Legal

Children’s Privacy Notice

Version 2 · Effective date: 26 September 2026

Kera helps households organise their shopping. A parent or guardian can add their child to their household with a child profile, so the child can ask for things they need, such as school supplies, snacks or birthday wishes. Adults decide what gets bought.

This notice explains what we collect from and about a child who uses Kera through a child profile, what we do with it, and what you can do as their parent or guardian. It covers every child under 18 with a child profile. For a child under 13 it is the notice the US Children’s Online Privacy Protection Act (COPPA) requires. It is part of our Privacy Policy.

1. Who we are and how to reach us

Kera is operated by SPIN LLC, a limited liability company registered in Georgia (company ID 405173191).

SPIN LLC is the only operator that collects or keeps children’s information through Kera.

2. How a child comes to use Kera

3. What we collect

From you, the parent, when you create the profile:

From your child, as they use Kera:

WhatExampleWhen
Sign-in detailsa PIN (stored only in scrambled, hashed form), and for each device they sign in on, a random device token and the device’s name (such as “Pixel 7”), which you see in Privacy & controlsAlways
Requestsitem names, quantities and notes such as “the blue one”Always (this is what a child profile is for)
Comments and reactionsa comment on a request, or an emojiAlways
Shopping preferencesa note they add, such as “I don’t like mushrooms”If they add one
Rewardsa reward a parent set up that your child redeemsIf your household uses rewards
Reportsa report they send us about content in the householdIf they send one
Photosa picture attached to a request, or a picture they upload for an itemOn unless you switch it off
Voice memos (recordings of your child’s voice)a spoken note attached to a requestOn unless you switch it off
Wishlistitems on your child’s wishlistOn unless you switch it off
Notificationsa notification token for your child’s deviceOn unless you switch it off
Technical and usage informationdevice type, app version, when they were last active, error reports, and in-app events such as “added a request”, linked to a random identifierAlways (see below)

About your child, entered by adults in your household: notes such as allergies or foods to avoid, if an adult chooses to add them, and a gift occasion for your child, such as their birthday. Because allergy and diet notes can be health information, we ask for your separate, explicit agreement before anyone can link such a note to your child (section 7).

What we don’t collect from children: email address, phone number, home address, precise or approximate location, contacts, payment details, government ID, date of birth, or any biometric data such as face or voice prints. We don’t use children’s voices or faces to recognise them.

Technical information and “persistent identifiers.” Like any app, Kera uses a few identifiers to work: a random account id, a session token, a device token for each device your child is signed in on, a notification token if notifications are on, and an error-report id. Under US law these count as personal information. We use them only to support Kera’s internal operations:

Usage records about a child keep only ids, counts and a few fixed labels (never what your child typed), and are deleted after 90 days. Error reports carry the random account id only, never your child’s name, and no screenshots. We don’t use these identifiers to build a profile of your child, to show them ads, or to track them across other apps or websites. There are no advertising, analytics or attribution tools from other companies in Kera.

Nothing your child posts is public. Your child’s requests, comments, wishes, photos and voice memos can be seen only by members of your household. Please remember that everyone in your household can see them, including adults who aren’t your child’s parents (for example a roommate or relative you invited). Photos and voice memos are stored privately and open only through short-lived links given to signed-in members of your household. Public gift pages never show your child’s wishes, never show an occasion for your child, and never show your child’s name.

4. How we use children’s information

We use it only to run the household features your child takes part in:

We never:

AI and search are for adults. Children can’t use Kera’s AI assistant (“Ask Kera”, by text, voice or live call), voice add, snap-to-add photo recognition, meal planning, AI suggestions, web or product search, receipt scanning or gift research. Links your child pastes are read without AI.

Money. Your child doesn’t see the household’s budgets, spending or other money information unless a household Admin chooses to show budgets to children.

A gentler experience. Child profiles see no leaderboards and no weekly challenges, get no badge notifications, and never appear on anyone’s leaderboard. On their first sign-in, your child sees a short explanation that you can see their requests and wishes, and a “Tell a grown-up” help screen is always available.

5. Features you control

When you create the profile, and at any time afterwards in Privacy & controls, you can switch these features on or off for your child. They start on; you can switch any of them off before you give consent:

When you switch a feature off, Kera stops your child adding that kind of information (our servers refuse it, not just the app), and you can delete what was already added. Switching notifications off also forgets your child’s devices for notifications. If notifications are off, Kera sends none to your child’s devices. From the next app update, your child’s device also asks for permission to show notifications only if you leave notifications on.

In Privacy & controls you can also pause the profile (your child is signed out and can’t sign in or add anything until you un-pause it; nothing is deleted), sign out your child’s devices, reset their PIN, and withdraw consent (section 9).

6. Who we share children’s information with

We share children’s information only with service providers that help us run Kera. Each one is bound by a contract. It may use the information only to provide its service to us, must keep it secure, and may not use it for anything else. That includes training AI models, advertising or selling it.

