In September 2025, hackers posted photos and profiles of roughly 8,000 children after breaching a nursery chain, then called parents to pressure a ransom. If your check-in app, parent-comms tool, or camera portal was vibe-coded with Lovable, Bolt, or Base44, we find and fix the gaps before a breach touches a child's data.
Get a Free Security Scan Book an AI App AuditChildcare software is fast-digitizing and heavily regulated: 92,550 licensed centers process photos, allergy and medical notes, parent PII and payment, and staff background-check records every day. Attackers weaponize this data directly — the Kido nursery hack didn't just leak records, it published children's names, photos, and addresses and used them to pressure parents. The amended COPPA Rule, which now treats faceprints as children's personal information and requires a written security program, has a compliance deadline of April 22, 2026.
These are the apps we see daycare and preschool operators stand up fast with AI builders — and exactly where the risk sits in each one.
Child photos and daily logs sit in cloud storage. AI builders have generated Supabase schemas with row-level security off (CVE-2025-48757), letting any visitor dump every child's photos and records. Even commercial daycare apps have shipped without 2FA.
Attendance reveals which children are in which building at what hours — a physical-safety and custody-dispute exposure. States also require accurate attendance for licensing, so a breached homemade system is a compliance-record failure too.
Under the amended COPPA Rule, faceprints are now "personal information." Photos plus child names plus center address is exactly what extortionists published in the Kido breach.
Card acceptance pulls the app into PCI DSS scope. AI-built billing pages have been found exposing Stripe credentials and payment records client-side.
Bitsight found 40,000+ cameras streaming openly with no password, roughly 14,000 in the US. A DIY parent-viewing portal proxying camera feeds without auth broadcasts a room of children to the internet, and adding audio triggers all-party-consent wiretap laws in about 12 states.
These collect child DOB, health and allergy data, and family details from people who never enrolled. An unsecured Elasticsearch instance behind one CRM leaked 140,000+ records tagged with children's names.
Childcare staff files contain CCDBG-mandated background-check data — FBI fingerprint results, abuse-registry checks — plus SSNs. Ransomware claims against one childcare chain listed employee records among 200GB stolen.
Childcare apps sit under federal children's-privacy law, state licensing rules, and camera/wiretap statutes all at once.
| Regulation | When It Applies | Penalty |
|---|---|---|
| COPPA (amended, compliance Apr 22, 2026) | Any online service directed to under-13s, or with actual knowledge of collecting their info, now including biometric identifiers like faceprints | Up to /violation |
| FERPA + IDEA confidentiality | Pre-K/early-childhood programs of educational agencies receiving US DoE funds | Loss of federal funding (no private right of action) |
| Head Start Standards (45 CFR 1303) | Head Start / Early Head Start programs | Deficiency findings; loss of grant funding |
| State childcare licensing record rules | Operating a licensed center — records access limited to parents/regulators, retention rules apply | Corrective action, administrative penalties, license suspension or revocation |
| CCDBG background checks (45 CFR 98.43) | All staff of licensed/CCDF providers: FBI fingerprint, sex-offender registry, state criminal/abuse registry checks | Loss of CCDF eligibility/license |
| CCPA/CPRA (+19 states) | Chains/franchises meeting thresholds; children's data counts as sensitive | /violation involving minors under 16, intent not required |
| PCI DSS 4.0 | Accepting any card payment for tuition, including a homemade billing page | –nth escalating, up to loss of card acceptance |
| State wiretap / all-party consent | Daycare cameras capturing audio in roughly 12 states | Criminal charges plus civil damages |
Attackers stole data on ~8,000 children (names, photos, addresses, DOBs, safeguarding and medical notes), posted child profiles online, and cold-called parents to pressure ransom. No ransom was paid; data was later deleted after backlash.
A password-less, misconfigured Elasticsearch instance leaked 140,000+ records tagged "leads/inquiries/children" from a CRM used by 9,000+ centers.
Sinobi ransomware claimed 200GB of data including employee records, financials, and operations files across this 150+ center chain (claim not independently confirmed by the company).
COPPA settlement over a kids' robot-toy app whose third-party SDK collected children's geolocation without consent — the FTC warned developers they're liable for vendors' and SDKs' COPPA violations too.
Missing row-level security left 170+ apps' databases fully readable and writable — directly relevant to any childcare app built the same way.
If it's built on Lovable and uses Supabase, it may be. This flaw left 170+ apps' databases fully readable and writable due to missing row-level security — in a childcare app that means child photos, logs, and parent contact details. We test for this exact misconfiguration.
Verifiable parental consent, a written information-security program, defined data-retention limits, and treating biometric identifiers like faceprints as regulated personal information. Full compliance is required by April 22, 2026, with penalties up to per violation.
Not always by statute, but leaving them open is a serious liability. Bitsight found 40,000+ daycare cameras streaming publicly with no password in June 2025. Adding audio also triggers all-party-consent wiretap laws in roughly 12 states.
Yes. State childcare licensing rules limit who can access child records to parents and regulators and impose retention requirements. A vibe-coded enrollment form collecting allergy or custody notes without access controls falls under those same confidentiality rules.
In September 2025, attackers stole data on roughly 8,000 children, including photos, addresses, and safeguarding notes, then posted profiles online and called parents directly to pressure the nursery into paying a ransom. No ransom was paid.
Most check-in, parent-comms, or camera-portal audits complete within a few business days. We start with a free automated scan, then a manual review of authentication, RLS/database access, and camera/stream exposure before handing you a prioritized fix list.
Related searches: daycare app data breach · is brightwheel safe for my child's photos · daycare camera privacy laws by state · COPPA compliance for childcare apps · can daycare cameras be hacked · daycare check-in app security · childcare website security audit · secure app built with Lovable · PCI compliance for daycare tuition payments · daycare photo sharing app privacy · preschool enrollment form data protection
Get a free automated scan of your daycare app — then a full audit if you need one.
Get Your Free Security Scan