Skip to content

Legal

KidKept Privacy Policy

Last updated September 29, 2026

DRAFT — for review by licensed counsel before launch. Last updated September 29, 2026

[Entity name and type to be confirmed at formation.]

The short version

  • You own your data. We use it only to run KidKept for you.
  • We never sell your data, never use it for advertising and never use it to train AI — and our service providers can't either.
  • Nothing is shared unless you share it. You choose the recipient, the scope and the expiry, and you can revoke access.
  • The prototype keeps everything in your own browser. The cloud version will encrypt your data in transit and at rest.
  • You can export everything or delete everything, any time.
  • If someone demands your data through legal process, we'll tell you (unless we're legally barred), send them to you first, and hand over as little as possible.

1. Who we are and what this policy covers

KidKept, Inc. ("KidKept," "we," "us" or "our") is a Delaware corporation. We provide a private platform at kidkept.com that helps a parent in a custody matter keep an organized record about their children (the "Service").

This Privacy Policy explains what information we handle, why, who can see it and what choices you have. It's part of our Terms of Service.

"Account information" means your name, email, login and billing details. "Your Content" means everything you put into your record — profiles, journal entries, files, recordings, and the transcripts, analytics and exports generated from them. For Your Content, you are in charge: we process it only on your instructions, to provide the Service.

2. Our promises

These commitments apply to every version of KidKept:

  1. You own Your Content. We receive only a limited license to store, process and display it so we can provide the Service.
  2. No sale of data. We don't sell your information, and we don't "share" it for cross-context behavioral advertising, as those terms are defined in California law.
  3. No advertising. There are no ads in KidKept, and we never use your information to target ads anywhere.
  4. No AI training. We never use Your Content to train or improve AI models — ours or anyone else's. Our AI subprocessors are contractually bound not to train on it, and to keep zero or minimal data retention where that option is available.
  5. User-initiated sharing only. We don't give Your Content to third parties unless you choose to share it, with the narrow exceptions in Sections 8 and 9 (service providers who help us run the Service, and legal process we must respond to).
  6. Full export and deletion. You can take all of Your Content with you or delete it at any time.

3. How the prototype handles your data

The current prototype of KidKept works differently from the cloud version described in the rest of this policy.

  • Your record is stored locally in your web browser (IndexedDB), not on our servers.
  • We can't see, recover or back up it. If you clear your browser data or lose your device, it may be gone for good. Please export regularly.
  • Anyone who can use your browser profile may see your record. Lock your device and avoid shared computers.
  • Share packets are encrypted with a passphrase you choose. We never receive the passphrase. Send it to your recipient through a different channel from the packet itself.
  • We may collect minimal technical information from the prototype website (see Section 15), but not the contents of your record.

When we launch the cloud version, we'll ask for your permission before moving any of your data to our servers.

4. Information we collect

Information you give us

  • Account information: your name, email address, password (stored only in securely hashed form), MFA settings, and optional details like your time zone and your state or country (which helps us show you relevant recording-consent and legal information).
  • Your Content: profiles, journal entries, tags, notes, and uploaded files — which may include medical and therapy records, school records (including IEP and ARD documents), legal documents, financial statements, text-message exports, photos, and audio and video recordings.
  • Sharing information: the names, email addresses and roles of people you share with, and the scope and expiry you set.
  • Communications: messages you send to our support team.

Information about other people

Your record will almost always include information about other people — your children, a co-parent, relatives, professionals and others. These people did not give us their information directly. You're responsible for adding it lawfully and only as relevant to your matter (see our Terms). We handle it with the same protections as the rest of Your Content.

If you believe your information is in someone else's KidKept record, see Section 12.

Information from share recipients

When someone accepts a share, we collect their name, email, role (for example, attorney or guardian ad litem), their acceptance of the confidentiality terms, and an access log of what they view and download.

Information collected automatically

  • Security and usage logs: IP address, device and browser type, login times, and actions taken in your account (such as uploads, exports and shares). We use these to secure your account, maintain an audit trail and fix problems.
  • Limited product analytics: aggregate information about which features are used, collected without the contents of your record. You can turn this off in settings.

Information from our payment processor

Our payment processor handles your card details. We receive only limited information, such as your billing name, the last four digits of your card, the expiry date and your billing ZIP or postal code. We never see or store your full card number.

