KnowGately Privacy Policy

Effective date: 20 August 2026. Consent disclosure version: 2026-08-30-p9.

KnowGately is a parent-controlled learning app for children. Parents choose exactly which videos and pages their child can open; the child sees only that. This page explains, in plain language, what data we handle and why. It is written for parents, not lawyers — and it says the same things as the consent disclosure every parent reads and agrees to before any child data is collected.

Looking for the shorter version written for a child? Read the child-friendly privacy notice.

YouTube API Services

When the reviewed YouTube integration is enabled, KnowGately uses YouTube API Services to let a parent preview and assign specific public YouTube videos, playlists, and channels. It uses the read-only YouTube Data API v3 methods channels.list, playlists.list, and playlistItems.list, plus the YouTube IFrame Player API for playback. KnowGately does not provide YouTube search or take write actions such as uploads, comments, likes, or subscriptions.

Requests use a server-side API key, not Google OAuth. KnowGately does not access a parent or child’s Google or YouTube account, YouTube credentials, subscriptions, private playlists, or YouTube watch history. The public API data used is limited to identifiers, titles, playlist or channel relationships, positions, publication timestamps, and availability status needed to preview and play content selected by the parent.

A parent’s own selections remain family curation until the parent deletes the resource, child, or account. Public titles, identifiers, relationships, positions, publication timestamps, and availability returned by YouTube API Services are revalidated by day 28. If they cannot be refreshed, KnowGately deletes them by day 29, before the 30-day policy limit. Short-lived public channel-feed data is cached for up to 15 minutes. Deletion also removes the family’s stored YouTube identifiers and titles with the rest of its curation data.

Use of YouTube content is governed by the YouTube Terms of Service. Google explains its processing in the Google Privacy Policy. See KnowGately’s Terms of Service and account-deletion information.

1. Who we are

KnowGately is published by Maremma Studio, an independent developer based in Poland. Maremma Studio is the data controller for the data described on this page. For anything about this policy or your data, contact support@maremma.dev.

2. What we collect, and why

We collect only what is strictly necessary to run the service. If something is not listed here, we do not collect it.

Your parent account

Your email address and a secure sign-in identity, handled by our sign-in provider, Clerk. We use it to create and secure your account, verify it is really you (this is our consent method — see section 3), and reach you about your account. The parent is the only account holder.

Your child’s profile

A display name you choose (a nickname is fine — it does not have to be their legal name), their date of birth (to record the age information you provide; every child profile currently receives the same child-directed protections), and their timezone (so daily learning limits reset at the right local midnight). That is the entire child profile. We do not collect a child email, phone number, address, photo, precise location, or contacts.

The content you curate

The learning structure you build yourself: subjects, the YouTube videos, web pages, and documents you assign, the topics you group them into, the YouTube channels you approve, and the time rules and prerequisites you set. This is data you author, not data we gather about your child.

Paired devices

For each device you pair for your child: its platform (Android or Windows), an optional non-unique manufacturer/model label, when it was paired, when it last checked in, and whether it is active or revoked — so you can distinguish and manage the devices linked to your child. The model label is never used as an identifier or authorization signal. The server also stores a one-way hash of a device security credential; it does not store the secret itself.

Device storage, cookies and similar technology

KnowGately and service providers acting on our behalf store, access, or collect information directly or indirectly on or from users’ devices and browsers using cookies and similar technologies. Clerk uses authentication cookies to keep the parent signed in securely. The parent website uses a locale cookie and browser local storage for language and theme preferences, plus temporary session storage for a safe return after sign-in and an account-deletion receipt. The Kids app uses encrypted device storage for its pairing credential, device identity, lock state, and playback-resume state. These technologies are used only to provide, secure, and remember the service; they are not used by KnowGately for advertising or cross-site tracking.

When an embedded YouTube player is loaded or used, Google and YouTube may receive network and device information and may place, access, or recognize cookies or similar technologies under the Google Privacy Policy. KnowGately uses YouTube’s privacy-enhanced embed host, but that does not eliminate provider processing when the player loads or playback begins. KnowGately does not send child profile fields or KnowGately learning analytics to YouTube.

Learning activity

The core purpose of KnowGately is to show you how your child is actually learning — not just screen time. The kids app records, per resource: time spent, whether it was completed, how much of a video was genuinely watched, seek and skip behavior, rewatch activity, and blocked navigation attempts (when your child tries to leave the area you approved, the attempt is blocked and the attempted address is recorded for you — it is shown only to you in your dashboard and never shown back to the child). These events are used for your reports and, if you enable the dashboard inbox, to create the completion, limit and weekly-summary notices described below.

Operational records and parent inbox

We store short-lived pairing codes, child-session records and duplicate-prevention receipts, plus daily report rollups derived from learning events. Resource checks store when assigned content was last checked and whether it was ready, unreachable, or disabled. Each adult must explicitly enable the private dashboard inbox. It can then show consequence-focused device offline/revoked, unavailable resource, completed plan, approaching limit, cleanup retry and weekly summary notices, plus an optional calm no-activity reminder. Notices include an internal recovery link and are kept for up to 90 days. This signed-in dashboard inbox is not email, browser push, mobile push, SMS or child-device push; none of those delivery channels is available. We also keep the first server-confirmed times the family verifies the parent account, adds a child, assigns content, pairs a device, receives an authorized play, shows activity, and returns after seven days. These account-level timestamps keep the setup checklist resumable and measure first value. They contain no child, content, device, URL, event-payload, advertising, or profiling identifier.

