1. About this policy
This policy explains what HopOff collects, why, where it lives, and the rights you have over it. It covers the HopOff iOS app in both of its modes (a parent's phone and a child's phone), the hopoffapp.com website, and the HopOff backend.
The data controller is QuantumPivot Limited, a company registered in England and Wales (“we”, “us”). “You” is the parent or guardian who uses HopOff. We have not appointed a statutory Data Protection Officer; privacy questions go to privacy@mindbackapp.com, a monitored mailbox for data-protection requests.
This policy sits alongside our Terms of Service. If it changes in a way that affects you, we will tell you in the app before the change takes effect.
2. Who HopOff is for, and who has an account
HopOff is used by parents and guardians. You create an account, add your children by first name and age group, and pair each child's iPhone or iPad with a code. The child's phone then runs HopOff in child mode: it shows their tasks and shop and applies the rules you set.
- Children never create an account. They have no email, password or login. A child's phone is identified only by a random credential created when you pair it, which you can revoke at any time by unpairing.
- You provide every piece of personal information about your child, and you control it: you can change it, remove a child, or delete the family from the app.
3. What we collect, and why
About you (the parent)
- Email and password - to sign you in. Your password is stored only as a hash by our sign-in provider; we never see it.
- Your name in the family (for example “Mum” or “Jamie”) - shown to your child (“Approved by Jamie”) and to any other parent in the family.
- Quiet hours and your time zone - if you set quiet hours, when you want approval requests to arrive silently.
- Push notification token for each of your devices - so we can tell your phone when a child finishes a task or a phone needs attention.
About your family
- The family's name and the words you use for points (stars, coins, and so on).
- Who is in it - each parent's account, their role, and when they joined. An invite code, while one is open.
- Your plan - whether the family has the family plan, which size, when it renews, and whether there is a payment problem, as told to us by RevenueCat (section 12). We never see your card or your Apple account.
About each child (all of it typed in by you)
- First name (or nickname) and age group (5 to 8, or 9 to 12) - so the app can talk to them by name and suit its words to their age. No date of birth, no surname, no photo.
- Block lists - the apps you choose for them to earn, by app name and bundle identifier (for example “TikTok”), whether each list is on, and whether it opens during screen time.
- Blocked times (for example bedtime) and any daily earning limit.
- Tasks - the titles, icons and points you set, and which children they are for.
- Their points balance, each task they tick off and your decision on it, any points you give them with your note, and each purchase of screen time (how many minutes, what it cost, when it ran).
- The activity log - every change in the family, who made it and when, so both parents can see what happened.
About each child's phone (sent by the phone itself)
To keep the controls working and to tell you honestly whether they are, a paired phone reports:
- The device name you gave it, whether it is an iPhone or iPad, its iOS app version, and how far through setup it is.
- Whether Screen Time access is granted and in which mode (Family Sharing or the Screen Time passcode), whether notifications and Background App Refresh are on, its time zone, how far its clock is from ours, and when it last checked in. These are how we can warn you that a setting was switched off.
- Which of about fifty popular apps are installed, so “Add apps” on your phone can show what is actually on theirs. The phone checks for these by name; it cannot see anything else that is installed.
- A push notification token, so your changes reach the phone in seconds.
- Names for apps picked on the phone. If you use Apple's own app picker on the child's phone for an app our list does not have, Apple gives the app an opaque token that only means something on that phone. The token never leaves the phone. What we receive is a random identifier for it and the name you type for it, so your phone can show it.
On the website
- Nothing personal. The website has no forms and no analytics. Our hosting provider keeps ordinary server logs (IP address, pages requested, browser) for security and to keep the site up.
Support
- Correspondence - if you email us, we keep your message and our reply so we can help and keep a record.
4. What we never collect
- Screen Time data. How long your child uses each app, and which apps they open, stays on their phone. Apple's Family Controls framework does not let us export it, and we do not try. We only apply restrictions; we never read usage.
- Location. Neither phone's location is ever collected.
- Contacts, photos, messages, browsing history, or anything on the phone beyond the items in section 3. There is no photo proof for tasks: nothing your child does is photographed or uploaded.
- Advertising identifiers. We do not use them and there are no advertising or analytics SDKs in the app.
5. Our legal bases for using your data
If you are in the UK or EU, data-protection law requires us to have a “legal basis” for each use of personal data. Ours are:
- Performance of a contract - we process your account and family data, and what each child's phone reports, to provide HopOff to you under our Terms of Service. Without it there is nothing to run.
- Consent - for push notifications, which you turn on in iOS and can turn off at any time. Data about your child is provided by you as their parent or guardian, which is your consent to its use for the purposes in this policy; you can withdraw it by removing the child or deleting the family, without affecting the lawfulness of earlier processing.
