CairnPrivacy Policy
Effective [EFFECTIVE DATE]
⚠ Draft — not yet in force
This document is an unfinished draft. It still needs the publisher’s details filled in and a review by a qualified lawyer before it can be relied on. Nothing here is legal advice, and it does not yet constitute an agreement.
Operator: set LEGAL_ENTITY, LEGAL_CONTACT_EMAIL, LEGAL_JURISDICTION, LEGAL_DATA_REGION and LEGAL_EFFECTIVE_DATE to remove this notice, and have counsel review the wording first.
Cairn is a family financial-education tool published by [LEGAL ENTITY NAME](“we”). It is used by a parent and the children that parent adds. This policy explains what we hold, why, and what you can do about it.
The short version: we collect the minimum needed to run the app, we do not advertise, we do not sell or share personal information, we have no analytics or tracking SDKs of any kind, and we never ask a child for an email address, phone number, or location.
Information about a parent
- Your email address and display name, used to sign you in and address you.
- Your password, which is stored only as a hash by our authentication provider. We cannot read it.
- If you enable two-factor authentication, the secret needed to verify your codes.
- If you subscribe, a customer and subscription identifier from our payment processor. We never receive or store your card details.
- Records of actions you take in the app (approving chores and payouts, creating loans, resetting a PIN), kept as an audit history for your own household.
Information about a child
A child account is created by a parent, and a parent can see everything in it. We collect:
- A display name and a username chosen by the parent.
- A birth year only — never a full date of birth — used solely to pitch wording at the right reading age. It is optional.
- A PIN, stored only as a hash by our authentication provider, and never readable by us or by you. Resetting replaces it.
- Their activity in the app: accounts and ledger entries, chores completed, savings goals and contributions, loans, rewards redeemed, lessons passed, and the free-text reflections a child writes as part of a lesson.
- Their chosen avatar appearance and the name they give it.
- If notifications are enabled on a device, the browser-issued push subscription for that device. It identifies a browser, not a person.
What we deliberately do not collect about a child
No email address, no phone number, no full date of birth, no home address, no location or GPS data, no photographs, no contacts, no school information, no government identifiers, and no bank or card credentials. A child account uses an internal, non-routable identifier that cannot receive mail, so there is no inbox attached to your child.
There is also no social layer: no messaging, no friends, no public profiles, no user-generated content visible to anyone outside your household. A child cannot be contacted through Cairn.
Children’s privacy and parental consent (COPPA)
Cairn is designed for a parent to use together with their own children, and child accounts exist only because a parent created them. We record your consent at the moment you create a child account, including the method and time.
As the parent, you can at any time:
- Review everything we hold about your child, by downloading a complete export from the Kids screen.
- Delete your child’s account and personal information from the same screen (see Retention below for the one exception).
- Withdraw consent by deleting the child account, or the household.
We do not condition a child’s participation on disclosing more than is reasonably necessary, we do not use children’s information for advertising or profiling, and we do not disclose it to third parties for their own purposes.
How we use information
To operate the app: authenticate sign-ins, keep the ledger, show balances and projections, send the notifications you have opted into, provide support if you ask, keep the audit history, and handle billing. That is all.
We do notuse your family’s data for advertising, sell or rent it, share it with data brokers, or use it to build profiles.
Artificial intelligence
One feature uses an AI model: the daily market-news summary written for children. The request that generates it contains only the date — no names, balances, goals, or activity. One summary is produced per day and shown to everyone, so there is nothing personal in it.
We do not send your family’s data to any AI provider, and your family’s data is not used to train any model.
Who else can see data
We use a small number of providers to run the service:
- Our hosting and database provider, which stores the application data and handles authentication.
- Our payment processor, for parent subscriptions only. It never receives information about your children.
- An AI provider, for the market summary described above (date only).
- Your browser vendor’s push service, if you enable notifications, in order to deliver them.
We have no advertising networks, analytics services, session recorders, or third-party trackers. Fonts are bundled at build time, so displaying a page does not call out to a font service.
We may disclose information if legally required, or to protect someone’s safety.
Cookies
We set cookies for one purpose: keeping you signed in. There are no advertising, analytics, or cross-site tracking cookies, so there is nothing to consent to beyond using the app.
Security
- Every household’s data is isolated by database-level access rules, not by application code alone — and that isolation is covered by automated tests that must prove a cross-household read is denied.
- Passwords and PINs are stored only as hashes.
- Optional two-factor authentication for parents, enforced everywhere once enabled.
- Repeated wrong PINs lock a username temporarily, counted so that unknown usernames cannot be probed.
- The financial ledger is append-only, so history cannot be quietly rewritten.
No system is perfectly secure, and we do not claim otherwise. Data is stored in [DATA STORAGE REGION].
Retention and deletion
We keep information for as long as your household uses Cairn. Deleting a child removes their sign-in, profile, and personal records — chores, goals, loans, and lesson work.
One deliberate exception:ledger entries remain, because they are the household’s financial history and the ledger is append-only by design. When a child is deleted, those entries are detached from them and the account is relabelled so that no child’s name or identifier remains in what is kept.
Your choices
- Notifications are off until you turn them on, and can be turned off again.
- Birth year is optional.
- You decide which external account balances, if any, you enter.
- You can export or delete a child’s data at any time.
Changes
If we change how we handle data, we will update this page and its effective date. Material changes affecting children’s information will be brought to your attention rather than made quietly.
Contact
Questions, or a request about your family’s data: [PRIVACY CONTACT EMAIL].
See also the Terms of Service and the Parent FAQ, which explains the same things in plainer language.