Last updated: May 31, 2026
The data controller within the meaning of the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) is:
Kiddowall is a parental control platform for iOS devices, designed to help parents protect their children online while respecting their privacy and applicable law.
Kiddowall collects the following categories of personal data:
Provide web filtering, screen time management, geographic zones and real-time location tracking. This is the core purpose for which all usage data is collected.
Send push or email notifications to parents when a child leaves a defined geographic zone, attempts to access blocked content, or when a device goes offline.
Create and maintain parent and child accounts, manage authentication (including 2FA), and handle subscription billing.
Analyze aggregated, anonymized usage statistics to improve platform performance, filter accuracy and user experience. No personal data is shared with third parties for this purpose.
Maintain records to comply with applicable laws (GDPR, COPPA) and respond to legitimate legal requests from authorities.
Parental consent (Art. 6(1)(a) GDPR): When creating an account, the parent explicitly consents to the collection and processing of their child's data (location, browsing history, screen time) for parental control purposes. This consent can be withdrawn at any time by deleting the child's profile or the parent account.
Contract performance (Art. 6(1)(b) GDPR): Processing parent account data (email, password, billing) is necessary to provide the Kiddowall service under the terms of use accepted at registration.
Legitimate interest (Art. 6(1)(f) GDPR): Security logs and fraud prevention measures are processed on the basis of Kiddowall's legitimate interest in securing the platform and protecting minors from harm.
Regarding children under 13 (COPPA compliance): Kiddowall does not create accounts for children. Only parents create accounts and manage their children's profiles. The child's device is enrolled by the parent. We do not knowingly collect personal data directly from children. Parents bear full legal responsibility for providing accurate consent.
| Data category | Free plan | Premium plan |
|---|---|---|
| DNS browsing history | 7 days | 90 days |
| GPS location history | 24 hours | 30 days |
| Screen time data | 7 days | 90 days |
| Alert logs | 30 days | 90 days |
| Parent account data | Until account deletion, then 30 days backup before permanent deletion | |
| Authentication logs | 12 months (legal requirement) | |
| Billing data | 10 years (French accounting law) | |
Any data can be deleted immediately upon request (see section 6). Account deletion triggers the permanent erasure of all associated data within 30 days.
Under the GDPR, you have the following rights regarding your personal data:
Right of access (Art. 15 GDPR): You may request a copy of all personal data held about you and your children. You can export your data in JSON format directly from Settings > Privacy > Export my data.
Right of rectification (Art. 16 GDPR): You may correct any inaccurate or incomplete personal data from within your account settings.
Right to erasure (Art. 17 GDPR): You may request the deletion of your account and all associated data. From Settings > Privacy > Delete my account. Deletion is permanent and irreversible.
Right to data portability (Art. 20 GDPR): You may request your data in a structured, commonly used, machine-readable format (JSON).
Right to object (Art. 21 GDPR): You may object at any time to processing based on legitimate interest by contacting us at [email protected].
Right to restrict processing (Art. 18 GDPR): You may request restriction of processing of your data in the circumstances provided for by the GDPR.
Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority (in France: CNIL).
Kiddowall is a parental control tool. The data of minors (location, browsing history, screen time) is collected exclusively for the purpose of enabling parents to exercise their supervisory duty. Children cannot create Kiddowall accounts themselves.
COPPA compliance (Children under 13 — United States): Kiddowall does not knowingly collect personal information directly from children under 13. Enrollment of a child's device is performed exclusively by the parent or legal guardian. If you believe that a child under 13 has provided personal data without parental consent, please contact us immediately at [email protected] and we will delete it promptly.
GDPR — Children's consent (Art. 8 GDPR): In the EU, where the lawful basis is consent, Kiddowall requires the consent of a parent or legal guardian for any child under the applicable national age (16 years in France, or lower in other member states). By creating a child profile, the parent confirms they are the legal guardian and have the authority to consent on the child's behalf.
Child data is used solely for the purposes described in this policy. It is never sold, monetized, or used for advertising.
Kiddowall implements the following technical and organizational security measures:
All personal data collected by Kiddowall is hosted exclusively in France on OVH SAS / Kimsufi infrastructure (Roubaix, France — EU). Kiddowall does not transfer personal data outside the European Economic Area (EEA).
Third-party service providers used by Kiddowall (e.g., transactional email delivery) are contractually bound to process data only within the EEA or under standard contractual clauses approved by the European Commission, and are prohibited from using data for their own purposes.
Apple Inc. processes certain data as part of the iOS MDM (Mobile Device Management) protocol. This processing is governed by Apple's privacy policy. Kiddowall uses Apple's MDM API solely to deploy configuration profiles and does not share children's personal data with Apple beyond what is technically necessary for MDM enrollment.
For any questions relating to the protection of your personal data, to exercise your rights, or to report a potential data breach, please contact:
We commit to acknowledging your request within 5 business days and providing a full response within 30 days.
Kiddowall uses only strictly necessary cookies:
Kiddowall uses PostHog analytics, session replay, heatmaps, and error tracking for registered accounts in order to improve the service. Creating an account and continuing to use the service means you accept these measurement features as part of the service terms. We do not use advertising cookies or tracking pixels, and we do not send data to Google Analytics, Facebook Pixel, or similar advertising services.
Kiddowall reserves the right to update this privacy policy to reflect changes in our practices, service features, or applicable law. We will notify registered users of any material changes by email at least 30 days before they take effect. The date of last update is displayed at the top of this page. Continued use of the service after the effective date constitutes acceptance of the revised policy.