Privacy Policy
Last updated: June 20, 2026
Effective date: June 20, 2026 · Applies to: SpyGuard Android app, FamilyGuard iOS apps (child & parent), web dashboard, and spyguard.in website.
1. Overview & Scope
SpyGuard Technologies Pvt. Ltd. (“SpyGuard”, “we”, “us”) operates a parental monitoring platform consisting of:
- FamilyGuard Child (iOS) — installed on the child's iPhone/iPad
- SpyGuard (Android) — installed on the child's Android device
- FamilyGuard Parent (iOS) — the parent's monitoring dashboard
- SpyGuard Web Dashboard — browser-based parent dashboard
- spyguard.in — marketing website
This policy explains what personal data we collect from each surface, why we collect it, how long we keep it, who we share it with, and how you can exercise your rights. This policy is designed to comply with the Information Technology Act 2000, India's Digital Personal Data Protection Act 2023 (DPDPA), the EU General Data Protection Regulation (GDPR), the US Children's Online Privacy Protection Act (COPPA), and Apple App Store Review Guidelines 5.1.1 and 5.1.2.
2. Information We Collect
2A. Parent Account Data
- Account credentials: Name, email address, hashed password
- Contact: Phone number (optional, used for 2FA only)
- Session tokens: JWT access token and refresh token stored in iOS Keychain / browser memory — never on our servers in plaintext
- Payment information: Billing address and transaction IDs — card details are handled exclusively by Razorpay; we store only the Razorpay order/payment IDs and subscription status
- Consent records: Timestamp and IP address when you accepted these Terms, this Privacy Policy, and gave parental consent — required by DPDPA and COPPA
- Push notification token (APNs/FCM): Device token used to deliver alerts to your parent device — not linked to any third-party advertising
- Geofence configurations: Names and GPS coordinates of safe zones you define
2B. Child Device Data (collected from the child's device with your parental consent)
- Precise GPS location: Latitude, longitude, and accuracy radius — uploaded when the device moves more than 100 m (iOS) or on a configurable interval (Android)
- App usage activity: Which apps are open, for how long — on iOS these are DeviceActivity opaque identifiers (app names are not transmitted to our servers; the OS protects them); on Android, app package names and session durations are transmitted
- Screen time summaries: Total daily usage in minutes per app category
- Battery level: Transmitted with each heartbeat so you can see the device's charge status in the parent dashboard
- Device platform & online status: “ios” or “android”, last heartbeat timestamp
- Device pairing token: A cryptographic identifier that authenticates the child's device to our API — stored in the iOS Keychain and Android Keystore; never shared externally
- APNs / FCM push token: Used to deliver parental control update notifications to the child device
- Call logs (Android only): Caller number (not contact name), call type, and duration — not collected on iOS
- SMS metadata (Android only): Sender number and timestamp — message content is not stored on our servers
- Social media activity metadata (Android only): Captured via Accessibility Service — limited to message counts and contact identifiers, not full message content
3. How We Use Your Information
- Authenticate parent and child devices and protect your account
- Display the child's location, app usage, and screen time in the parent dashboard
- Trigger geofence alerts when the child enters or leaves a defined zone
- Enforce screen time limits, app blocks, and downtime schedules set by the parent
- Send push notifications and email alerts to the parent account
- Process subscription payments and issue receipts
- Improve app performance and diagnose technical issues using aggregated, anonymised analytics
- Comply with legal obligations and respond to lawful government requests
We do not use child device data for advertising, profiling, or any purpose other than providing the parental monitoring service.
4. Data Retention
| Data type | Basic plan | Premium / Ultimate |
|---|---|---|
| Location history | 7 days | 30 days |
| App usage records | 7 days | 30 days |
| Call & SMS logs (Android) | 7 days | 30 days |
| Screen time summaries | 30 days | 90 days |
| Alert history | 30 days | 90 days |
| Account & consent records | Until deletion + 90 days | Until deletion + 90 days |
| Billing records | 8 years (GST Act) | 8 years (GST Act) |
| Aggregated analytics | 2 years (anonymised) | 2 years (anonymised) |
Data older than the applicable retention window is automatically purged by our cleanup worker. Account deletion requests are fulfilled within 30 days (see Section 7).