- Legitimate interests - keeping HopOff secure, preventing abuse, fixing bugs, telling you when a phone stops checking in, and answering support requests. We use the least data that does the job and balance these interests against your rights and your child's.
- Legal obligation - where the law requires it, for example a valid legal request or records we must keep.
6. Where your data lives, and international transfers
Our backend has two parts, both in the European Union:
- Supabase (Frankfurt, Germany) handles sign-in and stores everything in section 3 in a Postgres database. See supabase.com/privacy.
- Railway (Amsterdam, the Netherlands) runs our server. See railway.com/legal/privacy.
Push notifications go through Apple's Push Notification service, subscriptions through Apple and RevenueCat, both of which operate in the United States (section 12). Where we transfer personal data out of the UK or the European Economic Area, we rely on appropriate safeguards: the UK International Data Transfer Agreement (or Addendum) and the European Commission's Standard Contractual Clauses with our providers and, where a provider is certified, the EU-US and UK Data Privacy Framework. Ask us for more about these safeguards using the details in section 15.
7. How we use your data
We use it to:
- Sign you in and keep the family in sync between parents' phones.
- Tell each child's phone what to block, when, and what it may open during screen time.
- Show your child their tasks, their balance and the shop, and send you their finished tasks to approve.
- Keep the points honest: only a parent's approval, gift or refund of unused minutes adds points.
- Warn you when a phone has not checked in, or a setting it relies on was switched off.
- Send the notifications you have allowed.
- Know whether the family plan is running, and which size.
- Keep HopOff secure and prevent abuse.
- Reply to you if you contact support.
We do not sell or “share” personal data (as those terms are used in U.S. state privacy laws). There is no advertising in HopOff, we do not use your data or your child's to train machine-learning models, and we do not make automated decisions that produce legal or similarly significant effects on anyone. The only “profile” of a child is the one you build: their tasks and their points.
8. How long we keep it
We keep data for as long as your family exists in HopOff.
- Unpair a phone and its credential is revoked at once; the phone lifts its restrictions the next time it connects, and the apps picked on it are removed from your lists.
- Remove a child and everything about them - lists, tasks, history, balance - is marked deleted at once.
- Delete your account (Settings, then Delete account) and, if you are the only parent, the whole family goes with it; if there is another parent, the family carries on with them and only your own account is removed.
- Anything marked deleted is hard-deleted within 30 days. Your sign-in record is removed as part of the same flow, and we ask RevenueCat to delete the family's subscriber record.
Deleting your account does not cancel a family plan bought through Apple; cancel that in your Apple account's subscriptions. We may keep a limited amount of data for longer where the law requires it, or to establish, exercise or defend a legal claim, and never longer than the applicable limitation period (generally six years in England and Wales).
9. Children
HopOff is a tool for parents, and the parent's account may be created only by an adult. We designed it so that a child uses HopOff without any account and without giving us anything about themselves. Everything personal about a child (their first name and age group) comes from you, and what their phone sends is limited to running the controls, as listed in section 3.
- U.S. (COPPA). The information about a child that HopOff holds is provided by the child's parent or guardian for the sole purpose of running the parental controls and rewards that parent set up. It is not used for any other purpose, is not disclosed to anyone but the service providers in section 12, and is deleted when you remove the child or your account. You may review and delete it at any time in the app or by emailing us. We do not knowingly collect personal information from a child directly, and a child cannot create an account.
- UK and EU. We follow the UK Age Appropriate Design Code: the child mode collects the minimum, has no advertising, no profiling, no location, no social features, no nudges to spend, and its settings default to the most private option. The child's balance is theirs to see; the only people who can see a child's data are the parents in their family.
If you believe someone has created a parent account who is not the parent or guardian of the children in it, email privacy@mindbackapp.com and we will look into it without delay.
10. Your rights (UK and EU)
Under the UK GDPR and the EU GDPR you have the right to:
- Access - ask what we hold about you and your children.
- Deletion - delete a child, a device, or your whole account from the app.
- Export / portability - request a copy of your data in a machine-readable format.
- Correction - names, ages and the family's words are editable in the app; for anything else, email us.
- Objection and restriction - ask us to stop or limit how we use your data.
- Withdraw consent - turn notifications off in iOS; remove a child or the family to withdraw your consent to their data.
How to exercise these rights
- Deletion is self-serve, in the app. You do not need to email us.
- For export, access, correction, or anything else, email privacy@mindbackapp.com and we will respond within one month, as the law allows.
Exercising these rights is free. We may ask you to confirm that you are the account holder before we act, and in rare cases the law lets us charge a reasonable fee or decline a request that is manifestly unfounded or excessive.
