0
Skip to Content
Journal
Home
Why 400 Weeks
How It Works
Sample Week
Pricing
Science & Standards
FAQ
About
Contact
Privacy
Terms of Service
Governance
Trust
For Clinicians
Trust Verify
Changelog
Resilient Kids™
Login Account
Journal
Home
Why 400 Weeks
How It Works
Sample Week
Pricing
Science & Standards
FAQ
About
Contact
Privacy
Terms of Service
Governance
Trust
For Clinicians
Trust Verify
Changelog
Resilient Kids™
Login Account
Journal
Home
Why 400 Weeks
How It Works
Sample Week
Pricing
Science & Standards
FAQ
About
Contact
Privacy
Terms of Service
Governance
Trust
For Clinicians
Trust Verify
Changelog
Login Account
Resilient Kids
First 400 Weeks How it works Sample week Pricing Science & Standards
Sign in Get started
First 400 Weeks How it works Sample week Pricing Science & Standards
Get started Sign in

Privacy Policy

Effective date: July 14, 2026 Last updated: July 14, 2026

1. Who we are

Resilient Kids (“Resilient Kids,” “we,” “us,” or “our”) operates the website at resilient.kids and a mobile application that delivers weekly, age-timed, evidence-informed guidance for adult caregivers raising children. This Privacy Policy covers both the website and the app, and explains what information we collect, how we use it, who we share it with, and what choices you have.

  • Legal entity: Resilient Kids LLC (a Delaware limited liability company)
  • Contact: privacy@resilient.kids
  • Address: 2810 N Church St #769322, Wilmington, DE 19802, USA

If you do not agree with this policy, please do not use the app.

2. Who the app is for

Resilient Kids is intended for adult caregivers (18 years or older). The app is not directed to children, and children may not create accounts or use the service directly. Parents and other caregivers may, at their discretion, enter limited information about a specific child in their household — see Section 4 for how we handle that.

The Service is directed to adults and is not designed for or directed to minors; we do not knowingly permit anyone under 18 to use it.

3. What information we collect

3.1 Information you provide directly

  • Account information — your email address, display name, and (if you create a password-based account) a hashed password. If you sign in with Apple or Google, we receive the email address and user identifier those providers share with us.
  • Household information — a household name, one caregiving role per member (owner, collaborator, or viewer), and invite codes you generate or enter.
  • Child information you enter — the child’s first name (or nickname) and date of birth, which we use to compute the current week of guidance to show you. You are not required to use the child’s legal name or exact birthdate; you may use a nickname and an approximate date.
  • Optional intake answers — to tailor the guidance we show you, we may ask optional questions about your family’s circumstances. Some answers may touch on sensitive topics — for example, household safety, substance use, items in the home, mental-health history, or pregnancy or infant loss. These questions are optional; you can use the Service without answering them. We use your answers only to choose which guidance to show you. We do not sell them, do not use them for advertising, and store them under the same protections as the rest of your account. If you are a resident of Washington, Nevada, or Connecticut, see Section 9.5 (Consumer health data).
  • Phone number — only if you opt in to receive SMS notifications. The number is collected solely to deliver the SMS messages you have asked for; we do not use it for marketing or share it with any third party for that party’s own marketing. See Section 3.7 below for the full SMS data flow and Section 9 for opt-out.
  • Progress and usage notes — which weeks you’ve marked complete, which action items you’ve checked off, achievements earned, and any free-text notes you choose to save in the app.
  • Communications — if you email research@resilient.kids or send feedback through the app, we keep a record of that correspondence.

3.2 Information collected automatically

  • Device and app information — device type, operating system version, app version, language and region, and the time zone reported by your device. This helps us schedule local reminders and troubleshoot issues.
  • Log data — when the app communicates with our servers, we may log the request time, general location (derived from IP at city level, not stored long-term), and any error messages produced.
  • Crash reports — if the app crashes, a crash report may be sent to us so we can diagnose and fix the issue. Crash reports do not include the content of your notes or child information. The third-party service that collects these reports on our behalf is described in Section 3.4.

