Privacy Policy
Kido Do ("Kido Do", "we", "our") is a family habit and reward app available for Android and iOS. The app was previously named "Kido Habits" and "Kindo Habits". Those names, the legacy package identifier com.kido.habits and new identifier com.kidodo, the kidohabits.app website, and Kido Do refer to the same service operated by Nikita Ivlev. This Privacy Policy explains what information we collect, how we use it, and what choices families have.
Information We Collect
Parent account information
Depending on the platform and sign-in option selected, parents may sign in with Apple, Google, or email and password. Through Firebase Authentication and the selected sign-in provider, we may receive or store an account identifier, email address, display name, authentication provider, sign-in status, and related security information. Apple and Google process sign-in information under their own privacy terms.
Child profile and access information
Parents create and manage child profiles. A profile may include the child's name, avatar, birth date, gender, family relationship, and internal profile identifiers. Children do not create an independent email-and-password account. A child enters the child flow using a time-limited code or QR code provided by a parent. We process the code, its status and expiry, and technical session or authentication identifiers needed to connect the child to the correct family.
Family content and activity
We store information families create and use in the app, such as tasks and schedules, rewards and wishes, task submissions and parent review decisions, coin balances, notification and motivation settings, streaks, calendar history, progress, and related timestamps and activity records.
Photos and media
Users may choose to upload parent or child avatar photos, wish or reward images, and task proof photos. The app may use the camera or photo picker only when a user chooses a feature that needs an image or scans a child sign-in QR code. Uploaded images and their links are stored with the relevant family content in Cloud Storage for Firebase.
Device, app, security, and notification information
We and our service providers may process app version and build number, platform and operating-system version, device category, language, family timezone, network and request information such as IP address, internal app or installation identifiers, notification preferences, and push notification tokens. This information is used to operate, secure, support, and troubleshoot the app. Push delivery uses Firebase Cloud Messaging and, on iOS, Apple's notification service.
Purchases and subscriptions
Premium purchases are processed by the store where the purchase is made: Google Play on Android or Apple App Store on iOS. RevenueCat helps us manage products and entitlements across the app. We may receive store, product, transaction or receipt identifiers, subscription and entitlement status, purchase and restore events, price and currency metadata, and renewal, cancellation, grace-period, or expiration information. We do not receive full payment card details from Apple or Google.
Analytics
We use Google Analytics for Firebase for product analytics when collection is enabled. On Android, Analytics starts disabled and is enabled only after the app confirms an authenticated parent session and the Remote Config analytics switch permits collection. It remains disabled for child, unknown, and signed-out Android sessions. On iOS, analytics events may be collected when enabled by Remote Config.
Our custom analytics events are designed to use coarse parameters such as role, flow, result, feature, counts, booleans, and reason categories. We do not intentionally put child names, emails, raw Firebase identifiers, access codes, task or reward text, wish notes, photo URLs, or other free-text family content into custom analytics events. Analytics providers may still automatically process device, app, and interaction information as described in their documentation.
Diagnostics and crash reporting
Production versions use Firebase Crashlytics to help diagnose crashes, non-fatal errors, and, where supported, application-not-responding events. Crashlytics may process crash traces, diagnostic logs, app and OS versions, device state and identifiers, and information about app execution near a failure. In the current production configuration, crash reporting operates at the app-process level and may therefore collect diagnostics during parent, child, or signed-out use. We do not intentionally attach account IDs, family IDs, child IDs, names, emails, access codes, or free-text family content as Crashlytics user identifiers, custom keys, or logs.
Support
When a parent contacts support, we process the message, reply address, and information the parent chooses to provide. The app may create an opaque support request code and include app version, platform, OS version, device category, and similar diagnostics. Parents should not send passwords, child access codes, payment card details, raw account identifiers, or private family photos or text unless support specifically requests information that is necessary to resolve the issue.
How We Use Information
- Create, authenticate, and manage parent and child sessions.
- Provide family tasks, rewards, wishes, submissions, progress, and motivation features.
- Store and display family content and media to authorized family members.
- Provide Premium products and reconcile purchase, restore, and entitlement status.
- Send transactional push notifications and local reminders selected by the family.
