## ⚠️ DRAFT — NOT FOR PUBLICATION
**This is an unexecuted draft prepared for review by licensed counsel admitted in the relevant
jurisdiction(s). It has not been reviewed or approved by an attorney. It must not be published on
kithlane.com, app.kithlane.com, or any other surface, and must not be relied on by JRSB Solutions,
LLC or by any family, until a licensed attorney has reviewed, corrected, and approved it.**
This draft was prepared by an AI assistant acting in a drafting-support role. An AI assistant is
not a lawyer, is not a substitute for a licensed attorney, and cannot give legal advice or form an
attorney–client relationship. Every bracketed placeholder must be resolved with real, verified
facts before review. Every legal citation and compliance date must be independently confirmed
against current official sources.
Companion document:
COUNSEL_REVIEW_NOTES.mdin this directory lists every open question, everyfact required from the founder, and the prioritized items an attorney must confirm before launch.
Kithlane Privacy Policy
Kithlane is a product of JRSB Solutions, LLC.
Effective date: [EFFECTIVE DATE] Last updated: [LAST UPDATED DATE] Version: [POLICY VERSION — e.g., 1.0]
Read this first
Kithlane is a private digital home for one family. Children use it. That single fact shapes everything below.
Here is the short version, in plain words:
- We sell subscriptions. We do not sell you. Kithlane makes money one way: families pay us. We
do not run advertising, we do not sell or share personal information, and we do not build advertising profiles of anyone — adult, teenager, or child.
- Your family's content belongs to your family. Photos, messages, pages, files, and events stay
inside your household. There is no public profile, no discovery feed, no follower list, and no way for a stranger to find your family here.
- We do not train AI models on your family's content. Not our models, not anyone else's.
- Kithlane staff cannot browse your family's content. Support starts with technical information
only. Looking at actual content requires a specific reason, a guardian's approval, a time limit, and a permanent record. There are two narrow exceptions — a serious safety emergency and valid legal process — and both are described below.
- You can take your family's content with you, and you can delete it.
- We collect as little as we can. We do not ask for a child's legal name. We do not collect
precise location. We do not use facial recognition. We do not collect a child's voice.
We also want to be honest about what this policy is not. It is not a promise that nothing can ever go wrong online. No product can promise that, and we will not pretend otherwise. What we can describe is exactly what we collect, why, how long we keep it, and who can see it. That is what the rest of this page does.
Summary table
This table is a plain-language map. The detailed sections below control if there is any conflict.
| What we collect | Why we collect it | How long we keep it | Who can see it |
|---|---|---|---|
| Guardian account information — name, email address, sign-in credentials, recovery method, country/state | To create and secure an adult account, send required notices, and let you sign in | While the account is active, then [RETENTION: GUARDIAN ACCOUNT — PROPOSED 30 days after household deletion; CONFIRM] | The guardian; other guardians in the household see name and role; Kithlane staff only under an audited support grant |
| Household settings and roles — family home name, chosen subdomain, member roles, child policy settings | To run the permission system that decides who can see what | While the household is active | Guardians in the household; staff only under an audited support grant |
| Child profile — display name or nickname, avatar, guardian-confirmed age band, guardian-set rules | To give the child an age-appropriate experience and enforce the guardian's rules | While the child profile exists, then deleted per the children's retention schedule below | Guardians in the household; the child; other household members only to the extent the guardian allows |
| Child device authorization — an opaque device credential, a local PIN or picture code, coarse device/browser type, session timestamps | To let a child sign in without an email address or password, and to let a guardian revoke a device instantly | While the device is authorized, plus [RETENTION: DEVICE RECORDS — PROPOSED 90 days after revocation; CONFIRM] | Guardians; Kithlane security staff for abuse investigation, in pseudonymous form |
| Family content — photos, videos, files, messages, posts, comments, reactions, pages, events, approved links | To store, display, and deliver the content to the household audience you chose | Until you delete it, plus a short recovery window and a backup expiry period (see Retention) | Only the household members included in the audience you selected. Not Kithlane staff, except under the narrow paths described below |
| AI Guide conversations — what a person types to a Guide and what the Guide answers | To answer the request and to check the answer against the household's rules | [RETENTION: AI TRANSCRIPTS — default off or short retention; guardian-configurable; CONFIRM DEFAULT] | The person using the Guide; guardians to the extent household policy allows; not used to train any model |
| Requests, approvals, and safety events — a child's request to open a link, a guardian's decision, flagged safety incidents | To operate the approval workflow and to respond to safety concerns | [RETENTION: REQUESTS — PROPOSED 12 months; SAFETY EVENTS — PROPOSED 24 months; CONFIRM] | Guardians; the child at an age-appropriate level; a small trained safety team sees the minimum excerpt necessary |
| Subscription and billing information — plan, billing status, last four digits and card brand as reported by our payment processor | To charge the subscription and provide receipts | As required by tax and accounting law, [RETENTION: BILLING — PROPOSED 7 years; CONFIRM] | The guardian who manages billing; Kithlane billing staff (billing data only, never household content); our payment processor |
| Support conversations — messages you send us and our replies | To answer your question and improve support | [RETENTION: SUPPORT — PROPOSED 24 months; CONFIRM] | Kithlane support staff; contains only what you choose to tell us |
| Security and audit records — who changed a role, who published a page, who opened a support grant, sign-in events, pseudonymous identifiers | To detect abuse, investigate incidents, and prove that staff access rules were followed | [RETENTION: AUDIT — PROPOSED 24 months, longer where a legal hold applies; CONFIRM] | Kithlane security staff; guardians can see the support-access history for their own household |
| Marketing website analytics — aggregate page views and referral source on kithlane.com | To understand whether our public pages explain the product well | [RETENTION: ANALYTICS — PROPOSED 14 months; CONFIRM] | Kithlane staff, in aggregate. This is never applied to child surfaces inside the app |
We never collect: advertising identifiers, precise geolocation, face templates or facial recognition data, a child's voice recording, a child's legal name (we do not ask for it), a child's full contact list or address book, or a child's browsing history outside Kithlane.