We do not use advertising SDKs, third-party analytics trackers, or behavioral advertising identifiers in our mobile app. On our website (resilient.kids) we use Google Analytics 4 for basic, aggregated traffic measurement — see Section 3.6. We do not sell your personal information. We do not share personal information with data brokers.

3.3 Information from third-party services

  • Apple or Google Sign In — if you choose to sign in with Apple or Google, the respective service sends us a verified user identifier and, with your permission, your name and email address. Apple offers the option to hide your email behind a private relay; if you choose that, we receive a relay address and cannot see your real address.
  • Subscription purchases — when you buy or renew a subscription, the payment is processed by the Apple App Store or Google Play (in the mobile app) or by Stripe (on the web at app.resilient.kids). We do not receive or store your full card number, bank details, or full billing address. We do receive a purchase receipt or confirmation that tells us which plan you bought and when it renews or expires. Stripe’s privacy notice: stripe.com/privacy
  • RevenueCat — we use RevenueCat to manage subscription receipts and confirm your subscription status across devices. RevenueCat processes your purchase identifiers, platform user ID, and subscription state. RevenueCat’s privacy notice: revenuecat.com/privacy

3.4 Crash, error, and performance diagnostics

We use Sentry (sentry.io), a crash and error reporting service, on both the mobile app and our backend servers, to help us detect and fix bugs quickly.

  • What Sentry sees — when the app crashes or hits an unexpected error, Sentry receives the technical context of that error: a stack trace, the app version, the device type and OS version, the screen you were on, the timestamp, and your account’s user ID (an opaque identifier used to correlate the report with the event log). On the backend, Sentry receives the same kind of technical context for errors that occur while serving your requests.
  • What Sentry does not see — Sentry does not receive the content of your notes, the child information you’ve entered, your free-text answers, your email address, your subscription state, or the substance of any guidance content. We keep these out by attaching only your user ID to the events we send Sentry; we do not include your email, notes, child information, or free-text answers. Limited technical metadata (such as your IP address) may be transmitted as part of an error report and is used only to diagnose the error.
  • What it’s used for — Resilient Kids engineers review Sentry reports to fix the underlying bugs. Sentry data is not used for marketing, is not shared with third parties, and is retained for up to 90 days.
  • Sentry’s privacy notice: sentry.io/privacy

We also use Honeycomb (app performance traces) and Axiom (server-side request logs) to measure performance and reliability. These receive technical telemetry only — timings, request and trace identifiers, and screen or endpoint names — never the content of your notes, your child’s information, or your free-text answers, and never for advertising. Privacy notices: honeycomb.io/privacy and axiom.co/privacy

3.5 Product analytics — first-party, opt-out via account deletion

We measure how the product is used in order to improve it. Our approach is deliberately first-party and minimal:

  • No third-party tracking SDKs. We do not embed Google Analytics, Firebase Analytics, Mixpanel, Amplitude, Segment, Meta Pixel, TikTok Pixel, or any other behavioral-tracking SDK in the app. We have not installed and have no plans to install advertising SDKs.
  • Aggregate funnel measurement, no per-user dashboards. When you take a meaningful action in the app — creating a household, adding a child, completing the intake, finishing your first weekly module, marking a milestone — we record that action in our own database as part of how the app works (those actions are what let us show you the right content next). We periodically run aggregate queries against those records — for example, “how many caregivers completed intake last week” — to understand whether our product is helping families. We do not build per-user behavioral profiles, and the aggregate-funnel surface is accessible only to a small set of internal Resilient Kids team members under our access-control policy.
  • Server-side only. All measurement happens on our servers using records that are already part of how the app functions. There is no separate analytics SDK on your device.
  • Opt-out path. If you do not want your activity included in aggregate measurement, you may delete your account at any time from Settings → Delete Account. Deletion removes your activity records along with the rest of your account data; aggregate counts going forward will not include you. A more granular opt-out — keeping your account active while excluding your activity from aggregate measurement — is on our roadmap. Until then, account deletion is the available opt-out.

We chose this posture because we are building a product for families and take seriously the responsibility that comes with measuring children’s caregivers. The goal is to know enough to improve the product without building the kind of behavioral surveillance our families are trying to escape.

3.6 Website analytics and cookies

On our website (resilient.kids), we use Google Analytics 4 (“GA4”) to understand how visitors use the site — which pages are viewed, which links are clicked, and where visitors come from. GA4 is configured with IP anonymization and does not link website activity to your app account.

GA4 sets cookies in your browser (typically named _ga and _ga_*) to distinguish unique visitors. The data it collects includes your IP address (truncated before storage), browser type and version, device type, operating system, referring URL, pages viewed, and approximate city-level geographic location derived from IP.

You can opt out of GA4 by installing the Google Analytics Opt-out Browser Add-on or by blocking cookies from google-analytics.com. We honor the Global Privacy Control (GPC) signal where technically feasible. Google Analytics is configured as our service provider: Google Signals and advertising features are disabled and we have accepted Google’s data-processing terms, so we do not use GA4 to build cross-site advertising profiles and we do not enable any setting that shares your data with Google for advertising or ad-personalization purposes. Google’s privacy notice: policies.google.com/privacy

3.7 SMS notifications (when you opt in)

SMS is one of the notification channels you can enable in Settings → Notification Preferences. SMS is always opt-in — never default-on. The full SMS program terms (categories, frequency, opt-out, HELP keyword, message and data rates) live in our Terms of Service, Section 19.

What we collect when you opt in to SMS:

  • Your phone number, used solely to deliver the messages you have asked for.
  • The per-category opt-in toggles you set, recorded with a timestamp in our event log so we can prove consent was collected and process opt-outs reliably.
  • Delivery metadata for each message we send (timestamp, message ID, delivery status, bounce or unsubscribe events), used to debug delivery failures and honor opt-out requests.

How SMS is delivered. We do not run our own SMS infrastructure. We use Twilio, a US-based communications platform, as our SMS sub-processor. We hand Twilio your phone number and the message body; Twilio routes the message to your wireless carrier for delivery to your device. Twilio is contractually bound to process this data only on our instructions. Twilio’s privacy notice: twilio.com/legal/privacy

What we do NOT do with your phone number: we do not sell it; we do not share it with advertisers, data brokers, or any third party for that party’s own marketing; we do not use it for marketing or for behavioral profiling — only for the transactional notifications you opted in to.

How to opt out of SMS: reply STOP to any message, or toggle SMS off per category in Settings → Notification Preferences. Full opt-out details in Terms of Service § 19.5.

3.8 Push notifications (when you enable them)

If you turn on push notifications, your device generates a push token that we use to deliver them. We send that token and the notification through Expo’s push service and on to Apple Push Notification service (iOS) or Google Firebase Cloud Messaging (Android), which process the token solely to route the message to your device. We do not use push tokens for advertising or profiling. You can turn push off per category in Settings → Notification Preferences or in your device settings. Privacy notices: expo.dev/privacy, apple.com/legal/privacy, policies.google.com/privacy

4. How we handle children’s information

We treat the limited child-related information you enter with care.

  • It is stored only in association with your household, behind the same row-level security policies that protect your own account.
  • It is never shared with advertisers or data brokers.
  • You can delete the child’s entry at any time from the Household tab, which removes the name and birthdate from our database.
  • We do not build behavioral profiles of children based on what you enter.
  • We keep the child information you enter only as long as your account is active or as needed to provide the Service, and delete it on the schedule in Section 8; we do not retain it indefinitely.
  • We do not knowingly collect personal information directly from anyone under 13 (or 16 in certain jurisdictions). If you believe a child has created an account, contact privacy@resilient.kids and we will delete it.

