This policy covers Plum (listed in the stores as Plum for Kids; the “app”) on Android and iOS. It is separate from the privacy policy for this website, which describes what abd3lraouf.dev collects when you read it. Using the app is also governed by Plum’s terms of service.
1. Who is responsible
The controller of the personal data described here is abd3lraouf, LLC, a Wyoming limited liability company at 30 N Gould St, Ste R, Sheridan, WY 82801, United States.
Email support@abd3lraouf.dev or call +1 (917) 920-5169 with any privacy question, any request described in this policy, or any request a parent makes about a child’s data (section 8). Post to the address above works too, but email is fastest. No data protection officer has been appointed.
2. Parents, children and accounts
Plum is meant to be set up by a parent or guardian. Children do not create accounts, and the app never asks a child for an email address, a password or any way to contact them.
A guest account is created automatically. The first time the app opens, it signs in anonymously with Firebase Authentication. That gives the account a random identifier, tied to no name, email address or password, so that progress and purchases have somewhere to live.
Signing in is optional. A parent can sign in with Google, Apple or GitHub to keep the same account across devices. Plum then receives what the provider shares: your name, your email address (with Apple, a private relay address if you choose one), the address of your profile photo, and the provider’s account identifier. Plum never receives your password.
3. What Plum keeps
These records are stored in Google Cloud Firestore under the parent’s account, and the database’s access rules let only that account read or change them:
- Child profiles — for each child a parent adds: the name or nickname the parent types (up to 24 characters), an avatar chosen from Plum’s own set of pictures (never a photo), an age band, and whether the child is a boy or a girl, which the games use to suit themselves to the child.
- Game progress — for each game pack a child plays: the stars earned, the best score, how many times it was played, which levels are complete, and when it was last played.
- Parental settings — the daily play-time limit you set.
- App settings and privacy choices — the preferences chosen in the app, and a record of the choices made with the privacy switches in section 4 and when they were made.
- Subscription status — whether the account has an active subscription, copied from the subscription service in section 5.
Plum collects no photos, audio, video, location or contacts, and it asks for no access to the camera, the microphone, your location or your photo library. Beyond the name a parent types for a child, it holds nothing a child writes.
On the device itself, the app keeps its data in an encrypted database, with the key held in the device’s secure storage. Game packs are downloaded over a link that the app’s server issues only to a signed-in copy of the app, and only for packs the account is entitled to; each link expires after 15 minutes.
4. Crash reports, performance and usage analytics
Three kinds of technical data are collected through Google’s Firebase tools. None of them carries a child’s name, a game’s contents or anything typed into the app.
- Crash reports (Firebase Crashlytics) — when the app crashes: what went wrong in the code, the device model, the operating-system and app versions, an identifier for the installation, and the account identifier (for guest accounts too), so a crash can be traced to the account it happened on. On by default; the Crash Reports switch under Settings, Privacy turns it off.
- Performance (Firebase Performance Monitoring) — timings such as how long the app takes to start, with the device model, the operating-system and app versions and the installation identifier. On by default.
- Usage analytics (Google Analytics for Firebase) — a fixed set of events about which screens and features are used, with the app version, device and operating-system details and an identifier Firebase assigns to the installation. Governed by the Usage Analytics switch under Settings, Privacy. In the European Economic Area, the United Kingdom and Switzerland, and wherever the app cannot tell which region it is in, it stays off until you turn it on; elsewhere it is on until you turn it off. The app does not report screens automatically: only the events it is written to send.
Plum shows no advertising and contains no advertising network. On Android it removes the permission to read the advertising identifier, and on iOS it never asks to track you. No data from the app is used for advertising, by the studio or by anyone else.
5. Who else handles it
Personal data from Plum is not sold, and it is not shared for advertising. It is handled by these service providers, each only to provide its own service:
- Google (Firebase) — sign-in, the database in section 3, the server functions that issue game-pack links and handle exports and deletion, storage of the game packs, remote configuration of the app, and the crash, performance and analytics tools in section 4.
- Google Play Integrity, and Apple App Attest and DeviceCheck — before the server answers, the app asks Google (on Android) or Apple (on iOS) to confirm that the request comes from a genuine copy of Plum on a real device.
- Google Play services (Android) — in-app updates, the in-app review prompt, delivery of downloadable content, and the install referrer, which the app reads once on first launch only to open the page a link pointed to before the app was installed.
- Apple, Google and GitHub as sign-in providers — only if you choose to sign in with one of them (section 2).
