Kera helps households organise their shopping. A parent or guardian can add their child to their household with a child profile, so the child can ask for things they need, such as school supplies, snacks or birthday wishes. Adults decide what gets bought.
This notice explains what we collect from and about a child who uses Kera through a child profile, what we do with it, and what you can do as their parent or guardian. It covers every child under 18 with a child profile. For a child under 13 it is the notice the US Children’s Online Privacy Protection Act (COPPA) requires. It is part of our Privacy Policy.
1. Who we are and how to reach us
Kera is operated by SPIN LLC, a limited liability company registered in Georgia (company ID 405173191).
- Address: Ana Politkovskaia Street 22a, Floor 10, Apt 140, Vake District, Tbilisi 0186, Georgia
- Email: hello@spin.ge (subject line “Child privacy”)
- Phone: +1 908 742 4951
- In the app: House tab → Children → your child → Privacy & controls
SPIN LLC is the only operator that collects or keeps children’s information through Kera.
2. How a child comes to use Kera
- Children cannot sign up on their own. Everyone who creates their own Kera account must be 18 or older. When someone signs up, we ask for their birth month and year without saying which answer is needed, and we may also check the age on their Google or Apple account. We don’t keep the birth month or year, only that the person confirmed they’re an adult.
- A parent or legal guardian who is an adult member of a Kera household can create a child profile for their own child. They must confirm they are the child’s parent or legal guardian and must have confirmed the email address on their Kera account. Before the profile exists, we ask for your consent and check that it comes from you (section 7).
- The child profile has no email address, no phone number and no password. You choose a first name or nickname for your child. To sign your child in on their device, you create a one-time code (or QR code) that works for 10 minutes; your child enters it and chooses a PIN of 4 to 6 digits. A new device always needs a new code from you. After 5 wrong PINs, the profile is locked for 15 minutes.
- A child profile can’t be used to create or join a household or to invite anyone.
3. What we collect
From you, the parent, when you create the profile:
- your child’s first name or nickname (it doesn’t have to be their real name);
- your child’s age band: under 13, 13–15 or 16–17. We never ask for your child’s date of birth;
- which optional features your child may use (section 5);
- a record of your consent (section 7).
From your child, as they use Kera:
| What | Example | When |
|---|---|---|
| Sign-in details | a PIN (stored only in scrambled, hashed form), and for each device they sign in on, a random device token and the device’s name (such as “Pixel 7”), which you see in Privacy & controls | Always |
| Requests | item names, quantities and notes such as “the blue one” | Always (this is what a child profile is for) |
| Comments and reactions | a comment on a request, or an emoji | Always |
| Shopping preferences | a note they add, such as “I don’t like mushrooms” | If they add one |
| Rewards | a reward a parent set up that your child redeems | If your household uses rewards |
| Reports | a report they send us about content in the household | If they send one |
| Photos | a picture attached to a request, or a picture they upload for an item | On unless you switch it off |
| Voice memos (recordings of your child’s voice) | a spoken note attached to a request | On unless you switch it off |
| Wishlist | items on your child’s wishlist | On unless you switch it off |
| Notifications | a notification token for your child’s device | On unless you switch it off |
| Technical and usage information | device type, app version, when they were last active, error reports, and in-app events such as “added a request”, linked to a random identifier | Always (see below) |
About your child, entered by adults in your household: notes such as allergies or foods to avoid, if an adult chooses to add them, and a gift occasion for your child, such as their birthday. Because allergy and diet notes can be health information, we ask for your separate, explicit agreement before anyone can link such a note to your child (section 7).
What we don’t collect from children: email address, phone number, home address, precise or approximate location, contacts, payment details, government ID, date of birth, or any biometric data such as face or voice prints. We don’t use children’s voices or faces to recognise them.
Technical information and “persistent identifiers.” Like any app, Kera uses a few identifiers to work: a random account id, a session token, a device token for each device your child is signed in on, a notification token if notifications are on, and an error-report id. Under US law these count as personal information. We use them only to support Kera’s internal operations:
- to keep your child signed in;
- to deliver the notifications you allow;
- to keep the service secure and prevent abuse;
- to find and fix errors;
- to understand, in aggregate, how features are used so we can maintain and improve them.
Usage records about a child keep only ids, counts and a few fixed labels (never what your child typed), and are deleted after 90 days. Error reports carry the random account id only, never your child’s name, and no screenshots. We don’t use these identifiers to build a profile of your child, to show them ads, or to track them across other apps or websites. There are no advertising, analytics or attribution tools from other companies in Kera.
