Legal
Privacy Policy
Last updated: June 20, 2026
Cylux is a parental control and child safety platform. We take the privacy of both parents and children extremely seriously. This policy explains in detail what data we collect, why we collect it, who we share it with, how long we keep it, and how we protect it. We never sell your data. We are fully compliant with COPPA, GDPR, and CCPA/CPRA.
Table of Contents
1. Who We Are
Guardian Systems Inc., trading as "Cylux" ("we", "us", or "our"), operates the Cylux parental control and child safety platform. Our platform includes the Cylux Parent mobile app (iOS & Android), the Cylux Child mobile app, device monitoring agents for Fire TV, Google TV / Android TV, Windows, Roku, and browser extensions, and the web dashboard at cylux.co.
Cylux is designed to help parents and legal guardians monitor and manage their children's digital activity across multiple devices and platforms. We are committed to protecting the privacy and security of every user — both parents and the children they monitor.
Company address: Guardian Systems Inc., 535 Mission Street, San Francisco, CA 94105, United States.
2. Scope of This Policy
This Privacy Policy applies to all personal data collected through:
• The Cylux website at cylux.co
• The Cylux Parent mobile application
• The Cylux Child mobile application
• Device monitoring agents (Fire TV, Google TV, Android TV, Windows, Roku, browser extensions)
• The Cylux web dashboard
• Any communication between you and Cylux (email, support tickets, contact forms)
By creating an account, installing any Cylux application, or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please do not use our services.
3. Data Controller & Data Protection Officer
Guardian Systems Inc. is the data controller responsible for the personal data processed through the Cylux platform.
Data Protection Officer (DPO):
Email: dpo@cylux.co
For general privacy inquiries:
Email: privacy@cylux.co
EU/EEA Data Protection Representative:
Email: eu-privacy@cylux.co
We have appointed a Data Protection Officer to oversee compliance with applicable data protection legislation. You may contact our DPO at any time regarding questions or concerns about how we handle your personal data.
4. Personal Data We Collect
We collect different categories of data depending on how you interact with our platform.
4.1 Parent Account Data
When you create a parent account, we collect:
• Full name
• Email address
• Encrypted password (hashed using bcrypt; we never store plaintext passwords)
• Subscription and billing information (processed securely by Stripe — we never store raw payment card numbers, CVVs, or full card data on our servers)
• Device identifiers associated with your parent app installation
4.2 Child Profile Data
When you set up a child profile, we collect:
• Child's first name (or nickname) as provided by the parent
• Device identifiers for enrolled devices
• Device type, operating system, and model information
4.3 Device Monitoring Data
When a child's device is enrolled, we collect the following data from that device on behalf of the parent:
• App usage events — app name, package name, open/close timestamps, and total time spent per app per day
• Screen time — total active screen time per day, measured via OS-level usage APIs
• Web activity — domain names visited and domains blocked (we do not capture full URLs, page content, form inputs, or search queries)
• Content detection — titles of media content played on streaming apps (e.g., Netflix, YouTube, Disney+), detected via accessibility services or media session APIs
• GPS location — coordinates updated periodically while the device is active (frequency depends on plan tier)
• Device status — battery level, network connectivity, compliance state, and last-seen timestamp
• Installed applications — package names and app names for app management features
• Notification content (Android, optional) — when the parent enables Notification monitoring, the text of notifications the child's device receives is captured so the parent can review it. Because some apps surface message previews inside notifications, this text can include excerpts of messages from third-party apps. This requires the parent to grant Notification Access on the device and can be turned off at any time.
The Cylux Child app distributed through the Google Play Store does NOT access SMS messages, call logs, or contacts. A separate enterprise/sideloaded edition (never distributed through Google Play) may offer call-log and SMS monitoring where the parent enables it and where permitted by applicable law; that edition is covered by the same protections described in this policy.
4.4 Communication Data
When you contact us via email, support tickets, or our website contact form, we collect:
• Your name and email address
• The content of your message
• Any attachments you provide
4.5 Website Analytics Data
We collect anonymized, aggregated analytics data when you visit cylux.co:
• Pages visited, referral source, and session duration
• Browser type, operating system, and screen resolution
• Approximate geographic location (country/region level, derived from IP — we do not store your IP address in analytics)
This data is collected via Google Analytics and cannot be used to identify individual users.
