Smiley Man Check-In

Privacy Policy

Last updated September 17, 2026.

Applies to version 2.1.

Smiley Man Check-In is a parent-guided emotion check-in app for children. The app helps kids name feelings, try small calming steps, save bright moments, and grow local Smiley Pets through check-ins.

Smiley Man Check-In is not a diagnosis, screening, treatment, therapy, medical, or crisis-service app.

Short Version For Kids

Smiley Man Check-In helps you tell how you feel.

We save your check-ins so your grown-up can help notice patterns and remember bright moments.

We do not show ads. We do not sell your information. We do not let other companies track what you do across apps or websites.

Some things only happen if your grown-up turns them on or leaves them on during family setup:

Your grown-up can export or delete local child data from parent settings.

Information Stored On The Device

Smiley Man Check-In stores the information needed to run the app experience:

Optional Voice Notes can store short child recordings locally in app storage.

Optional Drawings & Journals can store drawings, colors, story prompts, and journal text locally in app storage.

Parent Raw Content Review is off by default. When it is off, the parent dashboard can show metadata and pattern summaries, but it does not open saved journal text, drawing images, creative story text, or voice-note playback.

Information That Can Leave The Device

Private iCloud Backup appears as an enabled recommendation during parent-guided family setup. A parent can turn it off during setup or later in Privacy & Consent. When enabled, the app stores a recoverable copy in the private Apple iCloud/CloudKit database of the Apple Account signed in on the device. The backup includes profiles, structured check-ins, consent and privacy settings, saved memories, raw voice-note audio, raw drawings, journal text, creative story text, and Smiley Pet data such as eggs, growth, names, outfits, parks, Sparkles, and reward history.

Family Device Sync is separate from Private iCloud Backup and is off by default. If a parent turns it on and links another parent device, Smiley Man Check-In uses Apple iCloud and CloudKit to share selected household data. This can include child profile data, structured check-in data, sync metadata, and invite metadata.

Parent PIN material stays local to each device. Neither the raw parent PIN nor its reusable verifier is included in Private iCloud Backup or Family Device Sync. A replacement or linked device uses its own local parent PIN.

Raw voice-note audio, raw drawing files, journal text, and creative prompt text are included in Private iCloud Backup. They are not intentionally included in the Family Device Sync snapshot sent to a linked parent viewer.

Smiley Man Voice uses bundled approved audio included with the app during normal child use. The app does not send narration requests, child names, check-in notes, drawings, journals, child voice notes, parent dashboard details, or arbitrary child-entered content to Supabase, ElevenLabs, or another narration provider during normal app use.

Parent Voice Narration is not part of this launch app. The app does not include parent voice cloning, parent voice upload, parent voice deletion, or parent voice setup.

Optional Weekly Report Email

Weekly report email is a separate, optional paid Smiley Man Plus feature. It does not turn on automatically with an Apple Account, an app subscription, Private iCloud Backup or Family Device Sync. Choose an inbox controlled by a parent or guardian; it can be different from the Apple Account on the child's device.

When a parent chooses Send verification email, the app sends the chosen email address, the selected children's app-generated identifiers, the device's timezone and signed App Store subscription proof to our Cloudflare-hosted report service. This registration happens before the inbox is verified. The service checks Plus access, stores an enrollment record, subscription identifier and access-expiry information, and sends a verification email. The signed proof is processed to validate the purchase; the report database does not store the complete signed transaction. Apple handles payment information; we do not receive payment-card details.

Confirming the email verifies access to that inbox. It does not by itself enable report uploads or establish that the recipient is a parent. After verification, the parent must return to the app and separately choose Enable weekly reports and share summaries. The service records this permission's version and time, then waits at least 24 hours before sending a follow-up notice with controls to stop reports or remove the connection. No second reply or confirmation click is required. After that notice is sent and the connection becomes active, reopening the app can upload the first summary. Parent gates, inbox verification and a subscription are not presented as legal verification of parental identity.

Only after that enable step, waiting period and follow-up notice can the app upload the selected children's names or nicknames and structured report summaries. Summaries contain reporting dates, the latest check-in timestamp, counts of recorded feelings and days, context categories, chosen activities and follow-up outcomes, including skipped answers and changes of feeling or size. They are linked to the selected child's app identifier and the parent email registration. They do not contain a full database or individual journal entries. The summaries are used to make the report, select relevant observations and conversation suggestions, and deliver it to the parent. They are not used for advertising or to profile families for marketing.

Drawings, voice recordings, notes, journal text and creative story text are not uploaded to the report service or embedded in the report emails. Links to check-ins and shared creations open the app's parent area and respect the parent gate and the family's raw-content visibility setting. Email does not make media on a child's device available on another device by itself.

Reports use the latest summaries uploaded when the app runs. A report may not be sent if there is no fresh information or subscription access cannot be verified. Email already received can be read by anyone with access to that inbox, forwarded or copied. Its contents are not protected by the app's PIN after delivery.

Cloudflare processes registration, report storage and sending on our behalf. The recipient's email provider also receives the delivered message. Our service stores hashed access/verification links, enrollment status, permission records, delivery status and temporary request-limit records. Request limits use hashed network addresses and email addresses to reduce abuse; these are not advertising identifiers. Ordinary network requests also disclose connection information to the providers handling them. We do not add advertising trackers or email-open tracking pixels.

