Privacy Policy
Pomet, Inc. · Effective date: August 24, 2026 · Last updated: August 24, 2026
KidBrief is built on a simple premise: information about your children belongs to your family. That extends to how we treat it. We built the app so your kids’ profiles stay on your own device by default, and this policy explains what we collect, who can see it, how we use it, and how we protect it. Plain language, no surprises.
01
What we collect
Sources of information
We collect personal information from the following sources: (a) directly from you, when you set up your family, add a profile, or contact us; (b) from your device, such as device type, operating system version, and crash reports; (c) from caregivers you share a brief with, when they open the link or leave you a note afterward.
What lives on your device, not with us
KidBrief is local-first. Your kids’ profiles — names, photos, routines, allergies, medications, emergency contacts, the small details that make a hard evening go well — are created and stored on your own device. We do not have accounts. There is no signup, no password held by us, and no copy of your family sitting on our servers waiting to be useful to us later.
In normal use, your family’s profile never leaves your device. There are three narrow exceptions, and each one is described below: a brief you deliberately share, text you send for AI sorting, and anything you email us yourself.
Briefs you choose to share
When you create a share link for a sitter or a grandparent, KidBrief sends a copy of that one brief to servers we operate — hosted on Vercel — so the caregiver can open it in their browser without installing anything. That copy contains only what you chose to include: the kids you selected, the fields on their profiles, any photos attached to those fields, your emergency contacts, and the note you wrote for the evening.
That copy is reachable only by the link’s random, unguessable token. It expires on the schedule you picked — a share is never open-ended — and you can revoke it at any time from the app. When a share expires or is revoked, we stop serving it immediately and delete the copy from our servers within 30 days.
Nothing is shared unless you tap share. Closing the app, adding a field, or updating a profile does not send anything anywhere.
Voice notes and brain-dumps
When you speak or paste a brain-dump so KidBrief can sort it into profile fields, the audio is transcribed on your device and is not sent to us. The resulting text is sent to our processing endpoint and on to OpenAI, which returns it as structured fields. That text can contain health details, because that is often what you are describing.
We hold a Zero Data Retention agreement with OpenAI: the text we send is not retained by them and is never used to train models. We do not store the transcript on our servers either — the structured result comes back to your device and stays there.
If you would rather nothing leave the device at all, KidBrief includes an offline parser that sorts a brain-dump on your phone without any network call. It is less clever, and it is entirely private.
Health and medical details
Allergies, medications, dosages, conditions, pediatrician contacts, and where the EpiPen is kept are treated as sensitive personal information under laws including the California Consumer Privacy Act (as amended by the CPRA) and consumer health data laws in Washington and Nevada.
To be precise about what that does and does not mean: KidBrief is not a healthcare provider, insurer, or vendor to one, so HIPAA does not apply to us. But we handle this information as the sensitive category it is. We process it for one purpose — displaying it to you and to the caregivers you deliberately share it with. We do not use it for anything else, we do not sell it, and we do not share it with advertisers or data brokers. California residents have the right to limit the use and disclosure of sensitive personal information under CPRA § 1798.121.
Because this information concerns your children, who cannot consent for themselves, you are providing it as their parent or legal guardian and consenting on their behalf. Where the law requires explicit consent for health-related data — including GDPR Art. 9(2)(a) and the Washington My Health My Data Act — we ask for it in the app before you add this kind of detail, and you can withdraw it at any time by deleting the fields. Our separate Consumer Health Data Privacy Policy, available at kidbrief.app/health-data-privacy, describes this in the specific form Washington law requires.
Information about your children
KidBrief is designed to be used by a parent or legal guardian describing their own children. Children do not use KidBrief, do not create accounts, and are not the audience for the app.
The information in a kid profile is entered by the adult responsible for that child, exercising their own authority as that child’s parent or guardian. We do not collect information from children, we do not ask children for information, and we do not knowingly permit anyone under 18 to set up KidBrief.
