← Back to PointSprout PointSprout

Privacy Policy

Effective date: July 2026  ·  Developer: Cypress Avenue Design, LLC
The short version: PointSprout is built by parents, for parents. We collect only what is strictly necessary to run the app for your family. We never sell your data. We never advertise to you. We never track you across apps or websites. PointSprout is an annual subscription — cancel anytime, and your data stays yours.

1. Who We Are

PointSprout is published by Cypress Avenue Design, LLC, a limited liability company. When this policy says "we," "us," or "our," it refers to Cypress Avenue Design, LLC.

Questions? Email us at patrick@cypressavenuedesign.com.

2. Who This App Is For

PointSprout is designed for parents and legal guardians (18+) to manage a behavior point system for children in their care. The parent-facing interface requires an adult Apple ID. A simplified child-facing mode exists for children, but all content visible in that mode is set by the parent — children cannot independently create an account, modify settings, or submit personal information without parent action.

3. What Information We Collect

Information You Provide

Data Who provides it Why we need it Where it is stored
Parent name (e.g., "Mom") Parent, during onboarding Stamped on transactions for attribution ("Mom awarded 5 pts"). This is a nickname you type; it is separate from, and not derived from, the name Apple may provide below. Device (app preferences) + Firestore
Name and email address Apple, via Sign in with Apple — only if you choose to share them (Apple lets you hide your name and substitute a private relay email) Account identification; the name you share, if any, becomes your account's display name Firebase Authentication
Child name Parent, during onboarding or kid setup Identify each child's point account Device (SwiftData) + Firestore
Child birthday (optional) Parent, during onboarding or kid setup — only if you choose to add it Shown on the child's profile, and used on your device to suggest age-appropriate activities (guidance from the AAP, CDC, and USDA). Age matching happens on the device — the birthday itself never leaves your family. Optional — you can leave it blank or remove it anytime. Device (SwiftData) + Firestore
Child profile photo (optional) Parent — or the child on a parent-configured kid device, applied only after a parent approves it Display the child's avatar in the app. A photo chosen on a kid device is held for parent review and deleted if the parent declines it. Device (SwiftData) + Firebase Storage
Kid Mode background image (optional) Parent — or the child on a parent-configured kid device, applied only after a parent approves it Personalize the child's Kid Mode screen. An image chosen on a kid device is held for parent review and deleted if the parent declines it. Device (local file) + Firebase Storage (only while awaiting review)
Point transactions and history Parent (by recording earn/lose/spend actions) Core functionality — tracking points Device (SwiftData) + Firestore
Rewards, activities, schedules Parent App configuration Device (SwiftData) + Firestore
Achievements and badges (including custom ones) Parent or child Display badges and goals, and track each child's progress Device (SwiftData) + Firestore
Family messages and point transfers Children and parents, via the in-app messaging interface Messaging, point gifts, and loans between family members Device (SwiftData) + Firestore
Reward requests, custom suggestions, and make-up challenges Children and parents, via the in-app request flow Lets a child request a reward or screen time, suggest a new reward, or claim an activity for a parent's approval (may include free text a child types) Device (SwiftData) + Firestore
Screen Time selection (apps to lock) Parent Screen Time enforcement feature Device only (app preferences, not uploaded)

Information Collected Automatically

Data Why we need it Where it is stored
Firebase Authentication UID Unique account identifier; links parent and kid devices to the correct family Firebase Authentication + Firestore
Anonymous Authentication UID (kids) Links a kid's device to the family account without requiring an Apple ID Firebase Authentication + Firestore
Family memberships Records which families you have created or joined, and your role in each (owner, co-parent, or caregiver) Firestore (under your user record and on each family record)
Firebase Cloud Messaging (FCM) device token Required to deliver push notifications (check-in reminders, reward approvals, messages, Screen Time alerts). The token is tied to your device and is shared across any families you belong to. Firestore (under your user record)
Subscription status Lets everyone in your family unlock the app from the owner's subscription. Includes an active/expired flag, a billing grace-period flag, the product identifier, the renewal/expiry date, the subscribing account's ID, and the subscription's anonymous App Store transaction identifier (see section 5). We never receive your payment details or App Store receipt — Apple handles all billing. Firestore (on your family record) + cached on-device (app preferences)
What we never collect:

4. How We Use Your Information

We do not use your data for any purpose beyond operating PointSprout for your family.

Sharing within your family

PointSprout lets you invite other people to a family using an invite code. You can invite a co-parent (full access) or a caregiver such as a grandparent, babysitter, or nanny (can record and manage points but cannot change who is in the family). Joining always requires your approval. Entering an invite code only sends a request to join; an owner or co-parent must approve it before that person — or a child's device — gains any access to the family. The code by itself never grants access, so a code that is shared, forwarded, or guessed cannot let anyone in without an approval, and you can deny a request you don't recognize. Invite codes are also single-use and time-limited. Everyone you approve can see all of that family's information — your children's names, birthdays, profile photos, point history, rewards, achievements, and family messages — so only approve people you trust with your children's information.

The owner can remove any co-parent or caregiver, and a co-parent can remove caregivers — at any time. Removal immediately revokes that person's access and regenerates the invite code so the old one can no longer be used; the removed person is notified. We keep a small internal record of a removal (including that device's notification token) only long enough to deliver the notice; it is deleted immediately afterward.

One account can belong to more than one family — for example, a caregiver who helps two households. Each family's data is stored separately; you can only access families you are a member of, and switching between them never mixes their information.

5. How We Share Your Information

We share data with no advertising networks, data brokers, or analytics companies. The only third-party services that process your data are:

Aside from the family members you invite (see "Sharing within your family" above), we do not share your family's data with anyone. We may disclose information if required by law, but we will notify you to the extent we are legally permitted to do so.

6. Children's Privacy (COPPA)

PointSprout is designed to comply with the Children's Online Privacy Protection Act (COPPA).

If you believe a child under 13 has independently provided personal information to us without parental consent, please contact us immediately at patrick@cypressavenuedesign.com.

7. Data Security

8. Data Retention

Your family's data is retained only for as long as you keep your account or your families. There is no separate archive — deleting your account or a family removes that data from our systems; it is not hidden or held for later. You can remove your data in two ways:

In rare circumstances — for example, if your device loses its internet connection at the exact moment a deletion runs — some data can survive the cleanup. If that ever concerns you, email us at patrick@cypressavenuedesign.com and we will remove anything left behind within 30 days. You can also use that address for any deletion request at any time.

9. Your Rights

All users:

California residents — under the California Consumer Privacy Act (CCPA), you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise any right, contact us at patrick@cypressavenuedesign.com.

10. Third-Party Links and Services

PointSprout does not contain links to third-party websites and does not integrate with social media platforms, advertising networks, or third-party analytics SDKs beyond Firebase (described above).

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Continued use of the app after changes are posted constitutes acceptance of the revised policy. We will make reasonable efforts to notify users of material changes via the app or App Store release notes.

12. Screen Time and Family Controls

PointSprout optionally uses Apple's Family Controls framework and Screen Time API to lock selected apps on a child's device. This feature:

13. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or your data, please contact us:

Cypress Avenue Design, LLC
Email: patrick@cypressavenuedesign.com

We will respond to privacy-related requests within 30 days.


Return to PointSprout home

© 2026 Cypress Avenue Design, LLC · PointSprout — no ads, no tracking. Cancel anytime. We never sell your data.