Privacy Policy - Jeebu ABA Buddy
Introduction
Welcome to Jeebu ABA Buddy ("Jeebu," "we," "our," or "us"). We are committed to protecting the privacy and security of children, families, and therapy professionals who use our mobile application. This Privacy Policy explains our practices regarding the collection, use, disclosure, and protection of information when you use the Jeebu ABA Buddy mobile application (the "App").
Our Core Privacy Commitment:
- ✅ Local-First: All therapy data stays on your device
- ✅ No Cloud Storage: We don't store your child's personal information on our servers
- ✅ HIPAA-Compliant: Healthcare-grade data protection practices
- ✅ COPPA-Compliant: Children's privacy is our top priority
- ✅ Transparent: Clear explanations of what data is used and how
By using Jeebu ABA Buddy, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the App.
1. Information We Collect
1.1 Personal Information You Provide
When you use the App, you may provide the following information directly:
Child Profile Information:
- Child's first name (stored locally only)
- Age in years
- Communication preferences
- Favorite activities and interests
- Avatar selection
Therapy-Related Information:
- Behavioral concerns and descriptions
- Therapy goals (short-term and long-term)
- Daily routines and preferences
- Helper information (caregivers, therapists)
- Reward preferences
Session Data:
- Trial logs (date, trial number, success/failure, behaviors observed)
- Session notes and observations
- Prompt levels used
- Reinforcers provided
- Progress tracking data
Generated Content:
- Lesson plans created by AI
- Task breakdowns
- Custom therapy strategies
1.2 Information Automatically Collected
Device and Usage Information:
- Device type and model
- Operating system version (iOS)
- App version
- Crash logs and error reports (anonymized)
- Performance metrics (app load times, API response times)
- Feature usage patterns (which screens are accessed, anonymized)
Technical Information:
- Anonymous analytics events (e.g., "lesson_generated", "trial_logged")
- API request success/failure rates (no personal data included)
- Session duration statistics (anonymized)
1.3 Information We Do NOT Collect
We explicitly do NOT collect:
- ❌ Child's full name or last name
- ❌ Child's date of birth or exact age
- ❌ Home address or location data
- ❌ Email addresses (unless you contact support)
- ❌ Phone numbers
- ❌ School information
- ❌ Medical diagnoses or treatment plans
- ❌ Insurance information
- ❌ Social Security numbers
- ❌ Photos or videos of children
- ❌ Biometric data
- ❌ Precise geolocation
- ❌ Financial information (beyond subscription purchase records)
2. How We Use Your Information
2.1 Primary Uses
We use the information collected to:
Core App Functionality:
- Generate personalized AI-powered lesson plans based on your child's needs
- Create task breakdowns with age-appropriate steps
- Track therapy progress and behavioral patterns
- Display progress statistics and visualizations
- Store and retrieve session notes and trial logs
- Manage therapy sessions and timers
App Improvement:
- Analyze feature usage to improve the app (anonymized data only)
- Identify and fix bugs and crashes
- Optimize app performance and speed
- Test new features and improvements
Support and Communication:
- Respond to your support requests
- Send important app updates and notifications
- Provide subscription management
2.2 AI Processing
When you generate a lesson plan or task breakdown, we send anonymized behavioral descriptions to our AI service (hosted on Google Cloud Run). This data includes:
- ✅ General behavioral concern description (e.g., "refuses to brush teeth")
- ✅ Child's age in years (general range)
- ✅ Communication style description
- ❌ No child's name
- ❌ No profile identifiers
- ❌ No historical trial logs or personal data
The AI service processes this information to generate therapy strategies and returns the lesson plan to your device. The AI service does not retain or store this data after processing.
2.3 Analytics and Improvement
We collect anonymized analytics to understand app usage:
- Feature usage patterns (e.g., "30% of users log trials daily")
- Session duration averages
- Crash rates and error frequencies
- API performance metrics
Important: Analytics data does NOT include child names, profile IDs, or therapy content.