Our reasons under data-protection law

  • Parental consent covers the child profile, learning activity and child-directed operation. You can withdraw it at any time.
  • Providing the service covers the parent account, curation and settings you ask us to keep.
  • Legitimate security interests cover access logs, device authentication, duplicate prevention and abuse protection.
  • Legal obligations and legal claims cover the limited pseudonymous consent and erasure evidence described below.

Parent account, child profile, timezone, curation and device pairing are required to provide the controlled learning service. Curation can include private PDF and image bytes uploaded by the parent. Parent dashboard inbox is optional, off until each adult opts in, and can be turned off again. If required data or consent is not provided, child collection and playback stay blocked; there is no penalty beyond the service not being available.

What we never do

  • KnowGately does not serve advertising and embeds no advertising SDKs. If YouTube playback is enabled after policy review, standard YouTube embeds may show YouTube-served ads.
  • We never sell your data or your child’s data.
  • We never share child data with third parties for their own use, and no third party profiles your child through KnowGately.
  • No profiling of children for automated decision-making — the analytics exist to inform you, not to make decisions about your child.
  • Children have no accounts and no logins — a kid device is paired by you, once. There is no chat, messaging, or social feature, so your child cannot be contacted through KnowGately.

We collect no child data until a parent has given verifiable consent. Our consent method is email-plus: you verify control of your email address, then give explicit consent against a plain-language disclosure of exactly what is collected — the same facts as this page. If consent is missing, the system blocks: it will not create a child profile or record a single analytics event.

You stay in control afterwards. From your dashboard’s Data & privacy section you can review everything we hold about your child, correct profile details, withdraw your consent (collection stops and every device is revoked the moment you do), and delete an individual child or your entire account.

Family data is erased. Deleting a child or your account runs an audited erasure: the child profile, every device record, every subject, resource, topic, and channel you created, and all learning-activity events and report rows are removed. Pseudonymous hashes, timestamps and deletion counts survive for up to six years to prove erasure, stop a stale identity from recreating the account, and handle provider retries or legal claims. They contain no child profile, curated content or learning activity.

4. Where the data lives

All child data — profiles, your curated content, device records, and learning activity — is stored in the European Union: our database runs in Frankfurt, Germany, and our backend runs in an EU region.

The one exception is parent sign-in data: your email address and sign-in credentials are processed by Clerk, our authentication provider, inside Clerk’s own infrastructure in the United States under GDPR transfer safeguards (Standard Contractual Clauses / the EU-US Data Privacy Framework). Clerk holds parent identity data only — children have no accounts anywhere, so no child data ever reaches Clerk.

5. How long we keep it

  • Active profile, consent, curation, private uploaded files, settings and device rows: until the resource, child or account is deleted.
  • Learning events: up to 395 days.
  • Blocked-navigation attempts and attempted addresses: up to 90 days.
  • Private parent-dashboard inbox notices: up to 90 days.
  • Expired or redeemed pairing codes and event duplicate-prevention receipts: up to 30 days.
  • Completed identity-provider and private-object deletion jobs: up to 90 days after completion.
  • Pseudonymous erasure audit and erased-identity suppression records: up to six years.

Daily reports are derived from retained events. Deletion refreshes those reports so deleted family data does not remain there.

6. Your data rights

Depending on the request and applicable law, you can ask to access, export, correct or erase data; restrict or object to processing; and receive portable data. You can withdraw parental consent at any time without affecting processing that was lawful before withdrawal. We do not make solely automated decisions about children.

Use Data & privacy in the dashboard or email support@maremma.dev. We may need to verify that the requester controls the parent account. You may also complain to Poland’s supervisory authority, the President of the Personal Data Protection Office (UODO), or the authority where you live or work.

7. Third parties we rely on

These providers process data strictly on our behalf to run the service — they are not permitted to use it for their own purposes:

  • Clerk — parent sign-in and account security (parent identity data only).
  • Vercel — hosts this parent web dashboard.
  • Railway — hosts our backend server (EU region).
  • Neon — our database (Frankfurt, EU).
  • Cloudflare R2 — private PDF/image object storage using its European Union jurisdiction. Objects have no public URL and are delivered only after paired-device authorization.

External content: The YouTube API Services compliance review for the demonstrated KnowGately client completed on 20 August 2026. Parent-assigned YouTube videos are enabled. General HTTPS webpages and Vimeo-as-webpage remain disabled for the public release while their physical-containment review remains open. External content loads directly from the selected provider, not through KnowGately storage; the provider receives network and device information and may use cookies or similar technologies under its own privacy terms. Standard YouTube embeds may show YouTube-served advertising. KnowGately does not send child profiles or KnowGately learning analytics to those providers.

8. Changes to this policy

If we ever materially change what we collect or why, we bump the versioned consent disclosure (currently version 2026-08-30-p9) and ask every parent to read and re-consent before the change takes effect — consent to an old version never silently covers new collection. We update this page and its effective date at the same time. Editorial fixes that do not change what is collected may refresh the date without requiring re-consent.

Questions? Write to support@maremma.dev.