Get a Quote

Childcare & Daycare App Security

In September 2025, hackers posted photos and profiles of roughly 8,000 children after breaching a nursery chain, then called parents to pressure a ransom. If your check-in app, parent-comms tool, or camera portal was vibe-coded with Lovable, Bolt, or Base44, we find and fix the gaps before a breach touches a child's data.

Get a Free Security Scan Book an AI App Audit
WHY CHILDCARE IS DIFFERENT

This Data Isn't Just Sensitive — It's a Child

Childcare software is fast-digitizing and heavily regulated: 92,550 licensed centers process photos, allergy and medical notes, parent PII and payment, and staff background-check records every day. Attackers weaponize this data directly — the Kido nursery hack didn't just leak records, it published children's names, photos, and addresses and used them to pressure parents. The amended COPPA Rule, which now treats faceprints as children's personal information and requires a written security program, has a compliance deadline of April 22, 2026.

92,550Licensed child care centers across the US — Child Care Aware of America, 2024
~8,000Children whose photos and profiles were posted online after the Kido nursery hack, Sep 2025
40,000+Daycare cameras found streaming openly with no password — Bitsight, June 2025
Maximum penalty per violation under the amended COPPA Rule (compliance deadline Apr 22, 2026)
WHAT CHILDCARE OPERATORS BUILD WITH AI

Every One of These Touches a Child's Data

These are the apps we see daycare and preschool operators stand up fast with AI builders — and exactly where the risk sits in each one.

Parent-communication / daily-report apps

Child photos and daily logs sit in cloud storage. AI builders have generated Supabase schemas with row-level security off (CVE-2025-48757), letting any visitor dump every child's photos and records. Even commercial daycare apps have shipped without 2FA.

Check-in / attendance apps

Attendance reveals which children are in which building at what hours — a physical-safety and custody-dispute exposure. States also require accurate attendance for licensing, so a breached homemade system is a compliance-record failure too.

Photo / video sharing galleries

Under the amended COPPA Rule, faceprints are now "personal information." Photos plus child names plus center address is exactly what extortionists published in the Kido breach.

Tuition / recurring-billing portals

Card acceptance pulls the app into PCI DSS scope. AI-built billing pages have been found exposing Stripe credentials and payment records client-side.

Live daycare-camera streaming portals

Bitsight found 40,000+ cameras streaming openly with no password, roughly 14,000 in the US. A DIY parent-viewing portal proxying camera feeds without auth broadcasts a room of children to the internet, and adding audio triggers all-party-consent wiretap laws in about 12 states.

Waitlist / enrollment forms

These collect child DOB, health and allergy data, and family details from people who never enrolled. An unsecured Elasticsearch instance behind one CRM leaked 140,000+ records tagged with children's names.

Staff scheduling / HR tools

Childcare staff files contain CCDBG-mandated background-check data — FBI fingerprint results, abuse-registry checks — plus SSNs. Ransomware claims against one childcare chain listed employee records among 200GB stolen.

REGULATIONS & PENALTIES

What a Bad Build Actually Costs

Childcare apps sit under federal children's-privacy law, state licensing rules, and camera/wiretap statutes all at once.

RegulationWhen It AppliesPenalty
COPPA (amended, compliance Apr 22, 2026)Any online service directed to under-13s, or with actual knowledge of collecting their info, now including biometric identifiers like faceprintsUp to /violation
FERPA + IDEA confidentialityPre-K/early-childhood programs of educational agencies receiving US DoE fundsLoss of federal funding (no private right of action)
Head Start Standards (45 CFR 1303)Head Start / Early Head Start programsDeficiency findings; loss of grant funding
State childcare licensing record rulesOperating a licensed center — records access limited to parents/regulators, retention rules applyCorrective action, administrative penalties, license suspension or revocation
CCDBG background checks (45 CFR 98.43)All staff of licensed/CCDF providers: FBI fingerprint, sex-offender registry, state criminal/abuse registry checksLoss of CCDF eligibility/license
CCPA/CPRA (+19 states)Chains/franchises meeting thresholds; children's data counts as sensitive/violation involving minors under 16, intent not required
PCI DSS 4.0Accepting any card payment for tuition, including a homemade billing page–nth escalating, up to loss of card acceptance
State wiretap / all-party consentDaycare cameras capturing audio in roughly 12 statesCriminal charges plus civil damages
REAL INCIDENTS

This Isn't Hypothetical

Sep 2025 — Kido International

Attackers stole data on ~8,000 children (names, photos, addresses, DOBs, safeguarding and medical notes), posted child profiles online, and cold-called parents to pressure ransom. No ransom was paid; data was later deleted after backlash.

