Who We Are
Parenting360 ("Company," "we," "us," or "our") operates the Parenting360 platform — a specialized Mobile Device Management (MDM) system engineered exclusively to support parents and legal guardians in monitoring and protecting their minor dependants.
This Privacy Policy explains what data we collect, why we collect it, how we protect it, and what rights you have over it. By creating a parent account or installing the monitoring agent on a child device, you acknowledge and agree to the practices described in this document.
For any privacy-related questions, contact us at: [email protected]
Scope of Application
This Privacy Policy governs all data processed across the following components of the Parenting360 platform:
- The Parenting360 Parent Dashboard — the Android application used by parents to view reports, configure rules, and receive alerts.
- The Parenting360 Monitoring Agent — the background service installed on the child's Android device that collects and transmits telemetry to the parent dashboard.
- Our backend API, databases, and cloud infrastructure that store, process, and serve the collected data.
Definitions
| Term | Meaning |
|---|---|
| Parent Account | The authenticated profile created and managed exclusively by the legal parent or guardian. |
| Child Device | The Android smartphone or tablet belonging to the minor, on which the monitoring agent is installed by the parent. |
| Telemetry Data | Device metrics and activity signals streamed from the child device to the parent dashboard: GPS coordinates, app usage, screen state, device health, and notification metadata. |
| Authorized User | The authenticated parent or legal guardian verified as the custodian of the child device. |
| Monitoring Agent | The background Android service installed on the child device. It runs as a foreground service with a visible notification. |
| Personal Data | Any information that identifies or can be used to identify a natural person, as defined under applicable data protection laws. |
Data We Collect
We operate under strict data minimisation principles. No data is collected unless it is directly required to deliver a specific feature. Below is a complete index of every category of data we process.
4.1 — Parent Account Data
| Data Field | Purpose |
|---|---|
| Full Name | Identity mapping and in-app personalisation. |
| Email Address | Authentication, account recovery, and system alert delivery. |
| Account Creation Timestamp | Account lifecycle and audit logging. |
4.2 — Child Device Telemetry
The monitoring agent collects the following data categories only when activated via the parent dashboard. Each category corresponds to a specific parental control feature.
| Data Category | Specific Data Collected | Feature It Enables |
|---|---|---|
| GPS Location | Real-time coordinates (latitude, longitude, accuracy radius), location history, geofence entry/exit events. | Live location map, location history timeline, geofence alerts. |
| App Usage | Names of installed apps, active app at foreground, session durations, blocked app attempt logs. | App usage reports, per-app screen time limits, app blocking. |
| Screen Activity | Total daily screen time. | Screen time reporting, bedtime/downtime enforcement. |
| Web Browsing Activity | URLs visited in browser apps, page titles, visit timestamps, blocked site events. | Web history reports, site filtering, content category blocking. |
| Device Health Signals | Battery level, charging state, Wi-Fi status, mobile data status, Bluetooth status, GPS enabled state, volume level, screen brightness, network data usage. | Device status dashboard, connectivity monitoring. |
4.3 — Data We Explicitly Do NOT Collect
The following data types are never collected by Parenting360 under any circumstances:
- SMS message content or contact lists — The READ_SMS and READ_CONTACTS Android permissions are not declared in our application.
- Phone call logs or call recordings — The READ_CALL_LOG and RECORD_AUDIO permissions are not used for call monitoring.
- Biometric data — No facial recognition, fingerprint data, or iris scans are collected or processed.
- End-to-end encrypted message content — Content from apps such as Signal, WhatsApp (encrypted), or similar secure messengers cannot be decrypted or read.
- Data from devices not linked to your account — We only process data from devices explicitly paired to your parent account.
- Camera or microphone captures — We do not take photos, record audio, or access live camera feeds.
Zero Data Monetization
Parenting360 prohibits all forms of data commercialisation, data rental, profile brokerage, ad targeting, or secondary telemetry licensing. Your family's data exists solely within your account environment and is never processed for commercial gain.
This constraint applies universally — including to anonymised datasets, aggregated usage metrics, and general behavioural graphs. No business event, funding round, or acquisition changes this policy without your explicit, prior written consent.
How We Use Your Data
Data collected through the platform is used exclusively for the following purposes:
- Dashboard Rendering: Displaying location maps, usage graphs, app reports, and device health indicators inside the parent application.
