← Vibe KidsVibe Kids Privacy Policy
Effective date: 2026-07-11 Last updated: 2026-07-20
Vibe Kids, operated by Anchored Imagination LLC ("Vibe Kids", "we", "us", or "our"), provides a supervised learning experience where young children (primarily ages 4–10) build simple, self-contained HTML games and interactive experiences together with an AI coding companion called "Vibe". The service is designed exclusively for co-use with a parent or guardian who is present during use. There is no separate child login, and children are not expected to use the service on their own.
This Privacy Policy explains what information we collect, how we use it, and your rights. It applies to our website, web application, and related services at vibekids.app and any associated domains.
How updates work. We may update this policy as Vibe Kids evolves. When we make a material change, we post the updated policy here with a new "Last updated" date and — where the change affects families with active accounts — let you know by email or an in-app notice. Continuing to use Vibe Kids after an update means you accept the updated policy.
Important context for families
- Parents create the account and work side-by-side with their children. The adult must be present while a child uses Vibe Kids; for the youngest users the parent or guardian is typically the one typing and guiding.
- Kids do not create their own independent accounts and there is no separate child login. A parent creates and controls the child profile.
1. Information We Collect
Account and profile information
- For parents: email address, name, and a securely hashed password. During our early phase, sign-ups may be gated (waitlist / invitation).
- For children ("kids"): first name (or nickname) and association to a parent account. We do not collect a child's email, phone number, or other direct contact details.
Content you create with your child
- The HTML games, visuals, and interactions ("builds") that you and your child create for each lesson.
- Per-turn snapshots of the work in progress (so progress can be resumed and you can see how a project evolved).
- The conversation turns ("transcripts") between you/your child and Vibe (the AI) — the prompts and questions you type and the AI's responses while building.
Mastery and feedback records
- Which lessons a child has completed or "mastered".
- For the mastery gate: a short concept-question answer the child (with adult help) gives, plus the remix build they created to demonstrate understanding.
- Skill signals (observations such as prompting or problem-solving) and feedback on specific builds.
Safety and moderation records
- The result of the automated safety screening we run on prompts and generated output (see Section 4), and, where a prompt or output is flagged, a record of the flag associated with the account for abuse prevention and support. Where a prompt or output is blocked, the blocked text itself is kept only briefly for review (see Section 7).
Technical, usage, and attribution information
- Session activity (when a build session starts/ends, idle timeouts, and an audit log of significant actions such as "kid added", "lesson mastered", "build saved", "account deleted").
- Technical logs necessary to keep the service running and secure (e.g., container start events, errors).
- Standard web information such as IP address (for rate limiting and security), browser type, and cookies we set for authentication.
- First-party attribution captured when you join the waitlist or create an account: the referring page, UTM parameters, the landing page you arrived on, and a coarse geographic location (country/region/city) derived offline from your IP address using a local MaxMind GeoLite2 database. We use this to understand where our families come from. We do not use third-party advertising trackers.
We do not:
- Sell personal information or use it for advertising.
- Share your family's builds or conversations with anyone outside the service providers described in Section 5.
2. How We Use the Information
- Deliver the core experience: let a supervised child (with a parent present) talk to Vibe, have Vibe edit a single HTML file inside a locked-down container, and see a safe, sandboxed preview of the result.
- Support parent co-use: parents create child profiles, select the active child, see their family's builds and progress, and view mastery evidence.
- Keep the service safe: run automated safety screening on prompts and output, enforce container isolation, rate-limit logins and sessions, detect abuse, lock accounts that misuse the service, and maintain audit records.
- Improve the product (see Section 3): review how families use the lessons — including the prompts children type and the games the AI produces — to fix problems and make Vibe Kids better.
- Legal and safety: comply with applicable law, enforce our Terms, and respond to safety concerns.
3. How We Review Prompts and Builds to Improve Vibe Kids
We look at the prompts children type and the games the AI produces in order to improve the product. Being clear about this matters to us:
- Members of the Vibe Kids team, and automated tools we operate, may review conversation transcripts and the builds created in a session to fix bugs, improve the lessons and the AI's coaching behaviour, catch quality problems, and make the experience safer and better for kids.
