Kidbys

Documents

Privacy Policy

How Kidbys collects, uses, shares, stores and deletes personal data about adults and children, and the rights you have over it.

DRAFT — pending legal reviewVersion 0.1-draftLast updated 2026-10-01

Short version (DRAFT — pending legal review; not yet in force)

  • We collect only what we need to run a safe gallery and marketplace for children's art. Your child's legal name, school, address and location never appear publicly.
  • We do not sell personal data, we do not show third-party ads, and we do not build advertising profiles of anyone, least of all children.
  • User data and media are hosted in the European Union. Kidbys itself is a US company, so some access happens from the US under legal safeguards.
  • Identity checks are done by a specialist provider. We receive a pass or fail result, not copies of ID documents or selfies.
  • You can download your data, correct it, withdraw consents and delete your account from Profile > Privacy & Data in the app, or by emailing [email protected].
  • Children's data has extra rules, explained in our Children's Privacy Notice.

Effective date: EFFECTIVE DATE

1. Who is responsible for your data

The controller of your personal data is LEGAL ENTITY NAME, REGISTERED ADDRESS, USA ("Kidbys", "we"). Contact us at [email protected].

Role Contact
Privacy team [email protected]
Data Protection Officer DPO NAME AND CONTACT — or state that no DPO is appointed and why
EU representative (GDPR Art. 27) EU REPRESENTATIVE NAME AND ADDRESS
UK representative (UK GDPR Art. 27) UK REPRESENTATIVE NAME AND ADDRESS

This policy applies to the Kidbys app, kidbys.com and related services. It uses the roles defined in our Terms of Service: Agent (parent or guardian), Collector (adult buyer), and Artist (a child profile managed by an Agent).

2. The short list of things we never do

  • We never put a child's legal name, exact date of birth, school, address, precise location or contact details in any public page or public data feed.
  • We never sell personal data or "share" it for cross-context behavioural advertising.
  • We never show third-party advertising and never use advertising SDKs.
  • We never use children's data, artwork or identity-check data to train AI models for others, or for marketing profiles.
  • We never let a child message other users.
  • We never store copies of identity documents, selfies or liveness videos ourselves.

3. What we collect

3.1 Data about adults (Agents and Collectors)

Category Examples Source
Account data Email address, display name, password (stored only as a secure hash), role (Agent or Collector), country of residence You
Sign-in with Apple or Google A stable account identifier from Apple or Google, and the email they share with us Apple or Google, at your request
Age check Your date of birth is checked at sign-up to confirm you are 18 or over. We store that the check passed and when; we do not keep the date of birth on your account You
Legal acceptances Which version of the Terms and Privacy Policy you accepted, and when; your consent choices You
Identity verification (Agents) Verification status, a reference to the provider's session, a failure category if it failed, and timestamps. The provider (Stripe Identity) collects your ID document and selfie on its own systems; we do not receive your name, date of birth, address, ID number or images from it You, via the provider
Family verification (Agents) The result of the joint parent-and-child liveness check (pass or fail, reason category, time, provider reference) and your attestation of parental authority You, via the provider
Payments and orders Order details, amounts, shipping address for physical orders, payment status and references to the payment provider's records. Card details are entered with and held by the payment provider, not by us You and our payment provider
Payouts (Agents) Status of your payout account with Stripe Connect (whether it is set up and whether payouts are enabled). Stripe collects the bank and identity details it needs directly Stripe
Seller tax records (Agents) Annual statements of sales, fees and payouts linked to your account and country, as required for tax reporting Generated by us
Marketplace activity Bids, offers, price requests, purchases, Sparks sent, artists followed, your private "My Sparks" list You
Communications Support requests, reports you make, appeals, and our replies You
Moderation and safety records Decisions about content or accounts, statements of reasons, suspensions, appeals and their outcomes Generated by us
Device and security data Sign-in sessions, IP address, user agent, device identifier, approximate time of last activity, rate-limit records, security audit events Your device
Push notifications A push token for your device and your notification preferences Your device
Product analytics A small, fixed set of events (for example "app opened" or "onboarding step completed"), keyed to a pseudonymous identifier rather than your account ID or email Your device and our servers
Crash reports Technical error reports with personal data stripped before sending Your device and our servers

3.2 Data about children (Artists)

We collect as little as possible about children. Most of it is provided by the Agent, not the child. Our Children's Privacy Notice explains this in detail.

