Privacy Policy
Version 2026-10-07 · Effective 2026-10-07
On this page
- 1. Overview
- 2. Why we process data
- 3. What we collect
- 4. How long we keep it
- 5. Sharing within the family and with others
- 6. Service providers and international transfers
- 7. Location data
- 8. Children's data
- 9. Generative AI
- 10. Listening to surroundings
- 11. Your rights
- 12. Deletion
- 13. Security
- 14. Cookies
- 15. Country and region-specific notices
- 16. Privacy officer and contact
- 17. Changes to this policy
- 18. Version history
1. Overview
Guardian Labs Co., Ltd. ("we", "us") operates StepGuardian (the "Service"). We comply with the Personal Information Protection Act and the Act on the Protection, Use, etc. of Location Information of the Republic of Korea, and with the privacy laws of the countries where the Service is used. This Privacy Policy explains what personal information we process, why, for how long, and the rights you have.
| Item | Details |
|---|---|
| Controller | Guardian Labs Co., Ltd. (가디언랩스 주식회사), CEO Taehee Ko |
| Business registration no. | 130-88-03529 (Republic of Korea) |
| Address | 413-C34, 13 Cheongnahannae-ro 72beon-gil, Seo-gu, Incheon, Republic of Korea |
| Contact | help@guardianlabs.app |
- Scope: This policy covers the parent app and the child app (Android) and the servers they use. Website visitors are covered by our separate Website Privacy Policy.
- What the Service is: StepGuardian is a family safety app that parents and children use together. Data collection on a child's device starts only after the child agrees, item by item, on the child app's consent screen. A parent's location is visible to the child as well, and the child's phone always shows a notification that the Service is running.
- No selling: We do not sell personal information or share it with third parties for advertising. We do not use advertising IDs or advertising and marketing analytics tools.
- Effective date: This policy applies from September 30, 2026.
2. Why we process data
| Purpose | Data (Section 3) | Legal basis |
|---|---|---|
| Parent sign-up, sign-in and family linking | Parent account data, device data | Performance of our contract |
| Location sharing, routes, safe-zone arrival and departure alerts | Location, safe-zone settings, device status | The child's consent (Location Information Act); parental consent where required |
| Showing app usage and applying the daily app time your family set | App usage, installed apps | The child's consent |
| Showing which apps sent notifications | Notification metadata | The child's consent |
| Walking-while-using-phone ("smombie") alerts and history | Alert history | Performance of our contract (walking is detected on the device) |
| Family chat | Messages and attachments | Performance of our contract |
| Listening to surroundings (Section 10) | Listening-session records, live audio | The child's separate consent for this item |
| AI weekly report and classifying new apps (Section 9) | Aggregated app use, distance and alert counts; app names | Performance of our contract |
| Protection status (alerts when the app is removed or permissions are turned off) | Protection checks, tamper alerts | Performance of our contract; legitimate interest in protecting the child |
| Weather and public holidays | Location coordinates (weather) | Performance of our contract |
| Error analysis and security | Error logs, integrity checks, consent records | Legitimate interest; legal obligation (proof of consent) |
3. What we collect
3.1 Parent account
| Data | When |
|---|---|
| Email address, nickname, profile photo, language and country settings | At sign-up and when you edit your profile |
| Push notification token; device data (Android ID, model, OS version, app version) | When you use the app |
| Location (coordinates, speed, accuracy, route) — only if the parent turns location sharing on | While sharing is on |
| Chat (text, photos, voice messages, stickers, files) | When you use family chat |
The parent app uses the microphone only to record voice messages the parent chooses to send.
