My Kid Space is a parental-control app for iPhone. Almost everything you do in the app stays on your device or in your own private iCloud. The only data that leaves your device is anonymous usage analytics — which you can turn off in Settings — and purchase information needed to run your subscription. We have no backend that stores your profiles or your children's data, and by design we cannot access, read, or retrieve them. This policy explains what is processed, by whom, and your rights.
My Kid Space (the “app”, “we”, “us”) is operated by Pablo Iturralde, an independent developer based in Spain. For any privacy question or request, contact us at hi@mykidspace.app.
Where data-protection law (such as the EU/UK GDPR) applies to you, we act as the data controller for the limited processing described here. We have not appointed a Data Protection Officer, which is not required at our scale.
It helps to understand how the app is built, because it shapes everything below:
| Data | Why | Where it lives | Legal basis (GDPR) |
|---|---|---|---|
| Apple sign-in identifier (Sign in with Apple) | To identify you as the account owner. No email or password collected. | Your device Keychain + your iCloud | Performance of a contract |
| Child profile — first name/nickname, age or age range, emoji avatar | To set up and recognize each child's session rules. | Your device + your iCloud only — never sent to us | Performance of a contract |
| Session & rule settings — allowed app selections, time limits, session history | To run and shield sessions and show you history. | Your device + your iCloud only | Performance of a contract |
| Subscription data — purchase/receipt, status, app-specific user ID, basic device info (via RevenueCat) | To provide, restore, and manage your subscription. | RevenueCat (our processor) + Apple | Contract; legal obligation (records) |
| Anonymous usage analytics — which screens are viewed and which features are used (via PostHog) | To understand how the app is used and improve it. Not linked to your identity. | PostHog (EU-hosted) — optional, off-switch in Settings | Consent |
We do not collect: child contact details, photos, precise location, browsing or message content, or advertising identifiers (no IDFA). The only analytics we collect is anonymous and optional — see Section 8. There are no child accounts. We do not profile you and make no automated decisions with legal or similarly significant effects.
The app uses Apple's Family Controls, ManagedSettings, and DeviceActivity frameworks to block and allow apps during a session. Because of how Apple designed these:
Face ID (or your device passcode) confirms a parent is present before a session can end. Matching happens entirely in iOS, in the device's Secure Enclave. Your biometric data never leaves your device and is never accessible to us or Apple. The app receives only a success/failure result.
Synced data is stored in your iCloud private database and encrypted by Apple in transit and at rest; where you enable Apple's Advanced Data Protection it is end-to-end encrypted so not even Apple can read it. This data is also governed by Apple's Privacy Policy and the iCloud Terms. Apple acts as our storage processor, and you control this data through iOS Settings.
We share data with only three companies, each as our service provider:
We use no advertising and no tracking SDKs, and we do not track you across other companies' apps or websites. The only analytics we use is the anonymous, optional product analytics described in Section 8. We never sell or share your personal information (including any about your children), and we do not use it for advertising.
To understand how My Kid Space is used and to improve it, we collect anonymous product-analytics events — for example, which screens are viewed and which features are used — through PostHog, a third-party analytics processor. This data is hosted in the European Union.
This information is not linked to your identity and is never used to track you across other companies' apps or websites. We do not send PostHog your name, email, Apple ID, or any information about your child — the apps you allow are represented by anonymous system tokens that never leave your device. We use no advertising identifiers (IDFA).
You can turn this off at any time in the app under Settings → Share anonymous usage data. When it is off, no analytics are collected or sent.
We also receive purchase information through RevenueCat and Apple to manage your subscription. This is used only to operate the app and is never used to track you.
All payments are processed by Apple through the App Store. Neither we nor RevenueCat ever receive your card numbers.
RevenueCat is based in the United States. If you use the app from the EU, UK, or elsewhere, your limited subscription data may be processed in the U.S. under appropriate safeguards (such as Standard Contractual Clauses via RevenueCat's data-processing agreement).
Because your data lives on your device and in your own iCloud, it persists until you delete it — by removing a profile in the app, deleting the app, or removing the data from iCloud. We hold no copy to delete on our side. RevenueCat retains subscription records as needed to provide the service and meet legal/accounting obligations.
Depending on where you live, you may have rights to access, correct, delete, restrict, port, or object to processing, and to withdraw consent where processing relies on it.
Most rights are self-service in this app, by design: because your data sits on your device and in your own iCloud that we cannot read, you can view, edit, and delete profiles and history directly in the app, sign out, or delete the app. For data held by our subscription provider, or any request we can action, contact us at hi@mykidspace.app and we will respond as required by law. EU/UK users may also lodge a complaint with their local supervisory authority.
My Kid Space is designed for parents to set up and manage. The only information about a child is what a parent enters — a first name or nickname, an age or age range, and an emoji avatar. That information stays on the parent's device and in the parent's own iCloud; we never receive it, never share it, and never use it for advertising or analytics. A parent can delete a child's profile at any time in the app. We do not knowingly collect personal information directly from children, and the app is not intended to be operated by a child.
For California residents: the categories of personal information are described in Section 3; the only third parties that receive information are the service providers in Section 7; you can review and change your information directly in the app; and we will note material changes as described in Section 17. We do not “sell” or “share” personal information as defined under California law, and we do not track users across third-party websites or services — so we do not receive or respond to “Do Not Track” signals.
We rely on Apple's platform protections — the device Keychain, the Secure Enclave, on-device storage, and iCloud encryption. No method is perfectly secure, but keeping data on your device and in your own iCloud, with no central server of ours to breach, is a deliberate part of how we protect you.
You can delete your data at any time: remove individual child profiles in the app, sign out of Sign in with Apple, and/or delete the app. To fully remove synced data, delete the app's data from iCloud in iOS Settings. Because we hold no server-side copy, these steps remove the data we could be associated with.
If we make material changes, we will update the “Last updated” date above and, where appropriate, describe the change in the app or on this page. Continued use after an update means you accept the revised policy. Questions or requests: hi@mykidspace.app. This policy is governed by the laws of Spain.