Privacy Policy

Who this is for

Tidiest is operated by Tidiest LLC ("we", "us"). This Privacy Policy explains what information we collect, why, and your rights as a parent or legal guardian. Tidiest is intended to be set up and controlled by a parent or legal guardian who is at least 18 years old. Children do not have their own accounts and cannot agree to this policy.

Our commitment to children's privacy (COPPA)

Tidiest is designed for households with children, including children under 13, and we comply with the U.S. Children's Online Privacy Protection Act (COPPA). Before we collect a child's nickname/profile information or enable child photo submission, a parent must review the child-data, child-photo, and AI-verification notice and give verifiable consent. Only after that consent may the parent create a child profile with a nickname and optional private non-photo display symbol, and pair the child's device. Auto Mode requires the additional blocking notice version 2026-07-30-auto-mode-v1 and a separate verifiable parent authorization before a child may send a before photo for chore suggestions. We collect the minimum information needed to run parent-managed chores, bounded Auto suggestions, AI-assisted chore verification, parent review, and rewards.

What we collect from the parent

• Identity: Tidiest uses Sign in with Apple for parent accounts. We verify Apple's identity token server-side, store only the stable Apple subject or a protected hash plus minimal email relay metadata when Apple provides it, and issue an opaque Tidiest session token. • Subscription status: your Tidiest Family plan and verified trial, paid, grace, expiry, revocation, and recovery dates. Apple processes payments; we never see your card details. Our Cloudflare Worker verifies an App Store-signed transaction bound to your household before family data is saved or reopened. • Parent-supplied reward codes: if you create a manual-code reward, Tidiest stores the single-use code encrypted with its optional descriptive face value and currency. Tidiest does not sell, purchase, fund, validate, or track the monetary balance of gift cards. • Parent-selected room photos: only when you choose parent room planning. Those images are face-checked, downscaled, stripped of metadata on your device, and sent through our Worker to Amazon Bedrock/Nova Pro. They are discarded after suggestions by default. Before the first reference-enabled save, you can instead choose to keep the complete sanitized single-photo derivative privately linked to the chores saved from that scan so assigned children can use it as a framing reference.

What we collect about a child

• After parental notice and verifiable consent, a child profile UUID, a nickname you choose, such as "Kid 1", and an optional private non-photo display symbol the child may change. • Chore photos the child submits after parental consent, child-profile creation, and pairing. For separately authorized Auto Mode, this can include one sanitized before photo shared by up to three chores and one separate sanitized after photo for each completed chore. A photo of a child is personal information under COPPA, which is why the camera path stays locked until the parent consent stack is complete and visible faces are rejected on-device. • Chore results: the AI verification result, any parent review or override, and the points earned. • Chore titles, finish rules, reward values, reward menu items, and redemption history that you create for the household. We do not collect a child's real name, email, phone number, precise location, profile photo, public profile, advertising identifier, or tracking identifier. Chore details are not used to build an AI profile of a child, and the private display symbol is not sent to AI providers, public records, or evidence metadata. Photo location metadata (EXIF/GPS) is stripped on the device before a chore photo is uploaded as evidence.

How we use chore photos

A child submission uploads only sanitized evidence to private R2-compatible object storage through a short-lived URL minted by Tidiest's Cloudflare Worker. The raw photo is never uploaded; metadata is stripped, images are downscaled, visible faces are rejected before upload, the bucket is not public, and parent review uses short-lived authorized download URLs. Evidence metadata, such as evidence ID, purpose role, opaque storage reference, status, approximate size, and deletion dates, is kept in Tidiest's backend evidence metadata store. If AI verification is enabled, /verify-chore resolves the evidence only after household authorization, active Family access, consent, and the applicable locked chore rules pass. For separately authorized Auto Mode, one sanitized before photo may be sent transiently to Amazon Nova Pro through Amazon Bedrock to return zero to three visually grounded suggestions from a closed safe-category list. After the child commits selected suggestions, each ordinary chore uses that locked before photo and its own exclusive after photo for completion verification. Unsafe, sensitive, unclear, unsupported, or hidden-work scenes return no suggestions; ambiguous, private, unsafe, or sensitive verification results require parent review. Auto rewards are disabled per child by default. Optional parent room planning remains separate and processes only room photos deliberately selected by the parent.

