Purpose and scope
This notice supplements the Kulaya Privacy Policy. It explains how Kulaya handles personal information about children, parent-managed child profiles, and supervised child or teen sign-in. If this notice conflicts with the general Privacy Policy regarding a child's information, this notice controls.
Kulaya is a family organization service. An adult may record information about a child even when the child never uses Kulaya directly. Different rules can apply when information is collected from the child through a login, device, upload, voice feature, or other interaction.
Age, parental verification, and supervised access
Public signup, independent household requests, and family administration are for adults 18 and older. A parent-managed profile is not a login. Parents can begin verification in Settings → AI & family permissions and manage an eligible supervised login in Members.
- Ages 0–5 - young children: parent-managed profiles only. No direct sign-in or AI.
- Ages 6–12 - children: direct sign-in requires verified parental consent. AI is unavailable to this age group, including the Learning helper. A checkbox or pending verification request alone never enables direct sign-in.
- Ages 13–17 - teens: a parent or legal guardian must authorize supervised sign-in. AI is unavailable to this age group, including accounts with earlier parental AI approval or teen assent.
- Ages 18 and older - adults: public signup and adult permissions. Each eligible adult makes their own AI choice for the exact account and family, after age and provider readiness checks.
Age is derived from date of birth, not a user-selected label. Missing or inconsistent minor age information blocks direct access. Permission is checked again when the age band, family, account, or controlling notice changes; it is not silently carried into a new category. An existing supervised account does not automatically become an adult account at 18.
AI permission is separate from permission to use the core app. Children and teens cannot use any AI, including the Learning helper, AI file or voice uploads, AI actions, connected external accounts, or adult health and nutrition AI features. Guest accounts cannot use AI. These restrictions also apply during testing.
Kulaya records the authenticated parent or guardian, exact family, profile, account, date of birth and derived age band, consent scope, notice version, decision, verification reference, expiry, and server timestamps. Only a completed verification reviewed through an approved process can create a verified receipt. The app does not allow a parent to self-mark a verification request as verified. Do not send identity documents through chat or email.
Information connected to a child
Depending on the features the family uses, Kulaya can handle:
- name, age or date of birth, relationship, grade, school, avatar, color, and member role;
- for supervised access, login email, authentication identifier, credential status, device and security information, and session records;
- calendar events, activities, deadlines, assignments, grades, tasks, habits, family notes, and manually recorded allowance, spending, savings goals, and educational money progress;
- allergies, dietary preferences, meals, nutrition, vaccines, appointments, clinicians, lab values, height, weight, sex, family health history, and device-health summaries;
- photos, documents, text, voice transcripts, and information selected from connected services;
- AI request information only when all current age, permission, verification, and provider gates for that feature are satisfied; and
- limited product-interaction records, such as whether onboarding, an invitation, a task action, or an AI request succeeded.
A family should provide only the information reasonably needed for the feature it has chosen. External Google connected-service features remain unavailable to child, teen, and guest roles. Guest roles also cannot use AI. Adults must have authority to provide the child information they select. Supervised children and teens cannot use AI, including the Learning helper. Earlier AI approvals do not enable access.
How child information is used
We use child information to:
- provide the family organization feature requested by the parent or authorized family member;
- maintain and secure a parent-managed profile and an enabled or paused supervised credential;
- provide a role-limited personal view to a supervised child or teen and display permitted child-related information to authorized family users;
- synchronize permitted family content across an authorized user's devices;
- provide optional adult import, photo, document, voice, or AI features only when the adult is eligible and authorized; AI is unavailable to all under-18 accounts;
- provide support, prevent abuse, investigate errors, and protect the Service; and
- comply with law and enforce the Terms of Use.
Kulaya does not sell a child's personal information, use it for targeted advertising, or use family content to create an advertising profile. Kulaya does not knowingly use manipulative design to prolong a child's use of the Service.
Device and persistent identifiers
Kulaya and its providers can process an IP address, authentication identifier, session token, device or browser information, cookies, local-storage identifiers, app version, request timing, and security or synchronization records. These identifiers support sign-in, security, fraud and abuse prevention, offline operation, synchronization, feature delivery, and reliability. Kulaya does not use them to build a child advertising profile or track the child across unaffiliated services for advertising.
Content connected to a child profile is not posted to a public social feed by Kulaya, but information saved in the shared family space can be visible to other people with access to that family. A parent should review the family roster and remove access that is no longer appropriate.
Who can receive child information
- Authorized family members. Information in a shared family space can be visible to other members according to their role and the feature. An owner or parent administrator should review family access regularly.
- Service providers. Supabase supports authentication, database, and file storage; Vercel hosts and delivers the application; OpenAI processes adult general questions and moderation without stored child records; DeepInfra processes adult-authorized school-email text, which may include child information; and Google supports optional adult sign-in, Calendar, Gmail, OAuth, and font delivery. AI processing and user-connected Google services are separate purposes with separate access controls. The current list is maintained in our Service Provider and Connected Services List.
- User-directed services. Information can be sent to a connected service or another person when the parent or authorized user deliberately chooses that action.
- Safety and law. We can disclose information when reasonably necessary to comply with law, protect a child or another person, investigate abuse, or secure the Service.
Optional disclosure to a third party that is not integral to the requested child feature requires a separate choice when applicable law requires one. A child cannot provide parental consent. This notice is not itself verifiable parental consent.
