Privacy Policy
Last updated: September 28, 2026
Effective Date: October 6, 2026 Version: 2.6 (updated October 6, 2026)
Scheduled change, effective October 28, 2026: if a parent's subscription lapses, Observed Users' data will be permanently deleted 30 days after the lapse (Sections 6 and 12.6). Until then, the previous rule applies.
1. Introduction
YouGuard ("we," "us," or "our") operates YouGuard (the "Service") at https://youguard.app, including the YouGuard web dashboard, YouGuard Messenger Android application, and YouGuard Browser Shield Chrome extension. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our Service.
YouGuard is a family monitoring and accountability service. By its nature, the Service collects personal information about both guardian users (parents, accountability partners) and observed users (children, partners, seniors, or other individuals being monitored). This Policy covers data practices for all user types.
By using the Service, you agree to the collection and use of information in accordance with this Policy.
2. Information We Collect
2.1 Guardian Account Information (Information You Provide)
- Account information: Name, email address, and profile picture collected through Google OAuth sign-in.
- Profile and preferences: Content evaluation rules, notification preferences, and account settings you configure.
- Communications: Messages you send us for support or feedback.
- Payment information: New subscriptions are processed by Stripe, Inc., our payment processor. Subscriptions started through Whop, Inc. before August 2026 continue to be billed by Whop as Merchant of Record. We do not collect, store, or process your payment card data. Stripe and Whop share your subscription status, plan, and customer or membership identifiers with us to manage your access.
- Parental consent verification: If you verify parental consent for a child under 13 (see Section 12.1), Stripe processes a $0.50 charge on your card, which we refund right away. Your card statement may show both the charge and the refund.
2.2 Observed User Data (Monitoring Data)
When a guardian initiates monitoring of an Observed User (child, accountability partner, or dependent), the following data is collected from or about the Observed User:
YouTube Activity (via YouTube Data API v3):
- Channel subscriptions (channel names, IDs, descriptions, thumbnails)
- Liked and disliked videos (video titles, IDs, channel attribution, thumbnails)
- Playlists, including Watch Later, and the videos in them
- Comments the account has posted, and comments on videos the account has uploaded (which may include personal information of other YouTube users)
- Videos the account has uploaded, and the account's YouTube activity feed
- YouTube account metadata (channel name, profile image)
- Sync logs (timestamps, status, video/subscription counts)
We do not retrieve watch history through the YouTube Data API. Through the YouTube Data API we do not access private videos, passwords, or payment information.
YouTube Watch History (via guardian-uploaded Google Takeout export):
- Video titles, URLs, channel names, and watch timestamps contained in the export file
- Upload metadata (upload date, uploading guardian)
- This data is collected only when a guardian uploads the export. We store it and display it to the guardians authorized on that Observed User's account. It is deleted when the Observed Account is removed.
SMS and MMS Messages (via YouGuard Messenger Android app):
- Message text content (SMS body, MMS subject)
- Phone numbers of message participants
- Timestamps and direction (incoming/outgoing)
- MMS media attachments (images, videos, audio, documents) — stored in Cloudflare R2
- Message thread metadata (participants, group status, display names)
State Law Notice: Some states (including California, Florida, and Illinois) require all-party consent before intercepting or monitoring electronic communications. If you reside in such a state, it is your responsibility as the guardian to ensure that third parties whose messages may be captured (e.g., your child's contacts) are aware that monitoring is in place, to the extent required by applicable law. YouGuard does not monitor compliance with state-specific consent laws on your behalf.
Phone Call Metadata (via YouGuard Messenger Android app):
- Phone numbers of call participants
- Call timestamps, duration, and type (incoming, outgoing, missed)
- Real-time call state events (for cross-channel scam detection)
- We do not record or store call audio content.
Browsing Activity (via YouGuard Browser Shield Chrome extension):
- URLs and domain names of pages visited in that Chrome browser, including YouTube pages
- Page titles
- The time of each visit
- Domain safety categorizations (banking, cryptocurrency, remote access, etc.)