Third parties we share with

• Apple: Sign in with Apple supports parent identity, and Apple processes App Store subscriptions. Children do not use Sign in with Apple. • Cloudflare Worker, D1, Durable Objects, Queues, R2, and evidence metadata storage: Cloudflare hosts Tidiest's service code for parent room planning, AI chore verification, purchase verification, household authorization, QR/code pairing, evidence signed URLs, redemption, bonus, and ledger signing. D1 stores canonical app rows and Durable Objects serialize household mutations. Sanitized child chore evidence is stored briefly in private R2-compatible object storage. Enabled room references are stored separately in a dedicated private R2 bucket with household-scoped metadata and chore links in D1. Neither bucket has public object URLs, and the Worker never returns object keys. • Amazon Bedrock / Amazon Nova Pro: receives sanitized parent room photos for optional chore planning and, after the applicable parental consent and authorization, sanitized child chore evidence for the limited purposes of bounded Auto suggestions or chore-completion verification. It does not receive a child's nickname, public profile, or real name from Tidiest. Tidiest does not permit child evidence to be used for model training, model improvement, child profiling, personalization, or unrelated AI use. AWS states that neither AWS nor third-party model providers use Amazon Bedrock inputs or outputs to train Amazon Nova, Amazon Titan, or third-party models, and that inputs and outputs are not shared with model providers. • Resend: sends parent-only transactional email. It receives the verified parent's email address and the minimum message content needed for a two-day annual-trial reminder or a 30-day or 7-day recovery warning. Depending on the notice, that content is limited to the applicable trial or deletion date, whether the trial is scheduled to renew, fixed subscription/recovery and support links, and a brief summary of Tidiest Family. Resend never receives child names, chores, balances, photos, or child identifiers from this flow. Tidiest disables open and click tracking and does not use Resend for marketing. We do not sell personal information, share it for advertising, or use third-party advertising or tracking SDKs.

Features Tidiest does not provide

Tidiest has no public child profiles, profile pictures, open chat, child messaging, public leaderboards, advertising, behavioral tracking, sale of personal information, face recognition, biometric identification, or child-facing AI/paywall surface. A private display symbol is not a profile picture and is never public.

How long we keep information

We keep each kind of information only as long as it is reasonably necessary, never indefinitely, then delete it. This is our data-retention policy; the same policy is also published in full as a standalone Data Retention Policy. • Chore photos (the review copy): approved evidence is deleted after roughly 72 hours. Rejected or disputed evidence may be retained for up to 30 days unless you delete it sooner. Abandoned or unconfirmed uploads are deleted after 24 hours. That window is deliberate - long enough for you to review a child's work, and no longer. Photos are stored only as private R2-compatible evidence objects and parent review uses short-lived authorized URLs. Auto Mode before evidence remains locked only while an issued set or linked chore needs it for verification or parent review, then follows the same 24-hour, roughly 72-hour, or up-to-30-day rule. The Worker sends evidence to Bedrock only transiently for the authorized request. • Parent-selected room photos: held only while the room-planning request is running, then discarded when chore suggestions return by default. Opted-in room-reference objects and metadata are queued for deletion as soon as Family access expires or is revoked and are not restored. They are also deleted after their final chore link is removed, when their child or household is deleted, or after 24 hours if an upload is never linked. • Structured household data—including child profiles, chores, ledgers, balances, rewards, pairing credentials, and consent records—remains recoverable for 12 calendar months after expiry or revocation. Resubscription before deletion begins cancels structured deletion and pending warnings. Immediate child or account deletion removes the applicable data without that recovery window. • Device pairing codes become unusable 24 hours after creation. The stable paired-device credential follows the structured-data recovery window unless the parent revokes pairing or deletes the child or account. • Your version-stamped consent record follows the structured-data recovery window as proof that consent was given; renewed consent is required before restored child data reopens. • The age-verification signal at setup: never stored - reduced to a yes/no result and immediately discarded. A child's nickname and private display symbol follow the structured-data recovery window and are deleted when recovery ends or when the child or account is deleted sooner.

Your rights as a parent

You can review every child photo and decision, correct decisions subject to the displayed spent-points limitation, choose Off, Auto, or Auto-trusted separately for each child, keep Auto rewards off, disable AI chore verification, or revoke Auto Mode authorization. Revocation turns every child's Auto policy off and blocks new Auto capture, suggestions, commits, and verification. You can also disable future room-reference attachment, remove a reference from an individual chore, remove a child and related app rows and private objects, delete child data, or revoke child-photo consent to disable future photo submission. Contact support@tidiest.app for assistance.

Security

Your family's household data lives in Cloudflare D1, with household mutations serialized by Durable Objects, while sanitized chore evidence and opted-in room references live in separate private R2-compatible buckets. A child's session can read only references linked to that child's active chores; reads stream through the authenticated Worker with private, no-store caching. A child's session can submit evidence but cannot alter its own points balance or mint parent review URLs. Points are authoritative because only our Worker can issue signed ledger records: every entry is cryptographically signed, and the app trusts only signed balances. Child-visible records contain only opaque reference IDs, never object keys or public image URLs. Parent-supplied reward codes are encrypted in the dedicated rewards database and revealed only to the authenticated child after parent approval. No system is perfectly secure, but we apply reasonable measures appropriate to the sensitivity of children's data. The full set of safeguards is published as our Information Security Program.

Changes & contact

If we make a material change to how we handle children's information, we will ask the parent to review and consent again before the change applies to your household. Questions or requests, or to reach the operator: Tidiest LLC, 12851 Tilden Dr., Rancho Cucamonga, CA, United States · +1 (909) 646-2488 · support@tidiest.app. This policy is governed by the laws of the State of California, United States.