Privacy Policy — Chat for Kids

Last updated: 2026-07-26 · Effective date: 2026-07-26

Chat for Kids ("the app", "we", "us") is a child-safe messaging app built for families. This policy explains what data we collect, how we use it, and the choices you have. It is written to comply with GDPR, GDPR-K, and COPPA requirements for services directed at children.

Short version: We collect the minimum data needed to run a family chat app. Messages are end-to-end encrypted. Parents have full control over their child's account. We do not sell data. We do not use behavioural advertising. Contact us anytime to delete everything.

1. Who is the data controller?

Stelios Vouzonikos, operating as NXT, is the data controller for Chat for Kids. Contact: [email protected].

2. Who can use the app?

Parents must be at least 18 years old to create an account. Children use the app only under a parent-linked profile set up by that parent. The parent consents to the processing described below on the child's behalf, as required by GDPR-K (EU 16+ / country-specific) and COPPA (US under 13).

3. What we collect

3.1 Account data

3.2 Message data

3.3 Technical data

3.4 Advertising

Non-personalised ads are served by Google AdMob inside the app. We do not collect any advertising identifier (IDFA / GAID) from children. AdMob operates under COPPA-compliant tagForChildDirectedTreatment and GDPR-K tagForUnderAgeOfConsent flags. A GDPR consent dialog is shown to EU users before any ad loads.

4. What we do with it

We do not: sell data, run behavioural ad profiling, share contacts, or use data for marketing outside the app.

5. Legal basis (GDPR)

6. Sharing with third parties

Processors we use:

We do not share data with advertisers, analytics providers outside Google, social networks, or data brokers.

7. Location sharing

Location is opt-in and controlled by the parent, not the child. When enabled, the child's device sends an approximate location every few minutes to the parent's account. The parent can disable it at any time and past coordinates are deleted within 30 days. Precise GPS is requested only at the moment the parent turns the feature on.

8. Security

9. Retention

10. Your rights

Under GDPR, parents (acting on behalf of their child) can:

Account deletion is available directly in the app: sign in as the parent, open the Dashboard tab and tap Delete my account. It permanently removes the parent account, every child profile, and all associated data. See Delete Your Account for details.

To exercise any of these rights, email [email protected] from the email address on the account. We respond within 30 days.

11. Children's data (COPPA)

Children do not provide contact information directly. The parent creates the child's account and consents to processing. Children cannot share their real-world identifying information publicly — there are no public profiles and the app has no open search.

Parents can review, delete or modify their child's data at any time from the Family Safety screen inside the app, or by emailing [email protected].

12. International transfers

Account data, messages and media are stored on our own servers in the European Union. Push notification delivery (Firebase Cloud Messaging) and ad serving (AdMob) may route through Google's global infrastructure, which transfers data under the EU-U.S. Data Privacy Framework and Google's Standard Contractual Clauses.

13. Changes to this policy

Material changes are announced in the app at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent change.

14. Contact

Data-protection questions, rights requests, security reports:
[email protected]