Skip to the main content
Legal

Privacy policy

Version 2.0 · Last updated May 15, 2026 · Effective May 22, 2026

Material changes that affect child-data processing trigger an in-app re-consent prompt before the next AI request.

Cubs is a family app designed for parents and children ages 4 to 18. This Privacy policy explains what personal data Cubs collects, the lawful bases on which we process it, who we share it with, how long we keep it, and the rights you and your children have. Every section starts with a plain-language summary; the full text below each summary is the binding version.

The whole policy, in short

We collect the minimum, we never sell it, we never train AI on your child's data, and you can see, export, or delete everything from Settings → Privacy & data.

Laws this policy satisfies

In short

This policy is written to meet the strictest child-privacy law that applies to your family — wherever you live.

  • United States: Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §6501; 16 CFR §312 as amended by the FTC Final Rule published April 22, 2025, with full compliance required by April 22, 2026); CCPA / CPRA (Cal. Civ. Code §1798.100+); California Age-Appropriate Design Code (AB-2273) — Cubs is designed to satisfy each operative provision regardless of the litigation posture on any given date; FERPA (20 U.S.C. §1232g) where Cubs processes school-imported records; and state child-safety statutes including the Utah Social Media Regulation Act, Florida HB 3, the New York SAFE for Kids Act, and the Arkansas Social Media Safety Act.
  • Europe + UK: EU General Data Protection Regulation (Reg. 2016/679) including Art. 8 protections for children; UK GDPR; UK Age-Appropriate Design Code (ICO Children's Code, 15 standards); EU Digital Services Act child protections; EU AI Act (Reg. 2024/1689) Art. 50 transparency obligation.
  • Other regions: Brazil LGPD (Lei Geral de Proteção de Dados) and ANPD guidance on children; Canada PIPEDA and Quebec Law 25 (Bill 64); Australia Privacy Act 1988 and the Australian Privacy Principles; Singapore PDPA; New Zealand Privacy Act 2020.
  • Platform rules: Apple App Store Review Guidelines 1.3 (Kids Category), 5.1 (Privacy), and 5.1.4 (Kids Category data limits); Google Play Designed-for-Families program; Microsoft Store family policies.

Where two regimes overlap, we apply the more protective standard.

1. Who we are and how to reach us

In short

Cubs is responsible for your family's data. Email support@cubsfamily.app with any question or request.

Cubs ("Cubs", "we", "us") is the data controller for personal data processed through the Cubs family app. Our acting Data Protection Officer is reachable at support@cubsfamily.app. Security and incident disclosures: support@cubsfamily.app. For EU/UK matters we will appoint an Art. 27 representative prior to our EU launch; the designation will be published in this section once confirmed. For Brazil, our LGPD representative will be appointed prior to Brazilian launch.

2. Who Cubs is for, and age thresholds

In short

Parents create every account. Kids never sign up on their own, and we always apply the strictest age rule that protects your child.

Cubs accounts must be created by an adult (18+) who is the parent or legal guardian of every child added to the family. Children do not create their own accounts and cannot access Cubs outside the family their parent administers. We apply the most protective age threshold across jurisdictions:

  • United States (COPPA): verifiable parental consent required for every child under 13.
  • European Union (GDPR Art. 8): Cubs uses the most protective member-state threshold (16) by default; we accept lower thresholds (13–16) only where a member state has legislated one and the parent confirms.
  • United Kingdom: verifiable parental consent for children under 13; the UK Children's Code applies to all users we know or could reasonably suspect are under 18, and Cubs applies its standards to every kid profile by default.
  • Brazil (LGPD): consent of at least one parent or legal guardian for children (under 12) and adolescents (12–17) where consent is the lawful basis.

3. Personal data we collect

In short

The minimum from parents, less from kids — and child data only after you say yes. No biometrics, no exact birth dates, no GPS, ever.

3.1 From parents

  • Name, email, optional phone number (transactional and emergency contact only).
  • Billing details held by Stripe (last 4 digits, card brand, ZIP). Cubs never stores full payment card numbers.
  • Postal code, city, and region captured at onboarding with explicit consent, used only to localize the marketplace and family experience.
  • Content you author inside Cubs (messages, notes, calendar entries).
  • Limited device and connection details (browser, OS, app version, language preference).

