Security & Incident Response
Last updated: August 2026
This trust document is maintained in English. For our data practices, see the Privacy Policy; for how we design our AI features, see Responsible AI at KidsAI.
1. Our security commitment
KidsAI stores children's drawings and the artwork generated from them. We treat every upload as a family's personal creative work: we collect the minimum data the product needs, we protect it with industry-standard encryption, and we never sell it or use it to train AI models. This page describes the technical and organizational measures behind that commitment, and exactly what we do if something goes wrong.
2. Encryption
- In transit: all traffic between your device and KidsAI — including uploads, generated results, and payments — is encrypted with TLS (HTTPS). We do not serve any product functionality over unencrypted connections.
- At rest: uploaded drawings and generated images/videos are stored on Cloudflare R2 with AES-256 encryption at rest. Account records live in a managed Postgres database that encrypts data at rest.
- Passwords: if you sign up with email, your password is hashed with bcrypt (one-way) before storage. We cannot read your password. Google and Apple sign-in never share your password with us at all.
3. Access control
- KidsAI is operated by a small team; production data access is limited to the founder-operator and protected by authenticated, access-controlled provider consoles (with multi-factor authentication where the provider supports it).
- Internal administrative tools are password-protected, are never linked publicly, and expose only the minimum data needed for support and safety review.
- Your works are private to your account. There are no public galleries of user uploads, no social feeds, and no sharing unless you explicitly download or share a work yourself.
- API credentials and secrets are stored in our hosting provider's encrypted environment configuration, not in source code.
4. Infrastructure & subprocessors
We build on established cloud providers rather than running our own servers. Providers that may process data as part of delivering the service:
| Provider | Role |
| Vercel | Application hosting and serverless compute |
| Neon | Managed Postgres database (accounts, works metadata) |
| Cloudflare R2 | Encrypted storage for uploaded and generated images/videos |
| Google (Sign-In, Gemini paid API) | Authentication; image understanding & generation. Paid API content is not used by Google to train models |
| Apple (Sign in with Apple, App Store) | Authentication and in-app purchases on iOS |
| BytePlus (Seedance paid API) | Video animation generation |
| OpenAI (paid API) | AI text and content generation |
| Stripe | Payment processing (we never see or store full card numbers) |
| Resend | Transactional email (e.g. verification codes) |
| Sentry | Error monitoring (technical diagnostics) |
| Google Analytics | Aggregate product analytics (with personalized-ads signals disabled) |
These are subprocessors bound by their own security and data-processing terms — we do not sell or share your data with third parties for their marketing purposes. See the Privacy Policy for what each one receives.
5. Backups & availability
- The production database is automatically backed up every night to encrypted off-site storage.
- We retain daily backups for 30 days and monthly snapshots for 12 months, and we periodically verify that backups actually restore.
- Hosting, database, and storage each run on providers with independent redundancy; a failed video or coloring generation never silently consumes a family's credits without a retry or refund path.
6. Monitoring & content safety
- Automated error monitoring alerts us to application failures in production.
- Payment-integrity checks reconcile purchases daily so billing errors are caught quickly.
- Uploads submitted for animation pass through child-safety content moderation before any AI processing; unsafe inputs are rejected and the family's credits are not charged.
- Generated output quality and safety regressions are reviewed continuously; every user can report a problematic result directly from the product (see Responsible AI).
7. Vulnerability reporting
If you believe you have found a security vulnerability in KidsAI, please email aistudio4kids@gmail.com with the subject line "Security". Please include steps to reproduce and do not access other users' data while testing.
- We will acknowledge your report within 72 hours and keep you informed as we investigate.
- We will not pursue good-faith researchers who respect user privacy, avoid service disruption, and give us reasonable time to fix issues before public disclosure.
8. Data incident response
If we ever suspect unauthorized access to personal data, we follow this process:
- Detect & contain — triage the report or alert, revoke affected credentials, and isolate affected systems immediately.
- Assess — determine what data was involved, whose accounts were affected, and the root cause.
- Notify — inform affected users by email without undue delay, and within the timelines required by applicable law (e.g. within 72 hours of confirming a personal-data breach where GDPR applies), including what happened, what data was involved, and what we and you can do.
- Remediate & review — fix the root cause, verify the fix, and publish a post-incident summary on this page when the incident materially affected users.
To date, KidsAI has had no known personal-data breach. If that ever changes, this section will link to the incident summary.
9. Legal & regulatory posture
- COPPA (US): KidsAI is designed for adult-guided use. Accounts are created by parents, teachers, or other adults; we do not knowingly collect personal information directly from children under 13 without parental involvement. The product shows no ads, has no open chat, and does not sell personal data.
- GDPR / UK GDPR (EEA & UK): we honor access, deletion, export, and objection requests for all users regardless of region, and process data on the lawful bases described in the Privacy Policy.
- FERPA (US schools): KidsAI does not require or collect student education records. When teachers use KidsAI in class, our teacher materials direct them to keep uploads free of student names, faces, and identifying details, and to follow their school's own data policies.
We state these as design commitments rather than third-party compliance certifications; independent reviews we complete (such as education-sector certifications) are listed on our About & Safety page.
10. Questions
Security questions or concerns: aistudio4kids@gmail.com (subject "Security"). Privacy requests: see the Privacy Policy.