Privacy Policy
Effective 25 August 2026. Last updated 25 August 2026.
Family Routine is made by Tengizi Bardavelidze ("we"). This policy explains what the app stores, where it goes, and how to get rid of it. It is short on purpose. If something here isn't clear, write to us at kidroutineapp@gmail.com and we'll fix the wording.
The short version
There are no accounts. You never give us an email address or a password to use the app. We hold a child's first name, their checklist, a record of what got ticked off, and a count of which setup screens people reach, and that's close to all of it. The photo your child takes is locked on their device before it is sent, and we cannot open it. There are no ads, no advertising identifier and no tracking across other apps, and nothing about you is ever sold.
What we collect
Family Routine keeps most of your family's information on your own phone. To let two devices see the same thing, some of it is also stored on our server:
- A child's first name. Whatever you type when you add them. Just the first name: the app never asks for a surname, a birthday, a school, or a photo of anyone's face. Setup does ask which age range your child is in, so the child screens can pitch their reading level; that answer is used on the spot and is never saved or sent anywhere.
- The routine itself. The evening and morning checklists you build, the steps in them, the reminder times, and the colour and character you picked.
- What happened each day. Which steps were ticked, when the routine was finished, whether you approved it, the note you wrote if you sent it back, and the note your child wrote when they sent the photo.
- The proof photo. One photo per routine, taken with the camera or chosen from the photo library. It is encrypted before it leaves the device. See below.
- An anonymous device identifier. When a device first connects, it signs itself in anonymously. The result is a random identifier stored in that device's keychain. It isn't linked to your name, your email, or your Apple Account, and we can't use it to find you anywhere else.
- Which kind of device joined, and when. When you pair a second device with a six-digit code, that device tells the family "iPhone" or "iPad" and the time it joined, so your screen can show that the code was used. It is only the model word, never the device's name.
- The six-digit pairing code, while it is alive. Codes stop working after fifteen minutes, and a code that has been used is deleted the moment it is redeemed.
- Where you heard about us, if you tell us. Setup asks one question: TikTok, a friend, the App Store, or somewhere else, plus an optional code if a creator gave you one. The answer itself is stored on its own, with no link to your family, your child or your device: a row that reads only “TikTok, code SOMETHING, 25 August, GE”, with a date rather than a time so it cannot be lined up against anything else. A creator code is the one exception: it is also passed to our subscription provider as the campaign a purchase came from, so the creator can be paid. That means the code sits beside your anonymous subscription record there, and nothing else about you does. It changes nothing about your price or what the app does, and you can skip it.
- Which setup screen you reached. The app counts how many people get to each of the twenty five setup screens and to the subscription page, because otherwise there is no way to know which screen is losing people. What is stored is a screen name, a date, and a random number this install made for itself on first launch. That number is not your device identifier, not an advertising identifier, and deliberately not the anonymous sign-in above: it is a different number, kept in a different place, so that even we cannot line up "this install saw the price" with "this family's child is called Luka". Nothing about your child, your routine or your photos is in it, and it is deleted with everything else when you delete your data.
- A support message, if you send one. Settings → "Contact us" sends us the reply-to address you type, your subject and message, your app version, your device model ("iPhone", "iPad"), and the anonymous identifier of the device that sent it, which is what lets us look up your family's setup while we answer you. Nothing else goes with it. A person reads it and replies to the address you gave.
If you set up a routine for yourself rather than for a child, that profile's name is stored the same way.
Our hosting provider also keeps ordinary server logs, including the IP address a request came from, to run and protect the service. We don't use those logs to build a picture of you or your family.
What we don't collect
- No email address, no password, no account of any kind, except the reply-to address you choose to type into a support message.
- No last names, no birthdays, no contacts, no calendar.
- No location. The app never asks for it and never uses it.
