Privacy Policy
Pass the Note — from Pass The Note Kids LLC
Applies to the Pass the Note website (passthenotekids.com) and to the Pass the Note app: the iOS app, the parent portal, and the kids app.
Read this first
Pass the Note is a small, closed messaging app for kids. A grown-up sets it up. A grown-up approves every person a child can write to. Every note is checked by an automated safety system before it is delivered.
That design means we handle two things that deserve a straight answer: your child's notes, and the pictures they draw and send. This policy tells you exactly what happens to them, who else sees them, and what we cannot yet do.
Pass the Note is not yet generally available. This policy describes how the service works and how information is handled today. Where something is designed but not finished, we say so plainly instead of promising it. We would rather be uncomfortable and accurate than smooth and wrong.
1. Who we are
Pass the Note is operated by:
Pass The Note Kids LLC [email protected]
Pass The Note Kids LLC is the only company that runs Pass the Note. Other companies help us run it — hosting, email, payments, the safety check — and every one of them is named in section 7.
For anything about privacy, parental consent, or your family's information, write to [email protected]. For everyday help, write to [email protected].
2. What this policy covers
| Surface | What it is | Covered here |
|---|---|---|
| passthenotekids.com | Our marketing website and the private-beta request form | Yes — section 16 |
| Parent portal | The grown-up web app: accounts, children, contacts, oversight, billing | Yes |
| Pass the Note for iOS | The app on the App Store, used by both grown-ups and kids | Yes |
| Kids app | The kids' messaging app | Yes |
The App Store "App Privacy" summary is narrower than this policy. That summary on our product page describes only what the iOS app itself collects. This policy covers the whole service — the parent portal and the website as well — so it names some things the App Store summary does not.
Where to find this policy. This page is always at passthenotekids.com/privacy.
What is not offered in this release. Some things are built in our code but are not offered to families today: a family/co-parent household, in-app notes between a grown-up and a child, and a paid Plus subscription bought inside the iOS app. Each is switched off by default in the apps we provide to beta families. If we switch any of them on, we will update this policy first, and where the change is material we will ask parents for consent again rather than assume it.
3. What we collect from grown-ups
When you create a parent account, we collect:
- Your email address and the display name you choose. Your email is how you sign in and how we reach you.
- Your password — handled by our sign-in provider, Supabase. We never see it or store it ourselves.
- An account identifier. We give your account, and each child's profile, an internal ID number so our records stay tied together. It is ours, it means nothing outside Pass the Note, and it is not your device, your phone number, or any advertising ID.
- Your consent record — the date, the method, the payment reference, and the exact words you agreed to when you gave parental consent (section 8).
- Your plan and billing state — whether you are on the free or paid plan, when it renews, and a customer reference number from our payment processor, Stripe. We never receive or store your card number.
- Some small settings — whether you want email notifications, whether you want push notifications on your own phone, whether you finished setup, whether you have dismissed the product tour, and whether you have allowed notifications on each of your children's devices.
- A device push token for your own phone, if you turn notifications on there. It is the same kind of token described in section 4, and section 10 says how long we keep it.
If you request a place in our private beta through the website, we collect the parent or guardian's full name and email address, the time of the request, and that it came from the website beta form. We do not ask for a child's name, age, or any other child information in that form.
If a selected beta parent refers another adult, we ask them to get that person's permission before replying with the person's full name and email address. We use that information only to consider and contact the referred adult about the beta. Do not send us information about a child in a referral.
When you invite another family so your child can write to theirs, we collect that other grown-up's email address, and optionally the first name you type for their child so they know who the invite is about. That person has not signed up with us at the time you send it. We store the invite so it can be accepted.
If you write to us — a support message, a suggestion, a reply in a support thread — we keep what you wrote and our replies.
We record when you last opened a conversation, so unread counts work. We do not record anything else about how you use the app — no taps, no screen views, no session analytics.
4. What we collect from children — and how little
We designed the kids' side to hold as little as possible.
We collect from a child:
- A display name and, if they choose one, a nickname.
- An age band — young child, tween, or teen. Chosen by you.
- A safety setting — how strict the automated check should be for that child. Chosen by you, not by them.
- An avatar they build from parts (see below).
- The notes they write — the words, kept in full.
- The pictures they send — a photo they pick, or a doodle they draw.
