Last updated: August 1, 2026
Effective date: July 31, 2026
Who we are
WakeKids is a mobile service that lets a parent or legal guardian set wake-up alarms that ring on a paired child phone. In this policy, "WakeKids", "we", "us", and "our" refer to the operator of the service.
WakeKids is operated by SOFTWARECARAFT SRL. Registered office: Calea Rahovei no. 303, building 66, entrance 1, apartment 42, Sector 5, Bucharest, Romania. Fiscal Code: 51542766. Registration: J2025022901007. EUID: ROONRC.J2025022901007. Email: softwarecaraft@gmail.com. Telephone: +40 766 239 722.
For users in the European Economic Area, the United Kingdom, and Switzerland, we act as the data controller for the personal data described in this policy.
Information we collect
We deliberately collect as little information as possible. WakeKids does not collect location, contacts, microphone content, browsing history, other app usage, advertising identifiers, biometric data, or information for advertising profiles.
From the parent, we may collect an email address used to create the account, sign in, verify control of the address before pairing, and receive the delayed notice about an authorized child-device connection; authentication information handled by Firebase Authentication; a display name derived from account information; and a device push notification token so the service can send acknowledgement or no-response alerts.
From the child device, after the parent authorizes the connection, we store a nickname chosen by the parent, a push notification token used only to deliver the alarms the parent sets, a random pairing-scoped identity created by our backend, and wake-up records showing when an alarm rang and whether it was switched off. We do not collect the child's full name, year of birth, or any hardware device identifier.
Before the parent authorizes the connection, the child device sends none of the above. The pairing session holds only a random six-character code, the hash of a separate secret held on the child device, and its creation and expiry times.
A parent can scan the QR code shown on the child phone or enter its six-character code manually. Camera frames used by the scanner are processed only on the parent device to read the code; they are not stored or uploaded.
Operational data includes alarm schedules, alarm events such as whether an alarm fired or the wake screen was acknowledged, pairing status and tokens, parental-authorization timestamp and policy version, monthly usage counters, App Check signals, and temporary rate-limit records used to prevent abuse.
Parental consent notice records may include the parent email address, chosen nickname, authorization-policy version, provider message identifier, delivery status and times, revocation expiry, and a hash of the revocation-link secret. Resend receives the parent email address and confirming notice, but not the child nickname, pairing code, or child-device secret. Short-lived webhook receipts retain only a hash of the provider event identifier and timestamps, not the email payload.
In the parent role only, and after the parent role is selected, WakeKids collects product analytics through Firebase Analytics: funnel and feature events such as authentication method and outcome, pairing method and outcome, alarm create, update and delete categories, notification-permission result, Wake Now outcome, and paywall outcome. Firebase Analytics may process an app instance identifier and ordinary app and device metadata needed to produce aggregate reports, and Firebase may derive a coarse country, region or city from ordinary network information. We do not set a Firebase Analytics user ID, and we do not send an email address, a child's name or activity, a pairing code, a pair identifier, an exact alarm time, or advertising identifiers as analytics event fields.
A parent can turn parent analytics off at any time under Privacy settings in the app, which disables collection and resets the local analytics instance. Analytics collection is disabled before a role is selected, automatic screen reporting is off, and the child role never sends analytics, even if analytics was previously enabled on that installation.
For WakeKids Plus, RevenueCat may process the parent Firebase UID as a pseudonymous App User ID, device type, operating system, app version, store and product identifiers, Apple receipt or Google purchase token, transaction, renewal, expiration, refund, restore and entitlement status, and last-seen timestamps. Payment-card details are handled by Apple or Google and are not received by WakeKids or RevenueCat.
The contact, data-export, and data-deletion forms may collect a reply email, optional name, optional WakeKids account email, request details, and an ownership or guardian confirmation. Netlify also processes limited request metadata for form delivery, security, and spam prevention, such as request time, IP address, browser or user-agent details, and submission status. Netlify states that all Netlify Forms submissions are filtered for spam using Akismet, a service operated by Automattic.
