ChildLock

Privacy Policy

Last updated: August 3, 2026

1. Introduction

ChildLock is a parental-control app for iPhone operated by EpowerX Labs Private Limited ("EpowerX", "we", "us"). A parent blocks the apps their child shouldn't open and approves the video channels their child may watch. This policy explains what the ChildLock app and the childlock.xyz website handle. The short version: we require no account for parents, and the identities of the channels your kid watches and the play state stay on your device.

2. Data we do not collect

If you contact support, we receive the email address and information you choose to include in your message so that we can respond.

3. On your iPhone

ChildLock uses Apple's Screen Time technology (the FamilyControls, Managed Settings, and Device Activity frameworks) to shield apps you have not approved. The apps you select are represented by opaque tokens that Apple's frameworks process entirely on-device — ChildLock never sees or transmits app names. The curated channel catalog is fetched from api.childlock.xyz without any per-user identifier. Your kid's watch history, focus sessions, and profile details are stored in a local database on the phone (on-device, never uploaded). Purchase state is handled by RevenueCat under an opaque customer ID (see section 5).

4. Website analytics

When you visit childlock.xyz, the site records one website_page_viewed event for the page load. When you select the site's download call-to-action (currently an email link), it records a website_app_store_clicked event. These events include only: the page path and title, the App Store link location, the referring domain (not the full referring URL), and any utm_source, utm_medium, utm_campaign, utm_content, or utm_term campaign values in the landing URL.

The site creates a random pseudonymous identifier in memory for each page load so that an App Store click can be associated with the page view that preceded it. The identifier is discarded when the page closes or reloads. We do not use analytics cookies, local storage, session storage, or tracking pixels. Our server necessarily receives your IP address while handling the request; the analytics pipeline uses only a temporary, process-specific one-way hash of that address for abuse rate limiting — the raw address is never stored in the analytics event, and the hash salt regenerates every server restart. Global Privacy Control and browser Do Not Track signals disable this collection entirely.

Separately from analytics, our web server keeps standard operational access logs — source IP address, browser user agent, request path, and timestamp — used only for security, abuse prevention, and troubleshooting. These logs are retained for 30 days and then deleted; they are never joined to analytics events, used for profiling, or shared with third parties. A verified erasure request against a specific IP address (see section 8) is fulfilled by deleting the matching log lines.

5. Purchases

ChildLock subscriptions are processed by Apple through the App Store. We never see your payment-card or bank details. RevenueCat processes purchase history, product and store information, purchase status, price and currency, country, transaction identifiers, and a pseudonymous RevenueCat App User ID to deliver, validate, and restore your subscription. See RevenueCat's privacy policy.

6. Children's privacy (COPPA and Apple kids-category rules)

ChildLock is built for children to use under a parent's control, and we take COPPA and Apple's guideline 5.1.4 obligations seriously. No data about your child is collected server-side. The parent is the only person we transact with. The age-band selection made during setup is a local classifier used to curate the suggested-channels feed on-device; it is never transmitted together with any identity. Your child's watch activity, session history, and profile stay on the phone. We do not knowingly collect personal information from children, we show no ads to children, and there are no third-party analytics or tracking beacons in the child-facing experience.

7. Third parties

8. Your rights

Email privacy@childlock.xyz for access, correction, or deletion requests. Under the GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection. Under the CCPA you have the right to know, the right to delete, and the right to opt out of the sale of personal information — the last is inapplicable because we do not sell data. Because ChildLock has no accounts and the website analytics carry no personal identifiers, in most cases there is nothing server-side to link to you; we will still investigate every request.

9. Data retention

Website analytics events are retained for at most 12 months in our self-hosted OpenPanel and contain no personally identifiable information — there is nothing to erase that identifies you. Web-server access logs (section 4) are retained for 30 days. Data on your iPhone is deleted when you delete the app. RevenueCat and Apple retain purchase records under their own policies and applicable legal obligations.

10. Changes to this policy

If we change this policy, we will post the updated version on this page and update the "Last updated" date above. If a change is material and the app is installed, we will surface it via an in-app notice.

11. Contact

Privacy, GDPR, CCPA, copyright, and DMCA notices: privacy@childlock.xyz

EpowerX Labs Private Limited
Plot No. 77, JBR Tech Park, 6th Rd
Whitefield, EPIP Zone
Bangalore, Karnataka 560066
India

12. Summary of what leaves your device

Catalog fetches (no per-user ID), subscription state (opaque RevenueCat customer ID), and — only if you browse childlock.xyz — the two website events in section 4. Everything else, including everything about your child, is on-device.