- If they use the "this doesn't feel right" button: the reason they picked, the conversation, and — in the kids web app — an optional short note in their own words. A safety report goes to our safety team so a grown-up can act on it, and our team can see the child's name and anything the child typed. We do not tell the other child that a report was made.
- Which notes they have opened.
We do not collect from a child:
- No date of birth. We ask for an age band, not a birthday.
- No email address. Children do not have one in our system.
- No phone number, no home address, no school.
- No location. No app on any platform asks for location permission, and we never ask a child where they are. When your child picks a photo, it leaves the device as it came off the camera. Our server removes the GPS and other camera metadata from JPEGs: the copy sent to the safety check is stripped, and so is the copy we store and serve back to you. We do not use location data, and we do not keep it.
- No microphone, no camera, no voice notes. The iOS app asks for three device permissions: Face ID (to check a grown-up is opening a grown-up area), read-only access to the photo library (so a child can pick a picture to send), and notification permission. On a child's device it asks for that third one only after a parent has allowed notifications for that specific device, from the Devices screen in the grown-up side of the app; a child's device is never asked before that. On the grown-up side, the app asks for notification permission only when you turn on "Notify me on this device" in Settings — never during sign-in. There is no camera permission and no contacts permission.
- Push notifications, and the device token that makes them possible. When push notifications are switched on for a child's device, or for your own, Apple gives the app a device push token — an identifier for that one app on that one device — and we store it so we can ask Apple to deliver a notification. We treat that token as personal information belonging to whoever the device belongs to, including a child. It is stored only while the device is signed in: signing out, re-linking a child to a new device, removing a child, or deleting the account all revoke it, and deleting your account erases it outright.
A notification never contains the note. It carries no message text, no picture, no name — not the sender's and not your child's — and nothing about a safety decision. It says only that something new is waiting; the app shows what it is after the person opens it. This is deliberate and it is not a style choice: a notification that has already been delivered to a lock screen cannot be recalled, so if a note is later withdrawn by a safety check, anything the notification had already displayed would be impossible to take back. A child's device gets no notification for a note that is held, blocked, or under review — not even a silent or generic one. If you have turned on notifications on your own phone, a held or blocked note produces the same generic notification as anything else waiting for you, and it never says what happened (section 5). The app icon may show a number. If you allow badges, it counts how many things are unread in Pass the Note — and that number is the only thing the badge says: not what they are, not who they are from, not which child they are about, and not whether anything was checked.
- No advertising identifiers, no tracking, and no device identifiers beyond that push token. The push token described above is the only device-level identifier we hold; we hold it only while that device is signed in, and we use it only while notifications are on for it. In the App Store "App Privacy" summary it is listed as "Device ID". (We do give each child profile an internal ID of our own — see section 3.)
Nothing a child writes or draws is ever public. Pass the Note has no public profiles, no feeds, no search, and no way for a child to publish anything to strangers or to the open internet. A child's notes, pictures, nickname and avatar go only to the specific contacts both parents approved, and to those children's parents. There is no feature that lets a child make their own information publicly available.
Avatars work differently for kids and grown-ups, and you should know which is which. A child builds their avatar out of parts — no camera, no photo upload; this is enforced in the code, not just by policy. A parent, in the web parent portal, can upload an actual photograph of their child as that child's picture. If you do that, you are giving us a photo of your child. It is checked by the safety system and stored privately.
Some things stay on the device and never reach us. The Sketchbook — every drawing your child saves but does not send — lives only on that device. It has no server and no sync. The same is true of the grown-up PIN, which is stored only as a scrambled fingerprint, never as the digits themselves. If your child is offline, a note they wrote waits on the device until the connection returns, and is then sent to us as normal.
5. How notes are checked before delivery — and what that means
This is the part parents most want explained clearly, so here it is without hedging.
Every note is checked before it is delivered. The check runs first and its result decides what happens next. In a narrow case where the same note is judged twice, a later judgment does not pull back a note that has already been delivered — when that happens we record both judgments. There is one exception: the child sexual abuse rule in section 14 is enforced even after delivery.
Here is what happens when your child taps send:
- The note is saved to our database.
- Simple built-in rules look at the words first. A plainly harmless, text-only note can be cleared right here and go no further.