- Google Safe Browsing / Web Risk API threat assessments
- YouTube filtering actions (blocked channel recommendations hidden)
Browsing activity is shown to the guardians authorized on that Observed User's account. Because Browser Shield records YouTube pages visited, it can show what the Observed User watched even though we do not retrieve watch history through the YouTube Data API. Uninstalling Browser Shield stops this collection.
Device Information (from Android app and Chrome extension):
- Device name, model, and Android version
- Extension device ID and browser identifier
- Last-seen timestamps and heartbeat status
- Device admin status (enabled/disabled)
2.3 AI Analysis Data
- YouTube data: YouTube channel data, video metadata, and content excerpts, together with family context you provide (such as your child's age, interests, and goals), are analyzed exclusively through Google Vertex AI (Gemini). YouTube data is not sent to Anthropic, OpenAI, or any other non-Google AI provider. Under Google's Vertex AI data governance terms, customer data is not used to train Google's foundation models.
- Message data: If SMS content analysis is enabled, message content (with phone numbers redacted) may be analyzed by Google Vertex AI (Gemini) or Anthropic.
- Output: AI-generated content excerpts, topic classifications, internal priority scores (never shown to users), and observations. These are stored in our database.
- What is NOT sent to AI: Uploaded watch history, payment data, login credentials, OAuth tokens, phone numbers (redacted before analysis), or MMS media attachments.
2.4 Information Collected Automatically
- Usage data: Pages visited within the dashboard, features used, interactions with the Service.
- Device and browser information: Browser type, operating system, IP address, and device identifiers.
- Analytics: We use Google Analytics (GA4), Umami (self-hosted analytics), and Vercel Analytics to understand Service usage and improve the experience. See Section 8.2.
- Cookies and tracking: See Section 8.
2.5 Security and Audit Data
- Security event logs: Rate limiting events, authentication failures, CSRF violations, and access anomalies, logged with IP addresses and timestamps for security audit purposes.
- Audit trail: Account lockout events, administrative actions, and data access logs.
3. How We Use Your Information
We use your information to:
- Provide the monitoring Service: Sync, store, analyze, and display Observed User data to authorized guardians.
- AI content analysis: Analyze YouTube content and SMS messages to extract informational excerpts and flag potentially concerning content for parental review.
- Scam detection: Correlate call activity with browsing activity to detect and alert on potential phone-assisted scam scenarios.
- Process transactions: Manage your subscription, communicate billing status, and coordinate with Stripe (and, for subscriptions started before August 2026, Whop) for payment processing.
- Send notifications: Deliver email alerts for flagged content, scam detection events, device status changes, and account-related updates.
- Improve the Service: Analyze aggregated, de-identified usage patterns to improve features, performance, and user experience.
- Ensure security: Detect and prevent fraud, abuse, unauthorized access, and security incidents through rate limiting, input validation, and audit logging.
- Comply with legal obligations: Respond to legal processes, enforce our Terms, and protect rights and safety.
We do not:
- Sell your personal information to third parties.
- Use monitored data (SMS, YouTube, browsing, calls) for advertising or marketing.
- Use children's data for AI model training.
- Share data with data brokers.
