🛡️ Security & Transparency

Your Family’s Data, Safeguarded

We build trust through transparency, industry-leading encryption, and strict adherence to children’s privacy regulations. Your family’s information never leaves our secure ecosystem.

📅 Last Updated: November 15, 2024

Our Security Commitments

Every system, process, and policy is designed with one goal: protecting your family’s digital footprint.

🔒

End-to-End Encryption

All data in transit and at rest is encrypted using AES-256 and TLS 1.3 protocols. Only authorized systems can decrypt and access your family’s information.

🛡️

Zero-Sell Data Policy

We never sell, rent, or share your personal data with third-party advertisers or data brokers. Your family’s information stays with you and us.

👶

Children’s Privacy First

We strictly comply with COPPA and GDPR-K. No tracking, no cookies, and no behavioral profiling on minors. Parental consent is required for all accounts.

🔍

Continuous Security Audits

Independent third-party security firms conduct quarterly penetration testing and annual SOC 2 Type II compliance reviews to identify and patch vulnerabilities.

📄

Transparent Data Requests

Parents can view, export, or permanently delete their family’s data at any time through the dashboard. No hidden processes, no account lockouts.

👨‍👩‍👧

Granular Parental Controls

Set visibility permissions, approve data sharing, and manage access for family members. You control who sees what, and when.

Certifications & Compliance

We hold ourselves to the highest standards recognized by global privacy and security authorities.

🇺🇸

COPPA Compliant

Verified compliance with the Children’s Online Privacy Protection Act. No data collection under age 13 without verifiable parental consent.

🇪🇺

GDPR & GDPR-K

Fully compliant with EU General Data Protection Regulation, including special provisions for children’s data (GDPR-K) and data portability rights.

🌍

SOC 2 Type II

Annually audited service organization control report covering security, availability, processing integrity, confidentiality, and privacy.

🔐

ISO 27001

Internationally recognized information security management standard for systematic risk assessment and control implementation.

How We Handle Your Data

Clear, straightforward answers to how your information is collected, used, and protected.

📥 What We Collect Minimal & Purposeful

Only essential data required for functionality: parent email, child age group, preferred language, and optional profile preferences. No device fingerprinting or cross-site tracking.

⚙️ How We Protect It Enterprise-Grade

Data is stored in geographically restricted, SOC 2 compliant cloud regions. Access is restricted to authorized personnel using multi-factor authentication and role-based permissions.

⏳ Data Retention User-Controlled

We retain data only as long as your account is active. Upon account deletion or request, all personal data is permanently erased within 30 days. Backup systems are purged within 90 days.

🤝 Third-Party Processors Strictly Vetted

We only partner with providers that sign Data Processing Agreements (DPAs) matching or exceeding our security standards. Full vendor list available upon request.

Report a Vulnerability or Contact Our Security Team

We welcome responsible disclosure. If you find a security issue, have a data request, or need assistance, reach out directly.

🔐 Security Inquiries security@familynest.com
📧 Data Requests (DSAR) privacy@familynest.com
🐛 Bug Bounty Program Submit via HackerOne
🔑 PGP Key Fingerprint: 8A3F 2C91 D4E5 7B02