- If a note with identical wording and context was already judged very recently, that earlier judgment can be reused.
- Otherwise — and always, without exception, for any picture — the content is sent to Anthropic, the company behind Claude, for an automated safety judgment.
- The result decides: deliver, hold for a grown-up to look at, or block.
What is sent to Anthropic, plainly:
- The full text of the note being checked.
- Up to 20 earlier notes from that same conversation, for context — which includes notes written by the other child.
- For a picture: the entire image file. Every photo. Every doodle. Every avatar image. The text of a nickname a child proposes goes through the same check.
- Not names. In the material we send, the children are described as "the child being moderated" and "the other child." Their names are not included.
- Not camera metadata. GPS and other EXIF data are stripped from JPEGs before the image is sent.
Anthropic processes this for us so we can make a safety decision. We do not use it for advertising, and there is no advertising anywhere in Pass the Note.
If the safety check cannot finish, we hold the note. A timeout or an outage never results in a note being let through. It fails safe, toward holding.
We keep a record of every check. That record includes the decision, the score, the model's written reasoning, and a copy of exactly what was sent for review — which means a second copy of your child's words, and of the other child's recent words, exists in that record. Deleting a note would not by itself remove that copy.
Blocked notes are kept, not thrown away. If a note is blocked, the note still exists and you can still see it in the parent portal, with the exception described in section 14. That is deliberate: we think you should be able to see what your child tried to send.
Your child is not told why — and if we push an alert to your phone, it does not say why either. A note that is blocked or held simply looks to your child like it did not send. A note held on its way to your child simply never appears — there is no placeholder and no notification. You can see it; your child cannot. Held and blocked notes appear in your parent portal when you open it. We do alert you when a note is held or blocked, in up to three ways: a notification always appears in your parent portal; unless you have turned parent emails off in your settings we also send you an email; and if you have turned on notifications on your own phone, it gets the same generic "Something new is waiting" push that any other item in your notifications produces — it never says what happened, which child it concerns, or who wrote the note. Turning email or push off changes how you are told, never whether you can see the note — the in-app notification is always written and the portal always shows the note. And there is one case where you are told nothing at all: when a note is blocked under the child sexual abuse rule in section 14, no alert reaches you — not in the portal, not by email, and not by push — and we may be legally barred from telling you a report was made. We think invisible moderation is the right call for a young child, and you should know we made it — and know its limits.
The strictest category cannot be turned off. If the safety check indicates apparent child sexual abuse material, the content is blocked outright. No setting, no plan, and no parental preference can override that, and it is handled as described in section 14.
6. What a parent can see — including the other family's child
The parent portal shows you your child's conversations, including notes that were held or blocked, and the moderation decision behind each one. The one category we do not surface to you is described in section 14.
Three things follow from that, and we want you to read them before you invite anyone.
First: you can see both sides of your child's conversations. When your child writes to another child, the other child's notes are in that conversation, and they are visible to you.
Second: the moderation record we show you includes the snapshot described in section 5 — which contains recent notes from the other child as well as your own. So the other family's child's words can appear in your view.
Third: approving a contact is how you consent to this. When you approve a contact, you are agreeing that your child's notes and pictures in that conversation — and the safety records about them — will be visible to the other child's parent, including in any copy of their information that parent asks us for. The other child's parent agrees to the same about their child. That is what a dual-approved contact means. Both grown-ups approved it, and both grown-ups can see it. If you are not comfortable with that, do not approve the contact; if you change your mind, revoke it.
Either parent can revoke a contact at any time, from the parent portal or the iOS app. Revoking it closes the channel for both children immediately.
7. Who we share information with
We do not sell your family's information. We do not share it for advertising. There is no advertising network, no analytics service, and no attribution or tracking SDK anywhere in the website, the parent portal, the kids app, or the iOS app. In the parent portal, the kids app, and the iOS app, automated tests fail our build if a known advertising, attribution, or analytics package is added.
