set of processors, each receiving only what their job requires: Supabase (database, authentication, and file hosting), Apple (subscription billing), RevenueCat (subscription status; identified only by a random household id — no names or emails), and Resend (email delivery for account and — only with your consent — product emails). Marketing-style emails require your explicit opt-in and every one includes a one-click unsubscribe.
Your rights
- Export: Settings → "Export family data" gives you your household's complete data as a JSON file, on demand.
- Delete a kid: Kids tab → remove — erases the profile and all related data, including destroying their photos in storage.
- Delete everything: Settings → "Delete account & all data" — requires your password, then permanently erases the household, every kid profile, all records, all photos in storage, and the account itself. This is immediate and irreversible.
- For anything else — questions, corrections, or COPPA requests — email earnjar.support@gmail.com.
Security
Data is encrypted in transit; access is enforced by row-level database rules so each household can only ever see its own data, and kids can only see their own slice of it. Kid PINs are salted-hashed; parent passwords are handled by our authentication provider and never stored by us in readable form.
Changes
If this policy changes materially, we'll note it here with a new date and, for significant changes affecting children's data, notify parent accounts by email.