Privacy Policy — DonePass
Last updated: 2026-08-20 Applies to: DonePass v1.0 for iOS, and the DonePass website.
1. Who we are
DonePass is a homework-accountability app for families. A parent sets a focus session; distracting apps on the child's iPhone are blocked for the duration; the child photographs the finished work; the parent approves it and the apps come back.
The service is provided by Sawariya Seth LLC, doing business as DonePass, 5 Kennedy Cir, Brentwood NH ("DonePass", "we", "us"). We are the data controller for the information described in this policy.
Privacy contact: support@donepass.com
2. What DonePass does not do
Stated first because it is the shortest section and it answers most of the questions parents actually ask.
- We do not sell, rent, or share personal information — for money or for anything else of value.
- We do not serve advertising, in the parent app or the child app.
- We do not disclose a child's personal information to anybody. Not to advertisers, not to data brokers, not to AI companies, not to anyone. See §7, where this is the single most important thing in the document.
- We do not use your family's data — including homework photos — to train artificial-intelligence models, and we do not send it to any AI provider. There is no AI in DonePass. A photo-checking feature was designed, built and then deliberately removed before launch; §4.5 explains why it is not coming back.
- We do not track you across other companies' apps or websites, and we use no advertising identifiers. The app never shows an App Tracking Transparency prompt, because it has nothing to track with.
- We do not collect precise or coarse location, contacts, calendars, health data, browsing history, or payment details.
- We do not see which apps your child opens, how long they use them, or what they do inside them. DonePass can block an app; it cannot watch one. §4.6 is the long version, and it is worth reading, because most parental-control products do the opposite.
- We do not record audio or video. The camera is used only at the moment a child takes a homework photo, and that single still image is the only thing kept.
- We do not collect diagnostics, crash reports, or analytics of any kind. See §4.8.
3. How we get a parent's consent, and why the method is what it is
DonePass collects personal information from children under 13. US federal law — the Children's Online Privacy Protection Act, and the FTC Rule under it at 16 CFR Part 312 — requires us to give a parent direct notice and to obtain verifiable parental consent before we do that.
3.1 The method we use
We use the FTC Rule's "email plus" method. In plain terms:
- When you add a child, we show you a direct notice in the app,
before you are asked to consent to anything. It says what we collect
from your child, what we do with it, and that we never sell it or
share it, and it links to this policy — which is where you will find
how to review or delete it. The fuller notice, covering the same
ground at greater length, is published at
https://donepass.com/consent-notice, so you can read it before you install DonePass and re-read it at any time afterwards. - You give consent inside the app, by confirming you are 18 or older, confirming you are the child's parent or legal guardian, consenting item by item to what we collect, and typing your full legal name as a signature. We record what you ticked, the name you typed, the version of this policy in force, and the time.
- We then take an additional confirming step: after a delay, we email the address on your account confirming that consent was given, what it covered, and how to withdraw it. If the consent did not come from you, that email is how you find out, and it tells you to reply or write to us so we can revoke it.
That confirming email is sent about a day after you give consent. It never names your child: it says "your child", because the company that delivers it is a third party and §3.2 is our promise that we do not hand a child's information to third parties.
3.2 Why we are allowed to use this method, and what it costs you
"Email plus" is not available to every service. Under the FTC Rule it is available only to an operator that uses a child's personal information for its own internal operations and never discloses it — never shares it with a third party, never makes it publicly available.
That is not a description we chose for marketing reasons. It is a constraint we have accepted on how DonePass can ever be built. It is why there is no AI photo check, no analytics SDK, no attribution SDK, no sharing, no feed, no chat, no leaderboard, no public profile, and no "invite a friend". Each of those would be a disclosure, and each of them would take this consent method away from us.
If we ever want to build one of those things, we cannot do it quietly. We would first have to move to one of the FTC's stricter consent methods — a government-ID check, a credit-card transaction, a video call with a trained reviewer, or a paid consent vendor — re-obtain consent from every existing parent under that method, and rewrite this section before the feature shipped. We are telling you that here so you can hold us to it.