4. How We Share Your Information
We share your information only in the following circumstances:
4.1 Service Providers (Data Processors)
| Provider | Data Shared | Purpose |
|---|---|---|
| Stripe, Inc. | Guardian email, subscription details, payment details you enter into Stripe's embedded payment field, parental-consent card authorization | Payment processing and parental-consent verification |
| Whop, Inc. | Subscription status, user email | Payment processing for subscriptions started before August 2026 (Merchant of Record) |
| Google (Vertex AI / Gemini) | YouTube content excerpts and family context; redacted message content if SMS analysis is enabled | AI content analysis (primary provider; the only provider for YouTube data) |
| Anthropic, PBC | Redacted message content if SMS analysis is enabled (never YouTube data) | AI content analysis for messages (alternative provider) |
| Google (YouTube Data API) | OAuth tokens, API requests | YouTube data sync |
| Google (Safe Browsing / Web Risk) | URLs visited | URL safety assessment |
| Cloudflare (R2) | MMS attachment files | Encrypted media storage |
| Neon (PostgreSQL) | All structured data | Database hosting |
| Vercel | Web application traffic | Application hosting |
| Resend | Guardian email addresses, alert content | Transactional email delivery |
| Inngest | Job metadata and account IDs; until our scheduled fix, some job results also include the child's name, email address, goals and interests, flagged video and channel titles with our AI observations, alert text, and guardian names and email addresses | Background job processing |
| Upstash (Redis) | Rate limiting tokens, IP hashes | Rate limiting and abuse prevention |
| Sentry | Error traces (PII scrubbed) | Error monitoring and diagnostics |
| Google Analytics (GA4) | Pages viewed, approximate location, device and browser type, referring site (via _ga cookies) | Usage analytics (Google Signals and advertising features disabled) |
| Umami, Vercel Analytics | De-identified usage and performance data | Analytics and experience improvement |
Our service providers are bound by contracts that limit their use of your data to providing services to us. Stripe and Whop process payment information as independent payment providers under their own terms (Whop as Merchant of Record for subscriptions started before August 2026). Google Analytics data is processed under Google's data processing terms with advertising features disabled.
4.2 Within Your Account (Guardian-Observed Data Sharing)
Observed User data (YouTube activity, SMS/MMS messages, call logs, browsing history) is visible to all guardians authorized on that Observed User's account. Shared guardian access allows multiple guardians to view the same Observed User's data.
4.3 Advertising
We do not run advertising within the Service, and we never use monitored data (YouTube activity, messages, call information, browsing activity, or uploaded watch history) for advertising of any kind.
4.4 Legal Requirements
We may disclose information when required by law, court order, subpoena, or governmental authority, or when we believe in good faith that disclosure is necessary to: protect our rights or safety; prevent fraud or abuse; investigate potential violations of our Terms; or protect the safety of any person.
4.5 Business Transfers
In connection with a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as a business asset. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
5. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
5.1 Right to Know
You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
5.2 Right to Delete
You may request that we delete the personal information we have collected from you, subject to certain exceptions (e.g., legal obligations, security, completing transactions).
5.3 Right to Correct
You may request correction of inaccurate personal information we maintain about you.
5.4 Right to Opt-Out of Sale/Sharing
We do not sell personal information and do not share personal information for cross-context behavioral advertising. There is no sale or sharing to opt out of.
5.5 Right to Limit Use of Sensitive Personal Information
The Service collects sensitive personal information as defined under CPRA, including: the contents of communications (SMS/MMS messages) and information about a known child. We use sensitive personal information only to provide the monitoring Service you have requested. We do not use sensitive personal information for purposes beyond what is necessary to provide the Service.
5.6 Right to Non-Discrimination
We will not discriminate against you for exercising your CCPA/CPRA rights.
5.7 Personal Information of Minors
We treat personal information of consumers under the age of 16 as sensitive personal information per the January 2026 CCPA regulation amendments. All processing of minors' data is governed by Section 12 (Children's Privacy) and is performed solely at the direction of their parent or legal guardian.
5.8 How to Exercise Your Rights
To exercise your rights, contact us at [email protected]. We will verify your identity before fulfilling requests. For requests regarding a child's data, we will verify that the requestor is the child's parent or legal guardian. We will respond within 45 days (extendable by an additional 45 days for complex requests).
Authorized agents: You may designate an authorized agent to submit requests on your behalf. We will require the agent to provide proof of authorization and may verify your identity directly.
6. Data Retention
| Data Type | Retention Period | Notes |
|---|---|---|
| Active account data | Duration of account | Deleted upon account closure |
| Observed User data (active) | Duration of monitoring relationship | Parent can delete anytime |
| Uploaded watch history | Duration of monitoring relationship | Deleted with the Observed Account (30-day soft delete, then purged) |
| Soft-deleted Observed Accounts | 30 days | Then permanently purged |
| Observed User data after a subscription lapse | 30 days from the lapse (from October 28, 2026) | Reminder sent a week before; parent may delete earlier; then permanently deleted |
| Post-account-deletion data | 30 days | Then permanently deleted or anonymized |
| Parental-consent records | 5 years after the Observed Account is deleted | Parent account, child account identifier, date, method, payment-authorization reference, and the versions of the consent notice and Privacy Policy shown, only; no child contact details are kept |
| Invites not accepted | 30 days after they are sent (from October 28, 2026) | Then deleted |
| Security audit logs | 1 year | Required for security compliance |
| Aggregated analytics | Indefinite | Fully de-identified, non-reversible |
| Payment records (via Stripe or Whop) | Per Stripe's or Whop's retention policy | We retain subscription status and customer identifiers only |
YouTube OAuth tokens are invalidated immediately upon disconnection of an Observed User's YouTube account. Device API tokens are invalidated upon device unpairing.
