Trust & Security
This page describes the controls and practices Yaylo has in place today. It reflects app-visible behavior and our current operating practices, and is not an independent certification.
Access and authentication
- Parents sign in with email and password; sessions are handled by our authentication provider.
- Kids sign in with a family-scoped username and PIN — no email required.
- Access to production systems is limited to authorized Yaylo personnel.
Platform and hosting
Yaylo runs on managed cloud infrastructure with encryption in transit and at rest provided by our platform. Backend services enforce row-level security so users only see their own family's data.
Data we collect and how we use it
- Account information you provide (parent email, family and profile details).
- Product activity needed to make the app work (missions, stars, rewards).
- We do not sell personal information and we do not show ads to children.
- See our Children's Privacy page for how we handle kids' data.
Subprocessors and integrations
We use a small set of vetted providers for hosting, authentication, transactional email, and payments. A current list is available on request via Contact.
Retention and deletion
You can delete your family account from settings at any time. On deletion, we remove your account data from active systems; residual copies in backups age out on our normal backup rotation.
Reporting a vulnerability
If you believe you've found a security issue, please contact us with details and steps to reproduce. We investigate reports promptly and won't pursue action against good-faith researchers who follow responsible disclosure.
Compliance
Yaylo is designed with COPPA and GDPR-K principles in mind: parent-directed profiles, minimal child data, and no advertising to children. If your organization needs a signed DPA or additional documentation, see our Schools DPA overview.
This page is maintained by Yaylo to answer common questions about our product. It is not an independent certification.