WatchGarden is a parental control app that lets parents curate video channels so children only see approved content. This privacy policy explains what data the app collects, how it is used, and with whom it is shared.
By using WatchGarden, you agree to the terms described below.
Summary
- Children never sign in. Only parents can create accounts. Children interact with a name-and-emoji profile created by the parent on the device.
- Most data is stored locally on your device. Parental PIN, kid profiles, allowed channels, likes, screen-time settings and usage, watch activity, and cached video metadata never leave the device unless you subscribe to Premium.
- Premium users (optional) sign in with Google so their profiles, channels, likes, screen-time settings (daily limits and bedtime windows), and watch activity can sync between devices via Firebase Cloud Firestore.
- Watch activity stays in the family. To power parental screen-time limits and the weekly parent report, the app records which approved videos each kid profile watched and for how long. This log lives on the device, is automatically deleted after 14 days, is visible only in the PIN-protected parent area, and is never used for advertising or shared with third parties. For Premium accounts it is additionally backed up to the parent's own Firestore data.
- Free users see ads through Google AdMob, configured for non-personalized ads so no behavioral ad profile is built.
- Subscriptions are managed by Google Play Billing through RevenueCat. We never see or store payment information.
- Premium scope. A Premium subscription only extends in-app features (more profiles, more channels per profile, more videos per channel, daily screen-time limits, bedtime windows, the weekly parent report, cloud sync, and removal of WatchGarden's own ads). It does not remove ads embedded in the video content itself by the original publisher (for example, the pre-roll, mid-roll, or post-roll ads that play inside YouTube videos) — those are controlled by the video platform and are out of WatchGarden's scope.
- Analytics. Firebase Analytics is bundled as a transitive dependency of the Firebase SDK, but automatic event collection is disabled at the Android manifest level (
firebase_analytics_collection_deactivated=true). No analytics events are transmitted from the app.
Who We Are
WatchGarden is developed and maintained by an independent developer (referred to in this policy as "we", "us"). Contact: cristobalbtech@gmail.com.
Data We Collect and Where It Goes
Data stored only on your device
The following data is saved to the device using AsyncStorage and never transmitted anywhere unless you enable Premium cloud sync:
| Data | Purpose |
|---|---|
| 4-digit parent PIN | Protects access to the parent area. Never transmitted, never synced to the cloud — even for Premium users. |
| PIN lockout state | Tracks failed PIN attempts and lockout timers |
| Kid profiles (name + emoji) | Identifies which child is using the app |
| Allowed video channels (per profile) | Defines which channels each child can watch |
| Video likes (per profile) | Lets children mark favorite videos; used to personalize the feed |
| Screen-time settings and daily usage (per profile) | Enforces the parent-set daily watch limit and bedtime window; usage counters reset at local midnight |
| Watch activity log (per profile) | Records which approved videos were watched and for how long to power the parents' weekly report; automatically deleted after 14 days |
| Cached video metadata | Temporarily stores video titles, thumbnails, and durations to reduce API calls |
| Video API quota usage | Tracks daily API usage to stay within rate limits |
Data collected when a parent signs in (Premium)
When a parent chooses to subscribe to Premium, they sign in with a Google account. This is the only way an account is created. The following data is then collected:
| Data | Where it goes | Purpose |
|---|---|---|
| Parent's Google email address | Firebase Authentication | Identifies the parent account so settings can be restored on another device |
| Firebase user ID (UID) | Firebase Authentication, RevenueCat | A pseudonymous identifier used to associate the subscription and cloud data with the account |
| Kid profiles, allowed channels, video likes, screen-time settings (daily limit, bedtime window), setup state | Firebase Cloud Firestore (users/{uid} subcollections) | Syncs the parent's configuration across devices when signed in |
| Watch activity log (per profile, last 14 days) | Firebase Cloud Firestore (users/{uid}/watchHistory) | Backs up the weekly-report data so it survives reinstalls and is available on the parent's other devices |
| Subscription status (active/expired, plan, expiry date) | RevenueCat + local cache | Determines whether Premium features are unlocked |
Important: the 4-digit parent PIN is never synced to the cloud — it remains device-local even for Premium users. Each device must have its own PIN set up.
Sign-in is fully optional. The app works as a free, fully offline-capable product without signing in.
Data collected from free-tier users (ads)
Free-tier users see Google AdMob ads (an app-open ad at launch, an interstitial ad before the Settings tab). The app requests non-personalized ads only (requestNonPersonalizedAdsOnly: true), meaning Google may collect basic information such as device type, language, and IP address to deliver an ad but does not build a behavioral advertising profile from a free user's activity inside WatchGarden.
Ads are completely disabled for Premium users.
Data sent to the YouTube Data API
The app sends channel-search queries and channel/video-ID requests to the YouTube Data API v3 to fetch channel info and video metadata. Requests include the app's API key but no personal user data — Google does not learn the identity of the parent or child from these requests.
