CookieCal is built for families. We take children's privacy seriously — not as a legal checkbox, but as a core product value.
This Privacy Policy describes how CookieCal ("CookieCal," "we," "us," or "our") collects, uses, and protects information when you use our web application, mobile application, and related services (collectively, the "Service").
CookieCal is a task management, time-awareness, and family coordination platform designed for children (ages approximately 4–18) and the adults who care for them — parents, guardians, educators, and caretakers.
This Policy applies to all users: parents, guardians, children, caretakers, educators, and Cheer Squad members.
If there is a conflict between this Policy and applicable law, the law governs. We comply with the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA) where applicable, the California Consumer Privacy Act (CCPA/CPRA), and applicable state Age-Appropriate Design Code laws (California AADC, Connecticut, Maryland, Texas, and others).
CookieCal is operated by its founding team. Our contact for privacy matters is:
We are pursuing COPPA Safe Harbor certification through an FTC-approved program (kidSAFE or iKeepSafe). Until certification is complete, this policy represents our best-effort compliance commitment and will be updated upon certification.
3.1 Parent / Guardian Accounts
3.2 Child / Kid Accounts
3.3 Educator / Teacher Accounts
3.4 Caretaker Accounts
3.5 Automatically Collected Data
3.6 What We Do NOT Collect
4.1 Verifiable Parental Consent
CookieCal collects verifiable parental consent through the credit card / payment method requirement at account creation. The use of a payment instrument by an adult to create the account constitutes the verified consent mechanism. We do not create child profiles without this consent gate.
At the time of account setup, the parent is presented with a clear consent screen (the "Parental Gate") that explicitly discloses:
4.2 Data Minimization for Under-13 Accounts
For children under 13, we collect the minimum data necessary to operate the service:
4.3 No Behavioral Advertising of Children — Ever
CookieCal does not and will never:
Consistent with California's Age-Appropriate Design Code (AADC), Connecticut's Act Concerning Data Privacy (SB 3), Maryland's Online Data Privacy Act, and similar state laws, CookieCal defaults are:
We use collected data solely to:
We do not use data to:
We disclose all third-party services that process user data. We do not use any ad networks, social widgets, or tracking SDKs.
We require all processors to implement appropriate security measures and to use data only for the specified purpose. None of our processors are authorized to use CookieCal user data for their own advertising or analytics purposes.
8.1 What AI Features Are Available
8.2 What Data Is Sent to AI Providers
When a user interacts with an AI feature, the text content of the conversation (and, in some features, limited context like the current task list or schedule) is sent to our AI provider (currently Google Gemini or OpenAI GPT, depending on feature) for processing. This is necessary to generate a response.
8.3 Data Retention by AI Providers
We configure our AI API calls to not allow the provider to use submitted data for training their models. We use API access (not consumer products), which provides data-processing agreements that prohibit training on user data.
8.4 Parent Visibility
All AI Pet Chat conversations are stored in our database and are visible to the linked parent account. Parents may view and delete conversation history at any time.
8.5 Content Safety
AI features include content-safety filtering to prevent inappropriate outputs. Our AI system prompts are designed to keep conversations age-appropriate, educationally focused, and never collecting personal information from children.
8.6 AI Is Not a Professional
AI features in CookieCal are tools to support — not replace — parental guidance, professional tutoring, therapy, or educational assessment. AI responses may occasionally be inaccurate. Do not rely solely on CookieCal AI for graded, high-stakes, medical, psychological, or legal matters.
For users of CookieCal's Educator / Classroom Mode, the following applies:
9.1 School Official Exception
When schools formally integrate CookieCal Classroom Mode under a written Data Privacy Agreement (DPA), CookieCal may qualify as a "school official" under FERPA with a legitimate educational interest in the student data it processes. We do not claim this exception without a formal DPA in place.
9.2 Student Data Minimization
Educator accounts do not require student email addresses. Students are identified by first name only within the classroom system. No student data from Classroom Mode is used for advertising or shared beyond the classroom context.
9.3 Data Privacy Agreements
Schools and districts may request a formal DPA. Contact hello@cookiecal.com to initiate this process. Our DPA framework is designed to comply with the Student Data Privacy Consortium (SDPC) framework and applicable state student privacy laws.
9.4 Home-School Data Bridge
The optional home-school data link (connecting a child's family CookieCal account to a classroom record) requires explicit, affirmative consent from the parent. It can be revoked by the parent at any time with immediate effect.
10.1 How Long We Keep Data
10.2 Self-Service Deletion
Parents can permanently delete their entire account — including all child profiles, tasks, photos, journal entries, and associated data — through the self-service account deletion flow at Settings → Account → Delete Account. Deletion is immediate and irreversible. We confirm deletion via email.
10.3 Requesting Deletion by Email
If you need assistance with data deletion or want to export your data before deleting, email hello@cookiecal.com. We will respond within 72 hours and complete any requested deletion within 30 days.
10.4 Child Data Deletion Requests
Parents may request deletion of a specific child's data without deleting their own account. This can be done through Settings → Kids → [Child Name] → Remove from Family. This action permanently deletes all data associated with that child profile.
Under COPPA, parents of children under 13 have the following rights regarding their child's data. CookieCal extends these rights to all minor users regardless of age:
To exercise any of these rights, use the tools in the parent dashboard or contact us at hello@cookiecal.com. We will respond to rights requests within 30 days.
CookieCal is a children's app and does not permit, tolerate, or knowingly host intimate imagery of any kind. Should any such content be reported:
We also use automated content moderation on uploaded images. Our content moderation pipeline is designed to flag and prevent distribution of such content before it reaches any other user.
We implement industry-standard security measures to protect your data:
No security system is perfect. If you discover a vulnerability, please disclose it responsibly to hello@cookiecal.com. We will respond within 48 hours.
We will notify users of material changes to this Privacy Policy by:
For changes that materially reduce privacy protections for children, we will re-obtain parental consent before implementing the change.
For any privacy questions, rights requests, or concerns:
We respond to all privacy inquiries within 72 hours and complete substantive requests within 30 days.
© 2026 CookieCal — No ads, no trackers, no data sold.