Privacy Policy
Last updated: April 11, 2026
Section 1
Introduction
KidForge protects your family's data under GDPR. By using KidForge, you agree to this policy.
KidForge is a family fintech platform that helps parents teach children about money through gifting, saving, earning, and supervised investing. We take the privacy and security of your family’s data extremely seriously — especially when it comes to children.
This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and what rights you have. It applies to all users of the KidForge platform, including parents, guardians, children, and gift-giving relatives.
Section 2
Definitions
Clear explanations of all the terms used in this document.
To help you understand this policy, here are the key terms we use throughout:
- Parent
- — The adult who creates and manages a KidForge family account. This includes guardians and other legal caregivers.
- Child
- — A minor user (typically ages 6–18) who uses KidForge under parental supervision.
- Family
- — The group of users connected under one parent account, including the parent, children, and optionally invited relatives.
- Personal Data
- — Any information relating to an identified or identifiable natural person, as defined by GDPR Article 4(1).
- Service
- — The KidForge platform, web application, and all related services we provide.
Section 3
Data Controller
KidForge is operated by [Company Name], based in Lisbon, Portugal.
The data controller responsible for the processing of your personal data is:
Section 4
Data We Collect
We collect only what's needed to provide the service. Less for kids than for parents.
We follow the principle of data minimisation — we only collect what is strictly necessary to operate KidForge. We deliberately collect less data from children than from parents.
Section 5
How We Use Your Data
To provide the service, secure your account, and improve KidForge — never to sell or advertise.
We use your personal data for specific, legitimate purposes only. We never sell your data or use it for targeted advertising.
Section 6
Legal Basis (GDPR Article 6)
We process data based on contract, legitimate interest, consent, and legal obligations.
Under GDPR, we must have a valid legal basis for processing your personal data. Here are the bases we rely on:
Section 7
Children’s Data — Special Protection
Children’s data has the strongest protection. Parents control everything.
KidForge is designed for use by children, and we take special care to protect their data. We comply with GDPR Article 8 (conditions applicable to child’s consent in relation to information society services).
Section 8
Data Sharing
We never sell your data. We share only with essential service providers.
We do not sell, rent, or trade your personal data. We share data only with the following categories of service providers, under strict contractual obligations:
Section 9
International Data Transfers
Your data stays primarily in the EU. International transfers use approved safeguards.
KidForge stores data primarily in the European Union via Supabase (EU region). When data is transferred outside the EU, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where available (e.g., EU-US Data Privacy Framework)
- Data Processing Agreements (DPAs) with all service providers
Section 10
Data Retention
We keep data only as long as necessary. Closed accounts are deleted within 30 days.
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy.
Section 11
Your Rights Under GDPR
You have full rights over your data: access, correct, delete, export, and complain.
Under GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of all data we hold about you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — request deletion of your data (“right to be forgotten”)
- Right to restrict processing — limit how we use your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — withdraw consent at any time, without affecting prior processing
- Right to complain — lodge a complaint with a supervisory authority (CNPD in Portugal)
Section 12
Security Measures
We use encryption, hashing, RLS, and 2FA to protect your data.
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data is transmitted over TLS 1.3
- Encryption at rest: Database encryption using AES-256
- Password hashing: bcrypt with salt rounds, never stored in plaintext
- Row Level Security (RLS): Database policies ensure users can only access data from their own family
- PIN protection: Parent accounts require a PIN for sensitive operations
- Audit logging: Immutable, append-only audit trail of all financial and administrative actions
- Input validation: All inputs validated with Zod schemas to prevent injection attacks
- Regular security reviews: Periodic code audits and dependency vulnerability scans
For a comprehensive overview of our security practices, see our Security page.
Section 14
Contact Us
Questions about privacy? Email privacy@kidforge.com
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Email: privacy@kidforge.com
Data Protection Officer: dpo@kidforge.com
Address: [Company Address], Lisbon, Portugal
You also have the right to lodge a complaint with the Portuguese supervisory authority:
CNPD — Comissão Nacional de Proteção de Dados
Website: www.cnpd.pt