MAPLE ROOST COPPA PARENTAL CONSENT NOTICE
Last Updated: August 4, 2026
Version: 1.10.1
This notice explains our practices regarding children's privacy under the Children's Online Privacy Protection Act (COPPA). Maple Roost LLC, a Florida limited liability company ("Maple Roost," "we," "us," or "our"), operates the Maple Roost baby tracking app. You — the parent or guardian — are the user of this app. The app collects information about your child only because you enter it. Please read this notice carefully before allowing your child's information to be collected through the Maple Roost app.
1. WHAT IS COPPA?
The Children's Online Privacy Protection Act (COPPA) is a federal law that protects the privacy of children under 13 years of age. COPPA requires that we obtain verifiable parental consent before collecting, using, or disclosing personal information about children under 13. You have the right to review, correct, and delete your child's information and to revoke your consent at any time.
2. INFORMATION WE COLLECT ABOUT CHILDREN UNDER 13
With your consent, you may enter the following information about your child through the app:
2.1 Information You Provide:
- Child's first name and last name
- Date of birth
- Gender (optional)
- Photos (optional — only if you choose to upload them)
- Physical measurements (height, weight, head circumference)
- Activity data (feeding times and amounts, sleep patterns, diaper changes)
- Developmental milestones and notes
- Health-related information you choose to track, including vaccinations, medications, symptoms, doctor appointments, and other health events, and optional feeding-safety details (for example, eczema severity or a doctor-diagnosed food allergy) used only to gently tailor First Foods guidance — never to diagnose or score your child
2.2 Information Automatically Collected:
- Technical information necessary for the app to function (device type, operating system, app version, server request logs). We do not use any third-party analytics or crash-reporting service.
- A small first-party sign-in-reliability diagnostic recorded when the app starts (a one-word storage status, app version/build/channel, and a random device identifier) — no child data, no content, no third parties, and never collected during guest (Sitter Pass) sessions.
- IP address — recorded server-side from your device's request to our own servers when you sign consents (no third-party service is involved), for fraud-prevention purposes; see the location note in Section 2.3 below
2.3 Information We Do NOT Collect:
- GPS or device-level precise location data. We do collect IP addresses (technical/security data), which can approximate a city or region.
- Social Security Number or other government identifiers
- Audio or video recordings (except photos you upload)
- Information from social media profiles
- Biometric data. The optional Face ID, Touch ID, or passcode app lock uses your device's built-in authentication; no biometric data is collected from you or your child. If you enable the optional Face Suggestions feature, face detection runs only on your device and no face data is ever sent to us (see Section 3.1)
- Any information not directly related to baby tracking
Account security features such as two-factor authentication and the optional app lock apply to the parent's account and device. They collect no information from your child, and any biometric authentication is performed entirely by your device.
3. HOW WE USE YOUR CHILD'S INFORMATION
We use information about your child ONLY for the following purposes:
3.1 Core App Functions:
- Storing and organizing your child's activity data
- Generating feeding, sleep, and growth reports for you
- Tracking developmental milestones
- Sleep prediction: Your child's sleep data is processed by Maple Roost's own predictive model, which runs on your device, to estimate the next nap window. This data is NOT sent to OpenAI or any external AI provider for this feature. The resulting estimate (the predicted time, the actual time, and the difference between them) is saved to your account so that both parents' devices show the same prediction; that derived estimate is not client-side encrypted (see Section 6.1).
- On-device summaries and recaps (Private AI): The app can generate short recaps and summaries about your child from the information you have entered (for example, a weekly recap). This processing is performed on your device only — your child's information is not sent to OpenAI or to any other third-party AI provider to produce it. Any summary saved to your account is stored like the other information you enter. These summaries are produced automatically and may be incomplete or imperfect. If you turn on the optional Face Suggestions feature, the app also analyzes the photos you have added to detect faces and suggest name tags — this face detection runs on your device only; no face data (including face geometry or the numerical face representations used for matching) is collected by, transmitted to, or disclosed by Maple Roost, and it is deleted from the device when you turn the feature off. Only the name tags you explicitly confirm are stored, as parent-authored content protected like the rest of your child's information (including the client-side encryption described in Section 6.1). The feature is off unless you enable it.
- Daily motivational quotes: Maple Roost uses OpenAI to generate daily quotes shown in the app. No personal data about you or your child is included in these prompts.