If you are not a parent or guardian of the children you are describing, or you do not have that parent’s permission, do not use KidBrief for those profiles.
Caregiver information
When you share a brief, we collect:
-
That the link was opened, and when, so your dashboard can show you the sitter has seen it.
-
The caregiver’s IP address and browser type, which their device sends automatically when it requests the page. We use this only to serve the page and to detect abuse, and we delete it on the same schedule as the share.
-
Questions the caregiver asks the brief, which are sent to our AI provider along with the brief content in order to generate an answer. These are not stored on our servers after the answer is returned, and they are not retained by our AI provider.
-
Any note the caregiver leaves you, which we pass back to your device.
Caregivers do not create accounts and we do not build profiles of them. We show caregivers a short notice when they open a link, explaining what we collect and what we expect of them.
Some caregivers are teenagers. If you are a caregiver under 18 and you would like us to delete what we collected when you opened a link, email privacy@kidbrief.app and we will do it.
Device and usage data
We collect basic technical information to keep the app running — device type, operating system version, crash reports, and general usage patterns. This data is aggregated or deidentified and used only to make the product work better.
Waitlist and marketing
If you join our early access list, we collect your email address and use it for launch announcements and significant product updates. We will never sell it or share it with advertisers. You can unsubscribe at any time.
Feedback and support
If you send us feedback or a support message, we receive it and we read it — that’s what it’s for. These messages are separate from your family’s profiles: nothing stored in KidBrief is attached to them unless you paste it in yourself.
Cookies and analytics
Our website at kidbrief.app may use standard website analytics to understand visits — pages viewed, how you arrived, approximate location derived from your IP address, and device and browser type. This information is kept separate from your KidBrief app data, is not used to identify you personally, and is never used for advertising. Where required by law, we ask for your consent before placing non-essential cookies, and you can withdraw consent or disable cookies in your browser settings at any time.
Within the app we collect a limited, predefined set of usage events — for example, whether setup completed successfully, or whether a share link was created. These events never include your kids’ names, profile content, photos, the text of a brain-dump, or anything a caregiver asked. Our analytics provider operates as a data processor under our instructions and does not use this data for any independent purpose.
02
Who has access to it
You
Your family’s profiles belong to you and live on your device. KidBrief is not a shared or collaborative product. Other KidBrief users cannot see your family.
The caregivers you choose
Only people you hand a link to. That link is unguessable, it expires, and you can revoke it. A caregiver sees exactly the kids and fields you selected for that share — nothing else, and nothing from past or future shares.
KidBrief employees
We never read your kids’ profiles. To understand how the app is used, we see only de-identified, category-level signals — for example, that a profile has an emergency contact filled in — never your words, your photos, or your children’s names. These signals are shown only in aggregate. Access to any user content is technically restricted and limited to authorized personnel, only when strictly necessary for security, support, maintenance, or legal compliance.
Vercel
Vercel hosts the KidBrief website, our serverless functions, and any temporary server-side data — including a shared brief while its link is active. Vercel operates as a data processor under our instructions and does not use your data for any independent purpose.
OpenAI
OpenAI processes brain-dump text into structured fields, and answers caregiver questions using the shared brief, under a signed Zero Data Retention agreement. Photos are not sent to OpenAI.
Apple
Apple processes subscription purchases through the App Store. We never see your payment details.
Our other service providers
We work with a small number of additional providers — for example, to store waitlist email addresses and to run product analytics — who process data on our behalf, and this list may change as the product grows. We keep a current list at kidbrief.app/service-providers.
Legal and regulatory authorities
We may be required to disclose data to law enforcement or regulatory bodies if compelled by law. Where legally permitted and appropriate, we will notify you. Because your profiles live on your device, in most cases there is very little for us to disclose.
Business transfers
If Pomet, Inc. is acquired, merges, or sells assets, information we hold may transfer as part of that transaction. Any acquirer would be bound by the commitments in this policy, and we would notify you before your data became subject to a different one. Because your family’s profiles live on your device rather than on our servers, there is very little about your children for any acquirer to receive.
