← Back to ParentalView

Privacy Policy

Prefer plain language? Read "What ParentalView sees — and what it never sees" →

Effective date: March 26, 2026

ParentalView ("we", "our", "us") is a parental control service for YouTube. We take the privacy of parents and children seriously. This policy explains what data we collect, how we use it, and the choices you have.

1. Information We Collect

Account Information (Parents): When you sign up, we collect your email address and name via Google Sign-In. We store the Google account ID and profile picture URL to facilitate login.

Device Information (Children's Devices): When a parent links a child's device, we generate a random device token stored locally in the Chrome extension. This token identifies the device to our server. We do not collect the child's name, email, or account details. The one thing we do ask you for is the age range described below, and you give us that — never the child.

Child Age Range (from the parent): During setup we ask you for your child's approximate age range, for example 8-10. We store the range, never a birthdate, and we use it to suggest sensible starting rules and to determine whether COPPA applies to your account.

Video Activity Data: When a child navigates to a YouTube video, the extension sends the video ID and device token to our server. We store the video title, whether it was allowed or blocked, and a timestamp. We do not record the child's browsing activity outside of YouTube.

Rules and Preferences: We store the content concerns and custom rules that parents configure.

Watch Requests: When a child requests to watch a blocked video, we store the video metadata and an AI-generated summary to help parents make a decision.

Payment Information: If you complete parental verification or subscribe to Pro, Stripe handles your card. We receive and store only a Stripe customer and subscription identifier and your plan status, never your card number.

2. How We Use Your Information

  • To evaluate YouTube videos against parent-defined rules using AI analysis
  • To display activity history and blocked video alerts to parents
  • To process "Ask to Watch" requests between children and parents
  • To authenticate parents and link their accounts to children's devices

We do not sell, rent, or share your personal information with third parties for marketing purposes.

3. Third-Party Services

Google Sign-In: We use Google's authentication service. Google's privacy policy applies to the sign-in process.

Anthropic (Claude AI): To evaluate a video we send Anthropic's API the video's public title, channel name and description, together with the concern categories you ticked and the text of the content rules you wrote. The AI has to see your rules in order to judge a video against them. We do not send your name, your email, your child's age range, or any account identifier. Anthropic processes this to return a verdict; under Anthropic's commercial terms, API inputs are not used to train their models.

Stripe: We use Stripe to process the $0.50 parental verification charge, which applies only when you link a device for a child under 13 and is refunded immediately, and to process Pro subscriptions. Card details go directly to Stripe and are never seen or stored by ParentalView. Stripe's privacy policy applies to that processing.

YouTube: We fetch publicly available video metadata (title, author, description) from YouTube to perform content analysis. We do not use the YouTube API; we access publicly available page data.

4. Children's Privacy (COPPA Compliance)

ParentalView is designed to be set up and managed by parents. We do not knowingly collect personal information from children under 13.

  • The Chrome extension collects no name, email, or account details. The one identifier it does create is the random device token described below.
  • The device token is a randomly generated persistent identifier. It contains nothing about your child, but because COPPA treats persistent identifiers as personal information, we collect it only from devices linked by a parent who has completed our consent step, use it solely to route verdicts and activity to that parent's dashboard, and delete it the moment the device is unlinked.
  • Video activity is associated with the device token and the parent's account, not with the child directly.
  • Parents have full control over their data and can delete their account and all associated data at any time.

Verifiable parental consent. If you tell us your child is under 13, we obtain your consent before issuing any device link code. We use a payment card transaction as the check: a $0.50 charge, refunded immediately, because a card charge is one of the consent mechanisms described in the COPPA Rule and is not something a child can normally complete. We record the date, the method used, and your IP address as the record of that consent, which the law requires us to keep. You can review everything collected from your child's device in your dashboard, unlink the device, or delete the account and all data at any time from Settings.

If you believe we have inadvertently collected personal information from a child, please contact us immediately so we can delete it.

5. Data Storage and Security

Data is stored in a SQLite database on the server. Authentication tokens are stored as httpOnly cookies and are not accessible to client-side JavaScript. Passwords (for email/password accounts) are hashed using bcrypt. We use CORS restrictions and rate limiting to protect our API.

While we implement reasonable security measures, no system is 100% secure. We encourage you to use a strong, unique Google account password.

6. Data Retention and Deletion

  • Video verdicts are cached for 24 hours, then re-evaluated on next access. Changing or deleting any rule clears that cache immediately.
  • Activity older than 90 days is deleted automatically by a daily job. You do not have to ask.
  • Rules, devices, and alerts are kept until you remove them. Parents can delete individual rules and dismiss alerts at any time.
  • You can delete your account and everything attached to it at any time from Settings, using the "Delete Account & All Data" button. Deletion is immediate and cannot be undone.

7. Your Rights

You have the right to:

  • Access the data we store about you (visible in the dashboard)
  • Delete your account and all associated data
  • Modify or remove any rules you have set
  • Unlink any child device at any time

8. Changes to This Policy

We may update this privacy policy from time to time. We will notify users of material changes by posting a notice in the web app. Continued use of the service after changes constitutes acceptance of the updated policy.

9. Contact Us

If you have questions about this privacy policy or our data practices, please contact us at markkaminsky99@gmail.com.