The short version: GuardianShield is a family protection service operated by First Love Movement. We collect the parent account, billing, device, notification, and operational data needed to run the service. Data handling varies by platform: for example, Android currently syncs blocked-domain and flagged-search events, while the audited iPhone/iPad code primarily sends device registration, setup, protection-status, and heartbeat data. We do not sell personal data or use GuardianShield data for advertising.
1. Who We Are
GuardianShield is a family digital protection service created and operated by First Love Movement (Team ID: USNJL2MZ9B). First Love Movement is the nonprofit organization behind GuardianShield and related family protection resources.
Contact: [email protected] · myguardianshield.org · firstlovemovement.com
2. Scope
This Privacy Policy applies to:
- The GuardianShield website and signup flow at myguardianshield.org
- The GuardianShield parent dashboard and web app at app.myguardianshield.org
- GuardianShield mobile and desktop software, setup packages, and companion apps for Android, iPhone/iPad, macOS, and Windows
- GuardianShield backend APIs, notification systems, support tools, and related service operations
3. Data We Collect
3.1 Parent account, authentication, and contact data
- Phone number - used for signup, login, account recovery, OTP verification, and alert delivery.
- Name information - we may collect first and last name when you provide them during signup, account setup, or dashboard use.
- Email address and timezone - we may collect these when you provide a notification email, additional recipient emails, or account preferences.
- Authentication and abuse-prevention records - hashed OTP codes, session records, remember-me preference, IP address, user-agent, and related security metadata.
3.2 Billing and subscription data
- Subscription and billing state - subscription status, pause/cancel/reactivation state, discounts, and related account lifecycle fields.
- Processor identifiers - Stripe customer and subscription IDs so we can manage billing and account access.
- Payment instrument handling - payment card details are processed by Stripe, Apple Pay, or Google Pay through Stripe; we do not store full card numbers ourselves.
3.3 Child profile and device registration data
- Child profile information - child name, age, platform target, and selected filtering tier.
- Device identifiers and setup records - device ID, install ID, enrollment or pairing tokens, profile tokens, device auth tokens or hashes, device name, platform, OS, and app version.
- Protection and status metadata - setup status, protection status, screen-time enabled status, last seen timestamps, online/offline state, access-revoked state, alert state, and tamper-risk metadata.
Data handling differs by platform and feature. In the current audited codebase, Android syncs blocked domains, flagged search queries, and protection alerts; the audited iPhone/iPad code primarily sends device registration, setup status, protection observations, and heartbeat events; and the desktop stack stores substantial filtering and audit state locally while also contacting remote services for PAC files, filter resources, DNS or proxy infrastructure, updates, and related setup assets.
3.4 Platform-specific activity, protection, and alert events
- Android - the current Android companion app records blocked domains, flagged search queries detected from monitored browser activity, DNS block events, heartbeat/protection status, and protection alerts, then syncs pending events to our backend. Specifically:
- Local VPN service — creates a device-local VPN tunnel to intercept and filter DNS queries. Blocked domain names are logged; allowed traffic is forwarded to a public DNS resolver (Cloudflare 1.1.1.1). No full browsing history or page content is captured.
- Accessibility service — monitors URL bar text in supported browsers (Chrome, Brave, Edge, Firefox, Opera, Samsung Browser) to detect search queries that match parental filtering rules. Only the matched search text and domain are recorded; no page content, form data, or passwords are accessed.
- HTTPS interception for search filtering — on supported devices, a user-installed CA certificate enables a device-local HTTPS proxy that can return a branded block page for filtered search queries on major search engines. The certificate is installed via the standard Android certificate-install prompt and operates only within the device-local proxy. No off-device traffic decryption occurs.
- Clipboard access — during initial device enrollment only, the app may read the device clipboard to detect a GuardianShield enrollment token. Clipboard content is checked once and is not stored, logged, or transmitted. This does not occur outside the enrollment flow.
- Overlay display — uses the "Display over other apps" permission to show a full-screen block page when harmful content is detected in a browser.
- iPhone and iPad - the current audited iPhone/iPad code sends device registration, setup progress, whether Screen Time is enabled during setup, protection-observation events, and heartbeat or tunnel lifecycle events.
- macOS and Windows - the current desktop stack stores filtering, audit, and child-profile data locally on device and contacts remote GuardianShield or network-filtering services for resources such as PAC files, filter lists, DNS, proxy, update, or setup content. Account-paired or managed desktop workflows may also process device and setup metadata.
- Parent dashboard and web app - the current web app can emit operational activation events such as child-add steps, install prompts, passcode events, trial start, and device activation confirmation.
3.5 Notification and communication preferences
- Notification email addresses - your primary notification email and any additional recipient emails you choose to add.
- Notification settings - quiet hours, summary cadence, timezone, urgent alert settings, tamper-alert channels, and marketing email preference.