Category Examples Source
Child profile Display name or nickname chosen by the Agent; an approximate age band where that feature is enabled Agent
Legal identity (restricted) Legal name and date of birth, only if needed for verification or a legal obligation. Held in a separate restricted store and never shown publicly Agent
Artwork Images of artwork, titles, publication status and moderation outcome. Location and camera metadata (EXIF/GPS) are stripped on upload Agent, or the child for private drafts
Child sign-in A picture-code credential (stored only as a secure hash), a device credential held in the device's secure storage, and short-lived child sessions Agent sets up; child uses
Encouragement Badges earned, Goals and their progress, the child's own Piggy Bank balance Generated by us
Joint liveness check The child takes part, with the Agent, in a liveness check run by the provider. We receive only a pass or fail result and reference; we do not receive or store the video Provider
Custody history Which Agent had custody of the profile and when Generated by us

We do not collect a child's email, phone number, address, school, precise location, contacts, voice or biometric templates. Child areas of the app have no free-text fields for personal information, no messaging, and no third-party advertising or analytics SDKs.

3.3 Visitors to kidbys.com

Our marketing website is a static site and sets no cookies. Our web hosting provider processes standard server logs (such as IP address and requested page) to deliver and secure the site. See our Cookie Policy.

If you are in the EU, EEA or UK, the law requires us to tell you the legal basis for each use. "Contract" means the processing is needed to provide the Service you asked for under our Terms. "Legitimate interests" means we have weighed our interest against your rights, with extra weight for children.

Purpose Data used Legal basis (GDPR / UK GDPR)
Create and run your account, sign you in Account data, device and security data Contract
Check you are an adult Date of birth at sign-up Legal obligation and legitimate interests (keeping minors out of adult accounts)
Verify Agents and family relationships before any child art is published or sold Identity and family verification results, attestations Legal obligation (parental consent rules); legitimate interests (child safety, fraud prevention); for any biometric step, explicit consent where required
Create and manage child profiles Child profile data Consent of the holder of parental responsibility (GDPR Art. 6(1)(a) and Art. 8) and contract with the Agent
Display a child's art publicly in the gallery and on their public page Display name, age band, published artwork Consent of the holder of parental responsibility, withdrawable at any time
Screen every upload for safety before publication, and review flagged, reported or appealed content Artwork, metadata, moderation records Legal obligation; legitimate interests (protecting children and users)
Detect, report and preserve evidence of child sexual abuse material and other serious crime Relevant content and account data Legal obligation; vital interests; legitimate interests
Run auctions, sales, prints, Sparks and Goals Marketplace, order and ledger data Contract
Take payments, pay out Agents, handle refunds, disputes and chargebacks Payment, order, payout and ledger data Contract; legal obligation
Keep financial and tax records, and report seller income where required Ledger, order, payout and tax records Legal obligation
Handle reports, complaints, appeals and support Communications, moderation records Legal obligation (EU Digital Services Act); contract
Send service messages (for example verification emails, order updates, safety notices) Email, push token Contract; legitimate interests
Send optional push notifications Push token, preferences Consent
Send marketing email Email Consent
Product analytics to understand which features work Pseudonymous analytics events Legitimate interests, with an opt-out in Privacy & Data; consent for feedback events
Fix crashes and keep the Service secure Crash reports, security logs, rate-limit records Legitimate interests
Comply with law-enforcement requests and legal claims Relevant records Legal obligation; legitimate interests

4.1 Automated decisions

Every upload passes through automated safety screening before it can be published. Screening can block clearly unsafe or malicious files, and sends anything uncertain or flagged to a trained human reviewer. Any appeal is always decided by a person, never by an automated system. These checks do not decide anything about your eligibility for credit, employment or similar matters.

