Balance — United States Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — also acts as Privacy Officer and Designated Child Safety Officer for all U.S. residents covered by this Annex. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) enactment of any new U.S. state comprehensive privacy law that takes effect before the next annual review, (b) any change to the federal COPPA framework (16 CFR Part 312) or the FTC's enforcement posture, (c) any litigation outcome that materially changes the enforceability of a state law referenced below, (d) any change to the universal opt-out signal framework (GPC), or (e) any change to a U.S. sub-processor's data-handling posture under our sub-processor register. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of a series of country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — US row).
- Children's Privacy Notice § 14 (Country annexes — US row).
- Child Safety Standards § 13 (Country annexes — US row).
- Terms of Service (governing-law carve-out for U.S. consumer-protection statutes).
- Subscription Terms (state auto-renewal statutes — California Bus. & Prof. Code § 17600 et seq.; New York GBL § 527-a; Vermont 9 V.S.A. § 2415; Oregon ORS § 646A.295; Tennessee Tenn. Code Ann. § 47-18-505; et al.).
- Data Retention & Deletion Policy (COPPA § 312.10 retention overlay + state attorney-general production-demand preservation periods).
- our breach-notification runbook (state breach-notification statutes — see § 11 below).
This Annex is the canonical U.S.-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a U.S. resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a U.S. resident a right that this Annex does not, the global Policy governs. The two are read together.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose state of residence is one of the fifty U.S. states, the District of Columbia, Puerto Rico, Guam, the U.S. Virgin Islands, American Samoa, the Northern Mariana Islands, or any other U.S. territory whose governing law treats the federal Children's Online Privacy Protection Act ("COPPA") as in force.
We determine state of residence at install/sign-up time by (a) the country and region the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
For inherited territories (Puerto Rico, Guam, U.S. Virgin Islands, American Samoa, Northern Mariana Islands), the federal-law layer of this Annex (§§ 2, 5, 9, 11–13) applies in full; the state-law layers in §§ 3 and 4 do not apply directly but their parallel federal-territory analogues are honored on a best-effort basis until the territory enacts its own comprehensive privacy law.
2. Federal layer — Children's Online Privacy Protection Act (COPPA)
2.1 Statutory cite
15 U.S.C. §§ 6501–6506, implemented at 16 C.F.R. Part 312 ("COPPA Rule"). The COPPA Rule sits with the U.S. Federal Trade Commission ("FTC"); the FTC enforces COPPA against operators of websites and online services directed to children under 13 and against operators with actual knowledge that they are collecting personal information from a child under 13. Balance is squarely in the first category (we self-declare "Children and older users" — mixed-audience track — per our country classification table § 1).
2.2 The notice + consent stack
| Touchpoint | What COPPA requires | Where Balance delivers it |
|---|---|---|
| Online notice (16 C.F.R. § 312.4(d)) | A clear, complete privacy notice describing what personal information the operator collects from children, how it uses the information, and its disclosure practices. | Privacy Policy (H1) at Privacy Policy. |
| Direct notice to parents (16 C.F.R. § 312.4(c)) | A separate, plain-language notice given directly to the parent at sign-up, before any collection of the child's personal information starts. | Children's Privacy Notice (H2) at Children's Privacy Notice. This notice is also surfaced in-app to the parent on the Verifiable Parental Consent screen at kid onboarding (Phase 3.1 of our internal compliance plan). |
| Verifiable Parental Consent (16 C.F.R. § 312.5) | The operator must obtain Verifiable Parental Consent before any collection, use, or disclosure of personal information from a child. | The parent creates an account using an email-and-password (or Google Sign-In), enters payment information at subscription time (a category of VPC method enumerated at 16 C.F.R. § 312.5(b)(2)(ii)), then creates the kid profile and pairs the kid's device. The act of creating the kid profile and pairing is logged as a Verifiable Parental Consent event with timestamp, consent scope, locale, and the parent's identity. The parent-creates-account-and-pairs-kid-device sequence is the consent mechanism; the kid never sees a consent screen. |
| Right of review (16 C.F.R. § 312.6) | The parent can review the child's personal information, can refuse to permit further collection or use, and can require deletion. | In-app: Settings → Family → [kid name] → "Export this kid's data" + "Delete this kid". Out-of-app: Delete-account page + . |
| Data security (16 C.F.R. § 312.8) | Reasonable procedures to protect the confidentiality, security, and integrity of personal information. | our encryption-posture record; our Records of Processing Activities (Article 30) § 7 (Article 32 control table — read as the COPPA § 312.8 control table in the U.S. context). |
| Data retention and deletion (16 C.F.R. § 312.10) | An operator must retain personal information for only as long as is reasonably necessary, and must delete using reasonable measures. | Data Retention & Deletion Policy (the COPPA-mandated written retention schedule). |
2.3 Specific FTC-recognised exception we rely on
Under 16 C.F.R. § 312.5(c)(3), an operator may collect a persistent identifier and no other personal information from a child without prior VPC, where the identifier is used solely to provide support for the internal operations of the website or service. Balance does NOT rely on this exception — we obtain full VPC at kid onboarding, before any collection starts. The exception is documented here for transparency only.