1. Who we are and how to reach us
Kithlane is operated by JRSB Solutions, LLC, a limited liability company organized under the laws of [STATE OF ORGANIZATION], with its principal place of business at [PRINCIPAL PLACE OF BUSINESS — FULL STREET ADDRESS].
For purposes of the Children's Online Privacy Protection Rule, JRSB Solutions, LLC is the operator of Kithlane. We are the only operator that collects personal information through Kithlane.
Privacy questions, requests, and complaints:
- Email: [PRIVACY EMAIL ADDRESS]
- Mail: JRSB Solutions, LLC, Attn: [PRIVACY CONTACT TITLE], [LEGAL NOTICE MAILING ADDRESS]
- In the app: Settings → Privacy → Contact us
Privacy contact / responsible person: [NAME AND TITLE OF PRIVACY CONTACT]
We answer privacy requests within the time limits required by the law that applies to you, and in any case we aim to respond within [RESPONSE TARGET — PROPOSED 10 business days; CONFIRM].
2. Who and what this policy covers
This policy covers:
- the Kithlane marketing website at kithlane.com;
- the Kithlane application at app.kithlane.com and any household subdomain or custom domain
connected to it;
- concierge setup, onboarding, and support services we provide to a household.
It does not cover:
- ops.kithlane.com, the internal staff console, which is not available to families;
- websites that a guardian approves for a child to visit. Those sites are operated by other
companies under their own privacy policies. When a child leaves Kithlane through an approved link, Kithlane does not control what that site collects or does.
Where Kithlane is available. At launch, Kithlane is offered only to households in the United States. [CONFIRM: US-ONLY LAUNCH.] We do not currently offer Kithlane in the European Economic Area, the United Kingdom, Switzerland, Canada, or elsewhere, and this policy is not written to satisfy those laws. If JRSB Solutions decides to make Kithlane available outside the United States, this policy and the underlying product must be re-reviewed first. See Section 16.
People this policy describes:
| Term | Who it means |
|---|---|
| Family Owner | The adult who created the household and holds final authority over it |
| Co-Guardian | An adult the Family Owner has given guardian authority |
| Guardian | Family Owner or Co-Guardian; the adult(s) legally responsible for a child |
| Trusted Adult | An invited relative or family friend with limited contribute or view rights |
| Teen Member | A household member in a teen age band with expanded personal controls |
| Child Member | A child profile created and governed by a guardian |
| Guide | A bounded AI assistant inside Kithlane that performs a specific, limited job |
| Support grant | A time-limited, guardian-approved permission that lets a named Kithlane staff member access a defined slice of a household for a stated reason |
3. What we collect, and where it comes from
We group information by where it comes from, because that is usually what people actually want to know.
3.1 Information an adult gives us directly
- Creating an account: name, email address, and the sign-in method you choose (a passkey, a
sign-in link, or a password with a second factor). We also ask for your country and state so we can apply the right consent rules.
- Setting up your household: the name of your family home, the subdomain you pick, the people
you invite, the roles you give them, and the rules you set for each child.
- Creating a child profile: a display name or nickname, an avatar, and a guardian-confirmed age
band. We do not ask for the child's legal name and we do not ask for an exact birth date unless a law requires it for a specific function. [CONFIRM: WHETHER EXACT DOB IS EVER REQUIRED.]
- Billing: your plan, and payment details you enter with our payment processor. Card numbers go
directly to the processor. We receive and store only the plan, the billing status, and a non-sensitive descriptor such as card brand and last four digits.
- Support: whatever you write to us when you ask for help.
3.2 Information a family creates inside Kithlane
This is the content of family life: photos, videos, documents, messages, posts, comments, reactions, family pages, albums, calendar events, event rooms, approved links, and a child's projects and requests.
