Mom Alarm Clock — Privacy Policy
Last updated: September 4, 2026
Mom Alarm Clock is a family alarm and morning routine app designed for guardians and children (ages 5–18). This policy covers the Mom Alarm Clock mobile app (“the App”), our website, and email update or waitlist forms that link to this policy. It explains what data we collect, why, and how we protect it.
Who We Are
Mom Alarm Clock is developed and operated by VARR Stack Technologies LLC. For questions about this policy, contact us at momalarmclock@gmail.com.
Data We Collect
Guardian Account Data
- Email address — On iPhone and iPad, a guardian may create an account with an email address and password, used for sign-in and account recovery, stored in Firebase Authentication. The Android app currently signs in anonymously and collects no email address.
- Display name — Shown in the app to identify the guardian. Stored in Firestore.
Child Profile Data
- Child's name — Display name set by the guardian. Stored in Firestore.
- Child's age — Used to tailor verification difficulty and wording to the child's age group (5–7, 8–10, 11–13, 14+). We store the numeric age, not date of birth. Stored in Firestore.
Alarm and Session Data
- Alarm schedules — Wake-up times, active days, verification settings. Stored in Firestore and locally on-device.
- Morning sessions — Records of each alarm event: when it fired, verification method used, whether it was approved, points earned. Stored in Firestore.
- Wake-up quiz results — Quiz style (math, picture identification, or pattern), difficulty, completion/pass status, timestamps, and responses needed to run and evaluate the check. No photos, location, step-count, or motion data are collected by the public V1 app.
Audio Data
- Voice alarm recordings — Guardians may optionally record a personal wake-up message attached to an alarm. The audio is stored in our Firestore database, scoped to the family, encrypted in transit (TLS) and at rest, and readable only by members of that family. We do not use Firebase Storage.
- Voice messages — Guardians and children may optionally send each other short voice messages (up to 30 seconds, ~120 KB). They are stored in our Firestore database, scoped to the family, encrypted in transit (TLS) and at rest, readable only by members of that family, and deleted when the recipient dismisses them. We do not use Firebase Storage.
Website, Waitlist, and Email Data
- Email address — If an adult chooses to join an Android waitlist or product-update list, we use the submitted email to send the requested updates. An app account is not automatically enrolled in marketing email.
- Signup and source data — Our email provider may process the form, confirmation status, signup time, referring page, and campaign parameters so we can honor the request and understand which signup source was used.
- Email engagement and preferences — Our email provider may record delivery, confirmation, unsubscribe, and message-engagement data needed to operate the list. Every marketing email will include an unsubscribe method.
The public landing page does not currently run Meta, TikTok, or Google advertising pixels. We will update this policy and provide any required choices before adding advertising tracking.
Location Data
- None. v1.0 does not request or collect any location data. The geofence verification method is scoped out of this release.
Photo Data
- Camera — Requested on the child’s device for two optional features: scanning a family QR code to join, and the QR or photograph wake checks. A photograph taken for a wake check is classified on the device by Apple’s Vision framework and then discarded — never uploaded, never saved, never shown to the guardian; only whether the requested object was recognised is recorded. The app does not request photo-library access.
Device and Diagnostic Data
- Crash reports — Collected by Firebase Crashlytics to identify and fix bugs. Reports may include technical device, app-version, performance, and crash-context data.
- Device and account identifiers — Firebase Authentication and other Firebase services generate identifiers used for authentication, app functionality, diagnostics, and analytics. They are not used for cross-app advertising.
- Push notification tokens — Used to deliver alarm notifications and guardian alerts. Tokens are stored in Firestore and rotated by the operating system.
- Usage analytics — We record product-interaction events such as pairing success, alarm firing, wake-check method and difficulty, and whether a wake check passed. These are written to our own database; we do not send them to an advertising network. Some are associated with your family identifier, so we can tell for example whether a family finished pairing — our App Store and Google Play privacy disclosures therefore treat product-interaction data as linked to you. Others are recorded with no family or account identifier at all. The iPhone and iPad app does not include the Firebase Analytics SDK. The Android app currently does, which means Google receives app and device identifiers from that version; we disclose that separately for that platform. The App does not show ads, does not use an advertising identifier, and does not use this data to track you across other companies’ apps or websites.
- Optional feedback diagnostics — When you submit in-app feedback, you may choose to include your device model and iOS version to help us reproduce issues. This is only sent if you leave the “include device info” option checked; it is never collected otherwise.
Data the App Does NOT Collect
- Date of birth (we use age only, grouped into age bands)
- Any location data — coarse, precise, or distance-only (geofence verification scoped out of v1.0)
- Photographs. A wake-check photo is classified on the device and discarded; no image is uploaded or stored
- Step counts or motion data (motion verification scoped out of v1.0)
- Browsing history
- Contacts or call logs
- Financial information
- Advertising identifiers
- Data from other apps on the device
Children's Privacy (COPPA Compliance)
Mom Alarm Clock is designed for use by families where a guardian manages the experience for children ages 5–18.
