Privacy Policy
Last updated: 24 August 2026
We wrote this policy ourselves, checked it line by line against what the app and our server actually do, and no lawyer outside our team has reviewed it yet.
Every Age ("the app") is operated by Rob Abramowitz. This policy explains what the app collects, why, and what you can do about it.
Who the account belongs to
The app is for parents and caregivers. We do not create accounts for children and children do not sign in. Everything in the app is entered by an adult.
What we collect
Your account identifier. When you use Sign in with Apple, Apple gives us an identifier for you. We store only a one-way hash of it, never the raw value. If you use Apple's Hide My Email, we store the private relay address Apple provides. We never receive your real email address unless you choose to share it.
Your child's nickname, if you give one. A nickname is optional. When you provide one it is encrypted with AES-GCM before it is written to our database. We never ask for your child's full name or date of birth. We store an age band (4 to 10) rather than a birthday.
What you record about mornings. The ratings you enter for how much you stepped in, how many reminders it took, and how much conflict there was, the practice steps you accept, your check-in answers, and the reasons you give when a morning is hard.
Steps you write yourself. If you add your own step, the words you type are stored. They are encrypted at rest with AES-GCM, exactly like a nickname, and for the same reason: a step you write may name your child. We do not read them to build content, we do not share them with other users, and there is no way for anyone else using the app to see them.
Whether your morning has a drop-off. For a four or five year old we ask whether there is a school or daycare drop-off. We store yes or no. It decides whether steps that only exist because of a deadline, such as packing a bag, are offered at all.
Which screens you reach. We record a short, fixed list of steps along the way: that the app was opened, that you signed in, that you added a child, that you started a plan, that you saved a check-in, that you saw the subscription screen. That is the whole list and the server refuses anything not on it, so it can never grow into a record of what your family does in the morning. It carries no device identifier, it is recorded by our own server with no third-party analytics company involved, and it is never used to track you anywhere else. Settings has a switch that turns it off. We use it for one thing: seeing where the app loses people, so we can fix that part.
Your settings. Your time zone, the outcome you chose to focus on, and your consent decisions with the policy version and timestamp.
Subscription status. Whether your subscription is active. Purchases are handled by Apple, and what Apple tells our server about a purchase is a transaction identifier and a product and status, never a card number or billing address. We store that transaction identifier so a later renewal or refund notification from Apple can find the right account, alongside which product you bought and when our record of it was last confirmed. We never see your payment details.
A request identifier and technical record of the request. Every call your device makes to our server is logged with a request id, the endpoint and method, the response status, how long it took, and your account id if you were signed in. Log lines never carry anything you typed: not a nickname, not a step you wrote, not a request body. These logs have no fixed deletion schedule yet. We will set one before the app is released widely, and this policy will say what it is.
Your IP address, briefly, to enforce a rate limit. An unauthenticated request, such as signing in, is throttled by IP address so one source cannot hammer the endpoint. That address is held only in the server's memory, never written to the database or to a log line, and never persisted to disk. It does not survive a server restart, and the in-memory record is capped and cleared automatically once enough distinct addresses have been seen, so it cannot grow without bound.
What we do not do
- We do not track you across other companies' apps or websites.
- We do not sell or rent your data.
- We do not show third-party advertising.
- We do not use your data to train machine learning models.
- We do not use any third-party analytics company, advertising SDK, or tracking library. The only measurement is the fixed list of screens above, recorded by our own server, and you can switch it off.
Why we collect it
Only to make the app work: to sign you in, to recommend a step suited to your child's age and morning, to track whether a practice is helping, and to manage your subscription. The one exception is the screen list above, which we use to find the places the app is failing people. We do not use any of it for any other purpose.
Who else sees it
- Apple, for Sign in with Apple and for subscription billing.
- Our hosting provider, which stores the database that runs the service.
Nobody else. We share data with no advertisers, data brokers, or analytics vendors.
How long we keep it
We keep your data while your account is open. When you delete your account, or delete a single child, we remove that profile and erase the nickname and the text of any steps you wrote. Deletion removes the words themselves, not just a marker saying they are deleted.
Your subscription transaction record is the one exception. We keep the transaction identifier, the product you bought, and its status after account deletion, the same way any purchase leaves a billing record. It carries no words you typed and no card details, only what Apple already knows about the purchase. Server request logs and the brief in-memory rate-limit record above are not tied to your deleted account either way.
Your choices
Export your data. Settings has "Export my data". It returns every morning you rated, the plans you ran, the steps you wrote in your own words, your settings, and your consent history.
Turn measurement off. Settings has a switch for the screen list above. It stops at our server as well as on your device, and anything still waiting to be sent is dropped.
Delete your account. Settings has "Delete my account and all data". This removes your account, your child profiles, every observation, and the text of every step you wrote. It cannot be undone. You do not need to contact us to do it.
Withdraw consent. Sign out at any time, or delete your account.
Depending on where you live you may also have rights to access, correct, or restrict processing of your data, and to complain to a data protection authority.
Security
Session tokens are stored in the iOS Keychain on your device. Child nicknames and any step you write are encrypted at rest with AES-GCM. Traffic between the app and our API uses HTTPS.
We periodically rotate the encryption key those values are stored under. When we do, the affected rows are re-encrypted under the new key. Rotation changes which key protects your data, not what we store or what it says.
No system is perfectly secure, and we do not claim otherwise.
Children
This app is a tool for adults. It is not directed to children and children should not use it. We do not knowingly collect personal information directly from a child. If you believe a child has provided us information, delete your account or contact us and we will remove it.
This is not medical advice
The app offers everyday parenting practice suggestions. It is not medical, psychological, or therapeutic advice, it does not assess or identify any condition, and it is not a substitute for a qualified professional.
A step you write yourself is yours. We did not write it, review it, or check it against anything, and the app says so on the screen where it appears. What the app does with it is measure it the same way it measures our own steps.
Changes
If we change this policy we will update the date above and show you the new version in the app before you continue.
Contact
Questions or requests: [email protected]