← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — United States Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — also acts as Privacy Officer and Designated Child Safety Officer for all U.S. residents covered by this Annex. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) enactment of any new U.S. state comprehensive privacy law that takes effect before the next annual review, (b) any change to the federal COPPA framework (16 CFR Part 312) or the FTC's enforcement posture, (c) any litigation outcome that materially changes the enforceability of a state law referenced below, (d) any change to the universal opt-out signal framework (GPC), or (e) any change to a U.S. sub-processor's data-handling posture under our sub-processor register. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of a series of country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical U.S.-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a U.S. resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a U.S. resident a right that this Annex does not, the global Policy governs. The two are read together.


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose state of residence is one of the fifty U.S. states, the District of Columbia, Puerto Rico, Guam, the U.S. Virgin Islands, American Samoa, the Northern Mariana Islands, or any other U.S. territory whose governing law treats the federal Children's Online Privacy Protection Act ("COPPA") as in force.

We determine state of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

For inherited territories (Puerto Rico, Guam, U.S. Virgin Islands, American Samoa, Northern Mariana Islands), the federal-law layer of this Annex (§§ 2, 5, 9, 11–13) applies in full; the state-law layers in §§ 3 and 4 do not apply directly but their parallel federal-territory analogues are honored on a best-effort basis until the territory enacts its own comprehensive privacy law.


2. Federal layer — Children's Online Privacy Protection Act (COPPA)

2.1 Statutory cite

15 U.S.C. §§ 6501–6506, implemented at 16 C.F.R. Part 312 ("COPPA Rule"). The COPPA Rule sits with the U.S. Federal Trade Commission ("FTC"); the FTC enforces COPPA against operators of websites and online services directed to children under 13 and against operators with actual knowledge that they are collecting personal information from a child under 13. Balance is squarely in the first category (we self-declare "Children and older users" — mixed-audience track — per our country classification table § 1).

Touchpoint What COPPA requires Where Balance delivers it
Online notice (16 C.F.R. § 312.4(d)) A clear, complete privacy notice describing what personal information the operator collects from children, how it uses the information, and its disclosure practices. Privacy Policy (H1) at Privacy Policy.
Direct notice to parents (16 C.F.R. § 312.4(c)) A separate, plain-language notice given directly to the parent at sign-up, before any collection of the child's personal information starts. Children's Privacy Notice (H2) at Children's Privacy Notice. This notice is also surfaced in-app to the parent on the Verifiable Parental Consent screen at kid onboarding (Phase 3.1 of our internal compliance plan).
Verifiable Parental Consent (16 C.F.R. § 312.5) The operator must obtain Verifiable Parental Consent before any collection, use, or disclosure of personal information from a child. The parent creates an account using an email-and-password (or Google Sign-In), enters payment information at subscription time (a category of VPC method enumerated at 16 C.F.R. § 312.5(b)(2)(ii)), then creates the kid profile and pairs the kid's device. The act of creating the kid profile and pairing is logged as a Verifiable Parental Consent event with timestamp, consent scope, locale, and the parent's identity. The parent-creates-account-and-pairs-kid-device sequence is the consent mechanism; the kid never sees a consent screen.
Right of review (16 C.F.R. § 312.6) The parent can review the child's personal information, can refuse to permit further collection or use, and can require deletion. In-app: Settings → Family → [kid name] → "Export this kid's data" + "Delete this kid". Out-of-app: Delete-account page + .
Data security (16 C.F.R. § 312.8) Reasonable procedures to protect the confidentiality, security, and integrity of personal information. our encryption-posture record; our Records of Processing Activities (Article 30) § 7 (Article 32 control table — read as the COPPA § 312.8 control table in the U.S. context).
Data retention and deletion (16 C.F.R. § 312.10) An operator must retain personal information for only as long as is reasonably necessary, and must delete using reasonable measures. Data Retention & Deletion Policy (the COPPA-mandated written retention schedule).

2.3 Specific FTC-recognised exception we rely on

Under 16 C.F.R. § 312.5(c)(3), an operator may collect a persistent identifier and no other personal information from a child without prior VPC, where the identifier is used solely to provide support for the internal operations of the website or service. Balance does NOT rely on this exception — we obtain full VPC at kid onboarding, before any collection starts. The exception is documented here for transparency only.

