Privacy Policy
Vine is operated by Vine Growth LLC, a Florida limited liability company.
Questions about this document? vineteam@vineteach.com.
Vine is a practice-investing app for ages 7–18+. We take privacy seriously because most of our users are children, and we built this policy to be clear enough that a parent or kid can read it without a law degree. The plain-English version: we collect the minimum we need to make Vine work, we don’t sell your data, and you can delete your account anytime.
1. What we collect
Account info you give us
- Email address — when you sign up with email or sign in with Google or Apple.
- Display name — optional; comes from your Google/Apple profile, or whatever you type during onboarding.
- Age band — “little” (7–9), “kid” (10–12), or “teen” (13–17). We don’t collect exact birthdate.
- Onboarding quiz answers — 5 multiple-choice questions used to recommend a starting lesson. Stored as a single score (0–5), not the individual answers.
- Parent/guardian name & email — when an under-13 age range is selected, we collect a parent or guardian’s name and email solely to obtain and record their consent (see the COPPA section below).
App-usage info we generate
- Practice portfolio — your simulated cash balance, which stocks you “own” in the simulator, the buy/sell history. No real money is involved.
- Lesson progress — which lessons you’ve completed, your level, claimed rewards.
- Goal data — if you set a savings goal in the app, the target amount, target year, and contribution schedule.
- Notification preferences — whether you’ve opted into price alerts and daily tips.
What we do NOT collect
- Real financial information. Vine has no access to your bank account, credit cards, or any real investment account. The cash in the app is fake.
- Location. The app does not request your location.
- Photos or contacts. Vine doesn’t ask for access to your camera, photo library, or contacts.
- Targeted-advertising identifiers. We use Firebase Analytics’ WithoutAdId variant specifically so we never collect Apple’s IDFA. This is required for “Made for Kids” apps and good practice generally.
2. How we use what we collect
- To run your account (sign you in, sync across devices).
- To save your progress — your portfolio, lessons, and goals follow you to a new phone or to the web.
- To send the notifications you opted into (price alerts, daily tips, email digests).
- To improve Vine — we look at aggregate, anonymized usage (e.g. “most kids skip Lesson 12”) to make the product better. Never individual users.
3. Who we share with
Vine is a small team. We don’t sell your data. We use the following third parties only because Vine cannot run without them:
- Firebase / Google Cloud — hosts your account, your portfolio, and your progress. Data is stored in Google data centers under Google’s privacy terms.
- Finnhub — provides real stock quotes and company news. We send a stock ticker; we never send your identity.
- Twelve Data — provides historical price charts. Same thing: ticker in, prices out, no identity.
- Cloudflare — the two requests above don’t go straight from your device to those companies. They pass through a small proxy we run on Cloudflare’s network, so our data-provider keys never end up in your browser. Cloudflare handles the request and sees the IP address it came from; it gets no name, email, or Vine account.
- CoinGecko — crypto prices on the Terminal screen. Ticker in, prices out, no identity.
- Company logos — the brand marks beside each stock are images loaded from
cdn.simpleicons.organd Finnhub’s image CDN. Like any image on the web, loading one tells that host your IP address and browser. No Vine account information goes with it. We’d rather serve these from Vine’s own domain so the kids’ app makes no outside image request at all; until it does, it is listed here. - Apple Sign In / Google Sign-In — handle the sign-in step. They tell us your email and verified-name token; we never see your Apple/Google password.
- Google Analytics 4 (property
G-HCNZMS9PLZ) — measures which public marketing pages people visit and how they arrive. It runs ONLY on public pages (never inside the kids’ app at/app,/onboarding, or/verify) and ONLY after a visitor taps “Accept” on the cookie banner. Data goes to Google under Google’s privacy terms.
The consent banner is how we gate optional analytics — tapping “Essential only” keeps Google Analytics off; tapping “Accept” enables it on public pages. Essential browser storage (keeping you signed in, saving your portfolio) is used either way — Vine can’t work without it.
4. Cookies, local storage, and similar technologies
Vine uses a small number of browser-storage items. Everything below is served over HTTPS. We do not use third-party advertising cookies. The kids’ app itself (any URL under /app, /onboarding, or /verify) uses ONLY the “essential” items below and NEVER the analytics ones — this is a hard rule enforced in code. For a plain-English standalone version of this section (with how to control cookies in each browser), see the Cookie Policy.
