Last updated: 13 September 2026 · version 1.2
Tori is a chores, habits and rewards app for families. This document explains exactly what information is collected, where it is sent, what is not collected, and how to delete everything. It is written so that a parent can read it to the end and understand what happens to their children's information.
The operator of the app and controller of the data is the developer of Tori. For any privacy question, request or complaint: adirkatar@gmail.com. We respond within 30 days.
The core of the app works locally. The following is stored in the app's storage on the phone:
As long as the family works on a single device, none of its content is sent to the server (other than what is described in section 2.7). The moment the parent generates a pairing code to add another device (a child's phone, or a second parent's), the family document is synced to our server so that both devices see the same data. The document contains the items listed in section 2.1.
Alongside the document we store an anonymous device identifier — an identifier generated at random by our authentication system. It is not linked to an email, a phone number, a Google or Apple account, or any other personal identity.
A parent can mark a chore as requiring a photo. In that case the photo the child takes is stored in the family's storage area on the server, in a separate folder tied to that family alone. Database permission rules prevent access to another family's photos. The photos are deleted together with the account.
Pingo is an AI-based assistant. When a child or a parent writes to him:
claude-haiku-4-5, and a reply comes back.Anthropic processes the requests in order to produce the reply. Under its commercial API terms, input sent through the API is not used to train models by default. Anthropic's privacy policy: anthropic.com/legal/privacy.
You can talk to Pingo instead of typing. Speech-to-text conversion is performed by the operating system's speech recognition service (Google on Android devices, Apple on iOS), subject to their privacy policies. We receive the text only, not the recording. Voice recordings are not stored by us and are not sent to our server. Microphone permission is requested only when the speak button is pressed.
For each family we store the number of requests per day to Pingo, in order to enforce a quota and prevent abuse. A number only is stored — no content, no questions and no answers.
Tori grants one trial week per device. So that it really is granted once — and not again on every uninstall and reinstall — a single row is stored on the server with three values:
This row is not linked to the family, to names, to the family document or to any other data in this policy, and cannot identify a person. It is not used for advertising, usage analysis or segmentation — only to enforce the one-time trial.
What is not stored: the device identifier itself, the device model, a phone number, an IP address as a permanent record, or any advertising identifier.
| Category | How it stands in Tori |
|---|---|
| Ads and ad networks | None. The app shows no advertising at all. |
| Analytics and tracking tools | None. No usage-analysis or tracking SDK is installed. |
| Geographic location | Not collected and not requested. |
| Contacts, device calendar, full gallery | Not accessible. Only a photo picked explicitly. |
| A child's email / password / phone | Do not exist. A child has no account. |
| Selling data to third parties | Does not happen, in any form. |
| Free text between siblings | Does not exist in the app. Structured actions only. |
Tori is intended for family use, managed by and under the responsibility of the parent. The parent installs the app, creates the children's profiles and decides which capabilities are on.
We do not knowingly collect personal information from children beyond what is described here. A parent who believes information was collected without their consent is welcome to contact us, and we will delete it immediately.
Data synced to the server is stored on Supabase infrastructure (database and file storage), on servers in Frankfurt, Germany (the European Union), protected by row-level permission rules that limit each family to its own data only.
Requests to Pingo are processed by Anthropic, which may process them outside the European Union, including in the United States.
From inside the app: Settings → Advanced → Delete account and data. The action deletes the family document, the proof photos and the device records from the server, and resets the device. There is no way to restore it.
What is not deleted: the free-week record (section 2.7). It is not part of the account and is not linked to it — it is a hashed device fingerprint and a date, and deleting it would in effect cancel the one-time trial. Keeping it rests on a legitimate interest in preventing abuse. To request that it be deleted as well, contact us at the address below.
Without the app: You can send a deletion request to adirkatar@gmail.com. More detail on the account deletion page.
You may at any time request access to the data stored, its correction, full deletion, or a copy of it. Most of these are available directly in the app; for anything else you can contact us by email. If you are in the European Union, you have the rights granted by the GDPR, including the right to lodge a complaint with a local supervisory authority.
A paid subscription is purchased and managed through the app store the app was installed from — Apple's App Store or Google Play. We do not see and do not store any payment details — credit card, bank account or any other financial detail. All we receive from the store is whether an active subscription exists.
Communication is encrypted with TLS. Access to data is enforced at the database level and not only in the app. Access keys for external providers are held on the server only and do not exist inside the app. That said, no system is entirely immune, and we cannot guarantee absolute security.
If we change the policy, we will update the date at the top of the page. A material change — a new category of data or a new provider, for example — will also be shown inside the app before it takes effect.