- Enabling you to share information with authorized caregivers
3.2 App Improvement:
- Improving app features and functionality (using aggregated, de-identified data only)
- Ensuring app security and preventing fraud
3.3 Legal Compliance:
- Complying with applicable laws and regulations
- Protecting the safety and well-being of children
4. HOW WE SHARE YOUR CHILD'S INFORMATION
We do not sell or rent personal information about your child for third-party marketing purposes. In the event of a merger, acquisition, or sale of assets, any successor entity is bound by this same commitment. We may share your child's information only in these limited circumstances:
4.1 With Your Authorization:
- Caregivers you explicitly grant access to (grandparents, babysitters, etc.) — optional
- Healthcare providers — optional, only if you choose to share
- Caregiver Handoffs (guest passes) — a Handoff is a temporary, time-limited pass that lets a babysitter or other caregiver, using an anonymous guest session with no account of their own, view your child's profile and emergency information and — unless you choose a view-only pass — log activities such as feedings, sleep, and diaper changes during a window you set (up to seven days). You choose the scope and can revoke a Handoff at any time.
4.2 Service Providers:
We work with the following third-party services to operate the app. We use each of them under their own published terms of service and data-processing terms, for the purpose described:
- Supabase: Provides hosting, database, and file storage for the app. Encryption in transit and at rest is provided at the infrastructure level by Supabase.
- OpenAI: used to generate the daily motivational quotes shown in the app; no personal data about you or your child is included in those prompts. The app's on-device summaries and recaps (Section 3.1) do not use OpenAI or any third-party AI service.
- Expo (exp.host push service and EAS Update): Delivers push notifications to your device, with Apple (APNs) and Google (FCM) as downstream push transports, and delivers over-the-air updates to the app. For notifications, only the notification payload and your device push token are transmitted; these notification payloads may include your child's first name and the activity being reported (for example, that a sleep session started) so co-caregivers receive a meaningful alert. Live lock-screen timers (Live Activities) are delivered directly to your device via Apple's push service (APNs) from our servers and carry the same limited content — your child's first name, the activity, and its timing. For over-the-air updates, your device asks Expo whether a newer version of the app is available. That check sends only the technical details needed to serve the right version — the device platform, the app's version and release channel, an identifier for the update currently installed, and a random installation identifier — together with the ordinary request information (such as an IP address) that any web request carries. No information about you or your child is included in an update check.
- Resend: delivers our transactional emails (for example, sign-in and verification codes) to the parent's email address. Only the parent's email address and the message being sent are shared, for delivery only — never your child's information.
- Cloudflare: routes email sent to our @mapleroost.app addresses (including coppa@mapleroost.app) to our mailbox. If you write to us about your child, what you write passes through Cloudflare in transit.
- Apple App Store: Processes in-app purchases and subscription billing. Apple handles that purchase as its own business, under its own terms and privacy policy — not on our behalf. Apple does not access your child's profile data.
- RevenueCat: manages subscription entitlements, so the app knows what the parent's account is entitled to. We send RevenueCat the parent's Maple Roost account identifier and the purchase information Apple provides. No information about your child is sent to RevenueCat.
- Netlify: hosts our public website at mapleroost.app, including this notice, the Handoff (guest pass) claim page, and the public Emergency Card page. If you create an Emergency Card for your child (Section 4.3), the sanitized medical subset you choose to publish is served to whoever opens that link through Netlify, which processes the request — including the link's token and ordinary request information such as an IP address — in order to serve the page.
4.3 Emergency Sharing You Initiate:
If you create an Emergency Card for your child, a sanitized subset of that child's medical information (for example, allergies, medications, conditions, and emergency contacts) is made available at a public web link encoded in a QR code, so first responders can access it without an account. You may optionally protect this link with a PIN. The link, the printed card, the Apple Wallet pass, and any NFC tag you write all carry this access and are shareable by you; anyone who has them can view the sanitized record until you regenerate the QR code. Insurance ID numbers, the PIN, and the underlying access token are never shown on the public page.
4.4 Legal Requirements:
- When required by law or court order
- To protect the safety of your child or others
- To investigate potential violations of our terms
- Child safety: we have zero tolerance for any content that exploits or endangers a child. If we become aware of apparent child sexual abuse material, we report it — including related account information — to the National Center for Missing & Exploited Children (NCMEC) as required under applicable law, including 18 U.S.C. § 2258A; the account is permanently terminated and the material and related records are preserved as required by law. We do not scan or review your content — entries and photos protected by your Memory Key are encrypted on your device (Section 6.1) — so we act on what is reported to us
4.5 Your Separate Authorization for Optional Sharing:
The consent you give when you add your child's profile authorizes us to collect and use your child's information to provide the app's core features. The optional sharing features above are off by default — each one requires a separate, deliberate action by you, and taking that action is your specific authorization for that disclosure:
- Creating a Handoff (a temporary guest pass for a sitter or helper, including the view-only variant) is your separate authorization to disclose the selected child information to that guest, for the time window you choose.