5. How we use information

We use information only to:

  • provide the Service — store, organize, search, transcribe, analyze and display Your Content, and create exports and shares you request;
  • secure the Service — authenticate you, detect suspicious logins, prevent abuse and keep audit logs;
  • support you — answer your questions (we'll ask your permission before viewing any of Your Content to help);
  • bill you — process payments and manage your subscription;
  • communicate with you — send service, security, billing and policy notices (we won't send marketing emails unless you opt in, and you can unsubscribe at any time);
  • improve the Service — using aggregate, de-identified usage information that doesn't include the contents of your record; and
  • comply with the law and enforce our Terms.

We don't use Your Content to build a profile of you for any purpose other than providing the Service, and we don't use it to make automated decisions that have legal or similarly significant effects on you.

6. AI processing

Some features use artificial intelligence, such as audio and video transcription, video descriptions, document analysis and summaries. In the cloud version:

  • AI features are optional. You can turn them on or off, overall or for specific files.
  • Processing is limited to your request. When you use an AI feature, we send only the content needed to perform that task to the relevant subprocessor.
  • No training. Neither we nor our subprocessors use Your Content to train or improve AI models.
  • Minimal retention. We use zero-data-retention or the shortest available retention settings with AI providers. Where a provider must briefly keep data for abuse monitoring or legal compliance, we will say so in our subprocessor list.
  • AI output is yours. Transcripts, descriptions and summaries are part of Your Content, and you can edit or delete them.
  • AI can be wrong. Please check AI output against the original material.

7. What we never do

Beyond the promises in Section 2, we never share Your Content with your co-parent, their attorney or anyone else unless you share it or we're legally compelled (Section 9). We never read Your Content for our own purposes, allow ad trackers in the Service, or give data brokers access to any of your information.

8. When information is shared

When you share it

Every share is started by you. Before a share is sent:

  1. You sign off. You confirm that you have the right to share the material, and that sharing doesn't violate any court order, protective order or confidentiality duty.
  2. The recipient agrees to confidentiality terms. They promise to use the material only for your matter, not redistribute it beyond the proceeding, and comply with applicable protective orders.

You can scope a share by person, category and date range; set it to expire; and revoke it at any time. Every share has an access log, and downloaded documents are watermarked with the recipient's name and date. Revoking a share stops future access through KidKept, but can't retrieve copies the recipient has already downloaded.

Service providers (subprocessors)

We use a small number of carefully chosen companies to help run the Service. They may process data only on our instructions, only to provide their service to us, and under written contracts that require confidentiality, security, no-sale and no-training commitments. Categories include:

PurposeExample providerWhat they process
Cloud hosting and storageA major cloud providerEncrypted account data and Your Content
AI document analysisAnthropicDocuments or text you choose to analyze
Speech-to-textA transcription providerAudio and video you choose to transcribe
PaymentsA payment processorBilling details
Email deliveryAn email serviceYour email address and notification content (never the contents of your record)

We'll publish a current list of subprocessors at kidkept.com and give you at least 30 days' notice before adding a new one that processes Your Content.

Business transfers

If KidKept is involved in a merger, acquisition or sale of assets, your information may be transferred. Any successor must honor this Privacy Policy. We'll notify you in advance and give you the chance to export and delete your data before the transfer.

We may disclose information when we're legally required to (Section 9), or in the rare event that we believe in good faith that disclosure is necessary to prevent imminent death or serious physical harm. As the law requires, we report apparent child sexual abuse material to the National Center for Missing & Exploited Children.

In custody disputes, the other side may try to get your records from us. Here's what we do:

  • We tell you first. We'll notify you of any request for your information and give you time to respond (for example, by seeking a protective order), unless the law or a court order prohibits notice, or there's an emergency involving risk of death or serious harm. If notice is delayed, we'll notify you once the restriction ends.
  • We send the requester to you. Your record is yours, and the right place to seek it is from you through normal discovery. We'll encourage requesters to do that.
  • We require valid legal process. We don't respond to informal requests. We review each request for validity and scope.
  • We give the narrowest response possible. If we must respond, we'll disclose only what's specifically and lawfully required, and we may object to or challenge requests that are overbroad or improper.
  • We keep a record of requests and plan to publish an annual transparency report once we launch.