Nothing your child posts is public. Your child’s requests, comments, wishes, photos and voice memos can be seen only by members of your household. Please remember that everyone in your household can see them, including adults who aren’t your child’s parents (for example a roommate or relative you invited). Photos and voice memos are stored privately and open only through short-lived links given to signed-in members of your household. Public gift pages never show your child’s wishes, never show an occasion for your child, and never show your child’s name.
4. How we use children’s information
We use it only to run the household features your child takes part in:
- to show your child’s requests and wishes to the adults who approve and buy;
- to let your child comment, react and keep a wishlist;
- to suggest a category for an item your child adds and to spot a duplicate request (section 6);
- to show a picture for an item: from our shared picture catalog, from a shop page your child linked to, or a category icon. We never create an AI-generated picture from something your child adds;
- to deliver the notifications you allow;
- to keep Kera secure, fix errors, meet our legal obligations and respond to your requests.
We never:
- sell or rent children’s information;
- use it for advertising, including behavioural or targeted advertising;
- use it to train or develop artificial intelligence models, or allow our providers to do so;
- make it public;
- ask a child for more information than they need to use a feature, or make a feature depend on it.
AI and search are for adults. Children can’t use Kera’s AI assistant (“Ask Kera”, by text, voice or live call), voice add, snap-to-add photo recognition, meal planning, AI suggestions, web or product search, receipt scanning or gift research. Links your child pastes are read without AI.
Money. Your child doesn’t see the household’s budgets, spending or other money information unless a household Admin chooses to show budgets to children.
A gentler experience. Child profiles see no leaderboards and no weekly challenges, get no badge notifications, and never appear on anyone’s leaderboard. On their first sign-in, your child sees a short explanation that you can see their requests and wishes, and a “Tell a grown-up” help screen is always available.
5. Features you control
When you create the profile, and at any time afterwards in Privacy & controls, you can switch these features on or off for your child. They start on; you can switch any of them off before you give consent:
- Photos on requests and item pictures
- Voice memos on requests
- Notifications on your child’s device
- Wishlist
When you switch a feature off, Kera stops your child adding that kind of information (our servers refuse it, not just the app), and you can delete what was already added. Switching notifications off also forgets your child’s devices for notifications. If notifications are off, Kera sends none to your child’s devices. From the next app update, your child’s device also asks for permission to show notifications only if you leave notifications on.
In Privacy & controls you can also pause the profile (your child is signed out and can’t sign in or add anything until you un-pause it; nothing is deleted), sign out your child’s devices, reset their PIN, and withdraw consent (section 9).
6. Who we share children’s information with
We share children’s information only with service providers that help us run Kera. Each one is bound by a contract. It may use the information only to provide its service to us, must keep it secure, and may not use it for anything else. That includes training AI models, advertising or selling it.
| Service provider | What it does for Kera | Children’s information it handles |
|---|---|---|
| Fly.io (Germany) | Runs Kera’s servers | All children’s information passes through it |
| Neon (Germany) | Database | All stored children’s information |
| Cloudflare (R2 storage) | Stores files privately | Photos and voice memos |
| Vercel | Hosts the web version of Kera | Technical request data when your child uses Kera in a browser |
| Anthropic | AI that suggests a category and spots duplicate requests | Only the item name, with no name or other detail about your child or your household |
| Expo, which passes messages to Apple or Google | Delivers notifications | Your child’s notification token and message text, if notifications are on; notifications to adults in your household can mention your child’s first name |
| Resend | Sends email | Emails to you about your child (consent, confirmation, reminders), which include your child’s first name. We never email your child. |
| Sentry (EU) | Error reports | Random account id and technical error details |
| OpenAI, Anthropic, Google | AI assistant used by adults in your household. When an adult asks the assistant about the household list, it can see the names of things your child asked for and any allergy or diet notes about your child, labelled “a child in the household”. | Item names, and allergy or diet notes, never your child’s name, and never anything your child wrote themselves (notes, comments, wish notes or their own preferences) |
What never reaches any AI, search or image provider: your child’s name, their household handle, their account id, and anything your child wrote themselves. Our search providers (Brave, Shopify) and our picture-generation provider (Replicate) receive nothing from your child’s profile; if an adult’s search or item mentions your child by name, we replace the name first. We check this with an automated test that runs on every change to our code.
We don’t share children’s information with anyone else, including advertisers, data brokers, retailers and other companies’ AI. If that ever changes, we will ask for your separate consent first, and saying no won’t affect your child’s use of Kera.
We may disclose information if the law requires it, for example in response to a valid court order, or to protect the safety of a child or others.
Where the information is stored. Kera’s database and servers are in the European Union (Germany). Some service providers above process information in the United States and other countries, under safeguards described in our Privacy Policy.
7. Your consent, and how we check it is you
Before we create a child profile, we ask for your consent and verify it:
- In the app, you confirm you’re the child’s parent or legal guardian and enter your child’s first name or nickname and age band. We show you a short notice and email the address on your Kera account, which you must have confirmed.
