Invitation-only Closed Beta

This Privacy Policy applies to the invitation-only Earn to Play closed beta for participating families and is the operative policy for that beta. Some workflows remain manual or under verification as described below. Before any public or global launch, this policy and those workflows must be reviewed and updated as necessary. Closed-beta status does not limit any rights or protections under applicable law.

Introduction

Earn to Play ("we," "our," or "us") is committed to protecting the privacy of children and families who use our parental control application and web portals. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use those mobile and web surfaces.

Data controller and service operator: Trukhnova Olha, Avenida Alas Clarín 16, 4.º Izq., 33404 Avilés, Spain. Phone: +34 671 918 928. Email for privacy and support requests: v.trukhnov@gmail.com. Earn to Play is operated by the individual named above; this policy does not represent Earn to Play as a separately incorporated company.

🛡️ Children's Privacy First

Earn to Play is designed with children's privacy as the highest priority. The product is being prepared for COPPA, GDPR, and other applicable privacy-law requirements; remaining compliance workflows must be completed before public launch.

Information We Collect

Information Provided by Parents/Guardians

Information Collected Automatically

Web Portal Authentication and Security

The child web portal uses a temporary eight-character code created by a parent. The maintained browser client keeps the parent password and child login code in memory, uses Firebase Authentication with browser-session persistence, and stores the child profile id, family id, and display name in sessionStorage while the child session is active. A separate PII-free session lease stores only version/status and activity timestamps so expired sessions are not restored. The child portal does not accept child photo, audio, or video submissions.

Firebase App Check with reCAPTCHA Enterprise is configured for web anti-abuse protection. Google may process browser, IP, device, and integrity signals and may use cookies or similar browser storage needed for that security purpose. Maintained portal source does not initialize advertising or analytics trackers. The current UI signs the parent portal out after 15 minutes of inactivity and the child portal after 30 minutes, and both browser leases have an eight-hour absolute limit; deployment and production behavior must still be verified before launch.

Information Not Cloud-Stored in Child Mode

For current tracked child photo proof flows, media is not uploaded to Firebase Storage; Firestore stores review metadata and local path references. Kid-side video capture/storage metadata is partial; parent video review/player support, audio reachability, and cleanup behavior remain under verification.

How We Use Information

We use collected information to provide, protect, debug, and support the service, including to:

Data Storage and Security

Local Storage

Current tracked child media files are intended to stay on the child device and are not uploaded to our servers. Firestore stores review metadata and local path references. Audio/video reachability, parent review support, and final cleanup behavior remain under verification across devices.

Website Cookies and Browser Storage

The maintained web portals are designed without optional advertising or analytics cookies. Strictly necessary Firebase Authentication, App Check/reCAPTCHA security, and sessionStorage mechanisms may operate so users can sign in and the service can prevent abuse. If optional analytics or marketing technologies are added later, they must remain disabled until the required choice and consent controls are implemented.

Cloud Data Services

We use Firebase/Google Cloud services. Firebase service locations must be verified in the selected project before launch; Functions are configured for europe-west1.

Security Measures

Third-Party Services

We use, or may use where a planned feature is implemented and approved, the following third-party services:

Current source is intended to avoid advertising networks and marketing trackers in the child interface. Crash diagnostics and functional data handling are disclosed here and must be verified before public launch.

AI Services

Where enabled, parent AI draft flows may use Google Gemini to propose quest drafts for parent review. Provider retention/logging, consent recovery, ownership tests, and launch readiness remain pending. Important details about our AI usage:

Where enabled and supported by the current flow, AI drafts are shown to parents for review. Provider retention/logging and recurring schedule activation remain pre-launch verification items.

Parental Rights and Controls

Parents/guardians have the right to:

Data Retention

Children's Privacy (COPPA-oriented Controls)

The closed beta uses the COPPA-oriented controls described below. These controls have not been represented as independently certified. Before any public or global launch, the consent method, deletion/export workflow, provider settings, retention practices, and store-policy requirements must be reviewed.

Verifiable Parental Consent

For the closed beta, the adult setup flow requires the adult to confirm parent or legal-guardian authority, acknowledge the child-data notice, and complete a separate email confirmation before child access is enabled. Before public or global launch, this method must be reviewed against the jurisdictions in which the Service will be offered and strengthened where required.

Data Breach Notification

In the event of a data breach that affects personal information:

International Data Transfers

For users outside the European Economic Area (EEA), data processing locations depend on the selected Firebase/Google Cloud services and must be verified before launch. Functions are configured for europe-west1.

Changes to This Policy

We may update this Privacy Policy as the closed beta changes. We will show the effective date, provide notice when required, and obtain renewed parental consent before materially different child-data practices begin where required. This policy must be reviewed and re-approved before any public or global launch.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact the operator:

Operator: Trukhnova Olha

Postal address: Avenida Alas Clarín 16, 4.º Izq., 33404 Avilés, Spain

Phone: +34 671 918 928

Email: v.trukhnov@gmail.com

Launch status: this Gmail address is the current privacy and support contact; dedicated domain mailboxes remain pending setup.