1. Who we are
Child360 is published by Appventure under its Techtangle brand ("we", "us", "our").
We are the data controller for the personal data described in this policy. You can contact us at hello@techtangle.site.
2. Scope of this policy
This policy applies to the following apps, which work together (together, the "Service"):
| App | Package name | Installed on | Purpose |
|---|---|---|---|
| Child360 (parent app) | com.child360.parental.control.screentime.family.aile | The parent's device | The parent signs in, pairs the child's device and views screen time reports. |
| Child360 Child (child app) | com.child360.child | The child's device | Collects app usage data on the child's device and sends it to the paired parent. |
This policy also applies to the iOS versions of these apps, as described in Section 16. It does not apply to third-party websites or services that are linked from the Service.
3. How Child360 works
Child360 is a consent-based product. It is designed so that the child always knows that their screen time is being shared.
- No hidden installation. The child app cannot be installed or run secretly. Its icon remains visible and it does not disguise itself as another app.
- Consent screen. When the child app is set up, a consent screen shows the child exactly which data will be shared with the parent. Setup continues only after the child confirms this screen.
- Permanent notification. While the child app is active, a notification that cannot be dismissed is shown on the child's device. It states that the device's screen time is being shared with the family.
- Pairing code. The parent app generates a 6-digit code. The two apps are paired only when this code is entered on the child's device. Each code is valid for 10 minutes and can be used only once. A child's device can be paired with more than one parent account (for example, both parents), and every pairing requires a new code to be entered on the child's device.
- Unpairing. The child can remove the pairing at any time from the child app. When the pairing is removed, the child app stops sending data and the paired parents are notified.
- Parental responsibility. For children who are minors, the parent or legal guardian is the person legally entitled to set up monitoring. The parent is responsible for installing and pairing the child app and for making sure they have the legal authority to do so. The Service must not be used to monitor an adult without that adult's knowledge and agreement. See our Terms of Use.
4. Data we collect and why
4.1 Child app (collected from the child's device)
| Data type | What exactly | Why we collect it |
|---|---|---|
| App usage statistics | For each app: the time (in milliseconds) it was in the foreground each day, and the distribution of that time by hour of the day. | To produce the daily and hourly screen time reports that the paired parent sees. |
| Installed apps | Package name, display name and icon of apps installed on the device. | To show recognisable app names and icons next to the usage figures in the parent's report. |
| Device information | Device model, Android version and time zone. | To identify the device in the parent's report, to keep data collection compatible with the Android version, and to calculate daily and hourly totals in the child's local time. |
| Push notification token | A device token issued by Firebase Cloud Messaging. | To deliver service messages to the child's device, such as sync requests, pairing and unpairing status, and changes to sharing settings. |
| Anonymous user ID | A random identifier created by Firebase Authentication. It does not contain the child's name, email or phone number. | To link the child's device to the paired parent account without the child having to create an account. |
The child app does not ask the child for a name, email address, phone number or any other contact details. The child app contains no advertising network and no advertising measurement SDK.
4.2 Parent app (collected from the parent)
| Data type | What exactly | Why we collect it |
|---|---|---|
| Account information | Email address and name received from Google when the parent signs in with Google. | To create and secure the parent account and to let the parent sign in. |
| Push notification token | A device token issued by Firebase Cloud Messaging. | To send notifications to the parent, such as pairing and unpairing alerts, screen time summaries and reminders, and messages about the Service. |
| App usage analytics | Events recorded by Firebase Analytics about how the parent app is used (for example screens opened and features used), an app instance identifier, device model and operating system version. Where available, the Firebase SDK may also access the device's advertising identifier (the Android Advertising ID or, on iOS, the IDFA only if you allow it). | To understand which features are used so that we can improve the parent app, and to measure the effectiveness of our own marketing campaigns (for example, which campaign led to an install). |
| Crash reports | Crash logs, stack traces, device state at the time of the crash and a Crashlytics installation identifier, recorded by Firebase Crashlytics. | To find and fix errors that cause the parent app to crash. |
The parent app also displays the child's data described in Section 4.1. That data is not collected again from the parent's device.
4.3 What we do not do with data
- We do not sell personal data.
- We do not share data collected from the child's device with anyone for advertising or marketing. The parent app does not show third-party ads.
