Privacy Policy

GUARDIANAI, LLC · Last Updated: September 13, 2026 · Replaces the April 28, 2026 policy in full

How to read this policy. Every sentence below describes what GuardianAI does today, as it is built. Where we are partway through making something better, we say so, we say what is true right now, and we say where we are going. We do not describe a plan as if it were finished. If you ever find a sentence here that the product does not live up to, tell us at privacy@guardianaiapp.com and we will fix the product or fix the sentence.

1. Who we are and what this covers

GuardianAI is made by GUARDIANAI, LLC, a Delaware company based in Holliston, Massachusetts ("we", "us"). This policy covers the GuardianAI apps for guardians and for children on Android, iPhone and iPad, computers, and web browsers; the website at guardianaiapp.com; and the services behind them.

GuardianAI is a family safety product. It is designed to be used by an adult guardian to supervise a child's devices, with the child's knowledge. It is never hidden on a device.

2. The words we use

3. Our standards, and how far along each one is

These are the rules we build to. Each one is marked with where it stands today. A standard marked in progress is a commitment about direction, not a description of the current product; the sections that follow describe the current product.

StandardStatus today
Privacy is literal, not marketing. When we say something stays on the device, it stays on the device. When we cannot say that, we say what actually happens instead.In force. This policy was rewritten against a line-by-line map of our own database to make it true.
We never sell data, never run ads, and never build advertising profiles of anyone, least of all children.In force. There is no advertising code in our apps. We removed the last analytics library from the Android app in August 2026.
Your child's own photos, messages and camera never leave their device.In force. See section 5.
Everything expires. Nothing about a child is kept indefinitely, and the schedule is published.In force. See section 15. The schedule is enforced by a daily job, not just written down.
Deleting is real, immediate for a child, and does not need our permission.In force. See section 17 and our deletion page.
Never hidden, never shaming. The child always knows GuardianAI is on their device, and nothing we send a guardian frames the child as the problem.In force.
Seal everything we can. Our goal is that alerts, location, activity, and settings all travel and rest sealed to your family's key, so that we could not read them if we were ordered to.In progress. Sealed today: the encrypted sync store, and safety alerts sent from Android devices set up with a Family PIN. Not yet sealed: alerts from iPhone and the browser extension, location, activity detail, and contact names. Section 12 has the exact list and the order we are shipping it in.
Nothing about a child is sent to an AI service unless it is public content, and then only for a moment and with no name attached.In force, with one narrow exception on Android that is disclosed in section 7 and scheduled for removal.
Outside experts check our work.Not yet. We have not had an independent security review. One is being arranged for the fall of 2026. We will not describe ourselves as audited until it has happened.

4. What we collect

About the guardian

About the child

About devices

5. What never leaves your child's device

6. What reaches our servers, and whether we can read it

For the product to work, some information has to travel from a child's device to a guardian's device, and it travels through us. This table is the honest account of what that is. "Sealed" means we store it but cannot open it. "Readable" means we can.

WhatTodayNotes
Sync store (settings, activity summaries, digest data synced between family devices)SealedEncrypted on the sending device with your family key. We have never been able to read it.
Safety alerts: what was detected, on which page, with a short excerpt of the matching textSealed from Android devices set up with a Family PIN. Readable from iPhone and the browser extension, and from Android devices not yet set up with a PIN.We always see, and need to see, an alert's severity and which of four broad categories it falls in (content, contact, wellbeing, system), so it can reach the right guardian. Sealing the rest for every device is in progress; see section 12.
LocationReadable for most devices today. Sealed for devices already sending in encrypted mode.See section 8.
Screen time by app, and time by website categoryReadableThis is how the daily grade and screen-time limits work. We plan to seal it; see section 12.
Blocked-page requests: the address of a page the child asked to unblock, and the reason they typedReadableDenied requests are deleted after 6 months. Approved ones are kept because they are the standing permission the filter enforces.
Contact names and the app a contact came from, for contact approval and Trusted CircleReadablePhone numbers are stored only as a one-way fingerprint. See section 10.
Ride-Share Monitor: driver name, vehicle, pickup and destination, routeReadableKept 6 months after a trip ends. We plan to seal it; see section 12.
Distress signal, check-in, and Safe & Sound session recordsReadableThese are emergency features. Their location and message text are deliberately readable so an alert can reach every guardian with zero delay. Kept 1 year.
Weekly digestReadableEncrypted at rest with a key we hold, which means we can read it. Digest emails carry only severity, category, and a generic line for any sealed alert, never alert detail.
Bleeped-media transcripts (see section 9)Sealed for families with a PIN, otherwise readableDialogue from a show or video, not your child's voice. Kept 30 days.
Your family's rules and settingsReadableBy design. Every device has to be able to apply them.