3. Data Storage and Security
3.1 Local Storage (Your Device)
All personal and therapy data is stored locally on your device using:
- SQLite database (encrypted by iOS file system)
- Secure device storage
- No automatic cloud backups (unless you enable iCloud backup for the app)
Data Stored Locally:
- Child profiles
- Trial logs and session notes
- Lesson plans and task breakdowns
- Progress tracking data
- App preferences
Security Measures:
- iOS file system encryption
- Secure database access
- Input validation and sanitization
- No root/jailbreak detection
3.2 Data Transmission Security
When communicating with our servers (for AI lesson generation only):
- ✅ HTTPS/TLS encryption (end-to-end)
- ✅ API authentication tokens
- ✅ Request validation and rate limiting
- ✅ No personal identifiers in API requests
3.3 Error Tracking (Sentry)
We use Sentry for crash and error reporting with strict privacy safeguards:
- sendDefaultPii: false (no IP addresses, cookies, or user identifiers)
- PII Sanitization: All error messages are scrubbed of names, ages, and personal data
- Session Replay: Limited to 5% of sessions, excludes sensitive screens
- Data Retention: 30 days only
- Anonymous User IDs: Random identifiers, not linked to profiles
Example of sanitized error:
❌ BAD: "Failed to save trial for Emma, age 5"
✅ GOOD: "Failed to save trial for [CHILD_NAME], age [REDACTED]"
3.4 Subscription Management (RevenueCat)
For subscription processing, we use RevenueCat, which collects:
- Anonymous user ID (not linked to child profiles)
- Purchase receipts and subscription status
- Device type and OS version
RevenueCat does not receive child names, therapy data, or trial logs.
4. Data Sharing and Disclosure
4.1 We Do NOT Sell Your Data
We do not sell, rent, or share your personal information with third parties for advertising or marketing purposes. Period.
4.2 Third-Party Services
We share limited, anonymized data with the following service providers:
| Service |
Purpose |
Data Shared |
Privacy Policy |
| Google Cloud Run |
AI lesson generation |
Anonymized behavioral descriptions, child age range |
Google Privacy |
| Sentry |
Error tracking |
Anonymized crash logs, no PII |
Sentry Privacy |
| RevenueCat |
Subscription management |
Anonymous user ID, purchase receipts |
RevenueCat Privacy |
| Apple App Store |
App distribution |
Purchase history (Apple-managed) |
Apple Privacy |
4.3 Legal Requirements
We may disclose information if required by law:
- Court orders or subpoenas
- Government investigations
- Protection of rights, safety, or property
- Prevention of fraud or abuse
We will notify you of such requests unless prohibited by law.
4.4 Business Transfers
If Jeebu is acquired or merged with another company, your data may be transferred. We will notify you and provide options before any such transfer.
5. Children's Privacy (COPPA Compliance)
5.1 Our Commitment
Jeebu ABA Buddy is designed for parents, caregivers, and licensed therapists to track therapy for children. We comply with the Children's Online Privacy Protection Act (COPPA).
Key Protections:
- ❌ No direct child interaction: App is not designed for children to use
- ❌ No child accounts: No login or account creation
- ❌ No social features: No chat, forums, or user-generated content sharing
- ❌ No advertising: No third-party ads or tracking for ad purposes
- ❌ No data selling: Children's data is never sold
- ✅ Parental control: Parents/caregivers control all data entry and management
5.2 Parental Rights
As a parent or caregiver, you have the right to:
- ✅ Review all data stored about your child (view within app)
- ✅ Delete your child's profile and data (within app settings)
- ✅ Refuse further data collection (uninstall app)
- ✅ Contact us with questions or concerns
5.3 Age Verification
We do not collect birthdates or precise ages. Parents provide only the child's age in years (e.g., "5 years old") for therapy planning purposes.
6. Your Rights and Choices
6.1 Access Your Data
All data is stored locally on your device and accessible within the app:
- View child profiles
- Review trial logs and session notes
- See lesson plans and task breakdowns
- Check progress statistics
6.2 Modify Your Data
You can edit or update any information at any time:
- Edit child profiles
- Update therapy goals
- Modify lesson plans
- Correct trial log entries
6.3 Delete Your Data
Delete a Profile:
- Go to Home Page → Edit Profile → Delete My Child Data
- All associated data (trials, notes, lessons) will be permanently deleted
Delete All Data:
- Uninstall the Jeebu ABA Buddy app from your device
- All local data will be permanently removed
Important: Deleted data cannot be recovered. We do not have backup copies on our servers.
