Privacy Notice & Policy
Last updated: June 28, 2026
This page is both a plain-language notice about how Kin Bots handles information and our full privacy policy. We built Kin Bots to collect as little personal data as possible, and to keep a child's world on their own device.
Who we are
Kin Bots is a mobile app for kids that lets a child build a unique AI battle robot ("Kin Bot") for each real friend, as a collectible, printable card. It is operated by Cory Macculloch. You can reach us any time at support@kinbots.app.
What we collect, and where it lives
We keep most of a child's information on the device only. A small amount is stored in the cloud (Google Firebase) so that accounts and credits work across reinstalls and devices, and so cards can be shared.
Stored on the device only (never sent to our servers):
- Friends' first names entered by the child.
- Interests — emoji-style like/dislike icons the child picks for each friend.
- The child's bots and cards, including generated art and backstories.
Stored in the cloud (Google Firebase):
- Parent account login — the email address and password used to create and sign in to the account.
- Credit balance and anonymous identifiers — the account's credit balance, the account ID, and a random per-child identifier, so credits follow the account across devices and reinstalls. The child's name is not part of this — the cloud identifies a child only by a random ID, never by name.
- Shared card records — when a card is shared, the card's text and art are stored so another device can receive it by scanning a QR code. These records contain the bot's details; they do not include account emails or the child's free-text entries.
Parent accounts
An account is created by a parent or guardian behind an adult-only check designed so that a young child is unlikely to complete it on their own. One account corresponds to one child. The parent controls the account and can request changes or deletion at any time.
Card sharing between families
Card sharing is a consent-gated feature that is turned off at launch and shown as “coming soon.” This section describes what will happen once it is enabled, so you have full disclosure in advance.
When sharing is enabled and a child scans another child’s printed card, the app does not transfer anything automatically. Instead:
- The scanning child’s parent must confirm the request, and a request is sent to the family who created the card.
- The creating child’s parent must approve the request. Nothing is sent unless they approve.
- Only upon approval is the card delivered. The delivered card includes the bot’s image and the first names associated with it (the friend the bot is based on, and the child who created it). No account emails, last names, addresses, or free-text entries are included.
- The card is sent end-to-end encrypted through a temporary cloud relay addressed only to the receiving device, and the relayed copy is deleted once delivered (and in any case expires automatically). We cannot read the encrypted contents.
Because an approved share sends a child’s first name and a bot image to another family, a parent reviews and approves each share before it is sent. Until sharing is enabled, no requests are created and no cards are transferred.
Children's privacy (COPPA)
Kin Bots is intended for children, with a parent or guardian setting up and supervising the account. The child's name and everything about the child's friends and creations stay on the device; the cloud holds only the parent's account email, a credit balance, and random identifiers that do not reveal who the child is. We do not knowingly collect personal information from children beyond what is described here, we do not show third-party advertising, and we do not use the information for behavioural tracking. Parents may review, request changes to, or request deletion of their child's information by contacting support@kinbots.app.
How AI generation works
Robot art and backstories are produced using Google's Gemini and Imagen AI services. The only personal detail included in a generation request is the friend's first name and the chosen interest icons; no account email, last names, or other identifying data is sent. Generation runs through kid-safe guardrails — designs are sci-fi and mechanical, with no gore or realistic weapons.
Third-party services
- Google Firebase (Authentication, Firestore, App Check) — account login, cloud storage for shareable card records and credit balances, and app-integrity security.
- Google Firebase Storage — the temporary, end-to-end encrypted relay used to deliver an approved shared card to another device. This relay is part of the card-sharing feature, which is turned off at launch; it carries only encrypted content we cannot read and auto-deletes shortly after delivery. It is named here for full disclosure even though it is not active yet.
- Google Gemini / Imagen — AI text and image generation, as described above.
- Resend — our transactional email provider. It is used to send account verification and password-reset emails, and to deliver a printable card PDF if a user chooses to email one. The recipient's email address is used solely to deliver that message and is not retained by us for any other purpose.
These providers process data on our behalf under their own security and privacy commitments. We do not sell personal information.
Data retention & deletion
On-device data (friends, interests, bots, cards) is removed when the app is uninstalled. To delete a parent account along with its cloud-stored login, credit balance, and any shared card records, contact support@kinbots.app and we will remove it. Step-by-step instructions are on our Delete Account page.
Governing law
This policy and any dispute relating to it are governed by the laws of the Cayman Islands, without regard to its conflict-of-law rules.
Changes to this policy
If we make material changes to how we handle information, we will update this page and revise the "Last updated" date above.
Contact
Questions, concerns, or a data request? Email support@kinbots.app.