- Provide support and troubleshoot technical issues.
- Measure and improve reliability and product experience where analytics is enabled.
- Prevent abuse, protect accounts and the service, and enforce app limits.
- Comply with applicable legal obligations and valid legal requests.
Service Providers and Store Platforms
We use service providers to operate Kido Do:
- Google Firebase: Authentication, Cloud Firestore, Cloud Storage, Remote Config, Cloud Messaging, Analytics, Crashlytics, and related security and backend infrastructure. See Firebase Privacy and Security and the Google Privacy Policy.
- RevenueCat: subscription product, purchase, restore, receipt, and entitlement management. See the RevenueCat Privacy Policy.
- Apple: Sign in with Apple when selected, App Store distribution and billing, and iOS push notification delivery. See Apple's Privacy Policy.
- Google: Google Sign-In when selected, Google Play distribution and billing, and Android platform services. See the Google Privacy Policy.
These providers may process information under their own terms and privacy commitments. Their processing locations, retention periods, and available controls can differ by service.
Advertising, Sale, and Tracking
Kido Do does not currently display advertising. We do not sell personal information, and we do not use child profile or family content for personalized advertising. If our advertising or data practices materially change, we will update this Policy and the applicable store disclosures before or when the change takes effect, as required.
Children's Privacy and Parent Control
Kido Do is designed for parent-guided family use. A parent creates the family account, creates and manages child profiles, chooses what child information and content to provide, and gives the child a code or QR code for access. Premium purchases and subscription management are intended for parent mode.
Parents should provide child information only when they are authorized to do so and should supervise the child's use of the app. We use child-related information to provide the family features described in this Policy, not for advertising. Children's privacy requirements vary by jurisdiction; this Policy does not by itself establish compliance with every children's privacy law or program.
How We Share Information
We share information with the service providers and store platforms listed above only as needed for the purposes described in this Policy. Authorized members of a family account can see the profiles, activities, and content made available within that family.
We may disclose information when reasonably necessary to comply with law or a valid legal process, protect users or the public, investigate abuse or security incidents, enforce our rights, or support a business transfer subject to appropriate safeguards. We do not make family content public through the app.
Data Retention and Deletion
We retain account and family information while it is needed to provide the service and for legitimate security, support, dispute-resolution, and legal purposes. Specific records may have shorter lifetimes; for example, child access codes are time-limited.
A parent can delete the family account in the app or request deletion without access to the app by following the instructions on our Delete Account page. Deletion removes the active family record and associated parent and child profiles, tasks, rewards, wishes, submissions, child login codes, support request records, and family media controlled by Kido Do. Limited information may remain temporarily in provider backups, security or operational logs, or where retention is required by law, after which it is deleted or de-identified according to the applicable retention process.
Deleting a Kido Do account does not cancel a store subscription. A parent must separately cancel the subscription with Apple or Google, depending on where it was purchased.
International Processing
Kido Do and its service providers may process information in countries other than the country where a family lives. For example, Firebase Authentication is operated from the United States, while other Firebase services may use global infrastructure or configured cloud locations. Where required, providers rely on contractual and other transfer mechanisms described in their terms.
Security
We use measures such as authenticated access, backend authorization checks, Firebase security rules, scoped storage paths, encrypted network connections, and access controls intended to protect family data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Parent and User Choices
- Parents can review and update family content and profiles in the app.
- Families can manage notification permissions and in-app notification preferences.
- Parents can use Restore Purchases to reconcile an existing store purchase.
- Parents can delete the family account or request deletion through the web instructions.
- Parents can contact us to request access, correction, deletion, or a copy of information associated with the family account.
Depending on local law, a parent or user may also have rights to object to or restrict certain processing, withdraw consent where processing depends on consent, or complain to a data protection authority. We may need to verify the requester's identity and authority over the family account before completing a request.
Changes to This Policy
We may update this Privacy Policy as the app, service providers, or legal requirements change. We will post the updated Policy here and change the effective date. If a change is material, we may also provide notice in the app or through another appropriate channel.
Contact
For privacy questions or requests, contact support@kidohabits.app.
Developer and service operator: Nikita Ivlev.