ParentEase: Screen Time Controller App Privacy Policy
ParentEase: Screen Time Controller App Privacy Policy
Effective Date: Oct-09-2025
Thank you for using ParentEase: Screentime Controller (the "App"), developed by Exxand. This Privacy Policy explains how we collect, use, disclose, and protect your information and your child's information when you use the App. The App is designed to help users manage screen time through features such as setting schedules for Sleep Time and Study Time; device locking (except for incoming and outgoing calls); message-based unlock passwords (e.g., 20-30 word phrases like "screen_time-is_injurious-for_mental-Health"); parental controls for linking child accounts via email; remote schedule setting; viewing app usage statistics (in hours and minutes); and locking/unlocking specific apps on child devices.
We are committed to protecting your privacy and complying with applicable data protection laws worldwide, including but not limited to:
United States: Children's Online Privacy Protection Act (COPPA) for children under 13.
European Union/European Economic Area (EU/EEA): General Data Protection Regulation (GDPR), which applies to EU/EEA residents and requires lawful bases for processing personal data, enhanced user rights, and strict consent requirements for children (typically under 16, varying by member state).
California, USA: California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), providing rights similar to GDPR for California residents.
Other Jurisdictions: Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada; Lei Geral de Proteção de Dados (LGPD) in Brazil; and equivalent laws in other countries, such as the UK GDPR (post-Brexit UK equivalent) and Australia's Privacy Act. Where local laws are stricter, we comply with those requirements.
By using the App, you agree to this Privacy Policy. If you are a parent or guardian, you also consent to our collection and use of your child's information as described herein. If you do not agree, please do not use the App.
1. Information We Collect
We collect the following types of information to provide and improve the App's functionality:
A. Personal Information from Parents/Users
Account and Contact Details: Email address, username, password (hashed), and subscription details.
Usage Data: Schedules set (e.g., start/end times for Sleep, Study), app usage statistics (hours/minutes) for your own device, and preferences.
Payment Information: Processed via Google Play Billing (we do not store credit card details; handled by Google).
Device Information: Device type, OS version, IP address, and unique identifiers for authentication and syncing.
B. Information from Children's Devices
Usage Data: App usage statistics (hours/minutes), schedules enforced, lock/unlock events, and device status (e.g., locked except for calls).
Device Identifiers: Unique tokens or IDs for linking and remote control (e.g., for app-specific locking).
No Sensitive Data: We do not collect children's names, photos, locations, audio, or any other unnecessary personal information.
C. Automatically Collected Data
Analytics: App performance metrics, crash reports, and usage patterns (anonymized where possible) via tools like Firebase Analytics.
Cookies and Similar Technologies: For web-based elements (if any), we may use cookies for session management.
We minimize data collection to what is necessary for the App's features. For children under 13 (COPPA) or under 16 (GDPR in EU/EEA), we only collect data with verifiable parental consent.
2. How We Use Your Information
We use the collected information for the following purposes:
Provide App Features: Enforce schedules, lock devices, generate usage reports, and enable remote parental controls.
Improve the App: Analyze usage to fix bugs, enhance features, and optimize performance.
Billing and Subscriptions: Process payments for plans and manage accounts.
Communications: Send service-related emails (e.g., subscription reminders, policy updates) or, with consent, promotional updates.
Compliance and Security: Detect fraud, ensure data security, and comply with legal obligations.
Lawful Bases (GDPR and Similar Laws): Processing is based on consent (e.g., for child data), contract performance (e.g., providing App services), or legitimate interests (e.g., security). For special categories of data (if any), we rely on explicit consent.
We do not use data for targeted advertising, profiling, or automated decision-making that significantly affects users.
3. Sharing and Disclosure of Information
We do not sell, rent, or share personal information with third parties except:
Service Providers: With trusted vendors (e.g., Firebase for storage, Google Play for billing) under strict confidentiality agreements compliant with COPPA, GDPR, and other laws.
Legal Requirements: If required by law, subpoena, or to protect rights, safety, or property.
Business Transfers: In mergers, acquisitions, or asset sales, with notice to users.
Aggregated/Anonymous Data: For research or analytics, stripped of identifiers.