7. Data Security
Written information security program: Since October 6, 2026, we maintain a written information security program, as the FTC COPPA Rule requires (16 CFR 312.8), designed to protect children's personal information against unauthorized access, use, or disclosure. It names a program coordinator and is reviewed at least once a year.
We implement commercially reasonable technical and organizational security measures:
- Encryption in transit: All data transmitted over TLS 1.2 or higher.
- Encryption at rest: OAuth tokens encrypted with AES-256-GCM. Android local database encrypted with SQLCipher (256-bit AES). MMS attachments stored in encrypted Cloudflare R2 buckets.
- Access controls: Data access restricted to authorized guardians only.
- Rate limiting: Upstash Redis-backed rate limiting with in-memory fallback to prevent brute force, DDoS, and abuse.
- Security audit and auto-lockout: Automated detection of suspicious behavior with progressive account lockout (10 violations in 15 minutes = 30-minute lockout; 25 in 60 minutes = permanent lockout pending review).
- Android app security: Certificate pinning, code obfuscation (R8/ProGuard), encrypted local storage, device admin for tamper detection.
- Sentry error monitoring: PII scrubbed from all error reports (request bodies, auth headers, cookies stripped in beforeSend filter; 4xx client errors excluded).
No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. If we become aware of a security breach affecting your personal information, we will notify you in accordance with applicable law.
8. Cookies and Tracking
8.1 Essential Cookies
- Session cookies: NextAuth session management (required for login).
- CSRF tokens: Security tokens to prevent cross-site request forgery.
8.2 Analytics
- Google Analytics (GA4): Usage and traffic analysis. Sets
_gacookies and collects the pages you view, approximate location derived from your IP address, device and browser type, and the referring site. Google Signals and advertising features are disabled; not used for advertising. Google's handling of this information is described at https://policies.google.com/technologies/partner-sites. - Umami: Self-hosted analytics. No cookies, no personal data collection.
- Vercel Analytics: Aggregated page-performance metrics. No cookies.
8.3 Your Choices
You can control cookies through your browser settings. Disabling essential cookies may prevent you from logging in. Analytics cookies can be blocked without affecting Service functionality.
We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking for advertising, and we do not sell personal information or share it for cross-context behavioral advertising.
We do not respond to Do Not Track browser signals.
9. Third-Party Services and Links
The Service may contain links to third-party websites (e.g., YouTube videos, external URLs captured in browsing logs). We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you interact with.
Google API Services: Our use of information received from Google APIs (including YouTube Data API) adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use YouTube API data to provide the monitoring Service and do not use it for advertising, selling, or transfer to unrelated third parties.
10. International Data Transfers
Your information is processed and stored in the United States (AWS us-east-1 region via Neon, Vercel edge network, Cloudflare R2). If you are located outside the United States, your use of the Service constitutes consent to the transfer and processing of your information in the United States, which may have different data protection laws than your jurisdiction.
11. Your Rights and Choices
Regardless of your location, you may:
- Access and update your account information through the dashboard settings.
- Review monitored data for all Observed Users linked to your account via the guardian dashboard.
- Delete an Observed User's data by removing the Observed Account (enters 30-day soft-delete, then permanent deletion).
- Disconnect YouTube by unlinking the Observed User's YouTube account. OAuth tokens are immediately invalidated.
- Unpair devices to stop SMS/MMS and call monitoring. Device API tokens are immediately invalidated.
- Remove Browser Shield by uninstalling the extension to stop browsing and URL monitoring.
