Privacy Policy
Effective Date: [TO BE SET UPON LEGAL REVIEW]
1. Introduction
Welcome to KidsSafeWeb. We are committed to protecting the privacy of our users, particularly children. KidsSafeWeb is a closed-loop, ad-free, and tracker-free social and communication portal designed specifically for children aged 6 to 13.
Our platform operates under strict parental supervision. Children can only communicate with contacts approved by their parent or legal guardian. This Privacy Policy explains our collection, usage, disclosure, and security practices in compliance with the Children's Online Privacy Protection Act (COPPA).
2. Information We Collect
To provide a secure and functioning environment, we collect a limited amount of personal information. We do not sell this data or use it for behavioral profiling.
A. From Parents / Guardians:
- Email Address: Used for account creation, password recovery, and parental notifications (such as activity digests or approval requests).
- Digital Signature (Full Legal Name): Captured to confirm Verifiable Parental Consent (VPC) before creating child profiles.
- IP Address & Timestamp: Logged at the time of VPC signing to maintain legally required records under COPPA guidelines.
- Password: Stored securely as a cryptographically salted bcrypt hash. We cannot read your raw password.
B. From Child Users:
- Username: A unique display name chosen for login and profile visibility. Real names are not required or collected for children.
- Age (Years): Collected to determine the appropriate security tier: Explorer (6–9) or Adventurer (10–13).
- Profile Settings: Choices such as preset avatar selections (no custom child photos are allowed as avatar icons).
- User-Generated Content: Messages sent via the internal safe email system, chat logs from instant messaging, blog/vlog posts (Adventurer tier only), photos uploaded to their private gallery, and files saved in their locker.
- Connection Data: Approved list associations mapping which children are authorized to correspond with each other.
3. How We Use Information
We use the information we collect strictly to operate the KidsSafeWeb platform. Specifically:
- To deliver safe emails and instant messages between approved contacts.
- To display user-generated posts and photos on the child's profile wall to approved friends.
- To display moderation feeds, activity logs, and settings parameters within the Parent Dashboard.
- To notify parents via email of flagged messages or new friend requests requiring review.
We enforce a zero-advertising policy. We do not track users across the web, we do not use advertising cookies, and we do not disclose child information to third parties except when legally required.
4. Parental Rights & Data Control
As a parent or guardian, you have full authority over your child's data under COPPA:
- You can review all emails, chat transcripts, wall posts, photos, and files created by your child.
- You can revoke contact approvals or modify feature permissions (like disabling blog access) at any time.
- You can delete your family account, child profiles, and all associated messages and files permanently from our servers.
5. Security and Data Protection Standards
We take the security of child and family data very seriously. We implement robust, industry-standard administrative, physical, and technical safeguards designed to protect personal information from unauthorized access, loss, misuse, or alteration:
- Transport Encryption: All data sent between your browser and our servers is encrypted in transit using industry-standard Secure Sockets Layer (SSL) or Transport Layer Security (TLS) technology.
- Cryptographic Password Hashing: Passwords are never stored in cleartext. We use secure, one-way cryptographic hashing algorithms to verify credentials, meaning your raw password is never accessible to our staff or anyone else.
- Access Controls & Authentication Gating: User-generated content, photos, and files are stored in secure directories. Access to these resources requires active authentication, ensuring that only verified family members and approved contact pairs can access child data.
- Server Firewalls & Network Isolation: Our hosting systems are protected by firewalls and security rules to restrict database access, shield the network from external vulnerabilities, and strictly prevent unauthorized entry.
- Data Deletion & Retention: Deleted files and accounts are systematically and permanently purged from server storage during routine cleanup cycles to minimize the amount of data we retain.
6. Contact Us
If you have any questions or concerns regarding this Privacy Policy or our security practices, please contact our Privacy Team at:
KidsSafeWeb Privacy & Safety Team
Email: privacy@kidssafeweb.com