Privacy Policy
What personal data FMS collects, why, how long it is kept, who else sees it and what you can demand of us. Section 4 lists what we deliberately do not collect.
Last updated: August 8, 2026 · Version 1.0
Draft — company details not yet filled in
This document is not in force. It is published for review only: the operating entity’s details are still missing, and a contract without an identified counterparty binds nobody. Fill in the company environment variables to publish it.
Missing: legalName, entityForm, registrationNumber, registeredAddress, governingLawCountry, disputeForum
1. Who is responsible for your data
The controller of the personal data described here is [[LEGAL NAME]] ([[ENTITY FORM AND JURISDICTION]]), registration number [[REGISTRATION NUMBER]], [[REGISTERED ADDRESS]].
- Privacy contact
- [email protected]
- Data protection contact
- [email protected]
- EU/UK representative (Art. 27 GDPR)
- [[EU REPRESENTATIVE]]
2. Who this policy covers
This policy covers the adult account holder, every child profile in a family account, and every device enrolled in that family — on Android, Windows, macOS and the web.
Data about a child is described here and in more detail in the Children’s Privacy Notice, which also explains the parental consent that must exist before a child profile is created.
3. What we collect
| Category | Examples | Whose |
|---|---|---|
| Account data | Email address, password hash, display name, family role, avatar choice, parent PIN hash, Google account identifier if you sign in with Google | Adult |
| Child profile data | First name or nickname the parent enters, avatar choice, age band or birth year where provided, family role | Child |
| Device data | Device identifier we generate, manufacturer, model, device type, OS name and version, app version and build, battery level and charging state | Both |
| Supervision configuration | Screen-time limits, allowed and restricted application lists, quiet hours, enforcement tier, permission state | Both |
| Usage data | Which applications were used and for how long, aggregated per application per calendar day per device; screen-time totals; whether a media session or user input occurred in an interval | Child |
| Enforcement events | Restriction applied or lifted, PIN unlock used, protection disabled, home launcher changed, device stopped reporting | Both |
| Task and reward data | Task titles and descriptions, completion notes, approval or rejection with comment, star and unit balances and their history | Both |
| Technical and diagnostic data | IP address, timestamps, request and error logs, crash diagnostics, push notification tokens, session and refresh tokens | Both |
| Payment data | Plan, status, renewal date, and the transaction identifier from the payment provider or app store. We never receive or store your full card number. | Adult |
| Support correspondence | What you write to us and our replies | Adult |
4. What we deliberately do not collect
A parental control app could technically collect far more than this. These are commitments, not omissions:
- No message content. We do not read, store or transmit SMS, chat messages, email or social media content.
- No call content. We do not record or transcribe calls. We do not collect call logs.
- No keystrokes. We do not run a keylogger. Where the product records that input activity occurred, it records only *that* it occurred in a time interval — never what was typed.
- No screenshots or screen recording of the child’s device.
- No location data. Location tracking and geofencing are not part of the product.
- No browsing history content, contacts, photos, files or microphone or camera capture.
- No advertising identifiers, no third-party advertising SDKs, and no third-party analytics SDKs in the child experience.
- No covert operation. A supervised device shows that it is supervised.
5. Why we process it, and our legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and operate your account, authenticate you | Account data, technical data | Performance of a contract (Art. 6(1)(b)) |
| Apply the supervision rules you configured | Device data, supervision configuration, usage data | Performance of a contract (Art. 6(1)(b)); for a child’s data, parental consent (Art. 6(1)(a) with Art. 8) |
| Show you usage reports and the child their own record | Usage data, enforcement events | Performance of a contract; parental consent for a child |
| Alert you when protection is disabled or a device stops reporting | Enforcement events, device data, push tokens | Performance of a contract |
| Run tasks and rewards | Task and reward data | Performance of a contract |
| Take payment and keep accounting records | Payment data | Performance of a contract; legal obligation (Art. 6(1)(c)) |
| Keep the service secure, prevent abuse and fraud | Technical data, enforcement events | Legitimate interests (Art. 6(1)(f)) — our interest in a service that is not abused, balanced against your privacy |
| Diagnose faults and improve reliability | Diagnostic data, crash reports | Legitimate interests (Art. 6(1)(f)) |
| Answer your support requests | Support correspondence, account data | Performance of a contract |
| Comply with law and respond to valid legal requests | Whatever the request lawfully requires | Legal obligation (Art. 6(1)(c)) |
We do not use your data or your child’s data for profiling, behavioural advertising or automated decisions that produce legal effects for you.