These are the companies and organisations that receive information, what they get, and why:
| Who | What they receive | Why |
|---|---|---|
| Supabase | Everything in our database and file storage: parent accounts and emails, children's profiles and pictures, note text, images, moderation records. Also handles parent sign-in, so your browser or the iOS app connects to Supabase directly when you log in. | Database, sign-in, and private file storage |
| Anthropic | The text of notes being checked, up to 20 recent notes from that conversation for context, the complete image file for every picture, doodle and avatar checked, and the text of a nickname a child proposes. Sender names are not included. | The automated safety check described in section 5 |
| Mailgun | Email addresses we send to, plus what is in the email. For a contact invite, that includes the inviting grown-up's name and the inviting child's first name, and sometimes the name you typed for the receiving child. Configured to Mailgun's United States region. | Sending invite, account, and support emails |
| Stripe | For the consent charge: a 50-cent payment and an internal reference number for your account — no name, no email, no child data from us. Your card details go from your browser straight to Stripe; they never reach our servers. | Parental consent charge and subscription billing |
| Cloudflare | Hosts our website, parent portal, and kids web app. Cloudflare also runs the Turnstile security check on the beta form and processes connection and browser signals, including your IP address, to distinguish people from abusive automated traffic. Beta-request names and email addresses pass through the website to our backend but are stored in our Supabase database, not with Cloudflare as the beta-request record. | Hosting, form delivery, and security |
| Fly.io | Runs our backend server, in a United States region. | Hosting |
| Apple | App Store distribution. When notifications are on for a device, Apple also receives that device's push token and each notification we ask it to deliver — which carries no note text, no picture, no name, and nothing about a safety decision, only that something is waiting and how many things are unread (section 4). If in-app subscriptions are switched on in a future release, Apple would handle that purchase — the app cannot make a purchase today. | App distribution; delivering notifications |
| Sentry | Scrubbed backend error events: exception messages and code stack traces; limited technical details such as request ID, route, status and duration; and, for urgent safety alerts, an opaque case ID and surface category. Request and user fields are removed, outbound context is allowlisted, email and phone patterns are redacted, and performance traces are disabled. We do not intentionally include note text or images. | Backend error monitoring and urgent operational alerting |
| Google Fonts | Your browser's IP address, when you load our website or the parent portal in a web browser. Google's font service is requested by those pages. The iOS app and the kids app bundle their fonts and do not contact Google. | Web page fonts |
| NCMEC and law enforcement | Where we are required to report apparent child sexual abuse material: the content itself, the account information of the child and the parent it came from, and the times involved. Separately, information we must produce in response to valid legal process, and information we may disclose in a genuine emergency. | Mandatory reporting under federal law; response to legal process; emergencies. See section 14 |
The companies above use their own service providers to run their services. Anthropic publishes its list at anthropic.com/subprocessors. We review changes to that list and will update this page if a change matters to your family's information.
Backend error reporting is configured. Our production backend is configured to send the scrubbed error events described above to Sentry. Sentry performance tracing is disabled. None of the apps — iOS, parent portal, or kids app — contains a crash-reporting, diagnostics, or performance SDK. If that changes, we will update this list and, where it applies, our App Store privacy details.
What our own staff can see. Our internal moderation tools show decisions, scores, and case references — not your child's note text or pictures. Separately, when a child uses the "this doesn't feel right" button, our safety team sees that report, including the child's name and anything the child typed in their own words, so we can act on it. Every action a staff member takes in those tools is written to an append-only log: our application is blocked from editing or deleting entries in it.
8. Parental consent
A child cannot sign themselves up for Pass the Note. There is no way to. A grown-up creates the account, creates each child's profile, and approves every contact — and a contact between two children only opens when both children's parents have approved it.
How we ask for consent. As the first step of setting up your account, in the parent portal in a web browser, we ask you to:
- Confirm that you are at least 18 and are the child's parent or legal guardian, and
- Complete a $0.50 charge on a payment card, which we refund immediately.
A card charge shows up on the cardholder's statement, so the person consenting has to control an adult payment card. We refund it immediately — it is a check, not a fee.
The safety check cannot be separated from the service. Every note and every picture is checked by Anthropic before it is delivered (section 5). That check is how Pass the Note works — there is no version of the service without it — so consenting to your child using Pass the Note necessarily includes consenting to that check. We do not disclose your child's information to any other third party except as set out in sections 7 and 14. If you do not want your child's notes and pictures checked by Anthropic, do not set up an account.
We record: the date and time, the method, the payment reference from Stripe, the amount charged and refunded, and the exact words you agreed to. We never see your card number.
The iOS app does not take a card. It sends you to the parent portal in a browser to do this.
