Privacy Notice
Last updated: October 4, 2026
1. Who we are
Can I is operated by Daniel Dethlefs, who is the data controller for the information described here. Can I is designed around collecting as little personal data as possible. Everyone signs in with a username and password. Email is not required, and child accounts cannot use one. A parent may choose to add an email only for account recovery.
2. What we collect
- Account data: the username you pick, a hashed password, your family group and role (parent or kid), and an optional recovery code (stored hashed).
- Optional parent recovery email: if a parent chooses this option, we use the address only to verify it and send password-reset messages. Children cannot add an email. We also record when the parent accepted the email-safety notice and its version.
- Family content: chores, requests, points, reviews, ratings, feedback messages, and the reference photos, wallpapers and how-to videos a parent uploads.
- Proof photos: taken live in the app by kids and deleted automatically as soon as a parent approves or rejects them.
- Technical data: basic device and log information (such as device type and IP address) needed to run and secure the service.
Payment details are collected and processed by Paddle, our Merchant of Record — we never see or store your card numbers.
3. Why we use it
- To create and run your account and family group (performance of our contract with you).
- To provide the chore, request, photo-proof and review features (contract).
- To keep the service secure and prevent fraud or abuse (legitimate interest).
- To send verification and password-reset messages when a parent chooses a recovery email (consent and performance of our contract).
- To respond to feedback and support requests (legitimate interest).
- To meet legal obligations where they apply (legal obligation).
4. Children's privacy
Kid accounts are created by a parent, who consents to the child's use when setting up the family. Kids are identified only by a username. Kids cannot see the parent chore idea feed, and kid-shared ratings only appear publicly after a parent approves them. We do not show advertising or sell anyone's data — especially not children's.
5. Who we share it with
- Service providers that host and operate the app (cloud hosting, database and file storage) under appropriate safeguards.
- Paddle, our Merchant of Record, for selling subscriptions, managing payments, tax compliance and invoicing.
- Professional advisers (legal, accounting) where needed.
- Authorities where the law requires it.
We never sell personal data.
6. How long we keep it
- Proof photos: deleted automatically the moment a parent approves or rejects them.
- Reference photos, wallpapers and how-to videos: kept until you delete them or close the account.
- Account, family and optional parent recovery-email data: kept while the account is active. A parent can remove or change the recovery email in Family settings; remaining account data is deleted or anonymised within a short period after closure.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or port your data, to object to processing, and to withdraw consent. Because sign-in is username-based, we may need to verify you through your signed-in session before acting on a request. You can also complain to your local data protection authority. We respond to requests within one month.
8. Security
We use appropriate technical and organisational measures, including encryption in transit, hashed passwords and recovery codes, and access controls that keep each family's data private to that family.
9. Cookies
We use only essential storage (for example, keeping you signed in). We do not use advertising or marketing cookies.
10. Contact
Privacy questions or requests: contact Daniel Dethlefs through the in-app feedback box.