5. Who we share data with

We share personal data only as described here.

  • Service providers (processors) who host, process or deliver the Service for us under contracts that limit their use of the data. Our current and planned providers are listed on our Subprocessor list, including hosting, storage, email, identity verification, payments, safety screening, crash reporting and push delivery.
  • App stores. If you buy through the Apple App Store or Google Play, they process your purchase under their own privacy policies. We receive transaction confirmations linked to an opaque account reference, never a child's data.
  • Other users, in a limited way. Collectors see an Artist's display name, age band and published art. A buyer and the selling Agent see what they need to complete an order, such as the buyer's shipping address for the Agent to post the artwork. Bidders never see each other's identities. Children never see buyers or prices.
  • Payment and payout providers (Stripe) act partly as independent controllers for their own legal duties, such as anti-money-laundering checks.
  • Authorities. We report apparent child sexual exploitation to the National Center for Missing & Exploited Children (NCMEC) and other competent authorities as the law requires, and respond to valid legal requests. See our Child Safety Standards.
  • Professional advisers such as lawyers, accountants and auditors, under confidentiality.
  • A buyer of our business, if Kidbys is sold or merged, subject to this policy.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

6. Where data is stored and international transfers

User data and media are hosted in the European Union: PRODUCTION HOSTING PROVIDER AND EU REGION. During the beta, data is hosted on a dedicated server and storage located in the EU (see Beta Test Terms).

Kidbys is a US company, and some of our providers are based in the US. When personal data from the EU, EEA, UK or Switzerland is accessed from or transferred to the US or another country without an adequacy decision, we rely on the EU–US Data Privacy Framework where the recipient is certified, or on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), plus additional safeguards such as encryption and access controls. You can ask us for a copy of the relevant safeguards at [email protected].

7. How long we keep data

We keep data only as long as we need it. Key periods built into the Service are below. Where a period is marked as a placeholder, it is pending legal review.

Data How long
Account data While your account is open, then deleted through the erasure process (Section 8)
Deletion "cooling-off" period 72 hours after you request deletion, during which you can cancel
Completion of a deletion request Within 30 days of the request
A data export file Available to download for 72 hours
Unfinished uploads Deleted after 60 minutes
Uploads held in quarantine or rejected by moderation Deleted after 30 days, unless under a safety hold
Orphaned media no longer attached to anything Deleted after 90 days
Product analytics events 180 days (365 days for feedback events), never more than about 13 months
Sign-in sessions (refresh tokens) Expire after 30 days of inactivity
Unaccepted custody-transfer offers Expire after 14 days
A single legal, financial or safety hold on deletion No more than 90 days at a time, and only for the specific data concerned
Financial and ledger records, orders, payouts, tax statements RETENTION — financial records, e.g. 7 years (US) / up to 10 years (some EU states). These are append-only accounting records and are linked to an anonymous placeholder after your account is deleted
Custody history Kept as an opaque record with no name, image or contact detail, to keep accounting and care history valid
Moderation and safety records, statements of reasons, appeals RETENTION — moderation and safety records
Evidence preserved for a child-safety report As required by law (for example, at least one year under US law for material reported to NCMEC)
Security and audit logs RETENTION — security and audit logs
Crash reports RETENTION — crash reports at the provider
Support emails RETENTION — support correspondence

8. What happens when you delete

You can request deletion in the app (Profile > Privacy & Data > Delete your account) or by email. Full steps are on How to delete your account. The erasure process is a fixed, ordered checklist. Public traces are removed first, so a hold on financial records can never keep a child's profile visible. For each step you can see whether it was completed, retained (with the legal reason), or held.

