KidGist ("we", "us", "our") is a tool that helps parents and guardians manage school and activity emails. This policy explains, in plain language, what data we collect, how we use it, who we share it with, and the choices and rights you have. It applies to our website, our web app at kidgist.com, and our mobile apps. Please read it alongside our Terms of Service.
KidGist is the data controller for the personal data described here. If you have any question about this policy or your data, contact us at contactkidgist@gmail.com.
KidGist is designed for and directed to parents and guardians — adults aged 18 or over. It is not directed to children, and children may not create accounts or use the service. We do not knowingly collect personal information directly from a child.
To help you organize your family, you (the parent) may choose to enter limited information about your children — a first name or nickname, a grade or year level, and a color you assign to them. You provide this yourself; we never collect it from the child, and we never ask children for information. We explain how we protect this information in the "Children's information" section below.
Where data-protection law such as the UK GDPR or EU GDPR applies, we rely on the following legal bases:
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are never shared with any third party, and are never sold, rented, or transferred to data brokers or lead generators under any circumstances.
Your mobile number is used only to deliver the reminders and summaries you asked for. The single exception is our messaging carrier, Twilio, which receives your number solely to deliver those messages to your phone and may not use it for any other purpose. Full details are on our text message reminders page.
Running KidGist requires us to share certain data with the service providers below. They process data only on our instructions, under contract. We do not sell data to anyone. This excludes text messaging originator opt-in data and consent, which is not shared with any third party for marketing or promotional purposes.
Google Gemini AI
The subject and body of each email or document you send is passed to Google's Gemini API to extract event dates, titles, and action items. We send only the content you choose to forward — we do not connect to your inbox. Google processes this content to provide the API and, per its terms for paid API use, does not use it to train its models.
Resend
Inbound emails are received via Resend's email routing, and Resend delivers our outbound emails (reminders, summaries). Email content passes through Resend's infrastructure in transit.
Supabase
All app data (accounts, children, emails, calendar events) is stored in a PostgreSQL database hosted by Supabase in the United States (AWS us-east-1).
Firebase (Google)
If you enable push notifications, your device token is registered with Google Firebase Cloud Messaging to deliver alerts.
Twilio
If you opt in to SMS reminders, your phone number and reminder text are sent to Twilio to deliver the message. If you never enable SMS, we do not share a phone number with Twilio. Full detail of what we send, how often, and how to stop is on our text message reminders page.
Vercel
KidGist is hosted on Vercel. Web requests and server-side processing run on Vercel's infrastructure.
If you connect a Google feature, here is exactly what we receive and who it is shared with:
Google user data is shared only with the infrastructure providers strictly necessary to run the service — Supabase (storage) and Vercel (hosting), both listed above and both bound by contract to process it only on our instructions. We never sell Google user data, never use it for advertising, and never share it with data brokers.
The only content we send to an AI model is the subject and body of emails/documents you choose to forward to your KidGist address, which Google Gemini processes to extract dates, titles, and action items. This is separate from, and never includes, the account name/email from Google Sign-In or any data from a connected Google Calendar described above.
Our use of any data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we do not use Google user data to train or improve any AI/ML model — ours or a third party's — and Google user data is never transferred to a third-party AI service for model training. We use Google Gemini directly through Google's own API under its paid-tier terms, not through any third-party aggregator or gateway.
KidGist's data is stored and processed in the United States. If you use KidGist from the UK, EU, Australia, Canada, or elsewhere, your data is transferred to and processed in the US and by the providers listed above. Where required, these transfers are covered by appropriate safeguards such as the providers' Standard Contractual Clauses and, where applicable, the EU–US and UK Data Privacy Framework commitments.
We know school emails can contain sensitive information about your children. Here is how we handle email content:
KidGist is intended for parents and guardians, not children, and is not directed to children under 13. We do not knowingly collect personal information from children. The only information about a child in KidGist is what you, the parent, choose to add — a first name or nickname, a grade level, a color, and whatever appears in the school emails you forward.
You control this information at all times: you can view, edit, or delete a child's profile in the app, and deleting your account removes it entirely (see below). We do not require a child's full name, address, photo, or contact details, and we ask you not to add more about your child than you need to. If you believe a child has provided us personal information directly, or you want a child's information reviewed or removed, email contactkidgist@gmail.com and we will act promptly.
If you invite a family member to share your KidGist account, they will be able to see all children, calendar events, and emails associated with your family account. You can remove a family member at any time in Settings → Family.
Depending on where you live, you have some or all of the following rights. To exercise any of them, use the in-app tools below or email us — we will respond within 30 days and will not charge you or discriminate against you for asking.
You can permanently delete your account at any time — no email or waiting required. Go to Settings → Family → Delete your account, type DELETE to confirm, and we immediately remove your profile, notification settings, phone number, device tokens, and connected-calendar tokens.
We keep your data for as long as your account is active so the service works. When you delete your account (or ask us to), personal data is removed from live systems immediately and from backups within 30 days. We may retain anonymised, aggregated statistics that cannot identify you, and any records we are legally required to keep.
Passwords are hashed and never stored in plain text. Data in transit is encrypted via HTTPS. Access to your data is restricted to your family account and a small number of authorized staff. No system is perfectly secure — if you discover a vulnerability, please email contactkidgist@gmail.com.
We may update this policy from time to time. If we make material changes, we will notify you by email. The date at the top of this page reflects the most recent update.
Questions, requests, or concerns about your data? Email us at contactkidgist@gmail.com.