Last updated 2026-09-05 · Operator: KyrosWorks LLC, Texas, USA · [email protected]
The short version
ChoreKey is a parental-controls app for families with children ages 8–17. We do not sell data. We do not run ads. We do not use analytics SDKs. We do not let third parties track your family.
What we do with your data depends on which app you use:
ChoreKey (iPhone, $2.99 one-time; Android, free): everything stays on your child's device. No cloud, no account.
ChoreKey+ (iPhone only, $4.99 one-time in-app upgrade): chore data and photos sync to a cloud backend so you can approve chores remotely. That backend is your own iCloud account via Apple CloudKit; we cannot see it.
Cloud sync is off by default. It only turns on once a parent buys ChoreKey+ and pairs it to a child's iPhone.
Things that are always true, at every tier
Phone calls always go through. On iPhone, ChoreKey locks only the apps and categories you choose in Apple's picker; iOS itself keeps phone calls and FaceTime reachable, and Messages and Maps are locked only if you choose to lock them (Lockdown mode locks every category except the apps you allow). On Android, phone calls, Messages, Maps, the camera, the emergency dialer, and Settings are never offered in the picker and can never be locked.
No analytics SDKs. No Google Analytics, Firebase, Mixpanel, Segment, Amplitude, or anything equivalent. There are no third-party SDKs in either app that report usage back to us or anyone else.
No advertising IDs. We do not read your Advertising Identifier (IDFA / AAID). We do not show ads.
No selling data. We do not, and will not, sell, rent, or trade any data to anyone, including anonymized or aggregated data.
No profiling for marketing. We do not build profiles of children or parents for advertising or behavioral targeting.
No accounts on your child's device. The ChoreKey app never asks for an email, phone number, or password. Pairing uses a one-shot token, not a user account.
You can delete everything. A parent can request full deletion at any tier. We act within 30 days, including from backups. Email [email protected] from the email tied to your Parent app sign-in.
ChoreKey alone (default, no-cloud mode)
Everything stays on your child's device. Nothing leaves the device. This is what you get on iPhone for $2.99, or on Android for free, before any ChoreKey+ upgrade.
What's stored, and where (all local, on your child's device)
Chore photos: stored in the app's private file storage. A cleanup that runs each time the app opens removes photos seven days after a parent approves or returns the chore.
Home geofence coordinate: the latitude/longitude of "home" you set during setup. Never transmitted.
PIN code: the 4-digit parent-approval PIN, stored as a hash. We never see it.
App settings and notification preferences.
What we don't do at this tier
We do not collect, transmit, or store anything on our servers. There are no servers.
We do not log a location history. The app only asks the OS, "Are you inside the geofence right now?" We never see coordinates.
The camera is used only for chore photos. Photos stay in the app's private storage.
No analytics, no crash reports, no telemetry. The app does not phone home.
On iPhone, ChoreKey uses Apple's Family Controls framework to lock and unlock apps; the framework runs entirely on-device, and selections of which apps are blocked never leave the device. The Android app locks and unlocks apps the same way, on-device, with no equivalent cloud step. On both platforms, a parent approves each chore in person, with the parent PIN, on the child's own device; ChoreKey+ remote approval is iPhone only for now.
ChoreKey+ (cloud sync turns on)
When a parent buys ChoreKey+ and pairs it to a child's iPhone, chore data and photos sync to a cloud backend so the parent can approve chores remotely. That backend is your own iCloud account via Apple CloudKit. ChoreKey+ is iPhone only; it is not available for Android devices.
Cloud sync is off by default. It enables only after the parent completes the pairing flow, which requires Sign in with Apple plus a confirmation tap on the child's device.
What syncs to the cloud at this tier
Chore records: title, description, schedule, due time, completion and approval status, and the chore's point value.
Chore photos: stored in your own iCloud account via CloudKit. See "Where your photos live" below.
Photo quality check: the pass or fail result of an on-device check for a blank or unreadable photo, so a bad photo can be flagged before you review it. The check itself runs on the device; only the pass/fail result syncs.
Pairing metadata: which children's devices are paired to which parent accounts, an opaque per-device token (not the device's serial number or advertising ID), the child's first name (your choice what to enter), and for each paired device its name, platform, and app version.
Sync timestamp: the last time each paired device checked in with the cloud. This is a sync timestamp, not a record of how long or how the device was used.
Family timezone: so chores and notifications schedule correctly across every device in the family.
Audit trail: every approval, redo, override, and tamper event, with timestamp.
