All legal docs
Uchi · Legal

Privacy Policy

Last updated: 28 July 2026 · Applies to Uchi for iOS (iOS 17 and later)

Uchi is a private home-management app for one family: shared shopping lists, bills and splits, chores and rewards, routines, a family calendar, meals and recipes, a pinboard, savings goals, subscriptions, pets and plants, home care, household documents, keepsakes, a private journal, and a quiet food log. It is made solely by Enes Kırgıl. This policy explains, in plain language, exactly what the app stores, where it goes, and — just as importantly — what it never collects.

Who this policy is for

Uchi is designed for a single household — the adults who set it up, and the children and guests they invite. Adults run the household: they invite members, set permissions, approve things, and can edit or delete anything the family has created.

Everyone old enough to hold their own account has one: the adults, and any teenager or guest who joins with the invite code. Children do not have their own account in the ordinary sense — a parent makes it for them, and the parental-consent section below sets out exactly what that parent is agreeing to.

How sign-in works (an account for every grown-up, and nothing at all from a child)

This is the part of Uchi that changed, so it gets said first and plainly. Until this version, Uchi signed your phone in anonymously and asked for nothing — no address, no password, no name. That was a genuine privacy promise, and it had a genuine cost: an anonymous sign-in lives on exactly one device, so a phone that was lost, broken, stolen or wiped took the whole household with it, permanently, and nobody — not even the person who made the app — could give it back. Uchi now asks every grown-up for an email address and a password so that a home outlives a phone.

What a grown-up gives, and where it goes. An email address, typed once when you make your account: Uchi mails six digits to it, you type those back into the app, and the address is confirmed. Until it is confirmed it counts for nothing. It is held by the service that runs sign-in and hosts the database on Uchi’s behalf, in the European Union (Frankfurt, Germany) — the same place as everything else your family adds. And a password, at least ten characters: Uchi does not store your password anywhere, in any form. It goes to the sign-in service, which keeps only a scrambled, one-way value it can check a future attempt against. Nothing else is asked for — no phone number, no legal name, no social login, no address book, no date of birth at sign-up.

What your address is used for — the whole list. Confirming your account. Letting you sign back in. Sending you six digits if you forget your password. That is all three of them. It is never used to market anything to you, never added to a mailing list, never sold, never shared with anyone, never handed to an advertiser or a data broker, and never used to build a profile of you or your family. Uchi has no newsletter and no marketing of any kind, so there is nothing for it to be added to.

Two-step sign-in, if you want it. You may add a six-digit code from an authenticator app on top of your password. It is optional and starts off. There are no recovery codes: if you lose both the authenticator and the phone, nobody can let you back in — that is said on the screen before you turn it on, and it is the honest cost of a second step nobody can talk their way past.

If you forget your password. Uchi mails six digits to your address and you type them into the app; you never have to leave it. The same mail also carries a link to the password page on this site, which does the same job in a browser. What that page does with your address is narrow and worth stating: it passes it to the sign-in service so a code can be mailed, and it keeps a short random value in your own browser’s storage so the link can be proved to have come home to the browser that asked for it. It stores nothing about you anywhere else, sets no advertising or tracking cookies, and carries no ads, no analytics and no trackers. The new password you type there goes straight to the sign-in service; the page keeps no copy. To avoid telling a stranger which families use Uchi, it says the same thing whether or not an address has an account.

If your family already had a home before this version. Your existing sign-in still works, and the app walks you through adding an address and a password to the account you already have. Nothing is copied, moved, exported or re-created: it is the same household, the same profiles, the same history, with a way back added. You cannot skip it, because a household with no way back is the problem this change exists to fix — but nothing of yours is touched whatever you do on that screen.

Children are never asked for an address or a password, and never given one. A parent creates a child’s account from inside the parent’s own account. Uchi then shows the parent a one-time eight-digit setup code; on the child’s phone, that code plus the child’s own PIN opens their profile. After that, the child’s phone holds a plain device sign-in that carries no email address, no password and no personal detail of any kind. Uchi has no way to send a child a message, because it has no way to reach one.

A child’s PIN. A child may set a short PIN to protect their profile. The PIN itself is never stored anywhere in readable form, only as an unreadable scrambled value that cannot be turned back into the PIN. Repeated wrong guesses lock the profile out for a while, and a parent can set a new PIN at any time without the child having to set the phone up again.

The invite code. An adult creates a household, which mints a 6-digit invite code. Anyone old enough to have their own account joins by entering that code and then signing up with their own address and password.