We store this content so we can show it to the people you chose. We do not analyze it to build profiles, to rank a feed, to decide what to show anyone, or to sell anything.
Automatic handling of uploads. When someone uploads a file, our system checks it before it becomes visible. We validate the file type, scan for malware, remove embedded metadata such as camera location tags, and run automated safety classification. Where household policy requires it, we route the item to a guardian for approval. This processing is automated. A person at Kithlane does not look at your files as part of it.
3.3 Information from a child's device
To let a child use Kithlane without an email address or a password, a guardian authorizes a specific device. That device holds an opaque credential the guardian can revoke at any time.
We collect: the device credential, a local PIN or picture code the child chooses, coarse device and browser type, and sign-in and session timestamps. We use this only to keep the child signed in safely, enforce the guardian's allowed hours and idle timeout, and let a guardian revoke a lost or shared device instantly.
We do not collect: advertising identifiers, precise location, contact lists, photos from the device camera roll except the specific ones a person chooses to upload, or browsing activity outside Kithlane.
3.4 Information generated when Kithlane runs
- Security and audit events. High-risk actions create a permanent, append-only record: a role
change, an owner transfer, a child profile created or deleted, a policy change, a page published, a link approved, a support grant opened or revoked, an export or deletion requested. Each record identifies who acted, on what, and when. It does not copy your private content into the log.
- Application logs. Technical records that let us keep the service working: event type,
pseudonymous household and actor identifiers, request identifier, route, status code, response time, and a redacted error category.
Our logging rules deliberately exclude message text, child prompts, file contents, access tokens, passwords or PINs, recovery codes, exact private addresses, and full email addresses where a pseudonymous identifier is enough.
- AI operation records. When a Guide is used, we record which Guide handled it, which policy
decision applied, which tools were permitted, and cost and performance measurements. Whether the actual conversation text is retained is a household setting. See Section 6.
3.5 Information from the marketing website
On kithlane.com we use privacy-respecting, aggregate analytics to understand which pages people read. We do not use third-party advertising trackers, we do not load advertising scripts, and we do not build cross-site profiles.
We do not run this analytics on child surfaces inside the application. The application's content security policy blocks third-party scripts in child surfaces entirely.
We honor browser-based opt-out preference signals, including Global Privacy Control, on our website. Because we do not sell or share personal information or run targeted advertising, there is nothing for such a signal to turn off — but we recognize it and record it.
3.6 Information from other people
- Invitations. If a guardian invites you, we receive your email address from them so we can send
the invitation.
- Family content about you. Relatives may post photos or write about family members, including
children. Kithlane does not control what your family chooses to share within your household. What we control is that it stays inside the household audience they selected.
4. Why we use information
We use personal information only for these purposes:
- To provide the service — create accounts, run the permission system, store and deliver
content to the audience you chose, run the calendar, deliver notifications you asked for.
- To keep the service secure — authenticate people, detect and stop abuse, scan uploads for
malware, rate-limit attacks, investigate incidents.
- To enforce the rules a guardian set — allowed hours, approval requirements, visible spaces,
contact permissions, download rights, external link behavior.
- To support families — answer questions, diagnose problems, provide concierge setup where
purchased.
- To bill for the subscription — process payment, send receipts, handle refunds and disputes.
- To respond to safety concerns — review flagged events under a defined policy, and act where a
person appears to be in danger.
- To meet legal obligations — tax and accounting records, responses to valid legal process,
and required notices.
- To improve Kithlane — using aggregate and de-identified measurements, and using what you tell
us directly. We do not read household content to do this.
What we do not do
We commit to all of the following, and we build the product so these are enforced technically, not only promised:
- We do not sell personal information, and we do not share it for cross-context behavioral
advertising, as those terms are defined under California and other state privacy laws. We have never done so.
- We do not serve advertising of any kind, to anyone, at any age.
- We do not engage in targeted advertising or build advertising profiles.
- We do not profile people in a way that produces legal or similarly significant effects.
- We do not use household content to train, fine-tune, or improve artificial intelligence
models — ours or any provider's.
- We do not rank a feed by engagement, run infinite scroll, use streaks, or send notifications
designed to pull a child back into the app.
- We do not use persistent identifiers to prompt or encourage a child to keep using Kithlane.
- We do not condition a child's participation in any Kithlane activity on disclosing more
personal information than is reasonably necessary for that activity.
5. Children's privacy — our COPPA notice
This section is our direct and online notice under the Children's Online Privacy Protection Rule. It applies to every child under 13 who uses Kithlane. A separate, child-friendly explanation is at [CHILD NOTICE URL] and in CHILDREN_PRIVACY_NOTICE.md.
Children do not create their own Kithlane accounts. A guardian creates a child profile and authorizes specific devices.
5.1 Operator identity
JRSB Solutions, LLC. Contact information is in Section 1. We are the only operator collecting personal information from children through Kithlane.