2.4 No advertising; no profiling; no third-party sale
Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, does not build a behavioural-advertising profile of any user, and does not sell, lease, or share personal information with any third party for advertising or marketing purposes. This is the per-our internal compliance plan § 6.3 universal posture and is independently confirmed in:
- the Play Console Data Safety form § 2 (Contains ads: No) and § 3 (every row: Shared with third parties: No).
- the Play Console Child Safety Standards declaration § 3 ATTESTATION-D and ATTESTATION-G.
- the Play Console Target Audience form § 3 M7-A4 (Designed-for-Families) and § 4 M7-B6 (no gambling / no lootbox / no randomised reward).
2.5 FTC complaint route
A parent who believes Balance has violated COPPA may file a complaint with the FTC:
- Online:
https://reportfraud.ftc.gov/(complaint form for consumer-protection violations) orhttps://www.ftc.gov/coppa-complaint(the COPPA-specific intake referenced in the FTC's COPPA materials). - By mail: Federal Trade Commission, Consumer Response Center, 600 Pennsylvania Avenue, NW, Washington, DC 20580, USA.
- By telephone: 1-877-FTC-HELP (1-877-382-4357).
Filing a complaint with the FTC does not affect any other right the parent has under federal, state, or local law. We will cooperate with any FTC inquiry directed at us; we are not aware of any open FTC investigation as of the Effective date above.
2.6 CSAE / 18 U.S.C. § 2258A — NCMEC CyberTipline reporting
If we obtain actual knowledge of a fact or circumstance that constitutes a violation of the federal child-sexual-abuse-material statutes referenced in 18 U.S.C. § 2258A(a)(2), we will file a report with the National Center for Missing & Exploited Children ("NCMEC") via the CyberTipline at https://report.cybertip.org/. The procedure is documented in Child Safety Standards § 8.1, § 9 and the Play Console Child Safety Standards declaration § 3 M6-Q5.
We acknowledge the federal preservation duty under 18 U.S.C. § 2258A(h): NCMEC reports must be preserved for at least 90 days, extendable by 90 days on agency request. Our preservation procedure in our breach-notification runbook § 5 honors this period.
2.7 Federal Trade Commission Safeguards Rule and Section 5
The FTC's Safeguards Rule under the Gramm-Leach-Bliley Act (16 C.F.R. Part 314) does not apply to Balance because Balance is not a "financial institution" within the meaning of GLBA. The FTC's general Section 5 authority over "unfair or deceptive acts or practices" does apply; the universal posture in Privacy Policy and the strict no-deception drafting of every public document in this Annex set is designed to remain inside the Section 5 bright lines.
