Privacy Policy

Effective: 2026-07-31 · Last updated: 2026-07-31

This Privacy Policy explains how KidsHalo ("KidsHalo", "we", "us", "our"), operated by Lakay Network, collects, uses, shares, retains, and protects information when you use our web dashboard at kidshalo.com, the KidsHalo — Family Safety parent app (Android and iOS), and the KidsHalo Child companion app (Android and iOS) — together, the "Service". It also describes your rights and how to request data deletion.

Single policy for all platforms: the same practices apply whether you use KidsHalo on the web, Google Play, or the Apple App Store.

1. Who is the data controller

KidsHalo (Lakay Network) is the data controller for parent account data. Parents acting through the Service are controllers for data they collect about their own minor children using KidsHalo; KidsHalo acts as their processor for child-device data and processes it only on documented parental instructions.

2. Data we collect

From parents (account holders)

  • Identifiers: full name, email address, Google or Apple sign-in identifier (if used), profile photo (optional). Apple's "Hide My Email" relay addresses are supported and stored as your account email.
  • Account & billing: subscription tier, RevenueCat / Stripe / Apple or Google in-app purchase identifiers, plan status and expiry. We do not store card numbers — payments are handled by Stripe, RevenueCat, Apple, and Google.
  • Family configuration: family name, co-parent invitations, rules, filters, geofences, retention preferences.
  • Push tokens: FCM (Android) or APNs (iOS) tokens so we can deliver alert, unblock-request, and chat notifications to you.
  • Support communications: messages you send us through the in-app contact form or email.

From a paired child device (Android or iOS companion)

  • Child profile: first name and optional birthdate, as entered by the parent.
  • Device: model, OS version, app version, language, battery percentage, last heartbeat timestamp, platform (android/ios), and push token (FCM or APNs).
  • App activity: installed app catalog (package/bundle name, label, category), foreground-app events with start/stop timestamps and durations, and screen-time totals against the budgets you set.
  • Location: GPS coordinates, accuracy, capture timestamp, and geofence enter/exit transitions — only while the parent has location features enabled.
  • Web/content events: requested domain and matched category for filtering decisions. DNS/content filtering is evaluated on-device; we receive only the blocked/allowed event, never your full browsing stream.
  • Text snippets for safety scanning: only short, redacted excerpts (from notifications or monitored social/messaging apps) that the on-device classifier flags as potentially concerning, submitted for AI risk evaluation. We do not collect full conversations.
  • Unblock requests and command results: requests the child submits, the responses you send, and acknowledgements from the device.
  • Family chat messages the child sends to their own family.

Generated by the Service

  • AI alert summaries and risk categorisations.
  • Audit logs of changes made by parents and co-parents.
  • Family chat messages exchanged between members of the same family.

What we never collect

  • Photos, videos, microphone audio, or camera frames from the child device.
  • Full message bodies, contact lists, call recordings, or keystrokes outside the specific risk-scan contexts you enable.
  • Data from any device that has not been paired with a code by a parent.
  • Information from advertising IDs (Android Advertising ID / Apple IDFA) — we do not run advertising and do not request App Tracking Transparency permission.

No tracking, no ads, no data sale

KidsHalo contains no advertising SDKs and performs no tracking as defined by Apple's App Tracking Transparency framework: we never link your data to third-party data for advertising or measurement, and we never share it with data brokers. We do not sell or "share" personal information as those terms are defined by the CCPA/CPRA.

2b. Sensitive permissions and why we need them

KidsHalo is a parental-control app. The companion app on the child's device requests only the permissions needed to enforce the rules the parent configures, and each is disclosed in-app before it is enabled.

Android (Google Play Families / parental control policy)

  • Accessibility Service — used solely to detect the currently foreground app for screen-time and app-block enforcement. It monitors window-state-change events only, canRetrieveWindowContent is disabled, and it does not read screen contents or act on the child's behalf.
  • Usage Access — screen-time reporting and budget enforcement.
  • Local VPN service — on-device DNS content filtering. Traffic is never routed through KidsHalo or third-party servers; only DNS lookups are compared to the parent's blocklist.
  • Device Administrator — prevents unauthorised removal of the companion app. It is never used to lock or wipe the phone.
  • Background location — location and geofence features, only when the parent enables them.
  • Notification access — reads notification text from monitored messaging/social apps solely for on-device safety classification.

iOS (Apple App Store / Kids & parental control guidelines)

  • Family Controls / Screen Time API — Apple-provided, on-device shielding of apps and websites. Apple's framework does not disclose which specific apps a child uses to us; enforcement happens locally under parental authorisation.
  • Location (While Using / Always) — location sharing and geofence alerts, only when the parent enables them.
  • Push notifications (APNs) — delivering rule updates, block/unblock commands, alerts, and family chat.
  • Network Extension / on-device content filter — DNS-level content filtering evaluated locally on the device.