Adult-only AI and child information
Kulaya offers two separately authorized AI purposes for eligible adults aged 18 or older. All AI features, including the Learning helper, are unavailable to anyone under 18. Parental approval does not override that restriction. Guest accounts cannot use AI. Non-AI family features retain their separate age and access rules.
Reduced general assistant: OpenAI. GPT-5.6 Terra processes only the adult's current typed or dictated question and its answer. We do not attach earlier chat messages, stored family records, school-email content, files, or images. This mode cannot read or change app data, browse the web, or execute tools. Do not submit children's information, private family details, contact information, or sensitive health information. Local screening reduces accidental disclosure but cannot reliably identify every kind of personal information in free text.
Existing Gemini permissions do not authorize OpenAI processing. Earlier full-assistant permissions do not authorize either new limited purpose. Each requires its own current notice and choice.
OpenAI also performs input and output safety moderation. We send an opaque safety identifier, not a raw email or account ID. API content is not used for model training by default. Kulaya's OpenAI Zero Data Retention request is pending, not approved: standard provider safety retention can apply. Disabling response storage is not ZDR. The full family-data assistant, uploads, and automatic OpenAI calendar classification remain disabled pending their separate privacy and readiness checks. See OpenAI's API data controls.
Email summaries: DeepInfra. With a separate adult permission, DeepInfra processes message text and subjects using DeepSeek V4 Flash to produce private summaries, importance assessments, action lists, and suggested calendar dates. Messages can concern school, work, household, or other topics; an approved sender is not a school-only filter. We do not send the stored family roster or email attachments, follow links, or automatically approve calendar changes. Email content is not sent to OpenAI. Only use this feature for information you are authorized to share, including any child information in an email.
Connecting Gmail alone does not authorize AI processing. You must save approved senders and select matching messages for manual analysis, or separately opt into checks about every ten minutes for newly arriving messages. Pasted or forwarded email also requires the separate email-summary AI permission. There is no automatic historical backfill. Empty checks do not call AI. The current pilot limits attempts and shares the household AI allowance; frequency is not a delivery guarantee or an emergency service.
Kulaya does not retain raw email bodies after processing. Private summaries, message identifiers, subjects, senders, proposed dates, and processing outcomes can remain until deleted. DeepInfra's terms prohibit training on customer content and limit content retention, with support, security, and legal exceptions. Technical prompt caching may apply; Kulaya does not request extended cache retention. It is not a promise that no data is ever retained, or a claim of U.S.-only processing. See DeepInfra's terms and the provider list.
Review or withdraw each permission separately in Settings → AI & family permissions. Background email checks can also be paused in Gmail settings. Withdrawal blocks future requests, but a transmission already sent cannot be recalled. General chat can remain in the current device's local history until cleared; it is not forwarded as conversation context. Permission, usage, and security records are retained as described in this policy. None of these choices authorizes another person's account.
AI is not a person, therapist, emergency service, or professional adviser. Safeguards cannot guarantee every answer is safe or correct. Check original messages and review proposed dates before accepting them. Do not rely on AI output for diagnosis, treatment, or medical, legal, financial, or high-impact decisions. In the U.S., call 911 for immediate danger or call/text 988 for a suicide or mental-health crisis.
Parent and guardian choices
A verified parent or legal guardian may ask to:
- review the personal information Kulaya maintains about the child;
- correct or delete the child's profile or information;
- delete a parent-managed profile where the adult has in-product authority, and submit a verified request concerning a historical linked login;
- withdraw consent and stop further direct collection from the child; turn off AI separately without withdrawing core-account consent;
- permit internal use while refusing a non-integral third-party disclosure where the law provides that choice; and
- receive information about the categories of information collected, uses, and recipients.
An owner or parent administrator can review the profile and use the current product controls to create, reactivate, or pause its supervised sign-in. Creating or reactivating requires a fresh acknowledgement of the current children's notice. Pausing records revocation and blocks product access for that login, while leaving sign out and account deletion available. Removing a person from a family space, pausing a credential, deleting a login, and deleting every record about that person are different actions. For help, email support@kulaya.app with the subject “Child privacy request.” We will verify the requester's identity and authority. We will not require a child to disclose more information than reasonably necessary to use an activity.
Retention and security
A child profile and the family content attached to it are generally kept while the family uses those features, until an authorized adult deletes the information, removes the profile, withdraws applicable consent, or successfully deletes the relevant account or family space. Pausing a supervised credential stops that login's product access but does not by itself delete the profile or family content. Authentication, product-interaction, security, support, legal, and backup records can follow different retention periods described in the main Privacy Policy.
Kulaya has not yet published or implemented a fixed expiration schedule for every category above. Before a public U.S. launch that permits supervised child or teen use, Kulaya must adopt and enforce a written child-data retention schedule with a business need and deletion timeframe for each category, and must maintain the security program, provider diligence, and written assurances required by applicable children's privacy law. Controlled prelaunch access is not public-launch clearance; any required identity, verifiable-parental- consent, teen-consent, assessment, and rights process must be implemented and verified before public launch in the affected jurisdiction.
Family-entered school information
Kulaya is currently offered directly to families, not by or on behalf of a school. Grades, deadlines, and school information entered or forwarded by a family are family-provided information, not an official education record maintained by Kulaya for a school.
If Kulaya later provides services under an agreement with a school or district, a separate agreement and school privacy notice will govern school-provided data. The family version of Kulaya should not be used by a school to disclose education records without the authorization and contract required by law.