Privacy Policy
Nobody reads walls of legal text, so we didn't write one. Every section below opens with a one-sentence summary, and the top card shows the whole policy at a glance. The full text is the binding version — and it says the same things.
Privacy facts
The whole policy at a glance — details in the sections below
- Data collected
- Location, per-app daily screen time, guardian account details
- Why
- The safety features your family turned on — nothing else
- Sold to anyone?
- Never. No advertisers, brokers, or tracking SDKs
- Who can see it
- Guardians in your own family group (and the child, for their own data)
- Where it lives
- Your family's Safentora server, TLS in transit, hashed credentials
- Kept until
- The account leaves the family — then it's deleted
- Child's awareness
- Consent screen before monitoring; every action visible on-device
- Your exit
- Delete members, data, or the whole family at any time
- 1
Collected
Only after the child accepts the consent screen — location and screen-time totals.
- 2
Used
To power the map, safe-zone alerts, and screen-time charts for your guardians.
- 3
Retained
On your family's server while the account is part of the family. TLS in transit; credentials stored as hashes.
- 4
Deleted
Remove the account from the family and its data goes with it. Deletion requests: 30 days, usually much faster.
What we collect — and what we don't
In short: Location, per-app daily screen time, and basic account details (name, email for guardians). No messages, no screen contents, no photos, no keystrokes — ever.
For a monitored child device, Safentora collects: device location (coordinates, accuracy, speed, and battery level) while location sharing is on, the package name of the app currently in the foreground, and how long each app is used per day (screen time totals).
For guardian accounts, we collect the name, email address, and password you register with (the password is stored only as a bcrypt hash — we cannot read it), plus the family configuration you create: members, safe zones, and app rules.
Safentora does not collect the contents of anyone's screen, messages, photos, browsing history, notifications from other apps, contacts, call logs, audio, or anything typed. The permissions that would make several of those technically possible are deliberately not requested — see Permissions Explained for the full manifest-level detail.
Why we collect it
In short: One reason: powering the safety features your family turned on. There is no advertising, profiling, or secondary use.
Location data powers the live family map and safe-zone (geofence) alerts. Screen-time totals power the screen-time charts. App rules and lock state power app blocking and the remote lock. Account data powers sign-in and family membership.
We do not use your family's data for advertising, we do not build behavioral profiles, and we do not use children's data to train AI models. Data collected for a safety feature is used for that safety feature.
Consent — especially the child's
In short: Monitoring starts only after the child accepts a plain-language consent screen on their own device. Their acceptance is recorded per policy version.
Safentora is built consent-first. Before any monitoring begins on a child device, the child is shown a consent screen summarizing exactly what will be shared — the same facts as this policy, in the same plain language. Monitoring does not start until it is accepted, and declining signs the device out.
Consent is recorded against a specific policy version (currently 1.0). If this policy materially changes, the version number changes, and the consent screen reappears on the child's device before monitoring continues.
As the parent or legal guardian, you provide the legally operative consent for your child's data under laws like COPPA and GDPR (see the compliance section below). The in-app consent gate exists because we believe the child's informed awareness matters too — ethically, and for how well family safety tools actually work.
Who can see your family's data
In short: Guardians in your own family group. That's the whole list — no advertisers, no data brokers, no 'partners'.
Location and screen-time data for a child is visible to the guardians (parent and invited partners) of that child's own family group, and to the child themselves for their own data. Access is enforced server-side on every request — a child account cannot read another family member's data, and no account can reach outside its family.
We do not sell personal data. We do not share it with advertisers, data brokers, or analytics resellers. The mobile app contains zero third-party advertising or tracking SDKs — a claim you can verify by inspecting the app's network traffic, which we openly invite.
Platform administration (our operations staff) uses a separate, restricted portal that shows account and family metadata for support purposes; it is technically segregated from family data APIs and every admin credential is structurally invalid on family data routes.
Where data lives and for how long
In short: On your family's Safentora server, only as long as the account is part of the family. Remove the account and its data is deleted.
Location points and screen-time records are stored on your family's Safentora server and transmitted only over TLS-encrypted connections. Credentials are never stored in recoverable form: passwords are bcrypt-hashed, and session tokens, invite tokens, and pairing codes are stored as SHA-256 hashes.
Data is retained while the associated account remains part of the family. When an account is removed from the family, its associated location and screen-time data is deleted. Expired invites and used pairing codes are dead on use — they cannot be redeemed twice.
Your controls and rights
In short: See it, correct it, delete it, walk away — and the child can revoke device permissions in Android Settings at any time.
Guardians can view all collected family data in the dashboard, remove members (which deletes their associated data), and stop using the service at any time.
The monitored child always keeps device-level control: Accessibility (app blocking), Device admin (remote lock), Usage access (screen time), and Location can each be revoked in Android Settings at any time — we document exactly how, including the honest consequences, on the Permissions page.
To exercise any data right — access, correction, export, or deletion — email privacy@scientistshublabs.dev. We respond to verified requests within 30 days, and sooner in practice.
GDPR & COPPA, in human language
In short: Guardians provide verifiable parental consent (COPPA); processing rests on that consent and our legitimate family-safety purpose (GDPR). All standard rights apply.
COPPA (US): Safentora collects children's data only under the direction and consent of a parent or legal guardian, who creates the family, pairs the device, and controls what is monitored. We collect the minimum needed for the safety features, never use children's data for advertising, and delete it when the guardian removes the account.
GDPR (EU/EEA): our lawful basis for processing a child's data is the consent of the holder of parental responsibility (Article 8), given when you pair the device; guardian account data is processed to perform the service contract. You have the rights of access, rectification, erasure, restriction, portability, and objection — all exercisable via the contact below, and you can lodge a complaint with your local supervisory authority.
Data-processing agreements and a subprocessor list will be published on the Trust Center as the hosting footprint is finalized ahead of general availability.
Changes and contact
In short: Material changes bump the version number and re-trigger the child's consent screen. Questions go to a human.
When this policy materially changes, we update the version number and the “last updated” date shown on this page, and the consent gate reappears on monitored devices before monitoring continues under the new terms.
Questions about this policy or your data? Contact ScientistsHub Labs at privacy@scientistshublabs.dev. A person, not a ticket bot, reads that inbox.