- No advertising, no advertising identifier, no crash-reporting service, and no tracking across other apps or websites. The app contains exactly two outside components: the open-source Swift library it uses to talk to our own server, and RevenueCat, which handles subscriptions. Neither is an advertising or tracking tool, and neither one is given your name, your email address, your child's name, or any photo.
- We do not track you or your child across other apps or websites. Nothing here is sold, rented, or handed to a data broker. Ever. Not as part of a merger either. If the app were ever sold, the buyer would be bound by this policy and you'd be told before anything changed.
The proof photo
This is the part we care most about, so here is exactly how it works.
Your device publishes a public key. When your child takes the photo, their device locks the photo to that key before uploading it, using standard end-to-end encryption (X25519 key agreement, HKDF-SHA256, AES-GCM). What lands on our server is a sealed blob, not an image file. The key that opens it lives in your device's keychain and is never sent to us. It does sync to your other Apple devices through iCloud Keychain, which Apple encrypts end-to-end, so a new phone can still open older photos. Neither Apple nor we can read the key in transit.
That means we cannot look at your child's photo. Not us, not anyone with access to the database, not anyone who steals a copy of it. It isn't a promise about how carefully we behave. There is no way for us to do it. It also means we cannot recover a photo for you if the parent device that holds the key is lost or reset.
If a photo can't be encrypted, for instance, if the app hasn't yet learned your key, it is not sent. It stays on your child's device and tries again later.
The photo is the only thing that is encrypted this way. The child's first name, your checklist steps and the notes you and your child write are stored as ordinary text so the two devices can show them, walled off from every other family, but readable by us if we look. Please don't put anything into a step or a note that you wouldn't want us to be able to read.
When the photo is deleted
- When you tap "Looks good", your phone tells our server to delete its copy, normally within seconds. Its only job was to get from one device to the other. If your phone happens to be offline at that moment, the deletion happens on the next clear-out instead.
- Otherwise, after 14 days. Your own phone does the clearing out: whenever the app runs, it removes anything in your family's folder older than fourteen days. If nobody in your family opens the app, that clean-up waits until somebody does.
- When you delete a child or a day, the photo still on our server is cleared by the fourteen-day sweep rather than immediately. It is unreadable to us in the meantime.
- The copy on your own phone stays, so your history screen still works. That copy is yours.
Where your data lives
On your devices, and on our server. The server is run for us by Supabase, our data processor, on Amazon Web Services infrastructure in the United States (region us-east-1). Supabase, and AWS beneath it, store the data on our instructions and for no other purpose. Apple is involved only in the ordinary way any iPhone app involves it: your photo key syncs through iCloud Keychain if you have it switched on, and the app's files are included in your device backups. Nobody else holds any of it.
If you use Family Routine from outside the United States, your family's data is stored in the United States.
Each family's data is walled off at the database level: a device can only ever read the family it belongs to, and the photo bucket is private and locked to a single family's folder.
How long we keep things
- Proof photos on the server: deleted on approval, or within about fourteen days.
- Pairing codes: they stop working after 15 minutes, and a used code is deleted the moment it's redeemed.
- Your child's name, routines and daily records: kept until you delete them. They exist so your two devices agree with each other; there is no schedule that removes them for you.
- Support messages: kept while we're helping you and for a reasonable period after, so we can pick up an old thread. They are deleted along with everything else if you delete your data, and you can ask us to delete one at any time.
Children's data, and your consent
Family Routine is designed for a parent or guardian to set up and run. You install it, you type your child's first name, you build the checklist, and you decide whether to put a second copy on your child's device, which can only happen if you generate a six-digit code on your own phone and it is entered on the other device within fifteen minutes. Nothing about your child is collected until you take that step. A child never creates an account, never types an email address, and is never asked for personal details. What a child can add is a tick, a short note, and a photo of a packed bag.
By setting up a routine for your child, you are consenting to the small amount of information described above being stored so the app can work. In the language of the US Children's Online Privacy Protection Act (COPPA), you are the parent giving that consent, and you can withdraw it at any time by deleting the data. See below. We don't knowingly collect anything from a child beyond what's listed here, and we never make your child's use of the app conditional on giving us more.
