What does it actually collect? How to check for yourself.
A parental control app sits between your child and the internet, which makes it one of the most sensitive pieces of software you will ever install. Very few parents read what it does with what it sees. Here's how to check any of them in about ten minutes.
We're not going to publish a table of what each named competitor collects. Privacy policies get revised, and a table like that is wrong the week after it's written — you'd be trusting a snapshot of somebody else's document. The method below stays accurate, and you can run it on us as easily as on anyone.
Why this matters more than it sounds
Consider what a monitoring app can hold: every site your child visited, every search, message content, screenshots, location history, and app usage by the minute. Aggregated over years, that's a more detailed record of a child's inner life than any other document that will ever exist about them.
The questions worth asking about that record:
- Who can read it?
- How long is it kept?
- What happens to it if the company is acquired?
- What happens if it's breached?
- Does your child, as an adult, have any say over it?
Children's data has been breached before, including from companies whose entire product was child safety. This isn't hypothetical.
The ten-minute audit
Step 1: Read the app store data disclosure first
Before the privacy policy, check the store listing. Apple's App Privacy section and Google Play's Data safety section are standardised, structured, and much faster to read than a policy.
Look for three things:
- Data linked to you — tied to an identity rather than anonymous.
- Data used to track you — the serious one. This means shared with third parties for advertising or brokerage.
- Browsing history, search history, messages, photos in the collected list.
If a child-safety app declares data used to track you, that answers the question and you can stop there.
Step 2: Search the privacy policy for six phrases
Open the policy and use find. These six do most of the work:
- "third part" — catches "third party" and "third parties". Read every occurrence. This is where sharing is disclosed.
- "affiliates" — often means the wider corporate group, which can be large and unnamed.
- "business partners" — frequently a euphemism for commercial data sharing.
- "aggregated" or "de-identified" — data described this way often falls outside the policy's own restrictions, and re-identification of behavioural data is well documented.
- "merger" or "acquisition" — almost every policy says data transfers with the company. Ask yourself whether you'd consent to the buyer, whoever that turns out to be.
- "retention" or "how long" — a policy with no stated retention period effectively means indefinitely.
Step 3: Ask the five questions
If the policy doesn't clearly answer these, that's your answer:
- Is browsing history stored on a server, or only checked on the device? Enormous difference. On-device checks leave nothing to breach.
- Is message content ever transmitted or stored? Not "analysed" — stored.
- Is location continuous or on-demand? Continuous location history is one of the most sensitive datasets that exists about a person.
- What's the retention period, in days? A specific number is a good sign. Silence is not.
- Can you delete everything, and does deletion mean deletion? Look for whether backups and de-identified copies are excluded.
Audit us with the same checklist
Defenras collects no browsing data, no message content, and no background location. Run the checks below on us.
Get Defenras free →What the answers mean
| If the policy says | What that means in practice |
|---|---|
| "We may share with third parties for marketing" | Your child's data is a revenue line |
| "Aggregated and de-identified data may be sold" | Behavioural data, frequently re-identifiable |
| "Data may transfer in an acquisition" | Standard, and worth noting you can't vet the buyer |
| "We retain data as long as necessary" | No stated limit — assume indefinitely |
| "We do not sell personal information" | Check the definition of "sell" — sharing often isn't covered |
| No server-side storage of browsing data | Nothing to breach or subpoena. The strongest answer available |
The structural point
The most useful question isn't what a company promises. It's what its business model requires.
- A free app from a company that sells nothing else must monetise something. In this category, the data is usually the only asset.
- A monitoring product has to collect activity — that's the product. Detailed reports are impossible without a detailed record.
- A filtering product doesn't need to store anything. Checking a domain against a blocklist requires no history.
This is why filtering and monitoring have such different privacy profiles. It isn't that filtering companies are more principled — it's that filtering doesn't require the data in the first place.
Also worth checking
- Where is the data stored? Jurisdiction determines who can compel access.
- Is there a children's privacy section? COPPA in the US, GDPR-K in the EU. Its absence in a product for children is a real signal.
- Has the company been breached? Search the company name with "breach" and "data leak". Several in this category have been.
- Is there a security page? Encryption in transit and at rest, and whether an independent audit has been done.
- Who owns it now? Several well-known parental control brands have changed hands, and the policy under the new owner may differ from the one that earned the reviews.
Our own answers
It would be poor form to publish this and not answer it ourselves. Run the checks above against our privacy policy:
- Browsing history: not collected. Filtering is a blocklist check at DNS resolution — we don't record which domains were requested, on the device or on our servers.
- Message content: never accessed, transmitted, or stored. We have no message-reading feature.
- Screenshots: never taken.
- Location: on-demand only. Your child can send their current location, or trigger the panic button, and we email it to you. There is no background or continuous tracking — the app has no always-on location service. Location history is stored on your child's phone and is never uploaded to us; the only coordinates that reach our servers are the ones attached to a location send or a panic alert, which are emailed to you and not retained as a history.
- Third-party sharing: no browsing or activity data is shared, sold, or licensed — there isn't any to share.
- What we do hold: account email, subscription status, device enrollment, and your blocklist configuration. That's what's needed to run the service.
This design has a real cost, and we'd rather name it than let you discover it later. Because we don't collect browsing data, we cannot show you activity reports. No "sites visited this week", no search history, no per-app usage breakdown. If that visibility is what you're looking for, a monitoring product will serve you better and we'd rather you bought one.
What we'd say for our side of it: with a teenager, the visibility usually costs more than it returns. A teen who knows they're read routes around you, and the early warning that actually matters is them choosing to tell you. But that's a judgement about parenting, not a technical fact, and it's yours to make.
Frequently asked questions
Why won't you just publish what each competitor collects?
Because privacy policies change, and a table like that would be out of date within weeks. The audit method above stays accurate and you can run it on any product, including ours.
What's the fastest single check?
The app store data-safety disclosure. It's standardised and takes a minute. If a child-safety app declares data used to track you, that's your answer.
Is 'de-identified' data safe?
Less risky than identified data, and not risk-free — re-identification of behavioural datasets is well documented. Treat clauses that exempt de-identified data from the rest of the policy as meaningful.
What does Defenras collect?
Account email, subscription status, device enrollment, and your blocklist configuration. No browsing history, no message content, and no screenshots. Location is on-demand only — sent when your child shares it or triggers the panic button — and the location history stays on their phone rather than on our servers.
Defenras blocks all of this — without collecting your child's data.
One app, every device, every browser. Adult content, gambling, vaping, scams, malware, social media — all blocked. PIN-locked. Free version available, no credit card.