Privacy

“We cannot read your data. That's not a promise, it's a technical impossibility.” Here is exactly what that means.

Without Premium: we know nothing about you

Co-Kids has no account, no sign-up, no server for your expenses. They exist only in your browser, on your device. Your WhatsApp conversation is read locally, never sent. The free app's only network call is the update check: a version number is downloaded, nothing is sent — and it can be turned off in “About”.

With Premium: we store data we cannot read

If you activate Premium, the calendar, the approvals and the documents you choose to share pass through our server to reach the other parent. But they are encrypted on your device, before they leave, with a key derived from your household password — a password our server never receives.

In concrete terms, our server stores unreadable files: it knows neither your children's names, nor the contents of your calendar, nor the names or contents of your documents. What we know about a Premium household: an anonymous identifier, the billing e-mail, file sizes and dates. That's all — and it's verifiable: the app's code can be read by anyone who opens the file.

Two things are never synced, even with Premium, by choice: your expenses and your WhatsApp conversation. They stay 100% on your devices.

How does the encryption work?

  1. The app generates a 20-character household password. You pass it to the other parent yourself — it never goes through us.
  2. On each device, this password is turned into an encryption key (600,000 PBKDF2 iterations, a banking standard). This key never leaves the device.
  3. Everything that goes to the server — calendar, approvals, documents — is first encrypted on your phone or computer (AES-256, the encryption used by banks and armies). The server only receives unreadable data.
  4. Each device signs what it sends (ECDSA electronic signature): no one can write in your place, or delete the other parent's documents.

The accepted flip side of this protection: if you lose the household password, no one — not even us — can decrypt what is stored. You then create a new household and re-send the documents from your local copies.

The site you are reading right now

This site uses no cookies, no trackers, no audience-measurement tools. When you download the app, we ask for your country and city — you declare them yourself, and that's what feeds our world map. Nothing else is collected: no name, no e-mail, no IP address kept, no identifier created. The city-typing assistance queries a geography service (geo.api.gouv.fr in France, photon.komoot.io elsewhere) with the letters you type, nothing more.

Payment

Premium payment is handled by Stripe, a certified payment provider: your bank card is entered with Stripe, never in Co-Kids or on our servers. We only see the payment confirmation and the billing e-mail.

In short

The best guarantee of privacy isn't our goodwill: it's the architecture. We built Co-Kids so that we cannot access your data. A doubt, a question? You can — the creator himself replies.