What is stored, and where

Everything your family creates lives in a hosted database and file storage run for us by Supabase, our data processor, located in the European Union (Frankfurt, Germany). Every piece of content is locked to the household that created it, so one family can never see another family’s data.

Your account — the email address, and whether it has been confirmed — sits with the sign-in half of that same service, in the same place. Your password is not stored by Uchi in any readable form anywhere; see the sign-in section above.

What that includes:

  • A child’s setup code, while it is still unused — the eight digits a parent hands their child’s phone, with the date it was made and the date it stops working (seven days). It is single-use, it disappears the moment it is used, and a parent can replace it at any time. It is shown to the parent once, when it is made, and can never be read back out of the app.
  • Which adult created a child’s profile — the parental-consent link, explained below.
  • A record that somebody agreed to these documents — which document, which version of it, in which language, when, who tapped, and who it was for. It has its own section further down, because it is the one thing Uchi stores that exists purely to protect you.

And the family content itself:

  • Family profiles, the display name your family chooses, a doodle avatar (a colour and a hairstyle), a role (owner, adult, kid, or guest), points earned from chores, an optional protected PIN, and optionally a birthday and a height if the family fills them in.
  • Household life, grocery and shopping lists; bills with their splits, payment history and reminders; chores, points and rewards; routines; plans and the family calendar; meals, recipes and the cookbook; pinboard scraps; savings goals; subscriptions; loans and settle-ups; pets and plant care; home care (maintenance, warranties, bin days, the emergency card, the house handbook); guests and party planning; keepsakes, memories, milestones and the growth chart; kindness notes; and your “Today” dashboard layout.
  • A private journal, each member’s own journal entries, kept to that member.
  • Photos and voice notes you choose to add, in private storage scoped to your household. See the sections below.
  • Household documents you choose to import — the boiler manual, a warranty, an insurance policy, a school letter — the file itself in that same private storage, plus the title you give it, an optional category, its file type and size, the page count for a PDF, and who added it. See the section below.
  • Food log entries, for anyone whose log is switched on: what was eaten, its calories, an optional portion in your own words (“1 bowl”, “iki dilim”), an optional meal slot, the day it belongs to, the moment it was written, and a link to a cookbook dish if it came from one.
  • The household’s calorie memory, a food’s name and what your family last said it costs, with no person and no date attached.
  • Body details on a profile, all optional: weight, the male/female constant the formula needs, roughly how much someone moves, and their own daily number if they set one. See the section below.

We store this because it is the app — it is the shared family notebook. Nothing is stored beyond what your family puts in.

What we do not collect

  • We never ask a child for an email address or a password. Nothing is collected from a child, at any point, by any route.
  • We never ask anybody for a phone number, a legal name, a social login, or a date of birth at sign-up.
  • We never use your email address for anything except the three things listed above — confirming your account, signing you back in, and resetting a forgotten password. No newsletter, no product mail, no reminders by email, no marketing, ever.
  • No advertising, analytics, crash-reporting, attribution, or tracking SDKs of any kind.
  • No advertising identifier (IDFA), no cross-app or cross-site tracking, and no App Tracking Transparency prompt.
  • No precise or background location. The only location involved is a weather coordinate you type in yourself, and it is blurred first (see below).
  • No contacts and no browsing history.
  • We do not read, index, scan, or analyse the contents of the documents you store.
  • We do not send anything Uchi reads from Apple Health to our servers, or to anyone else.
  • We do not put anybody’s food log, calories, bills, documents or journal into a widget.
  • We never sell, rent, or share your data with data brokers or advertisers, and we never build an advertising or marketing profile about you or your children.

One thing on that list used to be simpler than it is now, so it is worth being exact: if a family turns the food log on, Uchi does hold health data — what someone ate, and the optional body details behind the estimate. It is stored the same way as everything else in the app, in your household’s own rows, and it is described in full two sections below.

Camera

Uchi asks for the camera only when you tap to use it, and it is used in three different ways:

  • Chore-proof photos, a quick photo to show a chore is done. These are uploaded, into private storage locked to your household. The location and other hidden camera metadata are stripped on your device, before the photo leaves it, and the stored photo is served only through short-lived links.
  • Bill scanning, when you snap or pick a photo of a bill, the image is read entirely on your device to guess the amount, which you then confirm. For scanning, the image is not uploaded anywhere.
  • Food barcodes, pointing the camera at a barcode on a packet. The live camera frames are read on the device by iOS’s own barcode reader: no picture is taken, saved, or uploaded. The only thing that goes anywhere is the row of digits it found, and only to Open Food Facts.