6.4 Export Your Data
To export your data for sharing with therapists or record-keeping:
- Not supported at this point
6.5 Opt-Out of Analytics
To limit data collection:
- Disable crash reporting in iOS Settings → Privacy & Security → Analytics & Improvements
- Note: This may limit our ability to fix bugs and improve the app
6.6 Manage Subscriptions
To manage or cancel your Pro subscription:
- iOS Settings → [Your Name] → Subscriptions → Jeebu ABA Buddy
7. Data Retention
7.1 Local Data
Data stored on your device is retained until:
- You delete a profile
- You uninstall the app
- You manually clear app data
7.2 Server-Side Data
We do not retain personal therapy data on our servers. However:
Error Logs (Sentry):
- Retained for 30 days, then automatically deleted
- Anonymized and scrubbed of PII
Analytics Data:
- Retained for 14 months (standard practice)
- Fully anonymized, no personal identifiers
Subscription Data (RevenueCat):
- Retained as long as your subscription is active
- Purchase history retained per Apple/Google requirements
7.3 AI Processing
Behavioral descriptions sent to our AI service are not retained after lesson generation. They are processed in-memory and discarded immediately.
8. International Data Transfers
8.1 Data Location
Your Device:
- All personal data stays on your device (worldwide)
AI Services:
- Hosted on Google Cloud Run (US region: us-central1)
- Anonymized behavioral descriptions may be processed in the United States
- No personally identifiable information crosses borders
8.2 International Users
If you are located outside the United States:
- Your local data remains on your device
- Only anonymized API requests reach US servers
- We comply with local privacy laws where applicable (GDPR, etc.)
9. HIPAA Compliance
9.1 Our Commitment
While Jeebu ABA Buddy is not a HIPAA-covered entity, we implement HIPAA-grade security practices:
Administrative Safeguards:
- Privacy and security training for all team members
- Incident response procedures
- Regular security audits
Technical Safeguards:
- Device-level encryption (iOS file system)
- Secure API communication (HTTPS/TLS)
- PII sanitization in error logs
- Access controls and authentication
Physical Safeguards:
- Local storage only (no centralized servers with PHI)
- No cloud backups of therapy data (unless user enables iCloud)
9.2 Business Associate Agreements
We do not act as a Business Associate under HIPAA because:
- We do not access Protected Health Information (PHI) on our servers
- All PHI stays on your device
- AI requests are anonymized and do not constitute PHI
10. Third-Party Links
The App may contain links to third-party websites or services (e.g., support documentation, privacy policies). We are not responsible for the privacy practices of these third parties. Please review their privacy policies before providing any information.
11. Changes to This Privacy Policy
11.1 Updates
We may update this Privacy Policy periodically to reflect:
- New features or functionality
- Changes in legal requirements
- Improvements to privacy practices
- User feedback
11.2 Notification
When we make changes:
- ✅ We will update the "Last Updated" date at the top of this policy
- ✅ Significant changes will be announced in-app with a notification
- ✅ Continued use of the app constitutes acceptance of the updated policy
11.3 Review History
You can review previous versions of this policy by contacting us at aijeebu@gmail.com.