3. State layer — comprehensive privacy laws
As of the Effective date above, the following U.S. states have enacted a comprehensive consumer privacy law that is either in force or will be in force before the next annual review of this Annex. The table is the canonical Balance-side mapping; each row drives the rights enumerated in § 8 below and the complaint routes enumerated in § 13 below.
| State | Statute (short cite) | In force from | DSAR response window | Cure period (pre-suit) | Regulator | Private right of action? | Sensitive-data opt-in required? |
|---|---|---|---|---|---|---|---|
| California | California Consumer Privacy Act + California Privacy Rights Act ("CCPA / CPRA"); Cal. Civ. Code § 1798.100 et seq. | 1 Jan 2020 (CCPA); 1 Jan 2023 (CPRA amendments) | 45 calendar days, extendable by 45 days with notice | 30 days (sunset for AG actions 1 Jan 2023; CPPA continues to use cure case-by-case) | California Privacy Protection Agency (CPPA) + California Attorney General | Yes, narrow — security-breach private right at Civ. Code § 1798.150 | Yes (opt-in for "sensitive personal information") |
| Virginia | Virginia Consumer Data Protection Act ("VCDPA"); Va. Code § 59.1-575 et seq. | 1 Jan 2023 | 45 calendar days, extendable by 45 | 30 days | Virginia Attorney General | No | Yes (opt-in for "sensitive data") |
| Colorado | Colorado Privacy Act ("CPA"); Colo. Rev. Stat. § 6-1-1301 et seq. | 1 Jul 2023 | 45 calendar days, extendable by 45 | 60 days (sunsets 1 Jan 2025; AG continues to use cure case-by-case) | Colorado Attorney General | No | Yes (opt-in) |
| Connecticut | Connecticut Data Privacy Act ("CTDPA"); Conn. Gen. Stat. § 42-515 et seq. | 1 Jul 2023 | 45 calendar days, extendable by 45 | 60 days (sunsets 1 Jan 2025) | Connecticut Attorney General | No | Yes (opt-in) |
| Utah | Utah Consumer Privacy Act ("UCPA"); Utah Code § 13-61-101 et seq. | 31 Dec 2023 | 45 calendar days, extendable by 45 | 30 days | Utah Division of Consumer Protection + Utah Attorney General | No | No (opt-out only for sensitive) |
| Texas | Texas Data Privacy and Security Act ("TDPSA"); Tex. Bus. & Com. Code Ch. 541 | 1 Jul 2024 | 45 calendar days, extendable by 45 | 30 days | Texas Attorney General | No | Yes (opt-in for sensitive data of consumers known to be under 13) |
| Oregon | Oregon Consumer Privacy Act ("OCPA"); ORS § 646A.570 et seq. | 1 Jul 2024 | 45 calendar days, extendable by 45 | 30 days (sunsets 1 Jan 2026) | Oregon Attorney General | No | Yes (opt-in) |
| Montana | Montana Consumer Data Privacy Act ("MCDPA"); Mont. Code Ann. § 30-14-2801 et seq. | 1 Oct 2024 | 45 calendar days, extendable by 45 | 60 days (sunsets 1 Apr 2026) | Montana Attorney General | No | Yes (opt-in) |
| Florida | Florida Digital Bill of Rights ("FDBR"); Fla. Stat. § 501.701 et seq. | 1 Jul 2024 | 45 calendar days, extendable by 45 | 45 days | Florida Department of Legal Affairs + Florida Attorney General | No (with narrow exceptions) | Yes (opt-in for sensitive data of known minors) |
| Delaware | Delaware Personal Data Privacy Act ("DPDPA"); 6 Del. C. § 12D-101 et seq. | 1 Jan 2025 | 45 calendar days, extendable by 45 | 60 days (sunsets 31 Dec 2025) | Delaware Department of Justice + Delaware Attorney General | No | Yes (opt-in) |
| Iowa | Iowa Consumer Data Protection Act ("ICDPA"); Iowa Code § 715D.1 et seq. | 1 Jan 2025 | 90 calendar days | 90 days | Iowa Attorney General | No | No (notice/opt-out only) |
| New Hampshire | New Hampshire Privacy Act ("NHPA"); RSA 507-H | 1 Jan 2025 | 45 calendar days, extendable by 45 | 60 days (sunsets 31 Dec 2025) | New Hampshire Attorney General | No | Yes (opt-in) |
