Privacy Policy
Last updated: 30 September 2026
This notice matches the PlayStage app as it works today, including a market that stays on the phone, and it says which Firebase practices are planned but not switched on. It is written for a parent-directed app that can store family and child information. Have it reviewed before you rely on it for an App Store release. It is not formal legal advice.
Personal Information Collection Statement
This statement is for the Hong Kong Personal Data (Privacy) Ordinance. It applies when you enter personal data into the current on-device app.
- An email, a display name, and a password are required to keep an account on the phone. Without them, the app cannot sign you in. A child’s name and date of birth are required before age-based suggestions run for that child. Gender, notes, custom activities, and material photos are voluntary.
- The purposes are in section 3.
- Today the data stays on the phone. Family members on that phone see what their role allows. If you share an activity to the on-device market, other accounts on that same phone can read the listing. We do not transfer the data to another organisation. If Firebase is switched on later, Google will process it as described in sections 5 and 9.
- You may ask to access or correct your personal data. See section 11. A request will be answered within 40 days.
- Send that request to playstage.support@gmail.com. The operator’s name and postal address are not published on this page.
1. Who operates PlayStage
PlayStage is operated independently. For this notice, “PlayStage”, “we”, and “us” mean the operator of the PlayStage app. The operator’s name is not published on this page.
Contact: playstage.support@gmail.com.
2. What PlayStage collects
The current app stores information on the phone where you install it. You provide:
- Account: email address, display name, and password.
- Family: family name, members, roles (owner, parent, caregiver, or view-only), and invite codes created on that phone.
- Child profile: name, date of birth, optional gender, and optional focus areas. A stage illustration in the app is a bundled picture, not a photograph of a child.
- Play records, favourites, completions, parent notes, and the weekly plan you save.
- Daily routines: title, time, weekdays, who is responsible, whether a reminder is on, and whether a day is marked done.
- Family activities you write: title, age band, optional focus, duration, materials note, steps, words you might say, and a safety note.
- Optional photos of toys, books, or other materials, up to four per activity. These are not a child journal.
- If you share a family activity to the market on that phone: the activity text, your display name, and any photo you have marked for the market. A photo is left out unless you turn that on for that photo.
- Language choice, stored on the phone.
You do not have to add a gender, a photo, a note, or a custom activity. Without an email and password you cannot keep a local account. Without a child’s name and date of birth, age-based suggestions for that child do not run.
PlayStage does not ask you to create an account for a child. The account holder is the parent or caregiver.
3. Why PlayStage collects the information
- To sign you in on that phone and show your display name to your family.
- To keep a family, roles, and invite codes so people on the same phone can share a child and a calendar.
- To suggest official play ideas for the child’s age, and to keep the weekly five suggestions on official activities.
- To save play moments, notes, routines, and family activities you choose to keep.
- To schedule a reminder on that phone for a routine assigned to the person who is signed in.
- To show material photos with the activity they belong to.
We do not sell personal data. We do not use it for advertising. We do not use it to score or diagnose a child.
4. How information is used
Information is used to run the features you open: sign-in, family sharing on that device, the play library, the calendar, daily routines, reminders, and family activities. View-only members can read shared family material and cannot change it.
Routine reminders are scheduled by the phone’s own notification system. The notification does not include a person’s name. PlayStage does not send that reminder to another phone through Apple Push Notification service or Firebase Cloud Messaging.
Official play text, stage guides, communication tips, and theory cards ship inside the app. They are not collected from you.
5. Firebase and Google Cloud
The current app does not send accounts, family profiles, child profiles, play records, routines, or photos to Firebase. Firebase is not initialised, and the project keys in the app are placeholders.
A later family-sharing version is planned to use Google Firebase for:
- Firebase Authentication, for email and password sign-in and password reset.
- Cloud Firestore, for family, child, calendar, routine, and activity records.
- Cloud Storage, for material photos that stay private to the family.
- Firebase App Check and security rules, so one signed-in person cannot open another family’s data.
- Possibly Firebase Crashlytics, for crash reports that must not contain a child’s name.
That version is not released. Until this page says it is, assume your family data stays on the phone. Google’s processing of Firebase data will follow Google’s terms once the service is switched on. We will update this notice before that happens.
6. Data location
Today, the information in section 2 stays on the device. It is not stored on a PlayStage server, because there is no PlayStage server.
When the family-sharing version is released, family information in Firestore and photos in Cloud Storage are intended to be stored in Google Cloud in Hong Kong (asia-east2). Authentication data is processed by Firebase Authentication, which Google may handle on its own infrastructure and not only in Hong Kong. This page will name the live region when the project exists.
7. Account and authentication data
On the current on-device version, the email, display name, and password are stored in the app’s local storage so the phone can sign you in again. The password is stored on the device for this prototype. It is not a production password store, and it is not sent to us.
Password reset in this version does not send an email, because there is no mail service connected.
The planned cloud version will not keep the password in the app’s own database. Firebase Authentication will handle the password. A reset email will be sent by that service. We will not ask you to send a password to the support email.