3.3 What happens if you do not consent
Nothing about your child is collected. There is no child profile, no session, no photo, and no app blocking. A child profile cannot come into existence any other way.
4. What we collect, and why
Everything in this section is entered by a parent or a child, or is generated by the app in the course of doing what it was asked to do. There is no background or passive collection.
4.1 Parent account
| Data | Source | Why |
|---|---|---|
| Email address | Sign-up, or Sign in with Apple | Sign-in, account recovery, account-level notices, and the consent emails in §3 |
| Display name | Typed by the parent | Shown in the app |
| Family name | Typed by the parent | Groups the account's children |
If you sign in with Apple and choose Hide My Email, we receive Apple's relay address and never see your real one. That relay address is all we store. Note that the consent emails in §3 are sent to it, so it has to keep working.
4.2 The parental-consent record
At sign-up a parent types their full legal name and ticks each consent item individually. We store the typed name, which items were ticked, the name of the child the consent refers to, the version of this policy in force at the time, and the timestamp.
We keep this because COPPA — and, for UK and EU families, the GDPR's children's provisions — require us to be able to show that a verifiable adult consented before a child's information was collected. It is the single record that makes everything else in this policy lawful. §8 explains how long we keep it, which is deliberately different from everything else here.
4.3 Child profile
| Data | Source | Why |
|---|---|---|
| Child's first name or nickname | Typed by the parent | So the parent can tell their children apart in the app |
| Colour and emoji avatar | Chosen from a fixed list | Visual identity; no uploaded photo |
| Streak count and last streak date | Computed by the app | The streak feature |
We ask for a first name or nickname only. Nothing in the app requires a child's surname, birth date, school, address, or photograph of their face, and there is no field for any of them. We deliberately collect less about a child than we could, because under §3.2 everything we collect is something we then have to protect and be accountable for.
4.4 Paired child devices
When a parent pairs a child's device, we store the device's name as iOS reports it (for example, "Sam's iPhone"), when it was paired, when it was last seen, and whether it has been revoked. Pairing itself uses a short-lived code that expires and can be used once.
The child's device checks in with us roughly every 30 seconds while it is in use. That check-in carries no information about what the child is doing — it says "this device is still here, and blocking is still in the state you think it is". It is how the parent's screen knows whether the child's phone is online, and it is how we detect that Screen Time permission has been switched off (see §4.6).
We also keep an audit log of pairing events — code generated, code claimed, code cancelled, device revoked — so a parent can see the full history of which devices were ever connected to their family. This log is visible to the parent inside the app.
4.5 Sessions, tasks, and homework photos
| Data | Notes |
|---|---|
| Session start and end times, duration, approval mode | The focus session itself |
| Task descriptions and subject tags | Typed by the child or the parent |
| Break requests, their timestamps and outcomes | The break feature |
| Recurring schedules and saved session presets | Parent convenience settings |
| Homework photos | Taken by the child as proof of finished work |
| Optional note from the child, and the parent's decision and note | Attached to the proof |
Homework photos are the most sensitive thing DonePass holds, and they are treated accordingly — see §6.
A photo taken in DonePass is seen by exactly two categories of person: the child who took it and the parents on that family account. It is not seen by us in the ordinary course of running the service, it is not shown to any other family, and it is not sent anywhere for analysis.
An automated photo-check feature was designed and then cut before launch. Every trace of it is gone from the database as of 2026-08-13 — its log table, and the three columns on the proof record that would have held a verdict. No photo is sent to any external service for analysis, and there is nowhere left to record one if it were. As §3.2 explains, sending a child's photograph to an AI provider would be a disclosure, and a disclosure would end the consent method this whole product depends on. That is why this is a permanent decision rather than a scheduling one.
4.6 App blocking — what stays on the phone, and what reaches us
DonePass blocks apps using Family Controls, a framework built into iOS by Apple specifically so that parental-control apps can restrict apps without being able to see what a child is doing. We use it the way it was designed to be used, and the consequence is that we know strikingly little.
What happens on the child's device and never leaves it:
- The list of apps to block is chosen on the child's device, in a picker drawn by iOS itself. We do not draw that screen and we cannot read it while it is open.