We will not sell your personal data or share it with advertisers. We will never sell data about your children, in any form, to anyone.
03
How it’s used
To make the app work
We use your data to run KidBrief: sorting a brain-dump into fields, building the brief a caregiver sees, delivering the note they leave you, and reminding you when something looks out of date.
KidBrief uses AI to turn what you write or say into structured profile fields, and to answer a caregiver’s question using only the brief you shared. These are assistive tools for organizing and surfacing what you wrote. KidBrief does not make automated decisions about you that produce legal or similarly significant effects. You can always edit, correct, or delete anything the AI produced.
Improving the product
We use aggregated and de-identified usage data to understand how KidBrief is used. This data is stripped of direct identifiers and processed so it cannot reasonably be linked back to any individual family.
We never use your family’s profiles, photos, brain-dumps, or caregiver questions to train AI models, and we never share them with anyone for that purpose.
Communicating with you
We use push notifications and, if you’ve given us your address, email to send you product updates and service communications. You can turn off notifications in your device settings and unsubscribe from marketing email at any time. We will still send you essential service and security messages.
Security and abuse prevention
We may use technical and usage data to detect and prevent misuse, fraud, or attacks on the service — for example, to stop someone draining our AI endpoint. This is never used to profile you.
Legal bases
Where GDPR applies, we process personal data on these bases: (a) Contract performance (Art. 6(1)(b)) — providing KidBrief, including share links and field extraction; (b) Legitimate interests (Art. 6(1)(f)) — product improvement, security, and abuse prevention, where not overridden by your rights; (c) Consent (Art. 6(1)(a)) — marketing communications and processing of health-related details, which are special category data under Art. 9(2)(a); (d) Legal obligation (Art. 6(1)(c)) — complying with applicable law. You may withdraw consent at any time without affecting processing that already happened lawfully.
If we introduce materially different uses of your data, we will update this policy and ask for consent where required.
04
How it’s protected
On your device
Family data is stored on your device and encrypted at rest. KidBrief supports an app lock — a passcode, or Face ID or Touch ID where your device offers it — so the profiles are not readable by someone who picks up your unlocked phone.
On Face ID and Touch ID: when you unlock KidBrief with your face or fingerprint, Apple’s system tells the app only whether the check passed or failed. Your biometric data never leaves Apple’s Secure Enclave on your own device. KidBrief does not collect, receive, store, or have any access to a scan of your face, your fingerprint, or any other biometric identifier, and we could not share one if we wanted to.
Share links
Share tokens are generated from at least 32 bytes of cryptographic randomness, which makes them unguessable. Expiry and revocation are enforced on our server on every request. Shared pages are marked noindex so they cannot be found through search engines. An expired, revoked, or invalid link reveals nothing about your family — not even whether it was ever valid.
In transit and at rest
Everything that does travel to our servers moves over encrypted connections (TLS) and is encrypted at rest. Shared briefs are isolated by row-level security so one share can never reach another family’s data.
Zero Data Retention with OpenAI
Under our signed Zero Data Retention agreement, text sent for processing is not retained for model training or long-term storage.
Data minimization
We only collect what we need. We do not build advertising profiles and we do not do targeted advertising. We keep data only as long as it is serving you.
Breach notification
If a breach affects your personal information, we will notify you without undue delay and take immediate steps to contain and remediate it. Where the law sets a deadline for notifying you or a regulator, we will meet it.
05
Your rights
To exercise any of these, email privacy@kidbrief.app. We will respond within 30 days.
Access
You can request a copy of any personal data we hold about you. Note that your family’s profiles are already in your hands — they are on your device.
Correction
You can edit any profile, field, or photo directly in the app at any time.
Deletion
Deleting a kid, a field, or the app itself removes that data from your device. You can revoke every active share link from the app, which deletes the shared copies from our servers. To have us delete anything else we hold, email privacy@kidbrief.app.