- We do not use children's data for profiling, behavioural advertising or any purpose other than providing the reports to the paired parent.
- We do not make decisions based solely on automated processing that produce legal or similarly significant effects on anyone.
5. Data we do not collect
The Service does not collect, read, record or store any of the following:
- Content of messages (SMS or messaging apps)
- Call logs
- Contacts
- Photos, videos or other files
- Location (neither precise nor approximate)
- Keyboard input or keystrokes
- Browser history
- Microphone recordings or audio
- Camera images or video
The Service knows which apps were used and for how long. It does not know what the child did inside those apps.
6. Permissions used by the child app
Depending on the Android version, the child app may use the following permissions. It does not use any permission to access messages, calls, contacts, files, location, the microphone or the camera.
| Permission | Why it is needed |
|---|---|
| Usage access (PACKAGE_USAGE_STATS) | To read how long each app was in the foreground. Android requires the user to turn this on manually in system settings; we explain why before opening that screen. |
| Package visibility (QUERY_ALL_PACKAGES or package queries) | To read the list of installed apps, their names and icons. |
| Notifications (POST_NOTIFICATIONS) | To show the permanent notification and service messages. |
| Foreground service (FOREGROUND_SERVICE) | To keep the permanent notification visible while the app is active. |
| Run at startup (RECEIVE_BOOT_COMPLETED) | To resume sharing and show the permanent notification again after the device restarts. |
| Internet and network state (INTERNET, ACCESS_NETWORK_STATE) | To send usage data to our servers when a connection is available. |
7. Who can see the data
- The paired parent. Only the parent accounts that are paired with the child's device (for example, both parents) can view that device's usage reports. Each pairing requires a code entered on the child's device.
- Our service provider, Google. We use Google Firebase (Cloud Firestore, Firebase Authentication, Firebase Cloud Messaging, Google Analytics for Firebase and Firebase Crashlytics) to store data and run the Service. Google processes this data on our behalf under the Firebase data processing terms and may not use it for its own advertising.
- Authorities, when the law requires it. We disclose data to courts, regulators or law enforcement only when we are legally obliged to, and only the data that the specific request covers.
- A new owner. If the Service or its assets are sold, transferred or merged, data may be transferred to the new owner, who must continue to protect it under this policy. We will notify users before this happens.
We do not share data with any other third party.
8. Where data is stored
Data is stored in Google Cloud data centres used by Firebase. These may be located in the European Union, the United States or other countries where Google operates, and some Firebase services (such as Firebase Authentication, Cloud Messaging, Analytics and Crashlytics) may process data in the United States. Section 12.6 and Section 13.5 explain the safeguards for these transfers.
9. How long we keep data
| Data | Retention |
|---|---|
| App usage records of the child | Kept while the device is paired with at least one parent account, and deleted as described below. |
| Installed apps list and device information | Kept while the device is paired; deleted together with the device's usage records. |
| Data of a child device after the child unpairs | Data sending stops. Past records remain visible to the parents who were paired until a parent removes the device from the parent app or deletes their account. |
| Parent account and all linked child data | Deleted within 30 days after the parent deletes the account. If a child device is still paired with another parent account, that device's data is kept for the other parent. Deleted data may remain in backups for up to a further 30 days. |
| Firebase Analytics data | Up to 14 months. |
| Firebase Crashlytics data | Up to 90 days. |
We keep data longer only where a law requires us to, and only for the period that law specifies.
10. Security
- All data is encrypted in transit between the apps and Firebase using TLS.
- Data stored by Google Cloud is encrypted at rest.
- Access rules on our database allow a parent account to read only the data of the child devices paired with it.
- Access to production data is limited to authorised personnel who need it to operate and support the Service.
No system is completely secure. If a personal data breach occurs that affects you, we will notify you and the competent authorities as required by law.
11. Your choices and controls
- Child: stop sharing. The child can unpair in the child app at any time. Data collection and sending stop immediately. Uninstalling the child app has the same effect.
- Parent: view data. The parent can see all collected usage data of a paired child in the parent app.
- Parent: delete account. The parent can delete the account in the parent app under Settings (Delete account, at the bottom of the page) or on our account deletion page without installing the app. This deletes the parent account and the data of the child devices linked to it, unless a device is still paired with another parent account.
- Requests by email. Anyone, including a child, can write to hello@techtangle.site to ask for access, correction or deletion. We reply within 30 days. We may ask for information that lets us verify that the request comes from the person the data relates to or their parent.
12. European Union and EEA (GDPR)
12.1 Controller and representatives
The controller is Appventure (Techtangle), contact hello@techtangle.site. We have not appointed a Data Protection Officer because we are not required to.
12.2 Legal bases
| Processing | Legal basis |
|---|---|
| Parent account, sign-in, parent push token | Performance of a contract with the parent (Art. 6(1)(b)). |
| Child usage statistics, installed apps, device information, child anonymous ID and child push token | Consent (Art. 6(1)(a)), given by the holder of parental responsibility and confirmed by the child on the consent screen. Consent can be withdrawn at any time by unpairing or deleting the account. |
| Analytics in the parent app | Legitimate interests in improving the app and measuring our own marketing (Art. 6(1)(f)). You can object at any time. |
| Crash reporting in the parent app | Legitimate interests in keeping the app stable and secure (Art. 6(1)(f)). |
| Responding to legal requests and keeping records required by law | Compliance with a legal obligation (Art. 6(1)(c)). |
We do not process special categories of personal data under Article 9 GDPR.
12.3 Children and parental consent (Article 8)
Where the child is below the age of digital consent in their EU member state (between 13 and 16 depending on the country), the child's data is processed only with the consent of the holder of parental responsibility. The parent gives this consent by creating the parent account, generating the pairing code and pairing the child's device. We make reasonable efforts to confirm that consent is given by the holder of parental responsibility, namely by requiring the parent to confirm that they are at least 18 and the child's parent or legal guardian, to sign in with a personal account, and to have physical access to the child's device to enter the pairing code. The parent is responsible for the accuracy of this confirmation. The child is informed through the consent screen and the permanent notification in language suitable for children.
12.4 Your rights
You have the right to:
- Access your personal data and receive a copy (Art. 15);
- Rectification of inaccurate data (Art. 16);
- Erasure of your data (Art. 17);
- Restriction of processing (Art. 18);
- Data portability, meaning receipt of data you provided in a structured, machine-readable format (Art. 20);
- Object to processing based on legitimate interests (Art. 21);
- Withdraw consent at any time, without affecting processing carried out before withdrawal (Art. 7(3)).
A parent can exercise these rights on behalf of their child. A child can also exercise them directly. Send requests to hello@techtangle.site. We reply within one month; this can be extended by two further months for complex requests, in which case we will tell you why.
12.5 Complaints
You can lodge a complaint with the data protection authority of the EU member state where you live, work or where the alleged infringement took place.
12.6 International transfers
Where data is transferred outside the EEA, including to Google LLC in the United States, the transfer is based on the EU-US Data Privacy Framework certification of Google LLC and/or the European Commission's Standard Contractual Clauses incorporated in Google's data processing terms. You can request a copy of these safeguards at hello@techtangle.site.
13. Türkiye (KVKK)
This section is our information notice (aydınlatma metni) under Article 10 of the Personal Data Protection Law No. 6698 ("KVKK").
13.1 Data controller
Appventure (Techtangle), contact hello@techtangle.site.
13.2 Purposes of processing
The purposes for each data type are set out in Section 4. In summary: providing the screen time reports to the paired parent, managing the parent account, sending service notifications, improving the parent app and fixing errors.
13.3 Method of collection and legal grounds
Data is collected electronically and automatically through the mobile apps. Legal grounds under Article 5 KVKK:
| Processing | Legal ground |
|---|---|
| Parent account and parent push token | Processing is necessary for the establishment or performance of a contract (Art. 5(2)(c)). |
| Child usage statistics, installed apps, device information, child anonymous ID and child push token | Explicit consent (Art. 5(1)), given by the parent or legal guardian for a child under 18 and acknowledged by the child on the consent screen. |
| Analytics in the parent app | Legitimate interest of the data controller (Art. 5(2)(f)). |
| Crash reports | Legitimate interest of the data controller (Art. 5(2)(f)). |
| Legal requests | Compliance with a legal obligation (Art. 5(2)(ç)). |
Explicit consent can be withdrawn at any time by unpairing, deleting the account or writing to us.
