Sprout.
Terms
Version 3 · 24 September 2026. Plain words, on purpose. If anything here is unclear, write to us and we will explain it.
The short version. Sprout records the jobs, money and goals a family sets up together. About a child we keep a first name, an age band, an optional month and year of birth, an optional gender used only to pick a starting picture, and an avatar. Never a full date of birth, never contact details, never a photo, and a child never has an account. About you, the parent, we keep what we need to run your account. You can download all of it, or delete all of it, whenever you like.
Sprout is made by Vetri-Ed (Pty) Ltd, Gaborone, Botswana ("we", "us"). We are the data controller for the information described here. You can reach us at hello@sproutfamily.co.
Sprout is used by a parent or legal guardian, who sets up the family and adds the children. Children use the app only on a phone a grown-up has signed in or linked, behind a code the grown-up gives them. A child cannot register, cannot sign in with their own account, and cannot give us any information directly. When you add a child you are confirming that you have the authority to do so and that you agree to this policy on their behalf.
| What | Why | Kept until |
|---|---|---|
| First name | To show them their own jars and jobs | You delete the child or the family |
| Age band (5–8, 9–12, 13–17) | To show an age-appropriate screen | Same |
| Birth month and year (optional) | To keep the age band right as they grow. Never the day. | Same |
| Gender (optional) | Only to suggest a starting picture, which you can change. Never required, never inferred. | Same |
| Avatar | Their picture in the app | Same |
| Jobs, points, money movements, goals, allowance, streak days | This is the family record the app exists to keep | Same |
We do not store a child's surname, date of birth, address, phone, email, photo, location, or anything they type in free text.
| What | Why | Kept until |
|---|---|---|
| First and last name, and what the children call you | To address you in the app | You delete the family |
| Email address and password (stored only as a one-way hash) | To sign you in and send you codes to reset your password | Same |
| Mobile number | To identify your account if you lose access to your email | Same |
| Country | To show money in your currency and to know where Sprout is used | Same |
| Which app you signed up on (Android, iPhone or web) | To understand how families reach us | Same |
| The version of this policy you agreed to, and when | Our record that you agreed | Kept after deletion, as a record without your name |
| Messages you send us from Help, and any picture you attach | To answer you and to improve the app | You delete the family |
| Notices we showed you in the app, and whether you dismissed them | So we never show the same notice twice | You delete the family |
| A record of important actions on your account (exports, deletions, sign-in problems) | Security, and so you can see what happened | You delete the family |
When Sprout is opened we count the device: which platform (Android, iPhone, web), which version of the system and of Sprout, roughly what kind of screen, and which country. This is tied to a random number the app makes up and keeps on the device — not to you, your family, or your account. It has no name, no email, no address, no device identifier, no location. We use it to know which phones to test on. It is kept for 400 days and is not part of your family's data.
Your data is stored with Supabase in Frankfurt, Germany (EU), under the GDPR. Supabase does not offer hosting in Africa. The EU provides a level of protection that Botswana's data-protection law and South Africa's POPIA recognise for cross-border transfer, and this policy is our record of that transfer basis. A bank or organisation partnering with Sprout may require in-country hosting for its families; that would be a separate, isolated deployment and would be described to those families before they join.
| Who | What for | What they can see |
|---|---|---|
| Supabase | Database, sign-in, file storage | All app data, isolated per family |
| Cloudflare | Serves sproutfamily.co and the web app | Requests to our site; no family data at rest |
| Expo (EAS) | Builds the app and serves updates; also hosts the web app | Requests to the web app; no family data at rest |
| Resend | Sends our emails (sign-in codes, notices) | Your email address and the content of emails we send you |
| Google Fonts | Typefaces on the website | Requests from your browser for a font file |
Our own staff can look up a family only through a logged-in console that records every lookup. A second password guards it. Support staff cannot download lists of families.
Everything about a family is kept until the family deletes it. Two exceptions: device counts (section 3) are deleted after 400 days, and the console's record of staff lookups keeps only a scrambled form of any search term after 12 months. A family that stops using Sprout is not deleted automatically; we may write to ask whether you want it kept.
Every family's data is separated from every other family's by rules enforced inside the database itself, not only in the app. Money history cannot be edited, only corrected with a new entry, so the record you see is the record that exists. Passwords are hashed. Access on a shared phone is behind a per-person code. On the web version your session is kept in your browser; sign out on a shared computer.
When this policy changes in a way that matters, the app asks you to read and agree to the new version before you carry on, and the version number at the top goes up. Earlier versions are kept so you can see what you agreed to.