Tamper events: if Family Controls is revoked or the heartbeat drops, an event is logged so the parent is notified.
Nothing about location leaves the device: the home coordinate and the inside-or-outside state stay on the child's phone.
Where your photos live
Chore photos are the most sensitive thing ChoreKey handles: they are pictures taken by a child inside your home. We treat where they are stored as something you are entitled to know exactly, not in general terms.
We never see or keep the photo. Ever.
With ChoreKey+, the photo never touches our servers, our storage, or our accounts. When your child submits a chore, the image is attached to a record in your own iCloud account and shared to the parent device through Apple's CloudKit sharing. It counts against your iCloud storage, it is governed by your Apple ID, and Apple's private-database model gives app developers no read access to it. We could not retrieve one of these photos if we wanted to, and we could not produce one in response to a request, because we do not hold it.
It stays there until you delete it. Deleting the chore, the child, or the family removes it, and you can delete any individual photo at any time. We do not auto-delete these photos on a timer, because they are not ours to reach into. The copy on the child's own device is cleared automatically seven days after the chore is approved or rejected.
What we do NOT store in the cloud at this tier
Real-time location of the child. We never poll or log coordinates.
Location history of any kind. Nothing about where the child's device has been is stored in the cloud.
The home geofence coordinate, it stays on the child's device.
Phone call logs, message contents, contacts, browsing history, app-usage minute counts, none of this is collected.
Biometric data. Face ID data never leaves the device.
Security
All cloud traffic uses TLS 1.2+ in transit.
Data is encrypted at rest by Apple, as part of CloudKit.
The Approve action in the Parent app prompts for Face ID or Touch ID on devices that have it enrolled; it is a confirmation step, not a lock.
The child's device verifies a signed unlock event before lifting the lock. A child editing local storage cannot self-unlock.
Third parties at this tier
Apple Inc. (ChoreKey+ families). Apple stores the data inside your iCloud account. Apple's privacy policy applies.
Apple Push Notification service. Delivers push notifications. Payloads contain only short messages (e.g. "Mia submitted a chore"); no photos.
No other third party receives data at this tier.
Multi-parent and multi-child
When two parents are paired to the same family, both can see and approve chores for any paired child. Pair as many children as you need on ChoreKey+; each child sees only their own chores. Audit entries identify which parent approved which chore.
Children's data: special handling
ChoreKey is designed for children ages 8–17. We apply additional protections specifically for our youngest users:
We do not sell, rent, trade, or share children's data with advertisers.
We do not build advertising or behavioral profiles of children.
No third-party tracking. The ChoreKey app links no analytics, advertising, or tracking SDKs. It includes a client library (Supabase) from an earlier sync design. On a device that still holds a sign-in from that design, the app may refresh that session and register the device's push token with the service. It never sends chore data, photos, or anything about your children to it.
With ChoreKey+, we never hold a child's photo at all. It goes to your own iCloud account, not to us. The copy on the child's device clears seven days after approval.
The home geofence coordinate is never sent to the cloud. It stays on the child's device.
Parent consent gates every upgrade. Pairing requires the parent to authenticate with Sign in with Apple. Buying ChoreKey+ requires the parent to confirm Apple's own purchase confirmation before cloud sync turns on.
For US families with children under 13, we collect only what is necessary to operate the service the parent purchased, with verifiable parent consent via Apple's account systems and the in-app pairing flow for ChoreKey+. The standalone ChoreKey app, on iPhone or Android, collects nothing beyond what stays on the child's device.
If you believe we have collected information from a child without parent consent, or you want to review or delete information about your child, email [email protected]. We'll act within 30 days.
Your rights
At any tier you can:
See what we have. Email [email protected] from your Parent-app sign-in email; we will send a copy of your family's data within 30 days.
Correct it. Most data is editable in the Parent app. For anything you can't edit, email us.
Delete it. Ask for full deletion. We remove from primary storage immediately and from backups within 30 days. Audit-trail entries also get deleted, note that trade-off.
Export it. JSON export of chore and audit data on request.
Residents of California (CCPA/CPRA), the EU/UK (GDPR), and other jurisdictions with similar rights laws have the rights named in those laws. Email us from your sign-in email and we will honor them. We do not sell data, so the "right to opt out of sale" is already the default.
Changes to this policy
If we change this policy in a way that materially expands what we do with data, we will:
Update the Last updated date at the top.
Show the change in-app the next time you open the Parent app, in plain English.
Require an explicit tap to acknowledge.
We will not roll out a material change quietly via a buried link.