13.4 Recipients
Data is transferred only to the paired parent, to Google (Firebase) as our service provider, and to authorised public institutions when the law requires it (Section 7).
13.5 Transfers abroad
Because Firebase servers are located outside Türkiye, data is transferred abroad. This transfer is carried out under Article 9 KVKK on the basis of the appropriate safeguards provided in Google's data processing terms, including standard contractual clauses, or on another ground listed in Article 9.
13.6 Your rights under Article 11 KVKK
You have the right to:
- learn whether your personal data is processed;
- request information about the processing if it is processed;
- learn the purpose of processing and whether data is used in line with that purpose;
- know the third parties in Türkiye or abroad to whom data is transferred;
- request correction of incomplete or inaccurate data;
- request deletion or destruction of data under the conditions in Article 7 KVKK;
- request that corrections, deletions or destructions be notified to third parties to whom the data was transferred;
- object to a result against you that arises from analysis exclusively by automated systems;
- claim compensation for damage caused by unlawful processing.
Send your application in Turkish or English by email to hello@techtangle.site from the email address registered with us, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. We respond free of charge within 30 days at the latest. If your application is rejected or not answered, you may complain to the Personal Data Protection Board.
14. United States (COPPA)
This section is our notice under the Children's Online Privacy Protection Act ("COPPA") for children under 13.
14.1 Information collected from children under 13
From the child's device we collect only the data listed in Section 4.1: app usage statistics, installed apps, device information and two persistent identifiers (the anonymous user ID and the push token). We do not collect the child's name, email address, phone number, photos, audio, video or location, and we do not allow the child to make personal information publicly available.
14.2 How we use it
We use this information only to provide screen time reports to the parent and to operate the child app. We do not use it for behavioural advertising, and we do not build profiles of children.
14.3 Verifiable parental consent
We collect data from a child under 13 only after the parent has given consent. The parent gives consent by creating a parent account, confirming that they are at least 18 and the child's parent or legal guardian, and entering the pairing code on the child's device, which requires physical access to it. The child app sends no data before the pairing is completed.
14.4 Disclosure
We disclose children's information only to the paired parent and to Google Firebase, which supports the internal operations of the Service and processes the information only on our behalf. We do not disclose children's information to any other third party.
14.5 Parents' rights
A parent can at any time: review the information collected from their child in the parent app; ask us to delete it; and refuse further collection by unpairing the child's device or deleting the account. Parents can contact us at hello@techtangle.site.
14.6 Retention and security
We keep children's information only as long as described in Section 9 and protect it as described in Section 10.
15. Google Play policy compliance
- User Data policy. We collect only the data described in this policy, only for the purposes described, and our Data safety declarations in Google Play match this policy.
- Prominent disclosure. Before the child app requests usage access or any other sensitive permission, it shows an in-app disclosure that explains what data is collected and how it is used, and it asks for affirmative consent.
- Sensitive permissions. Usage access and access to the list of installed apps are used only for the core function of the child app, which is to show app usage to the paired parent.
- Monitoring apps (stalkerware policy). The child app is declared to Google Play as a child monitoring tool using the IsMonitoringTool declaration with the value child_monitoring. It does not present itself as a spying or secret surveillance tool, it does not hide its icon or behaviour, and it shows a persistent notification while it is active.
- Families policy. The parent app is intended for adults aged 18 and over. The child app is installed on a child's device by a parent and is used only to share screen time with the paired parents. The child app contains no ads, no advertising SDKs and no advertising measurement SDKs.
- Account deletion. Parents can delete their account inside the app and on our account deletion page.
16. Apple App Store and future iOS apps
This policy applies to the iOS versions of Child360 as well. Because iOS limits what apps can access, the iOS versions may collect less or different data, for example through Apple frameworks such as Screen Time. Where the iOS versions differ, our App Store privacy labels describe what they collect. The principles in this policy apply on iOS without exception: consent and visibility for the child, no sale of data, no advertising in the child app and no collection of the data listed in Section 5.
17. Changes to this policy
If we change this policy, we will update the "Last updated" date. If a change affects what data we collect from children or how we use it, we will notify the parent in the app or by email before the change takes effect and, where required by law, ask for new consent.
18. Contact us
Appventure (Techtangle)
Email: hello@techtangle.site