5.2 What we collect from children, and how we use it
| Information | Collected how | Used for |
|---|---|---|
| Display name or nickname | Entered by the guardian or chosen by the child | Showing the child to their own family inside the household |
| Avatar (an illustrated character, not a photo) | Chosen by the child from a Kithlane set | Personalizing the child's home screen |
| Age band, guardian-confirmed | Provided by the guardian | Delivering age-appropriate experience, permissions, and Guide limits |
| Local PIN or picture code | Chosen by the child | Letting the child sign in on an authorized device |
| Device credential and coarse device type | Generated by our system when a guardian authorizes a device | Keeping the session secure and letting a guardian revoke it |
| Content the child creates or uploads — messages, posts, drawings, project work, photos where the guardian allows uploads | Created by the child | Showing it to the household audience the child selected, after safety checks |
| Requests the child makes — for example, asking to open a website | Created by the child | Routing the request to a guardian for a decision |
| Guide conversations, if the household enables retention | Created by the child | Answering the request; showing history to the child and, per household policy, to a guardian |
| Persistent identifiers such as session and device tokens | Generated by our system | Security, authentication, session management, and abuse prevention — support for internal operations only |
We do not use persistent identifiers for advertising, for cross-site tracking, or to encourage a child to spend more time in Kithlane.
We do not require a child to give us more than the above. A child does not need to give a legal name, a birth date, an email address, a phone number, a photograph of themselves, a voice recording, or a location to use Kithlane. We do not condition participation in any game, activity, or feature on disclosing information beyond what that activity reasonably needs.
What we deliberately do not collect from children: precise geolocation; facial recognition or face template data; voice recordings (this is excluded from the product entirely at launch and would require separate review and separate parental consent before it could ever be added); advertising identifiers; contact lists or address books; browsing history outside Kithlane.
5.3 Verifiable parental consent
Before we collect personal information from a child, we obtain verifiable parental consent from a guardian.
How consent works:
- The adult creates and verifies their own Kithlane account.
- The adult confirms they are the parent or legal guardian of the child, and that they have legal
authority to consent for that child.
- We give the adult a direct notice describing exactly what we collect from the child, how we use
it, whether we disclose it to anyone, and their rights.
- We obtain consent using [VPC METHOD(S) SELECTED — must be chosen and confirmed by counsel; see
COUNSEL_REVIEW_NOTES.md § Information Required From Founder].
- We record who consented, for which child, to which version of this notice, for which purposes,
and when.
- Only after consent is recorded can a child profile be created and a device authorized.
Separate consent for materially different collection or disclosure. A guardian may consent to the core Kithlane service without consenting to features that involve materially different collection or disclosure. Specifically:
- AI Guides. Using a Guide sends the text of the request, plus only the household information
the Guide is permitted to retrieve, to an AI model provider acting as our service provider. This is a separate, per-child, revocable consent. A child can use Kithlane with Guides turned off.
- Uploads by children. Whether a child may upload media at all is a separate guardian decision.
- Any future feature that would collect a new category of information from a child, or disclose
a child's information to a new category of recipient, requires new notice and new consent before it applies to that child.
Consent to use is not consent to disclose. A guardian may consent to our collection and use of a child's personal information without consenting to disclosure of that information to third parties, except where a disclosure is integral to the service the guardian asked for. The infrastructure providers listed in Section 8 are integral: without hosting, storage, and content delivery, Kithlane cannot function at all. AI providers are not integral to the core service, which is why Guides carry their own consent.
Withdrawing consent. A guardian can withdraw consent at any time, for a specific feature or entirely. Withdrawing consent for a feature turns that feature off for that child. Withdrawing consent entirely means we stop collecting personal information from that child and delete the child's personal information under Section 5.5. We will tell you plainly what stops working.
5.4 Parental rights over a child's information
A guardian may, at any time:
- Review the personal information we have collected from their child;
- Export it in a portable format;
- Correct anything inaccurate;
- Delete it, and require us to delete it;
- Refuse to permit further collection or use, without deleting what already exists;
- Revoke consent for any specific feature.
To exercise any of these, sign in and go to Settings → Family → Child privacy, or email [PRIVACY EMAIL ADDRESS] from the address on the guardian account.
We verify that the requester is the guardian before we act. We may ask you to re-authenticate. We do not require you to create a new account or provide new information beyond what is needed to verify you.
One honest note. In a shared family home, a child's content sometimes appears inside content that belongs to other people — a comment on a relative's photo, a message inside a family thread. When you delete a child's information, we delete the child's own content and remove the child's identifiers from shared items. Where removing a message would make a family conversation unintelligible, we replace it with a neutral placeholder rather than silently rewriting history. We will describe exactly what happens before you confirm.