5. Data Sharing & Sub-Processors
We share data with the following sub-processors. We do not sell or rent personal data to any third party.
| Sub-processor | Purpose | Data shared | Location |
|---|---|---|---|
| Amazon Web Services (AWS RDS) | PostgreSQL database hosting | All account and monitoring data | ap-south-1 (Mumbai) |
| Amazon ElastiCache (Redis) | Session tokens, rate limiting, 2FA codes | Temporary session data only | ap-south-1 (Mumbai) |
| Amazon S3 | Screenshot storage (Android remote screenshot command) | Screenshot images linked to device ID | ap-south-1 (Mumbai) |
| Amazon SES | Transactional email (account verification, alerts) | Parent email address + name | ap-south-1 (Mumbai) |
| Amazon SNS | Push notifications via APNs (iOS) and FCM (Android) | Device push token only | ap-south-1 (Mumbai) |
| Apple APNs | Push notifications to iOS devices | APNs device token only | Apple servers (US) |
| Firebase Cloud Messaging (FCM) | Push notifications to Android devices | FCM registration token only | Google servers (US) |
| Razorpay | Payment processing and subscription billing | Parent name, email, billing address, order/payment IDs | India |
| Mapbox (web dashboard only) | Map rendering for location view | GPS coordinates (no personal identifiers) | US |
Legal disclosures: We may disclose data to Indian law enforcement or courts when required by a valid legal order. We will notify you of such requests to the extent permitted by law.
6. Data Security
- In transit: TLS 1.2+ for all API calls; certificate pinning in mobile apps
- At rest: AES-256 encryption for database volumes (AWS RDS); S3 server-side encryption (AES-256)
- Credentials: Passwords hashed with bcrypt (12 rounds); JWT secrets stored in environment variables, never in code
- iOS Keychain: Device token, JWT tokens, and parent PIN stored with
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly— excluded from unencrypted iCloud backups - Android Keystore: Device token encrypted with AES-GCM via Android Keystore hardware-backed key
- 2FA: Available for all parent accounts via TOTP app, SMS, or email
- Session management: Refresh tokens are rotated on every use and hashed before storage
- Rate limiting: Registration, login, and password reset endpoints are rate-limited via Redis
7. Your Rights & Data Deletion
Under the DPDPA 2023, GDPR, and Indian consumer law, you have the right to:
- Access: Request a copy of all personal data we hold about you and your child's device
- Correction: Update inaccurate or incomplete account information via the dashboard
- Deletion (Right to Erasure): Request permanent deletion of your account and all associated data — see below
- Data portability: Request a machine-readable export of your data (JSON format)
- Withdraw consent: Uninstall the child device app and delete your parent account at any time
- Restriction: Request that we restrict processing while a complaint is pending
- Lodge a complaint: With the Data Protection Board of India or your local supervisory authority
How to Delete Your Account & Data
You can request deletion in three ways:
- In-app: FamilyGuard Parent iOS app → Settings → Delete My Account & Data
- Web dashboard: Settings → Account → Delete Account
- Email: Send a request to privacy@spyguard.in from your registered email address
Grace period: Upon request, your account is immediately deactivated and a 30-day deletion window begins. During this time all data remains accessible to you via the dashboard. After 30 days, all personal data is permanently and irreversibly wiped from our systems and all sub-processor caches. Billing records required by Indian tax law (8 years) are the sole exception.
Response time: We process deletion requests within 30 days. You will receive an email confirmation when your data has been fully erased.
8. Children's Privacy & COPPA Compliance
SpyGuard is a tool for parents and legal guardians. The child device apps (FamilyGuard Child for iOS, SpyGuard for Android) collect personal data from child devices, but the data is provided to the parent account holder, not to the child.
COPPA Compliance (US users)
- The parent app requires users to declare they are 18 years of age or older before creating an account
- Verifiable parental consent is recorded with timestamp before any child data is collected — the parent explicitly accepts a parental consent declaration during onboarding
- We do not knowingly collect personal information from children under 13 for any purpose other than providing the monitoring service to the parent
- We do not share child data with any third party for advertising or profiling purposes
- Parents can review, export, or request deletion of all child data at any time (see Section 7)
- Child device data is transmitted over TLS and stored encrypted at rest
Child awareness (iOS — Apple guideline 1.3)
The FamilyGuard Child iOS app shows the child a plain-language disclosure screen before any permissions are requested. This screen lists every data type collected and links to this Privacy Policy. The child sees what is being monitored before the app becomes active. The child cannot be monitored silently or without their knowledge via the iOS app.
9. iOS App — Specific Disclosures
The following additional disclosures apply specifically to the iOS apps (FamilyGuard Child and FamilyGuard Parent):
FamilyGuard Child (installed on child's iPhone/iPad)
- Screen Time / FamilyControls: The app uses Apple's FamilyControls framework. The Screen Time passcode is never stored by SpyGuard — it remains with Apple's system. The parent must enter the Screen Time passcode on the child's device to authorise the app.
- App usage on iOS: App names and bundle identifiers are not transmitted to SpyGuard servers. Apple's DeviceActivity framework provides only opaque tokens; category-level usage summaries (e.g. “Social Networking: 45 min”) are the most granular data we store for iOS.