3.2 From children, only after verifiable parental consent

  • First name and age level (preK through grade 12). Cubs never stores a child's exact date of birth.
  • Grade level and subjects of interest.
  • Conversation content the child sends or receives in tutoring features.
  • Quiz, drill, portfolio, chore, and pocket-money interaction history.
  • Aggregated learning insights such as weak areas and time on task.
  • A one-way cryptographic fingerprint of the session connection (the raw network address is never kept). Used only to protect a session against takeover; never combined with the child's name in anything we send out.

3.3 School records imported with your authorization

If you connect Google Classroom, ClassDojo, Remind, or a similar school platform, Cubs imports assignment titles, due dates, rubric labels, and teacher comments associated with your child. These records are tagged as protected school records, and Cubs will not send any of them to an AI service that has not confirmed zero data retention (see §7).

3.4 Data we never collect

  • Biometric or face data — including fingerprints, voiceprints, gait, faceprints, retina or iris patterns, and genetic data (per the amended COPPA §312.2 definition of personal information).
  • Government-issued identifiers — state ID numbers, birth-certificate numbers, passport numbers, Social Security numbers (per amended COPPA §312.2).
  • Precise GPS or background location. Carpool uses approximate arrival estimates only.
  • Health, mental-health, or medical records (a future Health feature will have its own consent flow and impact assessment).
  • Any data Cubs would sell or share for cross-context behavioral advertising.

4. Lawful basis and purpose

In short

We process parent data to run your subscription, and child data only with your verified consent — collected separately for each kind of use.

For users in the EU/UK and other GDPR-aligned regimes:

  • Contract (Art. 6(1)(b)): delivering the subscription service to parent account-holders.
  • Verifiable parental consent (Art. 6(1)(a) + Art. 8): all child-profile creation and child-context AI processing.
  • Separate parental consent for AI personalization: captured at first AI use, versioned, and re-collected when a material change occurs (per amended COPPA §312.5).
  • Separate parental consent for any third-party disclosure: required by amended COPPA §312.5 even for disclosures necessary to provide a feature, unless the disclosure is integral to the service.
  • Legitimate interest (Art. 6(1)(f)): security, fraud prevention, and product analytics — only after a documented balancing test and never with child-context data.
  • Legal obligation (Art. 6(1)(c)): tax records; response to lawful subpoenas; mandatory breach notification.

5. How we use personal data

In short

Your data runs your family's Cubs — never advertising, and never AI training on child data.

  • Provide the Cubs subscription product to your family.
  • Generate personalized tutoring, family-planning, and learning suggestions. Every AI-mediated action surfaces as a draft a parent must approve before it takes effect.
  • Operate the parent-only audit, export, and erasure tools required by COPPA §312.6, GDPR Art. 15 / 17 / 20, and CCPA / CPRA.
  • Detect abuse, fraud, and safety incidents (security-only legitimate interest).
  • Meet legal obligations and respond to lawful requests.

We do not use child data, child content, or any feedback derived from a child session to train, fine-tune, or evaluate any AI system. We do not condition access to any general feature on disclosure of more child information than is reasonably necessary to deliver that feature (COPPA §312.7).

6. Verifiable parental consent (COPPA + GDPR Art. 8)

In short

Before a kid profile exists, we verify you are the parent — and you can take any consent back at any time, effective immediately.

Before any child profile is created, the parent confirms identity and grants consent through one of the FTC-approved verifiable parental consent ("VPC") methods set out in §312.5(b):

  • Knowledge-based authentication: dynamic challenge-response questions sourced from public-record databases that an unauthorized person cannot reasonably answer.
  • Card-charge verification: a verifying authorization hold ($0.01) on a parent payment instrument, voided immediately.
  • Text plus: a signed-paper or text-message confirmation step coupled with a verification call-back, where the message itself never discloses the child's personal information.
  • Signed consent form on request: for parents who prefer a paper trail. Email support@cubsfamily.app.

Consent is versioned and is captured separately for: (i) creating the child profile, (ii) any AI-mediated personalization, and (iii) any third-party disclosure not integral to the service. When we change what AI-mediated processing requires, we ask for fresh consent before the next AI request. You can revoke any consent at any time in Settings → Privacy & data; revocation takes effect immediately on the next request.

Detailed consent disclosures live on the Parental consent and COPPA compliance pages.

7. AI processing

In short

The AI services we use never keep or train on your family's words, names are masked before anything leaves Cubs, and every AI suggestion says it came from AI.