7. Content we send to an AI service for a moment

To judge whether a web page or a video is appropriate, GuardianAI may send the page's text (up to about 10,000 characters) to an AI service, currently provided by Anthropic. Here is exactly how that works:

The narrow exception, disclosed and scheduled for removal. On Android, when ScreenGuard sees an image in a public app (a browser, a video platform, a social feed) that its on-device model cannot judge, it may send one compressed screenshot of that image to the same AI service for a verdict. The screenshot is processed in memory, never written to disk or to our database, never linked to your family, and discarded immediately. Camera, gallery, and messaging apps are excluded from this entirely. We are building a stronger on-device model to replace this step, after which no image of any kind will leave a child's device.

8. Location

Your child's location exists so that you can see it, so it travels from their device to yours, through us.

Today, for most devices, our servers can read the coordinates. Location history is deleted after 90 days. Geofence crossings ("left the school zone") are kept 6 months. Distress-signal and check-in locations are kept 1 year, because they are emergency records.

Where we are going, and where some devices already are: location leaves the child's device sealed with the family key, our servers store and pass along an envelope they cannot open, and it is readable only on your family's devices. Devices already sending this way are sealed today. The rest join as the encryption rollout in section 12 reaches them. Emergency locations in a distress signal will stay readable on purpose, so that nothing can delay them.

9. Audio, calls, and Safe & Sound

There is no always-on microphone anywhere in GuardianAI. We decided against building one, permanently. Every use of a microphone is bounded and started by a person:

10. Contacts and Trusted Circle

Trusted Circle shows a verified badge next to contacts who are also GuardianAI children, and lets families warn each other about high-risk contacts, without anyone's address book being uploaded. Phone numbers are turned into a one-way fingerprint on the device, and only fingerprints are compared.

The one moment a number is sent: when a guardian is asked to approve a new contact, the child's device sends that one phone number to us so we can create the fingerprint. The number is not stored; the fingerprint and the contact's display name are. We are moving the fingerprinting onto the device so that the number never travels at all.

On Android, with the guardian's permission, GuardianAI also reads the call log to show contact patterns: who the child talks to, how often, and when. Never the content of a call.

11. Guardian Filter

Guardian Filter checks website names on the child's Android device against your family's rules and our blocklist, and blocks the ones that should not load. It runs on the device. No web traffic is sent through our servers.

Name lookups that the filter allows are resolved over an encrypted connection to Cloudflare's public resolver, so your internet provider cannot see them. Cloudflare's own privacy policy governs what it does with resolver queries. Names the filter blocks never leave the device.

Guardian Filter checks names, not connections. A site reached by a direct address, through a proxy, or from a server shared with allowed sites is not checked at this layer. That is a limit of the technology, and it is why ScreenGuard and the browser extension exist as separate layers.

12. Encryption, exactly

Everything between your devices and us is protected in transit with TLS. Our apps additionally pin our server's certificate, so a network attacker cannot impersonate us. Everything at rest on our servers is encrypted. Those two things are standard, and every serious company does them.

What we are building on top of that is end-to-end sealing: encryption with a key we never hold, derived from your Family PIN on your own devices, so that even we cannot read your family's data. Here is exactly where that stands.

DataSealed today?
Sync storeYes, always has been
Setup interview transcriptYes, since August 2026
Bleeped-media transcript excerptsYes, for families with a Family PIN
Safety alerts from AndroidYes, for devices set up with a Family PIN
Safety alerts from iPhone and iPadNot yet. Next in line.
Safety alerts from the browser extensionNot yet. The extension has no way to receive the family key today; that is being designed.
LocationPartly. Devices in encrypted mode, yes; the rest, not yet.
Screen time, website time, ride-share detail, contact namesNot yet. Planned after alerts and location.
Weekly digestNo. Encrypted with our key, which we can use. Planned.
Alert severity and broad category, family and device identifiers, timestamps, your rulesNo, by design. This is what routing an alert to the right guardian requires, and it contains no content.

While this rollout is incomplete, our systems still accept alerts in readable form from devices that have not been updated. When every device type can send sealed alerts, we will stop accepting readable ones, and this policy will be updated to say so.

