Children’s Privacy Notice
FMS processes data about children. This notice explains what, on whose authority, what a child can see about themselves, and how a parent takes it all back.
Last updated: August 8, 2026 · Version 1.0
Draft — company details not yet filled in
This document is not in force. It is published for review only: the operating entity’s details are still missing, and a contract without an identified counterparty binds nobody. Fill in the company environment variables to publish it.
Missing: legalName, entityForm, registrationNumber, registeredAddress, governingLawCountry, disputeForum
1. The principle we start from
A child under supervision is still a person with privacy rights. FMS is built so that a parent gets what they need to set limits, and the child can always see what is recorded about them. We collect the minimum that makes supervision work, and no more — see what we deliberately do not collect.
2. Children cannot sign themselves up
FMS is not directed to children as a service they choose. A child profile exists only because an adult account holder created it inside their own family account. There is no route by which a child can register independently, and we do not knowingly collect data from a child outside a family created by an adult.
If you believe a child has created an account as an adult, or that a child’s data reached us without parental authority, write to [email protected] and we will investigate and delete it.
3. Parental consent — how it is obtained
Before a child profile is created, the adult must hold an account of their own, which requires a verified email address, and must confirm the warranty in section 6 of the Terms: that they are the parent or legal guardian, that they may lawfully supervise the child and the device, and that they consent on the child’s behalf to the processing described here.
Setting up a child’s device requires physical access to that device and, on each platform, explicit acceptance of the system permission prompts. That combination — a verified adult account, an affirmative in-app declaration, and hands-on device setup — is the consent mechanism.
Where local law requires a stricter method of verifiable parental consent for a particular purpose, we do not carry out that purpose until the stricter method is met.
4. Age thresholds
The age at which a young person can consent for themselves, rather than through a parent, differs by country:
| Region | Threshold | What it means here |
|---|---|---|
| United States (COPPA) | Under 13 | Verifiable parental consent required before any collection |
| EU/EEA (GDPR Art. 8) | Between 13 and 16, set by each member state | Parental consent required below the national threshold |
| Spain (LOPDGDD) | Under 14 | Parental consent required below 14 |
| United Kingdom | Under 13 | Parental consent required below 13 |
| Elsewhere | Local law | We apply the higher of the local threshold and 13 |
Because supervision by its nature involves a parent configuring another person’s device, FMS relies on parental authority for every child profile, whatever the child’s age. Where a supervised person is above the local threshold, or is otherwise old enough that their own consent or their own notice is legally required, the adult undertakes in the Terms to have obtained or given it.
5. What we collect about a child
- The first name or nickname the parent typed, and an avatar chosen from a fixed set. We do not require a surname or a photograph.
- An age band or birth year, where the parent provides one, used to set sensible defaults.
- The devices assigned to the child, and their technical details.
- Which applications were used and for how long, aggregated per application per calendar day per device.
- Screen-time totals, and whether the device was in use during an interval.
- Enforcement events on that child’s devices.
- Tasks assigned to the child, what they submitted, and their star and unit balances.
We do not collect a child’s email address unless the parent chooses to give the child their own sign-in, and we never require one.
6. No advertising, no profiling, no sharing with anyone else
- No advertising of any kind is shown to a child in FMS.
- No third-party advertising SDK and no third-party analytics SDK operates in the child experience.
- No advertising identifier is collected or transmitted.
- A child’s data is never used to build a marketing profile, is never sold and is never shared with a data broker.
- There is no public profile, no discovery by strangers, no child-to-child messaging and no user-generated content visible outside the family.
7. What the child can see about themselves
A child using FMS can see their own screen-time summary, their own task list, and their own star history including why each star was granted. The device shows that it is supervised.
We ask parents to tell the child, in language the child can follow, that the device is supervised and what is recorded. It is both the right thing to do and, in most jurisdictions, a transparency requirement rather than a courtesy.
8. What a parent can do at any time
- Review everything held about their child, in the app or by request.
- Correct a child’s profile details.
- Export the child’s data in a machine-readable format.
- Delete the child’s profile, which erases that child’s usage history, tasks and balances and releases their devices, while the rest of the family account continues.
- Withdraw consent entirely, by deleting the child profile or the family account. Supervision stops when consent is withdrawn — the two cannot be separated, because the processing *is* the supervision.
Deletion routes are described on the account deletion page. A child cannot delete their own profile or the family account: giving a supervised child a one-tap exit from supervision would defeat the purpose of the product.
9. Schools and organisations
FMS is sold to families for use in a household. We do not currently offer it to schools, care institutions or other organisations supervising children who are not their own, and the Terms do not permit that use. If you need it in an institutional setting, write to [email protected] — that requires a different agreement and a different legal basis than a parent’s consent.
10. Questions about a child’s data
Write to [email protected]. We answer requests about a child’s data on the same 30-day timetable as any other data right, and we verify that the request comes from the adult who holds the family account before we act on it.