Effective date: 17 July 2026

Privacy Policy

This Privacy Policy explains how Thrive Digital Wellbeing Pty Ltd ("Thrive", "we", "us", "our") collects, uses, discloses, and protects information when you use the Thrive - Smarter Screen Time app, the Thrive - Just a Phone app, our website, and related services (together, the "Service").

Thrive builds products for families. We minimise data collection, we do not sell personal information, and we never use a child's personal data for marketing or advertising. Where we analyse data to improve the Service, we use aggregated or de-identified data where possible; where that is not possible, we use pseudonymous data (data linked to an internal identifier, not to a name), collected under the guardrails described in this Policy.

The two apps do not operate in exactly the same way:

  • Thrive - Smarter Screen Time is more account- and activity-driven, and may process activity, reward, and approval data that parents choose to create.
  • Thrive - Just a Phone is more device-configuration-focused and, in many cases, stores and applies settings locally on-device using Apple platform controls.

1. WHO WE ARE (CONTROLLER)

Controller: Thrive Digital Wellbeing Pty Ltd

Address: 117/530 Little Collins Street Melbourne, VIC 3000 Australia

Support: support@thrive.kids Privacy: privacy@thrive.kids

EU/UK privacy contact (not an EU/EEA Article 27 representative): Matthew Wood (mat@thrive.kids), Victoria, Australia

If we are required to appoint an EU/EEA and/or UK representative under GDPR/UK GDPR, we will appoint one and update this Policy accordingly.

2. KEY PRINCIPLES

  • Data minimisation: we collect and store only what is necessary to provide, secure, support, and improve the Service.
  • No child data for marketing: we do not use child personal data for marketing, targeted advertising, or advertising measurement — ever.
  • Outcomes, not engagement: Thrive exists to help children spend less unproductive time on screens. We design and measure the Service for family outcomes; we do not design or test features to maximise a child's time in the app or on the device.
  • Screen Time data stays in its lane: data we receive through Apple's Screen Time and Family Controls frameworks is used only to provide our family-controls features. It is never used for advertising or advertising measurement and is never given to advertising partners or data brokers.
  • On-device first where possible: especially in Thrive - Just a Phone, we aim to keep configuration and enforcement data on-device unless remote processing is needed for support, diagnostics, purchases, syncing, or another feature you choose to use.
  • Honest analytics: we use aggregated or de-identified data where possible, and pseudonymous data where not. We do not call pseudonymous data "anonymous".
  • No sale of personal information: we do not sell personal information.

3. INFORMATION WE COLLECT

We collect information depending on which Thrive product you use and how you use it.

A) Parent or guardian account information

  • Email address and account identifiers, where account creation is required
  • Account settings and preferences
  • Subscription and purchase status, including confirmation from Apple (we do not receive full payment card details)

B) Child profile and device setup information

  • Child profile label or nickname, and an optional age number (not a birthdate), if you create one
  • Device linking, configuration, and eligibility data necessary to provide core features
  • For Thrive - Just a Phone, local device configuration such as allowed app selections, website restriction settings, parent PIN settings, and related enforcement preferences may be stored on-device and may only be transmitted to us if needed for support, diagnostics, syncing, or another feature you choose to use

C) Activity and reward information This category mainly applies to Thrive - Smarter Screen Time:

  • Activities you create (for example, homework, reading, chores, or other tasks)
  • Activity completions, approvals, rewards, and timestamps
  • Reward rules and parameters you set

Thrive - Just a Phone generally does not require activity or reward tracking for core functionality.

D) Information from a child's device Collection from a linked child device is deliberately narrow. It is limited to:

  • a pseudonymous internal identifier (a random account identifier we issue — not a name, email, phone number, or advertising identifier)
  • feature-usage signals from a fixed, reviewed list (for example: the app was opened, an activity was started or completed, minutes earned or spent, which built-in feature was used)

Child devices never send us: free-typed text, names, contacts, photos, browsing content, advertising identifiers, or precise location coordinates. Where a location feature (such as approved places) is enabled by a parent, location is evaluated on the child's device; the device reports the feature's status, not the child's coordinates. If the device offers Apple's privacy-preserving age-range declaration, the age bracket is processed on the child's device and is not transmitted to our servers.