3.2 The child's device — collected after the child agrees
The child app has no account or login (anonymous authentication). We do not collect a child's legal name, email address or phone number. These are the items the child reviews on the consent screen before linking; the consent screen is generated from the same list as this table.
| Item | What we actually collect |
|---|---|
| Location | Coordinates, speed, accuracy, an estimate of whether they are in a vehicle, time, route |
| App usage | App package name, app name, time spent per app |
| Installed apps | Package name, app name, app icon, category, whether it is a system app |
| Notification metadata | The app that sent a notification, time, rough category and count — never the title, content or sender |
| Surroundings (Section 10) | Listening-session records (which guardian, start and end time). The audio itself is never stored |
3.3 Data created while you use the Service
| Data | Details |
|---|---|
| Device status | Battery, charging state, network type, connected Wi-Fi name (SSID) and signal strength |
| Safe zones | Wi-Fi name (SSID) and access point address (BSSID) your family registered, or the center and radius of a map zone |
| Smombie alert history | Start and end time, duration, how the alert was cleared |
| Protection checks | Permission status, whether developer options or USB debugging are on, installed VPN apps, app-cloning signals |
| Tamper alerts | Alert type and time |
| Activity history | Type and time of family events (linking, setting changes, etc.) |
| Consent records | Which items were agreed to, the policy version, and a linked history that reveals tampering |
| Error logs | Warning and error messages and stack traces when the app hits an error |
3.4 What we do not collect
- Step counts. We do not use the step sensor. Whether the child is walking is decided on the device from motion sensors; raw sensor data never leaves the device.
- Notification titles, content or senders; what is on screen; what you type.
- Browsing history. Harmful-site blocking happens on the device, and visited sites are not uploaded.
- Camera access or full photo library access. Only photos the user picks are sent.
- Advertising IDs or data from advertising and marketing analytics tools.
4. How long we keep it
Expired data is deleted automatically by a daily server job. See Section 12 for how deletion works.
| Data | Retention |
|---|---|
| Location and routes | 90 days |
| App usage (detailed) | 90 days |
| App usage (daily summaries) | 13 months |
| Family chat (messages and attachments) | 60 days |
| Notification metadata | 30 days |
| Tamper alerts, activity history | 90 days |
| Device status | Only the latest value, for live display |
| Installed apps, safe-zone settings | Only the latest value; deleted when the family link ends |
| Smombie alert history, listening-session records | While the family link lasts; deleted when the link ends or the account is deleted |
| Parent account data | Until the account is deleted |
| Consent records | While the family exists (legal proof of consent); deleted when the family is dissolved |
| Error logs | 90 days (the error-analysis service's retention) |
Where a law requires us to keep data longer, we keep it separately for that period and then delete it.
5. Sharing within the family and with others
- Within the family: By design, location, app usage and alert history are visible to guardians linked to the same family, and a parent's location and what is being shared are visible to the child. People outside the family cannot see them.
- Third parties: We do not give personal information to third parties without consent, except where the law requires it or authorities make a lawful request. Our standards are published in our Law Enforcement Guidelines.
- No selling or ad sharing: We do not sell personal information or share it for targeted advertising.
6. Service providers and international transfers
We use the providers below to run the Service. Some process data outside the Republic of Korea. Data is sent over encrypted connections (TLS) while you use the Service.
| Recipient (contact) | Country | Data | Purpose | Retention |
|---|---|---|---|---|
| Google LLC — Firebase (contact) | Republic of Korea (Seoul: database, server functions), Singapore (live location), U.S. and other Google data centers (authentication, push notifications, file storage) | Most data in Section 3 | Authentication, storage, server processing, push notifications | Periods in Section 4 |
| Google LLC — Vertex AI (contact) | Republic of Korea (Seoul) | Aggregated app time, top 10 apps, distance, alert counts; names and package names of new apps | AI weekly report, app classification | Not kept after the response (Google's short-term cache, up to 24 hours) |
| Google LLC — Firebase Crashlytics | U.S. | Error logs | Error analysis | 90 days |
| Google LLC — Play Integrity | U.S. and other Google data centers | Device and app integrity signals | Blocking tampered apps | Not kept after the check |
| Open-Meteo (terms) | Germany | Latitude and longitude of the device requesting weather | Showing weather | Not stored (lookup only) |
| Cloudflare, Inc. (privacy) | U.S. and worldwide | Live audio stream; IP addresses of both devices | Relaying audio for listening to surroundings when devices can't connect directly | Not stored |
- Public holidays are fetched from the Google Calendar API; no personal information is sent.
