KnowGately Privacy Policy

Effective date: 31 July 2026. Consent disclosure version: 2026-08-01-p2.

KnowGately is a parent-controlled learning app for children. Parents choose exactly which videos and pages their child can open; the child sees only that. This page explains, in plain language, what data we handle and why. It is written for parents, not lawyers — and it says the same things as the consent disclosure every parent reads and agrees to before any child data is collected.

Looking for the shorter version written for a child? Read the child-friendly privacy notice.

1. Who we are

KnowGately is published by Maremma Studio, an independent developer based in Poland. Maremma Studio is the data controller for the data described on this page. For anything about this policy or your data, contact support@maremma.dev.

2. What we collect, and why

We collect only what is strictly necessary to run the service. If something is not listed here, we do not collect it.

Your parent account

Your email address and a secure sign-in identity, handled by our sign-in provider, Clerk. We use it to create and secure your account, verify it is really you (this is our consent method — see section 3), and reach you about your account. The parent is the only account holder.

Your child’s profile

A display name you choose (a nickname is fine — it does not have to be their legal name), their date of birth (to record the age information you provide; every child profile currently receives the same child-directed protections), and their timezone (so daily learning limits reset at the right local midnight). That is the entire child profile. We do not collect a child email, phone number, address, photo, precise location, or contacts.

The content you curate

The learning structure you build yourself: subjects, the YouTube videos, web pages, and documents you assign, the topics you group them into, the YouTube channels you approve, and the time rules and prerequisites you set. This is data you author, not data we gather about your child.

Paired devices

For each device you pair for your child: its platform (Android or Windows), when it was paired, when it last checked in, and whether it is active or revoked — so you can see and manage the devices linked to your child. The server also stores a one-way hash of a device security credential; it does not store the secret itself.

Learning activity

The core purpose of KnowGately is to show you how your child is actually learning — not just screen time. The kids app records, per resource: time spent, whether it was completed, how much of a video was genuinely watched, seek and skip behavior, rewatch activity, and blocked navigation attempts (when your child tries to leave the area you approved, the attempt is blocked and the attempted address is recorded for you — it is shown only to you in your dashboard and never shown back to the child). These events are used for your reports and, if enabled, to decide whether to put a calm “no activity yet” reminder in the parent inbox.

Operational records and parent inbox

We store short-lived pairing codes, child-session records and duplicate-prevention receipts, plus daily report rollups derived from learning events. Resource checks store when assigned content was last checked and whether it was ready, unreachable, or disabled. Parent reminders are visible only in the signed-in parent inbox; the controlled beta does not push reminders to child devices.

Our reasons under data-protection law

  • Parental consent covers the child profile, learning activity and child-directed operation. You can withdraw it at any time.
  • Providing the service covers the parent account, curation and settings you ask us to keep.
  • Legitimate security interests cover access logs, device authentication, duplicate prevention and abuse protection.
  • Legal obligations and legal claims cover the limited pseudonymous consent and erasure evidence described below.

Parent account, child profile, timezone, curation and device pairing are required to provide the controlled learning service. Curation can include private PDF and image bytes uploaded by the parent. Parent inbox nudges are optional and can be turned off. If required data or consent is not provided, child collection and playback stay blocked; there is no penalty beyond the service not being available.

What we never do

  • KnowGately does not serve advertising and embeds no advertising SDKs. If YouTube playback is enabled after policy review, standard YouTube embeds may show YouTube-served ads.
  • We never sell your data or your child’s data.
  • We never share child data with third parties for their own use, and no third party profiles your child through KnowGately.
  • No profiling of children for automated decision-making — the analytics exist to inform you, not to make decisions about your child.
  • Children have no accounts and no logins — a kid device is paired by you, once. There is no chat, messaging, or social feature, so your child cannot be contacted through KnowGately.

We collect no child data until a parent has given verifiable consent. Our consent method is email-plus: you verify control of your email address, then give explicit consent against a plain-language disclosure of exactly what is collected — the same facts as this page. If consent is missing, the system blocks: it will not create a child profile or record a single analytics event.

You stay in control afterwards. From your dashboard’s Data & privacy section you can review everything we hold about your child, correct profile details, withdraw your consent (collection stops and every device is revoked the moment you do), and delete an individual child or your entire account.

Family data is erased. Deleting a child or your account runs an audited erasure: the child profile, every device record, every subject, resource, topic, and channel you created, and all learning-activity events and report rows are removed. Pseudonymous hashes, timestamps and deletion counts survive for up to six years to prove erasure, stop a stale identity from recreating the account, and handle provider retries or legal claims. They contain no child profile, curated content or learning activity.

4. Where the data lives

All child data — profiles, your curated content, device records, and learning activity — is stored in the European Union: our database runs in Frankfurt, Germany, and our backend runs in an EU region.

The one exception is parent sign-in data: your email address and sign-in credentials are processed by Clerk, our authentication provider, inside Clerk’s own infrastructure in the United States under GDPR transfer safeguards (Standard Contractual Clauses / the EU-US Data Privacy Framework). Clerk holds parent identity data only — children have no accounts anywhere, so no child data ever reaches Clerk.

5. How long we keep it

  • Active profile, consent, curation, private uploaded files, settings and device rows: until the resource, child or account is deleted.
  • Learning events: up to 395 days.
  • Blocked-navigation attempts and attempted addresses: up to 90 days.
  • Private parent-inbox reminders: up to 90 days.
  • Expired or redeemed pairing codes and event duplicate-prevention receipts: up to 30 days.
  • Completed identity-provider and private-object deletion jobs: up to 90 days after completion.
  • Pseudonymous erasure audit and erased-identity suppression records: up to six years.

Daily reports are derived from retained events. Deletion refreshes those reports so deleted family data does not remain there.

6. Your data rights

Depending on the request and applicable law, you can ask to access, export, correct or erase data; restrict or object to processing; and receive portable data. You can withdraw parental consent at any time without affecting processing that was lawful before withdrawal. We do not make solely automated decisions about children.

Use Data & privacy in the dashboard or email support@maremma.dev. We may need to verify that the requester controls the parent account. You may also complain to Poland’s supervisory authority, the President of the Personal Data Protection Office (UODO), or the authority where you live or work.

7. Third parties we rely on

These providers process data strictly on our behalf to run the service — they are not permitted to use it for their own purposes:

  • Clerk — parent sign-in and account security (parent identity data only).
  • Vercel — hosts this parent web dashboard.
  • Railway — hosts our backend server (EU region).
  • Neon — our database (Frankfurt, EU).
  • Cloudflare R2 — private PDF/image object storage using its European Union jurisdiction. Objects have no public URL and are delivered only after paired-device authorization.

External content: YouTube and general webpage playback are currently disabled in production while platform-policy and pre-dispatch containment reviews remain open. If either is enabled later, assigned content loads directly from that provider, not through KnowGately. Its privacy terms apply, and standard YouTube embeds may show YouTube-served advertising.

8. Changes to this policy

If we ever materially change what we collect or why, we bump the versioned consent disclosure (currently version 2026-08-01-p2) and ask every parent to read and re-consent before the change takes effect — consent to an old version never silently covers new collection. We update this page and its effective date at the same time. Editorial fixes that do not change what is collected may refresh the date without requiring re-consent.

Questions? Write to support@maremma.dev.