Sprout Privacy Policy
Last updated: July 19, 2026
Sprout is a family chore, allowance, and money-management app operated by [OPERATOR NAME] ("we", "us"). Sprout is designed for families: parents and guardians ("parents") set up the family, and children use the app under their parent's supervision. Because children use Sprout, this policy is written to comply with the U.S. Children's Online Privacy Protection Act (COPPA), and we hold ourselves to its standard for every child user worldwide.
The short version: we collect only what Sprout needs to work, we never show ads, we never sell or rent anyone's data, children's accounts are created and controlled by their parents, and parents can review, export, or permanently delete their family's data at any time from inside the app.
1. Who this policy covers
- Parents / guardians — adults who create a family, administer it, and create accounts for their children.
- Children — family members whose accounts are created by a parent, or who join using an invite code that a parent controls and chooses to share. A parent-created account signs in with a username and needs no email address; an invite-code signup instead uses an email address as its sign-in identifier and has no username (the exact data for each path is listed in section 2).
2. Information we collect
We collect only the information needed to run Sprout. We do not collect precise location, contacts, photos (other than an optional avatar), or browsing history, and we do not use third-party advertising or tracking analytics.
From parents
- Name, email address, and a password (stored only as a secure one-way hash).
- Family settings you configure (family name, timezone, allowance rules, allocation percentages, and similar preferences).
From and about children
- Account sign-in details, which differ by how the account was created:
- Created by a parent in the app: a first name or nickname and a username, both chosen by the parent, plus a password. An email address is optional.
- Joined using the parent's invite code: a name, an email address (which becomes the child's sign-in identifier), and a password. These accounts have no username. Parents who prefer their child to have no email on file can create the account themselves instead of sharing the code.
- A password (stored only as a secure one-way hash) and, on shared devices, an optional short PIN (also stored only as a hash).
- An optional avatar image URL.
- Activity inside the app: chores and their completion, jobs claimed and submitted, virtual account balances and transactions, spending goals, achievements, XP, streaks, and notifications. Sprout balances are a family ledger, not real money — Sprout is not a bank and holds no funds.
- Feedback or help questions a child chooses to type into the app.
Collected automatically (all users)
- Authentication cookies (an httpOnly session token and, if shared-device mode is used, an opaque device identifier). These are used solely to keep you signed in securely and to support the internal operations of the service — never for advertising or cross-site tracking.
- Push notification subscription endpoints, if you turn notifications on.
- Language and theme preferences.
3. How we use information
- To provide the service: chores, jobs, allowances, virtual balances, goals, notifications, and family administration.
- To keep accounts secure (authentication, session management, PIN lockouts).
- To answer help questions, including through the optional Sprout AI help assistant (see section 5).
- To fix problems and improve Sprout using feedback that users submit.
We do not use anyone's information — child or adult — for advertising, profiling, or marketing, and we do not sell or rent personal information. Ever.
4. Children's privacy (COPPA)
- Parental consent is built into how Sprout works. A child's account can only exist because their parent created it in the app, or because the parent deliberately shared the family's private invite code with them. Creating the account (or sharing the code) is the parent's consent to the collection described in this policy. Parents can also disable registration or rotate/expire the invite code at any time.
- We collect the minimum from children. A parent-created child account needs only a display name, a username, and a password (email optional); a child who signs up with the invite code provides a name, an email address for sign-in, and a password (no username). Either way, no phone number, address, or precise location is ever required or requested.
- Children's information is never made public. Everything a child does in Sprout is visible only inside their own family (and to us, as the operator, for running the service).
- Persistent identifiers (cookies and device identifiers) are used only to support Sprout's internal operations — sign-in, security, and remembering preferences — which COPPA permits without separate consent. They are never used for behavioral advertising.
- Parents stay in control. At any time a parent can:
- Review everything collected about their child directly in the app, or download it with the data-export tool (Settings → Privacy & Data).
- Delete a child's account and all of their data (Settings → Members), or delete the entire family (Settings → Privacy & Data).
- Refuse further collection by deleting the account — Sprout collects nothing from a child without an account.
- Questions about a child's data can also be sent to [CONTACT EMAIL]; we will verify you are the child's parent or guardian before acting.
5. Service providers (who else sees data)
We share personal information only with the service providers that host and power Sprout, and only so they can provide those services to us:
- Microsoft Azure — hosts the Sprout application and database.
- Microsoft Azure AI services — when someone uses the optional Sprout AI help assistant, the question they typed (and limited family context needed to answer it, such as family members' first names) is processed by an AI model hosted in our Azure environment. Help questions are not used to train AI models.
- Push notification services (Apple, Google, or Mozilla, depending on your browser/device) — deliver notifications you opted into.
These providers are bound to use the data only to provide the service. We do not share personal information with advertisers, data brokers, or any other third parties. We may disclose information if required by law, or to protect the safety of our users.
6. Data retention and deletion
- We keep your family's data for as long as the family account exists.
- When a parent deletes a child's account, that child's personal information is deleted immediately. When a parent deletes the family, all accounts and all family data are deleted immediately.
- Deleted data may persist in encrypted database backups for a limited period (up to 35 days) before those backups are automatically overwritten.
7. Data export
Parents can download a complete, machine-readable copy of their family's data (JSON format) at any time from Settings → Privacy & Data. The export includes every family member's profile, accounts, transactions, chores, jobs, goals, and activity.
8. Security
- Passwords and PINs are stored only as bcrypt hashes — we cannot read them.
- All traffic is encrypted in transit (HTTPS/TLS), and session tokens live in httpOnly cookies that page scripts cannot read.
- Every query is scoped to your family; one family can never see another family's data.
No system is perfectly secure, but if we learn of a breach affecting your data we will notify affected families promptly.
9. Your rights
Wherever you live, you can access, export, correct, or delete your family's personal information using the in-app tools described above, or by contacting us. If your local law (for example the GDPR or a U.S. state privacy law) grants you additional rights, we will honor them — contact us at [CONTACT EMAIL].
10. Changes to this policy
If we change this policy in a way that materially affects children's data, we will notify parents (by email or an in-app notice) and, where the law requires, obtain fresh consent before the change applies. The "Last updated" date at the top always reflects the current version.
11. Contact us
Operator: [OPERATOR NAME] Email: [CONTACT EMAIL]
If you are a parent with any question about your child's information, we're happy to help.