Cubs uses third-party AI services — currently Anthropic Claude and Microsoft Azure OpenAI — to power tutoring, summaries, and family assistance. These guarantees apply to every AI request that touches child context:

  • Zero data retention. Every AI service must operate under a posture that prohibits storing, logging, or training on prompts and responses — your child's words are never kept or learned from. Cubs never sends a child-context request to an AI service that has not confirmed this in writing.
  • Names are masked at the boundary. Family names are replaced with anonymous tokens (MEMBER_1, MEMBER_2) before anything leaves Cubs and put back only on the response. Postal codes, exact locations, and parent identifiers are stripped from child-context requests.
  • AI transparency (EU AI Act Art. 50). Every AI surface identifies itself as AI. On most surfaces that is the in-product AI disclosure chip — plain-English and age-appropriate — shown next to the suggestion itself. In the Cubs chat it is a line under the message box, because a chat is self-evidently a conversation with Cubs and a badge on every screen crowds out the chat itself. Either way an audit record is written each time an AI-mediated suggestion is shown to a kid or parent, and that record is written on our servers, so it does not depend on what the screen displays.
  • Reliability hint (FTC AI 2025–26). Wherever Cubs makes an AI suggestion we show a short, age-appropriate line reminding the reader that Cubs AI can be wrong. Young kids read "Always check with a grown-up"; older kids read "Cubs can be wrong — double-check it"; parents read "Output may be inaccurate — review before acting". The same wording is used everywhere in the product so this policy and the app cannot drift apart. In the kid chat this line also states that a grown-up in the family can read the conversation, so a child is never left assuming it is private. Safety surfaces (the distress card, refusals, the parent purchase gate, and the age gate) intentionally leave the hint off so safety messages stay authoritative.

Our public AI commitments are summarized in the Cubs Promise, with the engineering controls behind them in the Cubs AI safety standard.

8. Subprocessors

In short

Every company that touches Cubs data is listed here. We tell you 30 days before adding one that handles child data, and you can object.

We list every third party that processes Cubs data, the data category each touches, and the applicable safeguards. The complete list lives in our public subprocessor register. The current active subprocessors are:

Active subprocessors: vendor, service, and data category
VendorServiceData category
Anthropic, PBCClaude APIPrompts / responses, with personal details masked
Microsoft CorporationAzure OpenAI FoundryPrompts / responses, with personal details masked
Supabase, Inc.Managed Postgres + StorageStructured family / child data, audit records
Vercel, Inc.App hosting, FunctionsFunction execution context
Upstash, Inc.Redis (rate limit, cache)Short-lived cache rows (5 min or less)
Stripe, Inc.BillingPayment method + billing email (no child data)
Resend, Inc.Transactional emailParent email addresses + notification content

We give 30 days' written notice (in-app and by email to the family admin) before adding any new subprocessor that processes child data. Existing customers may object; an objection triggers a service-design conversation.

9. Retention

In short

Child data has hard deletion deadlines, checked automatically every day. Nothing about your child is kept forever.

Amended COPPA §312.10 and the GDPR's storage-limitation principle (Art. 5(1)(e)) prohibit indefinite retention of child personal data. Cubs enforces the following maximums, checked and deleted automatically every day and visible in Settings → Privacy & data:

  • Parent AI interaction records: 13 months, configurable down to 1 month.
  • Child AI interaction records: 18 months (the student-record floor under FERPA), configurable down to 90 days.
  • Child conversation content: the same window as child AI interaction records.
  • Security audit records: 13 months, archived to cold storage thereafter.
  • Family + member records: while the account is active, plus 30 days post-cancellation, then hard-deleted across every linked record.
  • Stripe billing records: 7 years (US / UK tax law).

On a parent erasure request the deletion is irreversible and completes within 30 days, cascading through every linked record. Deletion coverage is enforced by automated tests — no new data table ships without an explicit deletion plan.

10. Your rights

In short

You can download a CSV of every AI call made on behalf of your family from the Family AI hub's Activity tab (AI activity (CSV)), and you can permanently delete your family's account and all of its data in-app from Settings → Privacy & data. For any other records, email us at support@cubsfamily.app and we will provide them.