- This is our own internal review of activity on our service. We do not sell this data, use it for advertising, or share it outside the service providers listed in Section 5.
- We do not use your family's prompts, conversations, or builds to train foundation AI models, and — as described in Section 4 — our AI inference provider does not retain or train on the data we send them.
This product-improvement review applies to all accounts. We do not currently offer a way to opt out of it; if you do not want your activity reviewed for these purposes, please do not use the service, and you can delete your data at any time (Section 9).
4. The AI Companion ("Vibe") and Third-Party AI Providers
When you or your child interact with Vibe, the text you type (prompts) and the current state of the game are sent to an AI coding engine so it can suggest and apply edits to the HTML. The same provider also powers the mastery report, which scores a short thinking-signals rubric from the transcript and build.
Current configuration. Vibe Kids uses open-weight ("open-source") AI models hosted by Fireworks AI, an inference provider we use to run the models that power the building experience and the mastery report. We chose this arrangement deliberately for child privacy: Fireworks AI processes the prompts and game state we send only to return the model's response, and does not retain that data or use it to train models. The specific open-weight model may change as we improve quality and speed, but we do not route your child's data to AI providers that retain or train on it — open-weight, no-retention inference is our standard for the live service.
Automated safety screening. Every prompt and every piece of generated output is screened by an automated safety classifier (an AI content-safety judge) together with keyword filters, before output is shown. Prompts or outputs in unsafe categories (violence, weapons, adult content, self-harm, hate) are blocked with a gentle kid-friendly message, and repeated misuse can lock the account (a parent can then contact us to unlock it). This screening is performed by the same Fireworks-hosted open-weight models under the same no-retention terms described above — no additional AI provider receives your data for safety screening.
What this means for your data. Prompts and generated code are sent to the AI provider above solely to power the real-time building experience, the mastery report, and automated safety screening. We apply strict output review and a Content Security Policy so that even if the AI produced something unsafe, it is heavily sanitized before it can run in the browser. The container the AI runs inside is heavily restricted (read-only root filesystem, one small writable directory for the game, no general network access from the builder process, dropped capabilities, resource limits, and a non-root user).
5. How Information Is Shared or Disclosed
Within the service (by design):
- Parents see all data for the child profiles they created.
- A child working with a parent sees only their own current game and history for the lessons they are doing.
Optional sharing by you (only if enabled):
- Game sharing is off by default. If we enable it for your account, you can create a play-only share link or QR code for a finished game (no editing, no login required to view), and you control when and with whom you share them. While sharing is off, games stay private to your family account.
Service providers (subprocessors):
- Fireworks AI — receives the prompts and game state necessary for each building session, mastery report, and automated safety screening (no retention; no training), as described in Section 4. Fireworks applies Zero Data Retention by default for open-weight models — prompt and generation data are held only in volatile memory for the duration of the request and are not written to persistent storage. See the Fireworks Privacy Policy and Fireworks Zero Data Retention.
- Infrastructure / hosting — the servers and database that run the service.
- Stripe — if you purchase a paid plan, payment processing is handled by Stripe; we do not store your full card details.
- Email delivery — used to send account, support, and safety notices.
Legal requirements: We may disclose information if required by law, to protect the safety of children or users, to enforce our Terms, or in connection with a merger/acquisition (with notice where possible).
We do not sell personal information or use it for advertising.
6. Cookies and Similar Technologies
We use cookies (and similar technologies) only for essential purposes:
- Keeping you logged in (authentication sessions for parents).
- Remembering the "active child" a parent has selected so the experience feels continuous for that child.
- Security features such as login rate limiting.
We do not use third-party analytics cookies or advertising cookies. You can clear cookies in your browser; this will log you out.
7. Data Retention, Backups, and Durability
We store the data described above primarily in a SQLite database (with WAL mode for crash recovery). Builds, per-turn snapshots, transcripts, mastery records, signals, feedback, safety flags, and an audit log of important actions live in this database.
Retention. We keep each type of data only as long as needed for its purpose, then delete it:
- Your child's completed work (final builds, mastery, and learning evidence) is kept until you delete it or close your account — it is what your child made.