Because children are not direct users, the Children’s Online Privacy Protection Act (“COPPA”) does not require a verifiable-parental-consent workflow for this app. We nonetheless follow COPPA-aligned practices for the child information parents provide voluntarily.

5. How we use your information

We use the information described above to:

  1. Operate the app — authenticate your sign-in, compute the current week of content for your child’s age, sync progress across your caregiver accounts, and deliver reminders you’ve opted into.
  2. Manage subscriptions — confirm your subscription status, grant access to paid features, and support refund requests as described in our Terms of Service.
  3. Communicate with you — send important service notices (for example, a security notice or a change to these terms). We will only send marketing emails if you’ve explicitly opted in, and you can unsubscribe at any time.
  4. Improve the service — fix bugs, understand which features are used, and inform future development. We do this using aggregated, de-identified data wherever possible.
  5. Comply with law — respond to lawful legal process, enforce our Terms of Service, and protect the rights, property, or safety of Resilient Kids, our users, or others.

We will not use your personal information for any purpose that is materially different from the purposes listed above without notifying you.

6. Who we share information with

We share your information only as described below. Each provider below acts as our service provider / processor under a written contract (a data processing agreement or equivalent terms) that requires it to use your information only to perform services for us and prohibits it from selling your information or using it for its own purposes. We do not authorize any of them to use your information for cross-context behavioral advertising.

  • Infrastructure providers — we use Supabase (Postgres database, authentication, file storage) to host your account and content. Supabase processes data on our behalf under a data processing agreement.
  • Subscription management — RevenueCat, as described in Section 3.3.
  • Payment processors — Apple App Store and Google Play (mobile) and Stripe (web purchases at app.resilient.kids), as described in Section 3.3. Stripe processes your card payment to complete a web purchase; we do not receive or store your card number. Stripe’s privacy notice: stripe.com/privacy
  • Email delivery — we use Resend to send account and transactional emails and our opt-in newsletter. Resend processes your email address and the content of the messages we send in order to deliver them. Resend’s privacy notice: resend.com/legal/privacy-policy
  • SMS delivery — we use Twilio to send the transactional SMS notifications you have explicitly opted in to receive (see Section 3.7). Twilio processes your phone number and the message body to route messages to your wireless carrier. Twilio’s privacy notice: twilio.com/legal/privacy
  • Push notifications — when you enable push notifications, we use Expo’s push service together with Apple Push Notification service (iOS) and Google Firebase Cloud Messaging (Android) to deliver them. These services process your device’s push token to route the notification to your device; Expo does not receive your identity. Privacy notices: expo.dev/privacy, apple.com/legal/privacy, policies.google.com/privacy
  • Crash and error diagnostics — we use Sentry to detect and fix bugs in the app and backend. Sentry’s role is described in Section 3.4.
  • Performance and observability — we use Honeycomb (app performance traces) and Axiom (server-side request logs) to keep the Service fast and reliable. These receive technical telemetry only, never the content of your notes or your child’s information. Privacy notices: honeycomb.io/privacy, axiom.co/privacy
  • Website analytics — we use Google Analytics 4 to measure website traffic, as described in Section 3.6. Google processes this data on our behalf.
  • Legal and safety — we may disclose information if we believe in good faith it is required by law, court order, or subpoena, or necessary to investigate fraud or protect the safety of people or property.
  • Business transfers — if Resilient Kids is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

We will never sell your personal information or the information you enter about your child.

7. Where your information is stored

Your information is stored on servers located in the United States, operated by our infrastructure providers (primarily Supabase). Resilient Kids is intended for caregivers located in the United States. If you access the service from outside the United States, your information will be transferred to and processed in the United States, which may have data-protection laws different from those in your country.

8. How long we keep your information

  • Account information — kept while your account is active. When you delete your account, it enters a 7-day soft-delete window so an accidental deletion can be reversed; after 7 days, your account data is permanently removed from production databases. Backups are retained for up to 90 days and are then purged.
  • Subscription records — retained as long as required by Apple, Google, and applicable tax law, typically 7 years.
  • Support correspondence — retained for up to 2 years unless a longer retention is required by law.
  • Crash and diagnostic logs — retained for up to 90 days.

