Privacy Policy
Last updated: July 14, 2026
SmartProtect helps parents supervise their children’s devices. We take the privacy of your family — and especially your children — seriously, and we collect only what we need to provide the service.
1. Who we are
SmartProtect Technologies Inc. (“SmartProtect”, “we”, “us”) provides a parental control and screen-time management service operated by a parent or legal guardian (“you”) to supervise the devices of children in their care. This policy explains what we collect, why, and the choices you have. Questions? Email privacy@smartprotect.com.
2. Information we collect
We collect only what is needed to run the service:
- Parent account data — name, email, and authentication details (via email/password or Google sign-in).
- Child profile data — the name or nickname you enter for each child and the devices you pair to them.
- Device & usage data — app and website usage durations, categories, blocked-attempt events, and limited device telemetry reported by the SmartProtect agent you install, so you can review activity from your dashboard.
- Billing data — subscription status and customer identifiers. Card details are processed directly by Stripe; we never see or store full card numbers.
- First-party product analytics — allowlisted funnel events such as a marketing-page view, signup attempt, device pairing, or subscription activation; a random per-tab session identifier; page path without query parameters; language; broad campaign source; plan; and device platform when relevant. We do not store IP addresses, full referrer URLs, advertising IDs, child identifiers, message content, or location in this analytics dataset.
3. Children’s privacy (COPPA & GDPR-K)
SmartProtect is a tool for parents and guardians. We do not knowingly allow children to create accounts or contract with us directly. Data about a child is collected at the direction of, and under the verifiable consent of, the parent or guardian who controls the account, consistent with the U.S. Children’s Online Privacy Protection Act (COPPA) and Article 8 of the EU/UK GDPR.
We collect only the data necessary to deliver the supervision features you enable, we do not build advertising profiles of children, and we do not sell children’s data. A parent can review, export, or delete a child’s data at any time from the dashboard or by contacting us.
4. How we use information
- To provide the dashboard, enforce the rules and limits you configure, and deliver alerts.
- To authenticate you and keep your account secure.
- To process subscriptions and prevent fraud or abuse.
- To provide support and to maintain, debug, and improve the service.
5. AI features & automated processing
Some features — such as the optional AI Co-Parenting Coach and activity summaries — use a large language model (LLM) to generate guidance and insights from the usage data you choose to share within the dashboard.
- This processing runs on Cloudflare Workers AI, our infrastructure provider, and is not sent to any third-party AI vendor.
- Your family’s data is never used to train the underlying models. Prompts are used only to produce your response and are not retained to improve any model.
- These features are assistive only. They do not make automated decisions that produce legal or similarly significant effects about you or your child, and you can choose not to use them.
7. Legal bases (EEA/UK)
Where the GDPR applies, we process data to perform our contract with you (running the service), on the basis of your consent (which you may withdraw), to comply with legal obligations, and for our legitimate interests in securing and improving the service.
8. How we share information
We do not sell your data or share it for advertising. We share data only with service providers that process it on our behalf under contract:
- Cloudflare — hosting, database, and storage.
- Stripe — payment processing.
- OneSignal — push notification delivery.
- Google — optional sign-in.
We may disclose data if required by law, to protect our rights, or in connection with a merger or acquisition (subject to this policy).
9. Data retention
We keep account data while your account is active. Usage and activity data are retained on a rolling basis to power reports and trends, then deleted or aggregated. First-party funnel events are deleted after 90 days. When you delete a child, a device, or your account, the associated personal data is removed from active systems and purged from backups on our normal backup cycle.
10. Your rights and choices
You can access, correct, export, or delete your family’s data from your account, or by emailing privacy@smartprotect.com. Depending on your location you may have rights to access, rectification, erasure, portability, restriction, and to object to processing, as well as the right to lodge a complaint with your local data protection authority.
11. Security
We encrypt data in transit and at rest, scope access to a child’s data to the parents in that family, and authenticate child-device agents with per-device tokens. No system is perfectly secure, but we work to protect your information and will notify you of a breach as required by law.
12. International transfers
SmartProtect runs on globally distributed infrastructure, so your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
13. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app or by email, and the “Last updated” date above will change.
14. Contact us
SmartProtect Technologies Inc. — privacy@smartprotect.com.