- Rule Enforcement: Executing configured restrictions — app time limits, bedtime schedules, site filters, geofence boundaries, and content blocking rules.
- Real-Time Alerts: Sending push notifications to the parent device when configured alert conditions are triggered (geofence breach, SOS gesture, blocked app attempt).
- Service Reliability: Diagnosing crashes, monitoring API performance, and maintaining infrastructure stability.
- Security: Detecting unauthorised access attempts, account anomalies, and potential data breaches.
We do not use your data for advertising, user profiling, or any purpose beyond direct delivery of the parental control features you have configured.
Third-Party Services
The Parenting360 platform integrates a limited set of third-party infrastructure services. Each acts strictly as a data processor under contractual obligations and cannot use your data for their own purposes.
7.1 — Integrated Third-Party Providers
| Provider | Purpose | Data Shared | Their Privacy Policy |
|---|---|---|---|
| Google Firebase (FCM) | Push notification delivery to parent devices. | Device push token, notification payload. | firebase.google.com/support/privacy |
| Firebase Crashlytics | Crash reporting and app stability monitoring. | Crash stack traces, device model, OS version, app version. No personal user data. | firebase.google.com/support/privacy |
| Google Maps SDK | Rendering the live location map inside the parent dashboard. | Map tile requests (no personal data transmitted beyond standard API usage). | policies.google.com/privacy |
| MQTT Broker (Eclipse Paho) | Real-time bidirectional communication between parent dashboard and child device. | Encrypted device telemetry payloads routed through our own privately hosted MQTT server. No third-party MQTT provider reads this data. | Self-hosted — no external provider. |
| Cloud Hosting Infrastructure | API servers, database storage, and backend compute. | All stored application data, encrypted at rest (AES-256). | Governed by our data processing agreements (DPAs) with our cloud provider. |
7.2 — Legal Compulsion
If a valid, legally binding court order requires us to disclose records, we will: verify the legal authority of the order, provide only the precise records specified, and notify the affected user as promptly as applicable law permits.
Android Permissions Explained
The Parenting360 monitoring agent requests the following Android system permissions. Each permission is required for a specific feature and cannot be substituted with a less sensitive alternative.
8.1 — Location Permissions
- & — Required to read the device's GPS coordinates for live location tracking.
- — Required to continue location tracking when the app is not in the foreground (e.g., when the child is using another app or the screen is off).
8.2 — Accessibility Service
- — Required to detect which app is currently in the foreground in real time, enabling per-app usage tracking and enforcement of app blocking rules. Accessibility Service is used solely to determine the currently active application and to enforce parental control features such as app blocking and supported browser website filtering. We do not use Accessibility to record passwords, read private messages, capture keystrokes, or collect arbitrary screen content. Accessibility data is processed solely to provide parental control features explicitly enabled by the parent or legal guardian. We do not sell, rent, license, or otherwise monetize personal user data or child telemetry. If this policy ever changes, we will clearly notify users before such changes take effect where required by applicable law.
8.3 — App Usage Statistics
- — Required to retrieve a history of which apps the child has used and for how long. This data powers the app usage reports and per-app time limit features in the parent dashboard.
- — Required to build the complete list of apps installed on the child's device, which parents use to configure per-app rules and restrictions.
8.5 — Overlay Permission
- — Required to display a blocking overlay screen when the parent has configured app or screen time limits that have been reached. This is the mechanism that enforces restrictions.
8.6 — Foreground Service & Notifications
- / / — Required to keep the monitoring agent running continuously in the background. Android requires foreground services to display a persistent notification, which means the child can always see that the app is active.
- — Required to show the mandatory persistent foreground notification on the child's device and deliver alerts to the parent's device.
- — Required to display high-priority alerts (sent by the parent) over the child device's lock screen, ensuring the child cannot miss urgent notifications from the parent.
Security Architecture
Security is a core design constraint, not an afterthought. The following protections are in place across our entire infrastructure:
All data transmitted between the child device, parent app, and our servers is encrypted using TLS 1.3 with strong cipher suites.
All database volumes and stored files are encrypted at rest using AES-256 block encryption.
Internal employee access to production data is restricted by role-based policies and monitored through continuous audit logs.
Automated vulnerability scans run against our infrastructure and application code before every production deployment.
