Privacy Policy
Effective June 30, 2026
Pointsy (“Pointsy,” the “Service”) is operated by Highfivery LLC(“Highfivery,” “we,” “us”), a Texas, USA limited liability company. This policy explains what we collect, why, and the choices you have. It covers the hosted service at pointsy.kids.
Pointsy is built privacy-first, with special care for children. We collect the least data needed to run a family points app, we show no ads, we do no behavioral tracking, and we never sell your data.
Information we collect
- Parent account. Your name, email address, and a password (stored only as a secure hash). You may optionally set a PIN, also stored as a hash.
- Children’s profiles. A child profile is created and managed by a parent and contains only a display name, an avatar (a preset icon), a color, and a 4-digit PIN (stored as a hash). We do notcollect a child’s email, phone, photo, precise location, or any contact information, and we do no behavioral tracking or profiling of children.
- Family data.Your family’s name, a join code, your time zone (to schedule daily/weekly resets), and the activity ledger (points earned and redeemed for the chores and rewards you create).
- Technical data. Basic server and security logs (such as IP address and request metadata) needed to operate and protect the Service. We do not use third-party analytics or advertising trackers.
How we use information
We use this data only to provide the Service: to sign you in, keep your family’s data separate and secure, and run points, chores, and rewards. We do not use your data for advertising, profiling, or any purpose unrelated to operating Pointsy, and we do not sell or rent it. We do not send marketing email — in fact, Pointsy sends no email at all.
Children’s privacy (COPPA & GDPR-K)
Pointsy is designed for parents and guardians to manage their own family. Children do not have accounts of their own, do not provide any personal information directly to us, and cannot use Pointsy to contact anyone or be contacted.
- Only a parent or guardian creates and manages child profiles. By doing so, you provide consent — as required by the U.S. Children’s Online Privacy Protection Act (COPPA) and Article 8 of the EU/UK GDPR (“GDPR-K”) — for the limited information described above.
- We practice data minimization: a child is represented only by a display name, avatar, color, and PIN that you choose.
- You can review and edit any child profile in the app, permanently delete a child profile from Manage kids, and export your family or delete it entirely from your dashboard — all yourself, at any time. You can also email us and we’ll take care of it.
Legal bases (EU/UK)
Where the GDPR applies, we process data to perform our agreement with you (providing the Service), on the basis of your consent (including parental consent for children’s data), and for our legitimate interest in keeping the Service secure.
How we share data
We do not sell, rent, or trade personal data, and we do not share it for advertising. We rely on a small number of service providers to run Pointsy, who process data only on our instructions:
- Vercel — application hosting (United States).
- Neon — managed PostgreSQL database (United States).
We may also disclose information if required by law or to protect the rights, safety, or security of our users or the Service.
Data retention
We keep your family’s data for as long as your account exists. When you delete a child profile or your family — in the app or by request — the associated records are removed from our live systems, and any residual copies in routine backups are overwritten within 30 days.
Security
Passwords and PINs are stored only as strong one-way hashes (argon2), never in plain text. Data is encrypted in transit (HTTPS), sessions use signed tokens, and each family’s data is isolated from every other family. No online service can be guaranteed perfectly secure, but we take protecting your family’s data seriously.
Your rights
You can do most of this yourself, right in the app: export your whole family as a JSON file and permanently delete your family from your dashboard, and permanently delete a child’s profile from Manage kids. You can also email info@highfivery.comto access, export, correct, or delete your data and we’ll action it promptly. Depending on where you live, you may also have rights under the GDPR (EU/UK), the CCPA (California), or similar laws — including the rights to access, delete, and port your data. Because we don’t sell data or serve ads, there is nothing to opt out of on that front.
International users
Pointsy is operated from the United States, and our providers store data in the United States. If you use Pointsy from outside the U.S., you consent to your data being processed there.
Changes to this policy
If we make material changes, we’ll update the effective date above and, where appropriate, note the change in the app. Continued use of Pointsy after a change means you accept the updated policy.
Contact us
Highfivery LLC — Texas, USA.
Email: info@highfivery.com.