kidloop
PRIVACY POLICY

Kidloop Privacy Policy

Last updated: 7 September 2026 · Version: 1.1
Applies to: the Kidloop mobile app (iOS and Android) and the school admin panel at app.kidloop.gr

This is a faithful English translation of the Greek original, which is available at the same location and prevails in case of any discrepancy. The app's user interface is in Greek only; where a Greek label matters, it is given in quotation marks with an English gloss.


1. In short

Kidloop is the tool your school uses to record your child's day and show it to you on your phone.

  • What is recorded: attendance and absences, meals, sleep, toileting, mood, activities, allergies, the teacher's free-text notes, and photos — individual ones on your child's daily update, and photos in announcements. Some of this is information relating to your child's health — explained in section 4.
  • Who can see it: the teachers of your child's room, and the guardians the school has linked to that particular child. No other parent. The restriction is enforced in the database, not merely on screen (section 6).
  • Photos require your consent. They are optional; refusing or withdrawing consent changes nothing else for your child. Consent is held by the school; the system checks it automatically for your child's individual photos, but not for photos in announcements — which is why you should read section 7.
  • No advertising, no analytics, no sale of data. Ever.
  • The data is held in the EU (Frankfurt). Email and push notifications pass through providers in the USA — set out in full in section 8.
  • To access, correct or delete data, contact your school first. The school decides; we carry out its instructions. How, exactly: section 11.

There are parts of the service that are not yet as we would like them — data is not deleted automatically, photo metadata is not always removed, and we do not yet keep a log of technical access. We are not hiding them: you will find them stated plainly in sections 7, 10 and 12.

2. Who we are, and who decides

Kidloop is developed and operated by Nanobyte Ε.Ε., registered office 227 Gounari Street, Glyfada, Attica, 16674, Greece, VAT number EL802478318 (tax office: KEFODE Attikis).

The school is the "controller". It decides which children are entered and with what details, what is recorded each day, which teacher sees which room, who is recognised as a guardian, whether photographs are taken, how long data is kept, and the legal basis for each record.

We are the "processor". We process the data only on the school's instructions, so that the service works. We do not use it for our own purposes.

What this means for you in practice: if you want to see, correct or delete your child's data, the right address is your school. We have no right to change it on our own initiative — we can only assist technically. If you write to us directly, we will forward your request to the school and keep you informed.

In a few limited cases we decide, and are therefore the controller ourselves: the school's billing details as our customer, the security and availability of our systems, and correspondence with you when you write to us.

Data Protection Officer (DPO): we have not appointed a DPO. Given the current scale and nature of our activity, an appointment is not required under Article 37 GDPR. All data protection matters are answered by the company itself at info@nanobyte.gr. If your school has appointed its own DPO, its details are in the school's own privacy notice.

3. What Kidloop records

About the child (entered by the school): first and last name; date of birth, sex and home address, all optional; room; relationship to guardians; a photo-consent indicator; attendance and absences with arrival time; absence declarations with a reason and an optional note; the daily care record; the message of the day to the room and school announcements, both of which may name children; and photos, either individual ones on your child's daily update or inside announcements.

About you as a parent/guardian: first and last name, email, phone, your relationship to the child, whether you confirmed or refused your link to that child, your notification preferences, and a device identifier used for push notifications.

About school staff: first and last name, email, phone, role, rooms, announcement rights and account status. We also record which member of staff completed or closed each room's day, and who uploaded each photo.

Technical data: email and hashed password, session data, and sign-in logs (typically IP address and device type) kept by Supabase's authentication service for a period it sets; one device identifier per user for notifications; a record of which daily summary was sent, for which child and to whom, so the same email is not sent twice; our server's access logs, which include IP addresses; and the check for a new app version each time the app opens, which reveals to the update provider an IP address, platform and app version.

