Pre-pilot

Privacy at Kidoko Learning

Kidoko is built for children learning on shared school tablets in places with little or no internet. This page says, in plain terms, what the app stores, what it sends, and how a family or school can get data exported, corrected, or deleted.

What the app stores

What the app does not do

Where data goes when it syncs

Sync traffic is signed by the device and processed by the Kidoko API and the school program’s database (hosted on Supabase in the EU). Content packs are downloaded to the device and verified by signature before use. On a school LAN with a Kidoko hub, devices may sync to the hub first; the hub relays, it does not mint access.

Portfolio sharing

A learner’s work portfolio is never public. Sharing happens only when an authorized adult approves a specific, expiring link — the recipient sees a read-only sealed page, the link can be revoked (it then serves a “closed” answer forever), and it is marked noindex so search engines never list it. A downloaded export can never be recalled — the approval screen says so before an adult approves it.

Export, correction, deletion

A linked guardian (or school staff acting on a verified request) can ask for a copy of a learner’s data, a correction to a learner’s display label, age band or learning language, or deletion. Requests go through the program’s staff and are handled by the Kidoko privacy process: they are verified, approved by a second staff member (one person cannot approve their own deletion), executed, and recorded in a deletion ledger — a record that deletion happened, kept so the program can prove it.

Deletion removes the learner’s synced personal data from the service. Data still on a tablet or in a backup is deleted when the tablet next syncs or the backup rotates — the exact windows are documented for operators in the program’s privacy-ops documentation.

Contact and support

Support for the pilot runs through the school’s facilitator and the Kidoko program team — the routes are on the help page. The public site is kidoko.app. A staffed public support mailbox is part of launch preparation — this page will be updated when it exists.

This page describes the software as built and shipped for the pilot — last reviewed 2026-10-03. It is not legal advice, and the program’s full data-handling documentation (retention schedule, deletion ledger, consent records) lives in the project’s operator documentation.