Last updated: July 23, 2026
ChildLock is an iOS app that uses Apple's on-device Screen Time and FamilyControls frameworks to shield unapproved apps from your child, and to open a time-boxed viewing session of pre-approved YouTube channels curated by the ChildLock team. The blocking model runs entirely on-device — the list of "which apps to shield" never leaves your phone.
ChildLock collects only what is listed below, and nothing more.
api.childlock.xyz and childlock.xyz retain, for
30 days, the source IP address, the User-Agent header, the HTTP method,
the URL path, the response status, and the request timestamp of every
request. When a parent uses the "add channel from URL" flow, the URL
path on POST /catalog/lookup includes the normalized YouTube
handle the parent typed in. Logs are stored on our server and mirrored
to our Loki log store; both purge after 30 days.
We do not collect your name, email address, phone number, date of birth, Apple ID, or any account identifier. We do not use the AppTrackingTransparency framework and we do not request the IDFA. We do not access HealthKit, Contacts, Photos, Location, Camera, or Microphone. We do not register a push token. We do not run Sentry, Crashlytics, Firebase Analytics, Mixpanel, Amplitude, Meta / Facebook, TikTok, or any other third-party analytics / ad SDK.
When a parent pastes a channel URL to add it to the approved list,
ChildLock's server calls YouTube's public
channels.list endpoint with the handle to resolve the
channel ID. This call transmits only the handle to Google; the parent's
identity is never included. Resolved (handle → channelId) mappings are
cached in our database for 30 days to reduce upstream API calls; the
cached row contains only public YouTube metadata (channel handle,
channel ID, display name) — no personal information.
You have the right to (1) know what personal data we hold, (2) receive a copy, (3) correct inaccurate data, (4) request deletion, (5) restrict processing, and (6) object to processing. The only user-linkable data we hold about you is the IP address recorded in our server access logs (retained 30 days). A verified erasure request against a specific IP address is fulfilled by deleting the matching log lines.
To exercise any of these rights, email privacy@childlock.xyz.
ChildLock does not create user accounts and does not knowingly collect personal information from children. The app is rated 4+ on the App Store. Parents are the account holder; ChildLock does not sign the child in and does not store anything about them server-side.
Privacy: privacy@childlock.xyz
Support: help@childlock.xyz
Subscriptions: subscriptions@childlock.xyz
Postal: EpowerX Labs, Bangalore, India