Legal

Privacy Policy

Last updated: 24 May 2026

Note: This document is a general template provided for transparency purposes. It does not constitute legal advice. You should seek qualified legal counsel to ensure this policy meets the specific requirements of your jurisdiction and circumstances.

1. Who We Are

CapyBucks is a family money-education iOS application ("the App") that helps parents teach children healthy money habits using virtual balances, savings goals, and spending records — entirely within the app, with no real money involved.

The App is developed and published by [Your full legal name], acting as an individual developer and the data controller responsible for the personal data described in this policy.

Data controller contact details:

  • Name: [Your full legal name]
  • Address: [your address]
  • Email: [contact email]

2. A Quick Summary

Here are the most important things to know about how CapyBucks handles data:

  • Parents create and manage all accounts. Children do not register themselves and do not need their own email address to use the App.
  • All money is virtual. CapyBucks uses simulated balances for educational purposes. We do not process, hold, or transfer any real funds.
  • No advertising, no tracking. We do not show ads, we do not use advertising or analytics SDKs that track users across apps, and we never sell personal data.
  • You control your data. You can request access to, correction of, or deletion of your data and your children's data at any time.
  • We use Google Firebase as our backend infrastructure for authentication, data storage, file storage, and push notifications.
  • We take children's privacy seriously. The App is designed with GDPR and COPPA requirements in mind: parents consent on behalf of their children, and children's data is kept minimal and not used for any commercial profiling.

3. Information We Collect

3.1 Parent or Guardian Account Information

When you create an account, we collect:

  • Email address — used for authentication and essential service communications.
  • Password — stored as a secure hash by Firebase Authentication; we never see your plaintext password.
  • Google Sign-In (OAuth) data — if you choose to sign in with Google, we receive your name and email address from Google as part of the OAuth flow.
  • Family join code — a short code used to invite a co-parent or second guardian to your family group. No sensitive personal data is encoded in this code.

3.2 Children's Information (Added by the Parent)

Parents add their children to the App by providing:

  • Child's name — a first name or nickname chosen by the parent.
  • Optional age — used to personalise the experience (e.g., interest calculations).
  • Avatar — either a pre-set emoji or an uploaded photo from the device's camera roll.
  • 4-digit PIN — used so the child can switch to their own view within the app. This PIN is stored as a cryptographic hash; it is never stored in plaintext.

Children do not create accounts themselves. All of a child's data is associated with the parent's account and is entered and managed entirely by the parent.

3.3 Virtual Financial-Education Data

As you use the App, we store the virtual financial records you create:

  • Virtual balances, savings buckets, and savings goals.
  • Virtual transactions (income, expenses, allowance paydays).
  • Virtual interest accrued on savings.
  • Spending streaks and level/progress data.

This data has no monetary value and represents purely educational activity within the App.

3.4 Photos and Media

With your permission, the App may access your device's camera or photo library for:

  • Receipt photos — you can photograph a receipt to log a virtual transaction. The App uses on-device OCR to extract amount and merchant information. The photo itself is uploaded to Firebase Storage and associated with the relevant transaction record.
  • Avatar photos — a photo chosen by the parent to represent a family member's profile within the App.

3.5 Technical and Device Data

  • Push notification token — a device token provided by Apple and registered with Firebase Cloud Messaging so we can send you push notifications (e.g., payday reminders, allowance notifications). You can disable these in your device's notification settings at any time.
  • Basic usage and error logs — Firebase may collect standard diagnostic information (e.g., crash reports, anonymised performance metrics) to help us maintain the App. We do not combine this with advertising identifiers.
  • Device information — operating system version and device type, collected as part of standard Firebase SDK operation.

3.6 Currency Exchange Rate Data

The App fetches current exchange rates from frankfurter.app, a free, open-source exchange rate API. This request contains no personal data — only a request for rate information. Please refer to frankfurter.app's own privacy practices for details.

4. How We Use Information

We use the personal data we collect for the following purposes:

  • Providing and synchronising the service — authenticating you, storing your family's data, and making it available across your devices.
  • Push notifications — sending reminders and alerts you have enabled, such as allowance payday notifications or goal completion alerts.
  • Customer support — responding to questions or requests you send to our support email.
  • Security and fraud prevention — detecting and preventing unauthorised access or misuse of accounts.
  • Legal compliance — meeting our obligations under applicable law, including data protection regulations.
  • Service improvement — using anonymised or aggregated diagnostic data to fix bugs and improve performance. We do not build individual behavioural profiles for marketing.

If you are in the European Economic Area (EEA), we process personal data on the following legal bases under the General Data Protection Regulation (GDPR):

  • Performance of a contract (Art. 6(1)(b)) — processing your account credentials, family data, and virtual financial records is necessary to provide the service you have signed up for.
  • Consent (Art. 6(1)(a) and Art. 8) — for optional features such as photo uploads or push notifications, and for processing children's personal data, which is done on the basis of parental consent. You may withdraw consent at any time.
  • Legitimate interests (Art. 6(1)(f)) — for security monitoring and anonymised service diagnostics, where these interests are not overridden by your rights and freedoms.
  • Legal obligation (Art. 6(1)(c)) — where we are required to retain or disclose data to comply with applicable law.

