PointSprout is published by Cypress Avenue Design, LLC, a limited liability company. When this policy says "we," "us," or "our," it refers to Cypress Avenue Design, LLC.
Questions? Email us at patrick@cypressavenuedesign.com.
PointSprout is designed for parents and legal guardians (18+) to manage a behavior point system for children in their care. The parent-facing interface requires an adult Apple ID. A simplified child-facing mode exists for children, but all content visible in that mode is set by the parent — children cannot independently create an account, modify settings, or submit personal information without parent action.
| Data | Who provides it | Why we need it | Where it is stored |
|---|---|---|---|
| Parent name (e.g., "Mom") | Parent, during onboarding | Stamped on transactions for attribution ("Mom awarded 5 pts"). This is a nickname you type; it is separate from, and not derived from, the name Apple may provide below. | Device (app preferences) + Firestore |
| Name and email address | Apple, via Sign in with Apple — only if you choose to share them (Apple lets you hide your name and substitute a private relay email) | Account identification; the name you share, if any, becomes your account's display name | Firebase Authentication |
| Child name | Parent, during onboarding or kid setup | Identify each child's point account | Device (SwiftData) + Firestore |
| Child birthday (optional) | Parent, during onboarding or kid setup — only if you choose to add it | Shown on the child's profile, and used on your device to suggest age-appropriate activities (guidance from the AAP, CDC, and USDA). Age matching happens on the device — the birthday itself never leaves your family. Optional — you can leave it blank or remove it anytime. | Device (SwiftData) + Firestore |
| Child profile photo (optional) | Parent — or the child on a parent-configured kid device, applied only after a parent approves it | Display the child's avatar in the app. A photo chosen on a kid device is held for parent review and deleted if the parent declines it. | Device (SwiftData) + Firebase Storage |
| Kid Mode background image (optional) | Parent — or the child on a parent-configured kid device, applied only after a parent approves it | Personalize the child's Kid Mode screen. An image chosen on a kid device is held for parent review and deleted if the parent declines it. | Device (local file) + Firebase Storage (only while awaiting review) |
| Point transactions and history | Parent (by recording earn/lose/spend actions) | Core functionality — tracking points | Device (SwiftData) + Firestore |
| Rewards, activities, schedules | Parent | App configuration | Device (SwiftData) + Firestore |
| Achievements and badges (including custom ones) | Parent or child | Display badges and goals, and track each child's progress | Device (SwiftData) + Firestore |
| Family messages and point transfers | Children and parents, via the in-app messaging interface | Messaging, point gifts, and loans between family members | Device (SwiftData) + Firestore |
| Reward requests, custom suggestions, and make-up challenges | Children and parents, via the in-app request flow | Lets a child request a reward or screen time, suggest a new reward, or claim an activity for a parent's approval (may include free text a child types) | Device (SwiftData) + Firestore |
| Screen Time selection (apps to lock) | Parent | Screen Time enforcement feature | Device only (app preferences, not uploaded) |
| Data | Why we need it | Where it is stored |
|---|---|---|
| Firebase Authentication UID | Unique account identifier; links parent and kid devices to the correct family | Firebase Authentication + Firestore |
| Anonymous Authentication UID (kids) | Links a kid's device to the family account without requiring an Apple ID | Firebase Authentication + Firestore |
| Family memberships | Records which families you have created or joined, and your role in each (owner, co-parent, or caregiver) | Firestore (under your user record and on each family record) |
| Firebase Cloud Messaging (FCM) device token | Required to deliver push notifications (check-in reminders, reward approvals, messages, Screen Time alerts). The token is tied to your device and is shared across any families you belong to. | Firestore (under your user record) |
| Subscription status | Lets everyone in your family unlock the app from the owner's subscription. Includes an active/expired flag, a billing grace-period flag, the product identifier, the renewal/expiry date, the subscribing account's ID, and the subscription's anonymous App Store transaction identifier (see section 5). We never receive your payment details or App Store receipt — Apple handles all billing. | Firestore (on your family record) + cached on-device (app preferences) |
We do not use your data for any purpose beyond operating PointSprout for your family.
PointSprout lets you invite other people to a family using an invite code. You can invite a co-parent (full access) or a caregiver such as a grandparent, babysitter, or nanny (can record and manage points but cannot change who is in the family). Joining always requires your approval. Entering an invite code only sends a request to join; an owner or co-parent must approve it before that person — or a child's device — gains any access to the family. The code by itself never grants access, so a code that is shared, forwarded, or guessed cannot let anyone in without an approval, and you can deny a request you don't recognize. Invite codes are also single-use and time-limited. Everyone you approve can see all of that family's information — your children's names, birthdays, profile photos, point history, rewards, achievements, and family messages — so only approve people you trust with your children's information.
The owner can remove any co-parent or caregiver, and a co-parent can remove caregivers — at any time. Removal immediately revokes that person's access and regenerates the invite code so the old one can no longer be used; the removed person is notified. We keep a small internal record of a removal (including that device's notification token) only long enough to deliver the notice; it is deleted immediately afterward.
One account can belong to more than one family — for example, a caregiver who helps two households. Each family's data is stored separately; you can only access families you are a member of, and switching between them never mixes their information.
We share data with no advertising networks, data brokers, or analytics companies. The only third-party services that process your data are:
Aside from the family members you invite (see "Sharing within your family" above), we do not share your family's data with anyone. We may disclose information if required by law, but we will notify you to the extent we are legally permitted to do so.
PointSprout is designed to comply with the Children's Online Privacy Protection Act (COPPA).
If you believe a child under 13 has independently provided personal information to us without parental consent, please contact us immediately at patrick@cypressavenuedesign.com.
Your family's data is retained only for as long as you keep your account or your families. There is no separate archive — deleting your account or a family removes that data from our systems; it is not hidden or held for later. You can remove your data in two ways:
In rare circumstances — for example, if your device loses its internet connection at the exact moment a deletion runs — some data can survive the cleanup. If that ever concerns you, email us at patrick@cypressavenuedesign.com and we will remove anything left behind within 30 days. You can also use that address for any deletion request at any time.
All users:
California residents — under the California Consumer Privacy Act (CCPA), you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise any right, contact us at patrick@cypressavenuedesign.com.
PointSprout does not contain links to third-party websites and does not integrate with social media platforms, advertising networks, or third-party analytics SDKs beyond Firebase (described above).
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Continued use of the app after changes are posted constitutes acceptance of the revised policy. We will make reasonable efforts to notify users of material changes via the app or App Store release notes.
PointSprout optionally uses Apple's Family Controls framework and Screen Time API to lock selected apps on a child's device. This feature:
If you have questions, concerns, or requests related to this Privacy Policy or your data, please contact us:
Cypress Avenue Design, LLC
Email: patrick@cypressavenuedesign.com
We will respond to privacy-related requests within 30 days.
© 2026 Cypress Avenue Design, LLC · PointSprout — no ads, no tracking. Cancel anytime. We never sell your data.