8. Device and diagnostic information
The current app does not include a crash-reporting or analytics SDK, and it does not show an advertising-tracking prompt. The phone’s operating system may still keep its own logs outside PlayStage.
If Crashlytics is added later, it may receive device and app-version data and a crash trace. It must not receive a child’s name, a routine title that names a person, or the contents of a material photo. We will update this notice if that SDK is switched on.
Local notifications require the phone’s notification permission. The camera and photo library are used only when you choose a picture of a toy, book, or other material.
9. Whether information is shared with third parties
On the current version, we do not transfer your personal data to another organisation. Family members on that phone see what their role allows. If you share a family activity to the market, other accounts on that same phone can read the listing and download a copy into their own family library. That market is stored on the phone. Accounts on other phones cannot see it. The listing contains the activity text and your display name. A material photo is included only when you mark that photo for the market. That control is off until you turn it on.
When Firebase is switched on, Google will process the data in section 5 as the infrastructure provider. We do not authorise Google to use that data for its own advertising. We do not sell data, and we do not pass it to data brokers.
We may disclose information if Hong Kong law requires it, or to establish or defend a legal claim. Apple distributes the iOS app and handles App Store purchases and refunds under Apple’s own terms. Apple does not receive your family records from us.
These legal pages are hosted on GitHub Pages. Opening them does not send your PlayStage account to GitHub. GitHub receives ordinary web logs of visits to this site, under GitHub’s terms.
10. Data retention
On-device data remains until you reset local demo data in Profile, or until you delete the app. We have no separate copy to delete, because we do not hold one.
Invite codes, play records, routines, and photos stay with the family data on that phone until a member who is allowed to delete them does so, or until the on-device data is reset. A copy another family on that phone has already downloaded stays in their library until they delete it or reset that phone, even if you remove your listing.
The planned cloud version will keep family data until you delete the account or the family, as described in section 12. A backup of cloud data is not running today. If weekly backups are turned on later, the plan is to keep them for 30 days and then delete them. This page will say when backups start.
11. How to request access or correction
You can see and edit most family, child, routine, and activity fields in the app.
You can also email playstage.support@gmail.com and ask what personal data is held, or ask for a correction. Under the Personal Data (Privacy) Ordinance, a data-access or correction request will be answered within 40 days. We may ask you to confirm you are the account holder before releasing data.
Because the current version never uploads the data, the copy we can describe is the categories in this notice. The record itself is on your phone.
12. How to delete an account or data
Current version: open Profile and choose “Reset local demo data”. That clears, on this phone, the accounts, families, children, play records, favourites, notes, weekly plan, family activities, this phone’s market listings, material photos, daily routines, and the signed-in session. Your language choice is kept. Then delete the app if you want its files removed. Photos saved only on that phone are removed with the app’s storage.
There is no cloud account to delete yet. Emailing us cannot erase a copy we do not hold. It does not erase data on someone else’s phone, because this version does not sync.
Planned cloud version: account deletion will be inside the app, not only by email. The last owner of a family will need to appoint another owner or delete that family, including its child profiles, records, activities, and photos, before the login account is removed. We will update this section when that control exists.
13. Children and family information
PlayStage is for parents and caregivers. It is not directed at children, and it is not in a children’s app category. A child should not be asked to create the account.
A parent or caregiver who adds a child profile is providing that child’s name, date of birth, and any optional gender or focus. Please add only a child you are responsible for.
Privacy by default, in the product as built today:
- Gender, photos, notes, and custom activities are optional.
- A material photo is left out of a market listing unless you mark that photo. The market is only for accounts on this phone. There is no market on the internet, and other phones cannot see it.
- A reminder does not name the child or the caregiver.
- Official weekly suggestions stay the bundled activities. A custom activity does not replace them.
- View-only members cannot change family records.
Do not photograph a child’s face, a name, or contact details in a material photo. The app warns you; it does not scan the picture to enforce that.
14. Security
On-device data is protected by the phone’s own lock and by the operating system’s app storage. The prototype password store is not production security. Do not use a password you also use for email or banking.
The draft cloud database rules that sit in the source repository are not deployed. They must not be deployed as they are: a signed-in person could add themselves to a family, and invite codes would be too widely readable. The cloud version will not launch until rules are replaced and tested so that one family cannot read another, and a view-only member cannot write.
No method of storage is perfectly secure. Please keep the phone locked and do not share invite codes in public.
15. Not a medical service
PlayStage provides informational and organisational features only. It does not provide medical diagnosis, treatment, or professional medical advice.
Age bands, play ideas, communication examples, and theory cards are general educational material. They are not an assessment of any child and they are not a clinical record. If you are worried about a pregnancy, a child’s health, or development, speak to a qualified health professional. You can ignore any suggestion.
16. Changes to this policy
If the app starts sending data to Firebase, adds crash reporting, opens a market that other phones can see, or changes who operates it, this page will be updated first and the date above will change. The support page will carry the same date. Continued use of a cloud version after that date means you have had notice of the updated policy. The on-device version will keep behaving as this notice describes until an update says otherwise.
17. Contact
Support page: playstage-legal/support