Security
Last updated 4 October 2026
You are trusting this site with a connection to your child's Yoto player, so here is what it can do with it, how your account is kept safe, and where the protection stops. I'm one person, and I would rather say plainly what is done than promise more than I can.
Your Yoto account
- Your Yoto password never reaches this site. You sign in on Yoto's own page, and Yoto hands the server a token for your players.
- What the token allows: seeing the players on your Yoto account and sending them commands. It does not give access to your Yoto password or your payment details at Yoto.
- What the server does with it: it asks each player you set up what it is playing, and tells it to pause. It sends no other command.
- How it is kept: encrypted in the database (AES-256-GCM), with a key that is not in the database. A copy of the database alone cannot be used to reach your players. It is left out of the file you get from Download my data, and nobody you share a player with can get it.
- Removing it: in the app, remove the Yoto connection, or delete your account in Settings. Either deletes the token here, and the server stops talking to your players.
Your account here
- Passwords are kept only as a salted Argon2id hash, which cannot be read back. Recovery codes, the cookie that keeps you signed in, password reset links and invite links are kept only as hashes too.
- Guessing is slowed down: a few wrong passwords, recovery codes or links, and that email or network address has to wait.
- The sign-in page does not say who has an account. A wrong password and an unknown email get the same answer, and asking for a reset link says the same thing either way.
- Changing or resetting your password signs out every device. A reset link works once, within an hour.
- Google sign-in is never joined to an account that has a password until that password is entered once, so nobody can take over your account by registering your address first.
- Sensitive steps ask again: a new recovery code and deleting the account ask for your password again, even when you are signed in.
Who can see a player
Only its owners and the people they invite. An invite link works once and expires in 7 days. A member can see the player, add or take away time and pause it; only an owner can change limits or sharing. To anyone else, a player that exists looks exactly like one that does not.
Payments
Card details are entered on Stripe's page and never reach this site. The server keeps your Stripe customer ID and your plan, and checks that messages about payments really come from Stripe.
In your browser
- Everything is served over HTTPS, and browsers are told to refuse anything else.
- The site loads no scripts, fonts or trackers from other companies, and the browser is told to run only this site's own scripts.
- The cookie that keeps you signed in cannot be read by scripts and is not sent along with requests made from other sites. Requests that change something are refused when they come from another site.
- The site cannot be shown inside another site's frame.
Where it runs
On Fly.io in London, where the data is stored too. I keep the data small: what is held, and for how long, is listed in the privacy policy. The software the server is built from is checked for known vulnerabilities every week, and fixes go out as a new release.
What it does not protect against
- It is a guardrail, not a lock. A player is paused through Yoto's cloud, so a player that is offline cannot be paused. That is a limit of how it works, not a fault to report.
- Anyone who can sign in to your account can change the limits. Use a password you use nowhere else, and keep the recovery code like a password: it can reset it.
- No audit or certification. This is a small service run by one person, and it has not been reviewed by an outside security firm. No system is perfectly secure.
Reporting a security problem
Email [email protected] with “Security” in the subject. Say what you found, how to reproduce it, and what you think it allows. I usually answer within a day or two.
- Please test only with your own account and players, and do not read, change or keep anyone else's data.
- Please give me time to fix it before telling others.
- There is no paid reward, only my thanks.
The same details, for tools that look for them, are at /.well-known/security.txt.