The permission text you see in iOS names all three: “Take a quick photo to show a chore is done, scan a bill to read its amount, or scan a food barcode to look it up. Everything is read on your device, and photos stay in your family’s home.”

Photos you pick from your library

When you add a photo to a keepsake, memory, or milestone, you choose it through Apple’s system photo picker. Uchi receives only the photo you pick and never gets access to your library as a whole — which is why the app never shows a photo-library permission prompt. Photos you add are stored the same careful way as chore photos: hidden location metadata stripped on your device before the photo is uploaded, private storage scoped to your household, short-lived links only.

Microphone

You can optionally record a short voice note on a pinboard scrap. The microphone is used only while you are actively recording, and the recording is stored in private storage locked to your household. If you never record a scrap, the app never asks for the microphone.

Household documents

Uchi has a shelf for the family’s papers: the boiler manual, an appliance warranty, an insurance policy, a school letter, a cheatsheet. You add one by picking the file yourself in Apple’s system file picker, so Uchi receives only the file you choose and never goes looking through your device for anything else.

What is inside a document is entirely up to your family, and it may be sensitive — a tenancy agreement, a vaccination record, a payslip. So, to say it plainly: Uchi does not read, index, scan, or analyse the contents of your documents. Nothing about what a document says is sent anywhere except your family’s own private storage.

  • Where the file goes. Into a private storage area in the European Union (Frankfurt, Germany) that only your household can reach, handed out only through short-lived links — exactly the same handling as keepsake photos and voice notes.
  • Accepted files: PDF, JPEG, PNG, and plain text, up to 20 MB each. Anything else is refused, both in the app and on the server.
  • “Grown-ups only” is a real boundary, not a hidden card. When an adult marks a document grown-ups-only, the server itself keeps it away from children: they cannot see it, cannot change or delete it, and cannot fetch the file even if they know exactly where it sits. Only an adult can turn that on or off.
  • Searching happens on your phone. When you search inside a PDF, the search runs entirely on your own device. No search term and no page of your document is sent anywhere.
  • An offline copy on your device. Once you have opened a document, or asked to keep it on your phone, a copy stays there so the boiler manual still opens when the wifi is down. That copy is excluded from device backups, is capped in size and tidied up automatically, and goes away when you delete the document, replace its file, or drop the download yourself.
  • Photos you file as documents are cleaned first. A JPEG or PNG you import has its location and other hidden camera metadata stripped on your device before it is uploaded, like every other photo in Uchi. A PDF is stored exactly as it arrived, so anything its own author left inside it stays inside it — rewriting the file would break the text that in-document search depends on.
  • Deleting a document removes both its entry and the stored file. Adults can delete any document they can see; anyone can delete one they filed themselves.
  • Sharing it onward is your choice. If you send a document to another app with the system share sheet, what happens to it there is between you and that app — it has left Uchi.

The food log

Uchi can keep a quiet note of what someone ate. Please read the standing notice near the top of this page first — it explains what the daily number is and is not. This section is about where the writing goes.

  • Who it is on for. For grown-ups the log starts switched on, and any grown-up can switch their own off whenever they like. For children and for guests it starts off, and only a grown-up in the household can switch it on for them — a child cannot switch it on for themselves, and the server refuses the attempt rather than the screen merely hiding the button.
  • What one entry holds. The food’s name, its calories, an optional portion in your own words, an optional meal slot (breakfast, lunch, dinner, snack), the day it belongs to, the moment it was written, and a link to a dish in the family cookbook if it came from one. Nothing else.
  • Who can read it. Your own log, always. A grown-up may read a child’s log — that is the whole reason a parent is the one who has to switch it on — and the app tells the child so on their own screen. Nobody may read another grown-up’s: not their partner, not the person who created the household, and not a visiting grandparent’s either. And one child can never see another child’s.
  • Switching it off does not erase anything. It stops new entries being written; your own history stays yours, visible to you, and yours to delete line by line. Anyone can delete a line from their own log, including one a grown-up wrote for them — it is their record.
  • It is not broadcast. Food entries deliberately do not travel on the live channel other family surfaces use, so one person’s eating is not pushed at everyone else’s phone as it is typed. Devices pick up changes when the app next refreshes.
  • The household’s calorie memory is shared, and it holds no people. So that the second time somebody logs lentil soup it is one tap, Uchi keeps one row per food: the name and the number, and that is all. There is no “who logged it”, no date list, and no way to reconstruct who ate what from it. Any member can delete a remembered food from that list.