- Creating or enabling an Emergency Card public link is your separate authorization to make the selected emergency information available to anyone who has the link, QR code, Apple Wallet pass, NFC tag, and any required PIN.
- Inviting a caregiver, generating and sharing a file such as a keepsake or emergency PDF, or saving or sharing one of your child's photos from the app, is likewise your separate authorization for that specific disclosure.
You can revoke a Handoff at any time, and regenerate an Emergency Card link to invalidate links you shared before.
5. YOUR PARENTAL RIGHTS
As a parent or guardian, you have the following rights regarding your child's information:
5.1 Review and Access:
- View all personal information we have collected about your child
- Export your child's data: the in-app "Export everything" option bundles account data, activity records, and uploaded photos into a single file assembled on your device; a data-only export is also available.
- Access this information through the app or by contacting us at coppa@mapleroost.app
5.2 Modify and Correct:
- Update or correct any inaccurate information about your child
- Add or remove information as needed
- Choose which optional data categories to include or exclude
5.3 Delete Information:
- Request deletion of your child's personal information through the app or by emailing coppa@mapleroost.app
- When you delete your account, your personal data is removed promptly from our active production systems; if your child has a designated co-parent on Maple Roost, your child's records pass to that parent rather than being deleted. Residual copies in our hosting provider's encrypted backups are overwritten on the standard backup-retention cycle, within 90 days.
- Some information (such as consent/acceptance records and limited transaction records) may be retained longer where law requires
5.4 Control Future Collection:
- Refuse to allow further collection of your child's information
- Revoke your consent at any time (see Section 8)
- Modify privacy settings to limit data collection
- Choose which optional features and data sharing to enable
5.5 Communication:
- Choose how and when we communicate with you about your child's account
- Opt out of non-essential communications
6. DATA SECURITY FOR CHILDREN
We implement security measures for children's information:
6.1 Technical Safeguards:
- Encryption in transit and at rest is provided at the infrastructure level by our hosting providers (Supabase).
- Maple Roost uses client-side (on-device) encryption for sensitive family data: when a Memory Key (recovery key) is created, entries, notes, and photos are encrypted on the device with keys held by the parent (the Memory Key, and on Apple devices the device keychain), which we never receive. Because the keys stay with the parent, Maple Roost does not hold the keys to that content — so we cannot read those encrypted entries and photos, and they are stored on our servers only in encrypted form. That statement is about who holds the keys to that specific content; it is not a broader guarantee about the security of our systems, and it does not extend to the data listed next. This also means Maple Roost cannot recover that content if the Memory Key is lost and the device's keychain copy is not available — not even at the parent's request. If you have not created a Memory Key, this on-device encryption is not in effect for your account, and what you record is stored in readable form on our servers. Creating a Memory Key protects what you record from that point forward; it does not reach back and re-protect content that was already stored in readable form, and earlier readable copies — including photos — can remain on our servers. Some data is intentionally not client-side encrypted so the app can function (the child's name and basic profile details, emergency-profile information shown to responders, notification content, the nap-time estimates described in Section 3.1, exported data and PDFs, and basic scheduling metadata). A readable server-side copy briefly kept during an earlier rollout period as a safety net has since been removed.
- Secure authentication and access controls
- Periodic security reviews, automated checks that run on every change to our code, dependency updates, and remediation of the issues we find
- Access to production systems limited to the small number of people who operate the service
6.2 Operational Safeguards:
- The people who operate Maple Roost follow the children's-privacy practices described in this notice
- A written record of the claims we make and the practices behind them, which we re-check before each App Store submission and before each update to these documents
- A written incident-response plan for security issues
7. DATA RETENTION
7.1 How Long We Keep Information:
- Your child's information is retained while your account is active.
- When you delete your account, your personal data is removed promptly from our active production systems; if your child has a designated co-parent on Maple Roost, your child's records pass to that parent rather than being deleted. Residual copies in our hosting provider's encrypted backups are overwritten on the standard backup-retention cycle, within 90 days.
- Consent and acceptance records, and limited transaction records, are retained longer only where law requires.
7.2 No Separate Account For Your Child:
- Maple Roost is used by parents and caregivers to keep a family record. There is no separate account, sign-in, or experience for a child at any age, and nothing about the app changes automatically when your child reaches a particular age.
- You can review, correct, export, or delete your child's information at any time, and withdraw your consent at any time (see Sections 5 and 8).