5.5 How long we keep children's information — our written retention policy
We keep personal information collected from a child only as long as reasonably necessary to fulfill the specific purpose for which it was collected. We do not keep a child's personal information indefinitely, and "it might be useful someday" is not a purpose we accept.
| Child data | Purpose | Retained for | Deletion method |
|---|---|---|---|
| Child profile (display name, avatar, age band) | Running the child's experience | While the profile exists; deleted within [PROPOSED 30 days; CONFIRM] of profile deletion or household closure | Hard delete from primary systems; backup expiry per below |
| Device credential and PIN | Authenticating the child | While the device is authorized; [PROPOSED 90 days; CONFIRM] after revocation for abuse investigation | Hard delete |
| Content the child created | Showing it to the family audience the child chose | Until the family deletes it, or the household is closed | Hard delete after the recovery window |
| Guide conversations | Answering the request; showing history where the household allows | [PROPOSED: default off, or 30 days if enabled; guardian-configurable up to a maximum of [MAX]; CONFIRM] | Hard delete |
| Requests and approvals | Operating the guardian approval workflow | [PROPOSED 12 months; CONFIRM] | Hard delete |
| Safety events involving a child | Responding to and reviewing a safety concern | [PROPOSED 24 months; CONFIRM], longer only under a documented legal hold | Hard delete or, where required, minimized to a non-identifying record |
| Security and audit records referencing a child profile | Proving that access rules were followed | [PROPOSED 24 months; CONFIRM] | Pseudonymous by design; identifiers removed at expiry |
| Backups | Restoring the service after a failure | Backups expire on a rolling [PROPOSED 35-day; CONFIRM] schedule | Deleted content does not return to production; the backup copy expires on schedule |
When a child ages out of a band, or a guardian deletes a profile, or a household closes, or a guardian withdraws consent, we run this schedule. We do not keep the data "just in case."
5.6 Security of children's information
We maintain a written information security program covering children's personal information, including designated responsibility for it, regular risk assessment, technical safeguards, vendor diligence, and periodic testing. Section 9 describes the technical safeguards. The written program itself is an internal document; a summary is available to a guardian on request at [PRIVACY EMAIL ADDRESS].
We require every service provider that handles children's personal information to maintain confidentiality, security, and integrity, and to use the information only to provide services to us. We assess each provider before onboarding and periodically after.
5.7 Reporting a concern
If you believe we have collected personal information from a child in a way that is inconsistent with this notice, contact us immediately at [PRIVACY EMAIL ADDRESS]. You may also contact the Federal Trade Commission at ftc.gov.
6. AI Guides
Kithlane includes bounded AI assistants called Guides. A Guide does one specific job — for example helping with a homework concept, or helping a family write down a family story. A Guide is not a companion, is not always present, and is not designed to keep anyone engaged.
What a Guide is allowed to do. A Guide operates inside a permission system. It can only retrieve information the person asking is already allowed to see, in their own household. It cannot search the open internet on its own, cannot message anyone, cannot change household settings, cannot change permissions, and cannot open a website by itself.
What happens to what you type. When someone uses a Guide, the text of the request and only the permitted household information needed to answer it are sent to an AI model provider that acts as our service provider. We configure these providers so that:
- they do not retain the content after the response is returned (zero-retention configuration);
- they do not use it to train or improve their models;
- they use it only to return a response to us.
[CONFIRM: this must be verified in the executed contract with each AI provider, and re-verified when a provider or model changes. See COUNSEL_REVIEW_NOTES.md.]
Transcripts. Whether Guide conversations are kept, and for how long, is a household setting. [CONFIRM DEFAULT.] Whether a guardian can read a child's Guide transcripts is also a household setting, and the child is told plainly which setting applies to them. Teen members are shown exactly what a guardian can see.
Guides can be wrong. A Guide can produce an answer that is incomplete or incorrect. Guides do not give medical, legal, financial, or mental health advice. Kithlane runs automated safety checks on Guide responses before they are shown, and we test the system regularly, but automated checks are not perfect. Do not rely on a Guide for anything that matters without checking it.
Which provider we use. We use [AI MODEL PROVIDER NAME(S)] as of the effective date of this policy. We may change providers. If a change would materially alter what is collected, how it is used, or who receives it, we will provide notice and, where required for a child, obtain new consent before the change applies.
7. Who can see your family's content
This is the section families care about most, so we will be precise.
7.1 Your household
Kithlane is built around explicit audiences. Every photo, message, page, event, and file carries the audience its author chose, and the composer shows that audience in plain language before it is posted. The options are things like everyone in the household, guardians only, a specific space, a specific list of people, selected children, or only the creator.
Household isolation is enforced in the database itself, not only in the application. Every row of family data carries a household identifier, and access rules deny by default. We run automated tests that actively attempt cross-household reads, writes, searches, file access, live subscriptions, and AI retrieval, and those tests must pass before we ship.
7.2 Kithlane staff
Kithlane staff cannot browse household content.
Support begins with metadata and diagnostic states — error codes, upload status, whether a job failed — not content. If a support problem genuinely requires looking at content, a staff member must request a support grant, and a guardian must approve it. A support grant specifies:
- the purpose, in plain language;
- the exact scope of what may be accessed;
- whether content viewing is permitted at all, or only metadata;
- a start time and an expiry;
- a revoke control the guardian can use at any moment.