| New Jersey | New Jersey Data Privacy Act ("NJDPA"); N.J. Stat. Ann. § 56:8-166.4 et seq. | 15 Jan 2025 | 45 calendar days, extendable by 45 | 30 days (sunsets 15 Jul 2026) | New Jersey Division of Consumer Affairs + New Jersey Attorney General | No | Yes (opt-in) |
| Nebraska | Nebraska Data Privacy Act ("NEDPA"); Neb. Rev. Stat. § 87-1101 et seq. | 1 Jan 2025 | 45 calendar days, extendable by 45 | 30 days | Nebraska Attorney General | No | Yes (opt-in) |
| Tennessee | Tennessee Information Protection Act ("TIPA"); Tenn. Code Ann. § 47-18-3201 et seq. | 1 Jul 2025 | 45 calendar days, extendable by 45 | 60 days | Tennessee Attorney General | No | Yes (opt-in) |
| Minnesota | Minnesota Consumer Data Privacy Act ("MCDPA-MN"); Minn. Stat. § 325O.05 et seq. | 31 Jul 2025 | 45 calendar days, extendable by 45 | 30 days (sunsets 31 Jan 2026) | Minnesota Attorney General | No | Yes (opt-in) |
| Maryland | Maryland Online Data Privacy Act ("MODPA"); Md. Code Ann., Com. Law § 14-4601 et seq. | 1 Oct 2025 | 45 calendar days, extendable by 45 | 60 days | Maryland Attorney General | No | Strict — opt-in plus a hard data-minimisation rule that forbids processing of sensitive data unless strictly necessary to provide the service the consumer requested (MODPA § 14-4607(b)) |
| Indiana | Indiana Consumer Data Protection Act ("INCDPA"); Ind. Code § 24-15-1-1 et seq. | 1 Jan 2026 | 45 calendar days, extendable by 45 | 30 days | Indiana Attorney General | No | Yes (opt-in) |
| Kentucky | Kentucky Consumer Data Protection Act ("KCDPA"); KRS Ch. 367 (new Subchapter) | 1 Jan 2026 | 45 calendar days, extendable by 45 | 30 days | Kentucky Attorney General | No | Yes (opt-in) |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act ("RIDTPPA"); R.I. Gen. Laws § 6-48.1-1 et seq. | 1 Jan 2026 | 45 calendar days, extendable by 45 | 30 days | Rhode Island Attorney General | No | Yes (opt-in) |
Reading-rule. Where a U.S. resident's state of residence is not in the table above, Balance still extends to that resident the rights enumerated in § 8 below, on a "most-protective common denominator" basis, so the resident does not have to wait for their state legislature to act before exercising the rights other Balance users already enjoy. This is the universal posture documented in our internal compliance plan § 6.3 (the "global policy + per-country annex" architecture) and is not contingent on the resident's state law.
Pending bills (not in force at the Effective date). Pennsylvania, Massachusetts, Vermont (general; the existing Vermont data-broker law is separately referenced in § 12), New York (general comprehensive; the NY Child Data Protection Act is separately in § 4), Washington (general; the existing My Health My Data Act covers health-specific data and does not apply to Balance because we do not process health data), Michigan, and Illinois (general; the existing BIPA covers biometric data and does not apply to Balance because we do not collect biometric data). When any of these enacts in a form that takes effect before the next annual review of this Annex, the table above is updated.
4. State layer — child-specific overlays
A handful of U.S. states have enacted child-specific privacy or age-appropriate-design laws that overlay the comprehensive privacy laws in § 3. Balance's universal posture (no advertising, no profiling, no third-party sharing beyond declared sub-processors, no dark patterns, Verifiable Parental Consent for every kid) satisfies the substance of every such law as of the Effective date above; the rows below cite each law and the specific Balance-side handshake.
