Privacy Policy
RiseOhana helps families turn household responsibilities into quests that kids actually want to do. That means your child's data passes through our hands. We take that seriously.
This page has two parts. Part 1 is a plain-English summary of what we collect, why, and what you can do about it. Part 2 is the full legal policy with every detail. Both parts say the same things — Part 1 just says them faster.
Who this is for: Parents and legal guardians of children under 13. You are our user. Your child participates through you.
Who we are: RiseOhana, Inc., a Delaware C-Corporation. We are the sole operator of the RiseOhana mobile app.
Questions? Email privacy@riseohana.com. We respond within 7 business days.
What We Collect
We only collect what the app needs to work. Here is what that looks like, based on how you and your child use RiseOhana.
When you create a parent account
- Name and email address — from your sign-in provider (Google, Apple, or Microsoft)
- Family name — you provide this during setup
- Authentication tokens — generated automatically to keep you signed in
When you add a child
- First name or nickname — you choose what to share
- Birth month and year only — we do not collect the full date of birth. We use this for age eligibility and to tailor quest difficulty to your child's developmental stage.
- Avatar selection — your child picks their look in the app
When your child completes a quest
- Photo evidence — your child submits a photo showing the completed task
- AI verification result — the photo is analyzed by OpenAI to check if the quest was done (see “Who Sees Your Data” below)
- Quest activity data — assignment, completion timestamps, your review decisions
When your child earns rewards
- Points and allowance amounts — calculated by the app when you approve a quest
- Wallet balance and transaction history — visible to you in the parental dashboard
When your child uses their own device
- Session token and encrypted setup code — generated when you scan a QR code to set up the child's device
- PIN hash — your child's PIN is hashed; we never store the actual PIN
- Push notification token — a Firebase Cloud Messaging (Android) or Apple Push Notification (iOS) token so we can send quest reminders and activity alerts to your child's device. This token is app-specific, changes on reinstall, and is deregistered when your child logs out.
These are session-scoped or app-scoped identifiers, not persistent hardware identifiers.
Automatically
- Device session logs — kept for 90 days for security and troubleshooting, then deleted
What We Don't Collect from Kids
This matters. RiseOhana does not collect any of the following from children:
- Email addresses
- Physical addresses
- Phone numbers
- Social Security numbers or government IDs
- Precise geolocation
- Persistent device identifiers (IMEI, MAC address, IDFA, AAID)
- Behavioral advertising profiles or interest-based tracking data
Who Sees Your Data
We share data with five service providers. That's it. No ad networks, no analytics platforms, no data brokers.
OpenAI — Quest Photo Verification & AI-Assisted Authoring
When your child submits a quest photo, it goes to OpenAI's Vision API for automated analysis. OpenAI receives: the photo, the quest description, and your child's age range. OpenAI does not receive your child's name, your name, or any contact information. OpenAI retains photos for up to 30 days for abuse monitoring, then deletes them. They do not use photos to train AI models. We have a Data Processing Agreement in place.
If you use the optional AI-assisted authoring feature, the messages you type to our assistant go to OpenAI to generate quest suggestions. Your child's name is removed (replaced with a placeholder) before those messages are sent. OpenAI processes them as a service provider — it does not train on them or sell them. This is your own data as an adult, not your child's.
Stripe — Payment Processing (Parent Only)
Stripe handles subscription billing. They receive your payment method and billing info. They do not receive any child data — no photos, no quest data, no child names.
OAuth Providers — Sign-In (Parent Only)
Google, Apple, or Microsoft handle your sign-in. They provide us your name and email. They do not receive any child data.
Firebase Cloud Messaging — Push Notifications (Parent and Child)
Google's Firebase Cloud Messaging (FCM) delivers push notifications to both parent and child devices. FCM receives a device-specific push token and notification content (e.g., “You have a quest due!”). FCM does not receive your child's name, photos, quest data, or any personal information beyond the push token. We use FCM solely for notification delivery — not for Firebase Analytics, crash reporting, or any other Firebase service.
Email Provider — Notifications (Parent Only)
We use an email service to send you transactional messages (consent verification, account notifications). Your child's first name may appear in these emails in context (e.g., “You approved Emma's quest”). Children do not receive email from RiseOhana.
That's the complete list.
We do not use: Firebase Analytics, behavioral analytics (Mixpanel, Amplitude), crash reporting SDKs (Sentry, Crashlytics), advertising SDKs, social media plugins, or data brokers.
