Kidder legal information
Data Deletion Policy & Request Information
Complete Parent account deletion is not currently available as a verified live service. This page explains the current account controls, intended deletion scope, and request-channel limitations.
Document contents
1. Current status
Complete Parent account deletion is not currently available as a verified live service. Kidder will not describe a request as completed until the required account and identity removal has succeeded.
Emailing the privacy address does not automatically delete an account. Kidder must verify the requester’s identity and provide a clear request acknowledgement and completion outcome before this can serve as a complete outside-the-app deletion path.
2. Current account actions
- Available controls can include removing optional Parent and Child profile photos, deleting eligible Child profiles, unlinking a child device, ending Parent sessions, and logging out.
- Complete Parent account deletion is not represented as currently available or complete.
- An email request by itself does not prove identity or confirm deletion.
3. What device unlinking does
An authenticated device-removal signal causes the Child App to stop device-scoped work and clear its token, account preferences, scheduled work, and device-scoped local records. Reusable public catalogues may remain.
Unlinking is not the same as deleting the family account. Limited device-removal, security, location, usage, web, Content Safety, or related records may remain under the applicable retention terms.
4. Complete account deletion requirements
A complete in-app request will require a clear destructive confirmation in Parent App Account settings. A request made outside the app will require separate identity verification; requesters should never send a password, authentication code, or unnecessary child information.
Once a valid request is accepted, account access and connected-device authorization should be revoked promptly. Temporary failures must remain visible as pending or failed, and completion must wait until required account data and every recorded Kidder sign-in identity have been removed. The request must not wait indefinitely for an offline child device.
5. Deletion scope
Complete account deletion addresses Parent personal information, Kidder and Firebase authentication linkage, Child profiles and devices, photos, push tokens, sessions, pairing, rules, app inventory, usage, location, derived location, web and Content Safety events, notifications, commands, and current entitlement state.
The process removes the Kidder-linked Firebase identity without deleting the user’s separate Google Account. Ordinary family product data is erased, while protected security, legal, accounting, and backup records may follow the limited retention boundary below.
6. Information that may require retention or de-identification
For a completed deletion request, authentication and security events may be retained for up to 90 days from each event, and the protected device-removal record for up to 90 days. A one-way revoked-device marker may remain so a removed installation stays denied and can clear local data after reconnecting; its final retention period remains pending.
Protected backups and administrative security records follow separate access and retention controls. Consent and genuine subscription, payment, tax, or accounting records will be retained only where required; final legal or accounting periods remain subject to confirmation. Pseudonymous identifiers are not automatically anonymous.
7. Kidder sign-in and Google Account
Kidder can use email/password, phone, and Google sign-in for Parent authentication. A complete Kidder deletion request is intended to remove every recorded Kidder sign-in identity without deleting the user’s separate Google Account.
If identity removal cannot be confirmed, the request must not be described as completed.
8. Backups and service-provider copies
Protected backup copies do not require unsafe immediate removal if they are secured, age out through the normal backup lifecycle, and are not restored into an active deleted account. The exact backup window remains subject to service-provider and legal confirmation.
9. Request-channel safety
Only the centralized approved privacy address is published for privacy and deletion requests. Requesters should not include passwords, authentication codes, or unnecessary child information.