Legal

Children's Privacy Statement

How WakeKids handles child data, parental consent, parent controls, and child privacy protections.

Last updated: August 4, 2026

Effective date: August 4, 2026

Our approach

WakeKids is designed around a narrow principle: the parent is in control, and the child is a recipient of routine wake-up alarms rather than a tracked subject.

We collect only the information needed to prepare a short-lived pairing request, connect the devices after the parent authorizes pairing, deliver alarms, show the correct family identity, and protect the service from abuse.

WakeKids is operated by SOFTWARECARAFT SRL. Registered office: Calea Rahovei no. 303, building 66, entrance 1, apartment 42, Sector 5, Bucharest, Romania. Fiscal Code: 51542766. Registration: J2025022901007. EUID: ROONRC.J2025022901007. Email: softwarecaraft@gmail.com. Telephone: +40 766 239 722.

The child experience

The child does not create a conventional account and does not sign in with an email and password. The child device requests an anonymous, short-lived pairing session. A random technical Firebase identity scoped to that pairing is created by our backend only after the parent authorizes the connection, and only then can the device receive alarms.

The child app may show the nickname chosen by the parent, the next scheduled alarm, the connected parent identity, a full-screen alarm when one fires, and settings for theme, notification permissions, and legal information.

The paired-child Settings screen provides a confirmed disconnect control. The authenticated parent can also disconnect the pair, and a parent or child can contact us for deletion support.

WakeKids does not provide public profiles, messaging, social posting, content feeds, behavioral recommendations, or advertising surfaces for children.

Parental authorization and control

Pairing records affirmative authorization by an authenticated parent or legal guardian. The parent first verifies control of the parent-account email, scans the QR code shown on the child phone or enters its six-character code manually, reads the complete on-screen notice listing exactly what will be stored about the child device, including the random technical Firebase identity created after authorization, checks the explicit authority confirmation, and actively connects the device. The pair record stores the authorization method, accepted notice protocol version, notice language (en-EN or fr-FR), and server timestamp associated with that action.

Camera frames used to scan the QR code are processed only on the parent device to read the code; they are not stored or uploaded. Scanning alone does not complete pairing.

Before the parent authorizes the connection, the child device sends no name, year of birth, hardware identifier, push token or Firebase identity. The pairing session holds only a random six-character code, the hash of a separate secret held on the child device, and its creation and expiry times. The code expires after 15 minutes.

Pairing authorization and the ongoing controls are managed entirely in the app. An authenticated account and authorization record do not independently prove the person's identity or legal relationship to the child. On August 4, 2026, the operator confirmed that qualified legal counsel approved this exclusively in-app consent, direct-notice, and parent-control flow for the intended launch configuration.

In the app, Review stored data shows a summary and up to 20 recent wake-up records. The parent can disconnect a child device from Child Detail, remove alarms, and use Settings → Privacy → Delete account. The paired-child Settings screen also provides a confirmed Disconnect control. By website form or email request, the parent can ask for a full data export, deletion support, correction, restriction, objection, or other privacy help that cannot be completed in the app.

If a child device was paired without proper authority, contact softwarecaraft@gmail.com so we can review and delete the relevant data where appropriate.

Child data we collect

We collect a nickname, chosen and entered by the parent, so the parent can recognize the paired child and the child can recognize the wake-up screen. We ask parents to use a nickname rather than a full name.

We do not collect a child's year of birth, date of birth or age, and we do not perform automated age assurance. We process a device push notification token as personal technical data so alarms can ring on the child phone.

We do not collect any hardware device identifier from the child phone. The child's technical Firebase identity is a random value generated by our backend after the parent authorizes the connection, and it is scoped to that single pairing. We also process alarm schedules, whether the wake screen was acknowledged, pairing status, and authorization records related to the child device.

The child profile, pairing information, and alarm activity are not sent to RevenueCat. RevenueCat is configured only for the authenticated parent account.

Child data we do not collect

We do not collect child location, GPS, Wi-Fi location, contacts, calendar, photos, microphone content, camera content, other installed apps, app usage outside WakeKids, screen time, web browsing, search history, advertising identifiers, biometric data, voice recordings, or behavioral profiles.

We do not sell child data, rent child data, use child data for advertising, or share child data for third-party marketing or profiling.

Retention and deletion

Child profiles and pair records are kept until the parent or child disconnects the pair, the parent deletes the account, or a verified deletion request is completed.

Alarm events are intended to be kept for no more than 180 days and are deleted earlier when the relevant pair or account is removed. Production TTL must be enabled and verified before automatic expiry is treated as operational.

Pairing tokens cannot be used after 15 minutes and are intended to be removed by expiry cleanup after production TTL is enabled and verified. Deletion requests may take time to propagate through active systems and provider backups, as described in the Privacy Policy.

Disconnecting from either device or deleting the parent account immediately blocks the pairing and starts removal of active pair, alarm, and event records. The child's pairing-scoped Firebase Authentication identity is disabled and its refresh tokens are revoked immediately; final deletion follows a two-hour custom-token safety window and is retried automatically if cleanup is interrupted.

Parent review and deletion rights

Parents can use Review stored data in the app to see a summary of paired-child information and up to 20 recent wake-up records. This screen is not a complete export.

In the app, parents can disconnect a child device, remove alarms, and use Settings → Privacy → Delete account. The paired-child Settings screen also provides a confirmed Disconnect control. These controls withdraw authorization for future child data processing tied to the removed pairing or account.

By website form or email request, parents can ask for access, correction, a full export, deletion support, restriction, objection, and other privacy help that cannot be completed in the app. The website deletion form remains a fallback. Contact softwarecaraft@gmail.com. We aim to respond within 30 days, or sooner where required by law.

COPPA summary for United States users

COPPA may require direct notice and verifiable parental consent before personal information is collected from a child under 13. WakeKids presents the complete child-data notice directly in the authenticated parent app before pairing; requires a verified parent-account email and explicit authority confirmation; and records the authorization method, protocol version, notice language, and server timestamp.

Information about a child is used solely to operate the alarm service and may be processed by the necessary service providers described in the Privacy Policy. It is never sold or shared for advertising, marketing, or profiling. WakeKids contains no advertising and no advertising SDKs, and the child role sends no analytics.

The in-app authorization record does not independently verify the adult's identity or legal relationship to the child. On August 4, 2026, the operator confirmed that qualified legal counsel approved the exclusively in-app consent, direct-notice, and parent-control flow described above for the intended launch configuration.

WakeKids is designed to collect only information reasonably necessary to provide the wake-up alarm service, not condition child participation on unnecessary disclosure, provide no public disclosure surface, and let parents review, delete, and refuse further collection of child data.

UK Children's Code summary

For users in the United Kingdom, WakeKids is designed to align with Children's Code principles for a narrow routine wake-up function.

Our approach emphasizes data minimization, privacy-protective defaults, plain-language transparency, no profiling, no advertising, and no detrimental use of child data. Paired-child settings expose legal information, notification-permission status, an offline child-readable privacy summary, and a confirmed disconnect control.

This design statement does not replace a documented best-interests assessment, age-assurance analysis, or data-protection impact assessment.

Contact

For questions, parental requests, privacy requests, or complaints relating to a child's data, contact SOFTWARECARAFT SRL at softwarecaraft@gmail.com or +40 766 239 722. Registered office: Calea Rahovei no. 303, building 66, entrance 1, apartment 42, Sector 5, Bucharest, Romania.

You may also contact your national supervisory authority, such as ANSPDCP in Romania, the ICO in the United Kingdom, or the FTC or your state Attorney General for COPPA-related matters in the United States.