4.1 California — Age-Appropriate Design Code Act ("CA AADC")
Cite: Cal. Civ. Code §§ 1798.99.28–1798.99.40. Status: the statute was enacted in 2022; portions have been the subject of litigation (NetChoice v. Bonta, Ninth Circuit and underlying Northern District of California) and the enforceability of certain provisions has been the subject of preliminary injunction. Balance's substantive posture is independent of the litigation outcome — we apply the AADC standard regardless, because every element of the AADC standard is satisfied by the universal design rule in our country classification table § 2 and the architectural posture documented in Child Safety Standards § 5.
Handshake: Balance does not collect, share, or process the precise location of a child; does not estimate a child's age beyond the parent's declared age at kid creation; does not use a dark pattern, manipulative cue, or engagement-maximising nudge directed at a child; does not enable a child to communicate with adults outside their household; does not show advertising; does not profile a child. The AADC's data-protection-impact-assessment requirement (Civ. Code § 1798.99.31(a)(1)) is satisfied by our Data Protection Impact Assessment (H8).
4.2 Maryland — Age-Appropriate Design Code ("MD AADC" / "Kids Code")
Cite: Md. Code Ann., Com. Law § 14-4602 et seq. (the Maryland Age-Appropriate Design Code, MD Kids Code, enacted as H.B. 901 and effective 1 October 2024). Status: in force at the Effective date above.
Handshake: the MD Kids Code requires age-appropriate design for online services likely to be accessed by children, prohibits the processing of children's personal data for any purpose other than the one for which it was collected (unless the operator can demonstrate a compelling reason and the processing is in the best interests of the child), requires a data-protection-impact-assessment, and prohibits dark patterns and design features that promote compulsive use. Balance's universal posture (data-minimised by design; no engagement-maximising features; no advertising; no third-party sharing; explicit DPIA in H8; explicit children's notice in H2) satisfies each element.
4.3 New York — Child Data Protection Act
Cite: N.Y. Gen. Bus. Law § 899-ff et seq. (the New York Child Data Protection Act, S.B. S7695-A, effective 20 June 2025). Status: in force at the Effective date above.
Handshake: the NY Child Data Protection Act prohibits the processing of a covered minor's personal data except for the purpose of providing the service the minor (or their parent) requested, the operator's permitted purposes enumerated in the statute, or with informed consent. Targeted advertising to minors is prohibited. Balance's posture (no advertising; processing limited to providing the parental-control service the parent set up; VPC at kid onboarding) is in compliance.
4.4 Connecticut — child-specific provisions of the CTDPA (S.B. 3, Public Act 23-56)
Cite: Public Act 23-56 amends the CTDPA at Conn. Gen. Stat. § 42-515 et seq., adding heightened protections for consumers known to be between 13 and 18 years old. Status: effective 1 October 2024.
Handshake: the CT amendments forbid an operator that has actual knowledge a consumer is between 13 and 18 from selling that consumer's personal data, processing it for targeted advertising, or processing it for any "system design feature" that "increases, sustains, or extends the consumer's use" — i.e., engagement-maximising design directed at minors is forbidden. Balance does not sell personal data; does not engage in targeted advertising; does not engage in engagement-maximising design directed at any user. The handshake to M6 § 3 ATTESTATION-D and M7 § 3 M7-A4 (Designed-for-Families) is direct.
4.5 Florida — Online Protections for Minors Act (HB 3)
Cite: Fla. Stat. § 501.1736 (Online Protections for Minors), effective 1 January 2025. Status: the statute is principally directed at "social media platforms" within the meaning of Fla. Stat. § 501.1736(1)(f) — services that have addictive features and that allow account-holders to upload content for other users to view. Balance is not a social media platform within the statute's definition (no multi-user surface; no UGC sharing across households; no public profile; no public posting); the statute's central account-holder-age-verification and account-deletion regime therefore does not apply to Balance.
Handshake: to the extent any provision of HB 3 is read to apply to Balance notwithstanding the carve-out, our universal posture (Verifiable Parental Consent at kid onboarding; deletion paths at Delete-account page; no addictive design features) satisfies the substance.
