Mom Alarm Clock — Privacy Policy
Last updated: April 14, 2026
Mom Alarm Clock (“the App”) is a family alarm and morning routine app designed to help guardians and children (ages 5–18) build healthy wake-up habits. This policy explains what data we collect, why, and how we protect it.
Who We Are
Mom Alarm Clock is developed and operated by Ross Mathews. For questions about this policy, contact us at momalarmclock@gmail.com.
Data We Collect
Guardian Account Data
- Email address — Used for sign-in and account recovery. Stored in Firebase Authentication.
- Display name — Shown in the app to identify the guardian. Stored in Firestore.
Child Profile Data
- Child's name — Display name set by the guardian. Stored in Firestore.
- Child's age — Used to tailor verification difficulty and wording to the child's age group (5–7, 8–10, 11–13, 14+). We store the numeric age, not date of birth. Stored in Firestore.
Alarm and Session Data
- Alarm schedules — Wake-up times, active days, verification settings. Stored in Firestore and locally on-device.
- Morning sessions — Records of each alarm event: when it fired, verification method used, whether it was approved, points earned. Stored in Firestore.
- Verification results — Method used (math quiz), completion timestamp, and proof metadata (quiz score, answers given). v1.0 supports only the math-quiz verification path; no photos, location, or step-count data are collected.
Audio Data
- Voice alarm recordings — Guardians may optionally record a personal wake-up message attached to an alarm. Stored in Firebase Storage, scoped to the family, accessible only by family members.
- Voice messages — Guardians and children may optionally send each other short voice messages (up to 30 seconds, ~120 KB). They are stored in Firebase Storage scoped to the family, encrypted in transit (TLS) and at rest, accessible only by family members, and deleted when the recipient dismisses them.
Location Data
- None. v1.0 does not request or collect any location data. The geofence verification method is scoped out of this release.
Photo Data
- None. v1.0 does not request camera or photo-library access. The photo verification method is scoped out of this release.
Device and Diagnostic Data
- Crash reports — Collected by Firebase Crashlytics to identify and fix bugs. Contains no personally identifiable information.
- Device identifiers — Firebase anonymous authentication generates a device-scoped identifier for child devices. This is used only for authentication, not for tracking or advertising.
- Push notification tokens — Used to deliver alarm notifications and guardian alerts. Tokens are stored in Firestore and rotated by the operating system.
- Usage analytics — We use Firebase Analytics to collect non-identifying, aggregated product-interaction data (e.g. alarm fired counts, which verification was used, pairing success). It is not linked to your identity and is not used to track you across other apps or websites. The app does not show ads and does not use an advertising identifier.
- Optional feedback diagnostics — When you submit in-app feedback, you may choose to include your device model and iOS version to help us reproduce issues. This is only sent if you leave the “include device info” option checked; it is never collected otherwise.
Data We Do NOT Collect
- Date of birth (we use age only, grouped into age bands)
- Any location data — coarse, precise, or distance-only (geofence verification scoped out of v1.0)
- Any photo or camera data (photo verification scoped out of v1.0)
- Step counts or motion data (motion verification scoped out of v1.0)
- Browsing history
- Contacts or call logs
- Financial information
- Advertising identifiers
- Data from other apps on the device
Children's Privacy (COPPA Compliance)
Mom Alarm Clock is designed for use by families where a guardian manages the experience for children ages 5–18.
- Parental consent: A guardian must create an account and explicitly add each child. Children cannot create accounts independently.
- Child pairing: Children join the family using a time-limited code generated by the guardian. By entering this code, the guardian consents to the collection of the child's data as described in this policy.
- Minimal collection: We collect only the child's name and age from the guardian. The child's device collects verification data (math-quiz answers and score) only during active alarm verification.
- No advertising: We do not serve ads to children or use children's data for advertising.
- No social features: Children cannot communicate with anyone other than their guardian through the app.
- Guardian control: Guardians can view, modify, and delete all child data. Deleting the guardian account deletes all family data including all child profiles.
How We Use Data
All data is used exclusively for app functionality:
- Delivering alarms and verification challenges
- Calculating streaks, points, and rewards
- Sending push notifications to guardians about verification status
- Tailoring quiz difficulty and wording based on the child's age group
- Detecting and reporting tampering (e.g., device volume changes, permission revocation)
- Providing diagnostic information for support
We do not use any collected data for advertising, marketing, profiling, or sale to third parties.
Data Storage and Security
- Firebase: Account data, family data, and session data are stored in Google Firebase (Firestore, Authentication, Storage) with encryption in transit (TLS) and at rest.
- On-device: Local data is stored in the app's sandboxed Documents directory with iOS File Protection (encrypted at rest, inaccessible when device is locked).
- App Check: Firebase App Check with App Attest verifies that requests come from legitimate app installations.
- Access control: Firestore security rules enforce family isolation — users can only access data within their own family. Children can only update their own session data. Server-managed fields (rewards, review windows) cannot be modified by any client.
Data Retention
- Active accounts: Data is retained while the account is active.
- Session history: Limited to the most recent 500 sessions per child (older sessions are automatically deleted by a Cloud Function).
- Tamper events: Limited to the most recent 2,000 events per child.
- Account deletion: Deleting the guardian account permanently deletes all family data: child profiles, sessions, tamper events, voice recordings, push logs, and join codes. This action is irreversible.
Data Sharing
We do not sell, rent, or share personal data with third parties. Data is processed by:
- Google Firebase — Cloud infrastructure provider (data processing agreement in place)
- Apple Push Notification service (APNs) — For delivering push notifications
Your Rights
- Access: View all your data within the app (Settings, History, Diagnostics).
- Correction: Edit child profiles and alarm settings at any time.
- Deletion: Delete your account and all associated data from Settings > Delete Account.
- Data portability: Contact us to request an export of your data.
Changes to This Policy
We may update this policy as the app evolves. Material changes will be communicated through the app or via email. Continued use of the app after changes constitutes acceptance.
Contact
For privacy questions, data requests, or concerns: