← Back

Privacy

Last updated: July 9, 2026

The short version

We're a small team building a tool we'd use for our own kids. We don't sell data, share it with advertisers, or use it to train any AI model. We collect the bare minimum needed to make the product work, and you can delete everything anytime.

What we store

Here is exactly what user information — including the data we access from the YouTube API — Backpack accesses, collects, stores, and uses:

  • Your account: name, email, and the Google user ID Google gives us (so we can recognize you next sign-in).
  • Kid profiles: first name, age band (3-5, 6-8, or 9-12 — not exact age or birthdate), an avatar color, and your parent PIN as a one-way hash (we can't read it back).
  • Playlists you build: the YouTube channels and videos you've approved, the rules you set on channels, and which kid each playlist is assigned to.
  • YouTube tokens (if connected): a refresh token from Google so we can read the playlists we created on your behalf and search YouTube for you. Stored encrypted at rest.
  • View events: when a kid watched a video, for how long, and whether they finished. Used only to show you what your kids have been watching.
  • Cached YouTube data: video titles, thumbnails, durations, channel metadata, and the made-for-kids flag — pulled from YouTube's public API so we aren't hammering them on every page load. We refresh this cache at least every three days, well within YouTube's 30-day maximum.

YouTube API Services

Backpack uses YouTube API Services to power channel search, video metadata lookups, and — only when you explicitly grant permission — to create and update a Backpack-managed playlist on your own YouTube account.

Because we rely on Google's services, additional rules apply:

  • Your use of Backpack is also subject to the YouTube Terms of Service.
  • Data we fetch from Google APIs (channel titles, thumbnails, video durations, the madeForKids flag, etc.) is also governed by the Google Privacy Policy.
  • We do not store YouTube-derived data longer than three days without re-fetching it from YouTube.
  • We do not redistribute, download, or modify YouTube video content. Videos always play through YouTube's official embedded IFrame Player.
  • We do not use any YouTube data to train AI models, build advertising profiles, or share with third parties.
  • You can revoke Backpack's permission to access your Google account at any time at myaccount.google.com/permissions or by tapping Disconnect YouTube in Backpack Settings. Revoking removes our access immediately; previously-cached metadata is deleted on the same 30-day schedule as the rest of your account data when you delete your account.

Limited Use of YouTube API Services data

Backpack's use and transfer of information received from YouTube API Services adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use YouTube data only to provide and improve the features described above — principally, creating and reading the per-child YouTube playlist that surfaces parent-approved videos in your kid's Backpack library. We do not use YouTube data for any other purpose.
  • We do not transfer YouTube data to third parties, except (1) as needed to provide or improve user-facing features through service providers acting under contractual safeguards (hosting, database), (2) to comply with applicable law or valid legal process, or (3) as part of a merger, acquisition, or sale of assets, with notice to affected users.
  • We do not use YouTube data for advertising of any kind, including personalized, targeted, retargeted, or interest-based advertising. We do not sell YouTube data.
  • We do not allow humans to read your YouTube data, except (1) with your explicit consent (for example, when you ask our support team to investigate a specific problem), (2) when necessary for security reasons such as investigating abuse, (3) when required by law, or (4) when the data has been aggregated and anonymized so that it can no longer identify any individual user.

If we ever want to use YouTube data for a purpose beyond what is described in this policy, we will obtain your explicit consent first.

What we don't store

  • Your kid's exact birthdate, biometrics, or photo
  • Your location or your kid's location
  • Advertising IDs, device fingerprints, or browser history
  • Anything from your YouTube account other than the playlists we made for you
  • Behavioral profiles, recommendation models, or anything that feeds an algorithm

Security records

When you take a security-relevant action — signing in, setting or changing your PIN, connecting or disconnecting YouTube, accepting a legal notice, adding or removing a child, deleting your account — we record the action, the time, your IP address, and your browser or app version. This is the audit trail that lets us investigate if your account is misused, and it is the record that you gave consent. It is tied to your parent account, never to a child. It is kept for one year in our database, then moved to a monthly archive in which your account identifier and IP address are replaced by one-way hashes, so the archive cannot be used to identify you.

