Privacy

Paired Parent — Messaging Oversight & Monitoring System

Version 2 · 6 September 2026

The short version

Your child's messages, contacts, phone numbers, locations and browsing history are encrypted on their phone with keys that only your phones hold. We cannot read them. Neither can anyone who steals our servers, because what is stored there is encrypted to keys the servers do not have.

Three narrow things can travel to us, and each is described below: a problem report you send, a crash report your app sends automatically, and — only if you separately agree to it — your own judgements on messages the screening flagged.

What never reaches us

The child app and the parent app talk to each other through our server, but they seal everything before it leaves the phone. The server carries sealed packages between two phones and cannot open them. That covers:

This is not a promise about how carefully we behave. It is a property of the encryption: the keys are generated on the phones and never leave them.

What our sync server can see

Carrying sealed packages still means seeing some things about the delivery:

No readable message content, no contact names, no phone numbers. But a channel number, a push token, an internet address, a size and a time are still information about you, and we protect them as such rather than calling the list empty.

What the web filter can see, which is more

If web filtering is on, your child's phone asks our name server whether each site is allowed. That server therefore sees every domain the phone looks up, against a filter identity. We deliberately do not link that identity to your pairing anywhere in our data, so the filter side of the system does not know which family it belongs to.

We would rather say this plainly than claim more than we can deliver: a name server has to see the names it is asked about. There is no version of this where it does not.

Those lookups are kept for at most 24 hours on the server. Your browsing history is archived on your phone, for five days, and nowhere else.

The three things that can reach us

WhatWhen it is sentIs it linked to you?
A problem report When you write one and tap send. You can read the whole thing first. Yes — it names your pairing, so a fault can be diagnosed.
A crash report Automatically, on the next start after the app crashes. Yes, the same way.
Your judgement on a flagged message Only if you chose to share, on the sharing screen. No — see below.
A record of what you chose on that screen Every time you make or change that choice, including a refusal. Yes, deliberately.

Problem and crash reports never include your child's messages, contacts, phone numbers or location. They carry version numbers, settings, timings and diagnostic detail. All four are encrypted to a key whose private half has never been on a phone or on a server.

Sharing your judgements, if you choose to

The app asks once, the first time you judge a flagged message, and it defaults to sharing nothing. You can decline, share statistics only, or also share the text of messages you have personally looked at and judged. Phone numbers and email addresses are removed from that text before it is sent.

A shared judgement carries no name, no device, no pairing, no app version, and only the day it was made, not the time. Those fields do not exist in it, which is what makes it safe to pool.

That is de-identified, not anonymous, and we would rather tell you than reassure you. Stripping phone numbers and email addresses is automatic, and automatic is not the same as certain: a message can still point to somebody through a name, a place, a school, or a phrase only one person uses. We do not try to work out who a submission came from, and the design gives us nothing to work from — but choose the message-text option knowing that, rather than on a promise we cannot keep.

It is also why we may not be able to find a judgement you have already shared if you later ask us to delete it: nothing in it says it was yours. Removing one example also does not undo counts or a trained model it has already gone into. The consent screen says this in its own words before you choose.

You can change or withdraw the choice at any time in the app's settings. That stops all further sharing immediately.

The record of your consent

The record of what you chose, when, and the exact wording you agreed to is the one thing that is tied to your device, and it is kept. A consent that cannot be shown demonstrates nothing, and that record is what lets either of us say what was agreed.

It is kept even if you decline, and it shares no identifier with the pool of judgements, so your agreement can be shown without any of what you shared becoming traceable back to you.

It is not kept forever. It goes when what it covers goes, plus twelve months, and in no case later than three years from the day you chose — unless a specific legal claim needs it for longer.

How long things are kept

WhatWhereHow long
Your child's messagestheir phone only12 months (fixed — see below)
Alerts, with excerptsyour phone60 days, or 7 days after you judge one
Call log copyboth phones30 days
Locationsyour phonethe last 10
Browsing historyyour phone5 days
Sealed packages in transitsync serveran hour after the other phone reads them
Problem and crash reportssync server30 days
Shared judgementssync serverat most 24 months from when we receive it, sooner once it is no longer useful
Consent recordssync serveras long as any judgement they cover exists, plus 12 months — never beyond 3 years
Web filter lookupsname server24 hours

Deleting your data

The messages on your child's phone are a special case, and the honest answer is blunt. They are kept twelve months and then deleted automatically. You cannot shorten that period, and we cannot reach that archive to delete it for you — it is encrypted on a phone we have no access to, which is the same property that stops anyone else reading it. Ending supervision with Release hands the phone and its archive back to the person holding it; destroying the archive outright means a factory reset. Clearing the app's data and uninstalling it are deliberately blocked, because on this phone both would take the pairing and the keys with them.

If this policy changes

If a change would alter what is collected or shared, the app asks you to make the choice again, and sharing pauses until you answer — nothing new is shared under wording you have not seen. Your previous agreement covers the wording you actually agreed to, and nothing else.

Contact

Questions, or a request to delete what we hold: privacy@pairedparent.com.

Install page · Terms of use