How Long We Keep It
| Data | Retention | Then What |
|---|---|---|
| Child photos | 30 days | Auto-deleted |
| Photo metadata (AI score, timestamps) | 1 year | Auto-deleted |
| Quest activity data | 1 year | Auto-deleted |
| Device session logs | 90 days | Auto-deleted |
| Push notification tokens | Until logout or account deletion | Deregistered and deleted |
| Wallet & transaction history | 3 years | Deleted (financial records) |
| Parental consent records | 3 years or account lifetime | Retained for COPPA compliance |
| Child profile data | Account lifetime | Deleted when account is deleted |
| Parent account data | Account lifetime | Deleted when account is deleted |
Backups: After data is deleted from our primary systems, it may persist in automated backups for up to 90 additional days. Backups are used only for disaster recovery.
Your Rights as a Parent
Under COPPA, you have strong rights over your child's data. We honor all of them, promptly and without charge.
- Review — See everything we've collected about your child. In-app: Parental Dashboard > Child Data & Privacy. Or email us.
- Delete — Request deletion of specific photos, specific data categories, or the entire child account and all associated data. We process deletions within 24 hours.
- Stop collection — Refuse further collection at any time. Your child's account goes read-only.
- Withdraw consent — Revoke your consent entirely. Processed within 48 hours.
- Get a copy — Request a portable export (CSV or JSON) of your child's data. Delivered within 30 days.
- No penalty — We will never deny service, charge extra, or reduce quality because you exercised your rights.
How to reach us
| In-App | Parental Dashboard > Child Data & Privacy |
| privacy@riseohana.com | |
| Phone | [To be added] |
Security
- All data encrypted in transit (HTTPS/TLS) and at rest (database-level encryption)
- Passwords and PINs hashed with BCrypt
- Role-based access controls — parents see only their family's data
- Child sessions are temporary and session-based
- Third-party providers vetted and bound by Data Processing Agreements
- Access to child data is logged for compliance and security review
No security system is perfect. In the event of a breach affecting children's data, we will notify you and applicable regulators as required by law.
Changes to This Policy
If we make a material change — new data collection, new third parties, changed retention periods — we will:
- Email you before the change takes effect
- Post the updated policy in the app and on our website
- Get new parental consent if required by COPPA — material changes that involve new data collection or new third-party sharing will not take effect until you provide updated consent
Read the Full Privacy Policy
RiseOhana, Inc. Privacy Policy
Directed to Children Under 13 — COPPA-Compliant Disclosure
This Privacy Policy describes how RiseOhana, Inc. (“RiseOhana,” “RO,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information from users of the RiseOhana mobile application (the “App”), including personal information collected from children under the age of 13 (“Child Users” or “children”). RiseOhana is committed to protecting the privacy and safety of all users, and particularly children, in compliance with the Children's Online Privacy Protection Act (“COPPA”), 15 U.S.C. §6501–6506, and its implementing regulations at 16 C.F.R. Part 312, as amended (effective 2026).
This Privacy Policy is intended to be read by parents and legal guardians (“Parents”) of Child Users. If you are a Parent, please read this Privacy Policy carefully before allowing your child to use the App. By providing verifiable parental consent, you acknowledge that you have read and understood this Privacy Policy and consent to the data practices described herein.
1. Operator Information
RiseOhana, Inc. is a Delaware C-Corporation that operates the RiseOhana mobile application. RiseOhana is the sole operator of the App and is responsible for all data collection and processing described in this Privacy Policy.
| Company Name | RiseOhana, Inc. |
| Incorporation | State of Delaware, United States |
| Privacy Contact Email | privacy@riseohana.com |
| Phone | [To be added] |
| Mailing Address | [To be added] |
For questions or concerns about this Privacy Policy or our data practices, Parents may contact us at privacy@riseohana.com. We will respond within seven (7) business days.
2. Information We Collect
RiseOhana collects personal information from both Parents and Child Users. This section describes, in detail, all categories of personal information collected.
2.1 Information Collected from Parents
| Data Category | Specific Data Elements | Collection Method |
|---|---|---|
| Account Information | Name, email address | Provided via OAuth sign-in (Google, Apple, or Microsoft) |
| Authentication Data | OAuth tokens, refresh tokens | Generated during OAuth authentication |
| Family Information | Family name, parent-child relationships | Parent-provided during account setup |
| Billing Information | Subscription status, payment method tokens, billing history | Processed by Stripe (see Section 4.2) |
| Parental Consent Records | Consent status, consent method, date of consent, data elements consented to | System-generated during VPC process |
| AI Authoring Data (Parent) | The Parent's authoring-conversation messages; short derived notes about the Parent (stated parenting values, goals, or focus) | Parent-provided during an optional AI-assisted authoring session |
Note: RiseOhana does not store credit card numbers or detailed payment instrument data. All payment information is processed and stored by Stripe, our third-party payment processor.
