Last updated: June 11, 2026
The short version: KeySmash collects nothing from children. No accounts, no ads, no tracking of kids. Ever.
KeySmash is a web toy for children ages 1–5, operated by an independent developer. Because it is directed at children, we designed it to collect zero personal information from children — the strictest reading of the U.S. Children's Online Privacy Protection Act (COPPA).
To understand whether the toy works (e.g., "how many visitors play for five minutes"), we count a handful of anonymous events: a visit, a five-minute play session, the parent menu opening, a checkout starting, and a purchase. These are processed by PostHog configured in its strictest privacy mode:
The one-time unlock is purchased by a parent or guardian through Stripe, which processes the payment and your email address under its own privacy policy. We never see or store your card number. Your email is used for exactly two things: your receipt, and a "restore purchase" link so the unlock works on your other devices. It is never used for marketing and never shared beyond Stripe and our email delivery provider (Resend) for that single message.
KeySmash does not collect, use, or disclose personal information from children under 13. The only personal information touching this service — a purchasing parent's email — is collected from adults in a parent-gated checkout flow. We therefore operate without child accounts, parental-consent flows, or data-deletion requests for children, because there is no child data to manage.
Questions or requests: ianbondw@gmail.com
We will update this page if anything changes, and we will never change the core promise: nothing is collected from kids.