Trust
Security and child data privacy
Rawdly holds photographs of children, home addresses, allergy notes, and payment records. This page says what we do with that information, who can reach it, and what we have not done yet.
Last reviewed July 2026
The controls in place
Encryption
Traffic runs over TLS 1.2 or higher. Stored data and uploaded media are encrypted at rest. Database backups are encrypted with the same keys and kept for 30 days.
Per-child media permissions
A photo is visible only to the families of the children tagged in it. If four children appear in one picture, four families see it and nobody else. Parents who decline photo consent are excluded at upload time, so staff cannot share a photo of their child by mistake.
Role-based staff access
Assistants see the rooms they are assigned to. Lead staff see their room's records and messages. Only directors reach billing, enrollment documents, and health notes. Access ends the moment you deactivate a staff account.
Access logging
Every view and change to a child's record is written to a log with the account, the action, and the timestamp. Directors can pull the log for their own center at any time.
Authentication
Passwords are hashed, never stored in readable form. Two-factor authentication is available on every account and can be required center-wide.
Data isolation
Each center's records are scoped to that center. Multi-site accounts see their own locations only. No customer can query another customer's data.
Regulations that apply to childcare
COPPA
Information about a child is collected from the center and the child's own parent, never from the child. Parents can request deletion of their child's photos and records through the director, and we complete the deletion within 30 days.
GDPR
Providers in the EU and UK can sign a data processing agreement. We support access, correction, export, and erasure requests, and we name our subprocessors on request.
Licensing records retention
Attendance, incident reports, and meal counts export as PDF or CSV whenever you need them, which is what most state licensing bodies want to see during an inspection. Retention periods vary by state, so you set how long Rawdly keeps records for your center.
Who owns the data
- Your records belong to your center, not to Rawdly.
- We do not sell customer or child data, and we do not share it with advertisers.
- We do not train models on your children's photos or messages.
- You can export everything as CSV and PDF at any time, including after you cancel.
- Cancel and we delete your data within 30 days of your request. Backups age out within 30 days after that.
What we have not done
We are not SOC 2 certified yet
An audit is on the roadmap and not finished. If your center or your funder requires a SOC 2 report today, we do not have one to give you.
We are not a HIPAA covered entity
Rawdly stores allergy notes, medication schedules, and immunization dates because licensing requires them. It is not a medical records system and should not hold clinical notes from a provider.
Hosting is in the United States
Data is hosted in US regions. If your regulator requires storage inside the EU, tell us before you sign up so we can say whether we can meet it.
Questions directors ask
Who at Rawdly can see photos of children at my center?
Nobody, in normal operation. Support staff can reach a center's data only when a director opens a ticket and grants access, and that access is logged and time-limited. We do not browse customer media.
What happens to our data if we stop paying?
Your account moves to read-only. You keep export access for 60 days so you can pull attendance and billing history for your records. After that the account is deleted on request or at the end of the retention window.
Can a parent get a copy of everything you hold about their child?
Yes. The director can export a single child's full record, activity logs, attendance, photos, and messages, and hand it to the parent. If a parent asks us directly we route them to their center, because the center is the data controller.
Do you have a way to report a vulnerability?
Email hello@rawdly.com with the details and we will confirm receipt within two business days. We do not take legal action against researchers who report in good faith and do not access other customers' data.
Need something in writing for your board or licensor?
Ask and we will send the data processing agreement, our subprocessor list, and a summary of retention settings for your center.