Note on encryption: in the cloud version, your data is encrypted in transit and at rest, but it is not end-to-end encrypted by default. That means we could technically be compelled to produce it. Share packets created in the prototype are protected with your own passphrase, which we never have.

10. Children's information, health records and school records

Children

KidKept is for adults 18 and older. Children may not create accounts or use the Service. We do not knowingly collect personal information directly from children.

Information about children in the Service is provided by a parent or legal guardian, for the purpose of protecting that child's interests in a legal matter. The Children's Online Privacy Protection Act (COPPA) applies to online services that collect personal information directly from children under 13. KidKept is not directed to children and does not collect information from them. Even so, we treat children's information as among the most sensitive data we hold: it's never sold, never used for ads or AI training, and shared only through the user-initiated process above.

If we learn that a child under 18 has created an account, we will close it. If you think this has happened, contact privacy@kidkept.com.

Health information (HIPAA)

The Health Insurance Portability and Accountability Act (HIPAA) applies to health-care providers, health plans and their business associates. KidKept is generally not a HIPAA "covered entity" or "business associate" — when you upload a medical or therapy record you obtained, HIPAA typically doesn't govern our handling of it.

We still treat all health and mental-health information with heightened protection: encryption, strict access controls, logging, and no use for any purpose other than providing the Service to you. If we ever enter into a business associate agreement with a health-care provider, we'll follow HIPAA for the information it covers.

Some states have consumer health-data laws, such as Washington's My Health My Data Act. We will honor the rights and consent requirements of those laws where they apply, and we will publish a separate consumer health data notice where required.

School records (FERPA)

The Family Educational Rights and Privacy Act (FERPA) governs how schools handle education records. It gives parents the right to access their child's records. Once you've lawfully obtained your child's school records, including IEP and ARD documents, FERPA doesn't govern how you store them in KidKept. We protect them with the same safeguards as other sensitive information. Please check whether a court order or school agreement limits how you may share them.

11. Security

We use administrative, technical and physical safeguards designed to protect your information, including:

  • Encryption in transit (TLS) and at rest (AES-256 or equivalent) in the cloud version;
  • Passphrase-based encryption for prototype share packets;
  • Access controls that limit our staff's access to Your Content to authorized personnel with a specific need — such as when you ask for support and give permission, or when required for security or law;
  • Audit logs of account activity, sharing and staff access;
  • Multi-factor authentication, which we strongly encourage for all users and require for staff;
  • Security testing, staff training and confidentiality agreements.

No system is perfectly secure. You can help protect your record by using a strong unique password, turning on MFA, keeping your devices locked and updated, and reviewing your access log.

If there's a data breach

If we discover a security incident that affects your personal information, we'll notify you without undue delay — and within the time frames required by law — along with the relevant regulators. We'll tell you what happened, what information was involved, what we're doing about it and what you can do to protect yourself.

12. Your choices: access, export, correction and deletion

You can edit anything in your record directly. At any time you can also:

  • Export everything — a machine-readable copy (such as JSON or CSV) plus all your original files, in a single download.
  • Delete individual items or your entire account from your settings, or by emailing privacy@kidkept.com.

What happens when you delete

  • Deleted items move to a "Recently deleted" folder for 30 days, in case you delete something by mistake. You can empty it sooner.
  • After that, we delete the data from our active systems within 30 days.
  • Encrypted backups are overwritten on a rolling basis and fully purged within 90 days after deletion from active systems.
  • We may keep limited records where the law requires — for example, billing records for tax purposes, or data subject to a legal hold we've been ordered to preserve. We'll keep these secure and use them only for that purpose.

Deleting your account does not delete copies that recipients have already downloaded from a share.

If you're in someone else's record

Because KidKept records belong to the users who create them, we generally can't give non-users access to, or delete information from, another person's record. If you believe someone is using KidKept to harass you, or in violation of a court order, contact legal@kidkept.com and we'll review it under our Terms.

13. How long we keep information

InformationHow long we keep it
Your ContentUntil you delete it or your account ends, plus the deletion timelines above
Account informationWhile your account is open, plus up to 90 days
Billing recordsAs long as required by tax and accounting laws (typically 7 years)
Security and audit logsUp to 1 year, or longer if needed to investigate an incident
Share access logsFor as long as the share exists, then deleted with your account
Support messagesUp to 2 years

Inactive accounts

If a free account is inactive for 24 months, we'll email you at least twice over 60 days before taking any action. If we don't hear back, we may close the account and delete its data under the timelines above. Paid accounts are never closed for inactivity while the subscription is active.

