FMS

Privacy Policy

What personal data FMS collects, why, how long it is kept, who else sees it and what you can demand of us. Section 4 lists what we deliberately do not collect.

Last updated: August 8, 2026 · Version 1.0

Draft — company details not yet filled in

This document is not in force. It is published for review only: the operating entity’s details are still missing, and a contract without an identified counterparty binds nobody. Fill in the company environment variables to publish it.

Missing: legalName, entityForm, registrationNumber, registeredAddress, governingLawCountry, disputeForum

1. Who is responsible for your data

The controller of the personal data described here is [[LEGAL NAME]] ([[ENTITY FORM AND JURISDICTION]]), registration number [[REGISTRATION NUMBER]], [[REGISTERED ADDRESS]].

Privacy contact
[email protected]
Data protection contact
[email protected]
EU/UK representative (Art. 27 GDPR)
[[EU REPRESENTATIVE]]

2. Who this policy covers

This policy covers the adult account holder, every child profile in a family account, and every device enrolled in that family — on Android, Windows, macOS and the web.

Data about a child is described here and in more detail in the Children’s Privacy Notice, which also explains the parental consent that must exist before a child profile is created.

3. What we collect

CategoryExamplesWhose
Account dataEmail address, password hash, display name, family role, avatar choice, parent PIN hash, Google account identifier if you sign in with GoogleAdult
Child profile dataFirst name or nickname the parent enters, avatar choice, age band or birth year where provided, family roleChild
Device dataDevice identifier we generate, manufacturer, model, device type, OS name and version, app version and build, battery level and charging stateBoth
Supervision configurationScreen-time limits, allowed and restricted application lists, quiet hours, enforcement tier, permission stateBoth
Usage dataWhich applications were used and for how long, aggregated per application per calendar day per device; screen-time totals; whether a media session or user input occurred in an intervalChild
Enforcement eventsRestriction applied or lifted, PIN unlock used, protection disabled, home launcher changed, device stopped reportingBoth
Task and reward dataTask titles and descriptions, completion notes, approval or rejection with comment, star and unit balances and their historyBoth
Technical and diagnostic dataIP address, timestamps, request and error logs, crash diagnostics, push notification tokens, session and refresh tokensBoth
Payment dataPlan, status, renewal date, and the transaction identifier from the payment provider or app store. We never receive or store your full card number.Adult
Support correspondenceWhat you write to us and our repliesAdult

4. What we deliberately do not collect

A parental control app could technically collect far more than this. These are commitments, not omissions:

  • No message content. We do not read, store or transmit SMS, chat messages, email or social media content.
  • No call content. We do not record or transcribe calls. We do not collect call logs.
  • No keystrokes. We do not run a keylogger. Where the product records that input activity occurred, it records only *that* it occurred in a time interval — never what was typed.
  • No screenshots or screen recording of the child’s device.
  • No location data. Location tracking and geofencing are not part of the product.
  • No browsing history content, contacts, photos, files or microphone or camera capture.
  • No advertising identifiers, no third-party advertising SDKs, and no third-party analytics SDKs in the child experience.
  • No covert operation. A supervised device shows that it is supervised.

5. Why we process it, and our legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Create and operate your account, authenticate youAccount data, technical dataPerformance of a contract (Art. 6(1)(b))
Apply the supervision rules you configuredDevice data, supervision configuration, usage dataPerformance of a contract (Art. 6(1)(b)); for a child’s data, parental consent (Art. 6(1)(a) with Art. 8)
Show you usage reports and the child their own recordUsage data, enforcement eventsPerformance of a contract; parental consent for a child
Alert you when protection is disabled or a device stops reportingEnforcement events, device data, push tokensPerformance of a contract
Run tasks and rewardsTask and reward dataPerformance of a contract
Take payment and keep accounting recordsPayment dataPerformance of a contract; legal obligation (Art. 6(1)(c))
Keep the service secure, prevent abuse and fraudTechnical data, enforcement eventsLegitimate interests (Art. 6(1)(f)) — our interest in a service that is not abused, balanced against your privacy
Diagnose faults and improve reliabilityDiagnostic data, crash reportsLegitimate interests (Art. 6(1)(f))
Answer your support requestsSupport correspondence, account dataPerformance of a contract
Comply with law and respond to valid legal requestsWhatever the request lawfully requiresLegal obligation (Art. 6(1)(c))

We do not use your data or your child’s data for profiling, behavioural advertising or automated decisions that produce legal effects for you.

6. Children’s data

A child profile is created by an adult who warrants they hold parental authority. That adult’s consent is the basis on which we process the child’s data. Full detail, including age thresholds by country and how to withdraw consent, is in the Children’s Privacy Notice.

We do not knowingly allow a child to create an independent account. If we learn that a child registered as an adult account holder, we will delete that account.

7. Who else sees the data

We do not sell personal data. We do not share it with data brokers. We do not disclose it for anyone else’s advertising. Under the CCPA/CPRA we neither "sell" nor "share" personal information as those terms are defined.

Inside a family account, data is visible as follows:

  • The adult account holder sees the supervision configuration, usage reports, enforcement events and task history for the children in their family.
  • A child sees their own usage summary and their own star and unit history. Supervision a child cannot inspect is surveillance, so this visibility is deliberate.
  • A child does not see other children’s data beyond what the family shares by design, such as a shared task board.

Outside the family, we use a small number of processors that act only on our instructions and under a written data processing agreement:

ProcessorWhat it doesData it touches
Cloud hosting and infrastructure providerRuns the servers and databasesAll stored data
Google (Firebase Cloud Messaging)Delivers push notifications to Android devicesPush token, notification title and body
Google (Sign-In), where you choose itAuthenticates youEmail address, account identifier
Transactional email providerSends account and security emailsEmail address, message content
Payment provider or app store, once paid plans launchTakes payment and handles refundsPayment and subscription data
Error and crash diagnosticsReports faults so we can fix themDiagnostic data, device data

We also disclose data where legally required — to a court, regulator or law enforcement acting under valid authority — and in connection with a merger or acquisition, in which case the acquirer is bound by a policy no less protective than this one and you will be notified before your data is transferred.

The current list of processors is available on request from [email protected].

8. International transfers

Data may be processed outside your country, including outside the European Economic Area. Where it is, we rely on an adequacy decision where one exists, and otherwise on the European Commission’s Standard Contractual Clauses together with a transfer risk assessment and technical measures such as encryption in transit and at rest. You may request a copy of the safeguards from [email protected].

9. How long we keep it

DataRetention
Account and child profile dataWhile the account is active; deleted within 30 days of account deletion
Supervision configurationWhile the device is managed; deleted with the device or the account
Detailed daily usage dataRolling 13 months, then deleted
Enforcement events and alertsRolling 13 months
Task and reward historyWhile the account is active; deleted with the account
Push and session tokensUntil the device is removed, you sign out, or the token expires
Server and security logsUp to 90 days
Crash diagnosticsUp to 12 months
Support correspondenceUp to 24 months after the case is closed
Invoices and accounting recordsAs required by applicable tax law, typically 5–10 years, used for nothing else
BackupsRolling 35 days, after which deleted data cycles out on its own

Deletion means erasure from live systems within 30 days, and expiry from backups within the backup window above. Where full erasure is not technically possible, we irreversibly anonymise instead.

10. Your rights

Depending on where you live, you have some or all of the following rights. Under the GDPR you have all of them:

  • Access — a copy of the personal data we hold about you and your children.
  • Rectification — correction of data that is wrong or incomplete.
  • Erasure — deletion, which you can also do yourself from the account deletion page.
  • Restriction — pause processing while a dispute about accuracy or lawfulness is resolved.
  • Portability — a machine-readable export of the data you provided.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — withdraw parental consent for a child’s data at any time. Supervision then stops for that child, because the processing it depends on is what you would be withdrawing.
  • Complain — lodge a complaint with your data protection authority. In the EU that is the authority where you live or work; you do not need to contact us first, though we would rather you did.
  • Non-discrimination — where the CCPA/CPRA applies, we will not degrade your service for exercising a privacy right.

Write to [email protected] to exercise a right. We verify that the request comes from the account holder, then respond within 30 days, extendable by a further 60 days for a genuinely complex request, in which case we will tell you why within the first 30. Exercising a right is free unless a request is manifestly excessive or repetitive.

11. How we protect it

  • Encryption in transit (TLS) for every connection between apps, agents and our servers, and encryption at rest for stored data.
  • Passwords and parent PINs stored only as salted one-way hashes; we cannot read your PIN and cannot recover it for you.
  • Access to production data limited to the staff who need it, logged and reviewed.
  • Short-lived access tokens with separate refresh tokens, revocable per device.
  • Regular dependency and vulnerability review and least-privilege service accounts.

No system is perfectly secure. If a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk to you is high.

12. Cookies and this website

This website sets only the cookies it needs to work, including remembering the language you chose. Details are in the Cookie Notice.

13. Changes to this policy

We will update this policy as the product changes. For a change that materially affects how we use your data or your child’s data, we will notify you by email or in the app before it takes effect, and where the law requires it we will ask for your consent again rather than assuming it.

Privacy Policy | FMS