Skip to content

Privacy Policy

Version 1.0.0-draftEffective 16 August 2026Updated 15 August 2026

Kibu is a family app used by parents and by children. This policy explains what we collect, why, who we share it with, how long we keep it, and how you control it. Because most of our users are children, we hold ourselves to children's privacy rules everywhere we operate — not only where the law compels it.

1. Who we are

Kibu is operated by Kibu Company, 8098 Hajr, Dhahran 34254, Saudi Arabia. We are the data controller for the personal data described in this policy — meaning we decide what is collected and why.

You can reach our privacy team at [email protected]. If you are in the European Union or the United Kingdom, you may also contact our representative for your region — see section 14.

2. Who this policy covers

Kibu has two kinds of user. A parent or guardian holds the account, pays for the subscription and controls the family's settings. A child uses a separate, limited profile created by that parent.

A child cannot create a Kibu account. Only a parent or guardian can create a child profile, and only after giving the consents described in section 5.

There is a plain-language version of this policy written for children at getkibu.com/privacy-for-kids. Children should read that one.

3. What we collect

We separate this into what we collect about parents and what we collect about children, because the rules and our commitments differ.

3.1 About parents and guardians

DataWhy we collect itLegal basis (UK/EU)
Full name, email address, password (stored only as a cryptographic hash)To create and secure your accountPerformance of a contract
Phone number (in some countries)To verify it is really you, and to recover your accountPerformance of a contract; legitimate interests in account security
Country, derived once at registrationTo apply the right children's privacy rules and the right language to your familyLegal obligation
Your relationship to the child (for example parent, guardian, elder sibling)To set what you are permitted to do in the familyPerformance of a contract
Subscription and transaction identifiersTo manage billing and to verify parental consentPerformance of a contract; legal obligation
Messages you send to our AI assistantTo answer your questions about your family's activityPerformance of a contract
Consent records: what you agreed to, when, the notice version, your IP address, device and app versionTo prove we obtained your consent lawfullyLegal obligation
Device and app diagnosticsTo keep the app working and fix faultsLegitimate interests

3.2 About children

Everything below is collected only after a parent has given the consents in section 5. Some of it the parent provides; some the child provides themselves inside the app.

DataWho provides itWhy
Full name, date of birth, genderParentTo personalise the app and to set age-appropriate activities
Username and PINChildTo let the child sign in to their own profile
A photograph of the child's faceChild, using the cameraUsed once to generate a cartoon avatar, then deleted. See section 9.
The generated cartoon avatarDerivedShown as the child's picture in the app, and to friends if the social feature is on
Photographs attached to completed missionsChildSo a parent can see and approve what the child did
Posts: captions and photographsChildShared with approved friends, if the social feature is on
Messages within the family chatChildTo let family members talk to each other. Children cannot message anyone outside their family.
Friend connections, reactions and stickersChildTo run the social feature
Mission history, points, level, streak, badges, coinsDerivedTo run the game mechanics and produce the weekly report
Answers to the daily questionChildTo generate the family's daily activity
Device notification tokenDeviceTo deliver notifications to the child's device

3.3 What we deliberately do not collect

  • We do not collect a child's email address, phone number or home address.
  • We do not collect precise location from children.
  • We do not retain the original photograph of a child's face after their avatar is generated.
  • We do not serve advertising of any kind, to anyone, and we do not sell personal data.
  • We do not let children talk to an AI chatbot. The AI assistant is available to parents only.
  • We do not request the advertising identifier on any platform.

4. How we use what we collect

We do not use children's personal data for behavioural advertising, and we do not build advertising profiles. We do not use children's personal data to make automated decisions that produce legal or similarly significant effects.

  • To run the app: accounts, sign-in, missions, rewards, chat, notifications.
  • To generate a cartoon avatar from a photograph the child takes.
  • To produce mission suggestions and a weekly summary for the parent.
  • To keep children safe: screening content, handling reports, enforcing our community guidelines.
  • To take payment and manage subscriptions.
  • To understand how the app is used and improve it — for children, only where a parent has given verified consent.
  • To meet our legal obligations and to prove we did.

6. Analytics, and how we treat children differently

We use a third-party analytics provider to understand how Kibu is used. For adults this runs on our legitimate interest in improving the product, and you can object at any time.

For children it is different, and stricter. If a parent has not given verified consent for analytics, we collect nothing at all about that child — not a reduced set, not an anonymised event. No event is sent.

Where consent has been given, a child's analytics is still limited: a fixed list of permitted fields, no location, no advertising identifier, and no marketing profile. We do not create analytics profiles for children.

We do not rely on the COPPA 'support for internal operations' exception to collect from children without consent.

7. Who else sees this data

7.1 Other families

If — and only if — a parent turns on Kibu Club, a child can be found by other children who already know their exact username. Partial searches return nothing; browsing for strangers is not possible.