2.4 No advertising; no profiling; no third-party sale

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, does not build a behavioural-advertising profile of any user, and does not sell, lease, or share personal information with any third party for advertising or marketing purposes. This is the per-our internal compliance plan § 6.3 universal posture and is independently confirmed in:

2.5 FTC complaint route

A parent who believes Balance has violated COPPA may file a complaint with the FTC:

Filing a complaint with the FTC does not affect any other right the parent has under federal, state, or local law. We will cooperate with any FTC inquiry directed at us; we are not aware of any open FTC investigation as of the Effective date above.

2.6 CSAE / 18 U.S.C. § 2258A — NCMEC CyberTipline reporting

If we obtain actual knowledge of a fact or circumstance that constitutes a violation of the federal child-sexual-abuse-material statutes referenced in 18 U.S.C. § 2258A(a)(2), we will file a report with the National Center for Missing & Exploited Children ("NCMEC") via the CyberTipline at https://report.cybertip.org/. The procedure is documented in Child Safety Standards § 8.1, § 9 and the Play Console Child Safety Standards declaration § 3 M6-Q5.

We acknowledge the federal preservation duty under 18 U.S.C. § 2258A(h): NCMEC reports must be preserved for at least 90 days, extendable by 90 days on agency request. Our preservation procedure in our breach-notification runbook § 5 honors this period.

2.7 Federal Trade Commission Safeguards Rule and Section 5

The FTC's Safeguards Rule under the Gramm-Leach-Bliley Act (16 C.F.R. Part 314) does not apply to Balance because Balance is not a "financial institution" within the meaning of GLBA. The FTC's general Section 5 authority over "unfair or deceptive acts or practices" does apply; the universal posture in Privacy Policy and the strict no-deception drafting of every public document in this Annex set is designed to remain inside the Section 5 bright lines.


3. State layer — comprehensive privacy laws

As of the Effective date above, the following U.S. states have enacted a comprehensive consumer privacy law that is either in force or will be in force before the next annual review of this Annex. The table is the canonical Balance-side mapping; each row drives the rights enumerated in § 8 below and the complaint routes enumerated in § 13 below.

