Back to Blog

Open the setup screen on almost any app built for more than one kid and you hit the same fork in the road. Either every kid gets folded into one shared bucket where nobody's information is separate from anyone else's, or every kid gets their own account: an email, a password, a little corner of the app that's supposedly theirs to manage. The second option looks like the more careful choice. It usually isn't, not for a six-year-old, and honestly not for most nine-year-olds either.

An account is a small piece of infrastructure before it's anything else. It needs a way to prove you're you: a password, a PIN, sometimes a security question about a first pet nobody quite remembers the spelling of. It needs a way to recover access once that fails: an email address, a phone number, someone on the other end who can reset things. None of that maps onto a kid who's still sounding out her own last name. Hand a six-year-old a password today and you've given her something to lose, something to mix up with the dozen other passwords already floating around the house, something she'll eventually type wrong three times in a row at exactly the wrong moment.

The sign-up screen most apps default to

A lot of family software never actually stops to ask whether a kid needs a login of their own in the first place. The multi-user pattern gets copied straight over from tools built for adults: shared calendars, workplace software, banking apps where every person really does need a separately verified identity. Add a child to that same template and suddenly the form wants an email address that doesn't exist yet, a birthdate that trips an age-gate, sometimes a parent's own email just to approve a kid's account before it can even be used. What started as a way to keep three kids' information separate turns into three sets of credentials nobody in the house can keep straight, least of all the kids they supposedly belong to.

It's a strange answer to a problem that was never really about proving identity. Nobody needs Mia to confirm cryptographically that she's Mia before her mom can check whether she took this morning's allergy medicine. The entire point of tracking a kid's health is that a parent is the one doing the tracking. Giving the kid a login doesn't add any real security to that setup. It just adds a password.

What actually goes wrong

The failure mode here is rarely dramatic. Nobody's account gets hacked. It's smaller and more ordinary than that. A nine-year-old who wants to feel included taps around on an account that's technically hers, changes a setting by accident, and now nobody can find yesterday's log. A six-year-old types the same four-digit PIN wrong enough times that the account locks, and a parent spends twenty minutes in a support chat instead of getting anyone to bed. An eleven-year-old genuinely forgets a password two months after setup, because two months is a long stretch when you're eleven and the account wasn't something you touched every day.

None of this is hypothetical. A striking share of elementary and middle-school kids are already creating and managing their own passwords with very little oversight, well before most of them have the habits to do it reliably.

11.6 average age US kids get their first personal phone, years after most of them are already old enough to be tracked in a parent's app (Stanford Medicine, 2022)
$53,088 maximum FTC fine per violation for collecting a child's personal data without verifiable parental consent (FTC, COPPA Rule)
86% of 6th to 8th graders already create their own passwords with little parental involvement, a habit DoseNest never asks a young kid to start (NIST, 2021)

Put those next to each other and the picture gets clearer. Kids are getting personal devices later than a lot of parents assume, well past the age a family health app would already need to be tracking them. The law treats a child's personal data as something that needs a parent's explicit sign-off before any of it gets collected in the first place. And the accounts kids do end up managing, once they're old enough for school logins and their first social apps, already come with more password sprawl than most of them handle well. Against that backdrop, adding one more login for a six-year-old, just to log a dose of amoxicillin, doesn't hold up.

Added by name. That's it.

DoseNest handles this by not creating the problem in the first place. Adding a child takes one field: a name. Mia. Leo. Ava. No email, because a six-year-old doesn't have one and shouldn't need one. No password, because there's nothing behind that name for a password to protect on its own, it's a label inside the parent's own account, not a separate account of its own. No birthdate gate, no security question, no recovery flow, because there's no login anywhere to recover. The only credential that exists in this entire picture is the one the parent already uses to get into their own phone.

👤
No account for anyone under 18
Kids are added to the family by name only. Nothing gets created that requires an email, a password, or a login of their own.
🔒
Nothing to forget, nothing to lock
There's no PIN to mistype and no password reset flow tied to a child, so there's no account lockout to deal with at bedtime.
📱
One credential for the whole household
The parent's own login is the only one that exists anywhere in the app. Whoever's holding the phone can already get to everything.
🛡
Private by design, not by a setting
A child's medication history sits inside the parent's own account from the first entry. There's no separate child data trail to be mishandled later, because it was never created.

The legal reason this checks out too

There's a regulatory backdrop to all this that most parents have heard of in passing without necessarily connecting it to the apps on their own phone. The Children's Online Privacy Protection Act, COPPA, has applied in the US since 2000 to any app or service that knowingly collects personal information from a child under 13. If an app is going to gather a kid's name, birthdate, email, or anything else tied to that specific child, it has to get verifiable consent from a parent first, and give that parent a way to review or delete whatever's been collected. Violations can run tens of thousands of dollars per incident.

DoseNest sidesteps that whole question by design. A name typed into a parent's own account isn't a child creating an online identity. There's no child-controlled login, no separate credential, no account a kid manages on their own, which means there's nothing collected directly from a child in the way COPPA is built to regulate in the first place.

This wasn't a workaround found after the fact. It's the same decision that makes the app simpler for a six-year-old, arrived at from a completely different direction. Skip the account, and the privacy question a lot of children's apps spend real engineering effort trying to comply with never comes up, because there was never a child-facing account collecting anything to begin with.

What this doesn't mean

None of this makes the app less capable at tracking an actual kid's medication history. Mia still gets her own profile, her own schedule, her own record kept completely separate from her brother's or her sister's, the same separation we've written about before, keeping each sibling's history untangled from the others. What she doesn't get, and doesn't need, is a login of her own to reach any of it. The record belongs to her. The credential belongs to the parent holding the phone.

It also doesn't mean a growing kid is locked out of ever having more independence. Families who want to give an older teenager more visibility into their own health information can figure that out in whatever way makes sense for them, entirely outside of what this app requires. DoseNest just never forces that decision on a six-year-old by making an account a precondition for being tracked at all.

You can see exactly what this looks like on one parent's phone, three kids, zero accounts between them, in the 20-second version on Instagram (link in bio).

Frequently asked questions

Does DoseNest collect any personal information directly from my kids?
No. Every child profile lives inside the parent's own account. There's no separate sign-up flow for a kid, no email or birthdate collected specifically from them, and no independent login for a child to create in the first place. The name you type in is a label inside your own account, not a new account of its own.
What happens if my child taps around on the app while I'm not looking?
There's no login for them to break. A child's profile isn't protected by a PIN or password that can get mistyped into a lockout, because it was never built as a separate credential to begin with. Worst case, they switch to their own profile and look at their own schedule, the same way they'd flip to their own name in a shared photo album.
Will my kid ever need to create their own DoseNest account?
Not through anything the app requires. Every child profile stays inside the parent's account for as long as the family uses it that way. If an older teenager eventually wants more direct involvement in their own health tracking, that's a conversation for the family to have on its own timeline, not something DoseNest pushes as kids get older.

For the flip side of this same decision, how one parent's phone covers every kid's schedule without handing out separate devices, see Kids Don't Need a Phone to Be Tracked. And for how DoseNest keeps two kids' prescriptions from getting crossed even without separate logins, see Two Sick Kids, Two Bottles: Whose Medicine Is Whose?

Every kid tracked. Zero logins.

Add every child in the family by name, no account, no password, ever. Only the parent's own login exists. 7-day free trial, then a straightforward subscription.

Download DoseNest →