Legal
Privacy Policy
Last updated 25 July 2026
Who this covers
FamilyProtect is bought and configured by a parent or guardian (the "account owner") to protect devices they own or control and provide to their children. The account owner consents to this policy on behalf of their household.
Children do not have FamilyProtect accounts. There is no child login, no child-facing app to sign into, and no way for a child to create an account or submit information to us directly. Everything is set up and controlled by the account owner.
What we collect
To enforce the protections you turn on and to run your account, we collect:
- Device inventory & status: operating system, whether the protection agent is installed and running, and whether each protection you enabled is currently passing or failing.
- Web & DNS activity: the domains devices attempt to reach, so filtering can allow or block them. This is used to enforce and show filtering, not to build advertising profiles.
- Policy & configuration state: which protections are on, and the results of the checks that confirm they are working.
- Account information: the account owner's email and billing status. Billing is processed by Stripe and we never store card numbers.
- Signup referral: when you create an account, which page on our website you came from, so we know which of our guides are useful. That is a page address, not a profile, and we do not use cookies or any other storage on your device to work it out.
What we do not collect
We do not collect the contents of messages, keystrokes, screenshots, photos, microphone or camera data, precise location, or a child's personal social-media content. FamilyProtect enforces safety rules; it is not a covert monitoring tool.
Why we collect it
Solely to deliver the service you asked for: applying the filtering and protection settings you choose, showing you their status, and keeping your subscription active.
Under UK and EU GDPR our legal basis is performance of the contract between us (delivering the protection you subscribed to), and our legitimate interest in keeping the service secure and working. Where consent is the appropriate basis, the account owner gives it on behalf of the household and can withdraw it at any time by removing a device or closing the account.
What we never do
These are commitments, not preferences:
- We do not sell your data, or your child's, to anyone, for any purpose.
- We do not share personal information with third parties for their own marketing.
- We do not display targeted advertising in the product or use your data to target ads anywhere else.
- We do not allow third-party advertising trackers in the product or on this website.
- We do not track anyone across other apps, sites or services. The domains we see are used to apply your filtering rules and to show you what was blocked. They are never used to follow a person around the internet or shared with anyone who would.
- We do not build commercial profiles of parents or children, and we do not use the data for automated decisions that produce legal or similarly significant effects.
Who processes it for us
We use a small number of service providers, each of which handles only what it needs to:
- Cloudflare: hosting, the database and file storage that hold your account and device records, the DNS filtering layer that resolves and blocks requests from protected devices, bot protection on our sign-up form, and privacy-preserving website analytics.
- Stripe: subscription billing and payment processing. Stripe receives your billing details directly; we never see or store card numbers.
- Brevo: sending transactional email such as sign-in codes, alerts and receipts. Brevo receives the recipient's email address and the message.
The device management platform that talks to the agent on each PC runs on our own infrastructure rather than a third party's. We do not add processors without updating this list.
Where it is processed
Our providers operate globally and data may be processed outside the UK and EEA, including in the United States. Where that happens, transfers rely on the safeguards those providers put in place, such as Standard Contractual Clauses and the UK Addendum.
How long we keep it
- Web & DNS activity, including blocked requests: 90 days. Older records are deleted automatically on a rolling basis.
- Account activity timeline: 90 days, on the same rolling basis.
- Device inventory, status and configuration: kept while your account is active, so the dashboard reflects reality.
- Account and billing records: kept while your account is active, and afterwards only where we are required to retain them for tax or accounting purposes.
- Operational server logs: 7 days.
When you delete your account, all of your household's data (devices, configuration, activity and blocked-request records) is removed as part of account teardown.
How we protect it
All traffic between your devices, our software and our systems is encrypted in transit using HTTPS/TLS. Data at rest is held in Cloudflare's storage services, which encrypt it at rest. Access to production data is limited to the people who operate the service and is protected by two-factor authentication. Administrative actions on accounts are logged.
No system is perfectly secure. If a breach affects your personal data we will tell you and the relevant supervisory authority without undue delay, as the law requires.
Children's data
Because the service protects children's devices, some data relates to minors. It is collected under the direction and consent of the account owner, used only to operate the protections, and never sold or used for marketing.
This aligns with the intent of child-privacy rules including COPPA and the UK and EU GDPR. Children cannot create accounts or give us information directly. The account owner can see everything held about their household, can withdraw consent for any device by removing it, and can have all of it deleted by closing the account.
Your rights
You can ask us to give you a copy of the data we hold about your household, correct it, export it, restrict how we use it, or delete it. Deleting your FamilyProtect account permanently removes your household's data from the service. We respond to requests within one month.
If you are unhappy with how we have handled your data you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
This website
We use Cloudflare Web Analytics on this site. It does not use cookies, does not fingerprint visitors, and does not track anyone across other websites. We do not run advertising trackers here.
FamilyProtect has no public profiles, no chat, no messaging and no user-generated content, so there is nothing for a child to post and nothing for a stranger to contact them through. It is a consumer product sold to households and is not designed, sold or supported for use by schools.
Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects what we collect, who processes it or how long we keep it, we will email account owners before it takes effect.
Contact
For any privacy question or request, email support@getfamilyprotect.com or get in touch.