Body details, and what they are for

To offer a suggested daily amount, Uchi needs a few facts about a person. They are all optional, and this is the plain statement of what they are:

  • Weight, the male/female constant the formula needs, and roughly how much you move — the three that were added for this feature. Alongside them the formula uses the height and birthday already on a profile, if they have been filled in.
  • If any single one of them is missing, Uchi offers no suggestion at all rather than guessing. That is deliberate: a made-up number carrying the authority of a calculation is worse than no number.
  • The male/female value exists only as a constant in one equation. It is never shown as identity anywhere in the app.
  • Clearing any of them is a supported thing to do, not a mistake. Take one away and the app simply stops offering a suggestion.

Say it plainly: this is health data, and it is health data about a named person, including children. So is the food log itself, and so are two things Uchi already held — dietary notes (an allergy, a food someone must avoid) and the growth entries a family may keep for a child. All of it is stored the same way as everything else in this app: in your household’s own rows, in the database in the European Union, locked to your household by the same rules, with no analytics, no third party and no profile built from it.

Two extra guards worth knowing about:

  • Nobody can write a daily number into somebody else’s profile — not a parent, not the person who created the household. A target somebody else set for you would be a verdict; the suggestion is yours to accept or overwrite.
  • Under thirteen, no number can be stored at all, by anyone, by any route.

Apple Health (optional, off until you ask)

Uchi can link your food log to Apple Health. It is off until you turn it on, it is per person, and it only appears at all when your food log is on and you are old enough for the app to show a number in the first place.

  • Uchi asks Health for exactly one thing: dietary energy — the calories in food. It does not ask Health for your steps, your workouts, your weight, your sleep, your heart rate, or anything else, because it does not use them.
  • What Uchi can put into Health: your own food lines — the food’s name, its calories, and the time. Only ever your own: a grown-up who can see a child’s log inside Uchi cannot push that child’s eating into their own Health store.
  • What Uchi reads back: what Uchi itself wrote, so the screen can honestly say how many of today’s lines made it across, and today’s dietary-energy total from other apps, so the screen can show you whether the two agree.
  • None of it touches the network. Nothing read from Apple Health is sent to Uchi’s database, written to a file, put in the widget snapshot, or logged anywhere. It is read on the phone and used on the phone. The only thing Uchi stores about this link is which members switched it on, kept in the app’s own settings on that device.
  • Turning it off stops new writes immediately. What was already sent stays in Health, because that is your own store to keep or prune — Uchi does not reach back in and delete from it, and the screen says so instead of pretending otherwise.
  • One honest limitation. Apple deliberately refuses to tell an app whether reading was allowed, because “this person declined to share their food data” is itself private. So when Uchi finds nothing, it says “nothing there — or we weren’t allowed to look” rather than showing you a confident zero.

Looking up a packaged food (Open Food Facts)

When you look up a packaged food by name or scan its barcode, Uchi asks Open Food Facts — a free food database built by volunteers, with no account and no key.

  • What leaves your phone: the words you typed, or the digits of the barcode you scanned, plus a two-letter language code (English or Turkish) so product names come back in the right language. That is the entire request.
  • What does not leave your phone: no household id, no member id, no device id, no name, no location, no cookies (the connection keeps none), and nothing about who is asking. Uchi identifies itself with a fixed line naming the app and its version — the same for every copy of Uchi in the world.
  • Nothing is sent unless somebody actively asks. No search happens in the background, and none happens while you type until you pause. Your family’s own remembered foods and cookbook are searched first, on the phone, so most of the time nothing is sent at all.
  • Nothing is written to disk. Answers are remembered only in memory, only while the app is running, so what your family searched for does not outlive the session.
  • What comes back is only as good as the label somebody typed in. Open Food Facts is a volunteer project; a great many products in it carry no energy figure at all, and Uchi says “this product doesn’t list it” rather than showing you a confident 0. Nothing is saved to your household unless a person picks it and confirms it — and then only the name and the number, exactly as if they had typed it themselves.

Home Screen and Lock Screen widgets

Uchi’s widgets draw a small snapshot of the day. A widget gets a few hundred milliseconds and no account, so it cannot talk to the database at all — instead the app writes a small file the widget reads.