Do not submit passwords, payment-card details, medical information, identity documents, or unnecessary information about a child through a website form.
Why we use information
We use account and device information to authenticate parents, maintain pairings, deliver wake-up alarms, show the correct family identity in the app, and send service notifications.
We use alarm schedules and alarm events to run the wake-up service and show parents whether the app received an acknowledgement. An acknowledgement is evidence of app interaction, not proof that a child is awake, safe, healthy, supervised, or at a particular location.
We use pairing tokens, App Check, and rate-limit records for security, abuse prevention, and to ensure that only authorized parent and child devices are connected.
We use purchase and subscription information to display offers, process or restore purchases, verify WakeKids Plus access, prevent purchase fraud, and provide subscription support.
We use website submissions to answer support messages, verify and complete privacy requests, prevent spam, and keep the minimal record needed to demonstrate that a verified request was handled.
We do not sell or rent personal data. We do not use family data for advertising, behavioral profiling, interest-based ads, or third-party marketing.
Legal basis for processing
Where GDPR or similar law applies, we process parent account data and alarm data to perform the service requested by the parent.
We process purchase and subscription information to perform the WakeKids Plus contract and, where applicable, for legitimate interests in fraud prevention, support, and account security.
For the minimum temporary processing needed to prepare an unclaimed pairing request, where GDPR applies we rely on legitimate interests in secure, time-limited device pairing, subject to a child-rights balancing assessment and legal validation. For paired-child data, we rely on parental authorization or consent where applicable. The parent or legal guardian can withdraw that authorization by disconnecting a child device, deleting the account, or contacting us.
We process limited security data, such as rate-limit records and App Check signals, based on our legitimate interest in protecting families, the service, and our infrastructure from abuse.
We process support messages to perform or support the service and for our legitimate interest in answering users. We process verified privacy requests to comply with legal obligations and keep a minimal audit record for compliance and dispute handling.
Children, parental authorization, and the consent notice
A child does not create a conventional WakeKids account. Before pairing, the child device requests a short-lived anonymous session. It contains no name, no year of birth, no device identifier, no push token and no Firebase identity: only a random six-character code and the hash of a separate secret held on the child device. The code expires after 15 minutes.
Pairing is completed by an authenticated parent or legal guardian who first verifies control of the parent-account email, scans the QR code or enters the six-character code shown on the child phone, reads an on-screen notice listing exactly what will be stored about the child device, confirms authority, and actively connects the device. Only then does the backend create a random, pairing-scoped child identity and the pair record, which stores the method, time and policy version associated with that authorization.
Approximately 24 hours after pairing, we email the verified address on the authenticated parent account a second copy of that notice. It lists what is stored about the child and contains a link that disconnects the device and starts the deletion process described below. The delay is deliberate: it gives a parent who did not authorize the connection an opportunity to discover and undo it. We track provider delivery events; a notice reported as undeliverable, or still unconfirmed after 48 hours, is flagged for operational review. Provider acceptance or a delivery event cannot guarantee that a person actually read the message.
A parent can review everything stored about their child at any time in the app, under Privacy settings, and can delete it by disconnecting the device, using the link in the notice, or deleting their account.
Information about a child is used solely to operate the alarm service. It is never sold, and never shared with advertisers or other third parties. WakeKids contains no advertising and no advertising SDKs, and the child role sends no analytics.
This records affirmative parent authorization and verified control of the parent-account email, but does not independently prove the person's identity or legal relationship to the child. For United States users, COPPA may require direct notice and a method of verifiable parental consent before collecting personal information from a child under 13. The operator confirmed on July 31, 2026 that qualified legal counsel approved the consent method, direct notice, and complete flow for the intended launch configuration. Any material change to the data collected, purpose, audience, advertising posture, or consent flow requires renewed review before release.
