Privacy Policy - RiseOhana

Privacy Policy

Effective Date: March 2026

RiseOhana helps families turn household responsibilities into quests that kids actually want to do. That means your child's data passes through our hands. We take that seriously.

This page has two parts. Part 1 is a plain-English summary of what we collect, why, and what you can do about it. Part 2 is the full legal policy with every detail. Both parts say the same things — Part 1 just says them faster.

Who this is for: Parents and legal guardians of children under 13. You are our user. Your child participates through you.

Who we are: RiseOhana, Inc., a Delaware C-Corporation. We are the sole operator of the RiseOhana mobile app.

Questions? Email privacy@riseohana.com. We respond within 7 business days.

What We Collect

We only collect what the app needs to work. Here is what that looks like, based on how you and your child use RiseOhana.

When you create a parent account

  • Name and email address — from your sign-in provider (Google, Apple, or Microsoft)
  • Family name — you provide this during setup
  • Authentication tokens — generated automatically to keep you signed in

When you add a child

  • First name or nickname — you choose what to share
  • Birth month and year only — we do not collect the full date of birth. We use this for age eligibility and to tailor quest difficulty to your child's developmental stage.
  • Avatar selection — your child picks their look in the app

When your child completes a quest

  • Photo evidence — your child submits a photo showing the completed task
  • AI verification result — the photo is analyzed by OpenAI to check if the quest was done (see “Who Sees Your Data” below)
  • Quest activity data — assignment, completion timestamps, your review decisions

When your child earns rewards

  • Points and allowance amounts — calculated by the app when you approve a quest
  • Wallet balance and transaction history — visible to you in the parental dashboard

When your child uses their own device

  • Session token and encrypted setup code — generated when you scan a QR code to set up the child's device
  • PIN hash — your child's PIN is hashed; we never store the actual PIN
  • Push notification token — a Firebase Cloud Messaging (Android) or Apple Push Notification (iOS) token so we can send quest reminders and activity alerts to your child's device. This token is app-specific, changes on reinstall, and is deregistered when your child logs out.

These are session-scoped or app-scoped identifiers, not persistent hardware identifiers.

Automatically

  • Device session logs — kept for 90 days for security and troubleshooting, then deleted

What We Don't Collect from Kids

This matters. RiseOhana does not collect any of the following from children:

  • Email addresses
  • Physical addresses
  • Phone numbers
  • Social Security numbers or government IDs
  • Precise geolocation
  • Persistent device identifiers (IMEI, MAC address, IDFA, AAID)
  • Behavioral advertising profiles or interest-based tracking data
We do not serve ads to children. The app is ad-free for kids.

Who Sees Your Data

We share data with five service providers. That's it. No ad networks, no analytics platforms, no data brokers.

OpenAI — Quest Photo Verification & AI-Assisted Authoring

When your child submits a quest photo, it goes to OpenAI's Vision API for automated analysis. OpenAI receives: the photo, the quest description, and your child's age range. OpenAI does not receive your child's name, your name, or any contact information. OpenAI retains photos for up to 30 days for abuse monitoring, then deletes them. They do not use photos to train AI models. We have a Data Processing Agreement in place.

If you use the optional AI-assisted authoring feature, the messages you type to our assistant go to OpenAI to generate quest suggestions. Your child's name is removed (replaced with a placeholder) before those messages are sent. OpenAI processes them as a service provider — it does not train on them or sell them. This is your own data as an adult, not your child's.

Why this isn't optional: AI quest verification is how RiseOhana works — it's how the app checks whether the task was actually done. This is a core part of the service, like how Stripe processes payments.

Stripe — Payment Processing (Parent Only)

Stripe handles subscription billing. They receive your payment method and billing info. They do not receive any child data — no photos, no quest data, no child names.

OAuth Providers — Sign-In (Parent Only)

Google, Apple, or Microsoft handle your sign-in. They provide us your name and email. They do not receive any child data.

Firebase Cloud Messaging — Push Notifications (Parent and Child)

Google's Firebase Cloud Messaging (FCM) delivers push notifications to both parent and child devices. FCM receives a device-specific push token and notification content (e.g., “You have a quest due!”). FCM does not receive your child's name, photos, quest data, or any personal information beyond the push token. We use FCM solely for notification delivery — not for Firebase Analytics, crash reporting, or any other Firebase service.

Email Provider — Notifications (Parent Only)

We use an email service to send you transactional messages (consent verification, account notifications). Your child's first name may appear in these emails in context (e.g., “You approved Emma's quest”). Children do not receive email from RiseOhana.

That's the complete list.

We do not use: Firebase Analytics, behavioral analytics (Mixpanel, Amplitude), crash reporting SDKs (Sentry, Crashlytics), advertising SDKs, social media plugins, or data brokers.

How Long We Keep It

Data Retention Then What
Child photos 30 days Auto-deleted
Photo metadata (AI score, timestamps) 1 year Auto-deleted
Quest activity data 1 year Auto-deleted
Device session logs 90 days Auto-deleted
Push notification tokens Until logout or account deletion Deregistered and deleted
Wallet & transaction history 3 years Deleted (financial records)
Parental consent records 3 years or account lifetime Retained for COPPA compliance
Child profile data Account lifetime Deleted when account is deleted
Parent account data Account lifetime Deleted when account is deleted

Backups: After data is deleted from our primary systems, it may persist in automated backups for up to 90 additional days. Backups are used only for disaster recovery.

Your Rights as a Parent

Under COPPA, you have strong rights over your child's data. We honor all of them, promptly and without charge.

  • Review — See everything we've collected about your child. In-app: Parental Dashboard > Child Data & Privacy. Or email us.
  • Delete — Request deletion of specific photos, specific data categories, or the entire child account and all associated data. We process deletions within 24 hours.
  • Stop collection — Refuse further collection at any time. Your child's account goes read-only.
  • Withdraw consent — Revoke your consent entirely. Processed within 48 hours.
  • Get a copy — Request a portable export (CSV or JSON) of your child's data. Delivered within 30 days.
  • No penalty — We will never deny service, charge extra, or reduce quality because you exercised your rights.

How to reach us

In-AppParental Dashboard > Child Data & Privacy
Emailprivacy@riseohana.com
Phone[To be added]

Security

  • All data encrypted in transit (HTTPS/TLS) and at rest (database-level encryption)
  • Passwords and PINs hashed with BCrypt
  • Role-based access controls — parents see only their family's data
  • Child sessions are temporary and session-based
  • Third-party providers vetted and bound by Data Processing Agreements
  • Access to child data is logged for compliance and security review

No security system is perfect. In the event of a breach affecting children's data, we will notify you and applicable regulators as required by law.

Changes to This Policy

If we make a material change — new data collection, new third parties, changed retention periods — we will:

  1. Email you before the change takes effect
  2. Post the updated policy in the app and on our website
  3. Get new parental consent if required by COPPA — material changes that involve new data collection or new third-party sharing will not take effect until you provide updated consent

Read the Full Privacy Policy

© 2026 RiseOhana, Inc. • Delaware C-Corporation