- iOS hands our app opaque tokens, not app names. Apple designed them this way: a token identifies an app to the system, but it cannot be turned back into a name or a bundle identifier by us. Even on the device, DonePass does not know that one of your child's blocked apps is, say, a particular social network.
- The selection is stored in a private container on the phone, shared only between DonePass and its own iOS extension. It is not uploaded.
What reaches our servers:
- A count. For example,
12. - A SHA-256 digest of the selection — a one-way fingerprint we use only to tell whether the selection has changed since we last looked. A digest cannot be turned back into a list.
That is the complete list. It is why the parent's screen in DonePass shows "12 apps blocked" and not a list of names: we could not show the names if we wanted to, and neither could anyone who obtained a copy of our database.
What we do not get, at all: which apps your child opens, how often, for how long, at what time of day, or what they do inside them. Family Controls does not hand that to us, and we do not request it.
On Screen Time permission. Blocking requires the parent or the child to grant DonePass Screen Time (Family Controls) authorisation on the child's device. There are two ways to grant it, and they are genuinely different products:
- Through Family Sharing, where a parent approves with their own Apple ID. The child cannot revoke it. This is the mode we recommend and the mode the app steers you towards.
- On the device itself, where the child's own device grants it. Apple's own documentation is explicit that in this mode the system deliberately leaves the user able to bypass parental controls — by switching the permission off in Settings, by deleting DonePass, or by signing out of iCloud. We cannot prevent any of those, and we do not claim to. What we can do is notice: the 30-second check-in in §4.4 stops arriving, and we tell you. Detection is what this mode offers. Enforcement is what Family Sharing offers.
We are stating this in a privacy policy rather than burying it in a help article because a parent deciding whether DonePass is worth installing deserves to know which of those two things they are buying.
4.7 Notifications and push tokens
When something happens that a parent should know about — a proof submitted, a break requested, a session finished, a child's device gone quiet — we create a notification record containing the type, a title, a short body, and whether it has been read.
To deliver that as a push notification we store the device's Apple Push Notification service token, the platform, whether the token is for Apple's production or sandbox environment, and when it was last seen.
A push token is a device identifier. It is used solely to route notifications to the right phone. It is not an advertising identifier, it is not linked to anything outside DonePass, and it is deleted with the account. Push is best-effort: if delivery fails, the in-app notification still stands.
4.8 Diagnostics: none
DonePass v1.0 collects no diagnostics at all. Decided 2026-08-13, reaffirmed 2026-08-18, and not left to a default.
The Sentry crash-reporting library is present in the app bundle but is never started: the code checks for a reporting endpoint at launch, finds none, and skips initialisation entirely. It opens no connection and sends nothing — not a crash, not a performance sample, not a heartbeat.
There is no analytics SDK, no attribution SDK, and no product-usage logging in the app. Under §3.2, an SDK that profiled children would not merely be unpopular; it would take our consent method away.
The consequence, stated plainly: there are no crash reports for
v1.0. If DonePass crashes on your phone, we find out because you tell
us at support@donepass.com.
If a future build enables crash reporting, this policy will be updated
before that build ships, the App Store privacy labels will be updated to
declare Crash Data and Performance Data, and this section will say so.
We will not enable it silently. The order is deliberately awkward so it
cannot happen by accident: rewrite this section, add Crash Data and
Performance Data to PrivacyInfo.xcprivacy, tick both in App Store
Connect — and only then supply a reporting endpoint to the build.
Separately from the app: our infrastructure provider (§7) keeps short-lived operational logs of requests made to our servers, in the ordinary course of running a database. Those are its logs of our service's operation, not telemetry we collect from your phone, and we do not use them to build any profile of a parent or a child.
4.9 The website
Separately from the app, the DonePass website may collect an email address you type into the launch waitlist form, and your name, email, topic and message if you use a contact form. They are not merged with app account data. The website is not directed at children and collects nothing from them.
A waitlist address is used for two messages and nothing else: a confirmation when you join, and one message when DonePass launches. It is never sold, never rented and never shared with anyone outside the mail provider that delivers those two messages. Every one of them carries a one-click unsubscribe link, which takes effect immediately and needs no account, no password and no reply from us. You can also write to the address in §12 and we will remove you by hand.