Blocking and unblocking in KidsHalo applies to apps and websites through our block overlay or Apple's Screen Time shielding. KidsHalo never locks the device screen, never wipes the device, and never blocks emergency calling.

3. How we use data (purposes & legal bases)

  • Provide the Service — render dashboards, sync rules to the child device, generate alerts, deliver push notifications. Legal basis: performance of contract.
  • Safety scanning — process redacted snippets through Lovable AI Gateway to detect bullying, grooming, self-harm, and adult content. Legal basis: parental consent / legitimate interest in child safety.
  • Account & billing — manage subscriptions and prevent abuse. Legal basis: contract + legal obligation.
  • Security and abuse prevention — rate-limiting, integrity checks, fraud detection. Legal basis: legitimate interest.
  • Customer support — respond to your questions. Legal basis: legitimate interest.

We never use family data to train AI models, and we never sell or rent personal data.

4. Subprocessors & sharing

We share data only with vetted infrastructure providers acting on our instructions:

  • Supabase (Lovable Cloud) — database, authentication, storage. Hosted in the EU.
  • Cloudflare Workers — application hosting and edge runtime.
  • Lovable AI Gateway — AI inference for safety scans (no training on inputs).
  • Firebase Cloud Messaging (Google) — push notifications to Android devices.
  • Apple Push Notification service (APNs) — push notifications to iOS devices.
  • Stripe — web subscription payments.
  • RevenueCat — Android and iOS subscription entitlements.
  • Apple App Store / Google Play billing — in-app purchase processing and receipt validation.
  • Resend — transactional email delivery.

A current list lives at /legal/subprocessors. We do not sell or rent your data, and we never share it for advertising.

5. International transfers

Personal data may be processed in the European Union, the United Kingdom, and the United States. Where data leaves the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (2021/914) and the UK Addendum, with additional technical measures (encryption in transit and at rest).

6. Retention

Retention is configurable per family in Settings → Retention. Defaults:

CategoryDefault retention
Location pings30 days
App usage events90 days
Message-scan snippets30 days
Alerts365 days (or until dismissed)
Audit log2 years
Account & billing recordsDuration of the account + 7 years for tax/legal

When you delete a child or your family account, associated records are erased immediately (see Section 9).

7. Security

We protect data with TLS 1.2+ in transit, AES-256 at rest, Postgres Row Level Security on every table, short-lived device tokens, signed webhook verification, scoped service accounts, and continuous backend security scanning. Avatars are stored in a private bucket and served via short-lived signed URLs. Access is limited to engineers who need it for support or operations, under contractual confidentiality.

8. Children's privacy (COPPA / UK Children's Code / GDPR-K / Apple Kids guidelines)

KidsHalo is intended for use by parents and legal guardians to supervise their own minor children. We do not knowingly allow children to create their own KidsHalo accounts, and the companion app cannot be used to make purchases, view advertising, or share information with third parties. The Child companion app is installed by a parent and shows a persistent, plain-language notice on the child's device confirming that monitoring is active. We collect only what's necessary to deliver the parental controls the parent has configured. Verifiable parental consent is obtained through the parent's own authenticated account and the device-pairing code they generate. Parents may review, export, or delete a child's data at any time from Settings → Children or by emailing us.

We comply with Google Play's Families and parental-control policies and Apple's App Store Review Guidelines for kids and parental-control apps. If we learn that we hold data about a child without a parent's authorisation, we delete it.

9. Your rights & how to exercise them

Depending on where you live, you have the following rights:

  • Access & portability — download a JSON export of everything we hold for your family (Settings → Export).
  • Rectification — edit profile, family, and child fields directly in the app.
  • Erasure — delete a child, scope-delete categories (location/usage/messages/alerts), or delete your entire family account. See /data-deletion.
  • Restriction & objection — pause processing by disabling specific features or contacting us.
  • Withdraw consent — at any time, without affecting the lawfulness of prior processing.
  • Complain — lodge a complaint with your local supervisory authority (e.g. CNIL, ICO).

EU/UK residents have full GDPR rights. California residents have full CCPA/CPRA rights, including the right to know, delete, correct, and limit use of sensitive personal information. We honor Global Privacy Control signals.

10. Cookies & analytics

The web dashboard uses only first-party, strictly necessary cookies for authentication and session continuity. We do not use third-party advertising or cross-site tracking cookies. Our Android apps do not contain advertising SDKs.

11. Changes to this Policy

We will post material changes to this page and update the "Effective" date above. For significant changes affecting how we use your data, we will notify the account owner by email at least 14 days before they take effect.

12. Contact

Privacy questions, access/erasure requests, or supervisory complaints: privacy@kidshalo.com.

Postal: Lakay Network — KidsHalo Privacy, [postal address on request].

Need to delete your data?

Use the self-serve flow in your account, or request deletion without signing in.

Go to data deletion →