KnowGately Privacy Policy
Effective date: 29 July 2026. Consent disclosure version: 2026-07-03.
KnowGately is a parent-controlled learning app for children. Parents choose exactly which videos and pages their child can open; the child sees only that. This page explains, in plain language, what data we handle and why. It is written for parents, not lawyers — and it says the same things as the consent disclosure every parent reads and agrees to before any child data is collected.
1. Who we are
KnowGately is published by Maremma Studio, an independent developer based in Poland. Maremma Studio is the data controller for the data described on this page. For anything about this policy or your data, contact support@maremma.dev.
2. What we collect, and why
We collect only what is strictly necessary to run the service. If something is not listed here, we do not collect it.
Your parent account
Your email address and a secure sign-in identity, handled by our sign-in provider, Clerk. We use it to create and secure your account, verify it is really you (this is our consent method — see section 3), and reach you about your account. The parent is the only account holder.
Your child’s profile
A display name you choose (a nickname is fine — it does not have to be their legal name), their date of birth (required by COPPA so we can apply the correct age protections), and their timezone (so daily learning limits reset at the right local midnight). That is the entire child profile. We do not collect a child email, phone number, address, photo, precise location, or contacts.
The content you curate
The learning structure you build yourself: subjects, the YouTube videos, web pages, and documents you assign, the topics you group them into, the YouTube channels you approve, and the time rules and prerequisites you set. This is data you author, not data we gather about your child.
Paired devices
For each device you pair for your child: its platform (Android or Windows), when it was paired, when it last checked in, and whether it is active or revoked — so you can see and manage the devices linked to your child.
Learning activity
The core purpose of KnowGately is to show you how your child is actually learning — not just screen time. The kids app records, per resource: time spent, whether it was completed, how much of a video was genuinely watched, seek and skip behavior, rewatch activity, and blocked navigation attempts (when your child tries to leave the area you approved, the attempt is blocked and the attempted address is recorded for you — it is shown only to you in your dashboard and never shown back to the child). These events are used only for your reports, and nothing else.
What we never do
- No advertising — none, and no ad SDKs in the kids apps.
- We never sell your data or your child’s data.
- We never share child data with third parties for their own use, and no third party profiles your child through KnowGately.
- No profiling of children for automated decision-making — the analytics exist to inform you, not to make decisions about your child.
- Children have no accounts and no logins — a kid device is paired by you, once. There is no chat, messaging, or social feature, so your child cannot be contacted through KnowGately.
3. Parental consent (COPPA and GDPR-K)
We collect no child data until a parent has given verifiable consent. Our consent method is email-plus: you verify control of your email address, then give explicit consent against a plain-language disclosure of exactly what is collected — the same facts as this page. If consent is missing, the system blocks: it will not create a child profile or record a single analytics event.
You stay in control afterwards. From your dashboard’s Data & privacy section you can review everything we hold about your child, correct profile details, withdraw your consent (collection stops the moment you do), and delete an individual child or your entire account.
Deletion is complete. Deleting a child or your account runs a full, audited erasure: the child profile, every device record, every subject, resource, topic, and channel you created, and all learning-activity events are removed, leaving no residual data. The only thing that survives is a count-only audit record proving the deletion happened — it contains no personal data.
4. Where the data lives
All child data — profiles, your curated content, device records, and learning activity — is stored in the European Union: our database runs in Frankfurt, Germany, and our backend runs in an EU region.
The one exception is parent sign-in data: your email address and sign-in credentials are processed by Clerk, our authentication provider, inside Clerk’s own infrastructure in the United States under GDPR transfer safeguards (Standard Contractual Clauses / the EU-US Data Privacy Framework). Clerk holds parent identity data only — children have no accounts anywhere, so no child data ever reaches Clerk.
5. How long we keep it
We keep the data described above for as long as your account exists and you keep the child in your account — that is what makes your reports useful over time. When you delete a child or your account, the data is erased completely, as described in section 3. We do not keep child data after you delete it.
6. Third parties we rely on
These providers process data strictly on our behalf to run the service — they are not permitted to use it for their own purposes:
- Clerk — parent sign-in and account security (parent identity data only).
- Vercel — hosts this parent web dashboard.
- Railway — hosts our backend server (EU region).
- Neon — our database (Frankfurt, EU).
YouTube playback: videos you assign play inside our gated player directly from YouTube, using YouTube’s privacy-enhanced (no-cookie) embed, with recommendations and autoplay-next disabled. We do not route video through our servers, and YouTube’s own privacy policy applies to that playback. Likewise, web pages you assign load directly from their own servers.
7. Changes to this policy
If we ever materially change what we collect or why, we bump the versioned consent disclosure (currently version 2026-07-03) and ask every parent to read and re-consent before the change takes effect — consent to an old version never silently covers new collection. We update this page and its effective date at the same time. Editorial fixes that do not change what is collected may refresh the date without requiring re-consent.
Questions? Write to support@maremma.dev.