What "sealed" means for you: if you lose your Family PIN and your recovery phrase, sealed data is gone. We cannot recover it, because we cannot read it. Keep the recovery phrase somewhere safe.

13. How we use information, and what we never do

We use the information described in this policy to run the family safety features you turn on, to deliver alerts and the daily grade to guardians, to enforce the rules you set, to bill you, to secure the service against fraud and abuse, and to meet legal obligations.

We do not, and will not:

14. Companies that process data for us

These companies process data on our behalf, under contracts that limit them to providing their service to us. None of them is permitted to use your family's data for their own purposes.

CompanyWhat they do for usWhat reaches them
Amazon Web ServicesHosting, database, encrypted backups, and outbound emailEverything we store, encrypted at rest; the emails we send you
AnthropicAI classification of public contentPage text and, on Android, the occasional ambiguous screenshot of public content, with no family identifier (section 7)
DeepgramLive transcriptionStreamed audio for bleeping and for the voice assistant (section 9)
CloudflareEncrypted name resolution for Guardian FilterWebsite names the filter allows (section 11)
StripePaymentsBilling identifiers and your Stripe customer record. Card details stay with Stripe. Apple and Google are not involved in payment.
Apple and GooglePush notificationsA device token and the notification body. For sealed alerts, the body is a generic line with no child name or detail. For readable alerts, it may carry the alert title.

We use no advertising networks, no tracking pixels, and no third-party analytics in the apps.

15. How long we keep things

The amended Children's Online Privacy Protection Rule prohibits keeping children's data indefinitely and requires a published schedule. This is ours. It is enforced by a job that runs every day.

RecordKept for
Safety alerts45 days
Bleeped-media transcript excerpts30 days
Device tamper records30 days
Location history90 days
Device internet addresses90 days
Device heartbeats90 days
Geofence crossings6 months
Completed check-ins6 months
Completed ride-share trips6 months
TV and streaming activity6 months
Denied page requests6 months
Screen time and website time1 year
Distress signal, SOS, and Safe & Sound session records1 year
Approved page requestsUntil you revoke them; they are the permission itself
Your rules, settings, and sealed sync storeAs long as your family uses GuardianAI
Account, subscription, and device recordsAs long as your account exists, then deleted per section 17
One-way hash of a guardian email that has used a free trialKept after account deletion, to prevent a second free trial. Not reversible into the address (section 4)
Consent records7 years, required by law
Billing and tax recordsAs required by law, typically 7 years
Reports to NCMEC (section 18)1 year minimum, required by law

Deleting a child's profile removes that child's records from every table above immediately, ahead of any schedule. Deleted data is gone from live systems at once and from encrypted backups within 30 days.

16. Children's privacy and COPPA

GuardianAI is built for supervising children, so we collect information about children by design, and we take the Children's Online Privacy Protection Act seriously as the rulebook for doing that honestly.

Where two guardians share a family, either can add or remove a child, and either can delete the family account, which requires the account password.

17. Your rights, and how to use them

These rights are yours regardless of where you live. Where a state or national law gives you more, you have that too.

If GuardianAI detects known child sexual abuse material, United States law requires us to report it to the National Center for Missing & Exploited Children. The report contains a digital fingerprint of the image, never the image itself, and federal law requires us to preserve the report's contents for at least one year. We cannot withdraw such a report, and it survives account deletion. This is rare, mandatory, and we would rather tell you here than surprise you later.

If we receive a lawful demand for data, we comply only to the extent the law requires, and we can only hand over what we can read. Sealed data is sealed from us too.

19. Security

If we ever have a breach that affects your family's data, we will tell you directly, promptly, and in plain language, and we will tell regulators where the law requires it.

20. Changes to this policy

When we change this policy, we update the date at the top. For a change that affects what we collect about children or how we use it, we email every guardian at least 30 days before it takes effect and, where the law requires, ask for consent again. Each version notes what changed.

September 13, 2026. Full rewrite. The previous policy (April 28, 2026) said that location, page addresses, contact names, and alert detail never reached our servers. That was not true of the product as built, and it should not have been published. This version was written against a line-by-line audit of our own database so that every sentence matches the code. The product had no public users at the time.

21. Contact

GUARDIANAI, LLC, Attn: Privacy Team
3 Eagle Path, Holliston, MA 01746, USA

Privacy questions and requests: privacy@guardianaiapp.com
Security concerns: security@guardianaiapp.com, with URGENT in the subject line for anything involving a child's safety
Phone: 617-285-4460

We respond to privacy requests within 5 business days.