Privacy Policy
Privacy Policy for Choreeo
Choreeo is operated by Choreeo LLC. This policy covers the Choreeo web product, iPhone and Android apps, printable downloads, product-update signups, and support communications.
Overview
Choreeo is built for parents. The product helps a family keep a printed chore chart current without turning the chart into another screen for kids. We try to collect the minimum information needed to run that service.
Controller: Choreeo LLC, PO Box 91, Climax, MN 56523, United States. Privacy questions and requests can be sent to hi@choreeo.com.
What we collect
- The chart you build: your family name, the first names or nicknames and ages you enter for your children, the chores you set up, star values, completion history, and chart preferences.
- Your answer to the first-chart question about which chores you would like to improve. We keep that answer with your family's chart so a restricted Choreeo research team can understand why families try the product. We do not put the answer in advertising or product-usage telemetry.
- An optional email address, if you use it to save or recover a chart, receive product updates you request, or contact support. After verification, Choreeo keeps a keyed lookup value and a masked display form rather than the raw address in the family chart database.
- Content you send us, including support messages and any feedback you share.
- The transcript of a spoken chart update when you choose voice input. On the web, iPhone, and Android, the browser or device's selected speech-recognition service may process microphone audio and return transcript text to Choreeo. Choreeo does not upload or store raw browser microphone audio. On iPhone, Apple speech technology transcribes the recording on the device; Choreeo does not send the raw iPhone recording to its servers or another transcription provider. On Android, the selected system service may process audio off-device.
- Basic technical and usage information, such as a device-generated installation identifier, browser or app context, app version, secure-session and device-access records, and content-free interaction milestones, used to run, secure, measure, and improve the service.
- Limited acquisition information, such as a pseudonymous mobile-installation identifier, app-store/referrer context, and selected registration, content, trial-start, initial-purchase, or trial-conversion events, used to measure the effectiveness of Choreeo's own advertising. We do not send family names, children's information, chores, chart content, messages, voice content, precise location, or advertising identifiers to this measurement service.
- On selected public campaign pages whose addresses begin with
/go/, and on the public/make-a-chartstart page and/make-a-chart/chartworkspace, limited Pinterest advertising-measurement information: a page visit on eligible landings; a lead when a product-led chart starts; a customTTFPrintevent on the first successful print/paper action; and, only on/go/when you choose a store link, that store-link selection; the public page URL and referrer; bounded campaign and Pinterest click identifiers; a browser/server event identifier; and ordinary network context such as IP address and browser user-agent when needed for attribution. The Pinterest measurement flow does not receive family or chart content, child names, or email addresses. - Subscription, trial, transaction, and entitlement status handled through RevenueCat; Apple and Google process native-app purchases, while RevenueCat Billing uses Stripe as the payment gateway for web purchases. Choreeo does not receive or store your full payment-card number.
Where your chart is stored
Your family's chart is stored on secure Choreeo infrastructure hosted by Cloudflare in the United States so authorized browsers and the phones you link can open the same chart. Native apps also keep a device copy so they can work offline and open quickly.
The chart contains the family name, children's first names or nicknames and ages you enter, chores, stars, completion history, chart settings, and any answer you provide during first-chart setup. Choreeo does not ask for or store your precise location in the chart, and there is no separate account for children to sign into.
How we use information
- To create, store, and keep your family chart in sync across authorized browsers and phones, and to produce printable and shareable versions.
- To review first-chart answers in a restricted research view so we can understand what families hoped to improve and make setup more useful.
- To transcribe a spoken update. On the web, the browser or device speech-recognition service returns transcript text and Choreeo receives only that transcript. On iPhone, Choreeo uses Apple speech technology on the device and sends only the resulting transcript. On Android, the selected system speech-recognition service may process audio off-device and return transcript text to the app.
- To understand plain-language updates you type or speak ("Mira finished the dishes") and turn them into chart changes. This step is handled with the help of OpenAI; the small amount of chart context needed is sent to process the request. Choreeo disables response storage, and OpenAI does not use API content to train its models unless Choreeo separately opts in, which we do not do.
- To generate the printable chart page (PDF), including through our hosting provider's rendering tools.
- To send messages you asked for, such as a chart-save or recovery link, support replies, or service notices.
- To monitor reliability, prevent abuse, debug issues, and understand which parts of the product are used. We keep our operational logs free of names and chart content.
- To understand which of Choreeo's own marketing campaigns led to an app installation or selected registration, content, trial-start, initial-purchase, or trial-conversion action, using privacy-limited mobile attribution.