- Location: Requires “Always” location permission for background tracking. iOS will ask for “When In Use” permission first, then prompt for the upgrade to “Always”. The app uses significant-change monitoring (battery-efficient, ~500 m accuracy) by default. Location is uploaded only when the device moves more than 100 m and the reading is less than 30 seconds old.
- Background execution: The app uses BGProcessingTask (15-min minimum interval) and BGAppRefreshTask (10-min minimum interval) for background sync. Apple controls how often these tasks actually fire.
- Battery level: Collected via UIDevice and uploaded with each heartbeat so the parent can see device charge status.
- Push notifications: Requested after the user completes the privacy disclosure flow — never on cold launch.
- Parent PIN: If set, the parent PIN is stored in the iOS Keychain with
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnlyand is never transmitted to SpyGuard servers. - Required Reason APIs: The app uses
UserDefaults(App Group shared container — reason CA92.1),FileTimestamp(C617.1), andSystemBootTime(35F9.1) as declared in the app's PrivacyInfo.xcprivacy manifest. - No tracking:
NSPrivacyTrackingis declaredfalse. The app does not use App Tracking Transparency and does not participate in cross-app advertising.
FamilyGuard Parent (installed on parent's iPhone/iPad)
- Location: Only requested when setting up a geofence alert — used for map centering only, not stored.
- Push notifications: Used for child safety alerts (geofence breach, screen time limit reached, low battery, SOS). APNs token is stored on our server only for the purpose of delivering these alerts.
- Data collected by the parent app itself: Email address and device ID — both declared in the app's PrivacyInfo.xcprivacy manifest.
- No tracking:
NSPrivacyTrackingis declaredfalse.
10. Android App — Specific Disclosures
- Foreground service notification: Android law requires a persistent notification when a foreground service is active. The SpyGuard monitoring service shows a “Device protected by FamilyGuard” notification — it cannot be hidden. The child is always aware the app is running.
- Accessibility Service: Used to capture WhatsApp, Instagram, and Facebook message counts and contact identifiers. Full message content is not stored. This service is declared in the app manifest and requires explicit user grant in Android Settings.
- Calls & SMS: READ_CALL_LOG and READ_SMS permissions collect call metadata and SMS sender numbers. Message content is not stored on our servers.
- Remote commands: The parent can send Lock, Screenshot, or Factory Reset commands via the dashboard. Screenshot images are stored in our S3 bucket (ap-south-1) for up to 24 hours and then automatically deleted.
- Device admin: The Factory Reset command requires Device Administrator permission. The child must grant this explicitly. It cannot be granted remotely.
11. Consent & Legal Basis
Our legal basis for processing personal data:
- Contract performance: Processing parent account data to fulfil the subscription agreement
- Legitimate interests: Security, fraud prevention, service improvement
- Consent: Processing child device data — we rely on verifiable parental consent obtained during the parent onboarding flow. Consent is recorded with a timestamp and linked to the parent's account. You may withdraw consent at any time by deleting your account (Section 7).
- Legal obligation: Retaining billing records for 8 years under Indian tax law
12. Refund Policy
We offer a 7-day money-back guarantee for all new annual subscriptions.
- Contact support@spyguard.in within 7 days of first payment with your registered email and reason for refund
- Refunds are processed within 5–7 business days to the original payment method
- Not eligible: Monthly plans after billing cycle starts, requests after 7 days, partial-month usage, accounts terminated for Terms violations
13. Cookies & Tracking
The spyguard.in website uses strictly necessary cookies for session management. No third-party advertising cookies are used. Analytics are performed using aggregated, anonymised server logs — no third-party tracking scripts are loaded.
The iOS and Android apps do not use cookies. They do not participate in cross-app tracking. NSPrivacyTracking and NSPrivacyTrackingDomains are both empty in all iOS app manifests.
14. Changes to This Policy
We will notify you of material changes to this policy by email and in-app notification at least 30 days before the change takes effect. Minor changes (e.g. clarifications, adding sub-processors we already use) will be reflected here with an updated effective date. Continued use of the service after the effective date constitutes acceptance of the revised policy. If you object to a change, you may delete your account before the change takes effect.
15. Contact & Grievance
Data Protection Officer
privacy@spyguard.inAccount Deletion Requests
privacy@spyguard.inGeneral Support & Billing
support@spyguard.inSecurity Vulnerabilities
security@spyguard.inGrievance Redressal Officer
grievance@spyguard.inResponse within 48 hours as required by IT Rules 2021
Registered Address
SpyGuard Technologies Pvt. Ltd.
Koramangala, Bangalore
Karnataka 560034, India