If a user dies or becomes incapacitated

We understand how important a record like this can be for the children involved. If a user dies or becomes legally incapacitated:

  • A court-appointed personal representative, guardian or conservator, or a person the user named in advance as a legacy contact, may ask us to export or delete the account.
  • We'll require appropriate documentation, such as a death certificate or court order.
  • We won't give anyone else — including a co-parent — access to the account unless a court orders it.
  • You can name a legacy contact in your account settings and choose what they'll be able to do.

14. Your U.S. state privacy rights

Depending on where you live, state laws — such as the California Consumer Privacy Act as amended by the CPRA, and privacy laws in Colorado, Connecticut, Virginia, Texas, Oregon and other states — may give you rights to:

  • know what personal information we collect, use and disclose, and get a copy;
  • correct inaccurate information;
  • delete your information;
  • opt out of sale, targeted advertising and certain profiling (we don't do any of these);
  • limit the use of sensitive personal information (we use it only for purposes the law permits, such as providing the Service you request); and
  • not be discriminated against for exercising your rights.

Categories of information. In the past 12 months, we've collected identifiers, account and billing information, internet activity (security and usage logs), audio and visual information you upload, and sensitive personal information you upload (such as health, financial and children's information, and account login credentials). We collect them from you and your devices, for the purposes in Section 5, and disclose them only to the subprocessors in Section 8 and recipients you choose. We don't sell or share personal information, and we have no actual knowledge of selling or sharing the information of anyone under 16.

How to make a request. Email privacy@kidkept.com or use the privacy settings in your account. We'll verify your identity (usually by confirming control of your account) before responding. You may use an authorized agent, with proof of their authority. We'll respond within 45 days, or tell you if we need more time as the law allows.

Appeals. If we deny your request, you can appeal by replying to our decision or emailing privacy@kidkept.com with "Appeal" in the subject line. If you're not satisfied with the result, you may contact your state attorney general.

15. Cookies and similar technologies

We keep cookies to a minimum. We use only:

  • essential cookies that keep you signed in, protect against fraud and remember your security settings; and
  • optional, privacy-respecting analytics that count feature usage without tracking you across other sites. You can turn these off.

We don't use advertising cookies, social-media pixels, cross-site trackers or session-recording tools. The prototype stores your record in your browser's IndexedDB; that storage stays on your device and isn't used for tracking.

Do Not Track and Global Privacy Control. Because we don't track you across websites, there's nothing for a Do Not Track signal to turn off. We honor Global Privacy Control (GPC) signals as a valid opt-out request where required by law.

16. Users in the European Economic Area, the United Kingdom and Switzerland

KidKept is designed for U.S. custody matters, but we include this section for completeness.

Controller. KidKept, Inc. is the controller of account information. For Your Content, including information about other people, you generally decide why and how it's processed, and we act on your instructions.

Legal bases. We process information to perform our contract with you; for our legitimate interests in securing and improving the Service (balanced against your rights); to comply with legal obligations; and with your consent where required (for example, optional AI features and analytics). Special-category data, such as health information, is processed with your explicit consent and, where applicable, because it's necessary for establishing, exercising or defending legal claims.

Your rights. You may have rights to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent at any time. Contact privacy@kidkept.com. You may also complain to your local data protection authority or, in the UK, the Information Commissioner's Office.

International transfers. Your information is stored and processed in the United States. Where required, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms.

17. Changes to this policy

We'll update this policy as the Service evolves — especially when we move from the prototype to the cloud version. If we make a material change, we'll notify you by email or in the app at least 30 days before it takes effect and summarize what's changed.

We will never weaken our core promises in Section 2 — no sale, no advertising, no AI training, user-initiated sharing, and export and deletion — for information we already hold without your express consent.

18. Contact us

KidKept, Inc. Privacy questions and requests: privacy@kidkept.com Legal questions and legal process: legal@kidkept.com Website: kidkept.com

If you ever feel we've fallen short of these commitments, please tell us. We want to get this right for you and your children.