9. Your rights as a parent — and what we can actually do today
You have the right to see the information we hold about your child, to stop us collecting more, and to have it deleted. Here is the honest state of each.
Seeing it
Sign in to the parent portal, then email [email protected] from the address on your account. We will confirm it is you — by asking you to complete a confirmation step in the parent portal while you are signed in — before we send anything.
There is a built-in export that gathers, in one file: your account, each of your children's profiles, their approved contacts, their note and moderation history, any safety reports, your recorded consent, and your household. It only ever returns your own family's records. There is no self-serve download button yet — a person on our team runs the export and sends it to you.
Note that an export of your child's conversations will contain notes written by the other child in those conversations, for the reasons in section 6.
Stopping further collection — this works today
- Revoke a contact. In the parent portal or the iOS app. It takes effect immediately for both children.
- Remove a child. This closes that child's profile and revokes their contacts, so no new notes are sent or received.
- Close your account. In the iOS app. This closes the account and schedules it for deletion in 30 days. Read "Deleting it" below for what that does and does not remove.
Removing a child or closing your account stops new information from being collected. It does not by itself erase what is already stored. Read the next part.
Deleting it — read this carefully
We are not going to tell you something here that is not true.
Today we cannot erase your family's information on request. The in-app "delete my account" control closes your account and marks it for deletion after 30 days. It does not, by itself, erase your family's notes, pictures, and moderation records from our database. The automated erasure step is written and tested but is not yet connected to anything, and we are not going to imply otherwise.
What you can do now: email [email protected] and we will tell you exactly what we hold about your family and where your request stands.
We will replace this section the moment deletion runs end to end, and we will say what it removes and how long it takes.
One exception will always remain. If content is caught up in a suspected child sexual abuse case, we are required by federal law to preserve it, and it is deliberately excluded from deletion. We have built that exclusion into the deletion logic itself, so that when automated deletion runs it cannot erase preserved material — the code stops rather than guesses. Until that automated deletion is connected, deletions are carried out by a person, and applying this exclusion is part of that manual process. We will not confirm or deny whether any specific case exists.
If you say no
If you refuse to allow information that Pass the Note needs in order to work — a display name, an age band, the notes themselves — we may not be able to keep the account open for your child. We will tell you if that is the case.
10. How long we keep information
We are going to be direct: we have not yet set automatic deletion timers for most categories, and we are not going to publish numbers that our systems do not enforce. We do not intend to keep your family's information forever, and this table is an honest statement of where we are — not a target we have already hit.
| What | Why we collect it | Why we need to keep it | How long |
|---|---|---|---|
| Parent account, plan, settings | To run your account and bill it | To keep the account working | While your account is open. No automatic deletion timer is in place yet. |
| Children's profiles, nicknames, avatars, safety setting | To run the service for that child | To keep the profile working | While the account is open. Removing a child marks the profile as removed; it does not erase it. |
| Notes — text and pictures | So children can write to approved contacts | So you can see your child's conversations, including blocked attempts | No automatic expiry. Kept until deleted. |
| A photo or doodle in a blocked note | To check it before delivery | So you can see what your child tried to send | Kept in place. No automatic expiry. |
| Moderation records, including the copy of what was checked | To make a safety decision before delivery | So a decision can be explained and reviewed | No automatic expiry. |
| Safety reports your child sends, including anything they typed | So a child can flag something that feels wrong | So our safety team can act on them | No period set. |
| A nickname or avatar your child proposed, including one that was held and never shown | So a child can suggest a change for you to approve | So a proposal can be reviewed and approved | No period set. |
| Read markers — when a conversation was last opened | So unread counts work | So counts stay right between sessions | No period set. |
| In-app notifications and household records | To run your account | To keep the account working | While the account is open. No automatic deletion timer is in place yet. |
| Device push token for a child's device — only when notifications are on for it | So Apple can deliver a notification to that device | So a notification can reach the device while it is signed in | Only while the device is signed in. Signing out, re-linking the child to a new device, removing the child, or deleting the account revokes it; deleting the account erases it. |
