01
Overview
ReadBank ("ReadBank," "we," "us") is a mobile app that helps kids build a reading habit: they read books, answer a short AI-graded comprehension check, and earn screen time and in-app rewards their parent controls. This policy covers the ReadBank iOS app and its backend services. It does not cover third-party sites we merely link to.
ReadBank is operated by Cassandra Kim. If you have questions, see Contact us below.
02
What we collect
We collect only what the app needs to function. Two categories: information about the parent (who creates and controls the account), and information about each child profile the parent sets up.
From the parent
| Data | Why we have it |
|---|---|
| Email address | Sign-in and account identification (via Supabase, our authentication provider) |
| Name | Personalizing the app; pulled from your Apple/Google account if you sign in that way, or entered by you |
| Sign-in method | Email/password, Sign in with Apple, or Sign in with Google — we never see or store your password or your Apple/Google credentials ourselves |
| A separate "exit PIN," if you set one | Lets you gate leaving Kid Mode; stored only as a one-way hash, never in plain text |
| Subscription status | Whether you're on the free or premium plan; billing itself is handled entirely by Apple (see Subscriptions) |
For each child profile
| Data | Why we have it |
|---|---|
| First name | Personalizing their experience |
| Age, grade, reading level (all optional) | Pitching comprehension questions at the right difficulty |
| A 4–6 digit PIN, set by the parent | Lets the child open their own profile; stored only as a one-way hash |
| Reading activity | Which books, how long, pages read, comprehension answers/summaries, XP, level, streaks, badges, screen-time balance, and any custom reward goals a parent sets up |
What we don't collect
No location data, no contacts, no photos or camera access, no microphone access. We don't run any analytics SDKs. The one exception is Google AdMob, used only to show a small ad to free-plan parents in the parent dashboard (see Who we share it with) — it is never shown in Kid Mode, and it is configured to serve only non-personalized, contextual ads, never using a child's data or any advertising identifier to target them.
03
How we use it
- To create and run parent and child profiles, and keep Kid Mode separated from the parent's account.
- To generate and grade comprehension questions about what a child read (see AI & the comprehension check).
- To calculate and track XP, levels, streaks, badges, screen-time balance, and custom reward goals.
- To let a parent review their child's reading activity and approve or manage screen-time requests.
- To process subscription purchases (handled by Apple — see Subscriptions).
- To keep the service secure and working as intended (fraud prevention, rate-limiting, debugging).
We do not use any of this information to build advertising profiles, and we do not use a child's information for any purpose unrelated to running ReadBank for that family.
05
AI & the comprehension check
After a child finishes reading, ReadBank asks them to describe what they read in their own words, then asks a few follow-up questions to check understanding. This is powered by Anthropic's Claude AI.
- The AI is deliberately never given the book's actual text — only its title, author, genre, an official short description if one is on file, the child's reading level, and the child's own account of what they read. This is a design choice, not a limitation: it means the questions come from what the child tells us, not from the AI's memory of a copyrighted book.
- The child's typed answers and summaries are sent to Anthropic solely to generate the next question and produce a comprehension score. Anthropic acts as our service provider for this feature and does not use this content to train its models or for any purpose other than providing this feature to us. confirm current Anthropic API/DPA terms before launch
- Comprehension results (pass/fail, score) are visible to the child's parent in the app.
06
Children's privacy (COPPA)
ReadBank is used by children under 13, so we designed the app around the Children's Online Privacy Protection Act (COPPA) from the start:
- Children never create their own account. Only a parent, who has verified their own identity by signing in with email/password, Apple, or Google, can create a child profile. A child profile only exists inside, and is only reachable through, a parent's account.
- We collect the minimum needed to run the app for that child — first name, optional age/grade/reading level, a hashed PIN, and their reading activity. We do not collect a child's last name, address, phone number, or precise location, and we never ask a child to create their own login.
- We do not use a child's information for behavioral advertising, do not show ads to children, and do not enable any social features that would let a child communicate with people outside their own family.
- A parent can review, correct, or delete their child's information at any time — either by editing/removing that child's profile in the app, or by deleting the whole account (see Retention & deletion), which permanently removes every child profile and all associated reading data.
- A parent can refuse further collection of their child's information at any time by deleting that child's profile or the account entirely.
If you believe your child has provided us with personal information without your consent, contact us at the address below and we will delete it.
07
Retention & deletion
We keep account and reading data for as long as the account is active, so the app can keep working the way you expect (streaks, badges, and reading history all depend on it).
A parent can permanently delete their account at any time from My Account → Delete Account in the app. This immediately and permanently deletes:
- The parent's sign-in account.
- Every child profile under that account and all of their reading history, comprehension answers, XP/streaks/badges, and screen-time data — unless another parent is also on the account, in which case only the parent who requested deletion, and information solely tied to them, is removed.
This action cannot be undone. There is no separate "soft delete" or recovery window.
08
Your rights & choices
- Access & correction: edit a child's name, age, grade, or reading level anytime in the app.
- Deletion: delete a single child profile, or the entire account, from the app (see above).
- Portability: email us at the address below to request a copy of your account's data.
- Marketing: we don't send marketing email unless you separately opt in (e.g., the public waitlist), and any such email includes an unsubscribe link.
09
Security
We use industry-standard safeguards, including: encrypted connections between the app and our servers, one-way (bcrypt) hashing for every PIN and password — we cannot look up a PIN or password even internally — and authentication tokens verified against Apple/Google/Supabase's own signing keys rather than a shared secret. No method of transmission or storage is perfectly secure, but we work to protect your family's information and will notify affected users if we become aware of a breach involving personal information, as required by law.
10
Subscriptions & payment
ReadBank offers an optional Premium subscription. All payment is processed by Apple through the App Store — we never receive or store your card details. See our Terms of Service for the full subscription terms (pricing, auto-renewal, and how to cancel).
11
International users
ReadBank is currently designed for and offered to users in the United States. If you access it from elsewhere, you understand your information will be processed in the United States, which may have different data protection laws than your country. add a GDPR/UK-GDPR section before offering the app outside the US
12
Changes to this policy
If we make material changes to this policy — especially anything affecting how we handle children's information — we'll update the effective date above and notify parents in the app or by email before the change takes effect.
13
Contact us
Questions about this policy or your family's data: privacy@readbank.app