WakeKids is designed to align with UK Children's Code principles such as data minimization, privacy-protective defaults, no profiling, and age-appropriate information. This statement does not replace a documented best-interests assessment, age-assurance analysis, or data-protection impact assessment.
If you believe a child device has been paired without proper parental authority, contact softwarecaraft@gmail.com and we will review the request and delete relevant data where appropriate.
Processors and sharing
We share data only with providers needed to operate the service. Google Firebase and Google Cloud provide authentication, Firestore, Cloud Functions, Firebase Cloud Messaging, App Check, scheduling, and related infrastructure.
RevenueCat, Inc. acts as our processor for parent purchase and subscription information. RevenueCat supports offer display, purchase and restore handling, entitlement verification, subscription lifecycle, fraud prevention, and customer support. WakeKids does not send the child's name, year of birth, device identifier, push token, pairing information, or alarm activity to RevenueCat.
Resend acts as our email-delivery provider for the delayed parental-consent notice. It receives the verified parent email address and notice content, but not the child nickname, pairing code, or child-device identifier.
Netlify, Inc. hosts the public website and processes contact, data-export, and data-deletion form submissions on our behalf. Netlify states that it sends all Netlify Forms submissions through Akismet, operated by Automattic, for spam classification. Apple and Google provide storefront, billing, tax, transaction, cancellation, refund, and push-delivery services and may act under their own platform terms.
Firestore data is configured for europe-west3, Frankfurt, Germany. Cloud Functions also run in europe-west3. Push notifications may transit through Google Firebase Cloud Messaging and Apple Push Notification service global infrastructure.
Push notification payloads are limited to operational delivery data. Depending on the alarm flow, they may include the child's first name, alarm time and sound, event or pair identifiers, and scheduling metadata needed to deliver, acknowledge, reschedule, or cancel an alarm. They do not contain advertising content, location, medical information, or payment-card details. We do not share personal data for marketing, advertising, profiling, or research.
Where information is stored
WakeKids stores Firestore data in europe-west3, Frankfurt, Germany, and runs backend functions in europe-west3.
RevenueCat stores end-user customer data in AWS infrastructure in the United States and processes it under its Data Processing Addendum and applicable transfer safeguards. RevenueCat's privacy information is available at https://www.revenuecat.com/privacy and its DPA at https://www.revenuecat.com/dpa.
Netlify Forms stores website submissions in the site account. Netlify recommends that customers actively delete submissions containing personal data and states that all submissions are filtered using Akismet. Netlify privacy information is available at https://www.netlify.com/privacy/ and Akismet privacy information at https://akismet.com/privacy/.
Some support services, including Netlify, RevenueCat, and push delivery through Google or Apple infrastructure, may process limited data outside the EEA. Where required, we rely on contractual and other transfer safeguards used by those providers.
How long we keep information
Parent accounts are kept until the parent deletes the account or asks us to delete it. Child profiles and pair records are kept until the parent disconnects the pair, the parent deletes the account, or a verified deletion request is completed.
Alarm schedules are kept until deleted or until the related account or pairing is removed. Alarm events are intended to be kept for no more than 180 days and are deleted earlier when the relevant pair or account is removed. Production TTL must be enabled and verified before automatic expiry is treated as operational.
Pairing tokens cannot be used after 15 minutes. Pairing-token and rate-limit records are intended to be removed through expiry cleanup after production TTL is enabled and verified; until then, automatic deletion must not be assumed.
Parental consent notices are kept while the pairing exists, so that the removal link in the notice keeps working; the link itself stops working 90 days after pairing. They are deleted together with the pair when the device is disconnected or the account is deleted.
Resend webhook receipts are intended to be kept for no more than 90 days through Firestore TTL. They contain only a hash of the provider event identifier and receipt and expiry timestamps, not the email payload.
The child's Firebase Authentication identity is random and scoped to a single pairing. When the device is disconnected, consent is withdrawn through the notice, or the parent account is deleted, access is disabled and refresh tokens are revoked immediately. Final Auth-record deletion is attempted after a two-hour custom-token safety window and retried automatically if necessary; a minimal durable cleanup request is kept only until pair records and that final identity deletion are complete.