- To measure and improve selected Pinterest campaigns using limited visits and explicit store-link selections on public campaign pages.
- To measure selected Meta advertising using locked mid-funnel Pixel events on eligible public
/make-a-chartand/make-a-chart/chartpages. - To comply with legal obligations and enforce our terms and policies.
Pinterest measurement on public campaign pages
Choreeo uses the Pinterest Tag together with a direct, server-to-server Pinterest Conversions API connection on selected public campaign pages under /go/, on the public /make-a-chart start page, and on the public /make-a-chart/chart workspace for product-led mid-funnel steps. This Pinterest measurement is enabled only when Cloudflare's request-country signal identifies the request as coming from the United States and the request looks like a real browser. An eligible start page sends a PageVisit event. A product-led chart start may send a Lead event. The first successful print/paper action may send a custom TTFPrint event (the primary web-to-print conversion signal). If you explicitly choose an App Store or Google Play link on a /go/ campaign page, it sends a Lead event for that store-link selection. A shared event_id lets Pinterest deduplicate the browser and server copies of the same event. Pinterest Checkout / Subscribe events are not sent from this flow.
The limited Pinterest payload may include the public campaign-page URL and referrer; allow-listed campaign, ad-set, creative, and Pinterest click identifiers; the event name, time, and deduplication identifier; and IP address and browser user-agent only as needed for Pinterest attribution. The Pinterest Tag may set or read cookies and similar identifiers to measure activity after someone sees or engages with a Pinterest ad.
Automatic enhanced match is disabled. Choreeo does not configure this flow to send Pinterest email addresses, names, phone numbers, gender, birthdate, precise location fields, Choreeo family or user identifiers, another external customer ID, or any family-chart, invite, support, or private-page content. Choreeo does not send the request-country result to Pinterest. The public Tag ID identifies Choreeo's Pinterest measurement configuration; the Conversions API access token stays secret on Choreeo's server.
These public-page events help Pinterest measure and optimize advertising, but they do not establish that an app was installed. AppsFlyer remains Choreeo's mobile measurement partner for app-install attribution and selected lifecycle outcomes. Choreeo's AppsFlyer Pinterest integrations are active. For iPhone, the only mapped postbacks are registration, content, trial-start, initial-purchase, and trial-conversion events. For Android, the only mapped postbacks are registration and content events. Every mapped postback is limited to users attributed to Pinterest and sends no event values or revenue. Renewals, refunds, and ongoing subscription-revenue events are excluded. RevenueCat remains Choreeo's subscription and revenue source; its renewal and revenue events are not sent to Pinterest.
Pinterest's use of this website activity for measurement, ad delivery, and online behavioral advertising is described in its Privacy Policy and Ad Data Terms. Depending on where you live, this disclosure may be considered sharing or targeted advertising under privacy law even though Choreeo does not sell the information for money. You can use Pinterest's personalization settings, the AdChoices opt-out, and your browser's cookie controls. When a browser request sends a Global Privacy Control signal (Sec-GPC: 1) or a Do Not Track signal (DNT: 1), Choreeo does not load the Pinterest Tag, send the event through Pinterest's Conversions API, or route the store choice through AppsFlyer's web attribution handoff.
Meta Pixel measurement on public make-a-chart pages
Choreeo uses the Meta Pixel (also known as the Facebook Pixel) on eligible public /make-a-chart and /make-a-chart/chart pages (and on /make-a-chart/saved only after email challenge consume). This Meta web measurement is enabled only when Cloudflare's request-country signal identifies the request as coming from the United States and the request looks like a real browser. Eligible activity may send the locked mid-funnel events PageView (start page), StartTrial (kid submit / cookie trial), ViewContent (chart workspace load), FirstPrint (first successful print/paper), Lead (board save email), and CompleteRegistration (email challenge consumed). Other nested /make-a-chart/* paths and other Choreeo pages do not keep a standing Pixel.
The Pixel may set or read cookies and similar identifiers and may receive ordinary page and browser context that Meta uses for advertising measurement, such as the public page URL and technical browser information. Choreeo does not configure Advanced Matching or otherwise send email addresses, names, phone numbers, gender, birthdate, precise location fields, Choreeo family or user identifiers, or any family-chart, invite, support, or private-page content through this Pixel. Choreeo does not send email addresses to Meta. Choreeo does not send the request-country result to Meta. The public Pixel ID identifies Choreeo's Meta measurement configuration.