- Push subscriptions - browser push subscription endpoints and cryptographic keys for parent alerts.
- Message delivery channel - whether a verification or alert flow uses SMS, WhatsApp, push, or email.
3.6 Support, operational, and technical data
- Support and account-access records - information you provide when contacting support or when account access is changed for billing or security reasons.
- Audit and event logs - operational logs, device events, alert history, and similar records used to keep the service working and investigate issues.
- Analytics and onboarding telemetry - the parent web app can forward activation and install lifecycle events to a configured GuardianShield analytics or warehouse endpoint.
3.7 What we do not collect in ordinary use
- We do not sell personal data.
- We do not use GuardianShield family data for advertising or behavioral ad targeting.
- We do not collect contacts, photos, text-message content, microphone recordings, or precise GPS location through GuardianShield apps.
- We do not store full credit card numbers or full payment instrument details on our own servers.
- We do not maintain a universal, click-by-click browsing history across every platform. However, some current features do send limited protection event data such as blocked domains, flagged search queries, setup state, heartbeats, and alert metadata.
4. How We Use Your Data
- To create, authenticate, and secure parent accounts
- To register devices, pair them to children, and guide setup across Android, iPhone/iPad, macOS, and Windows
- To operate content filtering, protection monitoring, tamper detection, and device-status reporting
- To send verification codes, alerts, summaries, and support messages
- To process subscriptions, billing, account access, cancellations, pauses, and reactivations
- To troubleshoot service issues, investigate abuse, and improve onboarding and product reliability
- To comply with legal obligations and protect our users, organization, and systems
We do not sell your data. We do not use GuardianShield family data for advertising. We share data only as described in Section 6.
5. COPPA Compliance (Children's Privacy)
GuardianShield is intended to be set up by a parent or legal guardian for a child's device. We collect child-profile and device information only to provide the service to the family account that enrolled the device.
Some current platform features, especially on Android, can transmit protection event data that may include blocked domains or flagged search queries associated with a child's device. We use that data only to operate filtering, alerts, and parent-facing status features, not for advertising.
We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information without parental consent, contact us at [email protected] and we will delete it promptly.
GuardianShield complies with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, and its implementing regulations.
6. Data Sharing
We share data only in these limited circumstances:
- Stripe - for subscription billing, payment processing, checkout, billing portal access, and related subscription records.
- Twilio - for SMS and WhatsApp verification or alert delivery where configured.
- Email providers - for support, verification, alerts, and summary delivery where configured in our current deployment.
- Push and browser delivery services - to deliver parent push notifications to subscribed browsers or devices.
- Content-filtering, DNS, proxy, and update infrastructure - including services used by the current codebase for PAC delivery, DNS filtering, proxying, or network safety infrastructure, such as GuardianShield-managed endpoints and providers like CleanBrowsing or Cloudflare-style DNS services.
- Hosting and infrastructure providers - for backend, web, storage, and operational service hosting.
- Operational analytics or warehouse endpoint - when the parent web app is configured to forward activation/install analytics to a designated ingest destination.
- Legal compliance and safety - if required by law, court order, or to protect rights, safety, or system integrity.
We do not share GuardianShield family data with advertising networks, and we do not use GuardianShield family data for targeted advertising.
7. Data Retention
We keep personal data for as long as reasonably necessary to operate the service, maintain security, meet legal obligations, resolve disputes, and enforce our agreements. Exact retention can vary by subsystem and data type.
- Short-lived security records - some OTP codes, authentication sessions, pairing sessions, and setup tokens expire automatically.
- Android local event storage - in the current Android code, synced flagged events are pruned locally on a rolling basis after a short retention window.
- Account, billing, audit, notification, and support records - may be retained while your account is active and for a reasonable period afterward for security, accounting, legal, and operational needs.
You may request deletion of GuardianShield data associated with your account by emailing [email protected] or visiting our account deletion page. We will review requests and respond in accordance with applicable law and our operational requirements.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Withdraw consent (which may require account cancellation)
- Update notification email, push, quiet-hours, and marketing preferences
To exercise any of these rights, email [email protected].
9. Security
We use reasonable technical and organizational safeguards, including TLS for supported network traffic, hashed or tokenized security secrets where applicable, and access controls for service infrastructure. Some device-side data is also stored locally on the protected device or parent device.
No internet transmission is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.
10. Third-Party Links
Our website may contain links to other First Love Movement web properties as well as third-party services. Pages on firstlovemovement.com may have their own website notices or policies, and external services such as Stripe or social networks are governed by their own privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of GuardianShield after changes are posted constitutes acceptance of the updated policy.
For material changes, we will notify you via the phone number associated with your account.
12. Contact
Questions about this Privacy Policy? Contact us:
- Email: [email protected]
- Website: myguardianshield.org
- Parent organization: firstlovemovement.com
- Organization: First Love Movement · Team ID USNJL2MZ9B