Widgets And Local Reminders

Widgets use a small, local shared container between the app and its widget extension. It contains child identifiers, names used in the widget's child-selection control, current pet/egg artwork and stage, growth progress, check-in days and streak information, timezone and update time. Names are not displayed on the widget face. It does not contain recorded emotions, journals, drawings, recordings or the full app database. Widgets display saved state and cannot award rewards or save check-ins.

Check-in reminders are scheduled locally through iOS after a parent turns them on and allows notifications. The app keeps the selected child, time and weekdays locally and suppresses that child's pending reminder after a successful check-in that day. Reminders use the app's standard prompt and current pet/egg artwork, not a child's private writing or recording. No remote push-notification registration or notification advertising is used for this feature. Lock-screen visibility is controlled by the device's notification settings.

What Smiley Man Check-In Does Not Do

Device-Linking Records

When a parent creates a Family Device Sync invitation, the app stores a household identifier, a hashed invitation code, a sealed share URL, timestamps, expiry, and invitation status in the app’s public CloudKit database to connect the two devices. These linking records can be accessible to the app developer and are used only for app functionality and security, not advertising or analytics. They contain no child check-in text, drawings, or voice recordings. Private backups and shared household content remain in user-owned private/shared CloudKit databases; they are not available to the developer through the CloudKit console.

Parent Choices

Parents can manage app privacy choices in parent settings:

Parents can also run a backup immediately, delete the private iCloud backup, create a local privacy export, or delete local child data from parent settings.

Export And Delete

The local privacy export is a structured JSON file containing local profiles, structured check-in records, parent permission records, and privacy settings. It intentionally excludes raw voice-note audio, raw drawing image files, journal text, and creative prompt text.

Parents can delete local child data from parent settings. This removes local child profiles, local check-ins, and local referenced media files on that device. Deleting local data does not silently delete the separate private iCloud backup. Parents can delete that backup with the dedicated Delete iCloud Backup control. If Family Device Sync has been enabled or another linked device has a copy, additional cloud or device-specific deletion steps may be needed.

Parents can delete the selected child’s Smiley Pet Park data separately in Settings > Privacy & Data. This removes that child’s local egg, pets, Sparkles, and shop items while keeping check-ins and drawings. The action requires confirmation. Private iCloud backup deletion remains a separate control.

For weekly email, Pause removes currently uploaded summaries from the report service and stops future reports. Remove connection deletes the registration and its associated summary, subscription-link and delivery records. The email's management link also provides pause and removal. These controls do not delete app or iCloud records, and cannot recall emails already delivered. If the device is offline, the app stops its own uploads and retries pending pause or removal when reopened online; server-side changes cannot finish until that request reaches the service.

For access, correction or an export of information held by the report service, contact smileymancheckin@gmail.com. We will need to verify control of the relevant connection before sharing personal information. The local JSON export is not a complete export of server records. To change the connected inbox or selected children, remove the existing connection and set it up again. Changing or deleting data on one device does not automatically recall reports already received.

Retention

Local data remains on the device until the parent deletes it or resets local child data. Storage Report counts saved items by age; it does not schedule or perform automatic deletion. The latest private iCloud backup remains in the signed-in Apple Account's iCloud storage until it is replaced by a newer complete backup or a parent deletes it in the app.

The report service keeps the latest uploaded summary set rather than a cumulative history of every upload. Scheduled cleanup removes summaries more than 30 days after upload and delivery records more than 90 days after creation. Unverified registrations expire after 24 hours. This is separate from the waiting period that begins when a verified parent chooses to enable reports. Registrations with no qualifying activity for 180 days are removed with their associated records. Temporary request-limit records normally expire after 24 hours. Cleanup runs on a schedule, so expiry is not an exact deletion timestamp. These are the report application's active-record rules; they are not a promise about immediate erasure from provider backups or the recipient's mailbox. Cloudflare D1 keeps recovery history for up to 30 additional days after a database record is changed or removed. Copies already delivered remain subject to the recipient's mailbox controls. Provider transport and operational logs have separate retention rules.

Providers

Apple provides the operating system, local notifications, iCloud/CloudKit features, App Store payments, subscription validation infrastructure and App Store services.

Cloudflare provides the optional weekly-report backend, database and email sending. Email providers handle delivery and storage in the recipient's mailbox. Cloudflare retains operational email records separately from the app database's cleanup schedule. Message-body previews are turned off for new messages. Previews created before that setting was turned off may remain for about seven days; turning it off does not delete those earlier copies. Their own service terms and retention practices apply to their systems. We do not sell this information or authorize advertising use of report data.

Smiley Man audio may be generated before release with internal production tools, then bundled into the app. The launch app should not be described as sending Smiley Man narration requests to a third-party narration provider during normal child use.

Contact

The operator of Smiley Man Check-In is Daniel Praid. For privacy or support questions, contact:

Daniel Praid
120 N. Pearl Street, Apt 407
Port Chester, NY 10573
United States

Telephone: +1 347-569-5334
Email: smileymancheckin@gmail.com