Privacy Policy
Last updated: July 10, 2026
kind365 (“we,” “us,” or “the Service”) is a daily kindness habit app for families, children, and education communities. We operate from Colorado, United States. This Privacy Policy explains what information we collect, how we use it, how we protect children, and the choices you have.
1. Who We Are & Scope
This Policy applies to the kind365 mobile apps (iOS and Android), web and desktop clients, and related sites and portals we operate (including family/education/ business/church features), unless a product shows a different policy.
Controller: kind365, operated by the individual or organization publishing the app (Colorado, USA). For privacy requests: privacy@kind365.app.
2. Audience: Families, Kids & Education
kind365 is designed for families and education, including use by children under parental supervision. Adult users may create and manage child accounts (username + PIN; no email required for the child). Teachers and schools may use class codes and education portals to support classroom kindness habits.
If you are a parent, guardian, or school official, you are responsible for ensuring that use of kind365 with children complies with your school’s policies and applicable law (including obtaining any consents your school requires).
3. Information We Collect
3.1 Account information (adult / parent / teacher / leader accounts)
When you create an account, we collect information you provide through our authentication provider (Firebase Authentication), which may include:
- Email address and/or phone number
- Display name
- Password credentials (handled by Firebase; we do not store raw passwords)
- Optional public username (if you claim one)
- Optional community links (company, class, or church codes)
3.2 Child accounts (parent-managed)
A parent or guardian who is signed in may create a child account. For child accounts we store:
- Display name chosen by the parent
- Username (for kid sign-in; uniqueness index)
- PIN credential (stored as a salted hash-not in plain text)
- Parent/family owner association
- The child’s kindness activity (acts, streak-related data) on that account
Child accounts do not require an email address. Parents can change usernames, reset PINs, remove a child from their family list, or convert a child account to an adult account (with email/password) when appropriate.
3.3 Kindness & app activity data
We store activity needed to run the product, associated with the signed-in account, including: completed or skipped kindness days, streak and repair usage, streak pauses, referral codes and referral outcomes, reminder schedules, settings (theme, accent, accessibility, sounds, ads opt-in for adults), charity votes (adults), community memberships, friends lists, and optional group “sprint” participation. Timezone may be stored so reminders land on the right local day.
3.4 Push notification tokens
If reminders are enabled, we store a device messaging token (e.g., via Firebase Cloud Messaging) to deliver notifications you request. You can disable notifications in the app or system settings.
3.5 Analytics & diagnostics
We use Google Analytics for Firebase and similar tools to understand product usage and fix bugs (e.g., GlitchTip/Sentry error reporting). Events are designed to avoid names, emails, and other direct identifiers. Examples of event types: act completed, reminder set, streak milestone. We use this to improve the Service.
3.6 Purchases (adult accounts only)
Optional in-app purchases (such as streak repair packs or Kindness Sustainer subscriptions) are processed by Apple or Google. We may store purchase status and verification metadata needed to unlock features. We do not receive full payment card numbers.
3.7 Advertising data (adult opt-in only; never for Kids Mode)
Ads are off by default. If-and only if-an adult enables Ads for Charity, we may show banner ads via Google AdMob. AdMob may process device and ad-related information as described in Google’s policies. Net ad proceeds beyond basic operating costs are intended for charity. Child profiles / Kids Mode do not show ads and should not enable Ads for Charity.
3.8 Information we do not intentionally collect from children
We do not require children to provide an email address, phone number, or precise geolocation to use a parent-created child account. We do not sell children’s personal information. We do not use children’s data for behavioral advertising.
4. How We Use Information
- Provide, sync, and secure the Service across devices
- Enable streaks, reminders, communities, education/class features, and family profile switching
- Allow parents to manage child accounts
- Operate optional adult features (charity voting, ads opt-in, IAP)
- Improve reliability and understand aggregate product usage
- Comply with law and protect safety, security, and integrity of the Service
5. How We Share Information
We do not sell personal information and we do not share it for cross-context behavioral advertising of children.