While a grant is active, the staff member sees a persistent banner showing they are in support mode. Every action taken under the grant is recorded in an append-only audit log. When the grant expires, access ends automatically. The guardian receives a summary of what was actually accessed.
There is no silent impersonation. Kithlane does not have a feature that lets staff sign in as a family member without the household knowing.
7.3 The two exceptions
We will not claim these do not exist.
Safety emergency. If we have a good-faith belief that access is necessary to prevent imminent harm to a child or another person, a small number of trained staff may access the minimum necessary information without waiting for guardian approval. This requires dual authorization where feasible, creates the same immutable audit record, and is reviewed after the fact. We will notify the household unless notifying them would increase the risk to a person or is prohibited by law.
Legal process. If we receive a subpoena, court order, warrant, or other legally valid demand, we review it. We object to demands that are overbroad or improper. Where we must comply, we produce the narrowest set of information responsive to the demand. We will notify the affected household before producing anything, unless we are legally prohibited from doing so or notice would create a safety risk. [CONFIRM: law enforcement response policy and whether Kithlane will publish a transparency report.]
7.4 What is never visible to anyone outside your household
There is no public profile, no username directory, no search engine index of family content, no discovery surface, no follower list, and no way for a person outside your household to see that a household exists. Media files are stored privately. A download link is generated only after our database has authorized the specific person for the specific file, and that link expires quickly.
8. Service providers and disclosure
We disclose personal information only in these situations:
1. To service providers who work for us. Each is bound by contract to use the information only to provide services to us, to keep it confidential and secure, and not to use it for their own purposes. We do not authorize any of them to sell it, share it for advertising, or train models on it.
| Provider | What it does for Kithlane | What it can receive |
|---|---|---|
| Cloudflare | DNS, content delivery, edge security, web application firewall, bot protection (Turnstile) | Network-level data such as IP address and request metadata; content in transit through the CDN |
| Supabase | Database, authentication, file storage | Account data, household data, family content, files |
| [PAYMENT PROCESSOR NAME] | Subscription billing and payment processing | Adult billing contact and payment details. Never household content. Never child information |
| [TRANSACTIONAL EMAIL PROVIDER NAME] | Sending account, security, and notification emails | Adult name and email address, and the content of the email. Never child email addresses, because we do not collect them |
| [AI MODEL PROVIDER NAME(S)] | Generating Guide responses under zero-retention configuration | The text of a Guide request and only the permitted household information needed to answer it |
| [MALWARE / CONTENT SCANNING PROVIDER, IF ANY] | Scanning uploads for malware and unsafe content | Uploaded files, for automated scanning only |
| [ERROR MONITORING / OBSERVABILITY PROVIDER, IF ANY] | Detecting and diagnosing failures | Pseudonymous technical logs; configured to exclude content |
[CONFIRM: this list must be complete and current before publication, and must be updated whenever a subprocessor is added or removed. See COUNSEL_REVIEW_NOTES.md.]
An up-to-date list of subprocessors is maintained at [SUBPROCESSOR PAGE URL]. You may subscribe to notifications of changes at [SUBPROCESSOR NOTIFICATION SIGNUP].
2. To people your household chose. Content goes to the audience the author selected. That is the product working as intended.
3. When you tell us to. For example, if you ask us to connect a service or send an export somewhere.
4. For safety or legal reasons. As described in Section 7.3.
5. In a business transfer. If JRSB Solutions, LLC is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. If that happens:
- we will give you advance notice through the app and by email;
- the acquiring party must continue to honor this policy for information collected before the
transfer, or obtain new consent;
- for children's personal information, the successor must expressly agree to be bound by the
commitments in Section 5, and a guardian may delete their household before the transfer takes effect.
We commit that a change of ownership will not be used as a route to advertising, data sale, or model training on family content.
We do not disclose personal information for money or for anything else of value. We do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months, and we have no plans to.
9. How we protect information
Security is a design requirement for Kithlane, not a feature list. The main safeguards:
- Tenant isolation. Household data is separated at the database level with default-deny access
rules, plus a second enforcement layer in the application, plus automated tests that attempt to break it.
- Separate staff systems. Kithlane staff authenticate through a completely separate identity
system on a separate domain, with phishing-resistant multi-factor authentication and managed devices. A staff session cannot be used as a family session.
- Authentication. Adults use a passkey, a sign-in link, or a password with a second factor.
Sensitive actions require recent re-authentication. Sessions are revocable. Children use guardian-authorized device credentials with rate-limited PIN attempts.
- Encryption. Information is encrypted in transit and at rest.
- Private files. Media and documents are stored in private buckets. Access requires a signed,
short-lived URL issued only after the database authorizes the specific person for the specific file.
- Upload safety. Uploads land in quarantine, are validated against their real file signature,
scanned for malware, stripped of embedded metadata, and blocked if they are an unsafe type.