2.2 Information Collected from Child Users
RiseOhana collects the following personal information from children under 13, subject to verifiable parental consent:
| Data Category | Specific Data Elements | Collection Method | Purpose |
|---|---|---|---|
| Child Profile Information | Child's first name or nickname | Parent-provided during child account setup | Account identification and personalization |
| Birth Month and Year | Month and year of birth only | Parent-provided during child account setup | Age eligibility verification and COPPA compliance |
| Photos | Photographs submitted as evidence of quest completion | Child-submitted via device camera or photo gallery | Quest verification (AI-powered and parental review) |
| Quest Activity Data | Quest assignments, completion records, submission timestamps, AI verification results, parental override decisions | System-generated during App use | Quest management, parental dashboard, activity tracking |
| Wallet and Transaction Data | Points earned, allowance amounts, wallet balance, transaction history | System-generated upon quest approval | Allowance and reward management |
| Device Session Data | Session tokens, setup codes (encrypted), PIN hash | System-generated during device provisioning via QR code | Child device authentication |
| Push Notification Token | FCM or APNs token, device fingerprint, platform type | System-generated during app initialization with device permission | Delivering quest reminders, activity alerts, and family notifications |
| Avatar Customization | Avatar selection, background color preferences | Child or Parent-provided | Personalization |
What We Do NOT Collect from Children:
- We do not collect email addresses from children.
- We do not collect physical addresses from children.
- We do not collect telephone numbers from children.
- We do not collect Social Security numbers or government identifiers from children.
- We do not collect precise geolocation data.
- We do not collect persistent device identifiers (such as IMEI, MAC address, IDFA, or AAID).
- We do not use behavioral advertising, interest-based tracking, or profiling of children for marketing purposes.
3. How We Use Information
RiseOhana uses the personal information described in Section 2 solely for the purposes stated below. We do not use children's personal information for any purpose not disclosed in this Privacy Policy.
3.1 Purposes for Child Data
| Data Category | How We Use It |
|---|---|
| Child's Name | To identify the child within the family account; to display the child's name on quests and in the parental dashboard |
| Birth Month and Year | To verify age eligibility; to support COPPA age-gating; to personalize AI quest generation appropriate to the child's developmental stage |
| Photos | To verify quest completion through AI-powered analysis (see Section 4.1); to display quest evidence to the Parent for review; to maintain a record of quest completion during the retention period |
| Quest Activity Data | To operate the quest system (assignment, tracking, and completion); to display activity history in the parental dashboard; to calculate trust metrics (AI accuracy measurement) |
| Wallet and Transaction Data | To manage the child's allowance and point system; to provide transaction history to Parents |
| Device Session Data | To authenticate the child's device session; to maintain secure access during active sessions. Session data is temporary and is not used for tracking |
| Push Notification Token | To deliver quest reminders, activity alerts, and family notifications to the child's device. Not used for advertising, analytics, or tracking. Deregistered on logout and deleted on account deletion |
| Avatar Customization | To personalize the child's in-app experience |
3.2 Purposes for Parent Data
| Data Category | How We Use It |
|---|---|
| Account Information | To identify and authenticate the Parent's account; to send notifications and communications related to the child's activity |
| Family Information | To establish and maintain parent-child relationships within the App |
| Billing Information | To process subscription payments through Stripe; to manage subscription status |
| Parental Consent Records | To document compliance with COPPA; to maintain a verifiable record of parental consent |
| AI Authoring Data (Parent) | To power the optional AI-assisted authoring feature (generate Quest suggestions from the Parent's own description) and to provide continuity across sessions via a small set of Parent-private notes. Processed by OpenAI as a service provider (see Section 4.1). Not used for advertising, profiling, or AI model training. Parent notes are private to the individual Parent and can be viewed and deleted in-app. |
3.3 Prohibited Uses
RiseOhana does not use personal information collected from children for any of the following purposes:
- Behavioral advertising or interest-based targeting of children
- Sale of personal information to any third party for any purpose
- Profiling of children for marketing or commercial purposes
- Training of artificial intelligence models using children's personal information
- Manipulative design patterns (“dark patterns”) that encourage children to provide more personal information or engage in excessive app usage
4. Third-Party Service Providers
RiseOhana shares personal information with the following third-party service providers solely to operate the App and provide the services described in this Privacy Policy. We do not sell, rent, or otherwise disclose children's personal information for marketing, advertising, or any purpose unrelated to the operation of the App.
4.1 OpenAI — AI-Powered Quest Verification
Provider: OpenAI, L.L.C.
Location: United States
Purpose: AI-powered quest verification is a core component of the RiseOhana service. When a child submits a photo as evidence of quest completion, the photo is transmitted to OpenAI's Vision API for automated analysis.
Data Shared with OpenAI:
- Photo submitted by the child (image data)
- Quest completion criteria (text description of the task)
- Child's age range (derived from birth month and year)
Data NOT Shared with OpenAI:
- Child's name
- Child's exact birth date (only age range is shared)
- Parent's name, email, or contact information
- Payment or billing information
- Device identifiers
OpenAI's Obligations: RiseOhana maintains a Data Processing Agreement (“DPA”) with OpenAI that contractually requires OpenAI to: (a) process photos solely for the purpose of providing AI analysis as requested by RiseOhana; (b) not use photos to train, fine-tune, or improve its AI models; and (c) maintain appropriate security measures.
Photo Retention by OpenAI: After processing, OpenAI retains photos for up to thirty (30) days for trust and safety monitoring (abuse and misuse detection), after which the photos are automatically deleted.
Per-Record Deletion Limitation: If you request deletion of a specific photo, RiseOhana will delete it from our primary systems within 24 hours. However, if the photo was previously transmitted to OpenAI, RiseOhana cannot instruct OpenAI to delete that specific photo from its 30-day abuse-monitoring retention. The photo will be automatically deleted from OpenAI's systems no later than 30 days after original submission.
4.1(b) OpenAI — AI-Assisted Authoring (Parent Data)
Purpose: When a Parent uses the optional AI-assisted authoring feature, the Parent's authoring messages — and a small set of short, Parent-private notes derived from them — are transmitted to OpenAI to generate Quest suggestions and to provide continuity across sessions.
Data Shared with OpenAI:
- The Parent's authoring-conversation messages
- The short derived Parent notes (stated parenting values, goals, or focus)
- Limited non-identifying context (child age range, placeholder labels) used to tailor the suggestion
Data NOT Shared with OpenAI:
- Child's name or child-identifying details (removed and replaced with placeholders before transmission)
- Child's exact birth date
- Parent's email or contact information
- Payment or billing information
OpenAI's Obligations: The same Data Processing Agreement described in Section 4.1 applies — OpenAI processes this data solely to provide the requested assistance, does not use it to train, fine-tune, or improve its AI models, does not sell or commercially transfer it, and maintains appropriate security measures. OpenAI acts as a data processor and does not independently collect personal information.
Retention: Consistent with OpenAI's published API data policy, data submitted to the OpenAI API is not used to train or improve OpenAI's models. OpenAI retains these authoring requests for up to thirty (30) days for abuse-monitoring purposes, after which they are automatically deleted — the same window that applies to Quest photos (Section 4.1).
Consenting Adult's Own Data: This flow processes the Parent's own data as a consenting adult — not the child's. Child names and child-identifying details are removed before any authoring message is sent to OpenAI.
4.2 Stripe — Payment Processing
Provider: Stripe, Inc.
Location: United States
Purpose: Subscription billing and payment processing for Parent accounts.
Data Shared: Parent's payment method information, subscription status, billing events, parent's name and email.
Data NOT Shared: Any Child User personal information, photos, quest data, or activity data.
Stripe processes payment data in compliance with PCI-DSS standards. Stripe typically retains billing records for 3–5 years.
4.3 OAuth Authentication Providers — Google, Apple, Microsoft
Purpose: Parent account authentication via OAuth 2.0.
Data Shared: Authentication requests and tokens (standard OAuth protocol).
Data Received: Parent's email address and name (for account creation).
Data NOT Shared: Any Child User personal information, photos, quest data, or activity data.
4.4 SMTP Email Service — Transactional Communications
Purpose: Sending transactional emails to Parents (consent verification, account notifications, deletion confirmations).
Data Processed: Parent email address; email content that may include the child's first name in context.
Data NOT Processed: Children do not receive email from RiseOhana.
4.5 Firebase Cloud Messaging — Push Notifications
Purpose: Delivering push notifications to Parent and Child devices (quest reminders, reward alerts, system messages).