We share information only as needed with:
| Recipient | Purpose | More info |
|---|---|---|
| Google Firebase (Auth, Firestore, Cloud Messaging, Functions) | Accounts, data storage/sync, notifications, backend logic | Firebase privacy |
| Google Analytics for Firebase | Aggregated usage analytics | Google Privacy Policy |
| Error monitoring (e.g., Sentry/GlitchTip) | Crash and error diagnostics | See vendor policy linked in app configuration |
| Google AdMob (adults who opt in only) | Serve optional charity-supporting ads | AdMob & privacy |
| Apple / Google (IAP) | Process adult in-app purchases/subscriptions | Apple / Google payment terms |
Other users: If an adult claims a public username, that username and related public profile metrics (such as streak or total acts) may be visible to other users (e.g., friends leaderboards). Child accounts are not intended to self-serve public usernames; parents control child identity settings.
We may disclose information if required by law, legal process, or to protect rights, safety, and security.
6. Children’s Privacy (COPPA & Similar Laws)
In the United States, the Children’s Online Privacy Protection Act (COPPA) applies to operators of online services directed to children under 13, and to operators that knowingly collect personal information from children under 13.
kind365 supports children’s use primarily through parent-managed child accounts. By creating a child account, the parent or guardian:
- Represents that they are the child’s parent or legal guardian (or have authority to consent)
- Consents to collection and use of the child’s information as described in this Policy
- Agrees to supervise the child’s use of the Service
What parents can do: review or delete a child’s account data by managing or removing the child in Settings → Family, converting the account, or contacting us; disable notifications on the device; and prevent use of adult-only features (ads and paid items are not offered in Kids Mode).
Advertising to children: We do not serve Ads for Charity in Kids Mode / child profiles. Adult ads, when enabled, are not intended for children.
Schools: If a school or teacher facilitates student use (e.g., class codes), the school may have additional obligations under FERPA or state student privacy laws. kind365 is a tool for kindness habits; schools should only use student data consistent with their policies and notices to parents.
If you believe we have collected a child’s information without proper consent, contact privacy@kind365.app and we will investigate and delete as appropriate.
7. Colorado Privacy Rights (Colorado Privacy Act)
If you are a Colorado resident, the Colorado Privacy Act (CPA) may provide rights regarding personal data, subject to applicability thresholds and exceptions. Without limiting other rights, Colorado residents may have the right to:
- Access personal data we process about you
- Correct inaccuracies
- Delete personal data
- Data portability of certain data you provided
- Opt out of sale of personal data, targeted advertising, or certain profiling (we do not sell personal data; adult ads are opt-in only)
To exercise rights, email privacy@kind365.app with the subject “Colorado Privacy Request,” describe the request, and provide enough information for us to verify your identity and account. You may use an authorized agent as permitted by law. We will respond within the timeframes required by the CPA.
Colorado residents may appeal a denial by replying to our decision email with “Privacy Appeal.” If unresolved, you may contact the Colorado Attorney General.
8. Other U.S. State & International Rights
Depending on where you live (e.g., California CCPA/CPRA, Virginia, EU/UK GDPR), you may have additional rights to access, delete, correct, or restrict processing, or to object/opt out of certain uses. Contact us to exercise applicable rights. EU/UK users who enable adult ads will be presented with consent tooling where required before personalized advertising.
9. Your Choices
- Notifications: off in app or system settings
- Ads (adults): Ads for Charity off by default; toggle in Settings
- Child accounts: parent can edit, remove, or convert in Family settings
- Public username: optional for eligible accounts; choose carefully
- Account deletion: request via delete-account page, in-app where available, or email
10. Data Retention
We retain account and kindness data while the account is active and as needed to provide the Service. After deletion requests, we remove data from active systems within a reasonable period, subject to legal retention, backup cycles, and security logs. Child data is retained under the parent’s family relationship until removed or converted.
11. Security
Data is stored on reputable cloud infrastructure (including Google Firebase) and transmitted over encrypted connections (HTTPS/TLS). PINs for child accounts are stored hashed. No method of transmission or storage is 100% secure; we use reasonable administrative and technical safeguards appropriate to the Service.
12. International Transfers
We are based in the United States. If you use kind365 from another country, your information may be processed in the U.S. and other locations where our providers operate, which may have different data protection laws than your country.
13. Changes to This Policy
We may update this Policy from time to time. We will revise the “Last updated” date above. Material changes may be communicated in the app or on our website. Continued use after the effective date means you acknowledge the updated Policy, except where consent is required by law.
14. Contact
Privacy questions or requests:
Email: privacy@kind365.app
General: contact@kind365.app
Location: Colorado, United States
This Policy is provided for transparency and product compliance preparation. It is not legal advice. Operators should have qualified counsel review children’s privacy, education, and state privacy compliance before relying on this document in regulated contexts.