E) Device and technical information

  • Device type, operating system version, app version, language, and related technical metadata
  • Diagnostics, crash reports, and performance data
  • Approximate region, derived from device settings or IP address for web access and parent devices. We disable IP-based location for data sent from child devices.

We do not intentionally collect precise location unless a feature clearly requires it and we tell you so.

F) Usability recordings (parent devices only) To find and fix confusing screens, we may capture how the app's own screens were used during a session on a PARENT device (taps and screen states within our app, with names and profile photos masked, and typed text always hidden). We never record child devices, and these recordings never include other apps or the device outside Thrive.

G) Customer support information

  • Information you provide when you contact us, including messages and any attachments you choose to send

H) Website data (if you use thrive.kids or related Thrive web properties)

  • Usage data such as pages viewed, clicks, referrers, and device/browser information
  • Cookies and similar technologies, as described in "Cookies and Website Analytics"

4. HOW WE USE INFORMATION

We use information to:

  • Provide the Service and its product-specific features
  • Connect devices, manage family settings, and apply restrictions or rewards
  • Maintain security, prevent fraud or abuse, and troubleshoot issues
  • Provide customer support
  • Improve the Service, including analysing which features families use and testing different versions of features to learn which works better (see Section 8)
  • Measure marketing effectiveness using data from parent devices and our website only, aggregated or de-identified where possible
  • Provide optional AI help or suggestions where enabled by the user, including sending permitted AI request data to OpenAI as described in Section 11

For example:

  • In Thrive - Smarter Screen Time, we may use activity, approval, and reward data to provide the product's core "earned screen time" functionality.
  • In Thrive - Just a Phone, we may use device configuration and enforcement data to help apply the simple-phone setup and related controls.

We do not use child personal data for marketing or targeted advertising.

5. LEGAL BASES (EEA/UK GDPR)

If you are in the EEA/UK, we process personal data under these legal bases:

  • Contract: to provide the Service you request
  • Legitimate interests: to secure, maintain, and improve the Service, including testing different versions of features, balanced against your rights — and, where the data relates to a child, weighted in favour of the child's best interests
  • Consent: where required, for example for non-essential cookies on our website or optional AI features
  • Legal obligation: to comply with law and lawful requests

6. SHARING AND DISCLOSURE

We share information only as needed to run, support, and protect the Service. The service providers (processors) that may receive personal data are:

  • Mixpanel (product analytics): receives pseudonymous product-usage events so we can understand and improve the Service. For data from child devices, this is limited to the narrow set described in Section 3(D). Mixpanel is contractually restricted to processing this data only to provide its service to us — never for its own marketing, advertising, profiling, or other purposes.
  • Sentry (crash and diagnostics reporting): receives technical crash and performance data so we can fix defects.
  • OpenAI (third-party AI processor): if you choose to use AI features and give explicit in-app permission by tapping "Accept & Continue" or similar language, we send information needed to generate AI answers. This may include your submitted prompts or questions, AI responses, and relevant support or diagnostic context needed to provide the feature. If you withdraw permission, no new AI requests are sent to OpenAI. AI features are not available on child devices' data: child devices never send free text to us or to OpenAI.
  • Advertising attribution partners (for example Branch and Meta): receive limited signals from PARENT devices and our website only — for example that an app install or subscription occurred — so we can measure whether our advertising works. Child devices never send data to these partners, and no Screen Time usage data (from any device) is ever shared with them.
  • Hosting, security, communications, and customer support providers: as needed to operate the Service, in de-identified or aggregated form where possible and otherwise only as needed to provide the Service.
  • Platform providers (for example Apple): purchases, subscription or entitlement status, device linking, Family Controls, and related platform functionality.
  • Legal and safety: if required by law, court order, or to protect users, rights, or safety.
  • Business transfers: if we are involved in a merger, acquisition, financing, or asset sale, subject to applicable notice requirements.

Some features in Thrive - Just a Phone are performed locally on-device and may therefore involve less server-side collection or sharing than features in Thrive - Smarter Screen Time.

We do not sell personal information. We require our processors to protect personal data to the same or equivalent standard described in this Policy and applicable law, and we prohibit them from using child personal data for their own purposes.