Data Shared: App-specific push notification token (FCM registration token for Android; APNs device token for iOS); notification payload (title, body, category).
Data NOT Shared: Child name, photos, quest content, wallet data, or any other personal information. Notification payloads contain generic prompts (e.g., “You have a quest waiting!”), not personal data.
Token Lifecycle: Push tokens are registered when the app is installed and notification permission is granted; deregistered on logout; deleted from RiseOhana servers on account deletion or anonymization. Tokens are app-specific identifiers — they are not persistent hardware identifiers (IMEI, AAID, IDFA) and cannot be used to track a child across apps or services.
Firebase Data Processing: Google’s Firebase Cloud Messaging acts as a message relay. Google’s FCM data processing terms apply. RiseOhana does not use Firebase Analytics, Firebase Crashlytics, or any other Firebase service.
4.6 No Other Third Parties
RiseOhana does not integrate: advertising networks or ad SDKs, behavioral analytics platforms, crash reporting SDKs, social media plugins, or data brokers.
5. Data Retention and Deletion
RiseOhana retains personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected.
5.1 Retention Schedule
| Data Category | Retention Period | Justification |
|---|---|---|
| Child Photos | 30 days from submission | Parent review, quest verification, dispute resolution |
| Photo Metadata | 1 year from submission | Parental activity history, accuracy measurement |
| Quest Activity Data | 1 year from completion | Parental dashboard history, activity tracking |
| Device Session Logs | 90 days | Security, fraud detection, user support |
| Push Notification Tokens | Active session lifetime | Deregistered on logout; deleted on account deletion/anonymization |
| Wallet and Transaction History | 3 years | Financial record-keeping, dispute resolution |
| Parental Consent Records | 3 years or account lifetime | COPPA compliance documentation |
| Audit Logs | 1 year | Compliance audit and security |
| Child Profile Data | Account lifetime | Account operation |
| Parent Account Data | Account lifetime | Account operation |
5.2 Automatic Deletion
- Photos are automatically deleted from the primary database 30 days after submission.
- Quest activity data and photo metadata are automatically purged 1 year after creation.
- Session logs are automatically purged after 90 days.
5.3 Backup Retention
After data is deleted from the primary database, it may persist in automated backups for up to 90 days. Backups are used only for disaster recovery. RiseOhana cannot delete individual records from backups on a per-record basis.
5.4 Account Deletion
When a Parent requests deletion of a child's account:
- Immediate: The child's account is soft-deleted. Device access is revoked.
- 30-Day Grace Period: Data is retained to allow account restoration.
- Hard Delete (30 days): All child personal information is permanently deleted from the primary database.
- Backup Purge (up to 90 days after): Data is purged from automated backups.
Exceptions: Parental consent records (3 years), financial transaction records (3 years), and audit logs (1 year) are retained beyond account deletion for legal compliance.
5.5 How to Request Deletion
| Method | Details | Timeline |
|---|---|---|
| In-App | Parental Dashboard > Child Data & Privacy > Delete Data | Within 24 hours |
| Send request to privacy@riseohana.com | Within 24 hours of verification | |
| Phone | [To be added] | Within 24 hours of verification |
RiseOhana will send written confirmation within 7 calendar days, specifying the date and categories of data deleted.
6. Parental Rights Under COPPA
Under COPPA, Parents of Child Users have the following rights. RiseOhana honors these rights promptly and without charge.
6.1 Right to Review
Parents may review all personal information collected from their child: profile information, photos (during retention period), quest activity, wallet balance and transactions, AI verification results, and consent history.
How: Parental Dashboard > Child Data & Privacy, or email privacy@riseohana.com. Response within 30 days.
6.2 Right to Request Deletion
Parents may request deletion of specific photos, specific data categories, or the entire child account and all associated data. See Section 5.5.
6.3 Right to Refuse Further Collection
Parents may refuse further collection at any time. The child's account will be placed in read-only mode.
6.4 Right to Withdraw Consent
Parents may withdraw consent at any time via Parental Dashboard > Consent & Privacy Settings > Revoke Consent, or by email. Processed within 48 hours.
6.5 Right to Data Portability
Parents may request a copy of their child's data in CSV or JSON format. Delivered within 30 days via secure download link.
6.6 No Conditioning of Services
RiseOhana does not condition a child's participation on disclosure of more information than is reasonably necessary.
7. Parental Consent
7.1 Verifiable Parental Consent Required
RiseOhana obtains verifiable parental consent (“VPC”) before collecting any personal information from a Child User, in compliance with COPPA Section 312.5.
