Progress Pass

Privacy at Progress Pass

Progress Pass helps families connect practice with parent-approved screen time. This policy describes the information used to provide that service. Operator: Worthy Software LLC. Effective date: September 30, 2026.

Information used by the app

Parents sign in with Apple. We store an account identifier and the display name provided during setup. Parents create family and child profiles. Children join through a parent-issued code; the child flow does not ask for an email address or password.

We store practice activities, goals, times, summaries, parent messages and decisions, earned balances, and redemption history. Optional practice photos and videos, including sound recorded in videos, are uploaded when added to a practice. Device enrollment identifiers, device names, app and OS versions, authorization state, and notification tokens support pairing, synchronization, restrictions and notifications.

Family access and service providers

Authorized parents can review their family's practice information and evidence. A child receives information scoped to that child's profile. Inviting another parent gives that parent access to family information; invite only people you trust. Practice content is not published to a public feed.

Cloudflare provides our API, database, private media storage, consent email delivery, and operational infrastructure. Apple provides sign-in, push delivery and on-device Screen Time controls. Information needed to deliver these services is processed by those providers. We use encrypted connections. Private storage does not mean end-to-end encryption.

Screen Time and permissions

Parents authorize Apple's Screen Time controls on the enrolled child device. App and website exception tokens are stored locally; the current app does not upload these selections or raw app-usage reports. Practice and redemption durations are part of the family record. Camera access is optional for practice evidence or scanning a pairing code. Microphone access is used for sound in an optional video. Photo selection uses Apple's system picker.

Advertising and tracking

The current app has no advertising or third-party analytics SDK and does not track you across other companies' apps or websites. We do not sell practice content. Operational request metadata, timing, response status and error events are processed to run and protect the service. Our API also uses hashed IP addresses for rate limiting. Cloudflare processes network information when delivering requests. We do not intentionally log practice text, media, passwords or raw purchase receipts. Email confirmation delivery does not log its confirmation link. Worker logs and traces are retained for up to seven days; request query strings are redacted.

Retention and deletion

Practice activities, goals, summaries, timing and parent messages/decisions are scheduled for deletion 90 days after the practice request. Attached photos and videos have the same maximum lifetime. Reviewed media defaults to removal 30 days after completion review; parents can choose 90 days, always limited by the practice request's 90-day deadline. There is no indefinite media-retention option. Available screen-time minutes do not expire with practice content. We retain the child profile, device pairing and minimum balance/redemption accounting while needed to provide the family's account; older balance entries have practice links, free-text reasons and actor references removed. Parents may delete a child's profile and records earlier.

Expired media becomes unavailable through the app; deletion of practice records and physical files runs asynchronously and may retry after a service interruption. Cached copies on devices can remain while offline; reconnect and open the app to synchronize. Photos/videos saved separately to a device's photo library are controlled by that device's owner.

Parents can start account deletion in Settings → Privacy → Delete account, including before creating a family. If the departing parent is the only parent, their family, child profiles and practice data are removed. If another parent remains, the family retains children's work, media and balances, while the departing parent's identity and messages are removed and prior decisions retain anonymous outcome and amount information. The confirmation explains the affected families.

Other devices must reconnect and open Progress Pass to clear cached information and, for a deleted family, local restrictions. The service retains hashed security cutoffs and device-release records to reject revoked credentials and let offline devices discover deletion. These records currently have no automatic expiry. Apple event receipt hashes expire after 30 days. Cloudflare database recovery history can retain prior database records for up to 30 days after removal from the live service. Recovery history is restricted to service recovery and is not available through the app. Before a restored database returns to service, deletions, revoked access and current consent choices must be reconciled against the pre-restoration state. Routine support correspondence is deleted within 90 days after the request is resolved, except where needed for an ongoing dispute or a legal obligation.

Children and parental choices

Families use Progress Pass with parental involvement. Parents set up child profiles and approve practice and awards. Evidence is optional; families should avoid including other people's personal information. Parents can remove evidence, stop collection and delete an individual child's data. Parent sign-in and Apple's Screen Time authorization are separate from privacy consent.

Parental consent

The purchasing parent reads the notice, chooses whether optional media is allowed, confirms they are the child’s parent or legal guardian and control the purchasing Apple Account, and explicitly approves permission in the app. We verify the Apple subscription transaction, including eligible free-trial transactions, and link it to that child’s permission. A purchase by itself does not give permission. Apple handles transaction notifications; we do not receive payment card details. Photos and videos are off by default. Parents may stop collection or delete a child’s data from Child permissions. Invited guardians have access to family records; removal of the consenting parent requires new consent. Canceling a subscription does not withdraw privacy permission.

Older email permission requests expire after seven days. Consent contact details are cleared when requests expire or are canceled, within 30 days after confirmation, or promptly on withdrawal. Temporary email records are deleted 30 days after link expiry. Consent receipts retain the notice version and hash, choices, confirming parent account, method, approval time and receipt hash, plus the Apple transaction identifiers, product, purchase/check times, offer type and environment while active; inactive receipts are removed one year after withdrawal, confirmation or expiry. Child deletion removes these records. Cleanup is asynchronous.

Existing private-test devices

Existing paired test devices can retain access while their parents complete the transaction-confirmation process. A temporary device-setup exception is restricted to the developer's account. This access is recorded separately from consent and does not establish transaction verification. Sandbox transaction confirmations are labeled as test records. Parents can stop collection or delete the child. Ordinary new families must complete confirmation.

Subscriptions

Apple processes family subscriptions. Progress Pass retains a purchase-to-family identifier, purchaser reference, original and latest transaction identifiers, purchase time, introductory-offer type, product, store environment, subscription status, expiration and renewal setting to determine family access. Raw signed receipts are verified but not retained, and payment card information does not pass through our service. Billing records are removed with family deletion; if another parent retains the family, the purchaser reference is cleared and the family entitlement is retained. Hashed notification receipts expire after 30 days. Deleting an app account does not cancel an Apple subscription; cancellation is managed through Apple.

Contact and requests

Contact support@progresspass.app about privacy, access, corrections, deletion or support. Include only the information needed for your request; do not email child media, passwords, pairing codes or payment details. We may need to verify that you are authorized to act for an account. Worthy Software LLC, 3819 N Whitman St, Tacoma, WA 98407, United States. Phone: +1 206-822-8050.