Watchwise Family

Privacy Policy

Watchwise is used by children, so the standard has to be higher than "legally defensible." This page says exactly what we hold, why, and what we never touch. If anything here is unclear, email us and we'll explain it properly.

Last updated 6 August 2026.

The short version

What we actually store

About a parent: your email address (it's your login), your name, and a securely hashed version of your password — we cannot read your password, only check it. If you turn notifications on, a push token for your phone. Your notification preferences.

About a child: their first name only. That's the complete list. We don't ask for a birthdate, an email address, a photo, a school, or a last name, and a child never creates an account or signs in to anything.

About your family: your family's name, timezone and currency, the times of day you've defined as afternoon and evening, and — if you subscribe — the subscription status Apple reports to us.

About a paired watch: a name for the device, its hardware model string (e.g. "Watch7,2"), its watchOS version, our app's build number, and a notification token. We also store a hashed pairing token so the watch can identify itself. Apple does not give apps a device serial number or permanent hardware ID, and we don't have one.

What your family creates: the jobs you write, which ones got done and when, allowance settings, savings goals, the giving jar, and the ledger of credits and deductions. These are your family's records. We store them so the apps can show them to you.

If you join the waitlist: just your email address, so we can tell you when the app launches.

What we never collect

No location. No contacts. No photos or camera access. No health data. No microphone. No advertising identifier. No browsing or usage analytics. No crash-reporting service. No payment card details — when you subscribe, Apple processes the payment and tells us only whether the subscription is active, never your card.

There is no analytics or advertising software of any kind inside the iPhone app, the watch app, or this website. This isn't a promise about how we use such data — there is none to use.

Who else is involved

Your family's data lives on our own server in Canada. We don't use a third-party analytics provider, advertising network, or data broker. Three parties do unavoidably touch parts of it:

Apple

Handles subscription payments (we never see your card) and delivers notifications to your kid's watch. Apple's own privacy policy governs what they collect.

Expo's push service

Notifications to a parent's iPhone are delivered through Expo's push service, which means the text of those alerts — which can include a child's first name and a dollar amount — passes through their systems on the way to Apple. Turning notifications off in Settings stops this entirely.

Our own mail server

Invite emails, password resets and payday recaps are sent from a mail server we run ourselves. They aren't handed to a marketing platform, and we don't run mailing lists.

One more, for completeness: this website loads its typeface from Google Fonts, so Google sees the IP address of visitors to the website. The apps themselves talk to nothing but our own server. We intend to host the font ourselves and remove that.

Children

A parent creates the account and controls it. Children don't sign up, don't sign in, and have no credentials — a child's watch is paired by a parent using a short code, and the parent can unpair it or delete the child's profile at any moment.

Because we store only a first name, a child's records are not meaningfully identifying on their own. We do not build profiles of children, do not advertise to them, do not use their data to train anything, and do not disclose it to anyone. The watch app contains no browser, no links out, no social features, and no way for a child to contact a stranger or spend money.

How long we keep it, and how to delete it

We keep your family's data for as long as your account exists, because the whole point is that you can scroll back through last October and see what happened.

The account owner can delete the entire family from Settings → Delete account & all data. That removes your family's records from our systems, including your children's. It is permanent and we cannot undo it for you.

Deleted data can persist in encrypted backups for up to 30 days, after which those backups roll off automatically. Individual items you delete — a job, a savings goal, a ledger entry — are removed immediately.

Removing a co-parent ends their access straight away. Signing out ends the session on that device.

Security

Passwords are hashed with bcrypt and never stored in a readable form. Login sessions and watch pairing tokens are stored only as cryptographic hashes, so a copy of our database would not let anyone sign in as you. Traffic between the apps and our server is encrypted in transit. Pairing codes expire in fifteen minutes and work once.

We're a small operation and we won't pretend to be an enterprise security department. What we can promise is that we collect little enough that there isn't much to lose, and that if we ever discover a breach affecting your family, we will tell you directly rather than quietly.

Your choices

Canadian privacy law (PIPEDA) and, where it applies, your provincial or state law gives you rights over your personal information. Email us and we'll honour them.

Changes, and how to reach us

If we change this policy in a way that matters, we'll email the address on your account and update the date at the top. We won't quietly start collecting something new.

Watchwise Family is made by Colin Tulloch, a sole proprietor in Saskatchewan, Canada. Questions, concerns, or a request to delete something: hello@watchwisefamily.com. A real person reads it.

Our terms of service →