KiddoLog
by KitNow

Privacy Policy

Last updated: July 13, 2026

This Privacy Policy covers KiddoLog (the parent app) and KiddoSchool (the staff app), both operated by KitNow Co. ("we," "us"). The two apps share the same Firebase backend; your data is partitioned per family (KiddoLog) and per school (KiddoSchool) by your Firebase Authentication identity.

What we collect

From parents (KiddoLog users)

  • Account: email or phone number, display name.
  • Family: kid name(s), date of birth, allergies, pickup notes, emergency contacts (only what you type in), and photos you upload.
  • Activity: messages you send, and pickup/check-in passes you issue.
  • Device: push notification token (Firebase Cloud Messaging), and crash + non-fatal error reports (Firebase Crashlytics, with personal information redacted).

From staff (KiddoSchool users)

  • Account: email, display name, school assignment, and role.
  • Operational: clock-in/out times, attendance marks you record, messages you send, leave requests, and audit-log entries created by your actions.
  • Device: the same push token and diagnostics as parents.

From both

  • Analytics — off unless you turn it on. Usage analytics (Firebase Analytics) is opt-in and disabled by default. We ask once, in the app, and collect nothing until you say yes. You can withdraw consent at any time in Settings and we stop; declining costs you no functionality.
  • If you do opt in: anonymous app-open and screen-view events, and app actions that are not linked to your identity or to any child's. Analytics events deliberately carry no identifier that could be joined back to a person, a child, a message, or a conversation.
  • No advertising identifiers, ever. The apps do not access the iOS IDFA or the Android Advertising ID, and ad-storage and ad-personalisation signals are disabled outright.

What we do NOT collect

  • Cross-app advertising identifiers (IDFA on iOS; Advertising ID on Android).
  • Microphone, background location, photo library beyond the specific photo you pick, biometrics, health-sensor data, or browsing history.
  • Children's data beyond what a parent or staff member voluntarily types in. We do not knowingly collect data directly from children under 13 without parental supervision.

How we use it

  • Render the apps' content — your kid's roster, your message threads, your clock entries.
  • Send push notifications about pickups, messages, and notices.
  • Process Stripe subscription billing (KiddoSchool owners only).
  • Diagnose crashes and reliability issues, and understand which features are used.

How we share it

  • Within your family or school: data a parent enters is visible to the caregivers they invite and to staff at the school their kid is enrolled at; data staff enter is visible to colleagues at the same school.
  • With service providers we contract: Google (Firebase backend, analytics, crash reporting), Stripe (billing for schools), and Apple / Google (push delivery). Each processes data under its own privacy policy — see the Google, Stripe, and Apple privacy policies.
  • With law enforcement if required by valid legal process.
  • We do not sell your data.

Camera and device permissions

  • Camera: to capture photos for activities or profiles, and to scan QR codes for check-in / check-out.
  • Photo library: to select an existing photo to upload (we only access the photo you pick).

Photos may be compressed before upload to optimize storage and performance.

Retention

  • Account data: kept while your account is active. Deleting your account starts a 30-day retention window, after which the data is purged. The same email can be used to sign up again straight away; the new account starts empty and does not restore the old one.
  • Messages and passes: kept while the parent–school relationship is active.
  • Analytics: nothing is retained unless you opted in. If you did, standard Firebase retention applies (currently 14 months for events). Withdrawing consent stops further collection.
  • Crash reports: standard Firebase retention. A crash report carries a one-way hashed version of your account id (so we can tell one user's repeated crashes apart) and your role in the app. It never contains your name, email, messages, photos, or any child's details.

Removing a child — what is erased, and what the school keeps

This is not symmetrical, and we would rather say so plainly than let you assume.

  • Erased in full, permanently — the child's record on your side: their profile, their daily timeline, their photos and the underlying image files, their pickup and check-in passes, reported absences, and every caregiver's access to them. This is a real deletion, not a hidden flag.
  • Kept by the school — the school's own operational record: the attendance register, activity log, and incident / absence reports held in the school's account.

Why. An attendance and incident register is the school's record, not ours to erase on a parent's behalf, and childcare providers are commonly required to retain it. Deleting it would destroy the school's own history — including records that exist to protect children. The child's identifying information lives on the family side, and that is erased.

You are told this in the app, before you confirm the removal — not afterwards. If you want the school's retained records removed as well, that is a request to the school; you can also contact us at info@kitnow.co.

The child's photos stop resolving immediately: the image files themselves are deleted, so any link to them — including one someone had already opened — stops working at once. There is no lingering window.

Your rights

  • Access & export: Account → Export my data (KiddoLog), or Settings → Export school data (KiddoSchool).
  • Delete your account: Account → Delete account.
  • Remove a child: the child's profile → Remove. See Removing a child above for exactly what this erases and what the school keeps.
  • Turn analytics off (or on): Settings → Analytics. It is off until you opt in, and you can withdraw at any time.
  • Correct: edit your profile and your kid's profile from the parent app.
  • Ask us: email info@kitnow.co.

Children's privacy

KiddoLog and KiddoSchool are tools for adults (parents, teachers, and administrators) to record information about children. We do not knowingly collect personal information directly from children under 13, and we do not knowingly create accounts for them. If you are under 13 and using the app without a parent, please ask your parent to sign in instead. If you believe we have inadvertently collected data from a child, contact us and we will remove it.

Security

  • All network traffic uses TLS 1.3 (the Firebase SDK default).
  • Firestore security rules enforce per-family / per-school access boundaries.
  • Pickup and check-in passes are HMAC-signed tokens minted server-side; the apps never see the signing secret.

Changes to this policy

We will update the "Last updated" date above when this policy changes, and material changes are surfaced as an in-app banner. Please review this page periodically.

Contact us

If you have any questions about this Privacy Policy, please contact us at:

KitNow Co.
Email: info@kitnow.co

© KitNow Co. All rights reserved.
Support Privacy Policy Terms & Conditions