Family Routine

Privacy Policy

Effective 25 August 2026. Last updated 25 August 2026.

Family Routine is made by Tengizi Bardavelidze ("we"). This policy explains what the app stores, where it goes, and how to get rid of it. It is short on purpose. If something here isn't clear, write to us at kidroutineapp@gmail.com and we'll fix the wording.

The short version

There are no accounts. You never give us an email address or a password to use the app. We hold a child's first name, their checklist, a record of what got ticked off, and a count of which setup screens people reach, and that's close to all of it. The photo your child takes is locked on their device before it is sent, and we cannot open it. There are no ads, no advertising identifier and no tracking across other apps, and nothing about you is ever sold.

What we collect

Family Routine keeps most of your family's information on your own phone. To let two devices see the same thing, some of it is also stored on our server:

If you set up a routine for yourself rather than for a child, that profile's name is stored the same way.

Our hosting provider also keeps ordinary server logs, including the IP address a request came from, to run and protect the service. We don't use those logs to build a picture of you or your family.

What we don't collect

The proof photo

This is the part we care most about, so here is exactly how it works.

Your device publishes a public key. When your child takes the photo, their device locks the photo to that key before uploading it, using standard end-to-end encryption (X25519 key agreement, HKDF-SHA256, AES-GCM). What lands on our server is a sealed blob, not an image file. The key that opens it lives in your device's keychain and is never sent to us. It does sync to your other Apple devices through iCloud Keychain, which Apple encrypts end-to-end, so a new phone can still open older photos. Neither Apple nor we can read the key in transit.

That means we cannot look at your child's photo. Not us, not anyone with access to the database, not anyone who steals a copy of it. It isn't a promise about how carefully we behave. There is no way for us to do it. It also means we cannot recover a photo for you if the parent device that holds the key is lost or reset.

If a photo can't be encrypted, for instance, if the app hasn't yet learned your key, it is not sent. It stays on your child's device and tries again later.

The photo is the only thing that is encrypted this way. The child's first name, your checklist steps and the notes you and your child write are stored as ordinary text so the two devices can show them, walled off from every other family, but readable by us if we look. Please don't put anything into a step or a note that you wouldn't want us to be able to read.

When the photo is deleted

Where your data lives

On your devices, and on our server. The server is run for us by Supabase, our data processor, on Amazon Web Services infrastructure in the United States (region us-east-1). Supabase, and AWS beneath it, store the data on our instructions and for no other purpose. Apple is involved only in the ordinary way any iPhone app involves it: your photo key syncs through iCloud Keychain if you have it switched on, and the app's files are included in your device backups. Nobody else holds any of it.

If you use Family Routine from outside the United States, your family's data is stored in the United States.

Each family's data is walled off at the database level: a device can only ever read the family it belongs to, and the photo bucket is private and locked to a single family's folder.

How long we keep things

Children's data, and your consent

Family Routine is designed for a parent or guardian to set up and run. You install it, you type your child's first name, you build the checklist, and you decide whether to put a second copy on your child's device, which can only happen if you generate a six-digit code on your own phone and it is entered on the other device within fifteen minutes. Nothing about your child is collected until you take that step. A child never creates an account, never types an email address, and is never asked for personal details. What a child can add is a tick, a short note, and a photo of a packed bag.

By setting up a routine for your child, you are consenting to the small amount of information described above being stored so the app can work. In the language of the US Children's Online Privacy Protection Act (COPPA), you are the parent giving that consent, and you can withdraw it at any time by deleting the data. See below. We don't knowingly collect anything from a child beyond what's listed here, and we never make your child's use of the app conditional on giving us more.

Family Routine is a productivity app sold to parents, not a children's entertainment app. There is no advertising in it, no messaging with strangers, no social features, no web browsing, and no links out to buy anything.

What you control

Your device's own anonymous sign-in goes with it, in the same step. If a child's device is still connected when you do this, it keeps its own sign-in until somebody taps "Disconnect this device" there or deletes the app from it, an empty record either way, pointing at a family that no longer exists.

Permissions the app asks for

The app also uses a short background refresh so a finished routine can be waiting for you when you open your phone.

Payments

Family Routine has an optional subscription, Family Routine Plus. Purchases go through Apple, who handle the payment. We never see or store your card details, your name as it appears on the card, or your billing address. Apple does not give them to us.

To know whether your family is subscribed, we use RevenueCat, a subscription service that talks to the App Store on our behalf. It receives an anonymous identifier it generates itself, the country your App Store account is in, the receipt Apple issues for the purchase, and, if you entered a creator's code during setup, that code, so the creator can be paid for the referral. It does not receive your name, your email address, your child's name, or any photo. We have turned off its optional device-identifier and diagnostics collection. Their privacy policy is at revenuecat.com/privacy.

Four things are stored on our server against your family's random identifier, so that your child's device, signed in to a different Apple Account, knows the app is unlocked: whether your family is subscribed, the date the subscription runs to, whether it is set to renew, and when we last checked. That is the whole of it. No card, no price, no transaction, nothing Apple sends us about how you paid.

Security

Everything travels over an encrypted connection. Photos are additionally encrypted end-to-end, as described above, so they are unreadable to us and to our hosting provider. Each family's rows and files are isolated from every other family's by rules enforced on the server, not by the app. Only a parent device can delete a family's data or its photos.

No system is perfect, and we won't pretend otherwise. What we can do is hold as little as possible, keep the photo unreadable to ourselves, and throw it away quickly. That's the design.

Changes to this policy

If we change how the app handles your data, we'll update this page and change the date at the top. If the change is a significant one, we'll say so prominently at the top of this page and show a notice in the app in the next update. The current version always lives inside the app, under Settings → Privacy, and on the page you are reading now.

Contact us

Easiest: Settings → "Contact us" in the app. A person reads those.

Or write to us:

Tengizi Bardavelidze

kidroutineapp@gmail.com

This policy is governed by the laws of Georgia.