4.6 Texas — SCOPE Act (Securing Children Online through Parental Empowerment)
Cite: Tex. Bus. & Com. Code Ch. 509, effective 1 September 2024. Status: the SCOPE Act applies to "digital service providers" that allow account-holders to socially interact with others. Balance is not in scope because Balance has no multi-user surface (the same carve-out logic as Florida HB 3).
Handshake: to the extent any SCOPE-Act provision is read to apply, the universal posture above satisfies the substance. Texas-specific provisions on parental management of a minor's account are satisfied by Balance's posture that the parent is the account-holder; there is no separate minor account for Balance to manage.
4.7 Other state child-specific bills
The following bills have been enacted but are either enjoined, narrowly applicable to social-media platforms only, or not yet in force at the Effective date above. They are listed for transparency:
- Utah Social Media Regulation Act (SB 152 / SB 194 as amended) — directed at social-media-platform account-holders; does not apply to Balance.
- Arkansas Social Media Safety Act — enjoined in federal court; does not apply to Balance regardless.
- California Social Media Transparency Act (AB 587) — directed at large social-media platforms (>$100M revenue); does not apply to Balance.
When any of these bills becomes both in force and applicable to Balance, this row is updated.
5. Verifiable Parental Consent (VPC) — how Balance satisfies 16 C.F.R. § 312.5
The COPPA Rule enumerates a non-exclusive list of methods by which Verifiable Parental Consent may be obtained (16 C.F.R. § 312.5(b)(2)). Balance's VPC mechanism is the combination of (a) email-verified parent account creation, (b) payment-method capture at subscription time using a credit card (a COPPA-recognised VPC method under § 312.5(b)(2)(ii)) or Google Play Billing (which itself runs a payment-method check), and (c) the parent's affirmative in-app action of creating the kid profile and pairing the kid's device, accompanied by a Verifiable Parental Consent screen that itemises the categories of data being authorised. The combination is at least as protective as the FTC's enumerated "sliding scale" VPC examples.
The VPC event is logged at parents.vpcEvents (planned for Phase 3.1 of our internal compliance plan) with: timestamp, scope (which kid; which categories of data), locale (which English/Spanish/Portuguese rendering of the notice the parent saw), the IP/region the parent was in at consent time (discarded after 90 days per Data Retention & Deletion Policy § 6), and the parent's identity (the parents._id foreign key).
A parent may revoke VPC at any time at Settings → Family → [kid name] → "Delete this kid", or by emailing . Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7.
6. Data residency for U.S. residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Specifically, Emergent Labs Inc. (Delaware) hosts the FastAPI backend on infrastructure located in the United States. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage US multi-region (us location). |
| Where are push notifications dispatched from? | United States — Google Firebase Cloud Messaging dispatch endpoint. |
| Are any cross-border transfers involved for a U.S. resident? | No. Every sub-processor that touches a U.S. resident's data is in the United States. The controller (BabaYaga Program, TOO) is a Kazakhstan legal entity but the controller does not directly hold any U.S. resident's data on Kazakhstan infrastructure; the controller exercises rights over the data through the U.S.-hosted backend operated by Emergent Labs Inc. under a written data-processing agreement. |
| Does any U.S. resident's data leave the United States? | The controller's personnel in Kazakhstan have administrative access to the U.S.-hosted backend for operational purposes (incident response, account-deletion verification, support escalations). This is administrative access, not a data transfer. The substantive data-processing happens on U.S. infrastructure. |
For the full cross-border-transfer treatment under U.S. state laws (which do not require a transfer-mechanism in the GDPR sense), see § 11 of this Annex.
