Privacy Policy
Last updated: 2026-02-15
Friendrot ("we", "us", "our") is built for kids and operated through adult accounts held by parents, guardians, or teachers. We keep data collection minimal, use it to run and improve the product, and design the experience to be kid-safe — no ads, no third-party ad tracking.
Who this policy applies to
- Parents/Guardians: the account holder who signs in with Google and manages kid profiles for their household.
- Teachers: the account holder who signs in with Google and manages a classroom roster of students.
- Kids/Students: profiles created and managed by a parent/guardian or teacher. Kids do not create their own accounts.
What we collect
- Adult account information: when you sign in with Google, we receive your Google account ID, name, and email address for authentication.
- Kid/student profile information: a display name and optional username chosen by the child or assigned by a teacher. We do not collect email addresses, passwords, or birthdates from children.
- Gameplay and progress data: game results, progress, levels, rewards (GoldRot), and items collected in the shop.
- Social data: friend connections and, for parent-mode accounts only, text messages between approved friends (280 characters max, no links). Chat is completely disabled for classroom students.
- Device and usage data: information needed for reliability, security, and product analytics (for example: timestamps, error logs, page views, device and browser type, and general app usage events). Analytics are stored in our own database — we do not use third-party analytics services.
- Billing data (paid subscribers only): when you start a paid subscription, our payment processor (Stripe) collects your name, email, billing address, and payment method directly. Friendrot itself does not store your card number.
- Session and security data: cookies used to keep you signed in and protect the service from abuse.
What we do not do
- No third-party ad networks.
- No selling personal information.
- No building advertising profiles for kids.
- No targeted advertising.
How we use information
- To run the product: sign-in, kid profiles, saving progress, and providing rewards and collections.
- To improve Friendrot: diagnosing bugs, improving performance, and tuning gameplay balance.
- To keep it safe: detecting abuse, preventing fraud, and protecting accounts and kid profiles.
- To communicate with adults: service-related messages (like important updates or support replies) sent to the parent or teacher email on file.
Children’s privacy (COPPA)
Friendrot is designed to comply with the Children’s Online Privacy Protection Act (COPPA). We do not collect personal information directly from children. All kid profiles are created and controlled by a parent, guardian, or teacher acting with appropriate authority.
- Parents provide consent by creating and managing kid profiles through their own authenticated account.
- Teachers represent that they have obtained any required school or district consent before creating student profiles.
- We collect only the minimum information needed to operate the service (a display name and gameplay data).
- We do not condition a child’s participation on providing more information than is reasonably necessary.
- Parents and teachers can review, edit, or delete kid/student profiles and all associated data at any time from their dashboard.
- Parents may refuse further collection by deleting the kid profile.
Parent and teacher controls
- Parents manage kid profiles from the Parent Dashboard: create, edit, and delete profiles; control friend connections (parent PIN required on both sides for every request); enable an optional friend code for additional protection; and disable chat entirely. Friend requests are capped and auto-expire after 14 days.
- Teachers manage student rosters from the Teacher Dashboard: add, rename, remove students, regenerate credentials, and delete classrooms. Chat is disabled for all classroom students.
Data retention
We keep information only as long as needed to operate Friendrot, comply with legal obligations, and maintain security. When an account or profile is deleted, we remove or de-identify associated data within a reasonable period, except where we are required to retain certain records for security, fraud prevention, or legal compliance.
Sharing and service providers
We do not sell personal information. We share limited information only with service providers that help us operate Friendrot:
- Authentication: Google (OAuth sign-in).
- Hosting and database: MongoDB Atlas (cloud database) and standard cloud infrastructure.
- Image storage: Google Cloud Storage (avatar and game assets).
- Payment processing: Stripe handles subscription billing, including card details, billing address, and invoice history. See Stripe's privacy notice.
- Email delivery: Google Workspace (the mailbox behind hello@friendrot.com) is used to send transactional and support email.
These providers are required to protect information and use it only for providing services to Friendrot.
Cookies
Friendrot only uses essential cookies — the ones needed to keep you signed in and to protect the service from abuse (session ID and CSRF tokens). These are always active because the product cannot function without them. We do not use third-party analytics or advertising cookies, which is why you do not see a cookie banner.
Your rights
Parents, guardians, and teachers may at any time:
- Review the personal information associated with their account and kid/student profiles.
- Edit or correct profile information through their dashboard.
- Delete kid/student profiles and all associated data.
- Delete their entire account and all associated data through their dashboard.
Where we operate
Friendrot is operated from Ontario, Canada by Friendrot. We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Ontario law. If you are using Friendrot from outside Canada, your information will be transferred to and stored in Canada and other countries where our service providers operate.
Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice in the app. Continued use of Friendrot after an update means you accept the updated policy.
Contact
Questions or requests about your data: hello@friendrot.com