5. How We Use Your Data
We use the personal data we collect strictly for the following purposes:
• Providing the service — Delivering real-time monitoring, screen time management, content filtering, app management, and location tracking features to the parent account holder
• Account management — Creating and managing your parent account, authenticating logins, and processing subscription payments
• Notifications and alerts — Sending activity reports, security alerts, screen time warnings, content alerts, and service notifications to the parent
• Customer support — Responding to inquiries, troubleshooting issues, and providing technical assistance
• Service improvement — Analyzing anonymized, aggregated usage patterns to improve platform performance, fix bugs, and develop new features
• AI safety insights — When you use Cylux's optional AI insight features, concise summaries of the monitored activity are sent to our AI processor (Anthropic) to generate plain-language guidance for you. This data is processed only to produce your insights and is not used to train AI models.
• Legal compliance — Complying with applicable laws, regulations, and valid legal processes
We do NOT use your data for:
• Advertising or ad targeting
• User profiling for marketing purposes
• Sale or rental to any third party
• Training machine learning models on identifiable personal data
• Any purpose unrelated to the Cylux parental control service
6. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR) and similar data protection laws, we process personal data on the following legal bases:
6.1 Performance of a Contract (Article 6(1)(b) GDPR)
Processing parent account data and providing the monitoring service is necessary to fulfill our contractual obligations under the Cylux Terms of Service.
6.2 Legitimate Interest (Article 6(1)(f) GDPR)
We process certain data based on our legitimate interest in:
• Improving and securing our platform
• Preventing fraud and abuse
• Providing customer support
We balance these interests against your rights and freedoms and ensure processing does not override them.
6.3 Consent (Article 6(1)(a) GDPR)
Where required, we obtain your explicit consent before processing — for example, for marketing communications or optional analytics cookies. You may withdraw consent at any time.
6.4 Legal Obligation (Article 6(1)(c) GDPR)
We process data when necessary to comply with applicable legal obligations, such as tax record-keeping or responses to valid legal processes.
6.5 Parental Authority
Device monitoring data is collected on behalf of the parent or legal guardian who has authority over the child's device usage. The parent is responsible for ensuring that their use of Cylux complies with applicable local laws regarding monitoring of minors.
7. Children’s Privacy & COPPA Compliance
Cylux is a parental control platform designed to be used by parents and legal guardians to monitor their children's devices. We take the privacy of children extremely seriously.
7.1 COPPA Compliance
We comply fully with the Children's Online Privacy Protection Act (COPPA):
• Children do not create accounts with Cylux and do not interact with our service directly
• All monitoring data is collected on behalf of, and accessible only to, the verified parent or guardian who owns the account
• We do not knowingly collect personal information directly from children under 13
• Parents have full control over what data is collected and can delete their child's profile and all associated data at any time
7.2 Parental Consent
By enrolling a child's device with Cylux, the parent or legal guardian provides verifiable parental consent for the collection of monitoring data from that device. The parent can review, modify, or delete this data at any time.
7.3 Data Minimization for Children
We apply the principle of data minimization to all child-related data:
• We only collect data that is necessary for the monitoring features the parent has enabled
• We do not read SMS messages or call logs on the Google Play edition of the app, and we never read the full contents of your child's online accounts. However, if you enable Notification monitoring on Android, the text of notifications (which some apps use to show message previews) is captured so you can review it — you can turn this off at any time
• We do not record audio or video from any device
• We do not capture screenshots of the child's device
• Web activity logging captures domain names only — not full page URLs, search queries, or page content
7.4 Reporting
If you believe we have inadvertently collected personal information from a child without proper parental consent, please contact us immediately at privacy@cylux.co. We will investigate and delete any such data within 48 hours.
8. Disclosure & Transparency to Monitored Users
We believe in transparency. While Cylux is managed by parents, we strongly recommend — and in some jurisdictions it may be legally required — that parents inform their children that monitoring software is installed on their devices.
• Our Terms of Service require that parents disclose the use of Cylux to their children in an age-appropriate manner
• On enrolled devices, the Cylux monitoring agent is visible in the app list and is not designed to operate covertly
• Cylux is intended exclusively for monitoring minor children under the parent's or guardian's legal care — using Cylux to monitor adults without their knowledge or consent is a violation of our Terms of Service and may violate applicable law
9. Data Sharing & Third-Party Processors
We share personal data with trusted third-party service providers only as necessary to operate and improve the Cylux platform. All third-party processors are contractually required to protect personal data and use it only for the purposes we specify.
