Legal

Privacy Policy

Last updated: June 20, 2026

Cylux is a parental control and child safety platform. We take the privacy of both parents and children extremely seriously. This policy explains in detail what data we collect, why we collect it, who we share it with, how long we keep it, and how we protect it. We never sell your data. We are fully compliant with COPPA, GDPR, and CCPA/CPRA.

1. Who We Are

Guardian Systems Inc., trading as "Cylux" ("we", "us", or "our"), operates the Cylux parental control and child safety platform. Our platform includes the Cylux Parent mobile app (iOS & Android), the Cylux Child mobile app, device monitoring agents for Fire TV, Google TV / Android TV, Windows, Roku, and browser extensions, and the web dashboard at cylux.co. Cylux is designed to help parents and legal guardians monitor and manage their children's digital activity across multiple devices and platforms. We are committed to protecting the privacy and security of every user — both parents and the children they monitor. Company address: Guardian Systems Inc., 535 Mission Street, San Francisco, CA 94105, United States.

2. Scope of This Policy

This Privacy Policy applies to all personal data collected through: • The Cylux website at cylux.co • The Cylux Parent mobile application • The Cylux Child mobile application • Device monitoring agents (Fire TV, Google TV, Android TV, Windows, Roku, browser extensions) • The Cylux web dashboard • Any communication between you and Cylux (email, support tickets, contact forms) By creating an account, installing any Cylux application, or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please do not use our services.

3. Data Controller & Data Protection Officer

Guardian Systems Inc. is the data controller responsible for the personal data processed through the Cylux platform. Data Protection Officer (DPO): Email: dpo@cylux.co For general privacy inquiries: Email: privacy@cylux.co EU/EEA Data Protection Representative: Email: eu-privacy@cylux.co We have appointed a Data Protection Officer to oversee compliance with applicable data protection legislation. You may contact our DPO at any time regarding questions or concerns about how we handle your personal data.

4. Personal Data We Collect

We collect different categories of data depending on how you interact with our platform. 4.1 Parent Account Data When you create a parent account, we collect: • Full name • Email address • Encrypted password (hashed using bcrypt; we never store plaintext passwords) • Subscription and billing information (processed securely by Stripe — we never store raw payment card numbers, CVVs, or full card data on our servers) • Device identifiers associated with your parent app installation 4.2 Child Profile Data When you set up a child profile, we collect: • Child's first name (or nickname) as provided by the parent • Device identifiers for enrolled devices • Device type, operating system, and model information 4.3 Device Monitoring Data When a child's device is enrolled, we collect the following data from that device on behalf of the parent: • App usage events — app name, package name, open/close timestamps, and total time spent per app per day • Screen time — total active screen time per day, measured via OS-level usage APIs • Web activity — domain names visited and domains blocked (we do not capture full URLs, page content, form inputs, or search queries) • Content detection — titles of media content played on streaming apps (e.g., Netflix, YouTube, Disney+), detected via accessibility services or media session APIs • GPS location — coordinates updated periodically while the device is active (frequency depends on plan tier) • Device status — battery level, network connectivity, compliance state, and last-seen timestamp • Installed applications — package names and app names for app management features • Notification content (Android, optional) — when the parent enables Notification monitoring, the text of notifications the child's device receives is captured so the parent can review it. Because some apps surface message previews inside notifications, this text can include excerpts of messages from third-party apps. This requires the parent to grant Notification Access on the device and can be turned off at any time. The Cylux Child app distributed through the Google Play Store does NOT access SMS messages, call logs, or contacts. A separate enterprise/sideloaded edition (never distributed through Google Play) may offer call-log and SMS monitoring where the parent enables it and where permitted by applicable law; that edition is covered by the same protections described in this policy. 4.4 Communication Data When you contact us via email, support tickets, or our website contact form, we collect: • Your name and email address • The content of your message • Any attachments you provide 4.5 Website Analytics Data We collect anonymized, aggregated analytics data when you visit cylux.co: • Pages visited, referral source, and session duration • Browser type, operating system, and screen resolution • Approximate geographic location (country/region level, derived from IP — we do not store your IP address in analytics) This data is collected via Google Analytics and cannot be used to identify individual users.