6. Children’s data
A child profile is created by an adult who warrants they hold parental authority. That adult’s consent is the basis on which we process the child’s data. Full detail, including age thresholds by country and how to withdraw consent, is in the Children’s Privacy Notice.
We do not knowingly allow a child to create an independent account. If we learn that a child registered as an adult account holder, we will delete that account.
8. International transfers
Data may be processed outside your country, including outside the European Economic Area. Where it is, we rely on an adequacy decision where one exists, and otherwise on the European Commission’s Standard Contractual Clauses together with a transfer risk assessment and technical measures such as encryption in transit and at rest. You may request a copy of the safeguards from [email protected].
9. How long we keep it
| Data | Retention |
|---|---|
| Account and child profile data | While the account is active; deleted within 30 days of account deletion |
| Supervision configuration | While the device is managed; deleted with the device or the account |
| Detailed daily usage data | Rolling 13 months, then deleted |
| Enforcement events and alerts | Rolling 13 months |
| Task and reward history | While the account is active; deleted with the account |
| Push and session tokens | Until the device is removed, you sign out, or the token expires |
| Server and security logs | Up to 90 days |
| Crash diagnostics | Up to 12 months |
| Support correspondence | Up to 24 months after the case is closed |
| Invoices and accounting records | As required by applicable tax law, typically 5–10 years, used for nothing else |
| Backups | Rolling 35 days, after which deleted data cycles out on its own |
Deletion means erasure from live systems within 30 days, and expiry from backups within the backup window above. Where full erasure is not technically possible, we irreversibly anonymise instead.
10. Your rights
Depending on where you live, you have some or all of the following rights. Under the GDPR you have all of them:
- Access — a copy of the personal data we hold about you and your children.
- Rectification — correction of data that is wrong or incomplete.
- Erasure — deletion, which you can also do yourself from the account deletion page.
- Restriction — pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability — a machine-readable export of the data you provided.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — withdraw parental consent for a child’s data at any time. Supervision then stops for that child, because the processing it depends on is what you would be withdrawing.
- Complain — lodge a complaint with your data protection authority. In the EU that is the authority where you live or work; you do not need to contact us first, though we would rather you did.
- Non-discrimination — where the CCPA/CPRA applies, we will not degrade your service for exercising a privacy right.
Write to [email protected] to exercise a right. We verify that the request comes from the account holder, then respond within 30 days, extendable by a further 60 days for a genuinely complex request, in which case we will tell you why within the first 30. Exercising a right is free unless a request is manifestly excessive or repetitive.
11. How we protect it
- Encryption in transit (TLS) for every connection between apps, agents and our servers, and encryption at rest for stored data.
- Passwords and parent PINs stored only as salted one-way hashes; we cannot read your PIN and cannot recover it for you.
- Access to production data limited to the staff who need it, logged and reviewed.
- Short-lived access tokens with separate refresh tokens, revocable per device.
- Regular dependency and vulnerability review and least-privilege service accounts.
No system is perfectly secure. If a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk to you is high.
13. Changes to this policy
We will update this policy as the product changes. For a change that materially affects how we use your data or your child’s data, we will notify you by email or in the app before it takes effect, and where the law requires it we will ask for your consent again rather than assuming it.