- Raw conversation transcripts (the prompts your child typed and the AI's replies) are automatically deleted after 120 days.
- Intermediate build snapshots (used to resume an in-progress session) are automatically deleted after 180 days.
- Safety-flag records (the category and time of a blocked prompt or output) are kept for up to 1 year, then removed. Where we keep the blocked text at all, we retain it only for a short review period — generally no more than 30 days — then delete it. We may keep a small number of individually-reviewed examples longer to improve accuracy.
- Operational audit records (e.g., "account deleted", "lesson mastered") are kept for up to 1 year, then removed.
- Temporary items such as login sessions and email-verification / password-reset links expire and are deleted automatically.
An automated daily process enforces these timeframes; we do not retain your child's personal information indefinitely. You can also delete all of your data at any time using the self-service tools in Section 9.
Backups and durability. We take regular backups of the database (using SQLite's built-in backup mechanism) and store copies off the primary server, with tested restore procedures. Containers use only ephemeral storage that disappears when a session ends; the database is the authoritative store.
8. Security
We designed the technical architecture with young children in mind:
- The AI never runs on your device or with general network access. It runs in an ephemeral, hardened container that can only write the single game file you are building.
- All game output is sanitized and wrapped in a strict Content Security Policy before it reaches the browser. The preview runs in a sandboxed iframe with no ability to contact the outside world or your other tabs.
- Strong authentication, revocable sessions, and audit logging of important actions.
- Automated safety screening of prompts and output, with account lock on repeated misuse.
No system is 100% secure. If you believe your account has been compromised, change your password and contact us immediately.
9. Your Rights and Choices (Access, Export, Correction, and Deletion)
Depending on where you live, you (as the parent account holder) may have rights to access, correct, export, or delete your and your children's personal information.
Self-service tools (available now).
- Export: from Parent → Settings, download a complete archive of your family's data (
/parent/export.zip) — a ZIP containing your kids' builds as playable .html files plus machine-readable JSON of profiles, snapshots, transcripts, and mastery/signals.
- Delete: from Parent → Settings, permanently delete your account and all associated child data. Deletion is a scoped, complete, right-to-erasure purge: it removes builds, snapshots, transcripts, signals, feedback, and related records across every surface, leaving only a minimal audit record of the deletion request itself for compliance. You receive a confirmation of what was removed.
If you cannot use the self-service tools, email us (Section 12) and we will handle verifiable export or deletion requests manually (typically within 30 days, sooner for urgent child-safety requests). We may confirm identity before acting on deletion or large export requests.
You can stop using the service at any time by logging out or deleting your account.
10. Children's Privacy and Our Approach to Young Users
Vibe Kids is intended for children ages 4–10 only with direct adult supervision.
- The adult (parent/guardian) creates the account and the child profiles, must confirm parental consent at signup (Section 11), and must be present while the child uses the service.
- There is no separate child login; the parent selects the active child.
- We do not knowingly collect personal information directly from children without the parent first establishing the account and providing consent.
- If we learn that we have collected information from a child without proper adult involvement in a way that violates this policy or applicable law (including COPPA), we will delete it.
11. Parental Consent
Creating a parent account requires confirming parental consent. At signup, the parent agrees to a plain-language statement:
"I'm the parent or legal guardian, and my child uses Vibe Kids with me present (there's no separate child login). I understand Vibe Kids reviews the prompts we type and the games it helps create, to keep kids safe and improve the product. I agree to the Privacy Policy and Terms."
We record this consent — the date and the exact wording you agreed to — so we can always show precisely what you agreed to. If we change the wording materially, we ask you to agree to the updated statement.
12. Changes and Contact
Changes. We may update this policy as the service evolves. We post the updated policy here with a new "Last updated" date. Material changes that affect families with active accounts are communicated by email or an in-app notice where possible.
Contact. Vibe Kids is operated by Anchored Imagination LLC. For privacy questions, deletion/export requests, or concerns about a child's data:
- Anchored Imagination LLC
- 522 W Riverside Ave # 4270, Spokane, WA 99201, United States
- Phone: +1 (425) 200-5627
- Email: hello@vibekids.app
We take the privacy and safety of the children using Vibe Kids seriously and welcome direct questions from parents.