Policy
Security & Privacy
- Version
- —
- Effective
- —
- Last updated
- —
- Owner
- UrKidsBook
Controls in place
- Every database table uses row-level security scoped to the owning account or guest session.
- All sensitive actions run server-side; the browser never holds elevated credentials.
- Private storage buckets and signed, short-lived URLs for all customer-specific assets.
- Character preview is intentionally watermarked and low-resolution to reduce leak risk.
- Kill switches per global, action, and model can pause AI usage instantly.
- Hard per-account, per-order, per-day, and global cost caps on AI usage.
- Abuse protection via challenges and rate limits on high-risk endpoints.
Reporting a security issue
Please email security@urkidsbook.com with a clear reproduction, potential impact, and any relevant timestamps. Do not test in production against accounts you don't own.
This document is part of the UrKidsBook change-controlled policy set. Contact Support for questions or to request a change history extract.