7. ANALYTICS AND MARKETING MEASUREMENT

We use analytics to understand how the Service is used and to measure marketing performance.

  • We use aggregated or de-identified data where possible, and pseudonymous data (keyed to an internal identifier) where not.
  • Analytics from child devices is limited to the narrow, reviewed set described in Section 3(D) and is used solely to operate and improve the Service (see Section 10 for the specific purposes).
  • We do not use child personal data for marketing or behavioural advertising.
  • We do not allow analytics providers to use child personal data for their own purposes, including their own marketing.
  • Marketing measurement uses parent-device and website data only.
  • Because Thrive - Just a Phone is more on-device in nature, some product data processing may be less extensive than in Thrive - Smarter Screen Time.

If we ever introduce practices that constitute "sale" or "sharing" under California law, including sharing for cross-context behavioural advertising, we will:

  • update this Policy; and
  • provide required opt-out controls, including recognising valid opt-out signals where applicable.

8. PRODUCT IMPROVEMENT AND FEATURE TESTING

We sometimes test different versions of app features to learn which works better for families (often called "A/B testing"). Because some features appear on a child's device, we hold these tests to specific commitments:

  • Test versions are chosen at the parent-account level. We never select a test version based on an individual child's behaviour, characteristics, or profile.
  • Measurement of tests that affect a child's screens uses only the narrow child-device data described in Section 3(D) — nothing extra is collected for a test.
  • We review every test that affects children's screens against the child's best interests before it launches, and we stop any test that appears to work against them.
  • We never design or test features to maximise a child's engagement, session length, or time on device. Thrive's goal is the opposite: tests are judged on family outcomes, such as whether activities get completed and screen-time agreements hold.
  • Session recordings and third-party experimentation software remain disabled on child devices.
  • We assess the privacy impact of new features and tests that affect children before we launch them.

9. SCREEN TIME AND FAMILY CONTROLS DATA

Thrive's enforcement is built on Apple's Screen Time and Family Controls frameworks. Device and usage data received through these frameworks:

  • is used only to provide the family-controls features you configure (blocking, limits, earned time, reporting to the parent);
  • is never used for advertising or advertising measurement;
  • is never shared with advertising partners, attribution partners, or data brokers; and
  • is shared with our processors only so they can help us provide those family-controls features, under the restrictions in Section 6.

Much of this data is processed on the family's own devices; the child's detailed device activity is reported to the parent, not to us.

10. CHILDREN'S PRIVACY

Thrive products are intended for use by parents and guardians. A child uses Thrive on their own device only after a parent or guardian sets it up, links it, and consents.

A) Parental consent During setup, the parent or guardian affirmatively confirms responsibility for the child, consents to the processing described in this Policy on the child's behalf, and authorises the device link (including through Apple's Screen Time authorisation). Parents can withdraw consent at any time by unlinking the device or deleting the family account.

B) What we collect from children and why We collect the minimum child-related data necessary to provide the relevant Thrive product: the pseudonymous identifier and feature-usage signals described in Section 3(D), plus the child profile details a parent chooses to create. We use a persistent pseudonymous identifier from the child's device solely to support the internal operations of the Service — specifically: providing and syncing the family's configured features, security and abuse prevention, debugging, and analysing and improving how features work (including the feature testing described in Section 8). We ensure this identifier is not used to contact the child, build an advertising or marketing profile of the child, serve behavioural advertising, or track the child across other companies' apps or websites — none of our systems use child data for those purposes, and our processors are contractually barred from doing so.

C) Parents' rights over child data Parents and guardians can request access to, correction of, or deletion of child-related data, and can withdraw consent to further collection, subject to verification and applicable law. Deleting the family account deletes the family's data as described in Section 14. Contact privacy@thrive.kids.

D) A note for kids If you are a kid using Thrive: your parent set this up, and the app shows them things like which activities you finished and how much screen time you earned. Thrive does not read your messages, does not see your photos, does not know where you are, and never shows you ads. What you type stays on your device.

If you believe we have collected a child's personal data inappropriately, contact privacy@thrive.kids.

11. AI FEATURES AND AUTOMATED DECISION-MAKING

Some parts of the Service may offer optional AI-powered help and suggestions.

