Pluck is made for families: parents assign quests on their own phones, and each kid sees them as a game on theirs. This policy explains what the app stores, where, and why. It is written to be read by parents; a kid never has to agree to anything inside the app.
No accounts, no email
Pluck does not ask for names of adults, email addresses, phone numbers or passwords. Each phone signs in to our backend anonymously and receives a random identifier. A six-character code, shown on a parent’s phone, links other phones to the same family.
What a family stores
- Family data: the family name, each kid’s first name, age and, if the parent set it, whether the kid is a girl or a boy (used only so that languages with grammatical gender address the kid correctly), the parents’ display names and chosen avatars, and the app’s settings (quiet hours, auto-approve threshold, the grown-up code stored as a hash).
- Game data: quests and their status, coins, levels, streaks, badges, rewards and redemptions, and a short activity feed.
- Proof photos: when a quest asks for a photo, the kid’s phone takes one. It is stored privately for the family so a parent’s phone can review it. The app never asks for location, so photos carry no location; they are capped at 5 MB, can be deleted by any parent, are removed from our servers as soon as a parent has approved the quest or asked for a redo, and any photo that slips past that (a quest reset, deleted or re-shot) is swept within a day or two. The copy on the kid’s phone is deleted at the same moment.
- Push tokens: if you allow notifications, the phone’s push token is stored so that “quest submitted” and “quest approved” pings can reach the right phone. A token is visible only to the phone it belongs to and to the notification service.
Where it lives
Everything works on the phone first. When a backend is configured, family data is synced through Supabase (hosted Postgres, storage and realtime), with row-level security so that each phone can read only its own family, and a kid’s phone only its own kid. Data in transit is encrypted with TLS. The sign-in session on each phone is encrypted with a key held in the device’s Keychain or Keystore.
What we do not do
- No advertising, no ad identifiers, no third-party analytics or tracking SDKs.
- No chat, no social features, no contact with people outside the family.
- No sale or sharing of family data with anyone. Subprocessors are limited to hosting (Supabase), push delivery (Expo push service and the Apple / Google notification services) and, once subscriptions are enabled, the app stores’ billing.
Children
Pluck is a mixed-audience app. Kids’ phones show only the game: quests, coins, rewards and a buddy character. Leaving the game on a parent’s phone requires the family’s grown-up code. We collect from kids only what the parent enters (first name, age, optionally girl or boy) and what the game itself produces (quest progress, optional proof photos). The buddy’s “repeat after me” feature records the kid’s voice for a few seconds, plays it back once on the phone and deletes it; it never leaves the phone. Parents control all of it and can delete it at any time.
Deleting your data
On a parent’s phone, open Family and choose “Erase”. Leaving as the last parent deletes the whole family from our servers: every kid, quest, reward, feed entry and proof photo, and unlinks every phone. A kid’s phone is unlinked the moment a parent issues a new code for that kid or removes the kid; a removed kid’s name, age and game data disappear from every phone at once and are purged from our servers within 30 days. You can also write to privacy@pluck.family and we will delete a family on request.
Changes
If this policy changes in a way that matters, the app will say so on the parent side before the change applies.