Privacy Policy
Version 1.0 · Updated: September 2026 · Operator: Oshik Team (Yehuda) · udah10@gmail.com
Oshik is an educational money journal for families. Parents are the bank; the app is the ledger. All figures inside the application are educational simulations. There are no real bank accounts, debit cards, payment gateways, or financial institution connections.
Who This Policy Applies To
Family accounts are owned and managed by parents or legal guardians. Children connect to a family via a numeric PIN or QR code displayed on the parent's device — with no independent user accounts and no third-party social logins (such as Google or Apple) for minors.
Current State vs. Planned Architecture
Currently, the client application runs with in-memory local fixtures: demo data is held in device memory and resets upon app reload. There is no active backend server, no cloud storage, and no personal data collection by the Oshik operator.
Planned Architecture (Not yet active): A hosted journal backend on Supabase located in the Frankfurt, EU region. The sections below outline data practices planned for that deployment.
Planned Data Collection (When Cloud Backend Launches)
- Parent's name and email address for account authentication and service updates.
- First name or nickname of connected children (no independent child profiles).
- Journal ledger records: track balances (Spend, Save, Invest), child requests (cash-out, lock deposit, purchases), and family rules (caps, deposit interest rates, toggles).
Parent sign-in will be email-based (with optional single sign-on for parents only). Children do not use OAuth.
What We Never Collect
- Real money balances, bank account numbers, credit/debit card numbers.
- Payment processing details, payment apps, or fiat wire records — all real-world cash transfers occur offline between parent and child.
- Oshik does not hold deposits or act as a digital wallet. It records educational decisions.
Children's Privacy Protection (COPPA / GDPR Alignment)
Any use by minors requires the explicit consent and pairing by the parent account holder. We maintain strict child privacy safeguards: zero third-party advertising, zero ad tracking, and zero sale or sharing of user data. We will never use children's data for behavioral profiling or marketing.
Retention, Deletion, and Inquiries
Once the cloud service launches, family journal entries will be retained while the account is active to provide the service. You may request access, correction, or complete deletion of your family data by contacting hello@oshik.udah.dev. Deleting a parent account permanently purges all connected child data.
Until the cloud backend is active: no central database exists. Any data you enter remains strictly local to your device.
Governing Law
This policy shall be governed by and construed in accordance with the laws of the State of Israel, including the Protection of Privacy Law, 5741-1981, and applicable regulations. Exclusive jurisdiction shall lie with the competent courts of Israel.
Changes to this Policy
As Oshik evolves or following legal review, any policy revisions will be posted here with an updated revision date at the top of this document.