Privacy Policy

Effective date: [TO CONFIRM: effective date at release]  ·  Last updated: 10 August 2026
Draft, pending legal review. This policy has been expanded to cover the Q Guardian mobile app. Items highlighted in yellow still need confirming, and the whole document should be checked by a data-protection adviser and against current Apple App Store and Google Play requirements before it is published.
Short version: This policy covers two separate things. Our website collects your name and email when you join our waitlist, use our health checkers, or contact us. The Q Guardian app is a parent-led safeguarding tool: a parent sets it up on their child's phone to spot online safety concerns and get calm alerts. We use that information only to keep your child safer and to run the service. We do not sell your data, we do not use child data for advertising, and you can delete your account and data at any time.

Who we are and who is responsible for your data

The Q Guardian app and this website are provided by [TO CONFIRM: registered legal/company name] ("Q Guardian AI", "we", "us"), a UK-based organisation building an AI-assisted safeguarding platform for families and schools.

For the purposes of UK data-protection law, we are the data controller for the personal data described in this policy. Our contact details are:

Q Guardian AI
[TO CONFIRM: registered/postal address]
Privacy contact: info@qguardianai.com [or a dedicated privacy@ address]
Website: www.qguardianai.com (also qguardianai.co.uk)
ICO registration: [TO CONFIRM: ICO registration number]

Part A — The Q Guardian App

This part explains how the Q Guardian mobile app handles information. Q Guardian is set up and controlled by a parent or guardian to help keep their child safer online. It works across two devices: a parent app (where you see alerts, scores and reports) and a child app on the child's Android phone (which quietly looks for safety concerns).

A1. Parent account data

When you create a parent account we collect: your name, email address, login and account identifiers, and your subscription information (which plan you are on, trial and renewal status). Payment itself is handled by the Apple App Store or Google Play, or by our billing provider; we do not see or store your full card details.

A2. Child profile data

The parent creates a profile for each child. This includes the child's name or profile information you enter, and device-connection information needed to link the child's phone to your account (such as pairing and device-connection identifiers). A child does not create an account or enter payment details.

A3. What the Android child app accesses, and why

To detect safety concerns, the child app uses certain sensitive Android permissions. Each is used only for the safeguarding purpose you consent to at setup, and for nothing else. Google requires that sensitive access is necessary, clearly disclosed, and used only for the consented purpose, which is the standard we follow.

PermissionWhat it allowsWhy Q Guardian needs it
Usage AccessSee app-usage information such as screen-time totals and which apps are usedTo build the child's Activity Level picture (screen time, active periods, late-night use) so unusual changes can be noticed
Notification AccessRead notification content from messaging appsTo spot concerning messaging patterns (for example possible grooming or unsafe contact) in message previews
Accessibility ServiceRead certain on-screen information, such as browser search terms and page titlesTo detect exposure to harmful content and risky searches. (Google gives child-protection browser-history collection as a valid Accessibility use case, subject to disclosure and consent.)
Foreground / background serviceKeep monitoring running reliably, with a persistent notification on the child deviceSo protection keeps working when the phone is in a pocket or the screen is off, and so it is always visible that monitoring is active

The child device shows that monitoring is active. We do not hide monitoring from the person using the device.

A4. Safeguarding and activity data

Where relevant, the app processes: captured activity and safety signals; app-usage and Activity Level data; relevant information from notifications and on-screen content; and the alerts, concern scores, safeguarding categories and Weekly Insight summaries generated from them. Q Guardian is designed to surface concerns and guidance to the parent, not to provide a live feed of everything a child does.

A5. Why we use this data

We use app data to:

  • analyse for potential safeguarding concerns and generate alerts, scores and reports for the parent;
  • provide the Activity Level and Weekly Insight features;
  • operate, maintain and improve the reliability of the service;
  • support account, security, and fraud-prevention functions.

We do not use your or your child's data for advertising.

A6. What we do not do

  • We do not sell personal or child-monitoring data. (Google specifically prohibits selling personal or sensitive data obtained through sensitive permissions or APIs, and we do not.)
  • We do not use child-monitoring data to target advertising, and we do not allow others to.
  • We do not collect more than is necessary for the safeguarding purpose.
  • We do not claim to see everything: some apps block this kind of tool, and we are honest about our limits.

