Prefer plain language? Read "What ParentalView sees — and what it never sees" →
Effective date: March 26, 2026
ParentalView ("we", "our", "us") is a parental control service for YouTube. We take the privacy of parents and children seriously. This policy explains what data we collect, how we use it, and the choices you have.
Account Information (Parents): When you sign up, we collect your email address and name via Google Sign-In. We store the Google account ID and profile picture URL to facilitate login.
Device Information (Children's Devices): When a parent links a child's device, we generate a random device token stored locally in the Chrome extension. This token identifies the device to our server. We do not collect the child's name, email, or account details. The one thing we do ask you for is the age range described below, and you give us that — never the child.
Child Age Range (from the parent): During setup we ask you for your child's approximate age range, for example 8-10. We store the range, never a birthdate, and we use it to suggest sensible starting rules and to determine whether COPPA applies to your account.
Video Activity Data: When a child navigates to a YouTube video, the extension sends the video ID and device token to our server. We store the video title, whether it was allowed or blocked, and a timestamp. We do not record the child's browsing activity outside of YouTube.
Rules and Preferences: We store the content concerns and custom rules that parents configure.
Watch Requests: When a child requests to watch a blocked video, we store the video metadata and an AI-generated summary to help parents make a decision.
Payment Information: If you complete parental verification or subscribe to Pro, Stripe handles your card. We receive and store only a Stripe customer and subscription identifier and your plan status, never your card number.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
Google Sign-In: We use Google's authentication service. Google's privacy policy applies to the sign-in process.
Anthropic (Claude AI): To evaluate a video we send Anthropic's API the video's public title, channel name and description, together with the concern categories you ticked and the text of the content rules you wrote. The AI has to see your rules in order to judge a video against them. We do not send your name, your email, your child's age range, or any account identifier. Anthropic processes this to return a verdict; under Anthropic's commercial terms, API inputs are not used to train their models.
Stripe: We use Stripe to process the $0.50 parental verification charge, which applies only when you link a device for a child under 13 and is refunded immediately, and to process Pro subscriptions. Card details go directly to Stripe and are never seen or stored by ParentalView. Stripe's privacy policy applies to that processing.
YouTube: We fetch publicly available video metadata (title, author, description) from YouTube to perform content analysis. We do not use the YouTube API; we access publicly available page data.
ParentalView is designed to be set up and managed by parents. We do not knowingly collect personal information from children under 13.
Verifiable parental consent. If you tell us your child is under 13, we obtain your consent before issuing any device link code. We use a payment card transaction as the check: a $0.50 charge, refunded immediately, because a card charge is one of the consent mechanisms described in the COPPA Rule and is not something a child can normally complete. We record the date, the method used, and your IP address as the record of that consent, which the law requires us to keep. You can review everything collected from your child's device in your dashboard, unlink the device, or delete the account and all data at any time from Settings.
If you believe we have inadvertently collected personal information from a child, please contact us immediately so we can delete it.
Data is stored in a SQLite database on the server. Authentication tokens are stored as httpOnly cookies and are not accessible to client-side JavaScript. Passwords (for email/password accounts) are hashed using bcrypt. We use CORS restrictions and rate limiting to protect our API.
While we implement reasonable security measures, no system is 100% secure. We encourage you to use a strong, unique Google account password.
You have the right to:
We may update this privacy policy from time to time. We will notify users of material changes by posting a notice in the web app. Continued use of the service after changes constitutes acceptance of the updated policy.
If you have questions about this privacy policy or our data practices, please contact us at markkaminsky99@gmail.com.