9.1 — Data Breach Response
In the event of a verified data breach, we commit to the following response protocol:
- Where required by applicable law, we will notify affected users and relevant authorities without undue delay.
- Provide a clear summary of what data was accessed, how the breach occurred, and the remediation steps taken.
- Report to the relevant data protection authority where required by applicable law.
Data Retention
We retain data only for as long as necessary to deliver the service or satisfy legal obligations. The following retention schedules apply:
| Data Category | Retention Period | Reason |
|---|---|---|
| GPS Location History | 90 days | Enables parents to review historical location timelines. Older records are automatically purged. |
| App Usage Logs | 90 days | Powers weekly and monthly usage trend reports in the parent dashboard. |
| Notification Content | 30 days | Short-term alert review. Automatically purged after 30 days. |
| Device Health Signals | 30 days | Battery, connectivity, and hardware status history for trend analysis. |
| Web Browsing History | 30 days | Content review period for parental oversight. Purged automatically thereafter. |
| Parent Account Data | Until account deletion + 30-day grace period | Active account maintenance. The 30-day grace period allows account recovery before permanent deletion. |
| Crash & Error Logs | 60 days | Required for diagnosing and resolving stability issues. |
After retention periods expire, data is permanently and irreversibly deleted from our servers and backups within the next scheduled purge cycle (maximum 7 additional days).
Your Rights
Depending on your country of residence, you may have legal rights regarding your personal data under applicable privacy laws, including the GDPR (European Union), the CCPA (California, USA), and other applicable regional privacy laws. We respect and support these rights where applicable.
Request a full copy of the personal data we hold about you and your linked child device.
Request permanent deletion of your account and all associated data, including all child telemetry records.
Request correction of any inaccurate or incomplete personal data held in your account profile.
Request an export of your data in a machine-readable format (JSON or CSV) to transfer to another service.
Object to specific data processing activities where our legal basis is legitimate interest rather than contract or legal obligation.
Request that we pause processing of your data while a dispute or correction request is being resolved.
How to Exercise Your Rights
To submit any data rights request, contact our Privacy Team directly:
📧 Email: [email protected]
We will acknowledge your request within 48 hours and fulfil it within 30 days. If we need more time (up to 60 additional days for complex requests), we will notify you with an explanation.
We do not charge a fee for data rights requests. We may request identity verification before processing to protect your account security.
Children's Data & COPPA Compliance
12.1 — Parental Consent Framework
Parenting360 does not collect data from minors directly. All data collection from a child device is:
- Initiated by the parent or legal guardian who creates the account and physically installs the monitoring agent on the child's device.
- Configured and controlled by the parent through the dashboard — only features the parent explicitly enables are active.
- Consented to by the parent on behalf of their minor child, as permitted under applicable laws including COPPA (US), GDPR Article 8 (EU), and equivalent regional frameworks.
12.2 — Transparency to the Child
The monitoring agent is designed to be visible and transparent on the child's device:
- A persistent notification is displayed on the child's device at all times while the monitoring agent is active, clearly identifying the app as running.
- The app icon remains visible in the app drawer — it is not hidden or disguised.
- The app cannot be installed remotely without physical access to the child's device.
12.3 — COPPA (USA)
Parenting360 does not knowingly collect personal information directly from children under 13. The parent account holder (an adult) is the data subject for account purposes. Child device telemetry is collected under the consent and direction of the parent. Parents may contact [email protected] to review, correct, or delete data associated with their child's device at any time.
12.4 — GDPR (European Union) — Children's Data
Where applicable, data collection from child devices is based on the lawful basis of contract performance (the parent's service agreement) and legitimate interests of the parent in protecting the wellbeing of their minor child. Parents in the EU may exercise the full suite of GDPR data subject rights on behalf of their minor children as described in Section 11.
12.5 — Child Data Isolation
Child telemetry is strictly isolated to the linked parent account. It cannot be accessed by other users, other parent accounts, or any third party. When a parent deletes their account or unlinks a child device, all associated child telemetry is permanently deleted within the next scheduled purge cycle.
Contact Us
For any privacy-related questions, data rights requests, concerns about how your data is handled, or to report a potential privacy issue, please contact our Privacy Team:
📧 Privacy Email: [email protected]
🌐 Website: parenting360.app
⏱️ Response Time: We acknowledge all privacy requests within 48 hours and resolve them within 30 days.