🍪CookieCal
Terms of ServiceSupport
Last updated: July 12, 2026 — DRAFT (pre-legal review)

Privacy Policy

CookieCal is built for families. We take children's privacy seriously — not as a legal checkbox, but as a core product value.

Plain-language summary: CookieCal collects only what's needed to run the app. We never sell data, never show ads, and never behaviorally profile children. All minor-account settings default to maximum privacy. Parents control everything.

1. Overview

This Privacy Policy describes how CookieCal ("CookieCal," "we," "us," or "our") collects, uses, and protects information when you use our web application, mobile application, and related services (collectively, the "Service").

CookieCal is a task management, time-awareness, and family coordination platform designed for children (ages approximately 4–18) and the adults who care for them — parents, guardians, educators, and caretakers.

This Policy applies to all users: parents, guardians, children, caretakers, educators, and Cheer Squad members.

If there is a conflict between this Policy and applicable law, the law governs. We comply with the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA) where applicable, the California Consumer Privacy Act (CCPA/CPRA), and applicable state Age-Appropriate Design Code laws (California AADC, Connecticut, Maryland, Texas, and others).

2. Who We Are

CookieCal is operated by its founding team. Our contact for privacy matters is:

We are pursuing COPPA Safe Harbor certification through an FTC-approved program (kidSAFE or iKeepSafe). Until certification is complete, this policy represents our best-effort compliance commitment and will be updated upon certification.

3. What We Collect

3.1 Parent / Guardian Accounts

  • Name and email address (required for account creation)
  • Password (stored as a salted cryptographic hash — never in plaintext)
  • Payment information when subscribing — processed exclusively by Stripe; CookieCal never stores raw card data
  • Family configuration: names and profiles of children added to the account
  • Support chat messages (if you use our in-app support feature)
  • Optional: profile avatar, display name, subscription tier

3.2 Child / Kid Accounts

All child accounts are created exclusively by a verified parent or guardian. Children cannot self-register.
  • First name (or nickname) — provided by parent
  • PIN or Kid Code for login — no email required for children
  • Task and schedule data: tasks assigned, completion status, timestamps, coin values
  • Mood check-in scores (1–5 scale) — visible only to the linked parent account
  • Journal entries (text and photos) — stored privately, visible only to the child and their linked parent
  • Photo uploads attached to task completions — visible to parent; not shared outside the family unit
  • Pet state data (species, level, earned items) — stored to persist the virtual pet experience
  • AI Pet Chat and AI Tutor conversation content — see Section 8 (AI Disclosure)
  • Canvas drawings (if the Drawing feature is used)
  • Memory entries with optional photos and notes
  • Sensory profile preferences (motion settings, color modes, font preferences)

3.3 Educator / Teacher Accounts

  • Name and school email address
  • Classroom roster (student names only — no student email addresses required)
  • Class codes, schedule data, IEP/504 export requests
  • Teacher-generated notes on students (private by default)

3.4 Caretaker Accounts

  • Name (provided by the inviting parent)
  • Scoped access to the child data categories the parent explicitly enables — never broader
  • Messages sent through the Care Team messaging system

3.5 Automatically Collected Data

  • Session tokens (used to keep you logged in — stored as HTTP-only cookies)
  • IP address and browser/device user agent (stored with sessions for security; not used for profiling)
  • Error logs for debugging (no personal content from these logs is retained beyond 30 days)

3.6 What We Do NOT Collect

  • No advertising identifiers (IDFA, GAID, or equivalent)
  • No third-party tracking pixels, cookies, or SDKs
  • No persistent device fingerprinting
  • No children's email addresses (children log in via PIN or Kid Code)
  • No biometric data
  • No location data beyond what you explicitly provide (e.g., a school name)

4. COPPA Compliance & Children Under 13

The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal information from children under 13. CookieCal's architecture is built around this requirement.

4.1 Verifiable Parental Consent

CookieCal collects verifiable parental consent through the credit card / payment method requirement at account creation. The use of a payment instrument by an adult to create the account constitutes the verified consent mechanism. We do not create child profiles without this consent gate.

At the time of account setup, the parent is presented with a clear consent screen (the "Parental Gate") that explicitly discloses:

  • What data is collected from child accounts
  • That child data is never shared with third parties for advertising purposes
  • That the parent controls and can delete all child data at any time
  • A link to this full Privacy Policy and our Terms of Service

4.2 Data Minimization for Under-13 Accounts

For children under 13, we collect the minimum data necessary to operate the service:

  • No email address from the child themselves
  • No phone number
  • No geolocation beyond the family's general timezone (if set)
  • Login is via PIN or Kid Code only — no external identity provider

4.3 No Behavioral Advertising of Children — Ever

CookieCal does not and will never:

  • Serve behavioral advertising to any user, child or adult
  • Build advertising profiles based on any user's activity
  • Sell or rent any user data to third parties
  • Allow third-party advertising SDKs in the codebase

5. Privacy by Default (Age-Appropriate Design Code Compliance)

All settings for minor accounts default to the highest privacy option available. This is not a preference — it is a hard architectural choice made at account creation and enforced in our code.

