Privacy Policy
Last updated: 19 July 2026
KiddieBase ("we", "us") provides a daycare management app for childcare providers (home daycares, childminders, nannies) and the guardians they invite. This policy explains what we collect, why, and your choices. We do not sell your data, we do not run ads, and we do not use third-party advertising trackers.
Who controls the data
The childcare provider is the controller of the children's and guardians' data they enter; KiddieBase is the processor acting on their instructions. For provider account data, KiddieBase is the controller.
What we collect
- Account: name, email, role (owner/staff/guardian).
- Daycare & children: daycare name/type; child name, date of birth, photo, allergies/medical notes, pickup list.
- Activity: photos/videos, quick-action entries (meals, naps, etc.), attendance, messages, invoices (status only).
- Technical: device push token (for notifications), crash diagnostics, minimal in-app usage.
We do not collect precise location and do not collect payment card data (invoices are reminders with a paid/unpaid status).
How we use it
To provide the service: show each child's day to their own guardians, run attendance and invoicing, deliver notifications, keep the app secure, and diagnose crashes. Legal bases (GDPR): performance of contract, legitimate interests (security/diagnostics), and consent (a guardian's explicit consent before a child is visible to them; media processing).
Privacy by design
- Closed circles: staff see the daycare group; each guardian sees only their own child.
- No third-party ad SDKs or trackers. No social-media sharing from the app.
- Encryption: data encrypted in transit (TLS); allergy/medical notes encrypted at the field level; staff-only access to medical notes.
Sub-processors
We use a small number of service providers to run KiddieBase: Firebase (authentication and push notifications) and, optionally, Sentry (crash diagnostics). They process data on our behalf and are not permitted to use it for their own purposes.
Children (COPPA / GDPR-K)
Children do not use KiddieBase. Their information is entered by the provider and/or guardian. A guardian gives explicit consent before their child is visible to them; without consent the child is visible only to daycare staff. We collect the minimum necessary.
Your rights & choices
- Access, export, correct, delete: available in-app (account deletion and data export). Guardians can request removal of their child's content through their provider or us.
- Notifications: optional; the app works without them.
- Retention: we keep data while the account is active and delete it (or return it to the provider) after account closure, subject to legal retention.
Contact
Questions or requests: [email protected]. For EU/UK data requests, use the same address; we respond within statutory timeframes.