Where it's stored

Postgres database hosted in the United States (US-East region). All connections are encrypted in transit. YouTube access tokens are encrypted at rest with a key held outside the database. Parent PINs are never stored at all — only a one-way bcrypt hash, which cannot be reversed to recover the PIN.

Who can access it

  • You, anytime, through the app
  • Engineering staff at Backpack, only when investigating a support ticket you've opened or a security incident
  • The infrastructure providers that run the service on our behalf, under contract, and only for that purpose: Neon (database), Vercel (hosting), Sentry (crash reporting, with personal data disabled and all text masked), Resend (transactional email to you), Stripe (billing — never receives anything about a child), and Bunny.net (video storage and the archived security log described above).
  • Nobody else. We don't share data with advertisers, analytics companies, AI training data brokers, or anyone else, and we don't sell it.

Kids and COPPA

Backpack is designed to be used by parents on behalf of their kids. The kid never creates an account, never signs in, and never gives us any data themselves. Everything about a kid in our system is information you, the parent, provided. We comply with the Children's Online Privacy Protection Act (COPPA) and similar regulations elsewhere.

Before you add your first child, we show you a separate notice for parents listing exactly what we will store about them, and we ask for your consent. We record that consent and email you a confirmation. If we change what we collect, we ask again.

As a parent, you have the right to review, modify, or delete any information about your kid in our system at any time. The profile page shows everything; Settings → Export my data downloads all of it; and deleting a profile removes it permanently, immediately.

Ads and tracking

We don't serve ads. We don't use advertising trackers, analytics services, or tracking pixels anywhere in the app. Two pieces of third-party code do run, and we want to be exact about them:

  • YouTube's player, in kid mode. Videos play through YouTube's official player, which we load from youtube-nocookie.com — Google's privacy-enhanced version. It does not use anything it stores for ad personalization, and it does not receive your child's name, age, or profile. It does know which video was played. YouTube may show its own ads inside the video; that is their player and their policy, and YouTube Premium removes them.
  • Sentry, for crash reports. When something breaks we send an error report so we can fix it. Personal data collection is turned off, all on-screen text is masked, and media is blocked before anything is sent — Sentry sees that a button failed, not what your child was watching.

Cookies and device storage

Backpack places a small amount of information on your device — only what's needed to sign you in and remember your preferences. We do not set advertising cookies or cross-site trackers, and nothing Backpack itself stores on your device profiles you or follows you to other sites.

  • Essential sign-in cookies: a secure, HTTP-only session cookie that keeps you logged in, plus a CSRF-protection cookie. These are first-party and strictly necessary — without them you can't sign in.
  • Preferences (local storage): your light/dark mode choice is saved in your browser's local storage so the app remembers it. It never leaves your device.
  • No advertising or tracking technology: we do not place, allow, or recognize any advertising, analytics, or tracking cookies or similar technology on your device or browser.

When a YouTube video plays, it runs in YouTube's player served from youtube-nocookie.com. In that mode YouTube does not set cookies until playback actually begins, and what it does store is governed by the Google Privacy Policy, not ours, and is not used for ad personalization.

Deleting your data

You can delete a child's profile, or your entire account, from the Settings page at any time. The button works immediately — you don't need to email us or wait.

  • Immediately: the profile or account and everything under it — children, viewing history, playlists, PIN, YouTube connection — is deleted from our live database. Not hidden, not flagged: deleted.
  • Within 30 days: our database provider's point-in-time backups, which exist so we can recover from an outage, age out and are gone.
  • What remains: the security records described above, with your account identifier removed so they can no longer be linked to you. We keep those so that if someone else deleted your account, there is still a trail to investigate.

When we change this

If we change anything about how we handle your data, we'll email you and show a banner inside the app at least 30 days before the change takes effect. We won't make changes quietly or assume you read a notice. If we ever start doing anything we said we wouldn't — selling data, training models on your stuff, anything like that — that's the kind of change we'd tell you about and let you opt out of (or close your account first).

Contact

Questions, concerns, or to request a copy of all data we have about you: email privacy@backpack.kids. We answer every message.