7.2 How Consent Is Obtained
During child account creation, the Parent is presented with a detailed consent notice covering: data categories collected, purposes, third-party recipients, a link to this Privacy Policy, and parental rights under COPPA.
| VPC Method | Description |
|---|---|
| Email Plus | RiseOhana sends a verification email. The Parent must respond to confirm consent, followed by confirmatory communication. |
7.3 What Parents Consent To
- Collection of child's first name/nickname, birth month and year, photos, quest activity data, wallet data, device session data, and avatar customization
- Use of child's personal information for purposes described in Section 3
- Sharing of photos with OpenAI for AI-powered quest verification
- Retention per the schedule in Section 5
7.4 Consent Records
RiseOhana maintains records of each parental consent (identity, date/time, method, data elements, status) for a minimum of 3 years.
8. Security
8.1 Technical Safeguards
- Encryption in Transit: HTTPS/TLS for all data transmission
- Encryption at Rest: Database-level encryption
- Password Security: BCrypt hashing with salt
- Access Controls: Role-based; internal staff access limited and audited
- Session Management: Temporary, session-based child device sessions via encrypted setup codes and JWT tokens
8.2 Organizational Safeguards
- Data minimization (birth month/year, not full DOB)
- Third-party vetting via Data Processing Agreements
- Audit logging of all actions on child personal information
8.3 Limitations
No security system is perfect. In the event of a data breach affecting children's personal information, RiseOhana will notify affected Parents and applicable regulatory authorities as required by law.
9. Changes to This Privacy Policy
9.1 Material Changes
For material changes, RiseOhana will: (1) notify Parents via email before the change takes effect; (2) post the updated policy; and (3) obtain new parental consent if required by COPPA. Material changes requiring new consent will not take effect for any user until that user’s Parent has provided updated consent.
9.2 Non-Material Changes
Non-material changes (typographical corrections, contact info updates) may be made without advance notice.
9.3 Continued Use After Changes
For material changes requiring new consent, Parents must affirmatively provide updated consent before the new data practices apply to their family. For material changes that do not require new consent, continued use of the App following notice constitutes acceptance of the updated Privacy Policy.
10. Contact Information
| Privacy Contact Email | privacy@riseohana.com |
| Phone | [To be added] |
| Mailing Address | [To be added] |
| Response Time | Within 7 business days |
10.1 Complaints
If you believe RiseOhana has violated your rights or your child's rights under COPPA, you may file a complaint with the Federal Trade Commission:
- Website: ftc.gov
- Phone: 1-877-FTC-HELP (1-877-382-4357)
- Mail: Federal Trade Commission, 600 Pennsylvania Avenue, NW, Washington, DC 20580
11. Additional Disclosures
11.1 Children's Personal Information and Advertising
RiseOhana does not serve advertisements of any kind to Child Users. The App is advertisement-free for children.
11.2 No Sale of Personal Information
RiseOhana does not sell, rent, license, or otherwise commercially transfer personal information collected from children or Parents to any third party.
11.3 Anonymized and Aggregated Data
RiseOhana may create anonymized or aggregated data that can no longer identify a specific individual. Such data is not “personal information” under COPPA and may be used for product improvement, analytics, and reporting. RiseOhana commits that: (a) anonymization uses industry-standard de-identification methods; (b) anonymized data cannot be re-identified to a specific child; and (c) anonymized data is not shared with third parties for marketing or advertising.
11.4 International Users
RiseOhana is based in the United States and processes personal information in the United States.
11.5 California Residents
RiseOhana does not sell or share the personal information of any user, including minors, as defined under the CCPA/CPRA.
12. Definitions
- “App” means the RiseOhana mobile application, available on iOS and Android.
- “Child User” or “child” means an individual under the age of 13 who uses the App under the supervision of a Parent.
- “COPPA” means the Children's Online Privacy Protection Act, 15 U.S.C. §6501–6506, and its implementing regulations at 16 C.F.R. Part 312, as amended.
- “Parent” means a parent or legal guardian of a Child User who holds an account on the App.
- “Personal Information” has the meaning set forth in 16 C.F.R. Section 312.2.
- “Quest” means a task or activity assigned by a Parent to a Child User within the App.
- “Verifiable Parental Consent” or “VPC” means consent obtained from a Parent through a method reasonably calculated to ensure the person providing consent is the child's parent, per 16 C.F.R. Section 312.5.
© 2026 RiseOhana, Inc. • Delaware C-Corporation