Consistent with California's Age-Appropriate Design Code (AADC), Connecticut's Act Concerning Data Privacy (SB 3), Maryland's Online Data Privacy Act, and similar state laws, CookieCal defaults are:

  • Cheer Squad: Disabled by default. Parents opt-in and control all invitations.
  • Mood data: Visible to linked parent only. Not shared with any caretaker unless explicitly enabled by the parent on a per-caretaker basis.
  • Journal entries: Private to the child and linked parent. Not visible to caretakers, educators, or Cheer Squad members.
  • Photos: Stored privately. Not shared beyond the linked family unit unless the parent explicitly shares (e.g., a milestone card screenshot).
  • Reduce Motion: Available as a setting but not forced on — no default animation state is designed to be manipulative or addictive.
  • AI conversations: Not shared externally. Visible to linked parent. Not used to train models (see Section 8).
  • No dark patterns: CookieCal does not use countdown timers, social pressure mechanics, or other design techniques that manipulate children into spending more time in the app.

6. How We Use Data

We use collected data solely to:

  • Provide and improve the CookieCal service
  • Authenticate users and maintain secure sessions
  • Process subscription payments through Stripe
  • Send transactional emails (account confirmation, password reset, payment receipts, trial ending notices) through Resend
  • Generate AI-powered responses in the Pet Chat and AI Tutor features
  • Generate IEP/504 progress reports on parent request
  • Respond to support inquiries
  • Content moderation and safety alert generation (see Section 13)

We do not use data to:

  • Target advertising of any kind
  • Build behavioral profiles for sale or licensing
  • Share with data brokers
  • Train AI models on your personal or child data (see Section 8)

7. Third-Party Data Processors

We disclose all third-party services that process user data. We do not use any ad networks, social widgets, or tracking SDKs.

Stripe
Payments
Data shared: Payment card data, billing address, email address
Purpose: Processing subscription payments and managing billing
Privacy Policy →
Resend
Transactional Email
Data shared: Email address, name (for personalization)
Purpose: Sending account-related emails (welcome, receipts, password reset, trial reminders)
Privacy Policy →
Google Gemini 2.5 Flash / OpenAI GPT
AI Processing
Data shared: Text content of AI conversations (Pet Chat, AI Tutor, support assistant)
Purpose: Generating AI responses
Privacy Policy →
Uploadcare
File Storage
Data shared: Photos and images uploaded by users
Purpose: Storing and serving user-uploaded images (task photos, journal photos, avatars)
Privacy Policy →
Neon (PostgreSQL)
Database Hosting
Data shared: All structured app data (profiles, tasks, sessions)
Purpose: Hosting the application database
Privacy Policy →

We require all processors to implement appropriate security measures and to use data only for the specified purpose. None of our processors are authorized to use CookieCal user data for their own advertising or analytics purposes.

8. AI Features Disclosure

CookieCal uses AI to power the Pet Chat companion, the AI Tutor assistant, and the parent support chat. This section discloses specifically how AI works in our service.

8.1 What AI Features Are Available

  • AI Pet Chat: Children can converse with their virtual pet. Responses are generated by an AI language model.
  • AI Tutor: Provides guided academic support for homework and learning tasks.
  • AI Support Assistant: Answers parent questions about CookieCal features and account management.
  • AI Schedule Assistant: Helps parents build task schedules from plain-language descriptions.

8.2 What Data Is Sent to AI Providers

When a user interacts with an AI feature, the text content of the conversation (and, in some features, limited context like the current task list or schedule) is sent to our AI provider (currently Google Gemini or OpenAI GPT, depending on feature) for processing. This is necessary to generate a response.

8.3 Data Retention by AI Providers

We configure our AI API calls to not allow the provider to use submitted data for training their models. We use API access (not consumer products), which provides data-processing agreements that prohibit training on user data.

8.4 Parent Visibility

All AI Pet Chat conversations are stored in our database and are visible to the linked parent account. Parents may view and delete conversation history at any time.

8.5 Content Safety

AI features include content-safety filtering to prevent inappropriate outputs. Our AI system prompts are designed to keep conversations age-appropriate, educationally focused, and never collecting personal information from children.

8.6 AI Is Not a Professional

AI features in CookieCal are tools to support — not replace — parental guidance, professional tutoring, therapy, or educational assessment. AI responses may occasionally be inaccurate. Do not rely solely on CookieCal AI for graded, high-stakes, medical, psychological, or legal matters.

9. FERPA / Educator Mode

For users of CookieCal's Educator / Classroom Mode, the following applies:

9.1 School Official Exception

When schools formally integrate CookieCal Classroom Mode under a written Data Privacy Agreement (DPA), CookieCal may qualify as a "school official" under FERPA with a legitimate educational interest in the student data it processes. We do not claim this exception without a formal DPA in place.