State Statute (short cite) In force from DSAR response window Cure period (pre-suit) Regulator Private right of action? Sensitive-data opt-in required?
California California Consumer Privacy Act + California Privacy Rights Act ("CCPA / CPRA"); Cal. Civ. Code § 1798.100 et seq. 1 Jan 2020 (CCPA); 1 Jan 2023 (CPRA amendments) 45 calendar days, extendable by 45 days with notice 30 days (sunset for AG actions 1 Jan 2023; CPPA continues to use cure case-by-case) California Privacy Protection Agency (CPPA) + California Attorney General Yes, narrow — security-breach private right at Civ. Code § 1798.150 Yes (opt-in for "sensitive personal information")
Virginia Virginia Consumer Data Protection Act ("VCDPA"); Va. Code § 59.1-575 et seq. 1 Jan 2023 45 calendar days, extendable by 45 30 days Virginia Attorney General No Yes (opt-in for "sensitive data")
Colorado Colorado Privacy Act ("CPA"); Colo. Rev. Stat. § 6-1-1301 et seq. 1 Jul 2023 45 calendar days, extendable by 45 60 days (sunsets 1 Jan 2025; AG continues to use cure case-by-case) Colorado Attorney General No Yes (opt-in)
Connecticut Connecticut Data Privacy Act ("CTDPA"); Conn. Gen. Stat. § 42-515 et seq. 1 Jul 2023 45 calendar days, extendable by 45 60 days (sunsets 1 Jan 2025) Connecticut Attorney General No Yes (opt-in)
Utah Utah Consumer Privacy Act ("UCPA"); Utah Code § 13-61-101 et seq. 31 Dec 2023 45 calendar days, extendable by 45 30 days Utah Division of Consumer Protection + Utah Attorney General No No (opt-out only for sensitive)
Texas Texas Data Privacy and Security Act ("TDPSA"); Tex. Bus. & Com. Code Ch. 541 1 Jul 2024 45 calendar days, extendable by 45 30 days Texas Attorney General No Yes (opt-in for sensitive data of consumers known to be under 13)
Oregon Oregon Consumer Privacy Act ("OCPA"); ORS § 646A.570 et seq. 1 Jul 2024 45 calendar days, extendable by 45 30 days (sunsets 1 Jan 2026) Oregon Attorney General No Yes (opt-in)
Montana Montana Consumer Data Privacy Act ("MCDPA"); Mont. Code Ann. § 30-14-2801 et seq. 1 Oct 2024 45 calendar days, extendable by 45 60 days (sunsets 1 Apr 2026) Montana Attorney General No Yes (opt-in)
Florida Florida Digital Bill of Rights ("FDBR"); Fla. Stat. § 501.701 et seq. 1 Jul 2024 45 calendar days, extendable by 45 45 days Florida Department of Legal Affairs + Florida Attorney General No (with narrow exceptions) Yes (opt-in for sensitive data of known minors)
Delaware Delaware Personal Data Privacy Act ("DPDPA"); 6 Del. C. § 12D-101 et seq. 1 Jan 2025 45 calendar days, extendable by 45 60 days (sunsets 31 Dec 2025) Delaware Department of Justice + Delaware Attorney General No Yes (opt-in)
Iowa Iowa Consumer Data Protection Act ("ICDPA"); Iowa Code § 715D.1 et seq. 1 Jan 2025 90 calendar days 90 days Iowa Attorney General No No (notice/opt-out only)
New Hampshire New Hampshire Privacy Act ("NHPA"); RSA 507-H 1 Jan 2025 45 calendar days, extendable by 45 60 days (sunsets 31 Dec 2025) New Hampshire Attorney General No Yes (opt-in)
New Jersey New Jersey Data Privacy Act ("NJDPA"); N.J. Stat. Ann. § 56:8-166.4 et seq. 15 Jan 2025 45 calendar days, extendable by 45 30 days (sunsets 15 Jul 2026) New Jersey Division of Consumer Affairs + New Jersey Attorney General No Yes (opt-in)
Nebraska Nebraska Data Privacy Act ("NEDPA"); Neb. Rev. Stat. § 87-1101 et seq. 1 Jan 2025 45 calendar days, extendable by 45 30 days Nebraska Attorney General No Yes (opt-in)
Tennessee Tennessee Information Protection Act ("TIPA"); Tenn. Code Ann. § 47-18-3201 et seq. 1 Jul 2025 45 calendar days, extendable by 45 60 days Tennessee Attorney General No Yes (opt-in)
Minnesota Minnesota Consumer Data Privacy Act ("MCDPA-MN"); Minn. Stat. § 325O.05 et seq. 31 Jul 2025 45 calendar days, extendable by 45 30 days (sunsets 31 Jan 2026) Minnesota Attorney General No Yes (opt-in)
Maryland Maryland Online Data Privacy Act ("MODPA"); Md. Code Ann., Com. Law § 14-4601 et seq. 1 Oct 2025 45 calendar days, extendable by 45 60 days Maryland Attorney General No Strict — opt-in plus a hard data-minimisation rule that forbids processing of sensitive data unless strictly necessary to provide the service the consumer requested (MODPA § 14-4607(b))
Indiana Indiana Consumer Data Protection Act ("INCDPA"); Ind. Code § 24-15-1-1 et seq. 1 Jan 2026 45 calendar days, extendable by 45 30 days Indiana Attorney General No Yes (opt-in)
Kentucky Kentucky Consumer Data Protection Act ("KCDPA"); KRS Ch. 367 (new Subchapter) 1 Jan 2026 45 calendar days, extendable by 45 30 days Kentucky Attorney General No Yes (opt-in)
Rhode Island Rhode Island Data Transparency and Privacy Protection Act ("RIDTPPA"); R.I. Gen. Laws § 6-48.1-1 et seq. 1 Jan 2026 45 calendar days, extendable by 45 30 days Rhode Island Attorney General No Yes (opt-in)

Reading-rule. Where a U.S. resident's state of residence is not in the table above, Balance still extends to that resident the rights enumerated in § 8 below, on a "most-protective common denominator" basis, so the resident does not have to wait for their state legislature to act before exercising the rights other Balance users already enjoy. This is the universal posture documented in our internal compliance plan § 6.3 (the "global policy + per-country annex" architecture) and is not contingent on the resident's state law.

