ChoreKey

Privacy Policy

Last updated 18 August 2026. Maintained by KyrosWorks LLC.

ChoreKey is sold to parents, and it runs on a child’s device. That is about as sensitive as software gets, so this policy is written to be read rather than to be survived. If something here is unclear, email [email protected] and ask.

The short version


ChoreKey for Android

The Android app is entirely local. Chores, completion photos, your PIN, and your home coordinate are written to the app’s private storage on that one device and are never transmitted anywhere. There is no cloud sync, no pairing, and no backend of any kind.

Permissions, and what each one is actually for

PermissionWhy
Accessibility Service This is how ChoreKey blocks apps. Android offers no other way for an app that is not the device owner to notice which app just came to the foreground. ChoreKey uses a single callback, TYPE_WINDOW_STATE_CHANGED, and reads a single field from it: the package name of the app now in front. It does not read screen contents, does not record what you type, and does not capture or transmit anything the service sees. The package name is compared against the list of apps you chose to lock, and if it matches, ChoreKey puts its own “finish your chores” screen in front.
Location To work out whether the device is inside the home circle you set, because restrictions only apply at home. ChoreKey does not request background location. It reads position only while its own foreground service is running, which is the whole reason that service exists and posts a visible, permanent notification. What the app keeps is one true-or-false answer: home, or not home. Coordinates are not transmitted, no location history is kept, and the home centre point never leaves the device.
Camera For photo proof of a finished chore. Photos are written to app-private storage on the device and are deleted seven days after a parent approves them.
See all installed apps So a parent can pick which apps to lock from a list of what is on the device. Android has no narrower way to enumerate launchable apps. The list is used to draw that screen and is not stored or transmitted.
Display over other apps The block screen has to be able to appear on top of the app being blocked.
Notifications For the permanent notification that shows ChoreKey is running.

Some apps can never be blocked, whatever a parent selects: the phone dialler, messaging, Maps, the camera, and Android’s own Settings. A child can always call a parent. This is enforced in code, not by policy, and those apps are simply absent from the picker so they cannot be chosen by mistake.

You may notice that the app requests internet access. That comes from Google’s location libraries, which declare it. No ChoreKey code opens a network connection, and there is no HTTP client anywhere in the app.


ChoreKey for iPhone

Unpaired, which is the default, the iPhone app behaves like the Android one: chores, photos, your PIN, and the home location live on your child’s device and nowhere else.

If you choose to pair a parent’s iPhone so you can approve chores from your own device, chore data and approval photos sync through your family’s own iCloud account using Apple’s CloudKit. They travel between your devices via Apple’s infrastructure and land in your Apple account. They do not pass through, and are not stored on, any server KyrosWorks operates. Pairing is off unless you turn it on. Apple’s handling of iCloud data is governed by Apple’s privacy policy.

App blocking on iPhone uses Apple’s Screen Time and Family Controls framework. That framework is designed so the app doing the blocking never learns which apps you selected: iOS hands ChoreKey opaque tokens, not names. Phone and FaceTime stay reachable regardless, because iOS protects them. Every other app is blocked only if you select it.

Where chore photos actually live

A chore photo is a picture taken by a child inside your home. It is the most sensitive thing this app touches, so here is exactly where it goes, with no rounding in our favour.

An all-Apple family: we never see or keep the photo. Ever.

The photo never reaches our servers, our storage, or our accounts, because we operate none that it could reach. Unpaired, it stays in app-private storage on your child’s device. Paired, it is attached to a record in your own iCloud account and shared to the parent’s device by Apple. It counts against your iCloud storage and is governed by your Apple ID. Apple gives app developers no read access to a user’s private iCloud database, so we could not retrieve one of these photos on request, hand one to anyone, or lose one in a breach. We do not have it.

How long it lasts, stated accurately: the copy on your child’s own device is deleted automatically seven days after you approve or reject the chore. The copy in your iCloud stays until you remove it, and it is yours to remove at any time — delete the photo, the chore, the kid, or the family, or turn off pairing and delete the app. We do not delete it on a timer, because reaching into your iCloud to delete your own data is not something we can or should do.

An earlier version of this policy said cloud photos were auto-deleted on a seven-day timer. That was wrong: the seven-day deletion is on-device only. We corrected it here rather than leave a promise the software does not keep.

A family mixing Android and iPhone: the photo would pass through us.

Android devices cannot read or write an iCloud account. So the moment a family wants a parent on one platform approving chores for a child on the other, Apple’s route is unavailable and the photo has to travel through a backend we operate. There is no way to build that feature without the photo entering our possession, and we would rather say so plainly than imply a guarantee that only holds on Apple.

In that configuration the photo is uploaded to a private storage bucket we control, hosted on Supabase infrastructure on AWS in the United States. It is encrypted at rest, the bucket is not public, and a parent views a photo through a short-lived signed link, so the image is not reachable by anyone who merely has a URL. Access is limited to members of your own family. We do not browse these photos, we do not use them to train anything, and we never sell them or hand them to advertisers. But we could reach them, and you should assume that we technically can.

If that is not acceptable to you, an all-Apple setup avoids it entirely, which is why ChoreKey uses Apple’s route automatically whenever every device in the family supports it. Cross-platform sync is never silently switched on: it requires a parent to confirm it, and the app tells you the privacy tradeoff at that moment, not afterwards.

Today, the Android app performs no sync at all. It is entirely local, as described above, and no ChoreKey code on Android opens a network connection. If and when cross-platform sync ships, it is opt-in, and this policy is updated before it does.


Children’s data

ChoreKey is bought, installed, and configured by a parent or guardian, and it is intended for adults to use on a device they are responsible for. We do not knowingly collect personal information from anyone, of any age, because we do not collect personal information at all: there is no account, no profile, and no server-side record of your family.

The information a child produces in the app, a first name, a chore, a photo of a made bed, stays on the device the parent set up (and, on iPhone, in the family’s own iCloud if pairing is on). On an all-Apple family it is never sent to us and never shared with anyone else. In a mixed Android/iPhone family using cross-platform sync, it passes through our storage as described above, and is still never shared with anyone outside your family.

What we would have to tell you, if it applied

We do not have a database of users, so there is nothing to breach, subpoena, or sell in an acquisition. If that ever changes, this policy changes first and prominently, and any new data handling would be opt-in rather than assumed.

Your rights

Because everything lives on your device, you exercise most data rights directly. Deleting the app deletes the data. Settings has a “Reset all data” option that wipes chores, kids, photos, and settings without uninstalling. On iPhone, turning off pairing and deleting the app removes the CloudKit records from your iCloud.

If you are in a jurisdiction with statutory rights of access, correction, deletion, or portability, we can honour them trivially: we hold nothing about you. Write to [email protected] and we will confirm that in writing if you need it on paper.

Changes to this policy

If we change how ChoreKey handles data, we will update this page and change the date at the top. Material changes, meaning anything that sends data somewhere it did not go before, will be announced in the app before they take effect, not quietly shipped.

Contact

KyrosWorks LLC
[email protected]

A real person reads that address. Expect a reply within a couple of business days.