🕰️

Tocket

Privacy Policy

Last updated: July 30, 2026

Tocket is developed by an individual developer, Petru Codarcea. This policy explains what the Tocket iOS app (“the App”) collects and why. We built the App to be usable by kids ages 5–9, and we’ve tried to collect as little as possible.

What we collect

When you sign in with Sign in with Apple, we receive the identity token Apple provides and exchange it with our backend (Supabase) to create an account. We store your family ID and a true/false entitlement flag (whether your family has an active subscription) — nothing more is sent to our servers today.

If you use the contact form, we receive the name, email, and message you submit, solely to reply to you. We don’t add you to any mailing list.

What stays on your device

Lesson progress, streaks, hearts, stars, story progress, badges, child profiles, and app settings are all stored locally on your device (using Apple’s SwiftData framework, UserDefaults, and the Keychain for the parental Settings PIN). None of this is uploaded to our servers. The App works fully offline for gameplay.

What we don’t do

Children’s privacy

Tocket is directed at children, but account creation requires Sign in with Apple. Apple itself requires the device’s passcode or biometric authentication (Face ID/Touch ID) before it will complete a Sign in with Apple request — this is Apple’s own system-level check, not a screen built into the App. We rely on that existing check, rather than a separate in-app consent form, to help ensure a parent or guardian is present when an account is created. Only the first lesson of the App is playable without an account at all. (This is separate from the optional PIN that protects the App’s own Settings screen.)

Purchases

Subscription purchases, if offered, are handled entirely by Apple’s App Store. We never see or store your payment information.

Data retention and deletion

To delete your account data, contact us at the email below and we will remove your family ID and entitlement record from our backend. Data stored locally on your device can be removed by deleting the App.

Changes to this policy

We may update this policy as the App evolves. Material changes will be reflected here with an updated date.

Contact

Questions about this policy or your data: tocket@ermite.cloud or use the contact form.