⭐ KinHuddle

Privacy, children's data and deletion

Help ·

This is an app holding information about children, which sets the bar for what it's allowed to collect and how easily you can take it all back.

What KinHuddle stores

What it deliberately doesn't

Who can see your family's board

Only the logins you've invited. Every family's data is stored separately and every request is checked against the family it belongs to. Children don't have logins at all: Kid view is a mode of the grown-up's session, not an account.

A child can tick a habit in Kid view. That tap is saved to the family record as completion and review history. Children do not provide an email, password or other contact details, but it would be wrong to describe those saved taps as no direct child interaction.

Two logins are included free and Plus raises it to six. Anyone you invite as a helper can see the day and tick things off but can't change settings, invite others or touch billing.

A password that has already leaked can't be used here

When you choose a password, KinHuddle checks it against a public list of passwords found in known data breaches and refuses the ones on it. This is the single most useful thing an app can do for an account. Attackers do not sit and guess: they replay passwords already known to work somewhere else, which is why a password can meet every rule a form can express and still be worthless.

Your password does not leave our server to do this. We take a one-way fingerprint of it, send the first five characters of that fingerprint to Have I Been Pwned, and receive back every fingerprint in their list that starts with those five. The comparison happens here. Roughly one password in a million shares those five characters, so the service is never told which password was asked about, whose it was, or that it came from KinHuddle at all.

If the check can't be reached, your password is simply accepted. A family should never be unable to sign up because a service we don't run is having a bad afternoon.

We check the address before an account exists

Signing up sends a link to the email you typed, and the account is created when you open it. Two reasons, and the second is the one that matters more.

It confirms the address is really yours, so nobody can create an account in your name. And it means the signup form gives the same answer whichever address you put in it. Before, typing an email told you whether that address already had a KinHuddle account, which meant anyone could work through a list and learn which families are here. Now the only place the two cases differ is inside the mailbox itself, which only its owner can read.

A second lock on your account

Your password is the only thing standing between someone and your children's names, their routines, and the notes you write about them. If you have ever used that password anywhere else, it is worth adding a second step.

Turn it on in Menu → Account settings and, from then on, signing in asks for a six-digit code from your phone as well as your password. The code changes every thirty seconds, so knowing your password is no longer enough on its own. You may see this called two-factor authentication elsewhere; it is the same thing.

What it costs you. You will need a free authenticator app on your phone. Google Authenticator, Authy, and most password managers all work. Setting it up takes about two minutes and involves pointing your camera at a square on screen.

What happens if you lose your phone. This is the part worth reading before you start. When you turn it on we give you a set of backup codes. Each one works once, in place of your phone. Save them somewhere that is not your phone: print them, or put them in a password manager. Without your phone and without a backup code, getting back in means emailing us and proving who you are, which is deliberately slow.

It is per person, not per family. One parent turning it on does not turn it on for the other, and it does not affect anyone you have invited as a helper unless they set it up themselves.

Milestones are informational

The children's milestone library is age-banded and informed by public developmental guidance. It is there to celebrate things, not to assess anyone. KinHuddle does not assess, diagnose or treat anything, and a milestone not yet ticked means nothing at all. You can hide the age labels entirely in Household preferences if they're unhelpful.

Grown-ups can keep milestones too, and those work differently on purpose. They carry no ages, because there is no typical age for finishing a course or paying off a debt, and nothing is pre-filled: the suggestions are a list to browse, not a set of assumptions about you. Ticking one shows a celebration on your own screen and nothing else. The shareable win card is for the children's milestones only.

Getting your data out

Account settings → Download current family-board data gives you a file containing the current family-board data shown in the app: family configuration, tasks, completion and review history, milestones, rewards, journal entries, games, adventures and Night Cap entries. It is not a copy of operational records such as sign-in security events or payment records. No request, waiting or email is required.

Deleting your account

Deleting KinHuddle does not cancel a Stripe subscription. If Plus can still renew, account deletion is stopped and Account settings directs the owner to Manage subscription first. Once future renewal is canceled, return to the deletion screen. KinHuddle checks Stripe before removing anything; if that check cannot be completed, the account is kept so you can try again.

Account settings → Delete account permanently removes the family's records, every login into the family, nightly backups, push subscriptions, stored suggestions, unfinished sign-ups for the owner's address and account-scoped rate-limit records. It is deletion, not a disabled flag.

If any deletion step fails, KinHuddle reports that the deletion is incomplete and keeps the owner login so you can sign in and retry. It does not report success for a partial purge.

Some records may outlive the account: an administrator action record is kept for 365 days; Stripe keeps payment records required by tax and accounting rules; and the words of a suggestion already filed as an anonymous issue cannot be unsent automatically. Use the privacy request form to ask for an already-filed suggestion to be removed.

When protected saving is enabled, we also keep a one-way identifier derived from the household's random record ID and a deleted status. This marker contains no names, email addresses or family content. It has no automatic expiry because a delayed save must not recreate deleted data.

Removing one child

Household → Add or edit people and pets gives you two choices. Remove from board takes the child, their current habits and milestone list off the Board while keeping the family's past ticks, totals, milestones, reward claims, Night Cap entries and journal notes. A small past-member entry keeps the child's name, record id and removal time so you can find and erase that history later.

Erase records removes those structured records too, from the live family data and the backups KinHuddle still holds. It asks for your account password and the child's typed name, and it cannot be undone. For an older removed record where no name survives, Household preferences shows its historical id and asks you to type that instead. Family-level Night Cap notes stay because they are not filed under one person and the app does not guess who a sentence is about.

KinHuddle keeps a hashed erasure reference that does not contain the child's id or name. The server uses it to strip an old copy sent later by another open tab or an offline device. That reference leaves when the family account is deleted.

Backups

Every family's data is snapshotted nightly and kept for thirty days, so a bad write or an accidental wipe has a recovery path. Restores are never automatic: a human has to decide, and your current data is snapshotted first so an unwanted restore is itself reversible. Deleting your account removes you from this too. Erasing one child's records also removes that child's structured entries from every retained snapshot, so a restore cannot put them back.

Questions

Privacy questions and data requests go through the privacy request form. Everything else goes through the support form. The form stores the request in KinHuddle's private owner inbox before it confirms that the request arrived. Resend carries a notification copy to the owner so they can reply. An overdue alert carries only the request reference and assigned support address, not the message. Private support and privacy messages are never filed as GitHub issues. If the opt-in Sunday recap is on, Resend receives a generic nudge to open KinHuddle. Child names, emoji, points, streaks, milestones, best day and family activity totals stay out of that email.

Still stuck?

Use the support form and a real person reads it. If you're signed in, Menu → Help can copy your account details for you so the reply doesn't start with four questions.

Open KinHuddle