Skip to content
Rpenny
Open menu

Legal

Privacy Policy

Effective date 25 July 2026. This is the published Rpenny Privacy Policy.

Operator: Rpenny is currently operated on a pre-incorporation basis by its founding team. A registered legal entity name, incorporation jurisdiction, and registered address will be added here before public launch. Until then, “Rpenny,” “we,” “our,” or “us” refers to the individual(s) currently responsible for operating the Service, who can be reached via the contact details in Section 15.

Rpenny is a gamified financial literacy platform designed to help children develop healthy money habits through educational activities under parental guidance.

This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Rpenny platform, which consists of two Android applications — the Rpenny Parent app and the Rpenny Child app (a Child profile can only be created and used under a parent’s account) — and any associated website (collectively, the “Services”). Both apps are covered by this single Privacy Policy. If we release iOS versions in the future, they will be covered by this same policy.

By using Rpenny, you agree to the practices described in this Privacy Policy.

Sections

1. Who This Policy Covers

Rpenny serves users in different age bands. Depending on where a user is located, different legal protections apply:

  • India (DPDP Act, 2023): anyone under 18 years of age is a “child,” and verifiable consent from a parent or lawful guardian is required before we process their personal data.
  • United States (COPPA): children under 13 years of age are subject to additional protections described below.

Rpenny requires every child profile to be created and supervised by a parent or legal guardian, regardless of the child’s age or location. A child cannot register or use the Rpenny Child app independently — a parent must create the profile from the Rpenny Parent app first.

2. Information We Collect

Information Parents Provide

  • Parent/guardian full name
  • Email address (including the email address of a co-parent invited to a shared family)
  • Username
  • When creating a child profile: the child’s first name, date of birth, and a username for the child

Information Generated Through Use

  • Tasks created and completed
  • Virtual Rpenny balances
  • Savings goals
  • Achievement badges and learning progress
  • Streaks
  • Parent approvals
  • Family group information

This information is used solely to provide the educational experience within Rpenny. It is not used to build behavioral profiles (see Section 4).

We do not collect or store photographs of children. Each child’s in-app avatar is an automatically generated icon (a color and initial), not an uploaded image. There is no photo, camera, or file-upload feature anywhere in Rpenny.

Child Sign-In Credential

Each child signs in using their username and a 6-digit PIN chosen when the profile is created. The PIN is stored as an authentication credential (not a plain data field) and is never visible to us in readable form. A system-generated, non-public placeholder email address is used internally to create the child’s login and is not a real, reachable email address.

Device and Technical Information

  • Device type, operating system, browser type, app version
  • IP address
  • Language preferences
  • Diagnostic and crash information
  • A push notification token, used only to deliver in-app alerts (such as a task approval or reward) to the correct device — see Section 4 and Section 9

We use this technical information only for security, troubleshooting, and aggregate product improvement — never to track an individual child’s behavior across sessions for advertising purposes.

3. How We Use Your Information

We use collected information to:

  • Create and manage user accounts
  • Deliver the Rpenny educational experience
  • Track progress and achievements within the app
  • Enable family management features (tasks, approvals, analytics for parents)
  • Deliver push notifications about task and reward activity
  • Respond to support requests
  • Detect fraud, abuse, or unauthorized activity
  • Maintain platform security and reliability
  • Comply with legal obligations

We do not use children’s information to make decisions about them outside the app, and we do not use automated profiling to target content or offers at individual children.

4. No Tracking, Profiling, or Targeted Advertising Directed at Children

Rpenny does not:

  • Track or behaviorally monitor children across the app or across other sites/apps
  • Build advertising profiles based on a child’s activity
  • Serve targeted or personalized advertising to children
  • Sell or rent children’s personal information

Rpenny does not currently integrate any third-party analytics, advertising, or crash-reporting SDKs. The only third-party service integrated into the Apps is Firebase Cloud Messaging (a Google service), used solely to deliver push notifications to the correct device. Firebase Cloud Messaging receives only a device token for this purpose — it does not receive names, balances, activity history, or any data used for advertising, and no advertising identifiers are collected.

5. Verifiable Parental Consent

Before any child profile is created, the parent or guardian confirms their identity via email confirmation.

Email confirmation alone is a lower-assurance verification method. Both India’s DPDP Rule 10 and the updated COPPA Rule expect a method that provides a reasonable basis for concluding the person is actually an adult — e.g. an ID check, a small payment-card verification, or a signed consent form. This is reasonable for an early testing phase and is being tracked as a product gap to close before scaling.

