Kido Do

Privacy Policy

Effective date: August 23, 2026

Android and iOS Parent-guided child access No advertising

Kido Do ("Kido Do", "we", "our") is a family habit and reward app available for Android and iOS. The app was previously named "Kido Habits" and "Kindo Habits". Those names, the legacy package identifier com.kido.habits and new identifier com.kidodo, the kidohabits.app website, and Kido Do refer to the same service operated by Nikita Ivlev. This Privacy Policy explains what information we collect, how we use it, and what choices families have.

Information We Collect

Parent account information

Depending on the platform and sign-in option selected, parents may sign in with Apple, Google, or email and password. Through Firebase Authentication and the selected sign-in provider, we may receive or store an account identifier, email address, display name, authentication provider, sign-in status, and related security information. Apple and Google process sign-in information under their own privacy terms.

Child profile and access information

Parents create and manage child profiles. A profile may include the child's name, avatar, birth date, gender, family relationship, and internal profile identifiers. Children do not create an independent email-and-password account. A child enters the child flow using a time-limited code or QR code provided by a parent. We process the code, its status and expiry, and technical session or authentication identifiers needed to connect the child to the correct family.

Family content and activity

We store information families create and use in the app, such as tasks and schedules, rewards and wishes, task submissions and parent review decisions, coin balances, notification and motivation settings, streaks, calendar history, progress, and related timestamps and activity records.

Photos and media

Users may choose to upload parent or child avatar photos, wish or reward images, and task proof photos. The app may use the camera or photo picker only when a user chooses a feature that needs an image or scans a child sign-in QR code. Uploaded images and their links are stored with the relevant family content in Cloud Storage for Firebase.

Device, app, security, and notification information

We and our service providers may process app version and build number, platform and operating-system version, device category, language, family timezone, network and request information such as IP address, internal app or installation identifiers, notification preferences, and push notification tokens. This information is used to operate, secure, support, and troubleshoot the app. Push delivery uses Firebase Cloud Messaging and, on iOS, Apple's notification service.

Purchases and subscriptions

Premium purchases are processed by the store where the purchase is made: Google Play on Android or Apple App Store on iOS. RevenueCat helps us manage products and entitlements across the app. We may receive store, product, transaction or receipt identifiers, subscription and entitlement status, purchase and restore events, price and currency metadata, and renewal, cancellation, grace-period, or expiration information. We do not receive full payment card details from Apple or Google.

Analytics

We use Google Analytics for Firebase for product analytics when collection is enabled. On Android, Analytics starts disabled and is enabled only after the app confirms an authenticated parent session and the Remote Config analytics switch permits collection. It remains disabled for child, unknown, and signed-out Android sessions. On iOS, analytics events may be collected when enabled by Remote Config.

Our custom analytics events are designed to use coarse parameters such as role, flow, result, feature, counts, booleans, and reason categories. We do not intentionally put child names, emails, raw Firebase identifiers, access codes, task or reward text, wish notes, photo URLs, or other free-text family content into custom analytics events. Analytics providers may still automatically process device, app, and interaction information as described in their documentation.

Diagnostics and crash reporting

Production versions use Firebase Crashlytics to help diagnose crashes, non-fatal errors, and, where supported, application-not-responding events. Crashlytics may process crash traces, diagnostic logs, app and OS versions, device state and identifiers, and information about app execution near a failure. In the current production configuration, crash reporting operates at the app-process level and may therefore collect diagnostics during parent, child, or signed-out use. We do not intentionally attach account IDs, family IDs, child IDs, names, emails, access codes, or free-text family content as Crashlytics user identifiers, custom keys, or logs.

Support

When a parent contacts support, we process the message, reply address, and information the parent chooses to provide. The app may create an opaque support request code and include app version, platform, OS version, device category, and similar diagnostics. Parents should not send passwords, child access codes, payment card details, raw account identifiers, or private family photos or text unless support specifically requests information that is necessary to resolve the issue.

How We Use Information

Service Providers and Store Platforms

We use service providers to operate Kido Do:

These providers may process information under their own terms and privacy commitments. Their processing locations, retention periods, and available controls can differ by service.

Advertising, Sale, and Tracking

Kido Do does not currently display advertising. We do not sell personal information, and we do not use child profile or family content for personalized advertising. If our advertising or data practices materially change, we will update this Policy and the applicable store disclosures before or when the change takes effect, as required.

Children's Privacy and Parent Control

Kido Do is designed for parent-guided family use. A parent creates the family account, creates and manages child profiles, chooses what child information and content to provide, and gives the child a code or QR code for access. Premium purchases and subscription management are intended for parent mode.

Parents should provide child information only when they are authorized to do so and should supervise the child's use of the app. We use child-related information to provide the family features described in this Policy, not for advertising. Children's privacy requirements vary by jurisdiction; this Policy does not by itself establish compliance with every children's privacy law or program.

How We Share Information

We share information with the service providers and store platforms listed above only as needed for the purposes described in this Policy. Authorized members of a family account can see the profiles, activities, and content made available within that family.

We may disclose information when reasonably necessary to comply with law or a valid legal process, protect users or the public, investigate abuse or security incidents, enforce our rights, or support a business transfer subject to appropriate safeguards. We do not make family content public through the app.

Data Retention and Deletion

We retain account and family information while it is needed to provide the service and for legitimate security, support, dispute-resolution, and legal purposes. Specific records may have shorter lifetimes; for example, child access codes are time-limited.

A parent can delete the family account in the app or request deletion without access to the app by following the instructions on our Delete Account page. Deletion removes the active family record and associated parent and child profiles, tasks, rewards, wishes, submissions, child login codes, support request records, and family media controlled by Kido Do. Limited information may remain temporarily in provider backups, security or operational logs, or where retention is required by law, after which it is deleted or de-identified according to the applicable retention process.

Deleting a Kido Do account does not cancel a store subscription. A parent must separately cancel the subscription with Apple or Google, depending on where it was purchased.

International Processing

Kido Do and its service providers may process information in countries other than the country where a family lives. For example, Firebase Authentication is operated from the United States, while other Firebase services may use global infrastructure or configured cloud locations. Where required, providers rely on contractual and other transfer mechanisms described in their terms.

Security

We use measures such as authenticated access, backend authorization checks, Firebase security rules, scoped storage paths, encrypted network connections, and access controls intended to protect family data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Parent and User Choices

Depending on local law, a parent or user may also have rights to object to or restrict certain processing, withdraw consent where processing depends on consent, or complain to a data protection authority. We may need to verify the requester's identity and authority over the family account before completing a request.

Changes to This Policy

We may update this Privacy Policy as the app, service providers, or legal requirements change. We will post the updated Policy here and change the effective date. If a change is material, we may also provide notice in the app or through another appropriate channel.

Contact

For privacy questions or requests, contact support@kidohabits.app.

Developer and service operator: Nikita Ivlev.