This browser Pixel helps Meta measure and optimize advertising. It does not establish that an app was installed, and it does not by itself turn on Meta ads spend. AppsFlyer remains Choreeo's mobile measurement partner for app-install attribution and selected lifecycle outcomes. RevenueCat remains Choreeo's subscription and revenue source.
Meta's use of this website activity for measurement, ad delivery, and online behavioral advertising is described in its Privacy Policy and related advertising terms. Depending on where you live, this disclosure may be considered sharing or targeted advertising under privacy law even though Choreeo does not sell the information for money. You can use Meta's ad settings, the AdChoices opt-out, and your browser's cookie controls. When a browser request sends a Global Privacy Control signal (Sec-GPC: 1) or a Do Not Track signal (DNT: 1), Choreeo does not load the Meta Pixel.
How information is shared
We do not sell personal information for money or show third-party advertising in Choreeo. We use limited technical information to measure Choreeo's own advertising. We share information only with services needed to run, measure, and improve Choreeo. Providers that process information on Choreeo's behalf are governed by their agreements with us. Pinterest and Meta receive the limited public-page activity described above under their advertising terms and may use it for measurement and ad delivery. A device-selected platform service, such as Android speech recognition, operates under that service's own terms, privacy notice, and device settings:
- Cloudflare — hosting, secure chart storage, chart rendering, and email delivery.
- OpenAI — the AI that interprets plain-language chore updates.
- Anthropic — limited photo-to-chart intake, support triage, and spam screening.
- Your Android system speech-recognition provider — processes an optional spoken update and returns transcript text to the app; whether processing happens on-device depends on the service and device settings.
- RevenueCat — web and native subscription checkout, customer management, and family entitlement status. RevenueCat Billing uses Stripe as its web payment gateway.
- Stripe — payment-card processing for RevenueCat Billing web transactions. Choreeo does not receive or store the complete card number.
- AppsFlyer — privacy-limited mobile installation and campaign measurement. Choreeo uses AppsFlyer's no-IDFA iOS SDK, disables Android advertising identifiers, masks IP addresses in the AppsFlyer dashboard, and does not send family-chart content. Its active Pinterest integrations are limited to Pinterest campaign attribution and the platform-specific, partner-only postbacks described above, without values or revenue.
- Pinterest — advertising measurement on selected public
/go/campaign pages, the public/make-a-chartstart page, and eligible/make-a-chart/chartproduct-led steps through the Pinterest Tag and direct Conversions API. The direct web flow receives only the limited page-visit, chart-start lead, first-printTTFPrint, and explicit store-link activity described above. The active AppsFlyer partner connections may additionally attribute Pinterest-driven installs and send the limited, platform-specific no-revenue postbacks described above. Neither path receives family-chart content, and automatic enhanced match and partner advanced matching remain disabled. - Meta — advertising measurement on eligible public
/make-a-chartand/make-a-chart/chartpages through the locked Meta Pixel mid-funnel events described above (/make-a-chart/savedonly forCompleteRegistration). Advanced Matching remains disabled. Email is not sent to Meta. Other nested routes and family-chart content are excluded from the Pixel. This path does not by itself enable Meta ads spend. - Apple and Google — app distribution and in-app purchases/subscriptions.
- Google Fonts — website typography; when a public page loads a font, the browser sends Google ordinary network information such as its IP address and browser headers.
- Email and support providers — delivery and handling of messages you ask us to send or that you send to support.
We may also disclose information if required by law or to protect the rights, safety, and security of Choreeo, our users, or others.
Children's information
Choreeo is intended for parents and guardians, not for children to use independently. There is nothing for a child to download or sign into — a child's only part of Choreeo is the printed page on the fridge. Child information comes from the parent or guardian who builds the chart, not from the child. Parents choose what to enter, typically a first name or nickname and the chores assigned. Please enter only what is reasonably needed to run your chart, and avoid entering sensitive details. You can edit or remove a child, or delete the whole chart, at any time.
Retention
We keep your chart, first-chart answer, verified-email masked form and keyed lookup value, device access records, and subscription status while your family uses Choreeo. Short-lived email, invite, recovery, and device links expire automatically. Secure browser and app sessions expire or can be revoked. If you delete your family from web or app Settings, we hard-delete the chart and its contents, including the first-chart answer and web setup journey, from the live service and queue the corresponding customer-data erasure with RevenueCat and any applicable measurement provider. The deletion request remains in progress until those provider obligations are confirmed. Prior versions may remain in Cloudflare's encrypted disaster-recovery history for no more than 30 days before they roll off automatically.
