Skip to content
UrKidsBook

Policy

Security & Privacy

Version
Effective
Last updated
Owner
UrKidsBook

Controls in place

  • Every database table uses row-level security scoped to the owning account or guest session.
  • All sensitive actions run server-side; the browser never holds elevated credentials.
  • Private storage buckets and signed, short-lived URLs for all customer-specific assets.
  • Character preview is intentionally watermarked and low-resolution to reduce leak risk.
  • Kill switches per global, action, and model can pause AI usage instantly.
  • Hard per-account, per-order, per-day, and global cost caps on AI usage.
  • Abuse protection via challenges and rate limits on high-risk endpoints.

Reporting a security issue

Please email security@urkidsbook.com with a clear reproduction, potential impact, and any relevant timestamps. Do not test in production against accounts you don't own.

This document is part of the UrKidsBook change-controlled policy set. Contact Support for questions or to request a change history extract.