A minimal parent UID and account-deletion timestamps may be kept for up to 24 hours as a deletion fence so in-flight requests cannot recreate account data. A minimal RevenueCat deletion request may be kept through the 24-hour post-sign-out verification window, and longer only while a failed processor deletion still requires retry.
Subscription and entitlement records are kept for the life of the account or subscription and afterward only as required by processor agreements, tax or accounting law, dispute resolution, or fraud prevention. Apple or Google may retain store transaction records under their own legal obligations.
Netlify retains full form submissions until an authorized WakeKids operator deletes them. Our operational target is to delete a full submission normally within 90 days after the support or privacy request is closed, but this is a manual process and must not be assumed automatic until the production procedure is verified. You may ask us to remove a closed submission earlier. For a verified privacy request, we may retain a minimal audit record for up to three years without retaining the full request content.
Residual copies may persist temporarily under each provider's configured backup and continuity lifecycle after active records are removed. The duration depends on the provider and production account configuration.
Security
Traffic between the app and backend services is encrypted in transit. Firestore data is encrypted at rest by Google.
Authentication is handled by Firebase Authentication, and passwords are not visible to us in plaintext. Sensitive endpoints use Firebase App Check and rate limiting to reduce unauthorized or automated access.
RevenueCat receives only the authenticated parent Firebase UID as the WakeKids App User ID; we do not set the parent email or child profile as RevenueCat customer attributes. Secret RevenueCat API credentials remain server-side.
Netlify form submissions are available only to authorized site-account users. We ask users not to submit secrets or unnecessary child information through the forms.
No online service can be guaranteed completely secure, but we design WakeKids around data minimization, restricted access, and operational controls appropriate for a family wake-up service.
Your rights and parent controls
In the app, parents can use pairing controls to review paired child information, disconnect a child device, delete alarm schedules, and delete the parent account where available.
By web or email request, parents can ask for data export, deletion support, correction, restriction, objection, or other privacy help that is not available directly in the app. You may also withdraw consent for child data processing.
Account deletion removes the parent's active WakeKids records and linked pairing data, immediately disables each pairing-scoped child Firebase Authentication identity, and schedules final deletion of that identity after a two-hour custom-token safety window. It also requests deletion of the linked RevenueCat customer and always schedules a delayed verification and re-delete after local sign-out, with further retries if needed. Store transaction records and provider backups may remain where required or technically necessary.
Deleting the WakeKids account, disconnecting a child, uninstalling the app, or deleting RevenueCat customer data does not cancel a Google Play or Apple App Store subscription. Cancel the subscription separately in the applicable store if you do not want it to renew.
To make a privacy request, contact softwarecaraft@gmail.com. We aim to respond within 30 days, or sooner where required by law. You may also complain to your national supervisory authority, including ANSPDCP in Romania.
Cookies and website data
The WakeKids mobile app does not use cookies. It stores limited functional state on the device so the app can remember role, pairing, and alarm-related state.
The public website does not intentionally use advertising or analytics cookies. Netlify and network providers still process ordinary HTTP request metadata to deliver and protect the site, and Netlify Forms stores information you choose to submit. This is separate from the in-app parent analytics described under "Information we collect", which does not use cookies.
If we add website analytics, advertising cookies, or similar tracking, we will update this policy and provide any notice or consent required before enabling it.
Changes and contact
We may update this policy as the service changes. The updated date above shows the current public version. We will provide any notice required by applicable law and, where reasonably practicable, communicate material adverse changes in the app or by email before they take effect.
For privacy questions, data requests, parental requests, or complaints, contact SOFTWARECARAFT SRL at softwarecaraft@gmail.com or +40 766 239 722. Registered office: Calea Rahovei no. 303, building 66, entrance 1, apartment 42, Sector 5, Bucharest, Romania.