Privacy Policy
Effective date: 24 August 2026
Last updated: 24 August 2026
Loulwa Bukhadour ("we," "us," "our") operates the Youmi mobile and web application (the "Service"). This policy explains what information the Service collects, how it's used, and the choices available to you.
1. WHO THIS APPLIES TO
Youmi is a family task-management app used by three kinds of accounts within a household:
• Adults — sign up with an email and password, and can create and manage the family.
• Teens — sign up with their own email and password, subject to an age check at signup (see §5).
• Kids — do not have an email address or password. A parent creates a kid profile and gets a one-time family code; the kid signs in on their own device using that code plus a 4-digit PIN they set with a parent. We do not collect a kid's email, phone number, or any contact information.
2. INFORMATION WE COLLECT
Provided directly
• Account info (adults/teens): email address, display name, password (stored hashed, never in plain text), optional avatar, birth year (teens only, used solely for the age gate described in §5).
• Kid profiles: display name, avatar, and a PIN (stored as a one-way hash, never in plain text — we cannot recover it). No email or other contact info is collected for kid profiles.
• Family content: tasks you create (titles, notes, due dates, recurrence), task completions, star/reward activity, redemption requests, and messages implicit in feature use (e.g., a link request between a teen and a parent, or a schedule-sharing invite between two adults).
Preferences
• Language, numeral style, calendar preference, notification setting, and display preferences (text size and colour theme), stored on your profile so they follow you across devices.
Collected automatically
• Standard technical data needed to operate the Service (timestamps, device/session identifiers used for authentication). As of this writing, Youmi does not integrate any third-party analytics or advertising SDK — if that changes, this section must be updated before the change ships.
We do not collect
• Precise or coarse location data.
• Contact lists, photos/camera access, microphone, or other device sensors beyond what's listed above.
• Any behavioral advertising data, and we do not serve behavioral ads.
3. HOW WE USE INFORMATION
• To provide the core functionality: task lists, completions, streaks/trophies, reward redemption, family linking, schedule sharing between adults, and settings.
• To authenticate accounts and secure kid sign-in (PIN attempt limits and temporary lockout after repeated failures).
• To send in-app notifications you've opted into (§ Settings → Notification preferences). We do not currently send push or email marketing.
We do not sell personal information, and we do not use children's information for behavioral advertising, profiling, or any purpose unrelated to operating the family's own task list.
4. WHO CAN SEE WHAT
• A parent/adult who has actively linked a kid or teen profile can see that profile's tasks, completions, and reward activity — this is core to the product (a family task app).
• Two adults only see each other's tasks if one explicitly invites the other, the invite is accepted, and the owner then chooses specific tasks to share. Being connected grants no visibility on its own; either side can revoke the connection at any time.
• You may also connect people outside your household (for example a friend, a housekeeper, or a driver) and label the relationship. The same rule applies: they see only the individual tasks or grocery lists you deliberately share with them, and nothing else.
• We use row-level security at the database layer so an account can only read data it's actually entitled to see under the rules above — not "anything in the same family," but specifically the relationships that have been established and accepted.
5. CHILDREN'S PRIVACY (COPPA AND SIMILAR LAWS)
Youmi is a family app that necessarily involves children's data — this section exists to describe that plainly, not to bury it.
• A kid profile is created by a parent, inside the parent's own account, not by the child signing up independently.
• We collect the minimum needed to run the feature: a display name, an avatar choice, a PIN, and the child's task/reward activity within the family.
• Teens who sign up directly go through a birth-year check at registration; anyone below the age threshold configured for direct signup is blocked from self-registering and directed to have a parent create their profile instead (this is the "age gate" referenced in §2).
• Parents can review, edit, or delete their child's profile and data at any time from within the app (Family screen), and can revoke a linked device.
• We do not share children's information with third parties. The app contains no advertising, analytics, or third-party tracking SDKs.
• To request deletion of a child's data, contact developer.loulwa@gmail.com.
6. DATA RETENTION AND DELETION
• Account and family data is retained while the account is active.
• You can delete a task, redemption, or unlink a family member at any time within the app.
• You can delete your entire account from inside the app (Settings → Delete my account). This permanently removes your account and its data. Kid profiles for which you are the only parent are deleted with it, because such a profile has no other way to be reached or managed; a kid who still has another linked parent stays with that parent.
• You can also request deletion by contacting developer.loulwa@gmail.com. We will delete or anonymize the data within 30 days, except where retention is required by law.
7. SECURITY
• Passwords and kid PINs are stored as one-way hashes, never in plain text.
• Data is protected in transit via HTTPS/TLS.
• Access to family data is enforced at the database layer (row-level security), not just in application code.
• Data is hosted on Supabase infrastructure in Singapore (ap-southeast-1).
• To report a security issue, contact developer.loulwa@gmail.com.
8. YOUR CHOICES
• Notifications: toggle on/off in Settings.
• Language/locale: set in Settings; does not affect data collection.
• Sign out / delete: available from Settings on both adult and teen accounts.
• Access/export/correction requests: contact developer.loulwa@gmail.com.
9. INTERNATIONAL TRANSFERS
Data is processed and stored on Supabase infrastructure in Singapore (ap-southeast-1). If you use the Service from outside that region, your information is transferred there.
10. CHANGES TO THIS POLICY
We'll update the "Last updated" date above when this policy changes, and for material changes affecting children's data, we'll take reasonable steps to notify parents before the change takes effect.
11. CONTACT US
developer.loulwa@gmail.com