- You open the link in that email while signed in to your Kera account and fill in the consent form. The link works for 72 hours and only for you. We create the profile only when you submit the form.
- At least 24 hours later we send a second email, so the real account holder can stop anything they didn’t approve with one tap.
If you don’t confirm, we don’t create the profile, and we delete the details you entered about your child after 7 days. We don’t collect anything from your child until you have confirmed.
Health notes. On the same form, you can separately agree that adults in your household may record allergy, dietary or similar notes about your child. It is optional, and you can withdraw it at any time in Privacy & controls, which deletes those notes.
What we record. We keep a record of your consent: who gave it and for which child, the version of the form and a fingerprint of its exact wording, the method, the time, the features you chose, whether you agreed to health notes, and technical details of how you confirmed (the email and link used, the signed-in session, your IP address, your browser or app, and your device’s country setting). The record never contains your child’s name.
Where we offer child profiles. We may not offer child profiles in every country. If adding a child isn’t available where you live, the app tells you.
Our legal basis (EU, UK, Georgia and similar laws): your consent as the holder of parental responsibility, and your separate, explicit consent for health notes.
8. How long we keep children’s information
We keep it only as long as it’s needed for the reason we collected it, and then we delete it. Our full written Children’s Data Retention Policy is below and at aikera.io/privacy/children#retention. In summary:
- Photos and voice memos: deleted 30 days after the request they belong to is finished (bought, cancelled or declined), and in any case 180 days after upload (90 days for voice memos).
- Comments and reactions: deleted 90 days after the request closes.
- Requests: a request that wasn’t bought is deleted 90 days after it closes. For a bought request, your household keeps the purchase record and we clear your child’s note 90 days after the purchase.
- Usage records: deleted after 90 days.
- The whole profile: erased when you withdraw consent, or after 12 months without use (we’ll email you 30 days before, and you can keep it with one tap).
- Your consent record: kept for 3 years after the profile is erased or consent is withdrawn, without your child’s name, so that we can prove consent was given.
9. Your rights as a parent or guardian
At any time, you can:
- Review the information we hold about your child, in the app (Privacy & controls → See my child’s data) or by asking us.
- Download a copy of it (a file with every category; photos and voice memos are listed by link).
- Correct it, for example by editing or deleting a request or wish.
- Delete it, item by item or all at once, while keeping the profile. Requests your household has already bought, or that are on a shopping trip, stay with your household’s purchase records.
- Refuse further collection or use, by switching features off, pausing the profile, or withdrawing consent.
Withdrawing consent. Your child is signed out on every device at once, removed from the household, and can’t use Kera. We stop collecting straight away and erase the profile within 30 days (usually within a day): we remove your child’s name, PIN and devices, and delete their comments, reactions, photos, voice memos, wishes, the preferences they added and any notes about them. Requests your child made stay on your household’s list under “Removed member”, without their name, so the adults can finish or remove them; the retention rules in section 8 then apply to them. We keep only the minimal consent record described above.
You can do all of this in the app. The parent who gave consent and any Admin of your household can use these controls. You can also email hello@spin.ge from the email address on your Kera account, or call +1 908 742 4951. If you contact us another way, we will first check that you really are the child’s parent or guardian. We answer within 30 days at the latest.
10. Changes to this notice
If we make a material change to what we collect from children or how we use or share it, we will ask for your consent again before the change applies to your child. Until you consent again, your child’s profile keeps working under the terms you agreed to, and the new collection or use stays off for your child.
Children’s Data Retention Policy
This is our written policy for keeping and deleting children’s personal information, as required by the US Children’s Online Privacy Protection Rule (16 CFR 312.10). It forms part of this notice. Version 2.
Scope. Personal information collected from or about a child through a child profile (“child data”). “Child” means anyone under 18 whose profile was created through the parental consent flow.
General rules.
- We keep child data only as long as reasonably necessary for the purpose it was collected for, as set out below. Nothing is kept indefinitely.
- A scheduled job applies these periods every day. When a period ends, we delete the data, including the stored file. Records the household shares (such as a purchase) are de-identified instead: the child’s name is removed and the record shows “Removed member”.
- When a parent withdraws consent, collection stops at once, the child is signed out everywhere, and the profile is erased within 30 days (in practice at the next daily run). The minimal consent record (row 13) is the only record kept about the child.
- Backups. Deleted data remains in our database provider’s backups until they roll over, which is no more than 30 days. It is never restored into the live service except to recover from a disaster, and if that happens, pending deletions are re-applied.
- Legal holds. Deletion may be paused only where the law requires it, for example a preservation order. Any hold is recorded, and the parent is told unless that is prohibited.