  • Where it lives. A file a few hundred bytes wide, in a shared container on your own phone that only Uchi and its own widget can open. It is never uploaded, and the widget has no session, no network and no database connection of any kind.
  • What is in it. The fridge note and who wrote it, today’s chore tally, how many things are still to buy and the first few of their names, tonight’s dinner, up to three of today’s plans, who is home (name, avatar colour, in or out), the family streak, and the language and season so the paper matches the app.
  • What is deliberately kept out, and may never be added. Anybody’s food log or calories. Bills, splits, settle-ups and savings. Documents and the house handbook. Journal entries, kindness notes, personal board scraps and grown-up requests. The rule the app holds itself to is simple: if the app would not show it to the youngest member of the household without asking anything first, it does not go in the file.
  • The Lock Screen consequence, plainly. A widget on the Lock Screen can be read by anyone holding your phone, without unlocking it. The fridge note can be personal — so if that matters to you, keep the note widget on the Home Screen, or do not add it.
  • It is cleared when it should be. If there is no member on the device — a sign-out, or a fresh install — the file is deleted, so a household can never keep drawing on a phone that has left it.
  • Tapping a widget parks the name of a tab in the same shared container for a few seconds, so the app opens where you tapped. It is read once and thrown away.

Your device calendar (optional, read-only)

Uchi can show your own device calendar events faintly alongside the family plans, so you can see everything in one place. This is off by default and turns on only if you deliberately enable it and grant calendar access. When it is on:

  • The overlay is read-only. Uchi never adds, edits, or deletes anything in your calendar.
  • Your events are read on your device only, held briefly in memory, never written to disk, and never uploaded to us or to anyone else.
  • Turning the toggle off, or revoking the permission in iOS Settings, clears them immediately.

Face ID

You can optionally protect parent approvals with Face ID, Touch ID, or your device passcode. That check is performed by iOS itself: your biometric information never leaves your device and Uchi never sees it — the app only receives a yes/no answer about whether the unlock succeeded.

Notifications

Reminders for bills, chores, plans, routines, maintenance, warranties and bin days, plus an optional daily digest, are all local notifications scheduled by iOS on your own device. There is no push server and no push notification service behind Uchi, so no notification token or message is ever sent anywhere. Quiet hours can mute them, and you can turn them off entirely in the app or in iOS Settings.

The only other services Uchi contacts

Apart from the household database and storage described above, Uchi contacts exactly four free public services, and only for the feature named. Each is a plain, anonymous request with no account, key, or identifier of yours attached, sent from a session that keeps no cookies:

ServiceUsed forExactly what it receives
open-meteo.comWeather and season nudgesThe latitude and longitude your household typed in for weather — and only if someone typed one in, because it is blank by default. The coordinate is rounded to roughly one kilometre before it is sent, so it points at an area, not at your home.
themealdb.comOptional recipe step ideasThe dish name you searched for.
frankfurter.appCurrency rates for billsThe currency codes to convert between (for example USD to EUR). No amounts and no bill details.
world.openfoodfacts.orgLooking up a packaged foodThe words you typed, or the digits of the barcode you scanned, plus a two-letter language code. Nothing about who is asking, and only when somebody actively searches or scans.

These services have their own privacy practices, which are outside Uchi’s control. Uchi sends them the minimum shown above and nothing that identifies you or your family. There are no other network calls in the app, apart from Uchi’s own database and its sign-in service.

About that sign-in service, plainly. Supabase is Uchi’s data processor in the European Union and does three jobs and no others: it hosts the database, it hosts the file storage, and it runs sign-in — which means it holds the email addresses, checks passwords, and is the thing that actually sends the six-digit mails when you make an account, change your address or reset a password. Those mails are the only email Uchi will ever cause you to receive.

And the password page on this website. The reset page is part of Uchi’s own site, not a third party. It exists so a forgotten password has a way back that works in a browser. It passes your address to the sign-in service so a code can be mailed, keeps a short random value in your own browser so the link can be proved to have returned to the browser that asked for it, and keeps nothing about you anywhere else. It has no ads, no analytics and no trackers.

The supporter tip

At the foot of the About screen there is one optional supporter tip. It is purely a tip: it unlocks nothing, and the app is completely and permanently functional without it. If you choose to tip, Apple handles the payment through your App Store account — Uchi never sees, receives, or stores your card or payment details, and we learn nothing about you from it. A Restore Purchases option is available. (The tip is not switched on yet; until it is, that section simply shows nothing.)

What Uchi keeps on your device

Five things live on the phone rather than on a server, and each is worth spelling out.