8. GIVING AND WITHDRAWING CONSENT
8.1 How to Give Consent:
- When you create your account, you verify your email address — a one-time code is sent to your registered email address via our authentication system (Supabase Auth), which you must enter to confirm you control that address — and accept the Terms of Use and Privacy Policy with a single checkbox that is never pre-checked
- When you add your child's profile — before any information about your child is collected — you give explicit parental consent to the collection, use, and sharing described in this notice by checking an acknowledgment checkbox confirming you are the child's parent or legal guardian. The checkbox is never pre-checked, and the app will not add the child until you check it
- Your consent then remains in effect until you withdraw it; we will ask you to re-consent only if we make a material change to these practices (see Section 9)
- A copy of this notice is always available in the App (More → Legal) and at mapleroost.app/coppa, and you can read it in full before giving consent
8.2 How to Withdraw Consent:
- Email us at coppa@mapleroost.app to request withdrawal
- Use the account deletion feature in the app
8.3 Effect of Withdrawing Consent:
- If your child has no other parent on Maple Roost: we will stop collecting your child's information; existing information will be deleted on the schedule described in Section 7.1 (removed promptly from active production systems; encrypted backups overwritten within 90 days), except as required by law; and your child's profile will be closed.
- If your child has a designated co-parent on Maple Roost: your child's profile and records pass to that parent and remain available under that parent's own parental consent, given the same way described in Section 12; your own account, personal information, and consent records are still deleted.
- You can create a new account with fresh consent if desired
9. NOTIFICATION OF CHANGES
If we make material changes to how we collect, use, or share your child's information:
- We will post the updated notice with a new effective date, in the App (More → Legal) and at mapleroost.app/coppa
- The app will show you what changed, in plain language, and ask you to accept the updated notice before you continue using the app
- We will obtain new parental consent if required by COPPA
- If you do not accept the updated notice, you can withdraw your consent and delete your child's information at any time, as described in Sections 5.3 and 8
10. CONTACT INFORMATION
For questions about your child's privacy or to exercise your parental rights, contact our COPPA Compliance contact:
COPPA matters:
Email: coppa@mapleroost.app
General privacy questions:
Email: privacy@mapleroost.app
Postal address (required by COPPA):
Maple Roost LLC
7901 4th St N, STE 300
St. Petersburg, FL 33702, USA
We aim to respond to requests promptly and within the time required by applicable law. We do not accept requests by phone; please use email or the in-app tools.
11. ADDITIONAL RESOURCES
For more information about COPPA and children's online privacy:
- Federal Trade Commission: www.ftc.gov/coppa
- ConnectSafely: www.connectsafely.org
- Common Sense Media: www.commonsensemedia.org
12. HOW WE ASK FOR AND RECORD PARENTAL CONSENT
We ask for and record parental consent through the following two steps, which are the only steps we use:
- Email verification: When you create your account, a one-time verification code is sent to your registered email address via Supabase Auth. You must enter this code in the app to confirm you control the email account.
- Checkbox acknowledgment when you add your child's profile: Before any child information is collected, you must check an explicit acknowledgment checkbox — presented when you add your child's profile, and never pre-checked — confirming that you are the child's parent or legal guardian and that you consent to the collection, use, and sharing described in this notice. The app will not add the child until you check it. This notice and the Privacy Policy are available to read at that point and at any time in the App (More → Legal).
We do not use credit-card verification, government ID verification, video calls, mailed or signed forms, a second confirming contact, or any other verification method at this time.
Maple Roost is designed for use only by adults, and children may not create accounts or use the App. Before a parent or guardian adds a child's information, we verify control of the adult's email address, present this notice, require an affirmative acknowledgment that is never pre-checked, and record the consent event. We may strengthen or change this process as legal requirements and available technologies evolve.
The email verification and checkbox acknowledgment above authorize the collection and use of your child's information to provide the app's core features. Any optional sharing of your child's information with a third party — for example, creating a Handoff (guest pass) or enabling an Emergency Card public link — is separately authorized by the deliberate action you take to enable it, as described in Section 4.5.
13. YOUR CONSENT
By completing email verification when you create your account and checking the acknowledgment checkbox when you add your child's profile, you acknowledge that:
- You are the parent or legal guardian of the child whose information will be tracked
- You have read and understand this COPPA notice and the Privacy Policy
- You consent to the collection, use, and sharing of your child's information as described above
- You understand your rights and how to exercise them
- You can withdraw this consent at any time by emailing coppa@mapleroost.app or using the in-app account deletion feature
- You understand which data collection is optional and can control these choices
- A copy of this notice is always available in the App (More → Legal) and at mapleroost.app/coppa