- Opting out: These providers are necessary to run the Service. You can turn off individual features (such as weather or listening to surroundings) or stop using the Service through Delete account and data. Without required data, the Service can't be provided.
- Transfers to the U.S. are covered by safeguards such as the providers' Standard Contractual Clauses. If a provider changes, we will update this policy.
7. Location data
- Consent: A child's location is collected only after the child agrees. For children under 14, a parent or legal guardian also consents. For children aged 8 and under, Korean law allows a guardian to consent to location collection on the child's behalf (app usage, notifications and surroundings still require the child's own consent).
- Mutual sharing: Just as a child's location is visible to guardians, a parent's location is visible to the child when the parent shares it.
- Accuracy: Location comes from GPS, Wi-Fi and cell signals and can be off indoors or underground.
- Withdrawing consent: The child can turn off location sharing in the child app, and a guardian can do so in the parent app or unlink the family. Collection stops immediately.
8. Children's data
- StepGuardian is designed for guardians to use together with their minor children. The child app works without an account and does not ask for the child's name or email.
- The child's consent: During linking, the child sees each item on easy-to-read screens, and we collect only the items the child agrees to.
- Parental consent: Before we process data about a child under 14 (under 13 in the U.S.), the guardian must complete a verification step in the parent app that includes a confirmation sent to the guardian's registered email.
- Guide for kids: The child app's linking consent screen explains, in language a child can follow, what their parent will be able to see (location, app usage, notifications and so on), item by item. Linking continues only after the child has reviewed it.
- Children's data is used only to provide the Service. It is never sold or used for advertising.
9. Generative AI
- The AI weekly report and classification of newly installed apps use Google Cloud Vertex AI (Gemini models, Seoul region).
- We send only aggregated numbers and app names. We do not send information that identifies a child or family (account IDs, names, location coordinates).
- Under Google Cloud's terms, this data is not used to train Google's AI models.
- AI output is labeled as written by AI and may contain errors. We do not make decisions with legal effects on you based only on AI output.
10. Listening to surroundings
- This feature lets a guardian briefly listen to the sound around the child's device. It works only if the child separately agrees to this item on the consent screen. Other features still work if the child says no.
- Audio travels live between the two devices and is never stored. When a direct connection isn't possible, it passes through Cloudflare's relay servers (Section 6), and it is not stored there either.
- Our servers keep only a listening-session record (which guardian, start and end time).
- While listening is active, Android shows its microphone-in-use indicator on the child's device (Android 12 and later).
- Using this feature to listen to other people's conversations without their consent is prohibited under Section 8 of our Terms of Service and may be illegal.
11. Your rights
- Users (including children) and legal guardians can ask to access, correct, delete or stop processing personal information, withdraw consent, and, where the law provides, receive a copy (portability).
- How: Change settings in the app, use the Delete account and data page, or email help@guardianlabs.app. You may also act through an authorized agent.
- Timing: In Korea we act within 10 days of receiving a request. For users in other countries we meet the deadline set by local law.
- We never penalize you for exercising your rights. If you delete required data or stop its processing, however, the Service can't be provided.
12. Deletion
- Automatic deletion: Data past its retention period (Section 4) is permanently deleted by a daily job.
- Delete in the app: Parent app → Settings → Account → Delete account. After identity confirmation, the account is deleted immediately and permanently.
- Request without the app: Use the Delete account and data page. We verify you through your sign-up email and delete within 30 days of verification.
- Family data: If another guardian remains in the family, only the requesting parent's data is deleted (family admin rights pass to the remaining guardian). If the only guardian deletes their account, the family is dissolved and the child's data (location, app usage, chat, safe zones, consent records) is deleted too.
- Electronic files are deleted in a way that cannot be recovered.
13. Security
- Encryption in transit: All traffic between devices and servers uses TLS.