Third-Party Services
| Service | What it processes | Privacy policy |
|---|---|---|
| Google Sign-In | Email address of the signed-in parent | |
| Firebase Authentication | Email address, Firebase UID | Firebase |
| Firebase Cloud Firestore | Kid profile names/emojis, allowed channels, video likes, screen-time settings, watch activity (Premium only) | Firebase |
| RevenueCat | Firebase UID + subscription status | RevenueCat |
| Google Play Billing | Payment processing (we never receive payment details) | Google Play |
| Google AdMob (free tier only) | Non-personalized ad delivery; device type, language, coarse IP-based location | AdMob |
| YouTube Data API v3 | Channel search and video metadata requests |
Children's Privacy (COPPA)
WatchGarden is designed for use by families with children. The app is built around the principles of the Children's Online Privacy Protection Act (COPPA):
- No accounts for children. Children cannot sign in, register, or create an account. Only the parent ever interacts with sign-in, billing, or settings.
- No collection of personal information from children. Kid "profiles" are a name and an emoji chosen by the parent. No data identifying the child (name, age, photo, location, contacts) is required, collected, or transmitted.
- No advertising shown to children. Ads, when shown, only appear in the parent-facing Settings area (interstitial before opening Settings) or at app launch before a kid profile is selected. They are configured as non-personalized. Children do not see ads inside their video feed.
- Parental control by design. Setup, channel management, sign-in, billing, and reset are all behind a 4-digit PIN. Children only see the curated feed.
- No chat, social, or contact features. The app contains no way for a child to communicate with anyone or share personal information.
- No behavioral tracking of children by third parties. Video likes and the watch activity log (which parent-approved videos were watched and for how long, kept 14 days) are stored locally — or, for Premium, in the parent's own Firestore account. They exist solely so the app can reorder the parent-allowed feed, enforce the parent's screen-time limits, and show the parent a weekly report. They are never shared with third parties, never used for advertising, and never leave the parent's control.
If you are a parent and believe we have inadvertently collected information about a child outside what is described here, contact us at cristobalbtech@gmail.com and we will delete it.
Data Retention and Your Rights
- The copy on your device — kid profiles, approved channels, likes, your PIN, screen-time settings and the watch activity log — stays on the device and is not removed when you delete your account. To clear it, use your device's system settings (Settings → Apps → WatchGarden → Storage → Clear storage), or uninstall the app.
- With Premium, everything in that list except your PIN is also backed up to the cloud. Your PIN never leaves the device. Deleting your account removes the cloud copy; the device copy is untouched.
- Watch activity log is retained for a rolling 14 days and deleted automatically after that, both on the device and in the Premium cloud backup. Deleting a kid profile immediately deletes its watch activity and screen-time usage.
- Cloud-synced data (Premium): delete it yourself, in the app. Open the parent area (PIN required) → Settings → Account → Delete account. This immediately and permanently deletes your Firebase Authentication record and every
users/{uid}Firestore document — kid profiles, approved channels, likes and watch history. It cannot be undone.- Deleting your account does not cancel a Premium subscription: subscriptions belong to your Google Play account, not to this app. Cancel in the Play Store first, or you will continue to be charged.
- Deleting your account removes the cloud copy only. The profiles and settings on your device stay as they are — see The copy on your device above if you also want to clear those.
- If you cannot access the app, email cristobalbtech@gmail.com from the address associated with the account and we will delete the same data within 30 days.
- Subscription data is retained by Google Play and RevenueCat according to their own retention policies for accounting and chargeback purposes, even after account deletion.
If you are located in a jurisdiction with applicable privacy rights (such as GDPR, UK GDPR, or the CCPA), you may have additional rights to access, correct, or port your personal data. Use the email above to make such a request.
Security
- The parent area is protected by a 4-digit PIN with exponential backoff lockout after failed attempts (lockout at 5 failures, doubling each cycle).
- A math problem (addition with answer > 40) serves as a secondary deterrent before sign-in.
- All local data is stored in the app's private AsyncStorage sandbox, accessible only to WatchGarden.
- Cloud data is stored in Firestore under per-user document paths protected by Firebase security rules so that one signed-in user cannot read or write another user's data.
- We do not have any backend infrastructure outside of the managed Google services listed above.
International Data Transfers
Firebase, RevenueCat, and Google AdMob are operated by Google LLC and RevenueCat Inc., both US-based companies. If you use the app from outside the United States, your data may be transferred to and processed in the United States and other countries where these providers operate. These providers offer Standard Contractual Clauses and other safeguards for international transfers.
Changes to This Policy
If this privacy policy is updated, the "Last updated" date at the top will be revised. Material changes will also be announced in the app's release notes on Google Play.
Contact
Questions about this privacy policy, requests for data deletion, or any other privacy concern: cristobalbtech@gmail.com.
Attributions
WatchGarden uses free icons from Flaticon. Content icons by srip — Flaticon.