ChildStep is a family goal- and routine-tracking app for parents/guardians and their children. A parent or guardian sets up a family (the creator is the Organizer), adds other adults (Parent/Guardian) and their children, and plans goals and their steps. Because the app is about children's routines, it involves children's personal data, which we treat with special care.
App terms: Goal = something a child works toward; Step = a task within a goal on the child's daily list; Schedule = the family's weekly timetable; Cheer = a small encouragement on a completed step; Organizer/Parent/Guardian/Child = family roles.
1. Who controls the data
Truong Pham Xuan is the data controller for account data. Within a family, the Organizer and any Parent/Guardian members manage that family's data, including their children's profiles.
2. What we collect
We collect only what the app needs. We do not run advertising or third-party analytics/tracking SDKs, and we do not collect location, health, financial, contacts, or browsing data.
| Data | Examples | Why |
|---|---|---|
| Account | Email, Google account identifier, display name (from Google Sign-In) | Create/secure your account, sign you in |
| Family & child profiles | Member/child names, optional birth year/age, profile photos | Show who a goal/step belongs to |
| Content you create | Goals and their steps, weekly schedule, comments, "cheers", completions | Provide the core features |
| Photos | Images you pick from your library (avatars) | Personalise the app; the app opens the photo library only — never the camera or microphone |
| Device push token | An Expo push identifier | Send the reminders/notifications you enable |
| On-device cache | A local copy of your family's data | Work offline / load quickly |
| Crash reports | Error type, stack trace, app version, device model — with your family's names and emails removed before sending | Find and fix crashes |
Children's data (names, ages/birth years, photos, routines) is entered by the parent/guardian and used only to provide the app to that family. We never use it for advertising or profiling.
3. How we use it
Provide and sync the app across the family's devices; send reminders/notifications you enable; keep the service secure and working (authentication, abuse-prevention such as rate limiting). We do not sell personal data or share it for anyone's marketing or advertising.
4. Legal bases (GDPR, where applicable)
- Contract — to provide the app you signed up for.
- Consent — for children's data we rely on verifiable parental consent: the parent affirms consent in-app and confirms via a link we email them, before any child data is collected ("email-plus"). Parents can withdraw consent anytime by deleting the data.
- Legitimate interests — keeping the service secure and functional.
5. Service providers (sub-processors)
We use these providers strictly to run the service, under their data-processing terms:
- Google Sign-In — authentication.
- Sign in with Apple — authentication on iOS. If you choose Apple's private email relay, Apple forwards our mail without giving us your real address.
- Google Cloud SQL for PostgreSQL — application database (United States – us-central1), reachable only over a private network address, with no public endpoint.
- Google Cloud — backend hosting (Cloud Run) and photo storage (Cloud Storage), United States – us-central1.
- Cloudflare — reverse proxy and TLS termination for childstep.app, and protection against abuse. Requests are served from the Cloudflare location nearest to you, which may be outside the United States and the European Union; Cloudflare processes them in transit and does not store your family's data.
- Expo — push-notification delivery (Expo Push Service). A notification's text includes who did what — a member's display name and the title of a step — so that text passes through Expo on its way to your phone.
- Sentry — crash and error reporting (United States). Crash reports are stripped of personal data before they leave the device: no account identity, no request contents, no log messages that could carry a member's name.
Apple Push (APNs) and/or Firebase Cloud Messaging may be added for push delivery; any new sub-processor is added here before it ships. No advertising SDKs are used.
6. Data retention & deletion
- We keep your data while your account is active.
- Delete in the app anytime: Settings → Manage data → Delete account. If nobody else can manage a family after you go — an adult who was added but never signed in cannot — that family is permanently deleted with everything in it: children's profiles, goals, steps, schedule, comments and reactions. Where somebody else can, the family stays and only your account is removed from it. Before you confirm, the app shows you each of your families, what happens to it, and why.
- You can also request deletion via our data-deletion page or by emailing support@childstep.app.
- Backups are purged within 30 days. Server logs contain no child personal data.
7. Your rights
Depending on your region (GDPR/UK GDPR and others) you may access, correct, delete, export/port, or restrict processing of your data, and lodge a complaint with a supervisory authority. Account deletion and data export are available in the app (Settings); or contact support@childstep.app.
8. Children's privacy (COPPA §312 / GDPR Article 8)
ChildStep is set up and operated by a parent or guardian. A child does not create their own account without parental involvement — they join only via a parent's invite. We obtain verifiable parental consent (Section 4) and give the parent this notice before a child's personal data is collected, and we don't require more child data than necessary. Parents can review and delete their child's data anytime (Section 6). We do not knowingly collect children's data without parental consent.
9. How we protect data
- Encrypted in transit (HTTPS/TLS).
- The on-device cache is excluded from device backups and erased on sign-out and account deletion; auth tokens are held in the device's secure keychain/keystore.
- Least-privilege access to production data.
10. International transfers
Your family's data is stored in the United States (us-central1). Requests travel to us through the Cloudflare location nearest you, which may be in another country, and are processed there only in transit. Where required for transfers from the EEA/UK, we rely on Standard Contractual Clauses.
11. Changes to this policy
We'll post changes here and update the "Effective date"; significant changes will be notified in the app or by email.
12. Contact
Truong Pham Xuan — support@childstep.app