Privacy Policy
Last updated: June 27, 2026
1. Introduction
SafeKida ("we", "our", "us") respects your privacy. This Privacy Policy explains how we collect, use, store, share, and protect information when you use our parental control application and related services ("Service"). By using SafeKida, you agree to the practices described in this policy.
2. Information We Collect
2.1 Account Information
- Name, email address, and profile photo
- Authentication credentials (hashed with BCrypt, never stored in plain text)
- Family profile data (children's names, ages, device identifiers)
- Subscription and payment history
- Referral and points activity
- Jurisdiction-specific consent preferences and consent history audit trail
2.2 AccessibilityService API Usage (Android Child App)
SafeKida uses the Android AccessibilityService API strictly to enable core parental control features on child devices. Specifically, AccessibilityService is used to:
- Detect foreground app launches to instantly block restricted applications chosen by the parent
- Monitor web browser URL addresses to filter inappropriate web content and enforce safe search
- Enforce daily screen time limits and bedtime device locking
- Display PIN protection overlay screens over device settings to prevent unauthorized uninstallation or control bypassing
Data processed via AccessibilityService includes app launch events, web browsing URLs, device identifiers, and location coordinates for parental safety monitoring. SafeKida NEVER uses AccessibilityService for remote call recording, keylogging passwords, or selling data for advertising.
2.3 VpnService Usage (Android Child App)
SafeKida uses Android's VpnService strictly for parental control web content filtering and safe browsing protection on child devices.
- Local DNS Tunnel: Establishes a local, encrypted DNS tunnel on the child's device to route DNS queries to safe, child-friendly DNS providers (such as Cloudflare Families)
- Web Content Protection: Automatically blocks access to adult websites, explicit content, malware, and phishing domains across all browsers and applications
- Privacy & Data Security: VpnService operates strictly locally on the device. SafeKida does NOT proxy user web traffic to remote VPN servers, nor does it inspect, log, collect, or share personal browsing data through the VPN tunnel
2.4 Child Device Data
- Location data: GPS coordinates collected at parent-configured intervals (default: every 5 minutes, range: 30 seconds to 1 hour)
- App usage: Which apps are installed, used, for how long, and how frequently
- Screen time: Total active device usage per day
- Blocked events: Attempted access to blocked content or apps
- Device info: Device model, OS version, battery level, network status
2.5 Advertising Data
- Mobile advertising identifiers (AAID on Android, IDFA on iOS)
- Ad interaction data (impressions, clicks)
- Rewarded ad completion status for points redemption
2.6 Automatically Collected
- Firebase Cloud Messaging (FCM) tokens for push notifications
- Crash logs and error reports (anonymized where possible)
- App version, platform type, and build configuration
- API request metadata (timestamps, endpoints accessed)
3. How We Use Your Information
- Provide parental monitoring and control features (screen time, location, content filtering)
- Send push notifications for SOS alerts, screen time events, geofence crossings, and extension requests
- Generate activity reports and usage analytics for parents
- Process subscriptions, micro-payments, refunds, and referral points
- Deliver personalized and non-personalized ads through our ad network partners
- Reward ad engagement with in-app points
- Improve app performance, fix bugs, and enhance features
- Respond to support requests and customer inquiries
- Comply with legal obligations and enforce our Terms of Service
4. Data Storage & Security
Your data is stored on secure servers hosted on Google Cloud Platform (GCP). We implement industry-standard security measures including:
- Encrypted data transmission via HTTPS/TLS (all API communications)
- JWT-based authentication with device ID binding and token rotation
- Passwords hashed with BCrypt (never stored in plain text)
- Access tokens expire after 24 hours; refresh tokens after 30 days
- Database encryption at rest (Cloud SQL)
- HMAC-SHA256 signature verification for payment webhooks
5. Data Sharing
We do not sell your personal data. We do not share or use AccessibilityService API data for advertising, marketing, or call recording. We may share data only in the following circumstances:
- Service providers: Google Cloud (hosting and infrastructure), Firebase (push notifications, crash analytics, app verification), Stripe and PayPal (payment processing), Google AdMob / Meta Audience Network / AppLovin (ad delivery) — each bound by data processing agreements
- Legal compliance: When required by law, legal process, or to protect safety, rights, or property
- Co-parents: Family members you explicitly invite to share monitoring access — they see the same child data as you
- With your consent: In other circumstances, we will ask for your explicit consent before sharing
6. Children's Privacy (COPPA)
SafeKida is designed for use by parents and legal guardians to monitor their children. We do not knowingly collect personal information directly from children under the age of 13 (or the applicable age of digital consent in your jurisdiction). All child data is collected through the parent's authorized account setup and configuration. Child data is accessible only to authenticated parent accounts that have been granted access. If we learn that we have inadvertently collected information directly from a child, we will delete that information promptly.
7. Data Retention
- Account data: Retained while your account is active and for 30 days after deletion
- Location history: Retained for 90 days, then automatically and permanently deleted
- App usage and screen time reports: Retained for 30 days
- Activity feed events: Retained for 90 days
- Payment records: Retained as required by financial regulations (typically 5-7 years)
- Upon account deletion: All associated personal data is permanently removed within 30 days, except where retention is required by law
8. Your Rights (Including GDPR)
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to access: Request a copy of the data we hold about you and your children
- Right to rectification: Correct inaccurate or incomplete information
- Right to deletion: Request deletion of your account and all associated data
- Right to data portability: Export your data in a portable format (CSV)
- Right to restrict processing: Limit how we use your data
- Right to object: Object to certain data processing activities
- Right to withdraw consent: Withdraw consent at any time by uninstalling the App or contacting us
To exercise any of these rights, contact us at contact@safekida.com. We will respond within 30 days.
9. Third-Party Services
SafeKida integrates with the following third-party services, each with its own privacy policy:
- Advertising: Google AdMob, Meta Audience Network, and AppLovin — for delivering ads in the free tier
- Location: Google Maps and Places APIs — for address lookup and map visualization
- Push Notifications: Firebase Cloud Messaging — for SOS alerts, screen time events, and geofence notifications
- Payment Processing: Stripe, PayPal, Google Play Billing, and Apple In-App Purchase — for subscriptions and micro-payments
- Analytics & Crash Reporting: Firebase Crashlytics and Firebase Performance Monitoring — anonymized data, disabled in debug builds
- App Security: Firebase App Check with Play Integrity — for verifying app authenticity
We encourage you to review the privacy policies of these third-party services. You can manage ad personalization through your device settings (Android: Google Ads settings; iOS: App Tracking Transparency).
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal obligations. We will notify you of significant changes via email or in-app notification at least 30 days before they take effect. Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related questions, data requests, or concerns:
Email: contact@safekida.com
Response time: We aim to respond within 48 hours.
12. Secure Mode Data Handling
Secure Mode ("This Device" mode) enforces your child's parental control rules on your own device. In Secure Mode, the same device data is processed locally on your phone to enforce content filtering, app blocking, and device protection. This includes reading your installed apps list, monitoring app usage for blocking decisions, and applying DNS/VPN restrictions locally. No additional personal data is collected or transmitted to our servers solely because Secure Mode is active. All data collection and processing remains as described in the sections above. Your child's parental control rules (content filter settings, app block lists, device protection settings) are fetched from our servers to apply locally, but these are settings you configured, not personal data.