1. Overview
MyDaycareAI (“we”, “us”, “our”) operates a cloud-based daycare management platform (the “Service”). This Privacy Policy describes how we collect, use, store, share, and protect information when you access our Service at app.mydaycareai.com or any related subdomain.
By creating an account or using any feature of the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, do not use the Service.
2. Information We Collect
2.1 Account & Provider Information
When you register, we collect your name, email address, phone number, daycare name, business address, and licensing information. Daycare owners and administrators can invite staff and parents, whose contact details are then stored within the platform.
2.2 Child & Family Information
Authorized daycare staff enter information about enrolled children and their families, which may include: child's name, date of birth, allergies and medical conditions, emergency contacts, authorized pickup persons, attendance records, daily activity notes, and photographs for daily reports.
2.3 Billing & Payment Information
Payment processing is handled by our payment partners (Stripe, UniBee). We do not store full credit card numbers or banking credentials on our servers. We retain transaction records, invoice history, and subscription status for accounting and support purposes.
2.4 Usage & Technical Data
We automatically collect IP addresses, browser type, device identifiers, access times, feature usage logs, and error reports. This data helps us maintain security, diagnose problems, and improve the Service.
3. Children's Data & COPPA / FERPA
MyDaycareAI is designed for licensed childcare providers who operate under their own regulatory obligations. We recognize that information about children under 13 requires heightened protection.
- Role of the Daycare: The daycare provider is the “owner” of child data within the platform. MyDaycareAI acts as a data processor on the provider's behalf.
- Parental Consent: Daycare providers are responsible for obtaining appropriate parental consent before entering or sharing a child's information in the Service, in accordance with applicable state and federal laws.
- Access Controls: Child data is tenant-isolated. Only authorized staff and linked parent accounts within the same daycare can view a child's records. No cross-daycare data sharing occurs.
- Data Minimization: We recommend entering only the minimum information necessary for daily operations and licensing compliance.
- Photos: Photos uploaded for daily reports are stored in encrypted object storage and are accessible only to authorized users within the same daycare.
4. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Service's features
- Process attendance, billing, communication, and compliance workflows
- Generate AI-assisted content such as social media posts, parent messages, and business insights
- Send service notifications, security alerts, and important account communications
- Detect, prevent, and respond to fraud, security incidents, and abuse
- Comply with legal obligations and law enforcement requests where required
5. AI-Powered Features
The Service includes AI-powered tools (e.g., content generation, business insights, an AI assistant). These features use third-party AI providers (such as OpenAI) to process text and generate responses.
- Data Sent to AI Providers: Only the text inputs you explicitly submit to AI features (e.g., a message draft request, an insight query) are sent to our AI provider for processing. Sensitive fields such as child medical records and financial data are not automatically included in AI requests.
- No Training on Your Data: We configure our AI provider API calls to opt out of using your data for model training.
- AI Output Accuracy: AI-generated content may contain errors. Always review AI output before sharing it with parents or posting publicly. MyDaycareAI is not liable for decisions made solely on AI-generated suggestions.
6. Data Sharing & Third-Party Processors
We do not sell your personal information or children's data. We share data only with the following categories of service providers, each bound by data protection agreements:
- Database Hosting: Supabase / PostgreSQL (encrypted at rest and in transit)
- File Storage: Supabase Storage (encrypted object storage for photos and documents)
- Payment Processing: Stripe (PCI-DSS compliant) and UniBee (billing management)
- AI Processing: OpenAI (content generation, with training opt-out enabled)
- Email Delivery: Resend / Nodemailer via SMTP
- SMS Notifications: Twilio (when enabled)
- Error Monitoring: Sentry (error and performance data, no child PII)
- Rate Limiting & Caching: Upstash Redis
- Social Media Publishing: Facebook Graph API (only when you connect your account)
We may also disclose information if required by law, court order, or government regulation, or to protect the rights, property, or safety of our users or others.
7. Data Security
We implement industry-standard safeguards including:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption at rest in the database and object storage
- Multi-tenant data isolation — each daycare's data is logically separated and access-controlled
- Role-based access control (OWNER > ADMIN > STAFF) with permission checks on every request
- Authenticated sessions via secure JWT cookies (HTTP-only, SameSite)
- Rate limiting and abuse detection on public and authenticated endpoints
- Comprehensive audit logging of administrative actions
- Regular dependency and security scanning
No system is 100% secure. If we become aware of a security breach, we will notify affected users and relevant authorities as required by applicable law.
8. Data Retention & Account Deletion
- Active Accounts: Data is retained for as long as your daycare account is active and your subscription is current.
- Cancelled Accounts: Upon cancellation, you may export your data. After 30 days, child records, attendance history, and media are permanently deleted.
- Audit Logs: Security and administrative audit logs are retained for up to 24 months for compliance purposes.
- Account Deletion: Daycare owners can request full account deletion by contacting contact@mydaycareai.com. We will process verified deletion requests within 30 days.
- Soft-Deleted Records: Records removed through the application UI may be soft-deleted (marked inactive) to preserve audit trails. These are permanently purged during full account deletion.
9. Your Privacy Rights
Depending on your location (e.g., California, EU/EEA), you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request erasure of your personal data (subject to legal retention requirements).
- Opt-Out: Unsubscribe from marketing communications at any time.
- Data Portability: Request an export of your data in a machine-readable format.
To exercise these rights, contact contact@mydaycareai.com.
10. Cookies & Local Storage
We use essential cookies for authentication (session management) and security. We do not use third-party advertising or tracking cookies. Functional cookies may be used to remember UI preferences (e.g., theme, language).
11. International Users
The Service is designed for U.S.-based childcare providers. Your data is processed and stored on servers located in the United States. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S., where data protection laws may differ from your jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email or in-app notification at least 30 days before the changes take effect. The “Last updated” date at the top reflects the most recent revision.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at contact@mydaycareai.com.