Pending bills (not in force at the Effective date). Pennsylvania, Massachusetts, Vermont (general; the existing Vermont data-broker law is separately referenced in § 12), New York (general comprehensive; the NY Child Data Protection Act is separately in § 4), Washington (general; the existing My Health My Data Act covers health-specific data and does not apply to Balance because we do not process health data), Michigan, and Illinois (general; the existing BIPA covers biometric data and does not apply to Balance because we do not collect biometric data). When any of these enacts in a form that takes effect before the next annual review of this Annex, the table above is updated.


4. State layer — child-specific overlays

A handful of U.S. states have enacted child-specific privacy or age-appropriate-design laws that overlay the comprehensive privacy laws in § 3. Balance's universal posture (no advertising, no profiling, no third-party sharing beyond declared sub-processors, no dark patterns, Verifiable Parental Consent for every kid) satisfies the substance of every such law as of the Effective date above; the rows below cite each law and the specific Balance-side handshake.

4.1 California — Age-Appropriate Design Code Act ("CA AADC")

Cite: Cal. Civ. Code §§ 1798.99.28–1798.99.40. Status: the statute was enacted in 2022; portions have been the subject of litigation (NetChoice v. Bonta, Ninth Circuit and underlying Northern District of California) and the enforceability of certain provisions has been the subject of preliminary injunction. Balance's substantive posture is independent of the litigation outcome — we apply the AADC standard regardless, because every element of the AADC standard is satisfied by the universal design rule in our country classification table § 2 and the architectural posture documented in Child Safety Standards § 5.

Handshake: Balance does not collect, share, or process the precise location of a child; does not estimate a child's age beyond the parent's declared age at kid creation; does not use a dark pattern, manipulative cue, or engagement-maximising nudge directed at a child; does not enable a child to communicate with adults outside their household; does not show advertising; does not profile a child. The AADC's data-protection-impact-assessment requirement (Civ. Code § 1798.99.31(a)(1)) is satisfied by our Data Protection Impact Assessment (H8).

4.2 Maryland — Age-Appropriate Design Code ("MD AADC" / "Kids Code")

Cite: Md. Code Ann., Com. Law § 14-4602 et seq. (the Maryland Age-Appropriate Design Code, MD Kids Code, enacted as H.B. 901 and effective 1 October 2024). Status: in force at the Effective date above.

Handshake: the MD Kids Code requires age-appropriate design for online services likely to be accessed by children, prohibits the processing of children's personal data for any purpose other than the one for which it was collected (unless the operator can demonstrate a compelling reason and the processing is in the best interests of the child), requires a data-protection-impact-assessment, and prohibits dark patterns and design features that promote compulsive use. Balance's universal posture (data-minimised by design; no engagement-maximising features; no advertising; no third-party sharing; explicit DPIA in H8; explicit children's notice in H2) satisfies each element.

4.3 New York — Child Data Protection Act

Cite: N.Y. Gen. Bus. Law § 899-ff et seq. (the New York Child Data Protection Act, S.B. S7695-A, effective 20 June 2025). Status: in force at the Effective date above.

Handshake: the NY Child Data Protection Act prohibits the processing of a covered minor's personal data except for the purpose of providing the service the minor (or their parent) requested, the operator's permitted purposes enumerated in the statute, or with informed consent. Targeted advertising to minors is prohibited. Balance's posture (no advertising; processing limited to providing the parental-control service the parent set up; VPC at kid onboarding) is in compliance.

4.4 Connecticut — child-specific provisions of the CTDPA (S.B. 3, Public Act 23-56)

Cite: Public Act 23-56 amends the CTDPA at Conn. Gen. Stat. § 42-515 et seq., adding heightened protections for consumers known to be between 13 and 18 years old. Status: effective 1 October 2024.

