What your daycare's app knows about your child — a plain-English data guide
Your daycare hands you an app. Into it goes your child’s photo, their nap schedule, what they ate, when they arrived, sometimes their allergies and immunization records — and you tap “accept” on the terms because your kid starts Monday. It’s worth knowing, without the legalese, what that app actually collects and what say you have over it.
(Disclosure: I’m the founder of TinyGuard, a childcare platform, and a parent-adjacent one — my wife runs the daycare it was built for. Here’s the plain-English version I’d want.)
What childcare apps typically collect
Most of it is the ordinary machinery of running a daycare, and it’s genuinely useful:
- Identity and contacts — your child’s name and birthdate, your contact info, who’s authorized to pick them up.
- Attendance — when your child arrives and leaves each day.
- The daily record — naps, meals, diapering, activities, the photos in your feed.
- Health information — allergies, immunizations, medication logs, incident reports.
- Billing — your payment details, tuition history.
None of that is alarming on its own. It’s the kind of information a daycare has always kept; the app just makes it digital. The questions worth asking are about the edges.
The one red flag: biometrics
Here’s the collection category that deserves a hard look: biometric data — a scan of your child’s face or fingerprint. Some check-in systems log attendance by scanning a child’s face or finger instead of a code or a badge.
A faceprint isn’t like a password. Your child can’t change their face if that data leaks, and they’re too young to have consented to it being collected at all. The safe posture — the one I’d insist on as a parent — is that no part of the system uses facial recognition or biometric matching on the children. Ask your daycare directly whether check-in involves any face or fingerprint scanning. A QR code or a PIN does the same job without collecting anything irreversible about your kid. (TinyGuard’s own answer: zero biometrics, contractually — no facial recognition, ever.)
What COPPA gives you
The federal rule here is COPPA — the Children’s Online Privacy Protection Act, which governs how online services handle information about children under 13. In plain terms, it means the app can’t treat your child’s data as its own: you have rights to know what’s collected, to see it, and to have it deleted.
The practical test of whether a childcare app takes that seriously: is deletion built in, or is it a favor? A well-designed system has consent management and deletion workflows in the product, encrypts your child’s data at rest and in transit, and can honor a deletion request whenever you make one — including after your child leaves. If getting your kid’s data removed means emailing support and hoping, that tells you where the app’s priorities are.
The questions worth asking
Three, and they cover most of it:
- Does check-in use any face or fingerprint scanning? (You want: no.)
- What happens to my child’s photos and records when we leave? (You want: deletable, on request.)
- Who can see my child’s information, and is it encrypted? (You want: staff on a need-to-know basis, encrypted, not exposed.)
You don’t need to become a privacy lawyer. You need a daycare that can answer those three without getting defensive — because a center that chose its software with your child’s data in mind is a center that’s thinking about the right things.
If your daycare runs TinyGuard, here’s how your child’s data is handled, in plain language. If it doesn’t, these are fair questions to ask whoever they do use — and worth raising with your director.
— Del Peck Founder, TinyGuard
More for parents: Daycare cameras and your child’s privacy · Can I watch my child at daycare? · How to choose a daycare
TinyGuard puts cameras, care logging, billing, and compliance on one on-site box. Book a 15-minute demo or see the pricing.