App purpose
KiwiBee app purpose
A plain-English summary of the third-party APIs we use, what data flows in each direction, and how teachers can control or opt out.
Last updated: 2026-10-10
KiwiBee provides teaching resources and a connected school and classroom platform with free and paid plans. This page describes selected integrations, their data flows and choices. It complements the full privacy notice and Trust provider list; it is not an exhaustive statement of every feature or provider setting.
Pinterest API
We use the Pinterest API (v5) to automatically publish free worksheet pins to KiwiBee-owned Pinterest boards so that teachers can discover our resources directly from Pinterest search.
Data we send
- Worksheet title (e.g., "Addition Within 20 — Grade 1")
- Worksheet description (a short summary the admin wrote on upload)
- Preview image URL (publicly hosted on our Supabase Storage CDN)
- Destination link back to the worksheet detail page on kiwibee.io
- Subject + grade tags, used only to choose the right destination board
Data we receive
- Pin ID and board ID, stored only so we can audit what we've published
- API rate-limit headers (standard)
Impact on teachers
Teachers don't connect their own Pinterest accounts to KiwiBee. The integration runs against KiwiBee-owned Pinterest boards only — no user-level Pinterest access, no profile reads, no follower lists, no impersonation.
Opt-out
Worksheets uploaded by KiwiBee admin only get pinned when an admin chooses to. Community-uploaded resources are never auto-pinned. If you'd like a specific KiwiBee worksheet removed from Pinterest, email us at hello@kiwibee.io and we'll delete the pin within 7 days.
OAuth scopes: OAuth scopes requested: pins:read, pins:write, boards:read. We do not request user_accounts:read, user_followers:read, or any private board scopes.
Stripe API
We use the Stripe API to process the optional Standard or Premium upgrade, billed at KiwiBee's published prices. Stripe stores and processes payment information; KiwiBee never sees raw card data.
Data we send
- Teacher's email address (to attach the Stripe customer record)
- KiwiBee subscription plan ID (Standard or Premium), per-student rate, and selected licensed-student count
- A Stripe-issued customer ID, stored on the teacher's KiwiBee profile
Data we receive
- Subscription status (active, past_due, canceled)
- Webhook events when status changes
- Receipts and invoices, sent directly to the teacher by Stripe
Impact on teachers
Stripe is PCI-DSS compliant and handles all sensitive payment data. KiwiBee never sees or stores card numbers, CVCs, or bank details. Teachers manage their subscription (update card, cancel) entirely inside Stripe's Customer Portal.
Optional Google sign-in
Google sign-in verifies an identity token through KiwiBee’s google-auth server function and creates a KiwiBee application session. Email signup uses a password through the register-teacher server function; these flows do not use Supabase Auth accounts or email magic links.
Data we send
- Standard OAuth challenge (no KiwiBee user data)
Data we receive
- Google account email + display name + avatar URL
- A stable Google user ID, used only to recognize the teacher on return visits
Impact on teachers
Google sign-in is optional. This sign-in flow uses basic identity information and does not request contacts, calendars or Drive content. Separate authorized integrations, if enabled, have their own disclosures.
Resend API (transactional email)
Resend supports transactional and separately permitted marketing email. Email content and delivery information depend on the message. Website email signup uses a password, rather than a Supabase Auth magic link.
Data we send
- Recipient email address
- Email subject + body (plain-text and HTML)
Data we receive
- Delivery status (sent, bounced, opened — when tracked)
Impact on teachers
Resend processes only the email content we send, never inbound mail or address books. Teachers can unsubscribe from any marketing email; transactional sign-in / billing emails are sent only in response to their own actions.
Supabase (auth, storage, database)
Supabase hosts our teacher accounts, worksheet downloads, and AI generation history. All data lives in our own dedicated Supabase project.
Data we send
- Teacher profile (email, country, grade levels taught, subjects)
- Download records (worksheet ID, timestamp) for quota enforcement
- AI generation records (the prompts and outputs you create)
Impact on teachers
Request access, export, correction or deletion at hello@kiwibee.io. Closing an account does not automatically erase all school records, shared records or provider copies. We assess the request, school instructions and applicable retention obligations.
Questions or data requests
If you have any question about how we use these APIs, or want to request access, export, correction, or deletion of your data, contact us at hello@kiwibee.io.