  • Who receives data: OpenAI, acting as a third-party processor.
  • What may be sent: your submitted prompts or questions, AI responses, and relevant support or diagnostic context needed to provide the feature.
  • Permission first: we request explicit in-app permission before sending personal data to OpenAI for AI features.
  • Withdrawal control: you can withdraw permission at any time in the relevant app settings. After withdrawal, no new AI requests are sent to OpenAI.
  • Child devices: AI features run on parent devices; child devices never send free text to us or to OpenAI.
  • AI limitations: AI output may be inaccurate, incomplete, or inappropriate and is not professional advice.
  • No solely automated legal or similarly significant decisions: we do not use AI to make solely automated decisions that produce legal or similarly significant effects on users.

AI features are product- and feature-specific. Thrive - Just a Phone does not require AI for its core functionality and may involve fewer or no AI-enabled features compared with Thrive - Smarter Screen Time.

12. COOKIES AND WEBSITE ANALYTICS

If you use our website, we may use cookies or similar technologies for:

  • essential site functionality
  • security
  • analytics, aggregated or de-identified where possible

Where required by law, we request consent for non-essential cookies and provide controls.

13. INTERNATIONAL TRANSFERS

We are based in Australia and may store or process information in Australia and other countries where our service providers operate.

If you are in the EEA/UK and your personal data is transferred internationally, we use appropriate safeguards where required, such as Standard Contractual Clauses.

14. DATA RETENTION

We keep personal data only as long as necessary to:

  • provide and secure the Service
  • comply with legal obligations
  • resolve disputes and enforce agreements

When data is no longer needed, we delete it or de-identify it.

For children's data specifically:

  • Child profile, activity, and reward records are kept while the family account is active, because the Service needs them to work.
  • When a family account is deleted, or a parent asks us to delete a child's data, we delete or de-identify the child's personal data within 30 days, except where law requires us to keep specific records.
  • Pseudonymous product-usage events (including from child devices) are retained for no longer than 24 months, after which they are deleted or reduced to aggregate statistics.
  • We do not retain children's personal data indefinitely, and we review these retention periods at least annually.

Some data in Thrive - Just a Phone may remain only on your device unless you delete the app, reset the app, request support, or use a feature that requires transmission to us or our processors.

15. SECURITY

We use reasonable administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit and access controls where appropriate. We maintain a written information security program, with a designated coordinator, that we assess and test at least annually. No method is 100% secure, but we work to protect your information.

16. YOUR RIGHTS AND CHOICES

A) EEA/UK (GDPR/UK GDPR) RIGHTS Depending on your location and circumstances, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete data ("right to be forgotten")
  • Restrict or object to processing
  • Data portability
  • Withdraw consent where we rely on consent
  • Lodge a complaint with your local data protection authority

We respond without undue delay and, in most cases, within one month. In complex cases, we may extend by up to two additional months, with notice as required.

B) CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA) If you are a California resident, you may have the right to:

  • Know what personal information we collect, use, and disclose
  • Access a copy of your personal information
  • Delete personal information, subject to exceptions
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of personal information, if applicable
  • Limit the use or disclosure of sensitive personal information, if applicable
  • Not be discriminated against for exercising your rights

We do not sell personal information and we do not share it for cross-context behavioural advertising.

C) HOW TO EXERCISE YOUR RIGHTS Email: privacy@thrive.kids Suggested subject line: "Privacy Request"

To protect you, we may need to verify your identity before fulfilling certain requests. Parents and guardians may submit requests regarding their child's data. California authorised agents may submit requests on a consumer's behalf, subject to verification.

17. CALIFORNIA NOTICE AT COLLECTION (SUMMARY)

If you are a California resident, we collect the categories of personal information described in Section 3 above for the purposes described in Sections 4, 8, and 10.

We do not sell personal information and do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information beyond what is necessary to provide the Service, secure it, and comply with law.

18. CHANGES TO THIS POLICY

We may update this Policy from time to time. If changes are material, we will provide notice within the Service or by other reasonable means. The "Effective date" will be updated.

19. CONTACT

Privacy questions or requests: privacy@thrive.kids Support: support@thrive.kids

Mail: Thrive Digital Wellbeing Pty Ltd 117/530 Little Collins Street Melbourne, VIC 3000 Australia