A family app with no account and no server
Reward Study has no account to create, no sign-in screen, and no server the developer runs: a family's data lives only in that family's own iCloud, and the App Store's own privacy label reads 'Data Not Collected.' The reward.study website you are reading this on is a separate, smaller case, covered on its own page rather than folded into that promise.
The App Store's own privacy label for the app
The concern
Where does a family's information actually go?
Installing an app for a child raises a question most apps never really answer: once the onboarding questions are answered and the tasks are set up, where does any of that live, and who else can see it. It is not one of the eight problems on Reward Study's own onboarding screen, but it sits underneath most of them: a parent picking "Bedtime and mornings are a battle" or "Pocket money causes arguments" is trusting the app with a fairly detailed picture of one household's daily life.
The honest answer for Reward Study is that almost none of it goes anywhere at all. There is no account system to store it in, and no server owned by the developer for it to sit on in the first place.
That trust is easy to break quietly, in ways a parent would never see: an SDK that reports crashes back to a third party, an analytics library that logs which screens a child opens and for how long, an ad network that profiles a household without anyone agreeing to it first. None of those things are unusual in apps built for children. Reward Study's answer is not a policy promising restraint around them, it is not including any of them in the first place.
What the app does
No accounts, no server, and iCloud that belongs to the family
There is no sign-in of any kind: no email, no password, no account created anywhere. The household's data, its kids, tasks, rewards and ledger, is stored in the family's own iCloud, through Apple's NSPersistentCloudKitContainer, the same private space a family's photos or notes already sync through. Reward Study ships with zero third-party SDKs, and zero analytics, crash reporting, advertising or tracking code running inside the app itself. The onboarding answers to "What's hard right now?" never leave the device they were answered on. None of this is a promise layered on top of a system that could still collect data elsewhere: there is no elsewhere in the app's own design.
The App Store's own privacy label reflects that directly: it reads 'Data Not Collected,' Apple's own words, not a claim the developer wrote about the developer's own app. That label is generated from the answers a developer submits about what the app actually does, and for Reward Study the honest answer to nearly every question on it is nothing.
None of this required a compromise on convenience elsewhere. Family Sharing still covers every product, subscription or one-time, so one purchase reaches the whole Apple family group automatically, without anyone handing over an email address or creating a login to make that sharing work.
The PIN
How the parent PIN itself is protected
The parent PIN that gates approvals, the ledger and exiting Kid Mode is not stored as typed. It is salted and stretched into a hash kept only in the device's own Keychain, the same secure storage Apple gives every app for credentials, and there is no fallback to the device's own passcode. A child who happens to know the phone's unlock code still cannot use it to get past the parent PIN, because the two are checked against completely different things.
The PIN protects the same actions everywhere it appears: approving a task, exporting a CSV, exiting Kid Mode, spending from the ledger by hand. Face ID or Touch ID sits in front of the PIN as the everyday gate, with the PIN itself as the fallback when biometrics are not available or not set up.
The one honest exception
The website is not the app, and says so
The app's no-collection promise and the reward.study website you are reading this on are not the same claim, and this page will not pretend they are. The website itself runs Google Analytics, for a plain visit counter, and only after a visitor agrees to it: the consent banner asks first, and declining is respected. That is covered on its own website privacy page, separate from the app's own privacy page, because a marketing site counting its own visits and an app that stores a child's chores are two different questions with two different answers, and folding one into the other would make both claims less true.
A visit counter is a small thing next to a child's chore history, and this page is not arguing otherwise. It is stating the two facts side by side on purpose, because a marketing site that quietly ran analytics while its own blog post claimed no tracking anywhere would be the kind of small inconsistency that undermines a much larger and much truer claim about the app itself.
Where this shows up elsewhere
The same posture runs through specific features
This is not a separate policy bolted onto the app, it shows up in how individual features are built: the on-device word problem generator described in story word problems never sends a prompt, an answer or a child's name anywhere, for exactly the same reason the household ledger never leaves iCloud. A feature that needed a server to work would be a feature this app could not honestly ship under its own privacy label.
None of this changes what a subscription pays for. Pro is still about what a household can do inside the app, not about data, and the plans themselves are laid out the same way regardless of how the data question gets answered.