Security and privacy

A children's app is the wrong place to be clever with data

You're handing us your household's money picture and your kids' first names. Here is exactly what we do with both, in the plainest words we can manage.

Never

Sold, shared or advertised against

No ad networks, no data brokers, no third-party analytics following your kids around. Our own visit counter runs on our own server and sets no cookies.

Always

Yours to take with you

Download the whole history whenever you like. Delete the household and it is exported to you first, then purged after 30 days.

What we collect, and why

Six things. Each one earns its place or we don't ask for it.

  • A grown-up's name and email, and the household's name

    Your name labels what you did in the household's history; the household's name is what your kids see when they sign in. The email gets you back into your account and carries the emails the app needs — verification, invites, a locked PIN, your download link. Not a mailing list; there isn't one.

  • Each kid's first name, birth year and username

    The first name labels the jars. The birth year is there so a grown-up can tell two kids apart and so we can act on age rules if we ever need to. The username and a PIN are how they sign in. We don't ask for surnames, birthdays, schools, photos or a kid's email.

  • The money you record

    Chores, jars, transactions, budgets. Kept so the app can add up. Visible to the grown-ups in your household and to nobody else.

  • A receipt photo, if a grown-up attaches one

    You can attach a photo of a receipt to a transaction. It sits in your household's own storage, only grown-ups can see it, and it goes when the transaction or the household does. Kids can't attach photos.

  • A random id for each device you sign in from

    So the sessions from one device can be ended together and you can sign out everywhere at once. It is generated by the app, it is not an advertising id, and it is never shared.

How the kid side is protected

A child's account isn't a small version of an adult's. It's a different thing, with less in it on purpose.

  • No open text field a stranger could reach

    There is no chat, no comments, no sharing and no way for anyone outside your household to contact a kid through CubbyJar.

  • Nothing to buy, nowhere to spend

    Kid mode has no prices, no upgrade prompts and no payment method attached. A kid cannot spend real money in this app.

  • A kid sees their own jars and no further

    Not household accounts, not your income, not what a sibling earns. The wall is in the data model, not a setting you have to remember.

  • The grown-ups hold the keys

    You create each kid's access, you can end it, and you can download or delete their history. Five wrong PINs pause sign-in for 15 minutes and email the grown-ups.

The technical part, briefly

  • Encrypted in transit; backups and files encrypted at rest

    TLS on every connection. The app and its database run on a server we operate at Hostinger in Boston, Massachusetts. Backups, receipt images and export files sit on encrypted storage at Amazon Web Services in the United States.

  • Backed up, and restorable

    Backups run nightly. Backups are kept for 30 days, so a mistaken deletion is recoverable. Delete the household on purpose and the backups age out too.

  • Every change is logged

    Each change to your household's data is recorded with who made it and when, so we can answer "what happened" without guessing.

Found something that looks wrong? Write to security@cubbyjar.com. A person answers, usually within a day.

Read the privacy policy