5. Legal bases (UK/EU users)
| Purpose | Basis |
|---|---|
| Creating and running the account, sessions, proofs, notifications, and app blocking | Performance of a contract (Art. 6(1)(b)) |
| Storing a child's information | Parental consent (Art. 6(1)(a), Art. 8), given by the account holder |
| Keeping the consent record itself | Legal obligation, and legitimate interest in demonstrating compliance |
| Keeping the service secure and preventing abuse | Legitimate interests (Art. 6(1)(f)) |
Consent given for a child's data can be withdrawn at any time by deleting the child profile or the account. Withdrawal does not make the prior processing unlawful.
6. How homework photos are protected
- They are stored in a private storage bucket. There is no public URL for any photo, ever.
- Access is granted per-object by a database rule that walks the photo's path back to the task, the session and the family. A signed-in user who is not the child who submitted it or a parent in that family cannot read it, even with a direct link to the object.
- Where the app needs to display one, it generates a link that expires after 7 days.
- Photos are transmitted over HTTPS.
7. Who else touches the data — and why that is not "disclosure"
This section carries more weight than its length suggests, because §3.2 means that a single wrong entry in the list below would make our consent method unlawful.
The list has three entries.
Supabase — our database, authentication, file storage, and serverless functions provider, acting as a data processor on our instructions and under contract. All account, session, proof and notification data lives there. Supabase does not use it for its own purposes, does not sell it, and does not have permission to do anything with it other than run the service for us.
Apple — Sign in with Apple for authentication, and the Apple Push Notification service for delivering notifications. Apple receives the push token and the notification payload in order to deliver it. Apple also operates the Family Controls framework in §4.6, entirely on the device.
Resend — our email provider, acting as a data processor. It delivers the confirming email described in §3.1 step 3 and our own internal operations mail. Resend receives your email address, the legal name you typed as your signature, and fixed text written by us. It never receives your child's name, or anything else about your child. That is not a promise we merely intend to keep; it is a check in the sending code, which refuses to transmit a message containing the child's name we hold on the consent record.
Under the COPPA Rule, giving information to a service provider that processes it only to support the internal operations of our service is not a "disclosure". Making it public, selling it, or handing it to a company that will use it for its own purposes would be. We do none of those, and §3.2 explains why we have arranged the product so that we cannot start doing them without telling you first.
We use no analytics providers, no advertising networks, no attribution SDKs, no AI services, and no consent-verification vendor. If that list ever gains an entry, this policy changes before the build ships.
Data is stored in the United States — our Supabase project runs in AWS
us-east-1 (North Virginia). If you use DonePass from the UK or the
EEA, your data is transferred to the US, and that transfer relies on the
mechanisms in our processors' terms.
8. How long we keep things, and what deletion actually removes
We do not keep personal information indefinitely. We keep it for as long as it is needed for the purpose it was collected for, and then we delete it. The specifics are below.
Account data is kept for as long as the account exists. There is no inactivity purge in v1.0.
Settings → Delete Account erases, immediately and without a grace period: children, sessions, tasks, proofs, break requests, recurring schedules, notifications, saved presets, invitations sent, the family record, the parent record, the app-blocking count and digest, and the sign-in credential itself.
Two deliberate exceptions:
8.1 The parental-consent record is retained after deletion
COPPA requires us to be able to demonstrate that consent was obtained before a child's information was collected. If we destroyed that record along with the account, we would have destroyed the only evidence that the collection was ever lawful — which is the wrong half of the problem to solve.
So when an account is deleted, the consent record survives, stripped of everything that identifies a living person. What remains is: which items were consented to, the policy version, the timestamp, and the typed signature. It is keyed to an identifier that no longer resolves to an account.
We keep it for three years after the account is deleted, and then we
erase it. If you want it erased sooner, write to support@donepass.com
and say so; we will erase it and record that we did.
