Tap Guardian Privacy Policy

Last updated: June 10, 2026

Effective date: June 10, 2026

Introduction

Tap Guardian (“we”, “us”, or “our”) is a parental control application designed to help families manage children's digital wellbeing. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.

Information We Collect

We collect the following types of information:
  • Account Information: Name, email address, and password when you register.
  • Child Profile Data: Child's name, age group, and avatar selection. Child profiles are created exclusively by the parent — children never provide information directly.
  • Device Information: Device type, operating system, device identifiers, and FCM tokens for push notifications.
  • Location Data: Real-time and historical location data from child devices when location permissions are granted by the parent. Location is collected via the device's GPS and network services only while the app or its background service is active.
  • App Usage Data: Information about apps installed and used on child devices, including usage duration.
  • Screen Time Data: Daily screen time usage, limits set by parents, and schedule configurations.
  • Task & Reward Data: Tasks created by parents, task completion status, points earned and spent, reward store purchases, and achievement/badge progress.
  • Brain Boost Data: Quiz answers, scores, and completion history. Quiz content is generated based on the child's age group and is not linked to any external educational profile.
  • Chat Messages: Messages exchanged between parent and child within the app.
  • Phone Number: Parent phone number for SOS emergency alerts and account recovery (optional).
  • Website Waitlist: If you join our launch waitlist on tapguardian.io, we collect the email address you submit. It is stored with our email service provider Brevo and used only to contact you about Tap Guardian availability.

Device Permissions We Request

The App requests the following device permissions on the parent and child devices. Each permission is used solely for the stated purpose and can be revoked at any time through your device settings.
  • Location (precise & background): Real-time location and safety zone alerts on child devices. Disabled by default; requires explicit parental opt-in.
  • Notifications: Alerts for app blocking, location events, task reminders, and chat messages.
  • Apple Family Controls / Screen Time API (iOS):On-device screen time enforcement and app blocking. Data is processed on the device and not transmitted to our servers in raw form.
  • Android Usage Stats & Accessibility (Android):Usage measurement and app blocking on child Android devices.
  • Camera (optional): Used on the child's device to scan the pairing QR code shown on the parent's device, and optionally to set a profile avatar photo. Images are not retained on our servers unless you explicitly upload them as an avatar.
  • Photo Library (optional): Choosing an avatar.
  • Contacts: Not requested. We do not access your contacts.
  • Microphone: Not requested. We do not record audio.

App Tracking Transparency (iOS)

Tap Guardian does not track you or your family across other companies' apps and websites. We do not display the iOS App Tracking Transparency (ATT) prompt because we do not engage in tracking as defined by Apple. We do not use IDFA, third-party analytics that profile users, or any cross-app/cross-site advertising identifiers.

How We Collect Information

  • Directly from you: When you create an account, set up child profiles, configure settings, or contact support.
  • Automatically from devices: App usage data, screen time statistics, location data, and device information are collected automatically by the Tap Guardian app installed on child devices, with parental consent.
  • From third-party services: Authentication data from Firebase and subscription status from RevenueCat/app stores.

Children's Privacy (COPPA & GDPR-K Compliance)

Tap Guardian is designed for use by parents and legal guardians to manage their children's device usage. We comply with the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation provisions for children (GDPR Article 8), and Google Play's Families Policy. We take children's privacy seriously:
  • We do not collect personal information directly from children under 13 (or under 16 in applicable EEA jurisdictions) without verified parental consent.
  • Parental Consent mechanism: All child profiles are created and managed exclusively by an authenticated parent account holder. Before any child data is collected, the parent must create an account, affirmatively confirm that they are the child's parent or legal guardian, and expressly consent to the collection of child data via consent checkboxes presented at registration. The parent must be logged in and explicitly create each child profile before any child data is collected. For families on a premium plan, parental identity is further corroborated through Apple App Store or Google Play purchase flows, which involve identity-verified payment credentials.
  • Child data deletion timeline: When you delete a child profile, all data associated with that child (location history, app usage, screen time records, chat messages, quiz results, tasks, and rewards) is permanently deleted from our production systems within 14 days and from encrypted backups within 30 days.
  • Parents can review, modify, or delete their child's data at any time by editing or deleting the child profile in the app, or by using Settings > Export My Data.
  • Child data is only accessible to the parent who created the profile and any authorized co-parents.
  • We do not serve any advertising to children. The app contains no ads of any kind.
  • We do not sell, lease, or trade children's personal information to third parties for any purpose.
  • We do not use children's data for profiling, marketing, or behavioral targeting.
  • Parents may revoke consent and request deletion of their child's data at any time by deleting the child profile in the app or by contacting us at privacy@tapguardian.io.

Advertising Policy

Tap Guardian does not display any advertisements — including banner ads, interstitial ads, video ads, or native ads — anywhere in the application. We do not use any third-party advertising SDKs. We do not collect or share data for advertising purposes. This applies to both parent and child experiences within the app.

How We Use Your Information

  • To provide and maintain the Tap Guardian service.
  • To enable parents to monitor and manage children's screen time and digital activities.
  • To provide location tracking and geofence alerts.
  • To send push notifications for alerts, reminders, and app blocking commands.
  • To generate usage reports and weekly summaries.
  • To facilitate parent-child communication through in-app chat.
  • To send SOS emergency alerts (SMS and voice call) to parents when triggered by a child.
  • To improve and personalize the app experience.
  • To detect and prevent fraud or abuse.