Handshake: the CT amendments forbid an operator that has actual knowledge a consumer is between 13 and 18 from selling that consumer's personal data, processing it for targeted advertising, or processing it for any "system design feature" that "increases, sustains, or extends the consumer's use" — i.e., engagement-maximising design directed at minors is forbidden. Balance does not sell personal data; does not engage in targeted advertising; does not engage in engagement-maximising design directed at any user. The handshake to M6 § 3 ATTESTATION-D and M7 § 3 M7-A4 (Designed-for-Families) is direct.

4.5 Florida — Online Protections for Minors Act (HB 3)

Cite: Fla. Stat. § 501.1736 (Online Protections for Minors), effective 1 January 2025. Status: the statute is principally directed at "social media platforms" within the meaning of Fla. Stat. § 501.1736(1)(f) — services that have addictive features and that allow account-holders to upload content for other users to view. Balance is not a social media platform within the statute's definition (no multi-user surface; no UGC sharing across households; no public profile; no public posting); the statute's central account-holder-age-verification and account-deletion regime therefore does not apply to Balance.

Handshake: to the extent any provision of HB 3 is read to apply to Balance notwithstanding the carve-out, our universal posture (Verifiable Parental Consent at kid onboarding; deletion paths at Delete-account page; no addictive design features) satisfies the substance.

4.6 Texas — SCOPE Act (Securing Children Online through Parental Empowerment)

Cite: Tex. Bus. & Com. Code Ch. 509, effective 1 September 2024. Status: the SCOPE Act applies to "digital service providers" that allow account-holders to socially interact with others. Balance is not in scope because Balance has no multi-user surface (the same carve-out logic as Florida HB 3).

Handshake: to the extent any SCOPE-Act provision is read to apply, the universal posture above satisfies the substance. Texas-specific provisions on parental management of a minor's account are satisfied by Balance's posture that the parent is the account-holder; there is no separate minor account for Balance to manage.

4.7 Other state child-specific bills

The following bills have been enacted but are either enjoined, narrowly applicable to social-media platforms only, or not yet in force at the Effective date above. They are listed for transparency:

When any of these bills becomes both in force and applicable to Balance, this row is updated.


The COPPA Rule enumerates a non-exclusive list of methods by which Verifiable Parental Consent may be obtained (16 C.F.R. § 312.5(b)(2)). Balance's VPC mechanism is the combination of (a) email-verified parent account creation, (b) payment-method capture at subscription time using a credit card (a COPPA-recognised VPC method under § 312.5(b)(2)(ii)) or Google Play Billing (which itself runs a payment-method check), and (c) the parent's affirmative in-app action of creating the kid profile and pairing the kid's device, accompanied by a Verifiable Parental Consent screen that itemises the categories of data being authorised. The combination is at least as protective as the FTC's enumerated "sliding scale" VPC examples.

The VPC event is logged at parents.vpcEvents (planned for Phase 3.1 of our internal compliance plan) with: timestamp, scope (which kid; which categories of data), locale (which English/Spanish/Portuguese rendering of the notice the parent saw), the IP/region the parent was in at consent time (discarded after 90 days per Data Retention & Deletion Policy § 6), and the parent's identity (the parents._id foreign key).

A parent may revoke VPC at any time at Settings → Family → [kid name] → "Delete this kid", or by emailing . Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7.


6. Data residency for U.S. residents

Question Answer
Where is the backend hosted? United States. Specifically, Emergent Labs Inc. (Delaware) hosts the FastAPI backend on infrastructure located in the United States.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage US multi-region (us location).
Where are push notifications dispatched from? United States — Google Firebase Cloud Messaging dispatch endpoint.
Are any cross-border transfers involved for a U.S. resident? No. Every sub-processor that touches a U.S. resident's data is in the United States. The controller (BabaYaga Program, TOO) is a Kazakhstan legal entity but the controller does not directly hold any U.S. resident's data on Kazakhstan infrastructure; the controller exercises rights over the data through the U.S.-hosted backend operated by Emergent Labs Inc. under a written data-processing agreement.
Does any U.S. resident's data leave the United States? The controller's personnel in Kazakhstan have administrative access to the U.S.-hosted backend for operational purposes (incident response, account-deletion verification, support escalations). This is administrative access, not a data transfer. The substantive data-processing happens on U.S. infrastructure.

