Privacy Policy
Effective date: August 23, 2026 · Notice version: 1.2
1. Who We Are and What This Policy Covers
Girmanators LLC ("Girmanators," "we," "us") is a Maryland limited liability company. This Privacy Policy describes how we collect, use, and protect personal information when you use the Girmanators family and parental-controls service, including the girmanators.com website and web app and the Girmanators Android application (together, the "Service").
Girmanators is a family product: parents create and administer a family account, and children use the Service under profiles their parent creates and controls. Because the Service is designed in part for use by children, this Policy includes a dedicated section on children's privacy (Section 4).
2. Information We Collect
Information provided during account setup
- Parent account: parent first and last name, email address, and login credentials.
- Sign-in with Google or Microsoft (optional): if you choose to sign in with a Google or Microsoft account, we receive the basic identity information that service shares — your name and email address. We never receive your password for those services.
- Child profiles: child first and last name, timezone, and a parent-created login handle and PIN. Children do not provide an email address; an internal, synthetic address on a reserved domain is generated for system use only. A parent may optionally add a notification email, phone number, and profile photo for a child.
- Content you choose to upload, such as avatar photos and images for shop items, recipes, and family events.
Information collected from enrolled child devices
The following is collected only on a child device that a parent has explicitly enrolled and paired for parental controls, and only while the protection service is active. It is never collected on parent devices or unenrolled installs.
- Location. Precise device location (latitude/longitude/accuracy, with battery level), collected in the background — approximately every 5 minutes while the protection service runs, every 15 minutes via a scheduled worker, and when a parent requests a location update. Location is visible only to that family's parents.
- Installed apps. The list of apps installed on the enrolled child device is uploaded only as part of a parent-triggered diagnostics snapshot, held in server memory for no more than 5 minutes, and not persisted. The parent-chosen blocked-app list is stored.
- Diagnostics. Parent-triggered device diagnostics (permission status, battery, lock state, app version) and a parent-requested, size-capped device log excerpt.
- App usage (on device only). The child device detects which app is in the foreground in order to enforce blocking and lock schedules. This evaluation happens on the device; per-app usage history is not uploaded to our servers.
Information collected automatically
- Account and device identifiers: login handle, internal user ID, per-install installation ID, push notification token, and device model, name, and manufacturer.
- When you use the girmanators.com website: your IP address, browser type and operating system, and the pages and features you use. We use essential cookies and similar browser storage to keep you signed in and remember your preferences (including your analytics choice); analytics cookies are set only with your consent (see Section 5).
What we do not collect
- No payment card details — real-money payments occur on Stripe-hosted pages in your browser (Section 10). In-app balances are play-money ledger entries with no monetary value.
- No contacts, messages, SMS or call logs, health data, or browsing history.
- No advertising identifiers — the app contains no advertising SDK and does not request the advertising-ID permission.
3. How We Use Information
- To provide and operate the Service: accounts, family features, chores, rewards, calendars, and content you upload.
- To provide parental controls a parent has enabled: showing a child device's location to that child's parents, enforcing app blocking and lock schedules, and alerting parents to attempts to tamper with the controls.
- To deliver notifications you or your family have configured.
- To troubleshoot, secure, and improve the Service, including parent-requested diagnostics.
We do not use personal information for advertising, and we do not sell personal information. Data collected from child devices is used only for the parental-control features described above.
4. Children's Privacy
The Service is a mixed-audience product: parents administer it, and children use it under parent-created profiles. We design the child experience to minimize data collection:
- Children sign in with a parent-created handle and PIN; we do not collect a child's email address.
- Parental consent is obtained as part of family setup, before a child profile can be used, and before location or app-management features run on a child's device a parent must explicitly enroll that device.
- Parents can review their child's information in the family dashboard, export data, and delete a child profile or the entire account at any time (Section 8). Deletion permanently purges the child's records.
- Child data is never used for advertising or shared with third parties for their own purposes; social features are limited to the child's own family.
5. How Information Is Shared
We share personal information only with service providers that process it on our instructions to run the Service, and as required by law. We do not sell personal information or share it with third parties for their own marketing or advertising.