- The timelines below are maximums. A parent can delete earlier at any time.
| # | Data category | Purpose | Business need for keeping it | Retention period | Deletion method |
|---|---|---|---|---|---|
| 1 | Child profile: first name or nickname, age band, household handle, role, child-profile marker, feature switches, pause and “keep” dates, last-active time | Identify the child to the household; apply the right protections | Needed while the child uses Kera | While the profile is active. Erased within 30 days after consent is withdrawn, or after 12 months without use: the parents are emailed 30 days before, and the profile is kept if the child signs in or a parent or household Admin taps Keep profile. | Erased in place: the name becomes “Removed member”, and the PIN, handle, devices and household membership are removed, so shared household records still add up without identifying the child |
| 2 | Sign-in credentials: PIN hash, one-time device codes, device tokens, sessions | Authentication | Security of the account | PIN hash: while the profile exists. One-time codes: work for 10 minutes, deleted once expired. Devices: until a parent signs them out, or 180 days without use. Sessions: up to 7 days, ended at once when a parent pauses the profile, signs out the devices or withdraws consent. | Delete |
| 3 | Pending request: the child’s name and age band entered before consent | Complete the consent process | None if consent isn’t given | Deleted when the request expires, 7 days after it was made | Delete |
| 4 | Requests created by the child that are still open | Core feature | Needed until an adult acts on them | While open. When the profile is erased, an open request stays on the household’s list under “Removed member” until an adult finishes or removes it, and rows 5 and 6 then apply. | De-identify at erasure |
| 5 | Requests the child created that were bought | The household’s purchase record and budgets | The adults’ bookkeeping; the child’s identity isn’t needed for it | The purchase record follows the household’s adult retention rules. The child’s free-text note is cleared 90 days after the purchase. The child’s name is removed when the profile is erased. | Clear the note; de-identify at erasure |
| 6 | Requests the child created that were cancelled, declined or rejected | Household history | Short-term reference | 90 days after closing, unless the request is part of a purchase or shopping trip | Delete |
| 7 | Comments and reactions by the child | Collaboration | Context for open requests | 90 days after the related request closes. All deleted when the profile is erased. | Delete |
| 8 | Photos added by the child (attachments and item pictures) | Show what the child means | Short-term only | Attachments: 30 days after the related request closes, 180 days at most from upload. Item pictures the child uploaded: 180 days. All deleted when the profile is erased. | Delete the stored file and the database row; a weekly sweep removes any file left without a record |
| 9 | Voice memos (the child’s voice) | Let a child who can’t write explain a request | Short-term only | 30 days after the related request closes, 90 days at most from recording. All deleted when the profile is erased. | Delete the stored file and the row. Never sent to AI or transcribed. |
| 10 | Wishes created by the child, and occasions for the child | Gifting | Until the wish is fulfilled or removed | Bought or removed wishes: 90 days after that. Active wishes: while the profile exists. All wishes, and occasions for the child, deleted when the profile is erased. | Delete |
| 11 | Shopping preferences the child added, and notes about the child (allergy and diet notes) | Safety warnings; steering the assistant away from unsafe suggestions | Needed while the child is in the household | Until someone with the right removes the note, the parent withdraws health-notes consent (allergy and diet notes are then deleted), or the profile is erased | Delete |
| 12 | Technical and usage data: usage events, daily-activity records, notification tokens, error reports | Internal operations (security, debugging, delivery, aggregate feature metrics) | Short-term operational need | Usage events and daily activity: 90 days. Notification tokens: until the parent turns notifications off or signs the device out, and deleted after 90 days unused. Error reports: up to 90 days. | Delete |
| 13 | Parental consent record and health-notes consent record (guardian id, child id, version, text fingerprint, method, verification evidence, features, timestamps, withdrawal time) | Prove that verifiable consent was obtained | Legal compliance and defence | While the profile exists, then 3 years after consent is withdrawn or the profile is erased. The record never contains the child’s name. | Delete at the end of the period |
| 14 | A parent’s requests to exercise rights about a child | Handle and prove handling of the request | Compliance | 24 months after the request is closed | Delete |
| 15 | Data held by AI service providers (Anthropic for item names; OpenAI, Anthropic and Google when adults use the assistant) | Process the request | None after the response is returned | Zero retention where the provider offers it. Otherwise the provider’s abuse-monitoring window, 30 days at most, under contract. Never used for training. | Provider deletion under our data processing agreement |
| 16 | Server logs (Fly.io, Vercel) | Debugging and security | Short-term | Our hosting providers’ standard log periods. Logs carry ids, never a child’s name. | Provider rotation |
Review. We review this policy every year and whenever a new category of child data is introduced.