For the full cross-border-transfer treatment under U.S. state laws (which do not require a transfer-mechanism in the GDPR sense), see § 11 of this Annex.


7. Sub-processors that touch U.S. resident data

Sub-processor Role Location of processing Notes
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States Written DPA on file (per our sub-processor register); covers every PA-* processing activity in our Records of Processing Activities (Article 30) § 3.
Google LLC (Mountain View, CA, USA) — Google Cloud Storage Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) Ciphertext only. Google Cloud Storage cannot read the proof media; the file-encryption key never leaves the kid's device unwrapped.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) The backup archive holds the operational data we hold about the U.S. resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging (FCM) Delivers push notifications to the kid's and parent's devices United States Push body and title only (deliberately free of sensitive content); the push token attached to each device.
Google LLC — Google Sign-In (when the parent chooses Google as their identity provider) Authenticates the parent's Google identity United States We receive only the parent's googleSub (Google's stable opaque user identifier) and the email the parent consents to share. No other Google account data.
Google LLC — Google Play Billing (subscriptions) Processes the parent's subscription purchase United States We do NOT receive the parent's payment-card number; Google Play Billing returns to us only a subscription state token and the parent's purchase-token.
Resend (San Francisco, CA, USA) Delivers transactional email (welcome, password reset, security alerts) to the parent United States The parent's email address and the email body for each transactional message.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7. The full sub-processor list, with each row's DPA status, is at our sub-processor register.


8. U.S. resident rights — the universal common-denominator list

Regardless of the U.S. resident's state of residence, Balance honors the following rights, which are the most-protective common denominator across every comprehensive privacy law in § 3 above plus COPPA, and which Balance extends voluntarily to residents of states that do not currently provide them.

8.1 Right to know / right to confirm processing

A parent or kid (through the parent) may request confirmation of whether Balance is processing personal information about them and, if so, the categories of personal information, the categories of sources, the business and commercial purposes for processing, and the categories of third parties (including sub-processors) to whom Balance discloses the information. Response window: 45 calendar days, extendable by 45 days with written notice and a statement of the reason for the extension (CCPA/CPRA § 1798.130(a)(2)). Honored at .

8.2 Right to access / right to a copy

A parent or kid (through the parent) may request a copy of the personal information Balance has about them. Honored in-app (Settings → Family → [kid name] → "Export this kid's data") and out-of-app via . Response window same as § 8.1. Format: machine-readable JSON archive, plus a plain-English summary.

8.3 Right to correct / rectify

A parent may correct any inaccurate personal information about themselves or their kid. Honored in-app (Settings → Account → Edit) for fields the parent set, and at for any other inaccuracy.

8.4 Right to delete

A parent may request deletion of their account, their kid's account, or both. The cascade is the universal cascade documented in Data Retention & Deletion Policy § 7. Three paths:

Response window: 45 calendar days under state law and without unreasonable delay (in practice within 10 business days) for COPPA-grounded parental deletion requests (16 C.F.R. § 312.6(a)(3)). Where the deletion request would override a legal-retention obligation (e.g., the Kazakhstan tax-records overlay in our Records of Processing Activities (Article 30) PA-13, which Balance honors universally), we retain only the narrow record required by the overlay and we tell the parent so.

8.5 Right to opt out of sale / share

Balance does not sell or share personal information within the meaning of CCPA/CPRA or any state privacy law in § 3. The right is honored vacuously — there is nothing to opt out of — but a parent may nonetheless register an opt-out for the avoidance of doubt at . We confirm in writing that no sale or share has occurred or will occur.

8.6 Right to opt out of targeted advertising

Balance does not engage in targeted advertising — there is no advertising in Balance at all. The right is honored vacuously, as in § 8.5.

Balance does not engage in profiling within the meaning of CCPA/CPRA or any state privacy law in § 3. We do not score users; we do not use automated decision-making to deny anyone access to Balance; we do not use any user's personal data to make decisions that produce legal or similarly significant effects on that user. The right is honored vacuously.