Service providerWhat it does for KeraChildren’s information it handles
Fly.io (Germany)Runs Kera’s serversAll children’s information passes through it
Neon (Germany)DatabaseAll stored children’s information
Cloudflare (R2 storage)Stores files privatelyPhotos and voice memos
VercelHosts the web version of KeraTechnical request data when your child uses Kera in a browser
AnthropicAI that suggests a category and spots duplicate requestsOnly the item name, with no name or other detail about your child or your household
Expo, which passes messages to Apple or GoogleDelivers notificationsYour child’s notification token and message text, if notifications are on; notifications to adults in your household can mention your child’s first name
ResendSends emailEmails to you about your child (consent, confirmation, reminders), which include your child’s first name. We never email your child.
Sentry (EU)Error reportsRandom account id and technical error details
OpenAI, Anthropic, GoogleAI assistant used by adults in your household. When an adult asks the assistant about the household list, it can see the names of things your child asked for and any allergy or diet notes about your child, labelled “a child in the household”.Item names, and allergy or diet notes, never your child’s name, and never anything your child wrote themselves (notes, comments, wish notes or their own preferences)

What never reaches any AI, search or image provider: your child’s name, their household handle, their account id, and anything your child wrote themselves. Our search providers (Brave, Shopify) and our picture-generation provider (Replicate) receive nothing from your child’s profile; if an adult’s search or item mentions your child by name, we replace the name first. We check this with an automated test that runs on every change to our code.

We don’t share children’s information with anyone else, including advertisers, data brokers, retailers and other companies’ AI. If that ever changes, we will ask for your separate consent first, and saying no won’t affect your child’s use of Kera.

We may disclose information if the law requires it, for example in response to a valid court order, or to protect the safety of a child or others.

Where the information is stored. Kera’s database and servers are in the European Union (Germany). Some service providers above process information in the United States and other countries, under safeguards described in our Privacy Policy.

Before we create a child profile, we ask for your consent and verify it:

  1. In the app, you confirm you’re the child’s parent or legal guardian and enter your child’s first name or nickname and age band. We show you a short notice and email the address on your Kera account, which you must have confirmed.
  2. You open the link in that email while signed in to your Kera account and fill in the consent form. The link works for 72 hours and only for you. We create the profile only when you submit the form.
  3. At least 24 hours later we send a second email, so the real account holder can stop anything they didn’t approve with one tap.

If you don’t confirm, we don’t create the profile, and we delete the details you entered about your child after 7 days. We don’t collect anything from your child until you have confirmed.

Health notes. On the same form, you can separately agree that adults in your household may record allergy, dietary or similar notes about your child. It is optional, and you can withdraw it at any time in Privacy & controls, which deletes those notes.

What we record. We keep a record of your consent: who gave it and for which child, the version of the form and a fingerprint of its exact wording, the method, the time, the features you chose, whether you agreed to health notes, and technical details of how you confirmed (the email and link used, the signed-in session, your IP address, your browser or app, and your device’s country setting). The record never contains your child’s name.

Where we offer child profiles. We may not offer child profiles in every country. If adding a child isn’t available where you live, the app tells you.

Our legal basis (EU, UK, Georgia and similar laws): your consent as the holder of parental responsibility, and your separate, explicit consent for health notes.

8. How long we keep children’s information

We keep it only as long as it’s needed for the reason we collected it, and then we delete it. Our full written Children’s Data Retention Policy is below and at aikera.io/privacy/children#retention. In summary:

9. Your rights as a parent or guardian

At any time, you can:

Withdrawing consent. Your child is signed out on every device at once, removed from the household, and can’t use Kera. We stop collecting straight away and erase the profile within 30 days (usually within a day): we remove your child’s name, PIN and devices, and delete their comments, reactions, photos, voice memos, wishes, the preferences they added and any notes about them. Requests your child made stay on your household’s list under “Removed member”, without their name, so the adults can finish or remove them; the retention rules in section 8 then apply to them. We keep only the minimal consent record described above.

You can do all of this in the app. The parent who gave consent and any Admin of your household can use these controls. You can also email hello@spin.ge from the email address on your Kera account, or call +1 908 742 4951. If you contact us another way, we will first check that you really are the child’s parent or guardian. We answer within 30 days at the latest.

10. Changes to this notice

If we make a material change to what we collect from children or how we use or share it, we will ask for your consent again before the change applies to your child. Until you consent again, your child’s profile keeps working under the terms you agreed to, and the new collection or use stays off for your child.

Children’s Data Retention Policy

This is our written policy for keeping and deleting children’s personal information, as required by the US Children’s Online Privacy Protection Rule (16 CFR 312.10). It forms part of this notice. Version 2.

Scope. Personal information collected from or about a child through a child profile (“child data”). “Child” means anyone under 18 whose profile was created through the parental consent flow.

General rules.