  • Right of access (Art. 15 / §312.6 / CCPA §1798.110): download a CSV of every AI call made on behalf of your family (AI activity (CSV)) from the Family AI hub's Activity tab.
  • Right to rectification (Art. 16 / CCPA §1798.106): edit any profile field directly; flag incorrect AI-derived insights for human review.
  • Right to erasure (Art. 17 / §312.6 / CCPA §1798.105): delete an individual child profile or the whole family. Deletion is irreversible and cascades through every linked record within 30 days.
  • Right to portability (Art. 20): the AI activity (CSV) export is machine-readable and includes every AI call made on behalf of your family.
  • Right to restrict / object (Art. 18, 21): turn AI features off entirely or pause individual abilities.
  • Opt out of AI sampling and evaluation: a parent may pause all quality-sampling on the family from Settings → Privacy & data. The opt-out is honored before any data leaves the family scope.
  • Right to opt out of sale or sharing (CCPA / CPRA §1798.120 / §1798.121): Cubs does not sell personal information and does not share personal information for cross-context behavioral advertising. Server-side honoring of the Global Privacy Control ("GPC") signal is on the pre-GA roadmap; until that ships our posture is honored by the no-sale / no-share architecture itself, not by an automated response to the GPC header.
  • Right to limit use of sensitive personal information (CPRA §1798.121): all child-context data is treated as sensitive by construction and is never used outside the purposes disclosed here.
  • Right to lodge a complaint: EU / UK residents may complain to their data protection authority (for example, the ICO in the UK or the CNIL in France). We will not retaliate against you for exercising any right.
  • Right to know about automated decision-making (Art. 22 / CPRA §1798.185(a)(16)): every Cubs AI action is "propose, then human approval". No legally or similarly significant decision is taken about a child without parent confirmation.

We respond to verifiable requests within 30 days (15 days for COPPA §312.6 access; 45 days for CCPA, extendable by 45 with notice). To exercise any right, write to support@cubsfamily.app or use the in-app controls.

11. California disclosures (CCPA / CPRA + AADC)

In short

We do not sell or share personal information, and California kids get the highest default protections — regardless of where the court cases land.

For California residents and minors, Cubs is a "business" under CCPA / CPRA. In the 12 months preceding the last update of this notice, Cubs collected the categories of personal information listed in §3 above for the purposes listed in §5. We did not sell or share any personal information; we did not use sensitive personal information for any purpose other than those permitted by §7027(m) of the CPRA regulations. To exercise a California right, use Settings → Privacy & data or contact support@cubsfamily.app. You may designate an authorized agent to act on your behalf.

Cubs treats the California Age-Appropriate Design Code (AB-2273) as a design baseline regardless of where the NetChoice v. Bonta litigation lands. We apply the highest privacy settings by default to every kid profile, configure features so dark patterns cannot pressure a child, and publish the data-protection logic for child surfaces in our public compliance documentation. The impact-assessment provision struck by the Ninth Circuit in 2024 is documented as "not currently required"; we voluntarily maintain an assessment aligned with GDPR Art. 35.

12. EU / UK disclosures

In short

GDPR and the UK Children's Code apply to every kid profile by default, and our records are open to supervisory authorities.

Cubs is the controller for the personal data it processes. The lawful basis for each processing activity is set out in §4. We maintain a Record of Processing Activities (Art. 30) and a Data Protection Impact Assessment (Art. 35) — both available to supervisory authorities on request. The UK Children's Code (15 standards) is applied to all kid profiles by default. The EU Digital Services Act's additional child-protection obligations are addressed through our zero-advertising posture and the parent purchase gate (see §15).

13. International transfers

In short

Data is hosted in the US under EU-approved contractual safeguards; a dedicated EU region is planned.

Cubs primary infrastructure is hosted in the United States (Supabase aws-us-east-1; Vercel US). EU / UK customer data transferred to the US travels under (i) the EU Standard Contractual Clauses (2021), (ii) the UK International Data Transfer Addendum, and (iii) the Swiss-US Data Privacy Framework where applicable. Anthropic, Microsoft, Vercel, Supabase, Stripe, and Resend have executed the relevant SCC modules with us. A dedicated EU region mirror on Supabase aws-eu-west-1 is planned for our Year-2 EU launch. We complete a Transfer Impact Assessment (Schrems II) annually for each non-adequate destination.

14. Security and information-security program

In short

Encrypted in transit and at rest, family-isolated at the database level, and tested by outside experts every year.

