Privacy Policy — Bubbs
This policy covers the Bubbs mobile app on iOS and Android, and the Firebase backend services Bubbs uses to deliver messages between paired devices. It applies to you if you install Bubbs on an adult's phone ("caregiver mode") or on a child's device ("child mode"). Bubbs is operated by Abilene Website Design.
We've tried to write this in plain English. There's a one-page summary at the top. If anything is unclear, email us at bubbs@abilenewebsitedesign.com and we'll rewrite it.
At a glance
- We do not collect personal information from children. Bubbs is designed so the child's device never sends identifying data to our servers. Student names and photos on the child's device stay on the child's device.
- The caregiver is our customer. The adult who installs the caregiver side of the app is the person whose data we hold. That data is minimal: an anonymous ID, a device label you pick, your push token, and the messages your paired child sends you.
- No ads, ever. Bubbs has no advertising SDKs. Bubbs has no marketing partners. Bubbs does not sell, rent, or trade any data.
- The child's AAC board is always free. The subscription only turns on the parent-side message delivery. You never pay to let a child communicate.
- Crash reports and analytics are off by default. You can turn them on in Settings. They never run on the child's device.
- You can delete everything. Settings → Your data & privacy → "Delete everything" removes your account, paired devices, messages, and uploaded photos within 15 days.
1. Who we are
Bubbs is built and operated by:
Abilene Website Design
Email: bubbs@abilenewebsitedesign.com
Support: bubbs-app.com/support
If you are in the EEA or UK, we act as both data controller and data processor for the categories described below. If you are in California, we are a "business" under the CCPA and CPRA.
2. What we collect, and from whom
Bubbs has two distinct modes. What we collect depends on which mode the device is in.
2a. Child mode
We do not collect personal information from the child. The child mode is designed to work with zero account, zero sign-in, and no server calls unless a caregiver has been paired. Specifically, on the child's device:
- Student name and photo are stored locally on the device and never transmitted to us.
- The child's tile edits and custom tile photos are stored locally.
- When a caregiver is paired and the child taps tiles to send a message, the sentence (and optionally a tile photo) is sent to our servers solely for delivery to the caregiver's paired phone. It is not mined, profiled, aggregated, or shared with anyone else.
- No analytics SDK runs on the child device. No crash-reporting SDK runs on the child device.
- The child device has no Apple ID or Google account sign-in requirement.
2b. Caregiver mode
When an adult caregiver uses Bubbs on their own phone, we collect:
- An anonymous Firebase Auth UID. A random string that lets our backend recognize your device. It is not linked to your name or email.
- A display name you choose for the caregiver device (e.g. "Mom's phone"). This appears in the child's paired-devices list.
- Your push-notification token. We need this to deliver the child's messages to your phone.
- Messages sent by your paired child (the sentence plus an optional tile photo). These are delivered to your device and retained on our servers for 14 days.
- Your subscription status, managed by RevenueCat. We receive an anonymous record that you have (or do not have) an active entitlement. We never see your Apple ID, Google account, or credit card number.
- Pairing preferences (notification toggle, quiet-hours window per paired child). Stored so your phone remembers them.
2c. Opt-in only (default OFF)
In caregiver Settings you can enable:
- Crash reports (Sentry). Sends crash stack traces, app version, and OS version when the app crashes. Does not include messages, tile photos, push tokens, user IDs, or any field whose name ends in uid, token, phone, email, or similar.
- Usage analytics (PostHog). Sends a fixed list of 10 event types (app launched, role picked, pairing completed, message sent, photo added, photo bulk reset, paywall shown, paywall purchased, paywall restored, settings opened) with a fixed list of 12 dimensions (role, category, tile count, app version, OS, OS version, entitlement state, paywall reason, purchase outcome, pairing method, message token count, message length). No free text, no URLs, no names, no message content.
Both are off by default. You can turn them off any time.
3. What we do not collect
- We do not collect the child's name, age, birthday, or photo on our servers.
- We do not collect your email address unless you write to support.
- We do not collect your phone number (iOS and Android don't give apps your phone number without separate opt-in, and we don't ask).
- We do not collect location. Bubbs has no location permissions and does not read GPS, IP geolocation, Wi-Fi SSID, or Bluetooth beacons.
- We do not collect audio. Bubbs uses synthesized speech; it does not listen through the microphone.
- We do not use any advertising SDK. We do not track you across apps or websites.
- We do not use any attribution SDK (AppsFlyer, Adjust, Branch, Segment, etc.).
4. Why we collect what we do
| Category | Purpose | Legal basis (GDPR) |
|---|---|---|
| Anonymous UID + device label + push token | Deliver the child's messages to the right phone | Contract (Art. 6(1)(b)) |
| Message text + optional photo | Deliver the message | Contract |
| Subscription status (via RevenueCat) | Gate the caregiver bridge | Contract |
| Crash reports (opt-in) | Diagnose crashes to fix bugs | Consent (Art. 6(1)(a)) |
| Usage analytics (opt-in) | Understand which features help | Consent |
5. Who we share it with
We do not sell, rent, or trade any data about you or your child.
We use the following service providers. Each is contractually required to process data only for us:
- Google Firebase (Auth, Firestore, Storage, Cloud Functions, Cloud Messaging) — hosts our backend. Data centers in the US and EU. Google's terms: firebase.google.com/terms.
- RevenueCat — manages Apple/Play subscriptions. Receives an anonymous user ID and a purchase receipt from the store.
- Sentry (opt-in only) — crash reporting for caregiver devices.
- PostHog (opt-in only) — usage analytics for caregiver devices.
We may disclose information if required by a valid legal process (subpoena, court order, etc.), and we will notify you unless legally prohibited.
6. How long we keep it
- Messages. 14 days, then purged from our servers. Your phone may keep a local copy longer; you can clear it at any time.
- Tile photos uploaded for sync. 30 days, then deleted by a Firebase Storage lifecycle rule.
- Backups. 30 days of encrypted snapshots in Google Cloud Storage, for disaster recovery.
- Caregiver account. For as long as the app is installed. 30 days after uninstall or subscription cancellation, we purge.
- Sentry / PostHog (opt-in data). 90 days / 1 year respectively, per vendor defaults.
7. Your rights
- Review. Your caregiver device shows every message, paired child, and preference we hold. Settings → Your data & privacy is a read-only view of the server-side record.
- Export. Settings → Your data & privacy → "Download my data" writes a JSON bundle of your account, paired devices, and the last 14 days of messages, then hands it to the iOS/Android share sheet.
- Delete. Settings → Your data & privacy → "Delete everything" triggers a full delete across Firestore, Storage, Sentry, PostHog, and local storage. We complete this within 15 days and notify you when done. Subscriptions must be cancelled separately via Apple or Google.
- Correct. Most fields can be edited in-app. For the rest, email support.
- Complain. EU/UK residents can lodge a complaint with their data protection authority.
We honor these rights for the caregiver (as the account holder) and, on the caregiver's request, for data they consider their child's.
8. Children's privacy (COPPA)
Bubbs is usable by children and is in a category that the FTC would call "directed to children" — it is AAC software for non-verbal kids, many of whom are under 13. Even so, COPPA's "verifiable parental consent" requirement does not bind us, because we do not collect personal information from the child. The child's name, photo, and tile edits stay on the child's device; only the caregiver's data and the messages the caregiver receives are sent to our servers.
We've published the full analysis at bubbs-app.com/docs/coppa.
If you are a parent who believes your child has somehow sent us personal information despite this architecture, email privacy@abilenewebsitedesign.com and we will delete it.
9. Security
- All traffic between devices and our servers uses HTTPS/TLS 1.2+.
- Firestore documents are readable only by the owner's anonymous UID (via hardened security rules).
- Pairing QR codes are HMAC-signed, have a 5-minute TTL, and use a fresh nonce to resist replay.
- Secrets (API keys, DSN, etc.) live in EAS secrets and Firebase config, never in git.
- We run a secrets audit and a QR-payload penetration review.
No system is perfectly secure. If you suspect a vulnerability, please email security@abilenewebsitedesign.com.
10. International transfers
Our backend runs on Google Cloud. Data may be processed in the US, EU, or other regions where Google operates. For transfers out of the EEA/UK, we rely on the EU Standard Contractual Clauses as incorporated into Google's data processing terms.
11. California privacy (CCPA/CPRA)
In the last 12 months we collected the categories described in Section 2: identifiers (anonymous UIDs, tokens), internet-or- other-network information (crash/usage analytics, opt-in only), and commercial information (subscription status). We did not sell or share personal information for cross-context behavioral advertising.
You have the right to know, delete, correct, and opt out. Use the
in-app controls in Section 7. We honor the Global Privacy Control
signal at the browser level for the bubbs-app.com
marketing site.
12. Changes
If we materially change how we collect or use data, we'll update this page, bump the version hash, and prompt caregivers to re- consent on next launch.
13. Contact
Abilene Website Design Email: bubbs@abilenewebsitedesign.com Privacy: privacy@abilenewebsitedesign.com Security: security@abilenewebsitedesign.com Mail: [mailing address — add before public launch]