We do not process a child’s personal data until this verification is complete. If verification fails or is incomplete, the child’s profile is not activated and any data collected in the interim is deleted.

Parents may withdraw consent at any time by contacting us (see Section 15). Withdrawing consent will pause further collection of the child’s data and trigger deletion as described in Section 11.

6. No Real Money

Rpenny does not store, transfer, or manage real money. All balances, rewards, savings, and achievements within the platform are virtual, educational features intended solely for learning purposes.

7. Parental Controls

Parents are responsible for and able to:

  • Create and manage child profiles
  • Review their child’s activity and data through the Family Hub
  • Manage permissions for each child profile
  • Request access to, correction of, or deletion of their child’s information
  • Withdraw consent for further data collection at any time

We do not knowingly allow children to create independent accounts without parental involvement — a child profile can only be created from an authenticated parent account. If we learn that a child’s profile was created without verifiable parental consent, we will suspend the profile and delete the associated data within 30 days.

8. Data Storage & Security

Rpenny uses Supabase as its backend infrastructure for authentication, database, and server-side functions, provisioned in the Mumbai (ap-south-1) region, India, for production. Personal data — including children’s data — is stored within India as a result.

We implement administrative, technical, and organizational safeguards appropriate to the sensitivity of children’s data, including encryption in transit, access controls limiting who can view user data, and routine review of our security practices. Authorized Rpenny staff may access family data through an internal admin tool for the limited purposes of customer support, safety moderation, and sending platform-wide notifications; this access is subject to the same access controls described above.

No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

9. Sharing of Information

We do not sell personal information.

We may share information only:

  • With the service providers who help operate Rpenny — currently Supabase (cloud hosting, authentication, and database infrastructure) and Google Firebase Cloud Messaging (push notification delivery only, limited to a device token) — and only after taking reasonable steps to confirm they maintain adequate security measures and will not use children’s data for their own purposes
  • When required by applicable law or legal process
  • To protect the safety, rights, or security of users or the platform
  • During a merger, acquisition, or asset transfer, subject to the receiving party honoring this Privacy Policy for previously collected data

10. International & Cross-Border Data Transfer

Rpenny’s backend infrastructure (Supabase) is hosted in the Mumbai (ap-south-1) region, India. As a result, personal information — including children’s data — is not routinely transferred outside India by our core hosting provider.

A limited exception applies to push notification delivery: device tokens (see Section 2) are shared with Google’s Firebase Cloud Messaging service (see Section 9), which operates its own global infrastructure and may process that narrow data point — a device token only, never names, balances, or activity data — outside India.

11. Data Retention

We retain children’s personal information only as long as necessary for the purpose it was collected, and no longer than:

  • Active accounts: for as long as the account remains active and in use
  • Inactive accounts: data is deleted or anonymized after 12 months of inactivity
  • Upon parental deletion request: data is deleted within 30 days, except where retention is required by law

12. Data Breach Notification

If a data breach affecting personal information occurs, we will notify affected parents and, where required, the applicable regulator (e.g., India’s Data Protection Board) within the timeframe required by law (currently 72 hours under the DPDP Rules, 2025), including a description of the breach, the data affected, and steps parents can take.

13. Your Rights

Depending on your location, you (or, for a child, their parent/guardian) may have the right to:

  • Access the personal information we hold
  • Correct inaccurate information
  • Request deletion of information
  • Withdraw consent at any time
  • Request a copy of the information
  • Lodge a complaint with the relevant regulator

India-specific: You may also raise concerns with our Grievance Officer (see Section 15) or, if unresolved, with the Data Protection Board of India.

US-specific (COPPA): Parents of children under 13 have the right to review the specific data collected about their child, refuse further collection or use, and direct us to delete it — without terminating the child’s overall participation in an activity where that data was not required.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will update the “Effective Date” above and, where required by law, notify parents directly (e.g., by email) rather than relying solely on posting the updated policy.

15. Contact Us

General/Support: rpenny.support@gmail.com

Delete your account or data: see our Account & Data Deletion page.

Grievance Officer (India, DPDP Act): Interim contact: rpenny.support@gmail.com

Until a legal entity and dedicated Grievance Officer are designated, the support email above is being used as the interim contact point. This will be replaced with a named individual before public launch.

By using Rpenny, you acknowledge that you have read and understood this Privacy Policy.