What we explicitly do not do: no advertising and no advertising identifier; no analytics and no crash-reporting tool (no Google Analytics, no Firebase, no Sentry, nothing equivalent); no tracking cookies and no fonts from an external CDN; no sale or rental of data; no location permission; no automated evaluation or profiling of children. Parents upload nothing — the parent app has no file or photo upload at all. The app does not take photographs and does not record audio: the teacher only picks existing photos from their phone's library. One clarification is owed, however — the current release does technically declare camera and microphone permissions, because the photo-picker library adds them automatically; we never use them, and we are removing them in the next release.

4. Information relating to health

The law (Article 9 GDPR) gives special protection to health data, and Kidloop does record information that is, or may be considered, health data about your child.

(a) Absence declared for illness. The reason "Ασθένεια" (illness) is stored permanently, linked to the child's name and to specific dates. The optional free-text note of up to 500 characters is stored verbatim.

(b) Allergies. The school may record your child's allergies as free text. This is health data within the meaning of Article 9, and we record it for one reason: a school cannot safely feed a child without it. It is visible only to the teachers of your child's room and to your child's own guardians, inside the app. It is never sent in a mobile notification and is not included in the daily email — so it does not leave the EU. In the list of children only an indicator appears, showing that a record exists, never its content.

(c) The daily care record. With the default settings, the teacher records each day: «Ενεργήθηκε» (how many times the child had a bowel movement), «Δεκατιανό / Μεσημεριανό / Απογευματινό» (the three meals), «Ύπνος» (sleep), «Διάθεση» (mood: happy, sad, tired, unwell, restless), «Θα χρειαστούμε» (supplies needed: nappies, wipes, barrier cream, personal towel), «Δραστηριότητες» (activities) and «Σχόλια» (free-text notes). Toileting frequency, an "unwell" mood and any free-text note may reasonably be regarded as health information about a toddler.

(d) The school may add more. The admin panel lets a school create new record categories with any name and any options — for example a "Medication" category — and rename the default ones. The system does not restrict those names, so we cannot guarantee to you what exactly your school records — only what is recorded by default. Ask your school. The guarantees we give in sections 8 and 9 apply to the default categories.

Consent. Health data normally requires your explicit consent (Article 9(2)(a) GDPR). It is held by the school, not by us: Kidloop stores no separate consent record for health-related entries. All the system keeps is a yes/no indicator for photos, with no date and no change history. To see what you have signed, or to withdraw it, contact the school.

5. Legal basis, and what is optional

The legal bases are chosen by the school as controller; we record them here as the school has declared them to us.

PurposeLegal basis
Informing parents about the child's day; recording attendance and absencesPerformance of the school's contract with the parent (Art. 6(1)(b)) and the school's legal obligation (Art. 6(1)(c)). For the entries described in section 4: explicit consent (Art. 9(2)(a))
Holding guardians' contact details and addressPerformance of the contract (Art. 6(1)(b)); using them in an actual emergency: vital interests of the child (Art. 6(1)(d))
PhotosConsent (Art. 6(1)(a)), withdrawable at any time
Notifications and emails to parentsPerformance of the contract (Art. 6(1)(b)); your preferences control what you receive
Staff accountsEmployment contract (Art. 6(1)(b)) and employer obligations (Art. 6(1)(c))
Operating, securing and supporting the platform (our own basis)Our legitimate interest in a secure, uninterrupted service (Art. 6(1)(f))
Billing the school (our own basis)Legal obligation (tax law) and our contract with the school

What is mandatory: to enrol and care for the child, the school necessarily needs the child's name, room, your contact details, and the attendance record.

What is optional: photos, date of birth, sex, home address, and the free-text note on an absence declaration. Withdrawing any consent does not affect your child's place, care or treatment. If you are ever asked for consent in a way that suggests refusal has consequences, that is not right — speak to the school or contact the supervisory authority (section 14).

6. Who can see your child's data

Children have no account on Kidloop: they do not sign in, do not write and do not use the app. Only adults are users. The child is nonetheless the data subject, and you exercise the child's rights as the holder of parental responsibility.

