DRAFT — not legally published. Counsel review pending. Do not rely on this text as a published policy.
Trust Center
Security, privacy and safety practices, plus the contacts that reach a responsible human.
PHASE B — DOCUMENT 8: SECURITY / TRUST CENTER
Status: draft for review. Canonical route: kidchat.io/trust.
Who operates KidChat
KidChat is a technology service operated by NOXON, LLC, a Texas limited liability company (Texas, United States). Español: KidChat es un servicio tecnológico operado por NOXON, LLC, sociedad de responsabilidad limitada constituida en Texas, Estados Unidos.
Contact: privacy@kidchat.io · safety@kidchat.io · security@kidchat.io · legal@kidchat.io
No further corporate information is published unless legally required. Notice address per jurisdiction: [COUNSEL REVIEW REQUIRED — PRIVACY CONTROLLER / RESPONSIBLE ENTITY ADDRESS]
Primary message: "Built for children means held to a higher standard."
A. TRUST CENTER STRUCTURE
| Route | Contents |
|---|---|
| /trust | Entry page, the message above, links to everything below |
| /trust/privacy | Parent Privacy Policy / Aviso de Privacidad (doc 2) |
| /trust/children | Children's Privacy Notice, both layers (doc 1) |
| /trust/safety | Child Safety Policy (doc 5) |
| /trust/ai | Responsible AI / AI Limitations (doc 6) |
| /trust/security | This document |
| /trust/parents | Parent Rights & Controls (doc 7) |
Legal copies may also live at kidchat.io/legal/privacy, /legal/terms, /legal/cookies. /trust is the parent-facing entry point.
B. WHAT WE CAN SAY TODAY
- Data is encrypted in transit (HTTPS everywhere) and at rest by our managed database provider. (C-17) — wording must match the provider's own documentation.
- Access to a child's conversations requires the account holder's authentication plus Parent PIN or re-authentication, and each access is recorded. (C-12)
- Database access is restricted per account by row-level security: one family's data is not reachable from another family's session.
- Secrets and provider keys are held server-side only and are never exposed to the browser.
- Gateway prompt/content logging is off for child traffic; the AI cost ledger stores no conversation content. (C-18)
- No advertising SDKs, no advertising identifiers, and no third-party behavioral analytics run in Kid Mode. (C-09, C-10)
C. WHAT WE WILL NOT CLAIM
No certification or audited-compliance claim of any kind: no SOC 2, no ISO, no PCI, no "COPPA certified", no "GDPR compliant", no penetration-test badge, no 24/7 monitoring, no "your child's data is never shared". If we obtain one, we will publish the report date and scope, not a logo.
D. INFRASTRUCTURE AND SUBPROCESSORS
A current subprocessor list is published and dated at /trust/security: hosting/CDN, managed database and authentication, AI gateway and approved model providers, transactional email. Each must clear vendor review before touching child data: retention, training, logging, subprocessors, security, DPA, data location and transfer mechanism, deletion, incident notification. [TECHNICAL CONTROL REQUIRED — vendor files and dated subprocessor page]
Voice is off by server-side feature flag: microphone and audio endpoints are unreachable, and no dormant microphone functionality that records or transmits audio is exposed. (C-16) Re-enabling requires provider review, contract, retention review, consent analysis, safety review, and a privacy-copy update.
E. BACKUPS AND DELETION
Backups exist for disaster recovery. Deletion from active systems happens as soon as reasonably practicable; the target backup purge window is 30 additional days, pending measurement. [TECHNICAL VALIDATION REQUIRED — BACKUP RETENTION] Restored data is used only for disaster-recovery or security purposes, and deletion requests are re-applied where technically required.
F. INCIDENT RESPONSE
Report a vulnerability or suspected incident to security@kidchat.io. We acknowledge reports, investigate, and notify affected parents and regulators where the law requires it — in Mexico under the LFPDPPP breach-notification duty, in the United States under applicable state breach laws. We do not promise a notification time we have not committed to operationally. [TECHNICAL CONTROL REQUIRED — incident runbook + contact rotation]
G. SEGURIDAD — español (México)
- Ciframos la información en tránsito (HTTPS) y en reposo mediante nuestro proveedor de base de datos administrada.
- El acceso al historial requiere autenticación del titular de la cuenta y NIP, y cada acceso queda registrado.
- Aislamiento por cuenta mediante seguridad a nivel de fila.
- Sin SDK de publicidad, sin identificadores publicitarios y sin analítica conductual de terceros en el Modo Niño.
- No afirmamos ninguna certificación (SOC 2, ISO, PCI) ni cumplimiento auditado.
- Incidentes: security@kidchat.io. Notificamos a las personas afectadas y a la autoridad cuando la ley lo exige.
Who operates KidChat
KidChat is a technology service operated by NOXON, LLC, a Texas limited liability company.
KidChat es un servicio tecnológico operado por NOXON, LLC, sociedad de responsabilidad limitada constituida en Texas, Estados Unidos.
NOXON, LLC — Texas, United States. privacy@kidchat.io · safety@kidchat.io · security@kidchat.io · legal@kidchat.io
© 2026 KidChat. Operated by NOXON, LLC.