- Parental consent: A guardian must create an account and explicitly add each child. Children cannot create accounts independently.
- Child pairing: Children join the family using a time-limited code generated by the guardian. By entering this code, the guardian consents to the collection of the child's data as described in this policy.
- Minimal collection: We collect only the child's name and age from the guardian. During an active alarm check, the child's device collects the responses and result needed for the selected math, picture-identification, or pattern quiz.
- No advertising: We do not serve ads to children or use children's data for advertising.
- No social features: Children cannot communicate with anyone other than their guardian through the app.
- Guardian control: Guardians can view, modify, and delete all child data. Deleting the guardian account deletes all family data including all child profiles.
How We Use Data
App account, family, child, alarm, audio, and session data are used for app functionality, security, analytics, and support:
- Delivering alarms and verification challenges
- Calculating streaks, points, and rewards
- Sending push notifications to guardians about verification status
- Tailoring quiz difficulty and wording based on the child's age group
- Detecting and reporting tampering (e.g., device volume changes, permission revocation)
- Providing diagnostic information for support
We do not use child or family App data for advertising or email marketing, and we do not sell personal data. If an adult separately submits an email form, we use that email and related list data to send the requested waitlist or product communications, measure delivery and engagement, and honor subscription preferences.
Data Storage and Security
- Firebase: Account data, family data, session data and voice recordings are stored in Google Firebase (Firestore and Authentication) with encryption in transit (TLS) and at rest. We do not use Firebase Storage.
- On-device: Local data is stored in the app's sandboxed Documents directory with iOS File Protection (encrypted at rest, inaccessible when device is locked).
- App Check: Firebase App Check with App Attest verifies that requests come from legitimate app installations.
- Access control: Firestore security rules enforce family isolation — a person can only reach data inside their own family. A child’s device can update its own morning and its own reports, and nothing else: the fields that decide whether and when a guardian is alerted are writable only by our servers and by a guardian, so a child’s device cannot silence an alert about itself. Rules changes are checked against an automated test suite before they are deployed.
- Our practices: Access to production data is limited to the operator of the service and protected by two-factor authentication. Data is backed up daily with a seven-day retention window, and the database supports point-in-time recovery over the same window. We review the app’s data handling before each release. We do not sell data and we do not use it for advertising.
- Breach notification: If we become aware of a breach affecting personal data, we will notify affected guardians by email at the address on the account, and any regulator required by law, without undue delay.
Data Retention
- Active accounts: Data is retained while the account is active.
- Session history: Limited to the most recent 500 sessions per child (older sessions are automatically deleted by a Cloud Function).
- Tamper events: Limited to the most recent 2,000 events per child.
- Account deletion: Deleting the guardian account permanently deletes all family data: child profiles, sessions, tamper events, voice recordings, push logs, and join codes. This action is irreversible.
- Email lists: Waitlist and product-update data are retained until you unsubscribe, the list is retired, or you request deletion, subject to limited records needed to document consent, suppression, security, or legal obligations.
- Voice recordings: A wake-up message attached to an alarm is kept until the guardian replaces or removes it, or the alarm is deleted. A message recorded for one particular morning expires after that morning and is deleted automatically.
- Analytics events: Retained for no more than 24 months, and deleted with the family when an account is deleted.
- Diagnostics: Diagnostic reports you choose to send are retained for no more than 12 months.
- Backups: Retained for seven days. Data deleted from the live database is removed from backups as those backups age out, within that window.
- Children’s data: We keep a child’s data no longer than is reasonably necessary for the purpose it was collected for, and delete it when that purpose is fulfilled or the account is deleted.
Data Sharing
We do not sell, rent, or share personal data with third parties. Data is processed by:
- Google Firebase — Cloud infrastructure provider (data processing agreement in place)
- Apple Push Notification service (APNs) — For delivering push notifications
- Kit — Email form, confirmation, list-management, and product-update delivery provider for adults who choose to subscribe
Your Rights
- Access: View all your data within the app (Settings, History, Diagnostics).
- Correction: Edit child profiles and alarm settings at any time.
- Deletion: Delete your account and all associated data from Settings > Delete Account.
- Data portability: Contact us to request an export of your data.
- Email choices: Unsubscribe using the link in an email or contact us to request access, correction, or deletion of waitlist and product-update data.
Changes to This Policy
We may update this policy as the app evolves. Material changes will be communicated through the app or via email. Continued use of the app after changes constitutes acceptance.
Contact
For privacy questions, data requests, or concerns: