This policy explains what personal data Mission Monster (the “app”) processes, why, where it is stored and how you can control or delete it. The app is made for families: a parent creates the family, plans missions and approves them; a child uses a separate, simplified screen on their own device. We wrote this policy to be read by parents.
Who we are
The app is developed and operated by VRNS Studio, which is the data controller for the processing described here. You can reach us about anything in this policy at hello@vrnsstudio.com.
Our principles
- No advertising, and no third-party advertising or analytics SDKs in the app.
- Children do not create accounts and are never asked for an email address, phone number or other contact details.
- We collect only what a feature needs. Optional details (a child's age or photo) stay optional.
- Access is checked on our servers: a family's data is visible only to that family's parents and to the child's own paired device.
What we process
| Data | Whose | Why | Kept until |
|---|---|---|---|
| Email address and password (stored only as a secure hash) | Parent | Sign-in, email verification, password reset | Account deletion |
| Display name, avatar choice, app language | Parent | Showing the family to the co-parent; writing notifications in your language | Account deletion |
| Nickname and avatar choice | Child | Showing the child's profile | Deletion of the child profile or family |
| Birth date or approximate age (optional) | Child | Showing the child's age; you can remove it at any time | Removal or deletion |
| Profile photo (optional; resized to at most 512 px, location and other metadata removed) | Child | Optional avatar | Replacement, removal or deletion |
| Missions, completions, approvals, stars, badges, rewards and activity requests | Child, family | The core features of the app | Deletion of the child profile or family |
| A random, anonymous identifier for a paired child device | Child device | Letting the child's device see only that child's missions | Disconnection or deletion; unpaired identifiers after 30 days |
| Push notification token, platform, app version, language | Each device | Delivering notifications (only if you allow them) | Sign-out, invalid token or account deletion |
| Notification and delivery records | Parent, child device | Showing in-app notifications; avoiding duplicates | 30 days |
| Technical records (processed request IDs, change log for syncing) | Family | Reliable syncing between devices; preventing double actions | 30 to 90 days |
We do not collect phone numbers, addresses, school names, location, contacts, health data or advertising identifiers.
Data stored on your device
The app keeps a local copy of your family's data and any actions waiting to be sent, so it can work offline. This copy is deleted when you sign out or switch accounts, and it is excluded from Android cloud backups.
Notifications
Notifications are optional and controlled by your device settings. By default, lock-screen notifications use general wording (for example “Today's summary is ready”). Children's names and counts appear on the lock screen only if a parent turns on “show details on the lock screen”. Photos, birth dates and email addresses are never included in notifications.
Legal bases
- Providing the service you asked for (contract): your account, the family, missions, rewards and syncing.
- Consent: optional details such as a child's photo or age, and push notifications (given through your device's permission prompt). You can withdraw consent at any time.
- Legitimate interests: keeping the service secure and reliable, preventing abuse and fixing errors.
- Legal obligations, where they apply.
Service providers and where data is stored
We use a small number of providers who process data on our behalf, under agreements that require them to protect it:
- Supabase — database, sign-in and file storage. Data is hosted in the Tokyo, Japan region.
- Google Firebase Cloud Messaging (and Apple Push Notification service on iPhone) — delivering push notifications using your device token.
- Resend — sending verification and password-reset emails to parents.
- Cloudflare — hosting this website.
Because some providers store or process data outside your country, your data may be transferred internationally. We do this only in line with applicable data protection law, including the Turkish Personal Data Protection Law (KVKK) and, where it applies, the GDPR.
Children's privacy
Mission Monster is designed to be set up and managed by parents. A child's device is connected with a one-time code from a parent's phone; the child does not register, sign in with an email address or enter personal details. Parents decide which details to add about their child, can change or remove them at any time, and can delete the child's profile together with its history. We do not show ads to children, do not build profiles for marketing and do not sell personal data.
Security
- All connections are encrypted (TLS).
- Every change goes through server-side checks that confirm the person or device belongs to the family.
- Child photos are stored privately and shown only through short-lived links to the family's parents and the child's device.
- Secret keys never ship inside the app.
Your rights
Depending on where you live, you can ask to access, correct, delete or receive a copy of your data, to restrict or object to processing, and to withdraw consent. Under KVKK (Article 11) and the GDPR you can also complain to your data protection authority. Most things can be done directly in the app; for anything else, write to hello@vrnsstudio.com from the email address of your account. We reply within 30 days.
Deleting your data
You can delete your account in the app at any time. If another parent remains in the family, only your account is removed and the family continues with them. If you are the last parent, the whole family is deleted: children's profiles, history, stars, photos and paired devices. Step-by-step instructions, and how to ask for deletion without the app, are on ouraccount deletion page.
This website
vrnsstudio.com does not use cookies or advertising trackers. Our hosting provider may record basic technical data (such as IP address and browser type) to deliver and protect the site.
Changes to this policy
If we change how we process personal data, we will update this page and the date above, and let parents know separately when the change is significant.
Contact
VRNS Studio · hello@vrnsstudio.com