7. Sub-processors that touch U.S. resident data
| Sub-processor | Role | Location of processing | Notes |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | Written DPA on file (per our sub-processor register); covers every PA-* processing activity in our Records of Processing Activities (Article 30) § 3. |
| Google LLC (Mountain View, CA, USA) — Google Cloud Storage | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
Ciphertext only. Google Cloud Storage cannot read the proof media; the file-encryption key never leaves the kid's device unwrapped. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
The backup archive holds the operational data we hold about the U.S. resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging (FCM) | Delivers push notifications to the kid's and parent's devices | United States | Push body and title only (deliberately free of sensitive content); the push token attached to each device. |
| Google LLC — Google Sign-In (when the parent chooses Google as their identity provider) | Authenticates the parent's Google identity | United States | We receive only the parent's googleSub (Google's stable opaque user identifier) and the email the parent consents to share. No other Google account data. |
| Google LLC — Google Play Billing (subscriptions) | Processes the parent's subscription purchase | United States | We do NOT receive the parent's payment-card number; Google Play Billing returns to us only a subscription state token and the parent's purchase-token. |
| Resend (San Francisco, CA, USA) | Delivers transactional email (welcome, password reset, security alerts) to the parent | United States | The parent's email address and the email body for each transactional message. |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7. The full sub-processor list, with each row's DPA status, is at our sub-processor register.
8. U.S. resident rights — the universal common-denominator list
Regardless of the U.S. resident's state of residence, Balance honors the following rights, which are the most-protective common denominator across every comprehensive privacy law in § 3 above plus COPPA, and which Balance extends voluntarily to residents of states that do not currently provide them.
8.1 Right to know / right to confirm processing
A parent or kid (through the parent) may request confirmation of whether Balance is processing personal information about them and, if so, the categories of personal information, the categories of sources, the business and commercial purposes for processing, and the categories of third parties (including sub-processors) to whom Balance discloses the information. Response window: 45 calendar days, extendable by 45 days with written notice and a statement of the reason for the extension (CCPA/CPRA § 1798.130(a)(2)). Honored at .
8.2 Right to access / right to a copy
A parent or kid (through the parent) may request a copy of the personal information Balance has about them. Honored in-app (Settings → Family → [kid name] → "Export this kid's data") and out-of-app via . Response window same as § 8.1. Format: machine-readable JSON archive, plus a plain-English summary.
8.3 Right to correct / rectify
A parent may correct any inaccurate personal information about themselves or their kid. Honored in-app (Settings → Account → Edit) for fields the parent set, and at for any other inaccuracy.
8.4 Right to delete
A parent may request deletion of their account, their kid's account, or both. The cascade is the universal cascade documented in Data Retention & Deletion Policy § 7. Three paths:
- In-app: Parent Settings → "Delete my account" (or [kid name] → "Delete this kid" for a single-kid deletion).
- Public deletion page: Delete-account page.
- Direct contact:
.
Response window: 45 calendar days under state law and without unreasonable delay (in practice within 10 business days) for COPPA-grounded parental deletion requests (16 C.F.R. § 312.6(a)(3)). Where the deletion request would override a legal-retention obligation (e.g., the Kazakhstan tax-records overlay in our Records of Processing Activities (Article 30) PA-13, which Balance honors universally), we retain only the narrow record required by the overlay and we tell the parent so.
8.5 Right to opt out of sale / share
Balance does not sell or share personal information within the meaning of CCPA/CPRA or any state privacy law in § 3. The right is honored vacuously — there is nothing to opt out of — but a parent may nonetheless register an opt-out for the avoidance of doubt at . We confirm in writing that no sale or share has occurred or will occur.
8.6 Right to opt out of targeted advertising
Balance does not engage in targeted advertising — there is no advertising in Balance at all. The right is honored vacuously, as in § 8.5.
8.7 Right to opt out of profiling that produces legal or similarly significant effects
Balance does not engage in profiling within the meaning of CCPA/CPRA or any state privacy law in § 3. We do not score users; we do not use automated decision-making to deny anyone access to Balance; we do not use any user's personal data to make decisions that produce legal or similarly significant effects on that user. The right is honored vacuously.
8.8 Right to limit use of sensitive personal information (CCPA/CPRA only)
Balance does not process "sensitive personal information" within the meaning of CCPA/CPRA § 1798.140(ae). Specifically:
- No Social Security number, driver's license number, state-ID-card number, or passport number.