8.8 Right to limit use of sensitive personal information (CCPA/CPRA only)

Balance does not process "sensitive personal information" within the meaning of CCPA/CPRA § 1798.140(ae). Specifically:

The right to limit is honored vacuously — there is no sensitive personal information being processed beyond what the parent voluntarily declared. Where the parent's proof media (photos / videos / audio) might be read by an unauthorised reader as "sensitive personal information" in the abstract, the architectural reality is that the proof media is end-to-end encrypted and unreadable by Balance, by Google Cloud Storage, or by any third party (our encryption-posture record § 2).

8.9 Right to portability

A parent or kid (through the parent) may request the personal information Balance holds about them in a portable, machine-readable format. Honored as part of § 8.2 (JSON archive).

8.10 Right to non-discrimination

Balance will not discriminate against a U.S. resident for exercising any right under § 8 — no denial of service, no surcharge, no degradation of service quality. This is the universal posture and is independently confirmed in Privacy Policy § 13.

8.11 Authorised agent

A U.S. resident may designate an authorised agent to exercise any of the rights in §§ 8.1–8.10. The authorisation must be in writing and must include sufficient information to verify the authority. Honored at .

8.12 Right to appeal a refused request (where applicable)

Where a state privacy law in § 3 grants a right to appeal a refused privacy request (e.g., VCDPA § 59.1-577(C); CPA § 6-1-1306(3); CTDPA § 42-518(d); UCPA — none; TDPSA § 541.156; OCPA § 646A.578; MCDPA-MN § 325O.05; MODPA § 14-4607(d); FDBR § 501.706(2)(c); DPDPA § 12D-105(b); NHPA § 507-H:5; NJDPA § 56:8-166.8; INCDPA § 24-15-4-1(c); KCDPA), a parent may appeal a Balance privacy-request refusal by replying to the refusal email with the word "APPEAL" and a statement of the reason. The appeal is reviewed by the Privacy Officer; a written response is provided within 60 calendar days of receipt of the appeal. If the appeal is refused, the parent may complain to the relevant state regulator in § 13 below.


9. Universal Opt-Out Signal — Global Privacy Control ("GPC")

Several states (California under CPRA, Colorado under CPA, Connecticut under CTDPA, Texas under TDPSA, Oregon under OCPA, and others by extension) require operators to honor a universal opt-out signal — in practice, the Global Privacy Control header (Sec-GPC: 1) — as a valid sale/share opt-out signal.

Balance does not sell or share personal information (§ 8.5 above), so the GPC signal is honored vacuously — receipt of the signal does not change Balance's processing because there is no sale or share to opt out of. We log the signal at our public website (balance.babayagaprogram.com) so we can demonstrate honor; the in-app surface does not transmit a Sec-GPC header because the in-app HTTP client is not a browser, but we deliberately maintain no sale/share posture so the question does not arise.


10. Children's data — handling the COPPA / state-overlay interaction

When a kid is under 13 (the COPPA threshold), COPPA controls. When a kid is between 13 and 18 (or whatever the state-specific minor threshold is — varies between 13, 15, 16, and 18 across § 3 and § 4), the heightened state-overlay rules in § 4 control. Balance applies whichever standard is most protective in each case, with the COPPA standard as the universal floor. The architectural posture (no multi-user surface; no advertising; no profiling; no third-party sharing beyond declared sub-processors; no engagement-maximising design; end-to-end-encrypted proof media; VPC at kid onboarding) is designed to satisfy every regime in the universal-policy + per-country-annex sense, so no per-kid configuration is required to comply.


11. Breach notification — U.S. state statutes

Where a security breach affects a U.S. resident's personal information, Balance will notify the affected resident and the relevant state authority in accordance with the state's breach-notification statute. The procedural mechanics live in our breach-notification runbook § 5–§ 9; this Annex provides the cross-reference table that the Runbook draws from.

