Privacy Policy

Last updated: 11 September 2026

kudo.kids is a family-supervised habit tracker. This page explains what data we collect, why we collect it, how we use it, and your rights to delete it.

Who runs the service

kudo.kids is operated by Vijay Jonnakuti (VERA Technologies). Questions, requests to delete data, or other privacy enquiries: vera@veratech.dev.

Who can use kudo.kids

kudo.kids is designed to be set up and supervised by an adult (the guardian). Children under 13 (or the equivalent age of digital consent in your jurisdiction) may use the kid-facing screens, but only with their guardian's account and consent. Kid profiles are created, edited, and deleted by the guardian. Children do not register, provide an email address, or receive any communication from us. They can, however, enter content themselves inside the app — journal notes, and optional proof photos — which is stored under their guardian's account and is visible to that guardian.

What we collect

We collect the minimum data required for the app to function. We do not run advertising, do not embed third-party trackers, and do not sell data.

CategoryWhat's collectedPurposeWhere it lives
Sign-in identityEmail address, display name, profile picture (Google) or name fragments (Apple, first sign-in only)Authenticate the guardian; identify the family's data partitionAWS DynamoDB (us-west-1), encrypted at rest
Provider stable identifierThe opaque Google or Apple per-user ID (sub)Bind data to the user even if their email changesAWS DynamoDB
Kid profile dataKid first name, age, avatar emoji, optional PIN (stored as a salted SHA-256 hash, never plaintext)Display the kid's tasks; gate kid login on shared devicesAWS DynamoDB
Tasks and completionsTask titles, categories, schedules, completion timestamps, kudos values, guardian feedbackRun the app's core functionalityAWS DynamoDB
Proof media (photos / videos)Photos or short videos a kid voluntarily attaches to a completed taskShow the guardian what was done; display in the timelineAWS S3 (us-west-1), encrypted at rest with a customer-managed AWS KMS key (SSE-KMS). Auto-deleted after 180 days.
Journal notesShort free-text notes a kid writes about what they did or learned (up to 500 characters each, up to 20 a day)Let a kid keep their own record; show it to them and their guardiansAWS DynamoDB (us-west-1), encrypted at rest. Never sent to any third party.
Feedback messagesAny free-text feedback the user voluntarily submits via the in-app feedback formBug fixes and feature requestsAWS DynamoDB; optionally mirrored to a private issue tracker
Local device storageA copy of the family's data, the active sign-in token, and a small auth bootstrap mapOffline support and faster app launchOn-device (browser storage / iOS-Android secure preferences)

We do not collect: device contacts, location, microphone, biometric data, IP address logs (beyond what AWS naturally records for security), or anything else not listed above.

How long we keep it

How data flows between you and us

How we protect your data

Children's data

kudo.kids stores kid profile data (first name, age, avatar, optional PIN, tasks, completions, proof photos) that the guardian creates and manages, and journal notes that the child writes themselves. Those notes are free text, so a guardian should be aware their child may record anything in them; they are visible to every guardian on that child's account and are never shared outside it. The app is listed as a general-audience family / productivity app — not in Apple's Kids Category and not in Google's Designed for Families programme. Guardians are responsible for deciding which information about their child is appropriate to add to the app.

If you are a parent and want a child's data removed, email vera@veratech.dev with the kid's name and your account email. We will remove the requested data within 7 days.

Sign in with Apple — private email relay

If you sign in with Apple and choose "Hide My Email", Apple gives us a private relay address ending in @privaterelay.appleid.com. We treat that as your email address; mail we send to it is forwarded by Apple to your real inbox. You can revoke the relay at any time from your Apple ID settings → Sign in with Apple → Apps Using Apple ID.

Your rights

Changes

We will update this page when we change what data we collect or how we use it. The "Last updated" date at the top tracks the latest change.

Contact

vera@veratech.dev