- Apple App Store and Google Play — take the payment for a subscription. Plum never sees your card or billing details.
- RevenueCat — keeps track of subscriptions for the app: the account identifier, the store receipt, the product, the price, currency and country of a purchase, its transaction identifier, and the platform.
- Resend — sends the email telling you a data export is ready (section 7), to the address on your account.
- Cloudflare — routes email sent to support@abd3lraouf.dev, and hosts the web version of this policy.
Personal data may also be disclosed where the law requires it, to protect the safety of a child or anyone else, or to establish or defend a legal claim, and it may pass to a successor if the app or the company is sold or reorganised, under protections at least equal to these.
6. How long it is kept
- Child profiles, progress and settings — until you delete them or the account (section 7).
- Guest accounts — an account that never signs in is removed by a scheduled clean-up once it has been inactive for 90 days.
- Crash reports, performance data and analytics — for the retention periods set in Firebase for the app, then deleted by Google.
- Subscription and transaction records — for as long as tax and accounting law requires.
- Email and phone correspondence — for as long as it takes to answer, and no more than 24 months after that.
7. Exporting and deleting your data
Export. Under Settings, Privacy, Export My Data asks for a copy of what the server holds for the account: the account and subscription records, the app settings, the child profiles and the parental settings. A request is approved within 7 days at most, and the download link it produces works for a limited time.
Deletion. Under Settings, Account, Delete Account Forever removes the account after you confirm it. The sign-in record is deleted; the server deletes the account’s records, including every child profile, its progress and the parental settings; the app’s data on the device is erased and its encryption key destroyed; and the app starts again with a new, empty guest account. A Sign in with Apple connection is revoked as part of it.
Deleting the account does not cancel a subscription: cancel it in the App Store or Google Play, or it will keep renewing. Transaction records the law requires to be kept are retained for that period. Uninstalling the app erases its data from the device but does not delete the account or the server records.
You can also ask for the account, or one child’s profile and progress, to be deleted by emailing support@abd3lraouf.dev or calling +1 (917) 920-5169, including if the app is no longer installed.
8. Children’s privacy
Plum is made for children, so the personal information it holds about a child is kept to what is listed in section 3, entered by a parent, plus the technical identifiers in section 4, which are used only to keep the app working and to improve it. Plum has no chat, no messaging and no way for a child to post or share anything with other people, and it does not show advertising of any kind.
A parent or guardian can at any time review what Plum holds about their child (the export in section 7), have it corrected or deleted, and stop any further collection by deleting the child’s profile or the account and turning off the switches in section 4. Under the United States Children’s Online Privacy Protection Act, the GDPR and similar laws, a parent can make any of these requests by emailing support@abd3lraouf.dev or calling +1 (917) 920-5169. You may be asked for enough information to be sure you are the parent on the account.
9. Your rights
Depending on where you live — under the GDPR in the European Economic Area, its UK equivalent, and United States state laws such as California’s — you may have the right to access the personal data held about you, to correct it, to have it deleted, to restrict or object to its use, to receive it in a portable form, and to withdraw consent at any time without affecting what happened before. You will not be treated differently for using any of them.
Plum does not sell or share personal information as California law defines those terms, and does not use it for targeted advertising.
Use the controls in the app, email support@abd3lraouf.dev, or call +1 (917) 920-5169. Requests are answered within one month. You also have the right to complain to a data protection authority, normally the one where you live or work.
Legal basis. Under the GDPR, providing the app and its subscription rests on contract (Article 6(1)(b)); usage analytics, where your region asks first, on consent (Article 6(1)(a)); crash reports, performance data, security and the prevention of abuse on legitimate interests (Article 6(1)(f)); and keeping transaction records on legal obligation (Article 6(1)(c)).
10. Where the data is
The app’s database and game files are hosted by Google in the European Union. Google, RevenueCat and the other providers above may process data in the United States and in other countries; where data leaves the European Economic Area, the United Kingdom or Switzerland, it is protected by the safeguards each provider offers, such as the European Commission’s Standard Contractual Clauses.
11. Security
Data travels over encrypted connections; the app’s own data is encrypted on the device; the database lets each account reach only its own records; and the server answers only requests that come from a genuine copy of the app. No system is perfectly secure, and if a breach ever affects data described here, it will be handled and reported as the law requires.
12. Changes to this policy
When this policy changes, the date at the top changes with it. A material change will be announced in the app before it takes effect.