Data Storage & Security

Your data is stored securely on our servers. We implement industry-standard security measures including:
  • Encrypted data transmission (HTTPS/TLS).
  • Secure password hashing (bcrypt).
  • HTTP-only cookies for session management.
  • Firebase Authentication for identity verification.
  • Regular security audits and updates.

Third-Party Services & Data Sharing

We use the following third-party services. Each provider is contractually required to protect your data to the same or higher standard as described in this Privacy Policy:
  • Firebase (Google LLC): Authentication, push notifications (FCM), and crash reporting. Firebase Analytics is configured to not collect advertising identifiers (IDFA) or identifiable information from children. Privacy
  • MongoDB Atlas (MongoDB, Inc.): Encrypted database hosting for all app data. Privacy
  • Railway (Railway Corp.): Server hosting with TLS encryption. Privacy
  • RevenueCat (RevenueCat, Inc.): Subscription management. RevenueCat receives only anonymized user identifiers and subscription status — no child data. Privacy
  • Apple ScreenTime API / Android UsageStats: On-device screen time management. This data is processed locally on the device. Apple privacy · Google privacy
  • Twilio (Twilio Inc.): SOS emergency SMS and voice calls to parents. Twilio receives the parent's phone number and the alert message solely to deliver SOS notifications. See Twilio's privacy policy for details on their data handling. Privacy
  • Sentry (Functional Software, Inc.): Server error monitoring. Receives technical error reports and request metadata so we can detect and fix crashes and bugs; not used to profile users. Privacy
  • Brevo (Sendinblue SAS): Stores email addresses submitted to our website launch waitlist and sends launch notifications. Receives no app or child data. Privacy

We do not “sell” or “share” your personal information within the meaning of the California Consumer Privacy Act (CCPA/CPRA), and we do not engage in cross-context behavioral advertising. We have not sold or shared personal information of any consumer in the past 12 months and do not have actual knowledge of selling or sharing personal information of consumers under 16 years of age. Data is shared with the services listed above solely to provide the Tap Guardian service.

Data Retention

We retain personal data only as long as needed to provide the service or comply with legal obligations. Specific retention periods:
  • Account data (parent name, email): For the life of the account; deleted within 30 days after account deletion.
  • Location history: Rolling 7 days, then automatically purged. The most recent known location is retained while the child profile exists so parents can always see a last known position.
  • Screen time & app usage records: Per-app usage records are kept on a rolling 30-day basis, then automatically purged. Daily screen-time totals are retained for the life of the child profile.
  • Chat messages: Automatically deleted after 90 days, or sooner upon account deletion.
  • Brain Boost quiz results & reward history: Individual quiz logs are kept on a rolling 15-day basis. Aggregate points, achievements, and reward history are retained for the life of the child profile and deleted with the profile.
  • Encrypted backups: All deleted data is purged from backups within 30 days of deletion.
  • Billing & transaction records: Retained 7 years for tax and audit compliance, as required by law.

Sensitive Personal Information (CCPA/CPRA)

Under the California Privacy Rights Act, the following data we collect is classified as “Sensitive Personal Information”:
  • Precise geolocation (location of child devices, when enabled).
  • Account credentials (email and password used to sign in).

We use Sensitive Personal Information only for the purposes identified in “How We Use Your Information” — to provide location safety features and authenticate your account. We do not use Sensitive PI for inferences about characteristics, profiling, or any purpose other than providing the service. California residents have the right to limit the use and disclosure of their Sensitive PI; to exercise this right, email privacy@tapguardian.io.

Automated Decision-Making & Profiling

We do not use automated decision-making, including profiling, that produces legal effects or similarly significantly affects you or your child. Quiz difficulty in Brain Boost adapts to a child's past answers, but this is content personalization, not a decision producing legal or similarly significant effects under GDPR Article 22.

California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and how it is used, the right to delete your personal information, and the right not to be discriminated against for exercising your rights. We do not sell personal information.

EU/UK Representative

For users in the European Economic Area and United Kingdom, you may contact our designated representative regarding GDPR/UK GDPR matters at eu-rep@tapguardian.io. We will publish the name and address of our appointed representative on this page once Tap Guardian has formally designated one in accordance with Article 27 GDPR.

International Users (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, the following applies:
  • Legal basis for processing: We process parent data based on (a) your consent when you create an account, (b) contractual necessity to provide the Tap Guardian service, and (c) our legitimate interest in maintaining app security and preventing abuse. We process child data exclusively based on verified parental consent.
  • Your rights: You have the right to access, rectify, erase, restrict processing, data portability, and to object to processing.
  • Data transfers: Your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place through standard contractual clauses with our service providers.
  • Right to lodge a complaint: You have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us at privacy@tapguardian.io.

Data Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users without undue delay, and within 72 hours of becoming aware of the breach where required by GDPR or applicable law. Notifications will be sent to your registered email address and, if appropriate, posted in the App. We will report breaches to the applicable supervisory authority as required.

Cookies & Website Tracking

Our mobile app does not use cookies. Our marketing website (tapguardian.io) uses Google Analytics to understand aggregate site traffic and improve the site. Google Analytics sets cookies (such as “_ga”) for this purpose. We do not use advertising cookies, we do not sell visitor data, and analytics data is not linked to any app account or child data. You can opt out of Google Analytics with the Google Analytics opt-out browser add-on or by using your browser's tracking protection features.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes through the app or by email. Continued use of the app after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: