Skip to content

Privacy Policy and Personal Data Processing Policy

Version of 21 September 2026. Effective from 21 September 2026.

1. Scope of this Policy

1.1. This Policy explains what personal data we process in connection with the Kid Security and Tigrow service, why we process it, whom we share it with, how long we keep it and what rights you have.

1.2. The service consists of the Kid Security application installed on the device of a parent or another person holding parental responsibility, the Tigrow application installed on the child device, and the website at kidsecurity.org.

1.3. This Policy applies to users in the European Economic Area and, unless a separate local version applies, to users in other countries. Where this Policy refers to the GDPR, it means Regulation (EU) 2016/679.

1.4. This Policy is not a contract and does not constitute your consent. Where consent is required, we ask for it separately in the application, before the relevant processing starts.

2. Who is responsible for your data

2.1. The controller is Kid Security Limited, business identification number 200340900118, registered at 34B Turkestan Street, unit 1, Astana, Republic of Kazakhstan.

2.2. For users located in the Russian Federation, Kid Security LLC (OGRN 1247700760801, Moscow, Russian Federation) acts as controller in respect of the account, subscription and payment data. Each controller determines the purposes and means of processing within its own part and is responsible to you accordingly.

2.3. You may contact us on any matter concerning your data, including to exercise your rights, at support@kidsecurity.net.

3. Personal data we process

3.0. We obtain personal data from the user, from the parent device and from the child device, and we receive information about payments from payment service providers. We do not collect personal data from other sources.

3.1. Data provided by the parent: telephone number and email address; information about subscriptions purchased and payments made; settings selected in the application, including places on the map for which arrival and departure alerts are enabled; messages sent in the family chat; and the content of support requests.

3.2. Data collected from the child device: the name or nickname given to the child by the parent, the child age and, where the parent adds one, a profile picture; location data (latitude, longitude, timestamp, speed, accuracy, source and bearing) and location history; movement data recorded by device sensors, including step count and the recognised type of activity; the names of installed applications and the time spent using them; device status information such as battery level, power saving mode and sound settings; information about the device and its operating system; the status of permissions granted to the application; messages in the family chat, including voice messages; sound recorded around the device at the request of the parent as described in section 5; and images added by the child when using certain features.

3.3. Technical data collected automatically: application and device identifiers, application version, operating system, language and time zone, IP address and the country derived from it, records of errors and crashes, and information about interaction with screens and features of the application.

3.4. On Android devices the Tigrow application uses the accessibility service and notification access in order to collect application usage statistics, to keep the features working and to show the parent the child’s correspondence in messaging applications. We collect the names of applications, the time spent using them and the content of the correspondence.

3.5. We do not access contacts, call logs or SMS messages on the child device and we do not record telephone calls. We do not process health data, biometric data or data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs. Photographs and voice recordings are not used to identify a person.

3.6. We do not use artificial intelligence features in the service. The content of messages, images and sound recordings is not analysed automatically, and we do not build profiles in order to predict the behaviour of users. If such features are introduced, this Policy will be amended before they begin to operate and, where the law so requires, separate consent will be requested.

3.7. The type of activity of the child (walking, running, cycling or travelling by vehicle) is determined automatically from the readings of the device sensors. This determination is indicative only. It is not a medical or diagnostic assessment, it is not used to evaluate the personal qualities of the child, and it produces no legal effects for the child or for the parent.

4.1. We process the personal data of the parent in order to perform the contract concluded by accepting the Terms of Use, which is the legal basis under Article 6(1)(b) GDPR. Without this data an account cannot be created, a subscription cannot be managed and the service cannot be provided.

4.2. We process the personal data of the child on the basis of the consent given by the holder of parental responsibility, in accordance with Article 6(1)(a) and Article 8 GDPR. Consent is requested separately from the Terms of Use and from this Policy, before the child device is connected, and may be withdrawn at any time.

4.3. Product analytics and messages about discounts and special offers are based on your separate consent. Refusing or withdrawing such consent does not affect your access to the service.

4.4. To the extent necessary to keep the service secure, prevent abuse and ensure that the applications work correctly, we rely on our legitimate interests under Article 6(1)(f) GDPR. This processing is limited to technical data and is not used to build a profile of a user.

4.5. Where the law requires us to keep records, in particular accounting and tax records, we process data on the basis of Article 6(1)(c) GDPR.

5. Sound transmission feature

5.1. The feature allows the parent, at the parent’s own request, to hear the surroundings of the child device. It exists so that a parent can check that the child is safe.

5.2. The feature is activated only on request and does not run continuously. A single recording lasts no longer than 20 minutes. Covert listening is not provided for by the service.

5.3. While the feature is active, the child device displays an active microphone indicator and a notification. Neither can be disabled or hidden through the service.

5.4. Recordings are kept for 30 days and are then deleted automatically. The parent may delete a recording earlier in the application and may also save it to their own device. A saved recording is no longer under our control and the parent is responsible for its further use.

5.5. Other people may be captured by a recording. A parent who uses the feature must respect their rights. Recording and disseminating the speech of persons who have not consented is prohibited in most jurisdictions and may give rise to criminal liability. The corresponding obligation of the parent is set out in the Terms of Use, and a warning is displayed before the feature is used for the first time.

6. Children

6.1. An account may be created only by an adult. By creating an account and connecting the child device, the user confirms that they are a parent of the child or otherwise hold parental responsibility and is entitled to consent to the processing of the child personal data.

6.2. The child data is processed solely on the basis of the consent of the holder of parental responsibility. The Tigrow application must not be used in relation to a device of a person for whom the user does not hold parental responsibility.

6.3. Article 8 GDPR allows Member States to set the age at which a child may consent on their own behalf at between 13 and 16 years. Below that age the processing of the child data is based on the consent of the holder of parental responsibility, which the service requires in every case. Where the child has reached that age, we also ask for the child’s own consent.

6.4. The holder of parental responsibility may at any time review the child data in the application, correct it, switch individual features off, withdraw consent and request erasure.

7. Recipients

7.1. We do not sell personal data and we do not share it with advertising networks or data brokers for their own purposes. No third party analytics or advertising tools are integrated into the Tigrow application installed on the child device.

7.2. We use service providers who process personal data on our instructions, for our purposes only, under a contract that allows them to use the data only for the services they provide to us. They include providers of cloud infrastructure and storage, product analytics and advertising measurement, push notification delivery, technical diagnostics, subscription management and payment processing. The subscription management provider also receives a telephone number and an email address where these are entered for payment. A list of the processors acting on our instructions is provided on request at the address given in section 2.3.

7.3. Analytics and marketing services are activated only after the user has given the relevant consent. If consent is not given, they are not initialised and no data is sent to them. Refusing consent does not affect the operation of the service.

7.4. Data that identifies the child is not transmitted to external services. The content of family chat messages, sound recordings, photographs and the location data of the child are not transmitted to those services.

7.5. We disclose data to public authorities only where a lawful and duly issued request is made and only to the extent covered by that request.

8. Where data is stored

8.1. Personal data of users located in the Russian Federation is recorded and stored in a database located in the Russian Federation, as required by Russian law.

8.2. Personal data may be transferred to service providers located in other countries, including outside the European Economic Area. Such transfers take place under the appropriate safeguards required by applicable law.

8.3. A copy of the safeguards applied may be requested at the address given in section 2.3.

9. Retention

9.1. We keep personal data no longer than is necessary for the purposes for which it is processed, unless a longer period is required by law or is necessary for the establishment or defence of legal claims.

9.2. Account data, including child profiles, is kept for as long as the service is used and is deleted within 30 days after the account is deleted. Recordings of sound around the child device are kept for 30 days. Text messages in the family chat are kept for 365 days and voice messages for 90 days. Location data, movement data and application usage statistics are kept while the corresponding feature is in use and are deleted when it is switched off or when the account is deleted. Records of payments are kept for the periods required by accounting and tax legislation. Support correspondence is kept for no longer than three years after the last message.

9.3. We stop processing when the purpose has been achieved, when consent is withdrawn where the processing was based on consent, or where we establish that processing has been unlawful. The data is then erased or anonymised, unless its retention is required by law or is necessary for the establishment, exercise or defence of legal claims.

10. Your rights

10.1. You have the right of access to your personal data, the right to rectification, erasure and restriction of processing, the right to data portability, the right to object to processing based on our legitimate interests, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

10.2. We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.

10.3. To exercise your rights, write to support@kidsecurity.net from the email address or telephone number registered in your account. We reply within one month of receipt, and where the request is complex we may extend that period by up to two further months and will inform you of the extension and of the reasons for it.

10.4. You may delete your account yourself in the Kid Security application in the settings section, or request deletion without installing the application by writing to support@kidsecurity.net. Deleting the account removes child profiles, location and movement history, recordings, chat messages and usage statistics. Data that must be retained by law, in particular payment records, is kept for the statutory period.

10.5. You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.

10.6. The right to obtain a copy of personal data may not adversely affect the rights and freedoms of others. Where a request concerns a child connected to your account, we provide the information relating to that child and do not disclose information about other individuals whose voices may have been captured in a sound recording or who are mentioned in messages.

11. Security

11.1. We take technical and organisational measures appropriate to the risk. Employee access to user data is granted on a need to know basis, and our support staff have no access to the content of family chat messages. Data in transit is protected by encryption.

11.2. Where a personal data breach occurs, we notify the competent supervisory authority within 72 hours of becoming aware of it, and where the breach is likely to result in a high risk to your rights and freedoms we also inform you.

12. Cookies and the website

12.1. The website uses cookies, and those that are strictly necessary for the website to function are used without consent. Analytics and other non-essential cookies are used only after you have given consent through the cookie banner, and you may refuse them or change your choice at any time.

12.2. The categories of cookies used, their purpose and their lifespan are described in the cookie banner.

13. Messages we send

13.1. Service messages, such as payment confirmations, subscription renewal and expiry notices, notices of changes to the service and alerts generated by features you have enabled, are sent as part of the performance of the contract.

13.2. Messages about discounts and special offers are sent only with your separate consent. You may opt out in the application settings or through the link contained in the message, and the opt out takes effect immediately.

14. Changes to this Policy

14.1. We may amend this Policy. A new version is published on the website and in the applications, stating the date from which it takes effect.

14.2. Where amendments materially affect the categories of data processed or the purposes of processing, we inform you in advance and, where the law so requires, ask for new consent.

14.3. Previous versions are retained and are made available on request.

15. Details of the controllers

15.1. Kid Security Limited, business identification number 200340900118, 34B Turkestan Street, unit 1, Astana, Republic of Kazakhstan, email support@kidsecurity.net.

15.2. Kid Security LLC, INN 7720940949, OGRN 1247700760801, 5 building 40 unit 34/3, 2-ya Entuziastov Street, Moscow 111024, Russian Federation, email support@kidsecurity.net.