For international data transfers (e.g., from EU/EEA to non-adequate countries like the US), we use Standard Contractual Clauses (SCCs), Binding Corporate Rules, or other GDPR-approved mechanisms to ensure equivalent protection.
4. Data Security
We implement reasonable security measures to protect data:
Encryption: All data in transit (HTTPS/TLS 1.2+) and at rest (AES-256).
Access Controls: Role-based access, multi-factor authentication (MFA) for parent accounts, and secure tokens for child linking.
Credential Storage: Passwords are hashed (e.g., bcrypt); child credentials are unique, non-reversible tokens.
Vulnerability Management: Regular security audits, penetration testing, and updates.
Breach Notification: In case of a data breach, we notify affected users (and regulators under GDPR/CCPA) within required timelines (e.g., 72 hours under GDPR).
Despite these measures, no system is 100% secure. Users should use strong passwords and secure devices.
5. Verifiable Parental Consent
For children under 13 (COPPA) or under 16 (GDPR, varying by EU country):
Consent Process: Parents must provide verifiable consent before linking a child's device. Methods include:
Email Plus: Confirmation via email link with a secondary action.
Payment Verification: A small, refunded charge during subscription (e.g., when adding a second child).
Revocation: Parents can withdraw consent anytime, triggering data deletion.
6. Your Rights and Choices
You have the following rights, exercisable via app settings or by contacting us:
Access/Review: View your data or your child's data (e.g., usage stats).
Rectification: Correct inaccurate data.
Erasure ("Right to be Forgotten"): Delete data (COPPA/GDPR/CCPA), subject to legal obligations.
Portability: Receive data in a structured format (GDPR/CCPA).
Objection/Restriction: Object to processing based on legitimate interests or restrict it during disputes.
Opt-Out of Sales/Sharing: We do not sell data, but you can opt-out of any sharing (CCPA).
Do Not Sell My Personal Information: Link in app footer for CCPA compliance.
Automated Decisions: No such processing occurs.
Complaints: File with supervisory authorities (e.g., FTC for COPPA, national data protection authorities for GDPR).
Requests are processed within 30 days (GDPR) or 45 days (CCPA), free of charge unless excessive.
For children: Parents control all rights on behalf of the child.
7. Data Retention and Deletion
Retention: We retain data only as long as necessary (e.g., usage stats for 90 days; account data while active). Child data is deleted when the child turns 13/16 (as applicable) or upon revocation.
Deletion: Automatic for inactive accounts (after 12 months, with notice). Parents can delete via app (e.g., "Remove Child") or request. Data is securely overwritten.
8. Children's Privacy
The App is not directed at children under 13 without parental involvement. We comply with COPPA by obtaining verifiable consent, limiting collection, and providing parental controls. For EU/EEA children under 16, we apply GDPR's heightened protections.
9. International Users
If you are outside the US, your data may be transferred to and processed in the US or other countries. We ensure compliance with local laws:
EU/EEA/UK: GDPR/UK GDPR applies; we appoint an EU representative if required.
Canada/Brazil/Other: Equivalent protections under PIPEDA/LGPD.
Global: We adhere to the highest standards, including UN principles on privacy.
10. Changes to This Policy
We may update this Policy. Changes are posted here with the effective date. Material changes (e.g., new data uses) require consent or notice via email/in-app.
11. Contact Us
For questions, requests, or complaints:
Email: info@exxand.com
Address: 12 Lennox Road Walthamstow London E17 8NT
00447480063725
Message After Installing on Child's Device
Upon installation and login with parent-generated credentials on the child's device, display the following notice (as a pop-up or onboarding screen, requiring acknowledgment):
Welcome to Screen Time Controller on Your Child's Device
This App is installed under parental control. By proceeding, you acknowledge that:
Your parent/guardian has consented to the collection of your device data, including app usage (in hours/minutes), schedules, and lock events, to manage screen time.
Data is securely stored and used only for these purposes, in compliance with laws like COPPA (US), GDPR (Europe), and others worldwide.
You cannot change settings or unlock without parent approval or entering the message-based password (e.g., "screen_time-is_injurious-for_mental-Health").
For details, see the Privacy Policy in the App or ask your parent.