9.1 Service Providers
• Stripe (Payment Processing) — Processes subscription payments. Stripe is PCI-DSS Level 1 certified. We share only the data necessary to process transactions (email, subscription tier). We never transmit or store raw card data on our servers.
• Render & Supabase (Cloud Hosting & Database) — Render hosts our application servers and Supabase provides our managed PostgreSQL database. All data is encrypted at rest (AES-256) and in transit (TLS 1.3) and is stored in United States data centers.
• Firebase / Google Cloud (Push Notifications) — Delivers real-time push notifications to parent and child devices. Notification payloads contain minimal identifiers; sensitive content is encrypted end-to-end.
• SendGrid (Email) — Delivers transactional emails including account notifications, activity reports, and security alerts. Email addresses and message content are shared only as needed for delivery.
• Anthropic (AI Safety Insights) — Powers our optional AI insight features. When you request an insight, we send concise, purpose-limited summaries of the monitored activity to Anthropic to generate guidance text. Anthropic processes this data solely to return your result and does not use Cylux data to train its models.
• NextDNS (Web & Content Filtering) — Cylux uses NextDNS to filter unsafe websites and content across a child's device and your home network. When a NextDNS profile is connected, the device's DNS queries are resolved and logged by NextDNS on that profile. We use its API (with the profile/API key associated with your account) to: (a) sync the block/allow domain lists and parental-control categories you choose in Cylux (e.g. adult content, gambling, SafeSearch, YouTube Restricted Mode), and (b) read the profile's query logs to show you blocked-site and streaming-activity history. On iOS this DNS-layer filtering is the primary way third-party browsers (e.g. Chrome) are filtered, since Apple's on-device Screen Time filter only covers Safari. NextDNS therefore acts as a data subprocessor for your child's browsing data; it does not use this data for advertising and we do not sell or share it for cross-context behavioral advertising.
• Google Maps Platform (Location Display) — Renders the map view in the parent app/dashboard so you can see an enrolled device's location. Map tiles are served by Google; we do not share account identifiers with Google for this purpose beyond what is technically required to display the map.
• Google Analytics (Website Analytics) — Collects anonymized website usage data. No personally identifiable information is shared with Google for analytics purposes.
9.2 We Do NOT Share Data With:
• Advertisers or ad networks
• Data brokers or data resellers
• Social media platforms
• Any entity for the purpose of profiling, targeting, or marketing
9.3 Law Enforcement & Legal Disclosure
We may disclose personal data if required to do so by law or in response to valid legal process, including:
• Court orders or subpoenas
• Requests from law enforcement agencies with proper legal authority
• Situations involving imminent risk of harm to a child
We will notify the affected account holder of any legal request for their data unless prohibited by law from doing so.
9.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity. We will notify you via email and a prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
10. International Data Transfers
Cylux is operated from the United States. If you are accessing our services from outside the United States, your personal data will be transferred to and processed in the United States.
For users in the European Economic Area (EEA), United Kingdom (UK), or Switzerland:
• We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers of personal data to the United States
• Our third-party processors who handle EU/EEA data are contractually bound by equivalent safeguards
• We conduct transfer impact assessments to ensure adequate data protection standards are maintained
For users in other jurisdictions:
• We comply with applicable local data protection laws regarding international data transfers
• If your jurisdiction requires specific transfer mechanisms, please contact our DPO at dpo@cylux.co to discuss applicable safeguards
11. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by law.
11.1 Retention Periods
• Parent account data — Retained for the duration of your active subscription, plus 30 days after account cancellation to allow for reactivation. After this period, account data is permanently deleted.
• GPS location history — 90 days (Premium/Ultimate plans), 30 days (Basic plan). Older records are automatically purged.
• App usage and screen time logs — 90 days (Premium/Ultimate plans), 30 days (Basic plan). Older records are automatically purged.
• Web activity logs — 90 days (Premium/Ultimate plans), 30 days (Basic plan). Older records are automatically purged.
• Content detection history — 90 days (Premium/Ultimate plans), 30 days (Basic plan). Older records are automatically purged.
• Support communications — Retained for up to 2 years after the last interaction for quality assurance and dispute resolution.
• Billing and transaction records — Retained for up to 7 years as required by tax and financial reporting laws.
• Anonymized analytics data — May be retained indefinitely as it cannot be used to identify individuals.