  1. We keep child data only as long as reasonably necessary for the purpose it was collected for, as set out below. Nothing is kept indefinitely.
  2. A scheduled job applies these periods every day. When a period ends, we delete the data, including the stored file. Records the household shares (such as a purchase) are de-identified instead: the child’s name is removed and the record shows “Removed member”.
  3. When a parent withdraws consent, collection stops at once, the child is signed out everywhere, and the profile is erased within 30 days (in practice at the next daily run). The minimal consent record (row 13) is the only record kept about the child.
  4. Backups. Deleted data remains in our database provider’s backups until they roll over, which is no more than 30 days. It is never restored into the live service except to recover from a disaster, and if that happens, pending deletions are re-applied.
  5. Legal holds. Deletion may be paused only where the law requires it, for example a preservation order. Any hold is recorded, and the parent is told unless that is prohibited.
  6. The timelines below are maximums. A parent can delete earlier at any time.
#Data categoryPurposeBusiness need for keeping itRetention periodDeletion method
1Child profile: first name or nickname, age band, household handle, role, child-profile marker, feature switches, pause and “keep” dates, last-active timeIdentify the child to the household; apply the right protectionsNeeded while the child uses KeraWhile the profile is active. Erased within 30 days after consent is withdrawn, or after 12 months without use: the parents are emailed 30 days before, and the profile is kept if the child signs in or a parent or household Admin taps Keep profile.Erased in place: the name becomes “Removed member”, and the PIN, handle, devices and household membership are removed, so shared household records still add up without identifying the child
2Sign-in credentials: PIN hash, one-time device codes, device tokens, sessionsAuthenticationSecurity of the accountPIN hash: while the profile exists. One-time codes: work for 10 minutes, deleted once expired. Devices: until a parent signs them out, or 180 days without use. Sessions: up to 7 days, ended at once when a parent pauses the profile, signs out the devices or withdraws consent.Delete
3Pending request: the child’s name and age band entered before consentComplete the consent processNone if consent isn’t givenDeleted when the request expires, 7 days after it was madeDelete
4Requests created by the child that are still openCore featureNeeded until an adult acts on themWhile open. When the profile is erased, an open request stays on the household’s list under “Removed member” until an adult finishes or removes it, and rows 5 and 6 then apply.De-identify at erasure
5Requests the child created that were boughtThe household’s purchase record and budgetsThe adults’ bookkeeping; the child’s identity isn’t needed for itThe purchase record follows the household’s adult retention rules. The child’s free-text note is cleared 90 days after the purchase. The child’s name is removed when the profile is erased.Clear the note; de-identify at erasure
6Requests the child created that were cancelled, declined or rejectedHousehold historyShort-term reference90 days after closing, unless the request is part of a purchase or shopping tripDelete
7Comments and reactions by the childCollaborationContext for open requests90 days after the related request closes. All deleted when the profile is erased.Delete
8Photos added by the child (attachments and item pictures)Show what the child meansShort-term onlyAttachments: 30 days after the related request closes, 180 days at most from upload. Item pictures the child uploaded: 180 days. All deleted when the profile is erased.Delete the stored file and the database row; a weekly sweep removes any file left without a record
9Voice memos (the child’s voice)Let a child who can’t write explain a requestShort-term only30 days after the related request closes, 90 days at most from recording. All deleted when the profile is erased.Delete the stored file and the row. Never sent to AI or transcribed.
10Wishes created by the child, and occasions for the childGiftingUntil the wish is fulfilled or removedBought or removed wishes: 90 days after that. Active wishes: while the profile exists. All wishes, and occasions for the child, deleted when the profile is erased.Delete
11Shopping preferences the child added, and notes about the child (allergy and diet notes)Safety warnings; steering the assistant away from unsafe suggestionsNeeded while the child is in the householdUntil someone with the right removes the note, the parent withdraws health-notes consent (allergy and diet notes are then deleted), or the profile is erasedDelete
12Technical and usage data: usage events, daily-activity records, notification tokens, error reportsInternal operations (security, debugging, delivery, aggregate feature metrics)Short-term operational needUsage events and daily activity: 90 days. Notification tokens: until the parent turns notifications off or signs the device out, and deleted after 90 days unused. Error reports: up to 90 days.Delete
13Parental consent record and health-notes consent record (guardian id, child id, version, text fingerprint, method, verification evidence, features, timestamps, withdrawal time)Prove that verifiable consent was obtainedLegal compliance and defenceWhile the profile exists, then 3 years after consent is withdrawn or the profile is erased. The record never contains the child’s name.Delete at the end of the period
14A parent’s requests to exercise rights about a childHandle and prove handling of the requestCompliance24 months after the request is closedDelete
15Data held by AI service providers (Anthropic for item names; OpenAI, Anthropic and Google when adults use the assistant)Process the requestNone after the response is returnedZero retention where the provider offers it. Otherwise the provider’s abuse-monitoring window, 30 days at most, under contract. Never used for training.Provider deletion under our data processing agreement
16Server logs (Fly.io, Vercel)Debugging and securityShort-termOur hosting providers’ standard log periods. Logs carry ids, never a child’s name.Provider rotation

Review. We review this policy every year and whenever a new category of child data is introduced.