Export
You can export your family’s data from the app in a portable format at any time.
Opt out of marketing
Unsubscribe from any email, or contact us directly.
If you are asking about someone else’s KidBrief
Because family profiles live on the user’s own device, we usually cannot see, retrieve, or delete what someone else has stored. If you contact us about data you believe a KidBrief user holds about you or your child, we will take reasonable steps to help — which typically means relaying your request to that user.
Before we act on any request, we verify who is asking, using information proportionate to the sensitivity of what is being asked for. We will not disclose the contents of anyone’s KidBrief to a third party on request.
A note on custody and family disputes. We are not able to determine who has legal authority over a child, and we will not take a side. We do not adjudicate custody, and being contacted by one parent does not cause us to disclose or delete another parent’s data. If a court of competent jurisdiction orders us to act, we will comply with that order. If a request concerns immediate danger to a child, contact your local authorities — they can reach us faster through legal process than we can act on our own.
Your state privacy rights
Depending on where you live, you may have additional rights under your state’s privacy law, including the right to: (a) confirm whether we process your personal data and access it; (b) correct inaccuracies; (c) delete it; (d) obtain a portable copy; (e) opt out of sale, targeted advertising, or profiling; (f) limit the use of sensitive personal information; and (g) appeal if we deny a request. We do not sell your personal data, use it for targeted advertising, or profile you for decisions producing legal or similarly significant effects. Email privacy@kidbrief.app. To appeal a denied request, write to us with the subject line “Appeal.”
California residents (CCPA/CPRA)
California residents have the right to know what personal information we collect and how it is used, the right to delete, the right to correct, the right to opt out of sale or sharing, and the right to limit the use and disclosure of sensitive personal information. We do not sell or share your personal information. Email privacy@kidbrief.app. We will not discriminate against you for exercising these rights.
EU/EEA and UK residents
You have the right to access and receive a copy of your data; rectify inaccurate data; erase your data; restrict processing; object to processing based on legitimate interests; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with your local data protection supervisory authority. Email privacy@kidbrief.app.
06
Data retention
Your family’s profiles are retained on your device for as long as you keep them. We do not hold a copy, so there is nothing on our side to age out.
Shared briefs stop being served the moment they expire or you revoke them, and are deleted from our servers within 30 days. Caregiver open-records, IP addresses, and note-backs are deleted on the same schedule once delivered to you. Caregiver questions are not stored after the answer is returned.
Before you delete the app, revoke any active share links. Deleting the app removes your data from your device but does not automatically expire links already out in the world — and once the app is gone, you no longer have the means to revoke them. If this happens, email privacy@kidbrief.app and we will revoke them for you.
Waitlist email addresses are retained until you unsubscribe or until 24 months of inactivity, whichever comes first.
Device and usage data is retained in aggregated form for up to 12 months.
In limited cases we may retain certain records for longer where required by law — for example, financial recordkeeping — but this never includes your family’s profile content.
07
International transfers
KidBrief is operated from the United States and relies on a small number of trusted service providers that may process data in the United States or other countries. The United States does not have an EU adequacy decision. For transfers from the EEA or UK, we rely on Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where applicable), supplemented by additional safeguards where necessary. You can request a copy by contacting privacy@kidbrief.app.
08
Changes to this policy
We may update this policy as the product evolves or as laws change. If we make material changes, we will notify you in the app and update the effective date at the top of this page. Where required by law, we will ask for your consent before applying material changes to how we process your data.
09
Contact us
Questions, concerns, or requests about this policy or your personal data:
Email: privacy@kidbrief.app
Address: Pomet, Inc. · 2261 Market Street STE 76796, San Francisco, CA 94114
Pomet, Inc. is the data controller for the personal data we hold — shared briefs, text sent for AI processing, waitlist addresses, and usage data. For the profiles stored on your own device, you are the one who decides what is recorded and who sees it.