11.2 Account Deletion
You can delete your account and all associated data at any time from the Settings page in the Cylux Parent app or web dashboard. Upon deletion:
• All child profiles and monitoring data are permanently removed within 72 hours
• Billing records are retained only as required by law
• Backups containing your data are purged within 30 days
12. Security Measures
We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
12.1 Technical Safeguards
• Encryption in transit — All data transmitted between devices and our servers is encrypted using TLS 1.3
• Encryption at rest — All data stored in our databases is encrypted using AES-256
• Password security — User passwords are hashed using bcrypt with per-user salts; we never store or transmit plaintext passwords
• API authentication — All API endpoints require authentication via secure tokens with short expiry
• Infrastructure — Hosted on reputable cloud infrastructure (Render and Supabase) in United States data centers, with network isolation, restricted access, and automated patching
12.2 Organizational Safeguards
• Access control — Access to production systems and personal data is restricted to authorized personnel on a need-to-know basis, with multi-factor authentication (MFA) required
• Security audits — We conduct regular internal security reviews and periodic third-party penetration testing
• Incident response — We maintain a documented incident response plan and will notify affected users within 72 hours of discovering a data breach, in compliance with GDPR
• Employee training — All team members with access to personal data receive regular training on data protection best practices
12.3 Vulnerability Reporting
Despite these measures, no system is completely immune to security threats. If you discover a potential security vulnerability in our platform, please report it responsibly to security@cylux.co. We appreciate responsible disclosure and will not take legal action against researchers who report vulnerabilities in good faith.
13. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data under GDPR, UK GDPR, and other applicable data protection laws:
• Right to Access (Article 15 GDPR) — Request a copy of the personal data we hold about you and information about how it is processed.
• Right to Rectification (Article 16 GDPR) — Request correction of inaccurate or incomplete personal data.
• Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR) — Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected.
• Right to Restrict Processing (Article 18 GDPR) — Request that we temporarily limit how we process your data while a concern is being resolved.
• Right to Data Portability (Article 20 GDPR) — Request a copy of your personal data in a structured, commonly used, machine-readable format (JSON or CSV).
• Right to Object (Article 21 GDPR) — Object to processing based on legitimate interests, including profiling.
• Right to Withdraw Consent — Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
• Right to Lodge a Complaint — You have the right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.
How to exercise your rights:
Email privacy@cylux.co with your request. We will verify your identity and respond within 30 days. If the request is complex, we may extend this by an additional 60 days with notice. There is no fee for exercising your rights under normal circumstances.
14. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
• Right to Know — You can request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it.
• Right to Delete — You can request that we delete your personal information, subject to certain exceptions (e.g., legal obligations, completing transactions).
• Right to Correct — You can request correction of inaccurate personal information.
• Right to Opt-Out of Sale/Sharing — We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. No opt-out is necessary, but you may still submit a request for confirmation.
• Right to Non-Discrimination — We will not discriminate against you for exercising your CCPA/CPRA rights. You will not receive different pricing or service quality.
• Authorized Agents — You may designate an authorized agent to submit requests on your behalf with proper written authorization.
Categories of personal information collected in the preceding 12 months:
• Identifiers (name, email)
• Commercial information (subscription history)
• Internet activity (anonymized website analytics)
• Geolocation data (child device GPS, collected on behalf of parent)
• Inferences drawn from the above (activity reports)
To submit a CCPA/CPRA request, email privacy@cylux.co or use the "Privacy Request" option in your account settings.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
When we make changes:
• Material changes — We will notify you by email and display a prominent notice in the Cylux Parent app and web dashboard at least 14 days before the changes take effect
• Minor changes — We will update the "Last updated" date at the top of this page
Your continued use of the Cylux service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the revised policy, you may delete your account at any time.
We encourage you to review this page periodically for the latest information on our privacy practices.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
General Privacy Inquiries:
Email: privacy@cylux.co
Data Protection Officer:
Email: dpo@cylux.co
EU/EEA Data Protection Representative:
Email: eu-privacy@cylux.co
Security Vulnerability Reporting:
Email: security@cylux.co
Postal Address:
Guardian Systems Inc.
Attn: Privacy Team
535 Mission Street
San Francisco, CA 94105
United States
We aim to respond to all inquiries within 30 days. For urgent matters related to child safety or data breaches, we will respond within 48 hours.