Children's Privacy Notice - CriApp

NOTICE: Reviewed by the internal legal audit (2026-05-02) and completed with the owner's details on 2026-08-20. Sign-off by counsel licensed in Peru (governing law) is recommended before a large-scale launch campaign.

This notice is REQUIRED under COPPA (USA, FTC amendments April 2025), GDPR Art. 8 (children), LGPD Art. 14 (Brazil), INAI Guidelines (Mexico), Decree 1377/2013 + 090/2018 (Colombia), Law 25.326 (Argentina), Law 29733 + DS 016-2024-JUS (Peru), California AADC.

Version: 2.0.0

Last updated: 2026-08-20

Owner: Jose Giancarlo Palacios Loli.

DPO: dpo@criapp.smarthuaraz.cloud.


1. Who is this Notice for?

For parents and legal guardians using CriApp to track information about their children. Primary audience: 0-5 years. Legal coverage: under 13 (COPPA), under 16-18 per EU member state, under 18 (LGPD, Argentina, Colombia, Peru).

CriApp is NOT directed to children. It is directed to adults caring for children. Minors do not create CriApp accounts. The app is NOT enrolled in Google Play Designed for Families nor in Apple Kids Category.


2. Children's data we collect

Only the data you, as the responsible adult, choose to enter.

2.1 Identification

Name or nickname, date of birth or due date, gender (optional), prematurity (optional), family situation (biological/adopted/foster, optional).

2.2 Health (special category - GDPR Art. 9; LGPD Art. 11; Peru Art. 14)

Weight, height, head circumference, vaccinations, illnesses, allergies, medications, dosage, prenatal records (symptoms, kicks, contractions, gestational weight).

2.3 Behavioral

Sleep, feeding (breastfeeding/bottle/solids), diapers, developmental milestones (CDC checklists).

2.4 Media

Photos of the child / bump, scanned medical documents, drawings.

2.5 Data we do NOT collect from minors

Per the FTC 2025 COPPA amendment, "personal information" includes biometrics. We confirm we do NOT collect:


3.1 Before registering your child

We obtain verifiable consent through:

  1. Adult age verification (DatePicker, >=18 years or documented emancipation).
  2. Parental-consent screen with explicit disclosure of:
    • What child data will be collected.
    • For what purposes.
    • Who has access.
    • How to delete.
    • 2025 COPPA amendment notice: we require separate consent for any sharing with third parties beyond Service operation (not applicable to CriApp because we do NOT share child data with third parties beyond infrastructure).
  3. Express acceptance with timestamp + IP recorded (5-year retention).
  4. Ability to review and withdraw consent any time from Settings.

3.2 Verification methods (roadmap)

COPPA accepts several methods. Current and roadmap:

MethodStatusNotes
Email-plus (dual confirmation)ROADMAP Sprint 5+Recommended pre-USA launch
Credit-card verification ($0.50 refundable)NOT PLANNEDImposes burden on users; app is free
Phone / video callNOT PLANNEDDisproportionate cost
Government IDNOT PLANNEDGreater privacy risk
Mobile SMS to parent (valid post-2025 amendment)UNDER EVALUATIONOnly for confirmation

Until email-plus is implemented, we rely on adult age verification + account ownership + retained consent proof.

For shared-custody profiles we recommend obtaining the other parent's consent before uploading sensitive content (especially photos). CriApp does not technically require two-party consent but recommends it. Custody disputes are resolved through civil channels; CriApp will cooperate with valid court orders.


4. Purposes for child data

PurposeApplies?
Core functionality (tracking, reminders, WHO/CDC/AAP charts)Yes
Vaccine / medication push remindersYes
Personalized milestone trackingYes
Predictive algorithm improvement (anonymized + aggregated)Yes, with irreversible anonymization
Scientific researchNO, except with separate explicit consent
Personalized advertisingNEVER
Sharing with advertising networksNEVER
Selling dataNEVER
Sharing with external researchersNO, except aggregated and anonymized under specific DPA

5. Sharing and third parties

Child data is NEVER shared with advertisers or ad networks. CriApp v1.0 is 100% free and ad-free: we do not integrate any advertising SDK.

SubprocessorAccess to child data?Purpose
Hostinger (VPS, EU)Yes (encrypted at disk)Hosting infra
Garage S3 (self-hosted on VPS)Yes (child photos)Storage
SentryPossible if error logs include IDs (sanitization applied)Crash monitoring
Expo PushAdult push tokens only, no child dataNotification delivery
ResendOnly when you export data via emailTransactional email
Backblaze B2 / HetznerEncrypted data (key on our servers)Off-site backup

6. Your rights as parent / guardian

6.1 Right to know

Settings - Data - Export (generates ZIP with JSON of all child data + photos as JPEGs).

6.2 Right to correct

In-app edit of any record.

6.3 Right to erase (right to be forgotten)

Settings - Privacy - Withdraw parental consent:

6.5 Right to portability

Standard JSON / ZIP export including photos as JPEGs.

6.6 Right not to be subject to automated decisions

We do NOT make significant automated decisions about your child. Milestone, nap, and dose predictions are informational suggestions, not diagnoses.

6.7 Response time

30 calendar days (GDPR); 20 working days (Peru); 15 days (LGPD); 30 days (CCPA).


7. California AADC compliance

Although CriApp is not directed to minors, the Ninth Circuit (March 12, 2026) confirmed enforceability of parts of the California Age-Appropriate Design Code. As a precaution we apply:


8. Community and real names

Real names of your children NEVER appear in the community.


9. Loss or improper exposure

If you discover exposure of your child's data:

  1. Change your password immediately.
  2. Revoke caregiver access in Settings - Caregivers.
  3. Notify dpo@criapp.smarthuaraz.cloud.
  4. If it is a Service breach: we notify within 72h to authority and directly to you if high risk (GDPR Art. 33-34; LGPD Art. 48 - 3 business days, 6 for small-scale).

10. 13-17 audience (theoretical)

If a 13-17 year old creates an account despite the age gate (e.g., a teen mother):

Operational policy: the app validates age >=18. If we discover a 13-17 case, we evaluate individually with legal counsel and delete data as appropriate.


11. Safe Harbor program (COPPA)

We are evaluating enrollment in an FTC-approved Safe Harbor program (PRIVO, kidSAFE, ESRB Privacy Certified). Current status: not enrolled. The 2025 COPPA amendment requires Safe Harbors greater transparency (public membership lists).


12. Google Play Families & Health Connect


13. Contact

TopicContact
Urgent child data deletiondpo@criapp.smarthuaraz.cloud (<=7 days)
Suspected abuse or misusesafeguarding@criapp.smarthuaraz.cloud
COPPA questionscoppa@criapp.smarthuaraz.cloud (alias to DPO)
Security breachsecurity@criapp.smarthuaraz.cloud

14. Changes to this Notice

We notify any material change in-app and by email. Current version always at /legal/children-privacy-notice and in Settings - About.


Available in es/en/pt. Authoritative version: Spanish.