Security & Data Protection Declaration
Security is part of the product, not a decoration.
KinderNest.kids is designed to handle sensitive childcare-related information, including information about children, parents, guardians, providers, employees, schedules, attendance, incidents, authorized pickup and drop-off contacts, and communication history.
Last updated: May 28, 2026
We treat childcare data as sensitive by default. This page explains the security principles behind KinderNest.kids and the protections being built into the system.
Protect children first
Child-related information is sensitive by nature. KinderNest.kids is designed so that child records are only available to authorized users with a legitimate reason to access them. Parents and guardians should only see information for their own child or children.
Authorized pickup and drop-off contacts should not automatically receive access to private child or family records.
Provider ownership and control
Childcare providers are responsible for the records they create and manage. KinderNest.kids is designed so that a provider controls the child and family records associated with their childcare business.
System administrators may provide support, but administrative access should be limited, logged, and used only when necessary.
Role-based access
Users should only have access to the information needed for their role.
- Providers can manage their childcare records.
- Parent and guardian users can access appropriate information about their own child.
- Authorized pickup and drop-off contacts may be verified for pickup and drop-off purposes without receiving broader family record access.
- System administrators may have limited support access, but not unrestricted editing access to child records through the normal app.
Auditability
KinderNest.kids is being designed with audit records so important actions can be tracked.
- Who made a change.
- What was changed.
- When it was changed.
- Where the action came from.
- Why the change was made, when applicable.
No casual deletion
KinderNest.kids is designed around soft deletion rather than casual hard deletion. Records may be removed from normal views but retained for legal, audit, operational, or licensing-related reasons. Hard deletion of sensitive childcare data should be rare and may require legal review or court order depending on the situation.
Encryption and secure transmission
KinderNest.kids is intended to use secure encrypted connections when information is transmitted between users and the system. Where sensitive files or images are used, KinderNest.kids prioritizes encryption and access control so private information is not exposed unnecessarily.
Limited administrative access
Administrative access is powerful and should be rare. KinderNest.kids administrative tools are intended for support, system management, troubleshooting, and security oversight, not for casual browsing or editing of provider data.
Administrative access should be logged and reviewed.
Separation of roles
KinderNest.kids separates important roles, including provider, parent or guardian, authorized pickup and drop-off contact, employee or helper, and system administrator.
These roles should not be blended casually. A person may have one role for one child and a different role for another child. The system should preserve those boundaries.
What KinderNest.kids does not do
- KinderNest.kids does not sell child, parent, guardian, or provider personal information.
- KinderNest.kids does not use child records for advertising.
- KinderNest.kids does not allow children to create accounts or directly use the system.
- KinderNest.kids does not replace provider judgment, licensing guidance, legal advice, or official government resources.
Provider responsibility
- Enter accurate information.
- Keep login credentials secure.
- Manage authorized users carefully.
- Review records for accuracy.
- Follow licensing rules that apply to their childcare business.
- Maintain backup or alternate records during beta testing.
- Report suspected unauthorized access or data issues promptly.
Beta testing notice
During beta testing, KinderNest.kids is still under development. Features may change, screens may change, data structures may change, and beta data may need to be cleared, migrated, or rebuilt.
Beta testers should not use KinderNest.kids as their only official recordkeeping system until the product is production-ready.
Reporting a security concern
Security concerns can be reported to Wayne Pfeffer at wayne.pfeffer@kindernest.kids. Please include what happened, the date and time noticed, the page or feature involved, screenshots if available, and whether any child, parent, guardian, or provider information may have been affected.
