Privacy
Last updated: June 2026
Who we are
Fishtank is a curated kid-safe video viewer. The iOS app lets a parent or guardian sign in with Apple, optionally add per-kid profiles, and watch videos curated from public YouTube channels.
What we collect, and why
If you do not sign in: Fishtank collects nothing about you. No analytics, no advertising identifiers, no cookies.
If you sign in with Apple: we receive your stable Apple-generated user identifier and (if you choose to share it) your email address. We store this in Firebase Authentication, tied to a private user record we create for your account. We use this solely to keep your profiles and watch history attached to your account.
If you create kid profiles:we store the kid's name, age, and chosen avatar (an emoji + color). This data is stored in our Firestore database under your account.
If a profile is active when a video is opened:we log which video was watched, when, and which channel it belongs to. This appears in the “Watch history” panel inside the Grown-ups area. You can delete individual entries from the app.
What we do NOT collect
- No advertising identifiers (no IDFA, no ad tracking)
- No location data
- No contacts, photos, microphone, or camera access
- No third-party analytics SDKs (Firebase Crashlytics is not enabled)
- No data brokers or behavioral profiling
YouTube video playback
Videos play inside the app via YouTube's privacy-enhanced embed (youtube-nocookie.com). When a video begins playing, YouTube's own privacy terms apply for that session and YouTube may serve ads. Fishtank itself does not receive tracking signals from the YouTube embed.
Where your data is stored
Account and profile data is stored in Google Cloud (Firebase Authentication + Cloud Firestore) under a project we operate. The database is multi-region in the United States. Firestore security rules restrict each parent account to read and write only its own data — no one else can access your records.
Deleting your data
You can delete your account and all associated data at any time from inside the app: Grown-ups → Account → Delete account. This permanently removes your Firebase Authentication record, every kid profile, and every watch-history entry. If something goes wrong, email hello@fishtank.kids and we'll delete on request.
Children
Fishtank is designed to be used bychildren but the account itself belongs to the parent or guardian. Children do not create accounts and we do not collect their personal information directly. The kid-profile metadata a parent enters (name, age) is stored only under the parent's account.
Changes to this policy
If we ever change what data we collect, we'll update this page first and bump the “Last updated” date above.
Contact
Privacy questions, deletion requests, or anything else — email hello@fishtank.kids.