9.2 Student Data Minimization

Educator accounts do not require student email addresses. Students are identified by first name only within the classroom system. No student data from Classroom Mode is used for advertising or shared beyond the classroom context.

9.3 Data Privacy Agreements

Schools and districts may request a formal DPA. Contact hello@cookiecal.com to initiate this process. Our DPA framework is designed to comply with the Student Data Privacy Consortium (SDPC) framework and applicable state student privacy laws.

9.4 Home-School Data Bridge

The optional home-school data link (connecting a child's family CookieCal account to a classroom record) requires explicit, affirmative consent from the parent. It can be revoked by the parent at any time with immediate effect.

10. Data Retention & Deletion

10.1 How Long We Keep Data

  • Active accounts: Data is retained as long as the account is active.
  • After cancellation: Account data is retained for 90 days to allow account reactivation. After 90 days of inactivity post-cancellation, data is permanently deleted.
  • Payment records: Stripe retains payment records per their own data retention policies and applicable financial regulations. We retain billing records for 7 years as required by law.
  • Error logs: Retained for 30 days maximum.
  • Support conversations: Retained for 12 months from the date of the conversation.

10.2 Self-Service Deletion

Parents can permanently delete their entire account — including all child profiles, tasks, photos, journal entries, and associated data — through the self-service account deletion flow at Settings → Account → Delete Account. Deletion is immediate and irreversible. We confirm deletion via email.

10.3 Requesting Deletion by Email

If you need assistance with data deletion or want to export your data before deleting, email hello@cookiecal.com. We will respond within 72 hours and complete any requested deletion within 30 days.

10.4 Child Data Deletion Requests

Parents may request deletion of a specific child's data without deleting their own account. This can be done through Settings → Kids → [Child Name] → Remove from Family. This action permanently deletes all data associated with that child profile.

11. Parental Rights

Under COPPA, parents of children under 13 have the following rights regarding their child's data. CookieCal extends these rights to all minor users regardless of age:

  • Right to review: Parents may review all data collected from their child at any time through the parent dashboard, or by emailing us.
  • Right to delete: Parents may request deletion of any or all of their child's data (see Section 10).
  • Right to refuse further collection: Parents may delete the child's account to stop further data collection.
  • Right to correct: Parents may update any inaccurate child profile data through the parent dashboard or by contacting us.
  • Right to restrict processing: Parents may disable specific features (AI, journal, photos) through the feature toggles in Settings.

To exercise any of these rights, use the tools in the parent dashboard or contact us at hello@cookiecal.com. We will respond to rights requests within 30 days.

12. TAKE IT DOWN Act Compliance

The TAKE IT DOWN Act (effective 2026) requires platforms to remove reported non-consensual intimate imagery (NCII) within 48 hours of a valid report.

CookieCal is a children's app and does not permit, tolerate, or knowingly host intimate imagery of any kind. Should any such content be reported:

  • Reports must be submitted to hello@cookiecal.com with the subject line "TAKE IT DOWN REPORT."
  • We will acknowledge receipt within 24 hours.
  • Reported content will be reviewed and removed within 48 hours of a valid report.
  • User accounts that upload such content will be immediately suspended pending investigation.
  • Where legally required, we will report CSAM (child sexual abuse material) to NCMEC immediately upon discovery.

We also use automated content moderation on uploaded images. Our content moderation pipeline is designed to flag and prevent distribution of such content before it reaches any other user.

13. Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Passwords are hashed using Argon2 (a memory-hard algorithm resistant to brute-force attacks)
  • Session tokens are HTTP-only, secure cookies (not accessible to JavaScript)
  • Database access is restricted to application servers only; no public database access
  • Payment card data is never stored by CookieCal — all payment processing is delegated to Stripe's PCI-DSS compliant infrastructure

No security system is perfect. If you discover a vulnerability, please disclose it responsibly to hello@cookiecal.com. We will respond within 48 hours.

14. Policy Changes

We will notify users of material changes to this Privacy Policy by:

  • Posting the updated policy at cookiecal.com/privacy with a revised "last updated" date
  • Sending an email to the parent account email address on file
  • Displaying an in-app notice on next login for 14 days after the change

For changes that materially reduce privacy protections for children, we will re-obtain parental consent before implementing the change.

15. Contact Us

For any privacy questions, rights requests, or concerns:

🏫 Educator & school inquiries: hello@cookiecal.com
🌐 Website: https://cookiecal.com

We respond to all privacy inquiries within 72 hours and complete substantive requests within 30 days.

⚖️ Legal Review Notice: This is a well-researched draft privacy policy. It is NOT a substitute for review by a licensed attorney specializing in children's privacy, ed-tech law, or consumer privacy. Before wide public launch, this policy should be reviewed by qualified legal counsel. Nothing in this document constitutes legal advice.
Terms of ServiceSupportHome

© 2026 CookieCal — No ads, no trackers, no data sold.