Privacy Policy
Last updated: 3 July 2026
1. Who we are
Kibo (the "Service") — the Kibo Android application (com.pastelify.kibo) and the
kibokid.com website — is operated by PT. Pastelify Digital Teknologi ("we", "us").
You can reach us at [email protected].
This policy explains what information we collect, why we collect it, and the choices you have. It is written for parents: Kibo is a family app, and children use it only under an account that a parent or legal guardian creates and controls.
2. Scope
This policy covers the Kibo app and the kibokid.com website. The website is a static informational page and sets no cookies and runs no analytics or tracking scripts.
3. What we collect
- Parent account: your name, email address, and a securely hashed password — or, if you sign in with Google, the basic profile (name, email) Google shares with us.
- Child profile: a first name or nickname, age, a chosen avatar or character, and a 4-digit PIN. These are created and managed entirely by the parent. Children are never asked for an email address or phone number. A child's device joins the family through a one-time 6-digit invite code generated by the parent.
- Activity data: tasks, task check-ins, stars earned and spent, streaks, badges, and reward claims — the data needed to make the app work.
- Check-in photos: if a parent turns on photo proof for a task, the child can take or attach a photo when completing it (see section 5).
- Push notification tokens: a device token (Firebase Cloud Messaging) so we can deliver reminders and notifications you configure.
- Server logs: standard technical logs of API requests (such as timestamps and request paths) used for security and troubleshooting.
We do not collect payment information (the app is currently free), precise location, contacts, or advertising identifiers.
4. Children's privacy
Kibo is designed for family use with children roughly aged 7–12, and we treat children's data with particular care:
- Only a parent can create a family, add a child profile, and connect a child's device.
- Consent for a child's use of Kibo is given by the parent, who can review, edit, deactivate, or request deletion of the child's data at any time.
- Children cannot make their profile or activity visible to anyone outside their own family.
- We show no advertising and use no third-party analytics or tracking in the app.
5. Photos
Photo proof exists so a parent can see that a task was really done. Photos are uploaded to our storage provider (Supabase Storage) and shown to the parents in the same family for review.
Please note: photos are currently stored at unguessable web addresses that are technically accessible to anyone who holds the exact link. We do not publish these links anywhere, and they cannot be discovered by browsing; still, treat photo proof as convenient evidence, not as a private vault. A photo is deleted from storage when the related check-in is declined or removed, and when the associated data is deleted on request.
6. How we use your data
- To operate the Service: sync tasks, stars, badges, and rewards across your family's devices.
- To send reminders and notifications that you or your family configure.
- To send account emails (such as verification codes and password resets).
- To keep the Service secure and diagnose problems.
We show no ads, we never sell your data, and we run no third-party analytics or tracking.
7. Who processes your data
We use a small number of service providers to run Kibo:
- Supabase — database and photo storage.
- Google — optional Google sign-in, and Firebase Cloud Messaging for push notifications.
- Resend — transactional email (verification codes, password resets).
- Our own servers — the Kibo API that powers the app.
These providers may store data on servers located outside Indonesia. Where that happens, we take reasonable steps to ensure your data receives an adequate level of protection.
8. Retention and deletion
We keep your family's data for as long as your account exists. Deactivating a child in the app stops their access and reminders but does not delete their data — so you can reactivate them later.
To delete your account and your family's data, email [email protected] from your registered address. We will delete the data within 30 days, except where we are legally required to keep specific records.
9. Security
Data travels over encrypted connections (TLS). Passwords are stored hashed, never in plain text. Access to production systems is restricted. No system is perfectly secure, so we cannot promise absolute security — but we work to protect your family's data as if it were our own.
10. Your rights
Under Indonesia's Personal Data Protection Law (UU No. 27/2022) and comparable laws elsewhere, you may request access to, correction of, or deletion of your personal data, and you may withdraw consent for your child's use of the Service at any time. Contact [email protected] to exercise these rights. You also have the right to lodge a complaint with your data protection authority.
11. Changes to this policy
If we change this policy in a meaningful way, we will update the date at the top and, for significant changes, notify you in the app or by email. Continued use of the Service after a change means you accept the updated policy.
12. Contact
PT. Pastelify Digital Teknologi
Email: [email protected]