Mibo — Privacy Policy

Last updated 26 September 2026. Applies to the Mibo app (com.mibokids.app) and to the Mibo API.

Mibo is a chores and allowance app used by a parent and by their children. It is directed to children, so it is written to comply with the Children’s Online Privacy Protection Act (COPPA) and with Apple’s and Google’s rules for apps children use. The short version: a child using Mibo has no account, gives us no contact details, and is anonymous in everything we measure.

What a parent should know in one minute

Children have no accounts

A parent creates the child’s profile in the app, and a child’s phone or tablet joins the household by entering a short Join Code the parent generates. There is no sign-up, no identity provider and no credential belonging to a child. Because of that, the only things stored about a child are the ones a parent typed or the child’s own use of the app produced:

We do not ask a child for, and do not collect, an email address, a password, a birthday, a precise or coarse location, a phone number, contacts, photos from the camera roll, biometrics or anything else that would identify a child outside their own family’s household.

Parental consent and parental control

A household exists only after a parent signs in, and a child’s device gets access only through a Join Code that a signed-in parent created. Parent mode is protected by a PIN so a child’s device cannot reach it. A parent can, at any time, revoke a child’s device — which immediately and permanently ends that device’s access, and the anonymous analytics identifier it was using is never used again — delete chores and rewards, or ask us to delete the household outright.

Analytics

We use PostHog, hosted in the European Union, to count how the app is used. In parent mode the signed-in parent is identified by their account id and grouped by household. On a child’s device analytics is anonymous: the device is given a random identifier at the moment the Join Code is redeemed, that per-device identifier is retired when a parent revokes the device — a device that joins again is given a new one, and the two cannot be connected, and the only properties attached to it are the interface mode, a broad age band and a one-way hash of the household id. A child’s id, first name and pet name are never sent. Automatic event capture and session replay are switched off everywhere in the app.

Photo proof of a chore

A chore may ask a child to take a photo as proof. The image is uploaded straight to a private Cloudflare R2 bucket that is not publicly readable; only the object’s key is stored next to the completion. A parent in the same household can view it through a link that expires after five minutes, and the bucket deletes every such object after 30 days. The image is never shared outside that household, is never sent to another child’s device, and is never used for advertising, training or any purpose other than showing that parent the chore was done.

Crash reports and diagnostics

The app reports crashes and errors to Sentry so they can be fixed. Every report the app itself sends is rebuilt from an allowlist of known technical fields — an error type, a status code, a route whose variable parts are replaced by *, the app version and the platform — rather than by removing the fields we happened to think of. A crash severe enough to stop the app is written to disk and sent by Sentry’s own native code before ours can rebuild it; that report carries a stack trace and device information and nothing of ours, because the settings that would attach personal information or a screenshot of the screen are switched off. A child’s device sets no user identity in Sentry at all; the only properties it reports about itself are the same three analytics already allows: interface mode, age band and the hashed household id. Screenshots and session replay are off. Console logs are dropped rather than attached. A parent is identified only by their account id.

What we store about a parent

Notifications

Mibo sends exactly four kinds of notification: an optional reminder to a child, an evening summary to a parent, a notice that a child has asked to redeem a reward, and a notice that a parent approved one. A child’s notifications name nobody. A parent’s evening summary does name their own children by first name, because a summary that named nobody would be unreadable in a household with more than one child; that is the only place a child’s first name leaves our servers, it goes only to a device registered by a parent of that same household, and it never includes a pet name, a chore title or a reward title.

Who we share data with

We do not sell personal information and we do not share it for advertising. Mibo contains no ads and no advertising or tracking SDKs, and we do not track users across other companies’ apps or websites. Data is processed on our behalf only by the service providers named above — Clerk (accounts), Railway (application hosting and the database), Cloudflare R2 (photo storage), PostHog in the EU (analytics), Sentry (crash reports), RevenueCat with Apple and Google (subscriptions) and Expo (push delivery) — each limited to what is described here. We may also disclose information if the law requires it.

How long we keep things

Photo proof is deleted after 30 days. Chores, completions, coins and the grove are kept while the household exists, because they are the child’s history in the app and the app would be wrong without them. Account and subscription records are kept while the account exists. Everything is deleted when a parent asks us to delete the household.

A parent’s rights

A parent may ask to see what we hold about their household or their child, ask us to correct it, ask us to delete it, or refuse any further collection about their child by deleting the household — in which case the child’s data goes with it. Write to [email protected] from the address the parent account uses and we will act within 30 days.

Changes to this policy

If this policy changes we will update the date at the top of this page. If a change affects what we collect about a child, we will tell parents at the email address on their account before it takes effect.

Contact

Mibo — [email protected]