8.2 Photo files are removed on a slightly different schedule
Deleting your account walks your family's photos and removes them from storage first, then erases every database record. If a file removal fails — storage being briefly unavailable, say — the account deletion still completes rather than stopping half-done, and the file is left with no database record pointing at it, which means nothing in the app can reach it. Files in that state are cleared by a separate sweep, which runs once a day.
Deleting a single child profile, session, task or proof removes those records the same way, immediately.
9. Your rights
You can exercise all of these by writing to support@donepass.com. We
answer within 30 days. We do not ask you to file a public bug report
to exercise a privacy right — an earlier version of this policy did,
and that was wrong.
Because DonePass holds information about children, a parent has additional rights under COPPA that we want to state explicitly: you may review the personal information we hold about your child, refuse to let us collect any more of it, and require us to delete it — and we may not make continued use of the service conditional on your agreeing to more collection than is reasonably necessary.
- Access — every record we hold about your family is visible to you inside the app. Settings → Export my data produces the whole thing as a JSON file you can copy or share. On request we will also provide it by email.
- Portability — the same export is machine-readable. Note that photo links inside it stop working after seven days (§6); ask us if you need the image files themselves.
- Correction — profile, family name and child profiles are editable in the app at any time.
- Deletion — Settings → Delete Account, or ask us. §8 says exactly what that removes.
- Withdraw consent — delete the child profile or the account. This also ends any app blocking on that child's device.
- Object or restrict — write to us.
- Complain — you may complain to your data-protection authority. In
the UK that is the ICO (
ico.org.uk); in the EU, your national authority; in the US, the FTC.
10. Children
DonePass is set up and controlled by a parent or legal guardian. The parent is our customer; the child uses the app under that parent's account and supervision.
- A child cannot create an account. The only way a child profile exists is that an adult signed in, attested under their legal name that they are that child's parent or guardian, consented to each item individually, and completed the confirmation step in §3.
- A child cannot see, and cannot be seen by, any other family.
- There is no chat, no messaging, no friend list, no public profile, no feed, no leaderboard across families, no user-generated content visible to anyone outside the family, and no way for a stranger to contact a child through DonePass. Under §3.2 these are not features we have not got round to; they are features we have given up.
- There is no advertising and no profiling.
- A child cannot spend money in DonePass. As of 2026-08-19 the app does have in-app purchases — an unlock, sold as either a one-time Lifetime purchase or a Monthly subscription — but the purchase screen exists only in the parent's side of the app, behind the parent's sign-in. A paired child device never reaches it: it routes straight to the child's own screens and has no purchase surface anywhere in it. No price, no buy button, and no upsell is ever shown to a child.
- There is no advertising in the app, and nothing in it encourages a child to ask a parent to buy anything.
- Phone and Messages are never blocked by DonePass. A blocked child can always call and text, including emergency services.
If you believe a child's information has been provided to us without the
consent of their parent or guardian, write to support@donepass.com and
we will delete it.
11. Security
- Row Level Security is enabled and enforced on every table holding family data. A signed-in user's queries are filtered to their own family by the database, not by the app.
- Homework photos are in a private bucket with per-object access rules (§6).
- The child's app selection never leaves the child's device (§4.6), so it cannot be exposed by anything that happens to our servers.
- Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure provider.
- Administrative credentials are held only by our serverless functions and are never present in the app.
No system is perfectly secure. If you find a vulnerability, please
report it privately to support@donepass.com with "security" in the
subject line, and give us a reasonable chance to fix it before
disclosing it publicly. We will not pursue good-faith security research.
12. Changes to this policy
We will update this policy as the app changes. The date at the top always reflects the current version.
For changes that materially affect existing users we will show a notice in the app and ask you to acknowledge it before continuing. For any change that would widen what we collect from a child, or that would introduce a disclosure of a child's information to a third party, we will obtain fresh parental consent under §3 before the change takes effect — not merely notify you of it.
13. Contact
Privacy and data-protection enquiries: support@donepass.com
Support: support@donepass.com
Postal: Sawariya Seth LLC, DBA DonePass, 5 Kennedy Cir, Brentwood NH
This policy online: https://donepass.com/privacy
Terms of Service: https://donepass.com/terms
The direct notice to parents: https://donepass.com/consent-notice