There is no public sign-up: an account is created only by invitation from the school. When the school invites you, you are asked to confirm that you really are that child's guardian; if you refuse, you lose access immediately and the school's administrator is notified.

The child's daily record is visible only to the teachers of their room and to the guardians the school has linked to that particular child and who have not refused the link — not even to school management from that screen. The restriction is enforced technically in the database, not merely on screen: you do not see other children's data, and other parents do not see your child's.

To put it precisely: the check is on "has not refused the link", not on "has confirmed". A guardian whom the school has linked, who has activated their account but has not yet answered the confirmation question, can see the child's day. Emails and notifications, by contrast, are sent only to those who have confirmed. Because it is the school that decides who is linked to which child, a data-entry error there matters — check with your school who is registered as your child's guardians.

Who is recognised as a guardian is decided by the school, not by us. In cases of divorce, separation, sole custody or disagreement between parents, the school makes that decision on the basis of the documents you have given it. We carry out what the school has entered.

7. Photos

Photos reach you in two ways: as individual photos of your child inside their daily update, and inside announcements sent by the school to a room or to the whole school. The two paths are checked differently.

Individual photos on the daily update. The teacher picks up to five photos a day for each child from their phone's library. Here consent is checked automatically by the system: if your child's record carries no consent indicator, the upload is refused, and the check is repeated on every view — if consent is withdrawn, photos that were already sent are hidden too. A photo the teacher has picked does not reach you until they tap «Αποστολή» (Send); if they undo the send, it leaves your screen as well. These photos stay inside the app and are not included in the daily email (section 9).

Photos in announcements. These are not automatically checked against consent. An announcement concerns a whole group rather than a specific child, so the system cannot match the photo to a child and check that child's consent. The system warns the member of staff which children in the audience have not given consent, but it does not block publication. Responsibility for not including a child without consent lies with the school. If you see your child in an announcement without having consented, tell the school immediately; it can withdraw the announcement.

Where photos are stored. In private storage in the EU, with no public link of any kind. Every view uses a temporary link that expires after 5 minutes. They are never sent inside an email and never leave the EU. Consent is collected and held by the school; Kidloop stores only a yes/no indicator on the child's record, with no date and no history. To give, see or withdraw your consent, the request goes to the school.

Metadata is not always removed. A photo taken on a phone may carry capture metadata inside the file — date, device model and, if the camera recorded them, GPS coordinates. In the mobile app this metadata is not removed today. In the admin panel photos are usually downscaled and re-encoded before upload, which removes it — but not always: when the browser cannot decode the file type (for example HEIC files from an iPhone in Chrome), or when the photo is already small or already optimised, the file is uploaded as it is. You should therefore assume that metadata may survive on both paths. Photos remain in private storage and are not publicly accessible, but anyone with legitimate access to a photo can also read its metadata. We are working on removing it and will say so here when that is done.

8. Providers, and what leaves the EU

We use the providers below. That is all of them.

Inside the EU:

ProviderWhat it doesWhere
SupabaseDatabase, user accounts, photo storage — essentially all the dataeu-central-1, Frankfurt, Germany
HostingerThe server the application runs on; data passes through it but is not stored there, and the technical logs record IP addressesFrankfurt, Germany
Amazon Web Services (SES)Alternative email provider, not in use todayeu-central-1, Frankfurt

Supabase Inc. is a US-based company. Your school's data is held in Frankfurt; any access by its personnel from a third country is governed by its data processing agreement, which is incorporated into its terms of service and includes the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR), and the company also publishes a Transfer Impact Assessment.