5. How We Use Your Data

We use the personal data we collect strictly for the following purposes: • Providing the service — Delivering real-time monitoring, screen time management, content filtering, app management, and location tracking features to the parent account holder • Account management — Creating and managing your parent account, authenticating logins, and processing subscription payments • Notifications and alerts — Sending activity reports, security alerts, screen time warnings, content alerts, and service notifications to the parent • Customer support — Responding to inquiries, troubleshooting issues, and providing technical assistance • Service improvement — Analyzing anonymized, aggregated usage patterns to improve platform performance, fix bugs, and develop new features • AI safety insights — When you use Cylux's optional AI insight features, concise summaries of the monitored activity are sent to our AI processor (Anthropic) to generate plain-language guidance for you. This data is processed only to produce your insights and is not used to train AI models. • Legal compliance — Complying with applicable laws, regulations, and valid legal processes We do NOT use your data for: • Advertising or ad targeting • User profiling for marketing purposes • Sale or rental to any third party • Training machine learning models on identifiable personal data • Any purpose unrelated to the Cylux parental control service

7. Children’s Privacy & COPPA Compliance

Cylux is a parental control platform designed to be used by parents and legal guardians to monitor their children's devices. We take the privacy of children extremely seriously. 7.1 COPPA Compliance We comply fully with the Children's Online Privacy Protection Act (COPPA): • Children do not create accounts with Cylux and do not interact with our service directly • All monitoring data is collected on behalf of, and accessible only to, the verified parent or guardian who owns the account • We do not knowingly collect personal information directly from children under 13 • Parents have full control over what data is collected and can delete their child's profile and all associated data at any time 7.2 Parental Consent By enrolling a child's device with Cylux, the parent or legal guardian provides verifiable parental consent for the collection of monitoring data from that device. The parent can review, modify, or delete this data at any time. 7.3 Data Minimization for Children We apply the principle of data minimization to all child-related data: • We only collect data that is necessary for the monitoring features the parent has enabled • We do not read SMS messages or call logs on the Google Play edition of the app, and we never read the full contents of your child's online accounts. However, if you enable Notification monitoring on Android, the text of notifications (which some apps use to show message previews) is captured so you can review it — you can turn this off at any time • We do not record audio or video from any device • We do not capture screenshots of the child's device • Web activity logging captures domain names only — not full page URLs, search queries, or page content 7.4 Reporting If you believe we have inadvertently collected personal information from a child without proper parental consent, please contact us immediately at privacy@cylux.co. We will investigate and delete any such data within 48 hours.

8. Disclosure & Transparency to Monitored Users

We believe in transparency. While Cylux is managed by parents, we strongly recommend — and in some jurisdictions it may be legally required — that parents inform their children that monitoring software is installed on their devices. • Our Terms of Service require that parents disclose the use of Cylux to their children in an age-appropriate manner • On enrolled devices, the Cylux monitoring agent is visible in the app list and is not designed to operate covertly • Cylux is intended exclusively for monitoring minor children under the parent's or guardian's legal care — using Cylux to monitor adults without their knowledge or consent is a violation of our Terms of Service and may violate applicable law

