Legal

Privacy Policy

Last updated pre-launch draft — not yet legally reviewed

Guardian exists to give parents real visibility into their child's devices, which means we handle genuinely sensitive data — including a minor's. This page describes what we collect, why, and how it's protected, as accurately as we can while the product is still in early access. It is a working draft, not a substitute for review by a qualified privacy lawyer before general availability.

Who controls the data

A Guardian account belongs to a parent or legal guardian, not the child. All settings, reports, and data collected from a paired device are visible to the family account that paired it — Guardian does not sell, rent, or share your family's data with advertisers.

What we collect from a paired device

  • Device identity and platform (e.g. Android, iOS, a specific TV OS) — needed to know what enforcement that device actually supports.
  • App usage summaries and the policy/schedule state applied to that device.
  • Location, only if you enable location check-ins for that child.
  • Call and SMS metadata, and message content, only on platforms/plans where call & SMS monitoring is enabled.

SMS message body content is treated as a materially more sensitive category than everything else in this list: it's encrypted at rest with AES-256-GCM, not stored as plain text, as a hard requirement — not a nice-to-have.

Account and billing data

We store your account email and a securely hashed password (never the password itself — Guardian uses Argon2 hashing). If you subscribe to a paid plan, billing is handled by Stripe; we store your subscription status and plan, not your card details, which never touch our servers.

Who else sees it

We use a small number of third-party processors, each only for what they need to do their job:

  • Stripe — payment processing for paid subscriptions.
  • Our transactional email provider — account verification and notification emails.
  • Our cloud hosting/database provider — where your family's data is stored.

Retention and deletion

Your family's data is retained for as long as your account is active. You can request deletion of your account and associated data at any time by contacting us — we'll confirm what's deleted and any legal/billing records we're required to retain briefly for tax or fraud-prevention purposes.

Children's privacy

Guardian is designed to be set up and controlled by a parent or legal guardian, not signed up for by a child directly. If you believe a child has created a Guardian account without parental involvement, contact us and we will investigate and remove it.

Your rights

You can access, correct, export, or delete your family's data by contacting us. Depending on where you live, you may have additional rights under local law (e.g. GDPR, CCPA) — we will honor requests made under those laws even before we've completed a full regional compliance review.

Contact

Privacy questions or requests: hello@myguardian.fyi.