| Device push token for your own phone — only if you turn notifications on there | So Apple can deliver a notification to your phone | So a notification can reach your phone while it is signed in | Only while your phone is signed in. Turning the switch off stops us using it, but the token stays until you sign out; signing out or deleting the account revokes it, and deleting the account erases it. |
| Consent records | Legal proof that consent was obtained | Must outlast the account itself so we can evidence consent | [PERIOD TO BE SET — must survive deletion of the underlying child data] |
| Invites and invitee email addresses | So an invite can be sent and accepted | So a pending invite can still be accepted | An expired invite is marked expired; the record, including the email address, is not deleted. No sweep exists yet. |
| Support and suggestion messages | So you can reach us | So we can help you and follow up | No period set. |
| Safety cases involving apparent child sexual abuse material, and the content they implicate | Mandatory detection and reporting | Required by federal law | Preserved. Excluded from deletion. The exact window is set by law and applicable legal guidance, not by us. |
| A profile picture that was rejected as unsafe | Checked before it could be shown | Preserved as evidence | Moved to a locked internal area readable only by our server. Retained. |
| Cached safety decisions | To avoid re-checking identical content | To keep the check fast and cheap | Contains only scrambled fingerprints, never any note or picture. Marked expired after 7 days; rows are removed only when we run a clean-up by hand, which is not yet on a schedule. |
| Beta requests and referrals: adult names and email addresses | To review requests, manage limited beta places, and contact selected or referred adults | So we can manage the beta and public-launch invitation | Until public launch and for up to 12 months. |
| Internal staff action log | Accountability for our own team | So staff actions stay reviewable | Append-only. No period set. |
Backups, replicas, and the records our providers keep on their own systems are governed by those providers and may persist after we delete something on our side.
We know a privacy policy is supposed to give you timeframes. Setting them properly — and building the job that actually enforces them — is work we have not finished, and inventing them would be worse than admitting it.
11. What we store in your browser and on your device
Signing in stores a session in your browser's local storage so you stay signed in; our sign-in provider Supabase handles it. We also store small items there: an invite token while you sign in to accept an invite, whether you have seen the product tour, and whether a checkout is in progress. We use no cookies for advertising or analytics.
On iOS we keep your sign-in token in the system Keychain, and small display settings on the device — which tab you were on, which notes you have opened on that device, whether you have seen the welcome screens, and your saved Sketchbook drawings.
In the kids web app, the child's sign-in session and their profile are stored on that device, along with their Sketchbook and any note waiting to send while offline.
None of these are used to identify or contact anyone, none is an advertising or cross-site identifier, and none is shared.
12. Security
What we actually do:
- All traffic runs over HTTPS/TLS. There is no custom cryptography in the app.
- Pictures are private. The storage areas holding notes' images and children's avatars are not publicly reachable. The app gets a short-lived signed link each time, after we check you are allowed to see it.
- Camera metadata is stripped on our server. Our server removes GPS and other EXIF data from JPEGs — from the copy sent to the safety check and from the copy we store.
- Our database refuses browser and app clients by default. Every table denies direct client access; only our backend can read it, and only after checking who you are.
- Our logs are built not to hold sensitive things. They do not record request bodies or query strings. Anything that looks like a token, password, email address, note body, or child's name is replaced with
[redacted]before it is written. - The grown-up PIN is never stored as digits — only as a salted, hashed fingerprint on the device. On iOS, your login token is held in the system Keychain. Face ID and Touch ID are handled by Apple on your device; we never receive face or fingerprint data.
- Every staff action is written to an append-only log that our application is blocked from editing or deleting.
IP addresses. We do not write parents' or children's IP addresses to our database. We hold them only briefly, in memory, to rate-limit abusive traffic. When one of our own staff takes an action in our internal console, we log that staff member's IP address as part of our accountability record. Our hosting and network providers necessarily see IP addresses as part of delivering the service.
No system is perfectly secure, and we are not going to claim otherwise.
13. Children's privacy
Pass the Note is built for children, including children under 13, and the whole design assumes that. Where a child is 13 or older, the same protections in this policy still apply.
- Accounts are created by a grown-up. A child cannot register.
- We ask a parent for verifiable consent, by the card micro-charge described in section 8, and we keep the record.
- Contacts require two parents' approval. Either can revoke instantly.
- We collect an age band, not a birthday. No child email, no phone, no location, and no device identifier beyond the push token described in section 4.
- We do not condition your child's participation in any part of Pass the Note — sending a note, drawing, choosing an avatar, adding a contact — on giving us more personal information than is reasonably necessary for that activity. A child needs a display name and an age band, and whatever they choose to write or draw. There is no birthday field, no email field, no phone field and no school field on a child's profile.
- Nothing a child writes or draws is public. There are no feeds, no profiles, no search.
- No advertising. No third-party analytics. No behavioural profiling of children. Nothing is used to track anyone across other apps or websites.
- Every note is checked before delivery.
- A parent can review their own family's notes and moderation decisions, stop further collection, and ask us to delete — see sections 6, 9 and 14 for what each of those actually does today and where the limits are.
We do not currently use your child's notes to train any model of our own. If that ever changes, we will tell you before it happens and ask for your consent again.
We do not claim to be certified or approved by any regulator. We would rather describe what we do and let you judge it.
14. Law enforcement, safety, and mandatory reporting
We cannot promise that your child's notes are never shared with anyone. Here is when they are.
Apparent child sexual abuse material. As a provider of a messaging service, we are legally required to report apparent child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC), which shares reports with law enforcement. This duty is not optional, cannot be turned off by any setting, and does not depend on parental consent.
A report includes the content itself, the account information of the child and the parent it came from, and the relevant dates and times.
If our system flags apparent material of this kind, it blocks it, preserves the evidence, and raises an internal case. A person on our team — not an automated system — reviews that case and makes any report. There is no automated connection to NCMEC.
We do not send you an alert when this happens. Pass the Note has no notification that tells you your child's content triggered this category, and content blocked on this path does not appear in your ordinary review queue. The note is blocked, our team is alerted, and a case is opened internally. Separately, we may be legally prevented from telling you that a report was made.
Legal process. We disclose information in response to valid legal process, such as a subpoena or court order.
Emergencies. We may disclose information where there is a genuine emergency involving a risk of death or serious physical injury.
A note on what is not yet built. Our reporting to NCMEC is a manual process carried out by a person and recorded internally. Separately, our system does not perform known-image hash matching of the kind some larger services use; our detection is a single automated check.
15. State privacy rights
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There is no advertising and no ad technology anywhere in Pass the Note.
Depending on where you live, you may have rights to know what we hold, to correct it, to delete it, and to opt out of sale or sharing. Section 9 describes what we can do today for each of those, and is the honest answer for everyone regardless of state. Write to [email protected] and we will tell you what we can do and do it.
Pass the Note is built for families in the United States. Our backend server runs in a United States region and our email provider is set to its United States region. Our database and file storage are hosted by Supabase; we do not make a data-residency commitment for them in this version of the policy. If we offer the service outside the United States, we will update this policy first.
16. The website and private-beta requests
The marketing site at passthenotekids.com has no accounts, no advertising trackers, and no third-party analytics.
If you request a beta invite, we store the parent or guardian's full name, email address, the time of the request, and that it came from the website beta form in our Supabase-backed database. We deliberately do not add child details, your IP address, or your browser user-agent to that beta-request record. The form runs through Cloudflare Pages and uses Cloudflare Turnstile, which processes connection and browser signals, including your IP address, to protect the form from abusive automated traffic. We keep the beta-request record until public launch and for up to 12 months. Ask us and we will remove yours.
Our website and the parent portal load fonts from Google Fonts, which means your browser's IP address goes to Google when those pages load. The iOS app and the kids app do not do this.
17. If Pass the Note is ever sold or transferred
If Pass The Note Kids LLC is acquired, merged, or sells its assets, family information could transfer with the business. If that happens, the buyer will be bound by the promises made in the version of this policy in force when the information was collected. We will notify parents, and if the buyer wants to handle information differently, we will ask you for fresh consent rather than assume it.
18. Changes to this policy
We will post the new version here with a new effective date and a short summary of what changed.
If we materially change what we collect from children, how we use it, or who we share it with, we will give parents direct notice and ask for consent again. We will not treat your continued use of the app as agreement to a material change, and we will not apply a new policy retroactively to information already collected under an old one.
19. Contact us
Privacy, parental consent, access, and deletion requests: [email protected]
Everyday support: [email protected]
By post: Pass The Note Kids LLC
If you believe a child's information has been collected without a parent's consent, write to [email protected] and we will act on it.
← Back to home