- Minimal logging. Message text, child prompts, file contents, credentials, and exact addresses
are excluded from application logs by design.
- Audit. High-risk actions create append-only records that cannot be edited or deleted.
- Testing. We use an application security verification standard as our baseline, run automated
security testing on every change, and obtain independent penetration testing before broad launch and after major changes to identity, messaging, uploads, or AI. [CONFIRM SCHEDULE.]
What we cannot promise. No system is immune to every attack, and no security program eliminates all risk. We can tell you what we do, and we can tell you what we will do if something goes wrong. If a security incident affects your personal information, we will notify you and any required regulator within the time frames the law requires, describe what happened in specific terms, and tell you what we are doing about it.
10. How long we keep information
Section 5.5 is the retention schedule for children's information. This section covers everyone else.
| Category | Retained for |
|---|---|
| Adult account records | While the account is active, then [PROPOSED 30 days; CONFIRM] after household deletion |
| Household settings and roles | While the household is active |
| Family content | Until deleted by the family, then a [PROPOSED 30-day; CONFIRM] recovery window, then hard deletion |
| Guide transcripts | Per household setting; see Section 6 |
| Support conversations | [PROPOSED 24 months; CONFIRM] |
| Billing and tax records | [PROPOSED 7 years; CONFIRM with accountant and counsel] |
| Security and audit records | [PROPOSED 24 months; CONFIRM], longer under a documented legal hold |
| Backups | Rolling [PROPOSED 35 days; CONFIRM] |
| Marketing website analytics | [PROPOSED 14 months; CONFIRM] |
What deletion actually does. When you delete a household, we show you a deletion workflow before you confirm. It tells you: what disappears immediately, what enters the recovery window, what stays in security and audit records and why, when backups expire, which providers receive deletion instructions, and the status of each step. Deleted content does not come back into production when a backup is restored.
Some records survive deletion because the law requires it — tax records, and anything subject to a legal hold. We will tell you which.
11. Your rights and choices
11.1 Rights available to everyone using Kithlane
Regardless of where you live, we give every Kithlane household these rights, because the product is built for them:
- Know what we collect and why — this document.
- Access the personal information we hold about you.
- Export your household's content in a portable, machine-readable format.
- Correct inaccurate information.
- Delete your information and your household.
- Withdraw consent for any optional feature.
- Object to a decision we made — we will look at it again.
Use Settings → Privacy in the app, or email [PRIVACY EMAIL ADDRESS].
11.2 If you live in a U.S. state with a comprehensive privacy law
As of the effective date, this includes California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, and additional states as their laws take effect. [CONFIRM CURRENT STATE LIST AT PUBLICATION.]
Depending on your state, you have rights to:
- confirm whether we process your personal data and access it;
- obtain a copy in a portable format;
- correct inaccuracies;
- delete personal data;
- opt out of targeted advertising, sale of personal data, and profiling in furtherance of decisions
producing legal or similarly significant effects — we do none of these, for anyone;
- obtain a list of the categories of third parties to whom we disclosed personal data (Section 8);
- not be discriminated against for exercising a right. We will not deny service, charge a different
price, or provide a lesser experience because you exercised a privacy right.
Sensitive data. Personal information about a known child is sensitive data under these laws. We process it only with consent obtained under Section 5, and only for the purposes listed in Section 4.
Appeals. If we decline your request, we will tell you why and how to appeal. To appeal, reply to our decision or email [PRIVACY APPEALS EMAIL ADDRESS] with the word "Appeal." We will respond within the time your state requires and, if we still decline, we will give you your state attorney general's contact information for a complaint.
Authorized agents. You may use an authorized agent to submit a request. We will ask for proof of the agent's authority and may ask you to verify your own identity directly.
Verification. We verify requests before acting. For a household member, that normally means signing in and re-authenticating. We will not create a new profile about you just to verify a request.
11.3 If you live in California
In addition to the above:
- Categories collected, sources, purposes, and recipients are set out in Sections 3, 4, and 8.
- Sale and sharing: we do not sell personal information and we do not share it for
cross-context behavioral advertising. This includes the personal information of consumers under 16, for whom such practices would require opt-in consent in any event. We do not engage in them at any age.
- Sensitive personal information: we do not use or disclose sensitive personal information for
purposes beyond those permitted without an opt-out right. We do not use it to infer characteristics.
- **Limit the Use of My Sensitive Personal Information / Do Not Sell or Share My Personal
Information:** because we do not engage in the practices these links address, we do not display them. [CONFIRM this position with counsel before publication.]
- Financial incentives: we do not offer financial incentives in exchange for personal
information.
- Retention: see Sections 5.5 and 10.
- Submitting requests: email [PRIVACY EMAIL ADDRESS] or use Settings → Privacy. Because Kithlane
operates exclusively online and has a direct relationship with each household, we provide an email address as the designated request method. [CONFIRM whether a toll-free number is nonetheless advisable.]