A7. Third-party services we use

We use trusted service providers ("processors") to run the app. Their data collection is also reflected in our Google Play Data Safety and Apple App Privacy declarations.

ServiceUsed for
Google Firebase (Authentication, Firestore database, Cloud Messaging)Account sign-in, storing your data, and sending alert notifications to the parent phone
Firebase CrashlyticsDiagnosing crashes so we can keep the app stable
Apple App Store / Google Play billingProcessing subscriptions
RevenueCat [if adopted, once billing is added]Managing subscription entitlements across Apple and Google (processes purchase data only, not child data)

A8. Storage, security and international transfers

App data is stored in Google Firebase and protected with access controls and encryption in transit and at rest, as provided by the Firebase platform. Access is restricted to what is needed to run the service. [TO CONFIRM: data-processing region, e.g. EU/UK, and any transfers outside the UK and the safeguards used]

A9. How long we keep app data

Cancelling a subscription is not the same as deleting your data. If your subscription ends, monitoring pauses and new data stops being collected, but your account, child profile and history are kept so you can reactivate, unless you ask us to delete them.

  • Parent account data: [TO CONFIRM: retention period]
  • Child monitoring history, alerts, scores and reports: [TO CONFIRM: retention period]
  • After a subscription ends (paused account): [TO CONFIRM: how long data is retained before deletion]

Final retention periods are being confirmed alongside this policy and will be stated here before release.

A10. Account and data deletion

You are in control of your data. You can delete your account and associated child data:

  • Inside the app, via the account settings; and
  • Through an external web page at [TO CONFIRM: public account-deletion URL], without needing to open the app.

(Google requires account deletion to be available both in the app and through an external web route for apps with accounts.) Deleting your account removes your parent account and your child's profile and monitoring history, subject to any limited data we must keep for legal reasons. Account and data deletion is a separate action from cancelling a subscription.

A11. Parental control and children's data

Monitoring is set up and controlled by the parent or guardian, who holds the account and makes the decisions about their child's use of Q Guardian. The parent is responsible for using Q Guardian appropriately and, where relevant, for talking to their child about it in an age-appropriate way. We handle child data only to provide the safeguarding service to that parent, and we apply extra care to it: it is not sold, not used for advertising, and not shared except with the processors listed above that are needed to run the service.

A12. Your rights

Under UK data-protection law you have the right to access the data we hold, correct inaccurate data, delete your data, restrict or object to certain processing, and data portability, as well as the right to complain. To exercise any of these, email info@qguardianai.com. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Part B — Our Website

This part covers information collected through our website (qguardianai.com), separately from the app.

B1. What data we collect and why

HowWhat we collectWhy
Early Access waitlistFirst name, email address, role (e.g. parent, teacher)To keep you informed about our launch and invite you to test the product
Family Digital Health CheckerFirst name, email addressTo send you your results and keep you updated
School Safeguarding CheckerName, email, school name, role, school size, school phaseTo send results and tailor follow-up information to your school context
Contact formName, email, subject, messageTo respond to your enquiry

The website does not collect payment information, government identifiers, or special-category data.

B2. Legal basis for processing

  • Consent — when you submit a form on this site, you consent to us contacting you about Q Guardian AI. You can withdraw this at any time.
  • Legitimate interests — for responding to contact-form enquiries and maintaining basic website security.

B3. How we store website data

Email signups (waitlist and health checkers) are stored in Brevo (formerly Sendinblue), our email platform, which is GDPR-compliant and processes data in the EU (Brevo privacy policy). Contact-form messages are delivered to our team by email and are not stored in a website database. This website runs on WordPress and uses standard WordPress cookies for admin sessions only.

B4. Cookies

This website uses only essential cookies required to run WordPress. We do not use advertising, analytics, or tracking cookies. No consent banner is shown because no non-essential cookies are set.

B5. How long we keep website data

  • Waitlist and health checker data: kept in Brevo until you unsubscribe or ask us to delete it.
  • Contact form messages: kept in our email inbox for as long as reasonably needed to handle your enquiry, then deleted.
General

Changes to this policy

We may update this policy as the product develops or as legal requirements change. The "last updated" date at the top will reflect the most recent version. For significant changes, we will notify account holders and waitlist subscribers by email.

Contact

Q Guardian AI
Privacy contact: info@qguardianai.com
Website: www.qguardianai.com