Children's privacy policy
Last updated: August 31, 2026
If your child or the child in your care uses the Tasnna mobile app, this page explains what data we process, how we protect it and what rights you have as a parent or legal guardian.
Who creates and controls the account
Accounts are always created by an adult, who states they are the child's parent or legal guardian and gives consent for their data to be processed. The child reaches the app on their own device with a code the adult generates; the child's profile has no email, no phone, no password of its own, and receives no marketing messages.
Rights of parents and guardians
You have the right to:
- Download all of your child's data in a readable format (JSON), including chores, savings goals, achievements and activity.
- Permanently delete all of your child's data at any time from the app.
- Edit or update the child's nickname at any time from the app.
- Contact us if you have questions about how we process your child's data.
Data we process
- The child's nickname: an adult chooses it when creating the profile, and it does not have to be their real name (no surname, email or phone).
- Activity in the app: chores created and finished, savings goals, achievements, virtual money (wallet), wallet movements, balance transfers between siblings and streaks.
- Vacation periods: the dates the adult marks as vacation, so the child's streak is not broken and no consequences apply for chores that expire during those days.
- Behavior deductions: the parent or guardian can record behavior deductions with a reason, a description and a virtual penalty (money or XP). They are only visible inside the family and exist to help the adult follow the child's progress.
- Proof photos (optional): if the child attaches a photo when finishing a chore, it is stored only so the adult can review it and it is deleted automatically the moment the chore is approved.
- The child's access code and PIN, stored hashed, and a session and device token to keep the account signed in securely.
We do not ask for or store phone numbers, addresses or the child's location. We do not show ads and we do not use the child's data for advertising profiling. Data is synced only inside the family.
How to exercise your rights from the app
Without contacting support, you can:
- Open the app and go to Settings → Privacy
- Pick the child whose data you want to download or delete
- Tap "Download [nickname]'s data" or "Delete [nickname]'s profile"
- Confirm with your PIN when asked
The download is generated in JSON format and you can share or save it from your device. Deletion is permanent and cannot be undone. To edit the child's nickname, open their profile (Children tab → View profile, or Settings → Family) and tap Edit.
Where we operate and protection by country
Tasnna currently operates in Spain, the United States, Argentina, Mexico, Colombia, Chile, Peru, Uruguay, Paraguay, Bolivia, Costa Rica, Guatemala, Honduras, Nicaragua and the Dominican Republic. Data is stored on servers in the European Union (Ireland).
- European Union (Spain): minors' data is protected by the GDPR and Organic Law 3/2018 (LOPDGDD). Processing a minor's data is based on the consent of their parent or legal guardian.
- Argentina: we apply data protection Law 25.326, with the same standard of parental consent and rights of access and erasure.
- Mexico: Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).
- Colombia: Law 1581 of 2012.
- Chile: Law 19.628, in force until the new Law 21.719 takes effect (December 1, 2026), at which point we will apply that one.
- Peru: Personal Data Protection Law 29733.
- Uruguay: Personal Data Protection Law 18.331.
- Paraguay: Personal Data Protection Law 7.593/2025.
- Costa Rica: Law 8968 on the Protection of the Person in the Processing of their Personal Data.
- Nicaragua: Law 787, Personal Data Protection Law.
- Dominican Republic: Law 172-13 on the Protection of Personal Data.
- Bolivia, Guatemala and Honduras: as of today there is no general personal data protection law applicable to the private sector in these countries. With no specific rule, we apply the same criterion as in every other market as our own standard: the account is opened by an adult, who consents to the processing of the child's data, and that adult can access, correct or delete that data at any time. We will update this policy as soon as each country has legislation in force on the matter.
In every country where we operate we apply the same baseline: the account is opened by an adult, who consents to the processing of the child's data, and that adult can access, correct or delete that data at any time.
United States: verifiable parental consent (COPPA)
Tasnna is also distributed in the United States. The Children's Online Privacy Protection Act (COPPA) applies there, and it requires verifiable parental consent before collecting personal information from a child under 13.
When you create the family we ask once whether you live in the United States. That answer cannot be changed afterwards: if it could, unticking it would be enough to skip the permission.
What needs permission and what does not. What COPPA governs is information collected from the child. The nickname is typed by the adult, and the app stops a child from changing their own name. The device identifier used for notifications is covered by the support-for-internal-operations exception. The one piece the child uploads themselves is the proof photo of a chore, and the rule expressly mentions photographs containing the child's image. That is why, and only in the United States, photos start switched off until an adult allows them. The rest of the app works normally in the meantime.
How we verify that the person allowing it is the parent. We use the method the FTC calls email plus (16 CFR 312.5(b)(2)(vii)), which is available to us because we do not disclose the child's information to third parties: the photo never leaves the family and is deleted the moment the chore is approved. It has two steps:
- We send a 6-digit code to the email address on the adult's account (the server picks it, not the app) and it has to be typed in for the permission to count. The code expires in 30 minutes and allows five attempts.
- 24 hours later we send a second email to that same address confirming that the permission was given and explaining how to take it back. That second notice is what makes the method verifiable: if the person who typed the code was not the adult, the adult finds out anyway.
Taking it back is immediate and needs no code. In the app, under Settings → Privacy, you can switch photos off whenever you want. Putting an obstacle in the way of withdrawing consent would be the opposite of what the rule is for.
We keep the record of each consent: which address it was sent to, when it was confirmed, against which version of this notice, and when the second email went out. COPPA does not only ask you to have consent, it asks you to be able to show it.
As in every other country, you can access your child's data, download it and delete it at any time from the app, and write to us at info@tasnna.com with any question.
For any question about the child's rights, write to info@tasnna.com.
Security
Minors' data is stored encrypted on secure servers (Supabase, in the European Union). Access is restricted by family through row level security rules and authentication. If we detect a security breach affecting your child's data, we will notify you as the law requires.
Questions
If you have questions about how Tasnna handles your child's data, write to info@tasnna.com. You can also read our full Privacy policy.