Security and privacy
A children's app is the wrong place to be clever with data
You're handing us your household's money picture and your kids' first names. Here is exactly what we do with both, in the plainest words we can manage.
Never
Sold, shared or advertised against
No ad networks, no data brokers, no third-party analytics following your kids around. Our own visit counter runs on our own server and sets no cookies.
Always
Yours to take with you
Download the whole history whenever you like. Delete the household and it is exported to you first, then purged after 30 days.
What we collect, and why
Six things. Each one earns its place or we don't ask for it.
A grown-up's name and email, and the household's name
Your name labels what you did in the household's history; the household's name is what your kids see when they sign in. The email gets you back into your account and carries the emails the app needs — verification, invites, a locked PIN, your download link. Not a mailing list; there isn't one.
Each kid's first name, birth year and username
The first name labels the jars. The birth year is there so a grown-up can tell two kids apart and so we can act on age rules if we ever need to. The username and a PIN are how they sign in. We don't ask for surnames, birthdays, schools, photos or a kid's email.
The money you record
Chores, jars, transactions, budgets. Kept so the app can add up. Visible to the grown-ups in your household and to nobody else.
A receipt photo, if a grown-up attaches one
You can attach a photo of a receipt to a transaction. It sits in your household's own storage, only grown-ups can see it, and it goes when the transaction or the household does. Kids can't attach photos.
A random id for each device you sign in from
So the sessions from one device can be ended together and you can sign out everywhere at once. It is generated by the app, it is not an advertising id, and it is never shared.
How the kid side is protected
A child's account isn't a small version of an adult's. It's a different thing, with less in it on purpose.
No open text field a stranger could reach
There is no chat, no comments, no sharing and no way for anyone outside your household to contact a kid through CubbyJar.
Nothing to buy, nowhere to spend
Kid mode has no prices, no upgrade prompts and no payment method attached. A kid cannot spend real money in this app.
A kid sees their own jars and no further
Not household accounts, not your income, not what a sibling earns. The wall is in the data model, not a setting you have to remember.
The grown-ups hold the keys
You create each kid's access, you can end it, and you can download or delete their history. Five wrong PINs pause sign-in for 15 minutes and email the grown-ups.
The technical part, briefly
Encrypted in transit; backups and files encrypted at rest
TLS on every connection. The app and its database run on a server we operate at Hostinger in Boston, Massachusetts. Backups, receipt images and export files sit on encrypted storage at Amazon Web Services in the United States.
Backed up, and restorable
Backups run nightly. Backups are kept for 30 days, so a mistaken deletion is recoverable. Delete the household on purpose and the backups age out too.
Every change is logged
Each change to your household's data is recorded with who made it and when, so we can answer "what happened" without guessing.