Choreeo does not retain raw voice recordings on its servers. On the web, Choreeo sends only transcript text returned by browser or device speech recognition. On iPhone, a pending voice recording stays only in protected app storage until the requested chart update finishes, you cancel it, or you remove the app. On Android, microphone audio is handled by the device's selected system speech-recognition service according to that service's terms and device settings.
Pinterest states that cookies created or accessed by its Tag can persist for up to one year unless you delete or block them sooner. Pinterest processes Tag and Conversions API activity under its own privacy policy and advertising terms; those materials do not promise one single retention period for every use of that activity.
Meta processes Pixel activity under its own privacy policy and advertising terms. Meta cookies and similar identifiers may persist according to Meta's settings unless you delete or block them sooner; those materials do not promise one single retention period for every use of Pixel activity.
Choreeo disables OpenAI response storage for plain-language chart updates. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days by default. Anthropic ordinarily deletes auxiliary API inputs and outputs within 30 days; either provider may retain limited records longer where required for safety enforcement or legal obligations. Choreeo does not intentionally submit family content as product feedback or opt in to provider model training. AppsFlyer states that end-user data is retained for no more than 24 months unless Choreeo directs otherwise or law permits or requires it, and that aggregated reporting data may be retained for up to 25 months. Choreeo's limited, content-free acquisition ledger is deleted after no more than 25 reporting months or sooner when you delete your family; that deletion also sends an erasure request to AppsFlyer. We retain a minimal, content-free record that an export or deletion was completed for only as long as reasonably necessary to demonstrate compliance, resolve disputes, or protect legal rights. Support messages, transaction records, and security records are kept only as long as needed for those purposes or as required by law.
Your rights: export and deletion
You are in control of your chart:
- Export — from web or app Settings, get a copy of your family's chart, chores, and relevant account settings.
- Delete — from web or app Settings, delete your family. This removes the chart and everything on it, for everyone on it, and can't be undone. Subscription cancellation is a separate provider action. If a plan is still set to renew, Choreeo asks you to cancel it before chart deletion can continue.
An authorized app device can perform these actions directly. On the web, a retained session and recent email re-verification are required for sensitive actions. If you have lost device and browser access but previously verified an email for the chart, you can request an export or deletion here using that same email. We cannot export or delete a chart unless we can securely verify that it is yours.
If EU, EEA, or UK data-protection law applies to you, you may also ask to access, correct, erase, or restrict your personal data; receive portable data you provided; object to processing based on legitimate interests; and withdraw consent where processing depends on consent. Withdrawing consent does not affect earlier lawful processing. You may lodge a complaint with the data-protection authority where you live or work. We generally respond to a valid rights request within one month, subject to the law's verification, extension, and exception rules.
Legal bases and international transfers
Choreeo is operated from the United States, and your chart is stored in the United States. We process the chart, shared-phone access, printing, and subscription status as needed to provide the service you asked for. Where available and subject to platform and regional consent rules, we rely on legitimate interests to secure the service, prevent abuse, answer support requests, troubleshoot failures, understand reliability, and measure the effectiveness of Choreeo's own marketing, after considering the limited data involved and your rights. We rely on consent for an optional recovery email where consent is the applicable basis, and on legal obligations where we must keep or disclose limited records.
If you use Choreeo from outside the United States, information may be transferred to the United States and other countries where our providers operate. For transfers governed by EU, EEA, or UK law, Cloudflare relies on the EU-U.S. Data Privacy Framework where applicable and provides Standard Contractual Clauses and supplementary safeguards in its data-processing terms. OpenAI's and Anthropic's data-processing terms incorporate applicable contractual transfer safeguards. For other restricted transfers, we use an applicable adequacy decision or approved contractual safeguards. Email hi@choreeo.com if you would like information about or a copy of the safeguards relevant to your data.
Automated processing
Choreeo uses AI to interpret a parent's requested chart update, but it does not make decisions that produce legal or similarly significant effects about you or your children.
Security
No internet service is perfectly secure, but we use reasonable administrative, technical, and organizational measures appropriate to the information Choreeo handles. Email lookup values are keyed and access secrets are stored only in hashed form; secure browser cookies are not available to page scripts. Our operational logs are kept free of names, email addresses, transcripts, and chart content.
Changes and contact
We may update this policy as the product evolves. If we make material changes, we will update the date at the top of this page and may provide additional notice where appropriate.
Choreeo LLC is the controller responsible for this policy.
PO Box 91
Climax, MN 56523
United States
Privacy questions or requests: hi@choreeo.com