- Google Firebase Cloud Messaging — delivers push notifications to the app.
- Google Maps — renders the map in the parent's own dashboard view.
- Microsoft Azure Notification Hub — server-side notification delivery.
- Stripe — payment processing on Stripe-hosted pages (Section 10).
- Alpaca — provides market data and simulated (paper) trading for the Service's virtual, play-money investing feature. This runs server-side; users do not open brokerage accounts and no real securities are bought or sold for users.
Google Calendar (optional, parent-initiated)
If a parent chooses to connect their Google Calendar, we request read-only access (the calendar.readonly scope) and our server reads event details — title, description, date, time, and location — from the calendars that parent selects. We never create, edit, or delete anything in a user's Google Calendar. Only a parent can connect a calendar; child accounts cannot start this flow and we never receive Google data belonging to a child.
By default only the primary calendar syncs and the events are visible only to the parent who connected the account; they are shown to other family members only if that parent turns on "Share with family." Google Calendar data is displayed inside the Service only. It is not sold, not used for advertising, and not shared with third parties. A parent can disconnect at any time from calendar settings, which deletes the stored authorization tokens.
Girmanators' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google Analytics runs on the girmanators.com website only — it is not present in the Android app, it runs only if you accept analytics in our cookie banner, and it is never enabled for child users.
We may disclose information if required by law, subpoena, or to protect the rights, safety, or property of our users or others, and in connection with a merger, acquisition, or sale of assets, subject to this Policy.
6. Location Data
Location collection exists solely so parents can see where their enrolled child's device is. Before location reporting begins on a child device, the app presents a prominent disclosure and requests the Android location permissions, including background location. Location runs in the background because protection must continue while the device is locked or the app is closed. Parents can stop location collection at any time by disabling the feature, unenrolling the device, or uninstalling the app from the child device.
7. Data Security
All data is encrypted in transit using HTTPS/TLS; production endpoints accept no cleartext traffic. Device-to-server callbacks are additionally authenticated with signed (HMAC) requests. Access to personal data is limited to the family it belongs to and to administrative access needed to operate the Service.
8. Data Retention, Export, and Deletion
- Account data is retained while the account is active.
- A weekly retention job automatically purges location history older than 30 days, so historical location records are not kept indefinitely.
- Parent-triggered installed-app snapshots are ephemeral: held in server memory no more than 5 minutes and never written to storage.
- Deletion: a parent can delete a child profile or the entire account in the app (Admin → User Manager → Delete). Deletion permanently purges the owned records from our production systems immediately, and residual copies in encrypted backups are removed within 30 days. Instructions are also published at girmanators.com/account-deletion.
- Export: a parent can export the family's data from the app.
9. Your Rights and Choices
The Service is offered to users in the United States. Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing. The Service is administered from Maryland, and Maryland residents have rights under the Maryland Online Data Privacy Act. To exercise rights, use the in-app tools described in Section 8 or contact us at privacy@girmanators.com. We will respond within the time required by applicable law, and we will not discriminate against you for exercising privacy rights. If we decline a request, you may appeal by replying to our response with the word "Appeal," and we will reconsider and respond within 60 days.
Device-level choices: parents control the app's permissions through Android settings on their own devices; on an enrolled child device, permission changes are managed by the parent as part of the parental controls.
10. Payments
Premium subscriptions are purchased on pages hosted by Stripe, our payment processor, opened in your browser. We do not collect or store payment card numbers. Stripe's handling of your payment details is governed by Stripe's privacy policy. Our servers record subscription status and entitlements for your account. In-app currencies and balances are play money only — they have no cash value and are not financial accounts.
11. Changes to This Policy
We may update this Policy from time to time. The effective date and notice version above will change when we do, and for material changes we will provide notice in the app or by email, and where required obtain renewed consent from the parent account holder before the change applies to a family.
12. Contact Us
Girmanators LLC
2213 Newton Drive, Rockville, Maryland 20850
240-390-6376
privacy@girmanators.com (privacy requests) ·
support@girmanators.com (support)
Girmanators LLC · Rockville, Maryland · Delete your account