- Shine the Light (Cal. Civ. Code § 1798.83): we do not disclose personal information to third
parties for their own direct marketing purposes.
11.4 Communications choices
- Security and account emails — such as sign-in links, password changes, role changes, support
grants, and billing notices — are part of the service and cannot be turned off while your account is active.
- Product and marketing emails — optional. Unsubscribe in any message or in Settings.
- In-app notifications — configurable per person. Kithlane does not send notifications designed
to increase time in the app.
12. Design choices we treat as commitments
Several U.S. states have enacted age-appropriate design laws. Their enforceability is being litigated. As of the last update of this policy, key provisions of the California Age-Appropriate Design Code Act remain enjoined, and the Maryland law has also been challenged. [CONFIRM STATUS AT PUBLICATION.] We are not going to tell you we comply with a law that is not currently enforceable, and we are not going to claim credit for obligations a court has suspended.
What we will tell you is what we actually built, independent of what any court decides:
- privacy-protective settings are the default, not an option a family has to find;
- we do not use design patterns intended to nudge anyone into weaker privacy settings;
- we do not use engagement mechanics — no infinite scroll, no streaks, no public popularity counts,
no algorithmic ranking;
- we collect the minimum information necessary and we say what each item is for;
- children are given an age-appropriate explanation of what happens to their information;
- age band determines experience, permissions, and Guide behavior;
- we assess privacy and safety risk before we ship a feature that touches children.
We describe these as design commitments because that is what they are. If we change one, we will say so in the change log described in Section 15.
13. Cookies and similar technologies
We use a small number of cookies and equivalent storage:
| Type | Purpose | Can you turn it off? |
|---|---|---|
| Strictly necessary | Sign-in session, security tokens, CSRF protection, load balancing | No — the service will not function without them |
| Preference | Remembering language, theme, and layout choices | Yes, in Settings; some preferences will reset |
| Aggregate analytics on kithlane.com only | Understanding which public pages people read | Yes — see Section 3.5, and we honor Global Privacy Control |
We do not use advertising cookies, cross-site tracking pixels, or third-party trackers. Child surfaces in the application load no third-party scripts at all.
14. Where information is stored
Kithlane's infrastructure is operated in the United States. [CONFIRM: primary data region for Supabase; whether Cloudflare edge caching may place content in other regions; whether any AI provider processes outside the U.S.]
Our content delivery network operates globally, which means content may pass through infrastructure outside your state while it is being delivered to you. It is encrypted in transit.
If we ever store family content outside the United States, we will update this policy and provide notice before doing so.
15. Changes to this policy
We will not make a quiet change to a privacy policy that families relied on when they trusted us with their children's information.
- Any change: we update the effective date and post a dated change log at [CHANGE LOG URL]
describing what changed in plain language.
- Material change: we give at least [PROPOSED 30 days'; CONFIRM] advance notice by email to
every Family Owner and Co-Guardian, and by a notice inside the app.
- Material change affecting children's information: if a change involves collecting a new
category of information from a child, using a child's information for a materially different purpose, or disclosing it to a new category of recipient, we obtain new verifiable parental consent before that change applies to that child. Until consent is given, the child continues under the prior terms or the feature stays off.
We keep prior versions available at [POLICY ARCHIVE URL] so you can see what you agreed to.
16. International availability
Kithlane is currently offered only in the United States. [CONFIRM.]
We do not target, market to, or knowingly offer Kithlane to households in the European Economic Area, the United Kingdom, or Switzerland. This policy is not written to satisfy the EU or UK General Data Protection Regulation, and Kithlane has not appointed an EU or UK representative.
If JRSB Solutions, LLC decides to offer Kithlane outside the United States, that decision requires re-review of this policy and of the product before launch, including at minimum: the lawful basis for processing, the child consent age under GDPR Article 8 as implemented in each member state (which ranges from 13 to 16), the UK Age Appropriate Design Code, data subject rights procedures, international transfer mechanisms, appointment of a representative, and whether a Data Protection Officer is required. Until that review is complete, this document must not be presented to families outside the United States.
17. Contact us
Privacy questions, requests, and complaints Email: [PRIVACY EMAIL ADDRESS] Mail: JRSB Solutions, LLC, Attn: [PRIVACY CONTACT TITLE], [LEGAL NOTICE MAILING ADDRESS] In the app: Settings → Privacy → Contact us
Security vulnerability reports Email: [SECURITY EMAIL ADDRESS] Policy: [VULNERABILITY DISCLOSURE POLICY URL]
Child safety concerns Email: [SAFETY EMAIL ADDRESS] If someone is in immediate danger, contact local emergency services first.
If you have a complaint we have not resolved, you may contact your state attorney general or the Federal Trade Commission at ftc.gov.
*Kithlane is a product of JRSB Solutions, LLC.* *Related documents: Terms of Service · Children's Privacy Notice · Trust Center*