Where a friendship is approved, the friend can see the child's username, cartoon avatar, level and title, and the posts the child shares. A child's real name, date of birth, gender and family details are never shown to another family.

Chat is family-only. A child can never be messaged by someone outside their own family.

7.2 Service providers

We use a small number of companies to run Kibu. Each is bound by a written agreement requiring them to act only on our instructions, to keep the data secure, not to use it to train their own models, and to delete it when we say so.

The current list, what each receives, and where each is hosted, is published and kept current at getkibu.com/subprocessors.

7.3 Who never sees it

We do not sell personal data. We do not share it with advertisers, data brokers or social networks. We do not disclose children's personal data to anyone except as described in this policy or where the law requires it.

8. Artificial intelligence

Kibu uses AI in four places, all described in full at getkibu.com/ai. In summary: generating a cartoon avatar from a photograph; screening what a child types before it is used; suggesting missions to a parent; and writing the parent's weekly summary.

No AI provider is permitted to train on your family's data. Children cannot converse with an AI. The avatar is AI-generated imagery and is labelled as such in the app.

9. Photographs of children

This is the most sensitive thing we handle, so we are specific about it.

When a child creates an avatar, they take a photograph. It is sent once to our AI provider, used to generate a cartoon, and then deleted. We do not keep the original photograph. If the child wants a different avatar later, they take a new photograph.

Mission photographs and post photographs are kept for the periods in our retention policy and are deleted when that period ends, when the parent deletes them, or when the account is deleted.

We do not use facial recognition. We do not create or store faceprints or facial templates. We do not attempt to identify anyone from a photograph.

Photographs are stored encrypted and are not publicly accessible. Access requires an authenticated request from the family the photograph belongs to, or from our support staff under the access controls in our security programme.

10. How long we keep it

We do not keep children's personal data indefinitely. Every category has a defined retention period and an automated deletion process.

The full table — what we keep, why we need to keep it, and for how long — is published at getkibu.com/data-retention. It forms part of this policy.

One deliberate exception: records of the consents you gave survive account deletion, because they are the evidence that we collected your child's data lawfully. They contain no content about your child.

11. Your rights and controls

As a parent or guardian you can, at any time and from within the app: review everything we hold about your child; download it as a file; correct it; delete an individual item, the child's profile, or the whole family account; withdraw any consent; and turn the social features off.

Depending on where you live you may also have rights to object to processing, to restrict it, to portability, and to complain to a regulator. How to exercise each, what we need from you, and how quickly we respond is set out at getkibu.com/your-rights.

We never charge for these, and we never require you to create an account or install anything to exercise them.

12. Security

We maintain a written information security programme covering children's personal data, with a named individual responsible for it, regular risk assessments, and annual review. A summary is published at getkibu.com/security.

Data is encrypted in transit and at rest. Access by our staff is limited to those who need it and is logged. We require the same standard in writing from every service provider.

13. International transfers

Kibu is operated from Saudi Arabia and uses service providers located in PROCESSOR_REGIONS. This means personal data may be transferred across borders.

Where data leaves the United Kingdom or the European Economic Area, we rely on TRANSFER_MECHANISM — for example, Standard Contractual Clauses with the UK Addendum — together with technical measures. Where data leaves Saudi Arabia, we comply with the transfer conditions in the Personal Data Protection Law.

You can ask us for a copy of the safeguards that apply to any specific transfer.

14. Our representatives in the UK and EU

Because Kibu is established outside the United Kingdom and the European Union, we have appointed representatives you can contact directly about your data.

European Union: EU_REPRESENTATIVE_NAME, EU_REPRESENTATIVE_ADDRESS, EU_REPRESENTATIVE_EMAIL.

United Kingdom: UK_REPRESENTATIVE_NAME, UK_REPRESENTATIVE_ADDRESS, UK_REPRESENTATIVE_EMAIL.

Contacting a representative has the same effect as contacting us.

15. Complaints

Please contact us first at [email protected] — we would rather fix it. You also have the right to complain directly to a regulator.

Saudi Arabia: the Saudi Data and Artificial Intelligence Authority (SDAIA). United Kingdom: the Information Commissioner's Office (ico.org.uk). European Union: your national supervisory authority. United States: the Federal Trade Commission (ftc.gov), and your State Attorney General.

16. Changes to this policy

If we change how we handle children's personal data in a way that goes beyond what you already agreed to, we will not apply the change to your family until we have asked you again and you have said yes. Silence is never treated as agreement.

For other changes we will tell you in the app and by email at least 30 days beforehand. Every previous version stays available at getkibu.com/privacy-policy/archive.

The full policy set

This policy is one of 13. The rest cover children’s privacy, consent, retention, security, AI and the terms you agree to.