Essential — always on, needed for Vine to work
- Firebase Auth session (
firebaseLocalStoragein browser storage) — keeps you signed in across page loads. - Vine portfolio & progress (
vine.portfolio.v1,vine.progress.v1,vine.watchlist,vine.goal, etc.) — your practice cash, holdings, lessons completed, watchlist, savings goal. Stored inlocalStorageso your data is available offline; synced to Firestore when you sign in. - Language preference (
vine.progress.v1also holds your chosen language) — remembers whether you picked English or Spanish. - Firebase App Check token — a short-lived reCAPTCHA-derived token that proves the request is coming from the real Vine site (blocks bots and scrapers). Runs silently on every Firebase call.
- Cookie-consent choice (
vine.cookieConsent.v1) — remembers whether you tapped “Accept” or “Essential only” so we don’t re-ask you every visit.
Analytics — public pages only, off unless you accept
- Google Analytics 4 (property
G-HCNZMS9PLZ) sets cookies named_ga,_ga_<property-id>, and_gidto count unique visitors and page views on public marketing pages (/,/about,/parents,/teachers,/calculator, etc.). Set only after you tap “Accept” on the consent banner. If you change your mind, clear Vine’s cookies and site data in your browser — that removes these and re-asks you on your next visit. Data retention on our GA property is currently set to 14 months, then auto-deleted by Google. We do not use GA for advertising, remarketing, or Google Signals — those switches are turned off on our property.
You can clear all Vine cookies and local storage at any time from your browser’s site-data settings; this signs you out and resets your consent choice, but no Vine data is lost from the cloud if you were signed in.
5. For parents of kids under 13 (COPPA)
Vine is designed with kids in mind, including kids under 13. We follow the spirit of the U.S. Children’s Online Privacy Protection Act (COPPA):
- We collect the minimum information needed to run the app — no more.
- We don’t use your child’s data for advertising or marketing.
- We don’t allow other users to message your child or see their personal data.
- You can review, correct, or delete your child’s account by emailing us at vineteam@vineteach.com. We’ll respond within 30 days.
How consent works: When an under-13 age range is selected during onboarding, we require a parent or guardian to enter their name and email and give explicit, itemized consent before any further data is collected. Each consent is stored as an immutable record with a timestamp. Because Vine never shares a child’s personal information — name, email, progress, portfolio — with third parties, and shows no ads inside the kids’ app, we treat this as self-asserted parental consent; we’re working on adding an email-confirmation step so that this can meet the FTC-recognized “email plus” standard. A parent can review or withdraw consent at any time via Account → Delete account or by emailing vineteam@vineteach.com.
6. Your data, your rights
You can do all of the following at any time:
- See your data. The app shows you everything we have — your portfolio, lessons, goals, account.
- Delete your account. Account → Delete account permanently erases your cloud data (portfolio, lessons, goals) and your sign-in, immediately and from inside the app — no email required. (Account → Reset Vine is the lighter option: it clears your data but keeps your login.) You can also email us and we’ll process a deletion within 7 days.
- Export your data. Email us and we’ll send a JSON file of everything we have on you.
- Object to anything. Email us. We’ll read it and reply.
How long we keep it: we keep your information only while your account is active. When you — or a parent or guardian — delete the account, we erase your portfolio, lessons, goals, and sign-in. We don’t keep a child’s data longer than we need it to run Vine.
7. How we keep it safe
- All connections to Vine use HTTPS — no data travels in plaintext.
- Firestore (where we store account data) is locked down by per-user security rules — your data is unreadable by other users.
- We never log passwords. Sign-in tokens are managed by Firebase Auth and never touch our code directly.
8. International users
Vine’s servers (via Firebase) are operated by Google in the United States. If you use Vine outside the U.S., you consent to your data being processed in the U.S. The protections in this policy apply regardless of where you are.
9. Changes to this policy
We may update this policy from time to time. When we do, we’ll bump the “Reviewed” date at the top of this page. For changes that affect what we collect or who we share with, we’ll also notify signed-in users directly by email or in-app notice. Continuing to use Vine after the updated policy takes effect means you accept the change.
10. Contact
Questions or requests? Email vineteam@vineteach.com. A real person (currently the entire Vine team) reads everything that arrives there.