Privacy Policy
Last updated 30 July 2026
Paulo is a child-first, parent-assisted app that helps a family practice delayed gratification together: a child captures wishes as photo stickers, works toward them through a shared family “promise” ledger of stars, and makes a real choice between enjoying something now or saving toward a wish. Paulo is designed to run entirely on the family’s own device.
Data Paulo Stores
All of the following is stored locally, in the app’s own data store on the device it is installed on:
- Parent-entered profile information for each child: name, age, avatar, and an optional profile photo.
- Wishes: name, a photo sticker, target star count, and status (active, ready, fulfilled, archived).
- Photos selected or taken for wish stickers and profile pictures. Selected images are copied into Paulo’s local app data; nothing is uploaded.
- A per-child library of “temptations” (immediate alternatives) the family defines, each with a name, an optional sticker, and a star value.
- The child’s promise ledger: a running record of when stars were saved, spent, or corrected by a parent. This is an audit trail, not a score — every entry is kept, including parent corrections.
- Keepsake achievement cards created when a wish is fulfilled.
- My Trail entries: short voice notes and photos a parent adds to record a moment. Photos are re-processed on-device to strip location and other metadata before they are stored.
- An optional “My Plan” voice recording a child can make, describing their own process for a hot moment; only the most recent take is kept.
- Family rules and agreement settings a parent configures (what a star means, daily chance limits, and — if a parent turns it on — an optional real-money value per star).
- Sound, haptic, and other app preference settings.
Photos, Camera, and Microphone
Paulo asks for photo library, camera, and microphone access. These are used only so the family can choose or take a photo for a wish or profile sticker, and record short voice notes (My Trail, My Plan). Paulo only accesses these when a parent or child actively uses the relevant feature, and nothing captured this way leaves the device.
On-Device Only — No Network Calls
Paulo makes no network requests. There is no server, no account system, no analytics, no advertising, and no third-party tracking of any kind. When Paulo suggests a name for a wish from its photo, that suggestion is produced entirely on-device using Apple’s Vision and (where available) Foundation Models frameworks — no photo or description is ever sent anywhere to generate it.
iCloud / Family Sync
Paulo’s app configuration reserves an iCloud container for a future family-sync feature that would let a second caregiver see the same wishes and ledger. That feature is not active in the current build — Paulo’s data store is explicitly configured for on-device storage only, and no data syncs or leaves the device today. This section will be updated, and the App Store privacy disclosures revised, before that feature ships.
Data Sharing
Paulo does not share app data with any server, advertiser, analytics provider, or data broker, because none of those exist in the app.
Deleting Data
A parent can erase all local app data from Settings, which returns the app to first-run setup. Deleting the app from the device also removes all of Paulo’s local data. A more granular export/delete flow (for example, removing a single photo or voice note) is planned; see the app’s current settings for what’s available today.
Children
Paulo is built for children roughly ages 4–8 to use together with a parent or caregiver. A parent or caregiver sets up each child’s profile and chooses what photos, names, and recordings are added. Paulo does not knowingly collect personal information through any means other than what a parent or caregiver directly enters or captures within the app.
Future Changes
If Paulo adds cloud sync, accounts, analytics, or external sharing in a future version, this policy and the App Store privacy disclosures will be updated before that version ships.