Skip to content

Security at Kibu

Version 1.0.0-draftEffective 16 August 2026Updated 15 August 2026

A public summary of how we protect your family's data. The full written programme is an internal document; this page tells you what it covers and how to reach us if you find a problem.

1. Our security programme

We maintain a written information security programme specifically covering children's personal information, as US children's privacy law requires. It has five parts.

  • A named individual at Kibu is responsible for coordinating it.
  • We assess the risks to children's data at least once a year, and whenever we change what we collect.
  • We put safeguards in place against the risks we find, and record which safeguard addresses which risk.
  • We test and monitor those safeguards regularly rather than assuming they work.
  • We review and update the whole programme at least once a year.

2. Technical measures

  • All traffic between the app and our servers is encrypted in transit.
  • Data is encrypted at rest, including every photograph.
  • Photographs are not publicly accessible. Retrieving one requires an authenticated request from the family it belongs to.
  • Passwords are stored only as salted cryptographic hashes. Children's PINs are hashed the same way. Nobody at Kibu can read either.
  • Sign-in attempts are rate-limited and repeated failures are locked out.
  • Our logs are configured not to record children's content, photographs or location.
  • Application secrets are validated at startup, so the service refuses to start rather than running misconfigured.

3. Who at Kibu can see your data

Access is limited to staff whose role requires it, granted individually rather than by default, and logged. We do not browse family content. Access is reviewed when someone changes role and removed when they leave.

Support staff resolving a specific issue you have raised see the minimum needed to resolve it.

4. Our service providers

Before any company handles children's data on our behalf we assess whether it can keep that data confidential, secure and intact, and we obtain written assurances that it will. That is a legal requirement and we treat it as a hard gate rather than a formality.

The full list, with what each receives and where, is at getkibu.com/subprocessors.

5. If something goes wrong

We have a written incident response plan. If a breach affects your family's data we will tell you what happened, what was affected, what we have done, and what you should do — in plain language, without waiting for a complete investigation.

We notify regulators within the time limits that apply: 72 hours in the UK and EU, and as required by SDAIA in Saudi Arabia and by state breach laws in the US.

6. Reporting a vulnerability

If you have found a security problem in Kibu, please tell us at [email protected]. We will acknowledge within 3 working days and keep you updated.

We will not pursue legal action against anyone who reports a genuine vulnerability to us in good faith, gives us reasonable time to fix it, and does not access, modify or retain other people's data while investigating.

Please do not test against real family accounts. Ask us and we will provide a test account.

The full policy set

This policy is one of 13. The rest cover children’s privacy, consent, retention, security, AI and the terms you agree to.