9. Data Sharing & Third-Party Processors

We share personal data with trusted third-party service providers only as necessary to operate and improve the Cylux platform. All third-party processors are contractually required to protect personal data and use it only for the purposes we specify. 9.1 Service Providers • Stripe (Payment Processing) — Processes subscription payments. Stripe is PCI-DSS Level 1 certified. We share only the data necessary to process transactions (email, subscription tier). We never transmit or store raw card data on our servers. • Render & Supabase (Cloud Hosting & Database) — Render hosts our application servers and Supabase provides our managed PostgreSQL database. All data is encrypted at rest (AES-256) and in transit (TLS 1.3) and is stored in United States data centers. • Firebase / Google Cloud (Push Notifications) — Delivers real-time push notifications to parent and child devices. Notification payloads contain minimal identifiers; sensitive content is encrypted end-to-end. • SendGrid (Email) — Delivers transactional emails including account notifications, activity reports, and security alerts. Email addresses and message content are shared only as needed for delivery. • Anthropic (AI Safety Insights) — Powers our optional AI insight features. When you request an insight, we send concise, purpose-limited summaries of the monitored activity to Anthropic to generate guidance text. Anthropic processes this data solely to return your result and does not use Cylux data to train its models. • NextDNS (Web & Content Filtering) — Cylux uses NextDNS to filter unsafe websites and content across a child's device and your home network. When a NextDNS profile is connected, the device's DNS queries are resolved and logged by NextDNS on that profile. We use its API (with the profile/API key associated with your account) to: (a) sync the block/allow domain lists and parental-control categories you choose in Cylux (e.g. adult content, gambling, SafeSearch, YouTube Restricted Mode), and (b) read the profile's query logs to show you blocked-site and streaming-activity history. On iOS this DNS-layer filtering is the primary way third-party browsers (e.g. Chrome) are filtered, since Apple's on-device Screen Time filter only covers Safari. NextDNS therefore acts as a data subprocessor for your child's browsing data; it does not use this data for advertising and we do not sell or share it for cross-context behavioral advertising. • Google Maps Platform (Location Display) — Renders the map view in the parent app/dashboard so you can see an enrolled device's location. Map tiles are served by Google; we do not share account identifiers with Google for this purpose beyond what is technically required to display the map. • Google Analytics (Website Analytics) — Collects anonymized website usage data. No personally identifiable information is shared with Google for analytics purposes. 9.2 We Do NOT Share Data With: • Advertisers or ad networks • Data brokers or data resellers • Social media platforms • Any entity for the purpose of profiling, targeting, or marketing 9.3 Law Enforcement & Legal Disclosure We may disclose personal data if required to do so by law or in response to valid legal process, including: • Court orders or subpoenas • Requests from law enforcement agencies with proper legal authority • Situations involving imminent risk of harm to a child We will notify the affected account holder of any legal request for their data unless prohibited by law from doing so. 9.4 Business Transfers In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity. We will notify you via email and a prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.

10. International Data Transfers

Cylux is operated from the United States. If you are accessing our services from outside the United States, your personal data will be transferred to and processed in the United States. For users in the European Economic Area (EEA), United Kingdom (UK), or Switzerland: • We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers of personal data to the United States • Our third-party processors who handle EU/EEA data are contractually bound by equivalent safeguards • We conduct transfer impact assessments to ensure adequate data protection standards are maintained For users in other jurisdictions: • We comply with applicable local data protection laws regarding international data transfers • If your jurisdiction requires specific transfer mechanisms, please contact our DPO at dpo@cylux.co to discuss applicable safeguards

11. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by law. 11.1 Retention Periods • Parent account data — Retained for the duration of your active subscription, plus 30 days after account cancellation to allow for reactivation. After this period, account data is permanently deleted. • GPS location history — 90 days (Premium/Ultimate plans), 30 days (Basic plan). Older records are automatically purged. • App usage and screen time logs — 90 days (Premium/Ultimate plans), 30 days (Basic plan). Older records are automatically purged. • Web activity logs — 90 days (Premium/Ultimate plans), 30 days (Basic plan). Older records are automatically purged. • Content detection history — 90 days (Premium/Ultimate plans), 30 days (Basic plan). Older records are automatically purged. • Support communications — Retained for up to 2 years after the last interaction for quality assurance and dispute resolution. • Billing and transaction records — Retained for up to 7 years as required by tax and financial reporting laws. • Anonymized analytics data — May be retained indefinitely as it cannot be used to identify individuals. 11.2 Account Deletion You can delete your account and all associated data at any time from the Settings page in the Cylux Parent app or web dashboard. Upon deletion: • All child profiles and monitoring data are permanently removed within 72 hours • Billing records are retained only as required by law • Backups containing your data are purged within 30 days

12. Security Measures

We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. 12.1 Technical Safeguards • Encryption in transit — All data transmitted between devices and our servers is encrypted using TLS 1.3 • Encryption at rest — All data stored in our databases is encrypted using AES-256 • Password security — User passwords are hashed using bcrypt with per-user salts; we never store or transmit plaintext passwords • API authentication — All API endpoints require authentication via secure tokens with short expiry • Infrastructure — Hosted on reputable cloud infrastructure (Render and Supabase) in United States data centers, with network isolation, restricted access, and automated patching 12.2 Organizational Safeguards • Access control — Access to production systems and personal data is restricted to authorized personnel on a need-to-know basis, with multi-factor authentication (MFA) required • Security audits — We conduct regular internal security reviews and periodic third-party penetration testing • Incident response — We maintain a documented incident response plan and will notify affected users within 72 hours of discovering a data breach, in compliance with GDPR • Employee training — All team members with access to personal data receive regular training on data protection best practices 12.3 Vulnerability Reporting Despite these measures, no system is completely immune to security threats. If you discover a potential security vulnerability in our platform, please report it responsibly to security@cylux.co. We appreciate responsible disclosure and will not take legal action against researchers who report vulnerabilities in good faith.

13. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data under GDPR, UK GDPR, and other applicable data protection laws: • Right to Access (Article 15 GDPR) — Request a copy of the personal data we hold about you and information about how it is processed. • Right to Rectification (Article 16 GDPR) — Request correction of inaccurate or incomplete personal data. • Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR) — Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected. • Right to Restrict Processing (Article 18 GDPR) — Request that we temporarily limit how we process your data while a concern is being resolved. • Right to Data Portability (Article 20 GDPR) — Request a copy of your personal data in a structured, commonly used, machine-readable format (JSON or CSV). • Right to Object (Article 21 GDPR) — Object to processing based on legitimate interests, including profiling. • Right to Withdraw Consent — Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. • Right to Lodge a Complaint — You have the right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated. How to exercise your rights: Email privacy@cylux.co with your request. We will verify your identity and respond within 30 days. If the request is complex, we may extend this by an additional 60 days with notice. There is no fee for exercising your rights under normal circumstances.

14. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA): • Right to Know — You can request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it. • Right to Delete — You can request that we delete your personal information, subject to certain exceptions (e.g., legal obligations, completing transactions). • Right to Correct — You can request correction of inaccurate personal information. • Right to Opt-Out of Sale/Sharing — We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. No opt-out is necessary, but you may still submit a request for confirmation. • Right to Non-Discrimination — We will not discriminate against you for exercising your CCPA/CPRA rights. You will not receive different pricing or service quality. • Authorized Agents — You may designate an authorized agent to submit requests on your behalf with proper written authorization. Categories of personal information collected in the preceding 12 months: • Identifiers (name, email) • Commercial information (subscription history) • Internet activity (anonymized website analytics) • Geolocation data (child device GPS, collected on behalf of parent) • Inferences drawn from the above (activity reports) To submit a CCPA/CPRA request, email privacy@cylux.co or use the "Privacy Request" option in your account settings.

15. Cookies & Tracking Technologies

The Cylux website and web dashboard use a limited number of cookies and similar technologies. We do not use cookies for advertising or cross-site tracking. 15.1 Essential Cookies (Strictly Necessary) • Authentication cookies — Maintain your login session on the web dashboard (expire on logout or after 7 days of inactivity) • CSRF tokens — Protect against cross-site request forgery attacks (session-only) These cookies cannot be disabled as they are essential for the service to function. 15.2 Preference Cookies (Functional) • UI preferences — Store your selected theme (dark/light mode), language, and dashboard layout preferences • Consent state — Remember your cookie consent choices These cookies are set only with your consent and can be cleared via your browser settings. 15.3 Analytics Cookies (Performance) • Google Analytics — Collects anonymized usage data (pages visited, session duration, referral source). IP addresses are anonymized before processing. These cookies are set only with your consent and can be disabled via your browser settings or our cookie banner. 15.4 Cookies We Do NOT Use • Third-party advertising cookies • Social media tracking pixels • Fingerprinting or supercookies • Cross-site tracking cookies

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes: • Material changes — We will notify you by email and display a prominent notice in the Cylux Parent app and web dashboard at least 14 days before the changes take effect • Minor changes — We will update the "Last updated" date at the top of this page Your continued use of the Cylux service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the revised policy, you may delete your account at any time. We encourage you to review this page periodically for the latest information on our privacy practices.

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us: General Privacy Inquiries: Email: privacy@cylux.co Data Protection Officer: Email: dpo@cylux.co EU/EEA Data Protection Representative: Email: eu-privacy@cylux.co Security Vulnerability Reporting: Email: security@cylux.co Postal Address: Guardian Systems Inc. Attn: Privacy Team 535 Mission Street San Francisco, CA 94105 United States We aim to respond to all inquiries within 30 days. For urgent matters related to child safety or data breaches, we will respond within 48 hours.