Amended COPPA §312.8 and CCPA §1798.150(a) require a written information-security program appropriate to the sensitivity of the data. Ours includes:

  • TLS 1.3 in transit; AES-256 at rest (Supabase managed Postgres + Storage).
  • Database isolation rules enforce that one family can never read another family's data, on every table that touches a kid.
  • Emergency production access by Cubs engineering is logged to a permanent audit record; no developer has direct production write access outside that process.
  • Quarterly vulnerability scans; an annual third-party penetration test; SOC 2 Type II targeted for Year 1.
  • AI-specific controls: a closed list of AI abilities, retention checks on every AI service, two layers of content moderation, personal-detail masking in both directions, and spending caps that stop runaway use.
  • A documented incident-response playbook with role assignments, evidence preservation, and rehearsed run-throughs.

15. Safety and compliance surfaces in the kid app

In short

Kids' screens show exactly when data, AI, or money is involved — and money always waits for a parent.

Cubs surfaces four small indicators on every child screen so that you (and any app-store reviewer) can see exactly when and how data, AI, and money decisions are being made:

  • Inline consent indicator. A quiet pill next to every field that captures kid data, showing the current consent state (granted, missing, stale). Each first appearance per session writes an audit record you can review.
  • AI disclosure chip + reliability hint. A plain-English chip above any AI-mediated suggestion ("Made by Cubs" for younger kids, "AI-suggested" for older kids and parents), with the age-appropriate reliability line described in §7 directly beneath it. Each appearance writes an audit record carrying the AI service used, the feature, the retention confirmation, and the audience. Safety surfaces (the distress card, refusals, the age gate, and the parent purchase gate) intentionally leave the hint off so safety messages stay authoritative.
  • Distress card. An always-visible, collapsed life-line on every kid open-text surface. It never auto-expands on sentiment alone; it opens only on an explicit tap and routes to curated, jurisdiction-correct hotlines. A first-open-per-day audit record is written on our servers.
  • Parent purchase gate. Every kid money-moving action (gift-card request, marketplace interest, family-pot contribution) is routed through parent approval, not through Stripe. The gate writes an audit record carrying the surface, item type, and item, so Apple Kids and Google Play Designed-for-Families reviewers can verify the rule directly.

Gift-card requests are an exception worth calling out: the kid surface never charges a card. The request is sent to the parent for hand-fulfillment, and the fulfillment partner receives only the brand, value, and parent email — never the child's name.

16. Cookies and local storage

In short

Only the cookies needed to sign you in. No ad trackers anywhere — and no third-party code at all in the kid app.

Cubs uses only strictly-necessary cookies and local-storage entries: an authenticated session cookie (HTTP-only, SameSite=Lax), a security token, a theme preference, and a small offline cache for slow-network learning. We do not deploy advertising cookies, social-media pixels, or cross-site trackers in the kid app. No third-party software runs in any kid surface.

17. Breach notification

In short

If something goes wrong, we tell the authorities within 72 hours where required and your family without delay — even when the law would let us stay quiet.

On confirmation of a personal-data breach, we will notify the relevant supervisory authority within 72 hours where required (GDPR Art. 33; UK GDPR; California Civ. Code §1798.82). We notify affected families without undue delay where the breach is likely to result in high risk to rights and freedoms (Art. 34). Even where notification is not legally required, we publish a summary in the in-app notice tray within 7 days for transparency.

18. Apple Kids Category statement

In short

The kid app meets Apple's strictest Kids Category rules: no third-party tracking, no outside ads, and purchases locked behind a verified parent gate.

Cubs participates in the Apple Kids Category and complies with App Store Review Guidelines 1.3 and 5.1.4. In the kid surfaces we do not send personally identifiable information or device identifiers to any third party; we do not include third-party advertising or third-party analytics; in-app purchases and link-outs are blocked behind a verified parental gate (see §15); AI features carry inline disclosure and operate under the zero-data-retention posture described in §7. Our age rating is calibrated for the possibility that AI output may include sensitive content, despite our moderation, per Apple's 2025 guidance on generative content.

19. Changes to this policy

In short

We give 30 days' notice of material changes — and changes that touch child data require your fresh consent first.

We notify family admins by email and in-app banner at least 30 days before any material change takes effect (7 days for security-only fixes that do not alter processing). Material changes that affect child-data processing also trigger a re-consent prompt before the next AI request.

20. Contact

In short

support@cubsfamily.app — we answer within 30 days, sooner where the law requires.

Privacy questions, rights requests, and complaints: support@cubsfamily.app. Security disclosures: support@cubsfamily.app. Legal notices: support@cubsfamily.app.

See also: Terms of service · Parental consent · Beta waiver · COPPA compliance · The Cubs Promise