6. Children's Privacy

Protecting children's privacy is a core design principle of CapyBucks. Please read this section carefully.

6.1 Parent-Managed Accounts

Children do not create their own accounts and do not provide any personal data directly to us. All children's information in the App is entered and managed solely by the parent or guardian who holds the account. The parent account holder is the data subject for GDPR purposes in relation to their own data, and the parent acts as the consenting party in relation to their children's data.

6.2 COPPA (United States — Children Under 13)

CapyBucks is designed so that children under the age of 13 do not interact directly with our account creation or data collection systems. Because the parent creates the account and enters all child data, the parent's act of creating the account and adding their child constitutes verifiable parental consent as contemplated by the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 without this parental consent mechanism. If you believe a child under 13 has provided information without parental consent, please contact us at [contact email] and we will delete it promptly.

6.3 GDPR-K (European Union)

Under GDPR, processing the personal data of children under 16 (or a lower age set by the relevant EU member state) requires parental or guardian consent. Because the parent account holder is the one creating and consenting to all data about their children, we collect this consent at account creation. Children are not exposed to any consent flows within the App.

6.4 No Behavioural Advertising Directed at Children

We do not use children's data for advertising, profiling, or any commercial purpose beyond providing the educational service. The App contains no advertising, no third-party advertising SDKs, and no behavioural tracking.

6.5 Parental Access and Control

As the account holder, you have the right to review, correct, export, or delete all data associated with your children at any time. You can delete a child's profile directly within the App, or contact us at [contact email] to request deletion of the entire account including all associated children's data.

7. How We Share Information

We do not sell personal data. We do not share data with advertising networks or data brokers. We share data only in the following limited circumstances:

  • Google Firebase (data processors) — our backend infrastructure runs on Google Firebase (Firebase Authentication, Cloud Firestore, Firebase Storage, Firebase Cloud Messaging), operated by Google LLC. Google processes data on our behalf as a data processor under a Data Processing Agreement. Google's infrastructure may be located in the United States and other countries.
  • frankfurter.app — a no-registration, open-source exchange rate API used to fetch currency rates. No personal data is transmitted to this service.
  • Legal requirements — we may disclose data if required to do so by law, court order, or governmental authority, or to protect the rights, property, or safety of users or the public.
  • Business transfer — if the App is acquired or its assets transferred as part of a sale, merger, or similar transaction, personal data may be transferred to the successor. You will be notified of any such change via the App or email.

8. International Data Transfers

Because we use Google Firebase, your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where Google's infrastructure operates. Such transfers are carried out under appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) as part of Google's Data Processing Agreement. For more information on Google's international data transfer mechanisms, see Google's Privacy and Security documentation.

9. Data Retention

We retain your personal data for as long as your account is active. If you request deletion of your account, we will delete or anonymise all associated personal data (including children's data) as soon as reasonably practicable, and no later than within 30 days, except where we are required by law to retain certain records for a longer period.

You can delete individual data items (such as a child's profile, a transaction record, or a receipt photo) directly within the App at any time. To delete your entire account and all associated data, contact us at [contact email].

10. Security

We take reasonable technical and organisational measures to protect your personal data:

  • Encryption in transit — all data exchanged between the App and our servers is transmitted over TLS/HTTPS.
  • Encryption at rest — Firebase encrypts data stored on its servers using industry-standard encryption.
  • Hashed PINs — child PINs are stored as cryptographic hashes and are never readable even by us.
  • Firebase Security Rules — access to Firestore data and Firebase Storage is governed by security rules that ensure users can access only their own family's data.
  • Password security — account passwords are managed entirely by Firebase Authentication and are never stored in plaintext by us.

No security system is impenetrable. We cannot guarantee absolute security of your data and cannot accept liability for unauthorised access beyond what is required by applicable law.

11. Your Rights

If you are located in the EEA or another jurisdiction with data protection legislation, you may have the following rights regarding your personal data:

  • Right of access — to obtain confirmation of whether we process your data and to receive a copy.
  • Right to rectification — to have inaccurate personal data corrected.
  • Right to erasure — to request deletion of your personal data ("right to be forgotten"), subject to legal obligations.
  • Right to restriction of processing — to request that we limit how we use your data in certain circumstances.
  • Right to data portability — to receive your data in a structured, machine-readable format.
  • Right to object — to object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at [contact email]. We will respond within the timeframe required by applicable law (generally within one month under GDPR).

You also have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the App, our data practices, or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page and, where required, notify you via the App or email.

Your continued use of the App after any changes become effective constitutes your acceptance of the revised policy. If you do not agree to the updated policy, you may delete your account by contacting us.

13. Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

  • Email: [contact email]
  • Name: [Your full legal name]
  • Address: [your address]