The offline unlock value. So that a child can still unlock their own profile when the phone has no connection, Uchi keeps a small value on that device once their PIN has been confirmed online at least once. That value is a scrambled, one-way version of the PIN: it cannot be turned back into the PIN, and it is held in iOS’s protected keychain.

To be explicit about what it is not:

  • The PIN itself is never stored in readable form, on the device or on the server.
  • This value never leaves the device — it is never uploaded to us or to anyone else.
  • It does not sync to iCloud and it is not included in device backups.

Offline copies of documents you have opened, in a protected app folder excluded from backups — described in the documents section above.

The widget snapshot, in the shared container — described in the widgets section above.

An unfinished sign-up. If you close Uchi in the gap between typing your email address and typing the six digits, the app keeps a small draft on that phone so you can pick up where you left off: the address, and the home details you had already filled in. It never holds your password, and it never holds a child’s PIN. It is not uploaded anywhere, it is deliberately kept out of the shared container the widgets can read, and it is deleted the moment your account is made or you start again.

Your settings, in the app’s own storage: the language, whether you want reminders, the Face ID gate, the calendar overlay switch, and the ids of the members who turned on the Apple Health link. Nothing here is uploaded.

Children’s privacy

Uchi is a family app that children use, and now that every grown-up signs in with an email address, the honest question is what happens to the children. The answer is the shortest one available: nothing is collected from a child at all.

A child never signs up, and is never asked for anything. No email address is ever collected from a child — not at sign-up, because there is no sign-up for a child, and not afterwards. Uchi has no way to send a child a message, because it holds no way to reach one. No password either: a child’s phone holds a plain device sign-in that carries no personal detail of any kind, plus the child’s own PIN, which is stored only as an unreadable scrambled value. And no phone number, no precise location, no advertising identifier, no third-party tracking, and no ads — none of those exist anywhere in Uchi for anybody, and children are no exception.

What Uchi holds about a child, and who typed it. Everything is entered by a parent inside the parent’s own account, or created by the child inside their own family’s home: a display name, a doodle avatar (a colour and a hairstyle), their role, their points, an optional protected PIN, a birthday and a height if a parent fills them in — the birthday is not decoration, it is what holds the “no calorie number under thirteen” floor in place — whatever household content they add themselves, their own journal entries, which adult created the account, and, if and only if a grown-up switches it on, a food log and any body details a grown-up fills in for the estimate. If your family keeps a growth chart for a child, or writes down an allergy or a food they must avoid, those readings and that note sit alongside the rest of it.

Children can share content only inside their own household — there is no public profile, no discovery, no messaging with strangers, and no way to reach anyone outside the family.

A document an adult has marked grown-ups only never reaches a child’s device at all. That rule is enforced on the server, so a child cannot see the document, open its file, or find it by any other route.

Around food specifically: a child cannot turn their own log on; a grown-up who turns it on can read it, and the child’s own screen says so; a child can never see another child’s log; under thirteen no daily calorie number is calculated or storable at all; and the Apple Health link is not offered under that age either, because Health would happily chart and total a young child’s calories and route straight around the rule.

Who counts as a child here is the family’s decision, not a guess Uchi makes. Uchi does not try to infer anyone’s age from a birthday it cannot verify. A parent decides whether to make an account for somebody or to send them the invite code so they sign up for themselves — and the safe answer, for anyone the parent thinks of as a child, is to make the account. The next section covers the age thresholds the law actually uses.

Adults manage children’s profiles, permissions and approvals, and can change or delete anything a child has, or remove them from the household entirely, at any time. If you believe a child has ended up with information stored about them that you want removed, email [email protected] and it will be removed.

Parental consent — what a parent agrees to, and how to take it back

This section is for the parent or guardian who makes a child’s account, and it is written to be read before you tap, not afterwards.

How consent is given. Adding a child happens in the Family tab, inside your own signed-in account, and only an adult can do it. Before anything is created, Uchi shows you a page — not a tick-box — that says who is asking (Uchi, made by one person, Enes Kırgıl, with no company behind it), that you are creating an account for your child and agreeing on their behalf, exactly what will be stored about them, that no email address and no password is collected from your child, where it lives (a private database in the European Union, Frankfurt), that it is never sold, shared or used for advertising, and that you can see it all, change it and remove it whenever you like. The button you press is not labelled “OK”. It says, in words: “I’m [name]’s parent or guardian, and I agree to this.”