12. State-Specific Privacy Rights
12.1 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Right to Know:
- Categories of personal information collected (see Section 1)
- Sources of personal information (directly from you)
- Business purposes for collection (see Section 2)
- Third parties with whom data is shared (see Section 4)
Right to Delete:
- Request deletion of personal information (see Section 6.3)
Right to Opt-Out:
- We do not sell personal information, so no opt-out is necessary
Right to Non-Discrimination:
- We will not discriminate against you for exercising your privacy rights
How to Exercise Rights:
- Email: aijeebu@gmail.com
- Subject line: "CCPA Privacy Request"
12.2 Virginia, Colorado, Connecticut, Utah Residents
Similar rights apply under state privacy laws (VCDPA, CPA, CTDPA, UCPA):
- Access your data
- Correct inaccurate data
- Delete your data
- Opt-out of targeted advertising (we don't do this)
- Opt-out of sale of data (we don't do this)
12.3 European Union / UK Residents (GDPR)
If you are in the EU or UK:
Legal Basis for Processing:
- Consent (by using the app)
- Legitimate interests (app functionality, improvement)
Your GDPR Rights:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
- Right to withdraw consent
Data Protection Officer:
- Contact: info@jeebuai.com
Supervisory Authority:
- You have the right to lodge a complaint with your local data protection authority
13. Security Measures
13.1 Technical Security
- Encryption: HTTPS/TLS for all API communication
- Authentication: Secure API tokens and request validation
- Input Validation: All user inputs are sanitized to prevent injection attacks
- Rate Limiting: Protection against abuse and DDoS attacks
- Code Security: Regular security audits and dependency updates
13.2 Organizational Security
- Access Controls: Limited access to backend systems
- Employee Training: Privacy and security training for all team members
- Incident Response: Documented procedures for data breaches
- Monitoring: Real-time alerts for suspicious activity
13.3 Your Responsibility
To keep your data secure:
- ✅ Use a strong device passcode/biometric lock
- ✅ Keep your iOS software up to date
- ✅ Do not share your device with untrusted individuals
- ✅ Be cautious when sharing screenshots or exported data
14. Data Breach Notification
In the unlikely event of a data breach:
- We will notify affected users within 72 hours
- We will provide details on what data was compromised
- We will offer guidance on protective measures
- We will report to relevant authorities as required by law
Important: Since all therapy data is stored locally on your device, a breach of our servers would not expose your child's therapy data.
15. Contact Us
15.1 Privacy Questions
15.2 Support Requests
15.3 Legal Inquiries
16. Consent
By downloading, installing, or using Jeebu ABA Buddy, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
If you are using the app on behalf of a child, you confirm that:
- ✅ You are the parent, legal guardian, or authorized caregiver
- ✅ You have the authority to consent to data collection and use
- ✅ You will supervise the child's therapy data and app usage
17. Effective Date and Scope
Effective Date: January 12, 2026
Applies To: All users of Jeebu ABA Buddy mobile application (iOS)
Version: 2.0.25
This Privacy Policy supersedes all previous versions.
Appendix A: Data Mapping Summary
| Data Category |
Storage Location |
Shared with Third Parties? |
Retention Period |
| Child's name |
Device only |
❌ Never |
Until deleted by user |
| Child's age |
Device only |
✅ Anonymized for AI (age range only) |
Until deleted by user |
| Trial logs |
Device only |
❌ Never |
Until deleted by user |
| Session notes |
Device only |
❌ Never |
Until deleted by user |
| Lesson plans |
Device only |
❌ Never |
Until deleted by user |
| Behavioral descriptions |
Device + AI (temporary) |
✅ Anonymized for AI processing |
Not retained after generation |
| Crash logs |
Device + Sentry |
✅ Anonymized for error tracking |
30 days |
| Analytics |
Device + App |
✅ Anonymized usage patterns |
14 months |
| Subscription status |
Device + RevenueCat |
✅ Anonymous user ID only |
Active subscription period |
Appendix B: Glossary
PII (Personally Identifiable Information): Data that can identify a specific individual (e.g., name, address, email).
PHI (Protected Health Information): Health data protected under HIPAA (e.g., diagnoses, treatment plans).
Anonymized Data: Data that has been stripped of all personal identifiers and cannot be linked back to an individual.
Local Storage: Data stored on the user's device (not on remote servers).
End-to-End Encryption: Data encrypted on device, transmitted securely, and decrypted only by intended recipient.
COPPA: Children's Online Privacy Protection Act (US law protecting children under 13).
HIPAA: Health Insurance Portability and Accountability Act (US law protecting health information).
GDPR: General Data Protection Regulation (EU law protecting personal data).
CCPA: California Consumer Privacy Act (California law protecting consumer data).
Document Information