11. Your rights (United States)
Depending on the U.S. state you live in, you may have the right to know what personal information we collect and why, to access and obtain a copy of it, to correct it, to delete it, to opt out of its sale or “sharing” and of targeted advertising and profiling, and not to be discriminated against for exercising these rights.
Categories of personal information
In the category language of U.S. state privacy laws, in the past 12 months we have collected identifiers (your email, a user ID, device push tokens), customer records (your name in the family, your children's first names and age groups, your subscription status), and internet or other electronic activity limited to activity inside HopOff (the apps you block, tasks set and finished, screen time bought, and what each child's phone reports about its own settings). We collect this from you and from the phones you pair, use it for the purposes in section 7, and disclose it only to the service providers in section 12.
Sale, sharing, targeted advertising, and sensitive data
We do not sell personal information, we do not “share” it for cross-context behavioural advertising, and we do not use it for targeted advertising or for profiling that produces legal or similarly significant effects - as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) and similar state laws. This applies with particular force to information about children: we have no actual knowledge of selling or sharing the personal information of anyone under 16, because we do neither. Because none of these activities happen, there is no “Do Not Sell or Share” opt-out to action; we honour the right by not doing those things. We do not collect “sensitive personal information” beyond a child's age group, which is used only to suit the app's words to their age, and we offer no financial incentives in exchange for personal information.
How to exercise your U.S. rights
To delete data, use the app (section 8). For any other request, email privacy@mindbackapp.com. We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where the law allows and we tell you why. We may need to verify that you are the account holder. You may use an authorised agent; we will ask the agent for proof of authorisation and may still verify your identity directly.
Appeals. If we decline your request we will tell you why. You may appeal by replying to our decision within 45 days; we will respond to the appeal within 45 days (or 60 days where state law allows). If your appeal is denied and you remain unsatisfied, you may contact the Attorney General of your state.
12. Third parties
We use a small number of service providers, each acting as our processor or as an independent controller. Each is listed with what it does and what it sees:
- Supabase (sign-in and database, EU). Sees: everything in section 3 that is stored, including your email and password hash. See supabase.com/privacy.
- Railway (server hosting, EU). Our server runs there and handles everything in section 3 in transit. See railway.com/legal/privacy.
- Apple. Push Notification service: sees a device token and the notification text (for example “James finished Make your bed”). App Store: handles your subscription payment under Apple's own terms; we never see your payment details. Family Controls: the on-device framework that applies the restrictions; nothing goes to Apple from us. When your phone shows an app's icon in HopOff, it fetches the artwork from Apple's App Store servers by the app's bundle identifier. See Apple's privacy policy.
- RevenueCat (subscription management, US). Sees: a random family identifier as its customer ID, your App Store purchase and subscription status, and the basic device details its SDK collects from the paying parent's phone. It never sees your email, any name, or anything about a child. A child's phone never talks to RevenueCat. See RevenueCat's privacy policy.
- Discord (internal notifications, US). Our team gets a message in a private channel when a family plan starts, renews, is cancelled or ends. Discord sees: the family's random identifier, the plan, its price, and when it ends. Never an email, a name, or anything about a child. See Discord's privacy policy.
- Vercel (website hosting). Keeps ordinary server logs for this website. See vercel.com/legal/privacy-policy.
We put data-processing terms in place with our processors. We may also disclose data where we are legally required to, to enforce our Terms of Service, or in connection with a merger, acquisition, or sale of assets, in which case we will tell you and this policy will continue to apply.
There are no third-party analytics or advertising SDKs in HopOff. No Firebase Analytics, no Mixpanel, no crash reporting with user identifiers. If this ever changes, we will update this policy and tell you in the app before it takes effect.
13. How we protect your data
Every connection is encrypted in transit. Passwords are hashed by our sign-in provider. A child's phone holds a random credential that is stored hashed on our side and can be revoked in one tap. Access to our systems is limited to the people who run HopOff. No system is ever completely secure, so we cannot guarantee absolute security, but we work to protect your family's data and will notify you and the relevant regulator of a personal data breach where the law requires.
14. Changes to this policy
If we change this policy in a way that affects how we handle your data, we will:
- Update the “last updated” date at the top.
- Show a notice inside the app before the new version takes effect.
- Keep the previous version available on request.
Small edits for clarity or typo fixes do not trigger a notice.
15. Contact and complaints
Questions, requests, or complaints about privacy:
- Email: privacy@mindbackapp.com
- We aim to respond within one month, usually faster.
If you are in the UK and think we have handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk. If you are in the EU, you can complain to the data protection authority in your country. We would appreciate the chance to put it right first.