For an adult account the steps are: remove your public profile; end every session and token; delete push identifiers; delete the list of artists you followed; delete analytics identifiers; invalidate search and cache entries; erase your email, name, password, linked sign-in accounts and identity-verification link; and keep financial and custody history linked only to an anonymous placeholder.

For a child profile the steps are: remove the public profile and display name; revoke every child sign-in and device credential; delete uploaded artwork and every derivative; purge and rebuild the child's public web page; invalidate search and cache entries; purge expired private media; delete push identifiers; delete followers' records of following the child; delete badges; delete analytics identifiers; delete the child's legal name and date of birth; and keep financial and custody history as opaque records.

If a child profile has a sale still in progress, its custody arrangement stays open only until that order is finished so it can still ship and be paid for, and then closes automatically.

An Agent who still has child profiles in their care must first transfer or delete those profiles before deleting their own account, so no child profile is ever left without a responsible adult.

9. Your rights

9.1 Everyone

Wherever you live, you can ask us to access, correct or delete your data, and to stop optional processing. Use Profile > Privacy & Data in the app or email [email protected]. We may need to confirm your identity first, and in the app some actions ask you to re-confirm with your password or Apple or Google sign-in.

9.2 EU, EEA, UK and Swiss residents

You have the right to:

  • access your data and get a copy (the in-app export is a full machine-readable copy, including your child profiles' records while they are in your custody);
  • rectify inaccurate data;
  • erase your data;
  • restrict processing;
  • data portability;
  • object to processing based on legitimate interests, including analytics;
  • withdraw consent at any time, as easily as you gave it, without affecting earlier processing (in the app, under Consent records: product analytics, marketing email, push notifications and public gallery display);
  • not be subject to solely automated decisions with legal or similarly significant effects;
  • complain to a data protection supervisory authority, in particular in the country where you live or work. In the UK this is the Information Commissioner's Office.

We answer requests within one month, which may be extended by two further months for complex requests; we will tell you if so.

9.3 US residents

California (CCPA/CPRA). In the last 12 months we collected the categories of personal information listed in Section 3: identifiers; customer records; protected characteristics (age); commercial information; internet or network activity; approximate geolocation derived from country of residence; audio or visual information (artwork images); professional or employment information (none); inferences (none for advertising); and sensitive personal information limited to account log-in credentials and, for Agents, the outcome of identity verification. We use sensitive personal information only for purposes permitted without a right to limit. We have not sold or shared personal information, and we have no actual knowledge of selling or sharing the personal information of consumers under 16. You have the right to know, delete, correct, and opt out of sale or sharing (not applicable, as we do neither), and not to be discriminated against for exercising your rights. You may use an authorized agent. Requests: [email protected].

Other US states. Residents of states with comprehensive privacy laws (for example Colorado, Connecticut, Virginia, Texas, Oregon and others) have similar rights to access, correct, delete and obtain a copy of their data, and to appeal our decision on a request by replying to our decision email with "Appeal" in the subject line. We treat children's data as sensitive data in every state.

Children under 13. See our Children's Privacy Notice, which includes our notice under the US Children's Online Privacy Protection Act (COPPA).

10. Security

We protect data with encryption in transit, private storage for original media, hashing of passwords and child picture codes, strict role-based staff access with strong authentication, audit trails for sensitive actions, malware scanning of uploads, and regular backups with restore testing. Staff access to quarantined or reported content is limited to trained roles. No system is perfectly secure; if a breach affects you, we will tell you and the authorities as the law requires.

11. Changes to this policy

We will tell you in the app or by email before a material change takes effect and, where required, ask you to accept the new version. The app records which version you accepted. Previous versions are available on request.

12. Contact

Email [email protected], or write to LEGAL ENTITY NAME, REGISTERED ADDRESS. EU residents may also contact our EU representative, and UK residents our UK representative, listed in Section 1.