- Delete an uploaded watch history by removing the Observed Account.
- Delete your account by contacting [email protected]. All data is permanently deleted within 30 days.
- Request a data export by contacting [email protected].
- Opt out of marketing emails by clicking the unsubscribe link in any marketing email. Transactional emails (alerts, security notices) cannot be opted out of while your account is active.
12. Children's Privacy (COPPA)
YouGuard complies with the Children's Online Privacy Protection Act (COPPA) and the FTC's COPPA Rule. Because YouGuard is a parental monitoring tool, collection of children's data is integral to the Service and is always initiated and controlled by the child's parent or legal guardian.
12.1 Verifiable Parental Consent
We collect children's data only after their parent or legal guardian has:
- Authenticated with a Google account to create a guardian account.
- Affirmatively initiated the monitoring relationship (sent an invite, paired a device, installed Browser Shield, or uploaded a watch-history export).
- Agreed to our Terms of Service and this Privacy Policy.
For a child under 13, we require the parent to verify consent by completing a $0.50 charge on a credit or debit card through Stripe before the child's account or device can be connected. We refund the charge right away.
For a child under 13, we request read-only access to the child's YouTube account and do not take any action on that account (such as unsubscribing or removing likes).
12.2 What We Collect About Children
See Section 2.2 (Observed User Data). Data types depend on which monitoring features the parent activates.
12.3 How We Use Children's Data
Children's data is used exclusively to:
- Display monitored activity to authorized guardians via the web dashboard.
- Generate AI content analysis excerpts for parental review.
- Trigger alerts for flagged content, scam detection, or device status changes.
- Provide cross-channel scam protection (correlating call and browsing events).
We do not use children's data for: advertising, marketing, profiling, sale to third parties, AI model training, or any purpose unrelated to the parental monitoring Service.
12.4 Disclosure of Children's Data
Children's data is shared only with:
- The child's authorized guardian(s) via the dashboard.
- Service providers listed in Section 4.1, solely to operate the Service.
- Legal authorities when required by law.
12.5 Parental Access, Deletion, and Consent Revocation
Parents may at any time: review all collected data via the dashboard; delete data by removing the Observed Account; revoke consent by disconnecting YouTube, unpairing devices, or uninstalling Browser Shield; or contact [email protected] for data export or deletion. Upon consent revocation, collection from that source ceases immediately. Stored data is deleted when the parent removes the Observed Account (30-day soft delete, then permanent purge) or on request to [email protected].
12.6 Written Data Retention Policy
In compliance with the updated COPPA Rule (effective April 22, 2026): we retain children's data only as long as reasonably necessary to provide the monitoring Service to their parent. When monitoring ends, the child's data is deleted: when the parent removes the Observed Account, it is soft-deleted for 30 days and then permanently purged; from October 28, 2026, when the parent's subscription has lapsed, it is permanently deleted 30 days after the lapse, after a reminder to the parent a week before. We keep a record that parental consent was obtained (parent account, child account identifier, date, method, payment-authorization reference, and the versions of the consent notice and Privacy Policy shown) for 5 years after the child's Observed Account is deleted, to document compliance. That record contains no child contact details. We do not retain children's data for longer than the monitoring relationship requires.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If a change materially expands the personal information we collect, how we use or share it, or reduces your rights or choices, we will notify you by email or in-app notice at least 30 days before it takes effect, and the updated Policy will be posted at https://youguard.app/privacy with its new effective date. Corrections that make this Policy describe our existing practices more accurately, and changes that add protections or reduce what we collect, take effect when posted. Your continued use of the Service after a change takes effect constitutes acceptance of the revised Policy. If you do not agree, you must stop using the Service and may request account deletion.
14. Contact Us
For privacy-related questions, data access requests, or to exercise your rights:
YouGuard is operated by Daniel Swick, doing business as YouGuard.
Mailing address: 296 W Coshocton St, Johnstown, OH 43031
Telephone: (740) 403-9774
Email: [email protected]
Website: https://youguard.app
For COPPA-related inquiries or to exercise parental rights regarding your child's data, contact [email protected] with the subject line "COPPA Request."