- Access control: Server security rules allow only members of the same family to access family data, and integrity checks block tampered apps.
- Data minimization: Walking is detected on the device, notifications are recorded without content, and AI receives only aggregates.
- Records: Personal information in server logs is masked, and consent records are stored so that tampering can be detected.
- Internal controls: We have a designated privacy officer and limit operational access to the minimum number of people.
14. Cookies
The StepGuardian apps do not use cookies or advertising IDs. For cookies on our website, see our Cookie Policy.
15. Country and region-specific notices
StepGuardian can be used in many countries. This policy applies to everyone, and users in the regions below also have the rights described there. Wherever you live, the rights your local law gives you take precedence over this policy.
15.1 Republic of Korea
- Under the Location Information Act, you may withdraw all or part of your consent to the collection, use or provision of personal location data, request a temporary suspension, and ask to see or be notified of any provision of it.
- To report a privacy violation: Personal Information Infringement Report Center (118, privacy.kisa.or.kr), Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), Supreme Prosecutors' Office (1301), Korean National Police Agency (182).
15.2 United States
- COPPA: We collect information from children under 13 only after the guardian verification described in Section 8 (verifiable parental consent). Guardians can review or delete their child's information and refuse further collection, and children's data is not kept beyond the periods in Section 4.
- State privacy laws (including California's CCPA/CPRA): The categories of personal information we collected in the past 12 months are those in Section 3 (identifiers, geolocation, device and internet activity, audio session records). We do not sell or share personal information for cross-context behavioral advertising, and we use sensitive information (including precise location) only to provide the Service. You can request access, deletion and correction, and we will not discriminate against you for doing so.
- Regardless of Do Not Track or Global Privacy Control signals, we do not track users across sites.
15.3 European Economic Area, United Kingdom and Switzerland
- We are the controller under the GDPR and UK GDPR. Our legal bases are listed in Section 2: contract (Art. 6(1)(b)), consent (Art. 6(1)(a) — with parental consent for children below the digital age of consent in their country, Art. 8), legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)).
- You have the right to access, rectify, erase, restrict, port, object and withdraw consent, and to complain to the supervisory authority where you live. We respond within one month.
- Transfers outside the EEA (to Korea, the U.S., etc.) rely on adequacy decisions (the EU has an adequacy decision for the Republic of Korea) or Standard Contractual Clauses.
- We will appoint an EU and UK representative under Article 27 GDPR before we actively offer the Service in those regions, and we will publish their details here.
15.4 Other countries
If your local law gives you additional rights or procedures, email help@guardianlabs.app and we will handle your request under that law.
16. Privacy officer and contact
| Item | Details |
|---|---|
| Chief Privacy Officer | Taehee Ko (CEO) |
| Contact | help@guardianlabs.app |
| Location Information Manager | Taehee Ko (same person) |
Send questions, complaints or requests about personal or location information to the address above or through our contact page. We will respond and act without delay.
17. Changes to this policy
- We announce changes on our website and in the app at least 7 days before they take effect. Changes that significantly affect your rights, such as new data items or purposes, are announced at least 30 days in advance, and we ask for consent again where the law requires.
- The version of this policy matches the policy version recorded on the child app's consent screen.
18. Version history
| Version | Effective | Changes |
|---|---|---|
| 2026-07-10 | (not in effect) | First draft, before legal review (DRAFT) |
| 2026-09-30 | 2026-09-30 | Added controller details; reconciled data items, retention and providers with the actual app (clarified that step counts, notification content and browsing history are not collected; added installed apps, device status, protection checks, consent records and error logs); disclosed Vertex AI (Seoul), Crashlytics, Play Integrity, Open-Meteo and Cloudflare; added generative AI and listening-to-surroundings sections; restructured country and region notices (Korea, U.S., EEA/UK); the kid-friendly notice now lives only on the child app's consent screen (the separate web guide for kids was retired) |
| 2026-10-07 | 2026-10-07 | Changed the contact and privacy officer email to our company-domain (guardianlabs.app) address |
