Skip to main content
NestBoard

← Journal

Why kid accounts work differently (and why we never ask for a child's email)

The NestBoard team · 2026-05-15

Two kinds of accounts

When you add someone to your NestBoard household, we ask whether they are an adult or a child. It sounds like a small question. It sends the two down completely different paths through the app.

Adults get full accounts. Email login, password recovery, and the ability to start a household of their own. Kids get something lighter: a seat in the household with no email required, managed by the parents who invited them.

That difference is not a shortcut. It comes from two things pushing the same way: a law that draws a hard line at age 13, and a piece of infrastructure most family apps ask parents to fake.

The fake email problem

A lot of family apps require every household member to have a verified email address, even if that member is six years old. So parents end up creating emma.smith.2018@gmail.com for a child who will not touch email for another five years.

It is awkward infrastructure for a reality that does not exist yet. The inbox is never read, the verification link gets clicked once and never again, and it trains families to treat consent flows as obstacles to route around rather than safeguards.

We decided not to do that. When you add a child to NestBoard, you vouch for them. No email required. No verification link sent to an inbox nobody checks.

The under-13 flow

In the US, COPPA, the Children's Online Privacy Protection Act, requires verifiable parental consent before a service can collect personal information from anyone under 13. That includes email addresses, profile photos, and persistent identifiers tied to a child.

So if you are adding a child under 13, NestBoard never asks them to create an account. They do not get a login email. They do not set a password. The parent who invites them provides consent, and the child gets a household-only profile.

That child can do the collaborative parts of NestBoard: see shared calendar events, complete chores, check medication reminders, interact with the family meal plan. Their data lives inside the household, managed by the parents who control the workspace.

How parent vouching works

The trust model is simple. If you control the household, you control who is in it. When you create a kid profile, you are asserting that this person belongs to your family. We trust that assertion because you are the account holder, and because the assertion is not doing much work.

That last part matters more than it sounds. This model would be irresponsible on a social network, where a fake profile can reach strangers. NestBoard is not one. Kids are not sending friend requests or posting publicly. They are marking off chores, checking the dinner plan, and looking up what time their soccer game starts. Contained scope and a small risk surface are what make a lighter trust model appropriate rather than reckless.

Parents stay in control of what sits inside that scope. Robin is adults only, so a kid profile never talks to it at all. Adults decide which events are marked adults-only, which parts of the app the household shows, and when a child graduates to a login of their own. We apply the same care to what Robin can access across the household.

The tradeoff, stated plainly

Skipping email verification is not free, and we would rather name the costs than let you find them later.

No login of their own, so no password to recover. A no-email profile isn't an account. The child taps their name on a device the household is already signed in on, which means there's nothing for them to forget and nothing for us to reset. It also means access to that profile is exactly access to that device. Less convenient, and more honest about who is really in charge of security here.

No individualized email to children. We cannot send a child their own messages, which is almost certainly a feature. Nobody wants their eight year old getting notifications about household updates, let alone promotional mail. The kitchen tablet shows what needs to be shown.

Both point at the same thing: in a house with young children, the adult who set things up is the real security layer. We would rather build around that than paper over it.

Why this matters for family apps specifically

Most productivity tools are built for individuals or coworkers, and adding kids is an afterthought when it is possible at all. A household calendar is different by definition: it exists to coordinate people of different ages, from school pickups to whose turn it is to feed the dog.

Treating every family member as a standard user lands you in one of two bad places. Either young kids are excluded and the app becomes a parent tool the rest of the family merely appears in, or you collect data on children you have no business holding.

When kids do get email

At some point your teenager has their own email address and wants more autonomy. When a child turns 13 we do not flip a switch on our own. Parents can invite them to create a full account, or leave the managed profile as it is. Some families prefer the lighter setup even for teenagers, and that is a legitimate choice rather than a delayed upgrade.

When the change does happen, it is not a migration. The teen links an email to the profile that already exists and takes over password management from there. The account gains a credential it did not have before.

The regulations exist for good reasons. Making a parent create a burner inbox for a toddler is a bad answer to a real problem, so we built a model without one.