Privacy Policy — Chat for Kids
Last updated: 2026-07-26 · Effective date: 2026-07-26
Chat for Kids ("the app", "we", "us") is a child-safe messaging app
built for families. This policy explains what data we collect,
how we use it, and the choices you have. It is written to
comply with GDPR, GDPR-K,
and COPPA requirements for services
directed at children.
Short version: We collect the minimum data needed
to run a family chat app. Messages are end-to-end encrypted.
Parents have full control over their child's account. We do not
sell data. We do not use behavioural advertising. Contact us
anytime to delete everything.
1. Who is the data controller?
Stelios Vouzonikos, operating as NXT, is the data controller
for Chat for Kids. Contact:
[email protected].
2. Who can use the app?
Parents must be at least 18 years old to create an account. Children
use the app only under a parent-linked profile set up by that parent.
The parent consents to the processing described below on the child's
behalf, as required by GDPR-K (EU 16+ / country-specific) and COPPA
(US under 13).
3. What we collect
3.1 Account data
-
Parent: email address, display name, avatar,
date of birth (used once to verify 18+, not retained as the raw
date; only the "verified 18+" fact is retained), hashed PIN, FCM
push notification token, X25519 identity public key.
-
Child: first name, avatar, age, hashed PIN, FCM
token, X25519 identity public key, link to their parent account.
Children do not provide an email address.
3.2 Message data
-
Text and voice messages sent within the app. These are
end-to-end encrypted on the sender's device
and decrypted only on the recipient's device — we cannot read
them, and neither can anyone with access to our servers.
-
Message metadata: sender ID, receiver ID, chat ID, timestamp,
message type (text / photo / sticker / voice / missed call),
reactions, the ephemeral public key used for forward secrecy.
Metadata is not encrypted because the server needs it to route
and deliver messages.
-
Photos and videos uploaded to Memories or shared in chat. These
are encrypted before upload.
3.3 Technical data
- App version, device type, OS version, IP address of the
request (retained in our server logs for fraud prevention,
rotated out automatically within 30 days).
- WebRTC signalling data for voice/video calls (session
descriptors, ICE candidates) — encrypted in transit, deleted
when the call ends.
- Approximate location if — and only if — the parent has
explicitly enabled "Share location with parent" for the child.
See §7.
3.4 Advertising
Non-personalised ads are served by Google AdMob inside the app.
We do not collect any advertising identifier (IDFA / GAID) from
children. AdMob operates under COPPA-compliant
tagForChildDirectedTreatment and GDPR-K
tagForUnderAgeOfConsent flags. A GDPR consent dialog
is shown to EU users before any ad loads.
4. What we do with it
- Authenticate users.
- Deliver messages, calls and notifications.
- Enforce parental controls (time limits, feature toggles, chat
monitoring).
- Prevent abuse (rate limiting, PIN brute-force protection, basic
moderation of flagged content).
- Serve non-personalised ads as described above.
We do not: sell data, run behavioural ad profiling,
share contacts, or use data for marketing outside the app.
5. Legal basis (GDPR)
- Parent consent for processing their child's
data, obtained at sign-up (Art. 6(1)(a) + Art. 8 GDPR).
- Contract with the parent for providing the
service (Art. 6(1)(b) GDPR).
- Legitimate interest in security, abuse
prevention and service reliability (Art. 6(1)(f) GDPR).
6. Sharing with third parties
Processors we use:
- Our own servers in the European Union —
accounts, encrypted messages and encrypted media are stored on
infrastructure we operate ourselves (a self-hosted open-source
Supabase stack); no third-party cloud database holds your data.
- Google Firebase Cloud Messaging — push
notification delivery only.
- Google AdMob for non-personalised ads (parent
dashboard only).
- Self-hosted LiveKit and TURN relay for voice
and video calls — also operated by us, no third party.
We do not share data with advertisers, analytics providers outside
Google, social networks, or data brokers.
7. Location sharing
Location is opt-in and controlled by the parent,
not the child. When enabled, the child's device sends an approximate
location every few minutes to the parent's account. The parent can
disable it at any time and past coordinates are deleted within 30
days. Precise GPS is requested only at the moment the parent turns
the feature on.
8. Security
- End-to-end encryption for 1-on-1 messages
(per-message ephemeral X25519 keys for forward secrecy).
- End-to-end encryption for group chats (per-member sealed chat
key, rotated when someone leaves).
- PINs are hashed with PBKDF2-SHA256 at 600,000 iterations with a
per-user random salt.
- Rate limiting and lockout on repeated bad PINs.
- Database row-level security enforces per-user access; the
server cannot decrypt chat contents.
- A web-application firewall and strict transport security guard
the server edge.
9. Retention
- Account data is kept while the account is active.
- Messages remain until the sender deletes them or the chat is
deleted.
- Call signalling data is deleted at the end of the call.
- Location coordinates are deleted after 30 days.
- Flagged content (reported for moderation) is retained for up
to 12 months for safety review.
10. Your rights
Under GDPR, parents (acting on behalf of their child) can:
- Access the data we hold about them or their child.
- Correct inaccurate data.
- Delete the account and all associated data ("right to be
forgotten").
- Export a copy of the data.
- Object to or restrict processing.
- Lodge a complaint with their national data-protection
authority (for Cyprus: Office of the Commissioner for Personal
Data Protection,
www.dataprotection.gov.cy).
Account deletion is available directly in the app: sign in as the
parent, open the Dashboard tab and tap
Delete my account. It permanently removes the parent
account, every child profile, and all associated data. See
Delete Your
Account for details.
To exercise any of these rights, email
[email protected] from the email
address on the account. We respond within 30 days.
11. Children's data (COPPA)
Children do not provide contact information directly. The parent
creates the child's account and consents to processing. Children
cannot share their real-world identifying information publicly —
there are no public profiles and the app has no open search.
Parents can review, delete or modify their child's data at any
time from the Family Safety screen inside the app, or by emailing
[email protected].
12. International transfers
Account data, messages and media are stored on our own servers in
the European Union. Push notification delivery (Firebase Cloud
Messaging) and ad serving (AdMob) may route through Google's global
infrastructure, which transfers data under the EU-U.S. Data Privacy
Framework and Google's Standard Contractual Clauses.
13. Changes to this policy
Material changes are announced in the app at least 14 days before
they take effect. The "Last updated" date at the top of this page
reflects the most recent change.
14. Contact
Data-protection questions, rights requests, security reports:
[email protected]