9. Your rights

Depending on where you live, you may have the following rights:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to correct information that is inaccurate or incomplete.
  • Deletion — delete your account and associated personal information from Settings → Delete Account, or by emailing privacy@resilient.kids. Account deletion runs through a 7-day soft-delete window; you can change your mind within those 7 days. After that, your account and the events your household generated are deleted from our production systems. Residual copies in encrypted backups are overwritten within 90 days and are not used except for disaster recovery. We may retain a limited set of records where the law requires it — for example, subscription and tax records (typically up to 7 years) — or to comply with legal obligations or resolve disputes. See Section 8.
  • Portability — receive a copy of your personal information in a structured, machine-readable format. Use Settings → Account → Export my data from inside the app, or email privacy@resilient.kids if you can’t reach the app. We email a download link within 72 hours; the link expires 24 hours after we send it.
  • Opt out of marketing — unsubscribe from any marketing emails we send.
  • Withdraw consent — where we rely on consent to process your data, withdraw that consent at any time.

Residents of California have additional rights under the California Consumer Privacy Act, including the right to know what personal information we have collected and the right to request deletion.

To exercise any of these rights, contact privacy@resilient.kids. We respond to verifiable requests within 45 days (as California law requires); we may extend once by another 45 days where permitted and will tell you if we do. We will not discriminate against you for exercising these rights.

9.5 Consumer health data (Washington, Nevada, and Connecticut residents)

Some of the optional intake answers described in Section 3.1 may be “consumer health data” under the laws of Washington (My Health My Data Act), Nevada (SB 370), and Connecticut. If you are a resident of one of these states: we collect this data only with your consent; we use it solely to provide the guidance you asked for; we do not sell it; and we will not share it without your separate written authorization. You may withdraw consent, and request access to or deletion of this data, at any time by emailing privacy@resilient.kids. Our dedicated Consumer Health Data Privacy Policy describes these rights and our handling of consumer health data in full.

10. Security

We use industry-standard practices to protect your information, including:

  • Encryption in transit (HTTPS/TLS) between the app and our servers.
  • Encryption at rest for data stored in our primary database.
  • Row-level security in the database so one household’s data cannot be read or modified by another.
  • Hashed passwords (we never store plaintext passwords).
  • Access controls that limit which Resilient Kids personnel can see production data.

No method of transmission or storage is 100% secure. If we learn of a breach that materially affects your personal information, we will notify you as required by applicable law.

10.5 Public content provenance — what is not covered

To keep our published content auditable, every content version Resilient Kids publishes — and every advisor sign-off recorded against it — is hash-anchored on a public Hedera consensus log. These anchors carry no personal information: only the content version’s identifier, the advisor’s published identity (name + credential, the same information shown on the public Governance Ledger), the cryptographic hash of the content, and the on-chain timestamp. No event a household or caregiver emits is ever anchored on-chain. See /trust for the full public record and /governance for advisor information.

11. Third-party links

The app may contain links to external websites or resources. We are not responsible for the privacy practices of third parties. Please review their privacy notices before providing information to them.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by email before the changes take effect. The “Effective date” at the top of this document reflects the most recent revision.

13. Contact us

Questions, concerns, or requests? Email privacy@resilient.kids and include “Privacy” in the subject line.

Resilient Kids
A weekly science-based guide for families
Support: support@resilient.kids
Research: research@resilient.kids
Explore
Why 400 Weeks Matter How it works Sample week Pricing Journal
More
FAQ About Contact Privacy Policy Terms of Service Consumer Health Data
Trust & Science
Science & Standards Governance Ledger Trust Ledger For Clinicians
Get Resilient Kids Download on theApp Store GET IT ONGoogle Play Use it on the web
© Resilient Kids LLC
Educational information only; not medical advice. For urgent concerns, consult a licensed clinician.