Disclosed 2025 — LineLeader / ChildcareCRM

A password-less, misconfigured Elasticsearch instance leaked 140,000+ records tagged "leads/inquiries/children" from a CRM used by 9,000+ centers.

Nov 25, 2025 — Kids & Company

Sinobi ransomware claimed 200GB of data including employee records, financials, and operations files across this 150+ center chain (claim not independently confirmed by the company).

Sep 2, 2025 — FTC v. Apitor Technology

COPPA settlement over a kids' robot-toy app whose third-party SDK collected children's geolocation without consent — the FTC warned developers they're liable for vendors' and SDKs' COPPA violations too.

May–Jun 2025 — Lovable CVE-2025-48757

Missing row-level security left 170+ apps' databases fully readable and writable — directly relevant to any childcare app built the same way.

THE FIX-IT CHECKLIST

What We Check On Every Childcare App

  • Row-level security enabled and tested on every table holding child photos, daily logs, or enrollment data
  • Two-factor authentication available on parent-communication and check-in apps
  • Camera streaming portals require authentication and encryption — no open RTSP proxy reachable without a password
  • Enrollment forms collecting allergy, medical, or custody information sit behind access controls that satisfy state licensing confidentiality rules
  • Staff background-check data (FBI fingerprint results, SSNs, abuse-registry checks) is access-controlled and never exposed in a public API
  • Tuition/billing pages are scoped and tested against PCI DSS — no Stripe credentials exposed client-side
  • Camera audio capture has documented consent where required by state wiretap law
  • A written information-security program and data-retention policy exist ahead of the April 22, 2026 COPPA compliance deadline
FAQ

Childcare App Security Questions

Is my daycare check-in app affected by CVE-2025-48757?

If it's built on Lovable and uses Supabase, it may be. This flaw left 170+ apps' databases fully readable and writable due to missing row-level security — in a childcare app that means child photos, logs, and parent contact details. We test for this exact misconfiguration.

What does the amended COPPA Rule require for daycare apps by April 2026?

Verifiable parental consent, a written information-security program, defined data-retention limits, and treating biometric identifiers like faceprints as regulated personal information. Full compliance is required by April 22, 2026, with penalties up to per violation.

Are daycare cameras required to have passwords?

Not always by statute, but leaving them open is a serious liability. Bitsight found 40,000+ daycare cameras streaming publicly with no password in June 2025. Adding audio also triggers all-party-consent wiretap laws in roughly 12 states.

Does a homemade enrollment form need to comply with state licensing rules?

Yes. State childcare licensing rules limit who can access child records to parents and regulators and impose retention requirements. A vibe-coded enrollment form collecting allergy or custody notes without access controls falls under those same confidentiality rules.

What happened in the Kido nursery hack?

In September 2025, attackers stole data on roughly 8,000 children, including photos, addresses, and safeguarding notes, then posted profiles online and called parents directly to pressure the nursery into paying a ransom. No ransom was paid.

How fast can Zooc Digital audit an AI-built childcare app?

Most check-in, parent-comms, or camera-portal audits complete within a few business days. We start with a free automated scan, then a manual review of authentication, RLS/database access, and camera/stream exposure before handing you a prioritized fix list.

RELATED

More Ways We Can Help

Related searches: daycare app data breach · is brightwheel safe for my child's photos · daycare camera privacy laws by state · COPPA compliance for childcare apps · can daycare cameras be hacked · daycare check-in app security · childcare website security audit · secure app built with Lovable · PCI compliance for daycare tuition payments · daycare photo sharing app privacy · preschool enrollment form data protection

Don't Let a Vibe-Coded App Put a Child's Data at Risk

Get a free automated scan of your daycare app — then a full audit if you need one.

Get Your Free Security Scan