What SafeParent processes
SafeParent processes a parent email address, display name, encrypted authentication data, child profile labels and age ranges, linked-device identifiers, protection settings, custom blocked hostnames, subscription status, push-notification tokens, and minimal safety-event metadata such as a hostname or app label, category, linked device, and time.
When website protection is enabled, a local Android VPN compares DNS domain names on the child phone with parent-selected categories and custom rules. Allowed domains are not stored. For a blocked request, only the blocked domain, category, linked device, and time may be sent to the linked parent and SafeParent server. Page paths, page contents, searches, passwords, messages, and calls are never inspected. Web traffic is not routed through a SafeParent server.
After a child phone is paired, Child Mode collects that phone's precise location in the background, including when the app is closed or not in use. While the phone is moving it may send an updated point about every five seconds; while stationary it sends at most about once per minute. The server uses these points to show the linked parent the latest location and to create arrival and departure alerts for parent-defined places.
What SafeParent does not collect
SafeParent does not read messages, record calls, access microphone content, collect contacts, sell personal information, or use child activity for advertising. Camera access is used only when the user chooses to scan a temporary pairing QR code. A parent phone may use its GPS locally to center the map or create a place, but the parent GPS point is never uploaded or shared. Only a paired child phone publishes child-location points.
Purpose and service providers
Data is used only to authenticate parents, pair devices, synchronize rules, provide requested protection features, deliver safety notifications, prevent abuse, and maintain subscriptions. Hosting and network delivery use the SafeParent server and Cloudflare. Purchases are processed by Google Play and RevenueCat; SafeParent never receives or stores card details.
Security, retention, and deletion
Traffic uses HTTPS. Pairing codes expire, are single-use, and are stored only as cryptographic hashes. Account data is kept while the account is active. A parent can permanently delete the account and associated SafeParent data inside the app or through the web deletion page. Limited records may be retained only where required for security, fraud prevention, tax, or legal compliance.
Children and parental responsibility
A parent or legal guardian creates and controls the account and is responsible for installing and authorizing Child Mode in accordance with local law. SafeParent minimizes data from child devices and does not use it for advertising or profiling.
Your rights and contact
You may access, correct, export, or delete your information from the app. Privacy and deletion requests can also be started through the secure deletion page. Questions can be sent to [email protected].