What is recorded, and why that matters. When you tap it, Uchi stores a record: which documents you agreed to, which version of each, in which language you read them, when, that it was you who tapped, and that it was for your child. That last difference — the person agreeing is not the person it is about — is precisely what makes the record a record of parental consent rather than an ordinary acceptance. The next section lists every field.

Where this stands in law, honestly stated.

  • COPPA (United States). The rule protects personal information collected from a child under thirteen. Uchi’s answer is to collect none: there is no sign-up for a child, no address, no password, no message ever sent to them, and everything on a child’s profile is typed by a verified parent inside that parent’s own account. Uchi also discloses a child’s information to nobody — there are no advertising, analytics, crash-reporting or tracking services in the app at all, and nothing about a child is shared with any third party.
  • GDPR, GDPR-K and the UK Age-Appropriate Design Code (Europe and the UK). The lawful basis for holding a child’s information in Uchi is the consent of the holder of parental responsibility, given and recorded as described above. The digital consent age is not the same everywhere: it is thirteen in some member states and sixteen in others, including Germany. Uchi does not try to resolve that by guessing an age. If somebody in your home is near that line, the safe course is for a parent to create their account rather than sending them the invite code.
  • KVKK (Türkiye). Uchi is made in Türkiye and stores data in the European Union; the same consent, the same record and the same rights apply.

Your rights as the parent, and how to use them.

  • See everything. There is nothing Uchi holds about your child that you cannot see inside the app, in your own account. There is no hidden profile and no second copy.
  • Change or delete any part of it. Names, avatars, birthdays, heights, chores, points, food entries, body details — all editable and all deletable, by you, in the app.
  • Withdraw consent and remove the child entirely. Removing the child in the Family tab deletes their profile and everything attached to it, including their food log. That is the withdrawal mechanism, and it takes one adult and a few taps. If you would rather it were done for you, or you want a copy of everything first, write to [email protected].
  • Move a child to a different phone, or take one away. A parent can unlink the phone holding a child’s account and issue a new setup code. Nothing of the child’s is lost when they do — the points, the chores and the history belong to the profile, not to the handset.
  • Nothing is conditional. Uchi never asks for more about a child in exchange for more of the app. A child’s account works fully with nothing on it but a name and an avatar.

Teenagers. Somebody old enough to have their own account — the family decides who that is, with the age thresholds above in mind — joins with the invite code and signs up with their own address and password, exactly as an adult does. No parental consent record is created for them, because they are agreeing for themselves.

What is recorded when you agree to these documents

Uchi asks you to agree to this Privacy Policy, the Terms of Service and the License before your account is made, and it keeps a record of that. It is the one thing in this app that is stored purely to protect you, so here is exactly what it holds:

  • Which document — privacy, terms or license.
  • Which version of it. Each of the six bundled documents (three, in English and Turkish) carries a version stamp, and the record stores the stamp, not just a date. So the answer to “what did I actually agree to?” is a specific document, not a guess.
  • Which language you read it in — English or Turkish. A family who accepted the Turkish text and was later shown the English one would have a fair complaint, so the language is part of the record.
  • When, by the server’s clock rather than the phone’s.
  • Who tapped — the member and the account behind them at that moment.
  • Who it was for. For a grown-up agreeing for themself, those are the same person. For a parent consenting for a child, they differ — and that difference is the parental-consent record.
  • Which version of the app it happened in.

Who can see it, and who can change it. Everyone in your household can read their own household’s records, so a parent can see and show what they agreed to. Nobody can edit or delete one — the app has no way to change a consent record, only to add one. They go when your household or that member goes, which is the correct behaviour for a deletion request and the reason the record is not something extra you have to ask us to clear.

Children agree to nothing, ever. A child is never shown a legal document to accept and is never asked to tap one. Their parent accepts for them, and the record says so.

When the documents change. If the Terms or the License change, the adults in a household are asked to read and accept the new version before carrying on, and a parent’s acceptance covers the children they set up — the screen says so out loud rather than doing it quietly. A change to this Privacy Policy alone does not put a wall in front of the app: it is a notice, so it appears as one calm line on your own page, linking to the new text. Whatever changed is described in a sentence, rather than leaving you to re-read the whole thing to find out what moved.

Keeping and deleting your data

  • Your content stays in your household for as long as the household exists. We do not keep copies elsewhere. The food log is no different: the app only loads the last two weeks onto the screen, but the entries themselves stay until somebody deletes them.
  • Adults can remove members, and delete individual items — lists, bills, chores, photos, voice notes, documents, food entries, and the rest — from inside the app at any time. Deleting a document removes both its entry and the stored file, and clears the offline copy from the device.
  • Anyone can delete a line from their own food log, including one a grown-up wrote for them. Removing a member takes their food log with them — their entries are their own record, so they leave when they do.
  • The household’s calorie memory has no person attached to it, and any member can delete a remembered food from the list.
  • Deleting a household permanently removes all of its content along with it, including the stored photos, voice notes, documents, and food entries.
  • Removing a child deletes their profile and everything attached to it, and is how a parent withdraws consent.
  • Your sign-in account is a separate thing from your place in the household, and deleting one is not deleting the other. Leaving a household means an adult removes you in the Family tab; that takes your profile and your own content with it. Deleting your account erases the sign-in itself — your email address and your password — so that address can never sign in again.
  • Honestly stated, twice over. There is currently no one-tap household deletion inside the app, and the Delete my account row in the app hands you a message to send rather than doing it on the spot. Either way, write to [email protected] from the address on the account and it will be done by hand, usually within a few days. Both automatic versions are being worked on, and this page will say so plainly when they ship rather than quietly starting to be true.

Your rights

Depending on where you live — for example under the EU GDPR, the UK GDPR, or Türkiye’s KVKK — you may have the right to access your personal data, correct it, export a copy, delete it, and to object to or restrict certain processing. Because Uchi holds so little about you, and because adults can edit or delete household content directly in the app, most of these are things you can do yourself in a few taps. A parent exercises all of them on a child’s behalf.

For anything else — including a full copy of your household’s data, deleting your account, or deleting the whole household — email [email protected]. Your family’s data is stored in the European Union, and the only company that processes it on our behalf is Supabase, which hosts the database and storage and runs sign-in.

Security

  • Passwords are never held by Uchi. They go to the sign-in service, which keeps only a scrambled, one-way value; nothing readable exists on the phone or in your household’s rows. An address counts for nothing until the six digits sent to it have been typed back in.
  • Two-step sign-in with an authenticator app is available to anyone who wants a second lock on their household.
  • A child’s setup code is eight digits, works once, expires after seven days, is shown to the parent once and can never be read back out of the app, and is protected by a wrong-guess lockout that doubles. A parent can replace it in one tap.
  • A consent record cannot be edited or deleted by the app at all — only added to. That is deliberate: a record that can be quietly changed is not a record.
  • Every piece of content is locked to your household, so one family can only ever read its own things.
  • Photos, voice notes, and documents sit in private storage and are handed out only through short-lived links that expire.
  • A document marked grown-ups-only is gated both at the record and at the file, so a child cannot fetch its contents even with the exact address.
  • The food log’s boundaries are server rules, not screen logic: the switch a child cannot flip, the “no daily number under thirteen” floor, the rule that nobody may write a target into another person’s profile, and the rule that a grown-up’s log is readable only by that grown-up.
  • Offline copies of documents live in a protected app folder that is excluded from device backups, is capped in size, and is swept whenever the shelf refreshes.
  • A child’s PIN is kept only as an unreadable scrambled value, never as the PIN itself, and repeated wrong guesses lock the profile out for a while. The offline unlock value stays in the device’s protected keychain, out of iCloud and out of backups.
  • The widget snapshot lives in a container only Uchi and its own widget can open, carries nothing personal or permission-gated, and is deleted when the device has no member.
  • Nothing read from Apple Health is ever put on the network.
  • All traffic between the app and its database uses encrypted connections, and the data is hosted in the European Union.

No system is perfectly secure, but Uchi is built to collect little and expose less.

Changes to this policy

If the app starts doing something new with data, this page will be updated and the “last updated” date at the top will change. Meaningful changes will also be noted in the app and in its release notes on TestFlight or the App Store. Each document also carries a version stamp, so the record of what you agreed to always points at a specific text.

A change to this policy is a notice, not a new bargain: it appears as one calm line on your own page in the app, linking to the new text, with a sentence saying what moved. A change to the Terms or the License is different — those are the agreement itself, so the adults in a household are asked to read and accept the new version, and a parent’s acceptance covers the children they set up.

Contact

Uchi is made by Enes Kırgıl. Privacy questions, data requests, and deletion requests: [email protected].

This document is a plain-language description of how Uchi handles data. It is provided for transparency and is not a substitute for legal advice, and nothing in it is medical advice.

See also: Terms · EULA · Support