State Statute Notification trigger Resident-notice deadline Authority-notice trigger and deadline
California Cal. Civ. Code § 1798.82 Unauthorised acquisition of computerised data that includes personal information "In the most expedient time possible and without unreasonable delay" Notify the California Attorney General if > 500 California residents affected (single incident)
Virginia Va. Code § 18.2-186.6 Unauthorised access to and acquisition of unencrypted and unredacted computerised data "Without unreasonable delay" Notify the Virginia Attorney General if any Virginia residents affected (no threshold)
Colorado Colo. Rev. Stat. § 6-1-716 Unauthorised acquisition of unencrypted computerised data Within 30 days of determination of breach Notify the Colorado Attorney General if > 500 Colorado residents affected
Connecticut Conn. Gen. Stat. § 36a-701b Unauthorised access to or acquisition of computerised data Within 60 days Notify the Connecticut Attorney General
Texas Tex. Bus. & Com. Code § 521.053 Unauthorised acquisition of computerised data Within 60 days Notify the Texas Attorney General if > 250 Texas residents affected
New York N.Y. Gen. Bus. Law § 899-aa + § 899-bb (SHIELD Act) Unauthorised access to or acquisition of computerised data, including access to private information "In the most expedient time possible and without unreasonable delay" Notify the New York Attorney General, the NY Department of State, and the NY State Police; consumer-reporting agencies if > 5,000 NY residents
Florida Fla. Stat. § 501.171 Unauthorised access to data in electronic form Within 30 days, extendable by 15 Notify the Florida Department of Legal Affairs if > 500 Florida residents affected
Illinois 815 ILCS 530/10 Unauthorised acquisition of computerised data "In the most expedient time possible and without unreasonable delay" Notify the Illinois Attorney General if > 500 Illinois residents affected
Massachusetts Mass. Gen. Laws ch. 93H Unauthorised acquisition or use of unencrypted computerised data "As soon as practicable and without unreasonable delay" Notify the Massachusetts Attorney General and the Director of Consumer Affairs (no threshold)
Maryland Md. Code Ann., Com. Law § 14-3504 Unauthorised acquisition of computerised data Within 45 days Notify the Maryland Attorney General
(every other U.S. state has its own breach-notification statute; the rows above are exemplars; the full table is in our breach-notification runbook § 9.5)

If a Balance breach affects a U.S. resident regardless of state, we will follow the most protective applicable timeline and notify the affected resident and the relevant state authority simultaneously. The internal breach-decision SLA is at our breach-notification runbook § 5.4: a preliminary classification within one business day, a fuller assessment within seven days, and an authority-and-resident notification trigger no later than the earliest applicable statutory deadline above.


12. Data-broker registration

Balance is not a "data broker" within the meaning of California's Data Broker Registration Act (Cal. Civ. Code § 1798.99.80 et seq.), Vermont's data-broker statute (9 V.S.A. § 2446), Oregon's data-broker registration (ORS § 646A.604), or Texas's data-broker statute (Tex. Bus. & Com. Code § 509.001). The reason is that Balance does not knowingly collect, sell, or share the personal information of consumers with whom the business does not have a direct relationship — every parent and every kid in Balance has a direct relationship with the controller (BabaYaga Program, TOO), and we do not on-sell or on-share their data. Balance is therefore not registered as a data broker in any U.S. state and is not required to register.

If at any future point Balance's business model changes such that a data-broker registration is required, the relevant state's registration is completed within the statutory window and this row is updated.


13. Complaint routes (per regulator)

A U.S. resident who believes Balance has violated any right under §§ 2, 4, 8, 9, 10, or 11 above may complain to:

13.1 Federal

13.2 State (by statute alphabetical — selected; the full list mirrors the table in § 3)

The URLs above are recorded as they appeared at the Last updated date above. If a regulator changes its URL between annual reviews, the FTC's general consumer-complaint route (§ 13.1) remains a backstop and we will direct any complaint to the right state regulator on receipt.

A U.S. resident may always first raise the matter with us at (DSAR; named individual: ). We will respond within the statutory window in § 8.1. Raising the matter with us first is not a precondition to complaining to a regulator; many state regulators encourage but do not require the consumer to attempt resolution with the operator first.


14. Cross-references


15. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of United States Country Annex.

← Back to Privacy Policy · Children's Privacy Notice