Outside the EU:

ProviderWhat it receivesTransfer mechanism
Resend (USA) — sending emailThe recipient's email address and the entire content of the email, which the provider retains for 30 days on all its plansData processing agreement with standard contractual clauses, executed on sign-up; SOC 2 Type II certification
Expo (USA) — delivering push notificationsThe device identifier and the text of the notificationBeing confirmed — see below
Expo (USA) — app updatesIP address, platform, app version. No child dataBeing confirmed — see below
Apple (USA)Device identifier, notification text, testers' email addresses; app distributionBeing confirmed — see below
Google (USA) — distribution only via the Play StoreDistribution details and testers' email addresses. Android notifications do not operate today, so Google receives no notification dataBeing confirmed — see below

For the last four providers we are currently confirming the exact transfer mechanism (standard contractual clauses, or EU–US Data Privacy Framework certification). We would rather tell you that than name a mechanism we cannot produce on request; we will update this section once it is documented. You may request a copy of the safeguards in place for any provider at info@nanobyte.gr.

What we do not use: there is no payment or e-invoicing provider connected to the service today. We will update this policy before any new provider is added.

9. Notifications and email

Push notifications. The text sent to Expo and Apple contains no child name, no child identifier and no recorded value — it is fixed text along the lines of "New update". When a single category has been filled in, the title may contain the category's name (e.g. "Δεκατιανό" / morning snack), never the value. The category «Ενεργήθηκε» (bowel movement) is explicitly exempt and is never named — neither in a notification nor in the daily email — and the exemption holds even if the school renames it.

The qualification: the exemption covers that specific category. It does not cover new categories a school creates, nor default categories a school has renamed (section 4c): the name the school chooses may appear in a notification title on your lock screen — "Medication", for example — and as a row inside the daily email. We cannot prevent this today and we are fixing it in a future release. If this concerns you, ask your school which categories it has enabled, or turn notifications off.

The daily email «Η ημέρα του …» ("X's day"). It contains the child's first name in the subject line and, in the body, attendance, the meals, sleep, «Διάθεση» (mood, including the "unwell" value), «Θα χρειαστούμε» (supplies needed) and any other category with predefined options that your school has added. It does not contain «Ενεργήθηκε», does not contain free-text notes and does not contain photos — those stay inside the app, and the email points you there.

Because, as explained in section 4, mood and supplies-needed may be regarded as health-related information, for as long as the daily email is enabled, such information is transferred every day to an email provider outside the EU together with the child's name. You can switch the daily email off in the app's settings, with no other consequence: the same information remains available inside the app, where it does not leave the EU.

The password-reset email is not composed by our application but by Supabase's authentication service, and is delivered by the same US email provider. It contains your email address and a single-use link.

You also receive the enrolment invitation and school announcements. We send no marketing or promotional email.

10. How long we keep data

We are honest here, because a fictitious deletion schedule is worse than the truth.

Deleted automatically today: in-app notifications, which contain children's names, after 12 months; technical notification-delivery records after 30 days; device identifiers unused for 14 days are deactivated; the local copy on a teacher's phone is deleted on sign-out and cleaned up daily. Email content is retained for 30 days by the email provider (section 8).

Not deleted automatically today: everything else. There is no automatic deletion of children's details, guardians' and staff details, the daily care record, attendance, absence declarations (including the "illness" reason and the free-text note), photos, announcements or invitations. Specifically:

  • When a child leaves the school, their record is deactivated but not deleted. When it is deleted is decided by the school as controller and stated in the school's own privacy notice.
  • There is no automated process for deleting a specific individual. A deletion request is carried out manually by us, on the school's instructions, within the one-month deadline set out in section 11.
  • Deleting a parent or member of staff from the school does not delete the underlying sign-in account (email and hashed password). That is done separately, on request.
  • Backups. After a deletion, the data still exists in the database's daily backups until those are recycled, for the period set by our database provider's plan; you may ask us for the period currently in force. In the meantime the data is not accessible from the application and is not used for any other purpose.

A school's data as a whole is deleted 90 days after the end of our engagement. Billing records are kept for as long as Greek tax law requires (normally 5 years).

11. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21), as well as the right to withdraw your consent at any time (Art. 7) — for photos, for example. Withdrawal takes effect from the moment you tell the school: once it changes the indicator on your child's record, your child's individual photos are hidden automatically; for a photo already published in an announcement, the school must withdraw the announcement (section 7). You exercise these both for your own data and, on your child's behalf, for theirs.

How:

  1. Contact your school first. It is the controller and has the tools to respond.
  2. If the school needs technical assistance, or if you receive no reply, write to us at info@nanobyte.gr. We will forward the request to the school and support it technically.
  3. A response is given within one month; for complex requests the deadline may be extended by two months, with notice to you.
  4. There is no charge, unless the request is manifestly unfounded or excessive. We may need to verify your identity before responding — for the child's own protection.

On erasure specifically: as explained in section 10, it is carried out manually and on the school's instructions, within the same deadline.

Settings you control yourself in the app: which notifications you receive, whether you receive the daily email, and the notification permission on your phone itself. Declining notifications does not affect your use of the app.

12. Security

We list only measures that actually exist.

  • Separation at database level. Every table has row-level security enabled, deny by default. A user cannot read another school's data even if something goes wrong in the application. Signed-in users have read access only; every write goes through our server.
  • Access to the daily record only as described in section 6.
  • Photos in private storage, with 5-minute links. Encryption in transit (HTTPS/TLS) throughout. Daily database backups.
  • Invitation only. There is no public sign-up; nobody gains access without being added by the school.
  • On phones: a parent's device stores no child data. A teacher's device stores the room's day locally so that it works without a connection.

Our own team's access — stated as it is. So that the service can be operated, upgraded and repaired, a limited number of named technical staff at Nanobyte Ε.Ε. hold administrative credentials for the database. Those credentials bypass the database's access controls, so reading children's data is technically possible with them. We will not claim otherwise. For that access:

  • It is used only to operate, support and repair the service, and only on the school's instructions.
  • The credentials are not in the source code; they are stored separately, and our accounts with our providers are protected by two-factor authentication.
  • Anyone with such access is bound by an obligation of confidentiality (Art. 28(3)(b) GDPR).
  • Our internal admin panel (HQ), when used, additionally requires mandatory two-factor authentication for any access to school data. There is no active account of that kind today.
  • We do not currently keep a working log of these accesses. We therefore cannot show you a history of who read what and when. It is the most important measure we are missing, and we are implementing it.

Two further points that are not yet as they should be: on teachers' phones, the sign-in session and the locally stored room data — which include the "illness" indicator and free-text notes — are stored without additional encryption in the app's private storage, protected only by the phone's own lock; the school must ensure staff devices are locked. And invitation activation codes are stored in readable form and are not deleted after use.

Data breach. If a security incident occurs, we notify the school without undue delay, so that it can meet its own obligations (notifying the supervisory authority within 72 hours and, where required, notifying parents).

13. Changes to this policy

We will update this policy as the service changes. Material changes — in particular a new provider or a new category of data — will be announced to schools in advance and will be reflected in the date at the top.

14. Contact and right to complain

The controller of your child's data is your school. Its contact details, and its DPO if it has appointed one, are in your enrolment contract and in the school's own data protection notice, which also covers what it does outside Kidloop. If you do not have them, ask the school's office, or write to us and we will tell you which school operates your account. For anything concerning your child's data — access, correction, deletion, consent — contact the school.

For the Kidloop platform (the processor):

  • Company: Nanobyte Ε.Ε.
  • Registered office: 227 Gounari Street, Glyfada, Attica, 16674, Greece
  • VAT number: EL802478318 (tax office: KEFODE Attikis)
  • Email for data protection matters: info@nanobyte.gr
  • Data Protection Officer: none appointed (see section 2)

Right to complain. If you consider that your data, or your child's data, is not being processed lawfully, you have the right to lodge a complaint with the Greek supervisory authority:

Hellenic Data Protection Authority
1-3 Kifissias Avenue, 115 23 Athens, Greece · Telephone: +30 210 6475600 · www.dpa.gr

You may also bring proceedings before the competent courts.