Family Routine is a productivity app sold to parents, not a children's entertainment app. There is no advertising in it, no messaging with strangers, no social features, no web browsing, and no links out to buy anything.
What you control
- Delete all data. Settings → Advanced → "Delete all data". This deletes your family from our server, children, routines, every daily record, every pairing code, every photo in the bucket, and any support message you have sent us, as well as from the device you're holding. It needs a working connection: if the app can't reach the server it will not have deleted anything there, so do it while you're online. There is no undo.
- Disconnect a child's device. On your child's device, Settings → "Disconnect this device" removes that device from your family and ends its access. It needs a fresh six-digit code to join again.
- Delete one child, or one day. Deleting a child removes their routines and history. Deleting the app from a device removes the photos and everything else the app saved on that device, though, as with any iOS app, they may still be in an iCloud or computer backup you made earlier, and the device's anonymous sign-in stays in the iOS keychain until you delete all data.
- Turn reminders off at any time, in Settings or in iOS Settings.
- See what we have. Everything we hold about your family is already visible in the app on your phone. There's no hidden profile to request. If you'd like a copy in another form, or want something removed by hand, email kidroutineapp@gmail.com.
Your device's own anonymous sign-in goes with it, in the same step. If a child's device is still connected when you do this, it keeps its own sign-in until somebody taps "Disconnect this device" there or deletes the app from it, an empty record either way, pointing at a family that no longer exists.
Permissions the app asks for
- Camera: so your child can photograph the packed bag. We only ever receive that one photo.
- Photo library: your child can pick an existing photo instead of taking one, from a button next to the camera. The picker runs outside the app: we receive only the single photo chosen, and the app is never granted access to browse your library.
- Notifications: reminders are scheduled and delivered by your own device. There is no push server, and we never receive a push token. Nothing about your reminders is sent to us. If you decline notifications, the app works exactly as before, minus the reminder.
The app also uses a short background refresh so a finished routine can be waiting for you when you open your phone.
Payments
Family Routine has an optional subscription, Family Routine Plus. Purchases go through Apple, who handle the payment. We never see or store your card details, your name as it appears on the card, or your billing address. Apple does not give them to us.
To know whether your family is subscribed, we use RevenueCat, a subscription service that talks to the App Store on our behalf. It receives an anonymous identifier it generates itself, the country your App Store account is in, the receipt Apple issues for the purchase, and, if you entered a creator's code during setup, that code, so the creator can be paid for the referral. It does not receive your name, your email address, your child's name, or any photo. We have turned off its optional device-identifier and diagnostics collection. Their privacy policy is at revenuecat.com/privacy.
Four things are stored on our server against your family's random identifier, so that your child's device, signed in to a different Apple Account, knows the app is unlocked: whether your family is subscribed, the date the subscription runs to, whether it is set to renew, and when we last checked. That is the whole of it. No card, no price, no transaction, nothing Apple sends us about how you paid.
Security
Everything travels over an encrypted connection. Photos are additionally encrypted end-to-end, as described above, so they are unreadable to us and to our hosting provider. Each family's rows and files are isolated from every other family's by rules enforced on the server, not by the app. Only a parent device can delete a family's data or its photos.
No system is perfect, and we won't pretend otherwise. What we can do is hold as little as possible, keep the photo unreadable to ourselves, and throw it away quickly. That's the design.
Changes to this policy
If we change how the app handles your data, we'll update this page and change the date at the top. If the change is a significant one, we'll say so prominently at the top of this page and show a notice in the app in the next update. The current version always lives inside the app, under Settings → Privacy, and on the page you are reading now.
Contact us
Easiest: Settings → "Contact us" in the app. A person reads those.
Or write to us:
Tengizi Bardavelidze
kidroutineapp@gmail.com
This policy is governed by the laws of Georgia.