- No financial-account number, debit-card number, or credit-card number combined with any access code (the parent's subscription payment is processed by Google Play Billing; we never see the card number).
- No precise geolocation (LOCATION permissions are not requested — our permissions register § 2).
- No racial or ethnic origin, religious or philosophical beliefs, or union membership.
- No genetic data or biometric data processed for the purpose of uniquely identifying a person.
- No personal information collected and analysed concerning a consumer's health, sex life, or sexual orientation.
The right to limit is honored vacuously — there is no sensitive personal information being processed beyond what the parent voluntarily declared. Where the parent's proof media (photos / videos / audio) might be read by an unauthorised reader as "sensitive personal information" in the abstract, the architectural reality is that the proof media is end-to-end encrypted and unreadable by Balance, by Google Cloud Storage, or by any third party (our encryption-posture record § 2).
8.9 Right to portability
A parent or kid (through the parent) may request the personal information Balance holds about them in a portable, machine-readable format. Honored as part of § 8.2 (JSON archive).
8.10 Right to non-discrimination
Balance will not discriminate against a U.S. resident for exercising any right under § 8 — no denial of service, no surcharge, no degradation of service quality. This is the universal posture and is independently confirmed in Privacy Policy § 13.
8.11 Authorised agent
A U.S. resident may designate an authorised agent to exercise any of the rights in §§ 8.1–8.10. The authorisation must be in writing and must include sufficient information to verify the authority. Honored at .
8.12 Right to appeal a refused request (where applicable)
Where a state privacy law in § 3 grants a right to appeal a refused privacy request (e.g., VCDPA § 59.1-577(C); CPA § 6-1-1306(3); CTDPA § 42-518(d); UCPA — none; TDPSA § 541.156; OCPA § 646A.578; MCDPA-MN § 325O.05; MODPA § 14-4607(d); FDBR § 501.706(2)(c); DPDPA § 12D-105(b); NHPA § 507-H:5; NJDPA § 56:8-166.8; INCDPA § 24-15-4-1(c); KCDPA), a parent may appeal a Balance privacy-request refusal by replying to the refusal email with the word "APPEAL" and a statement of the reason. The appeal is reviewed by the Privacy Officer; a written response is provided within 60 calendar days of receipt of the appeal. If the appeal is refused, the parent may complain to the relevant state regulator in § 13 below.
9. Universal Opt-Out Signal — Global Privacy Control ("GPC")
Several states (California under CPRA, Colorado under CPA, Connecticut under CTDPA, Texas under TDPSA, Oregon under OCPA, and others by extension) require operators to honor a universal opt-out signal — in practice, the Global Privacy Control header (Sec-GPC: 1) — as a valid sale/share opt-out signal.
Balance does not sell or share personal information (§ 8.5 above), so the GPC signal is honored vacuously — receipt of the signal does not change Balance's processing because there is no sale or share to opt out of. We log the signal at our public website (balance.babayagaprogram.com) so we can demonstrate honor; the in-app surface does not transmit a Sec-GPC header because the in-app HTTP client is not a browser, but we deliberately maintain no sale/share posture so the question does not arise.
10. Children's data — handling the COPPA / state-overlay interaction
When a kid is under 13 (the COPPA threshold), COPPA controls. When a kid is between 13 and 18 (or whatever the state-specific minor threshold is — varies between 13, 15, 16, and 18 across § 3 and § 4), the heightened state-overlay rules in § 4 control. Balance applies whichever standard is most protective in each case, with the COPPA standard as the universal floor. The architectural posture (no multi-user surface; no advertising; no profiling; no third-party sharing beyond declared sub-processors; no engagement-maximising design; end-to-end-encrypted proof media; VPC at kid onboarding) is designed to satisfy every regime in the universal-policy + per-country-annex sense, so no per-kid configuration is required to comply.
11. Breach notification — U.S. state statutes
Where a security breach affects a U.S. resident's personal information, Balance will notify the affected resident and the relevant state authority in accordance with the state's breach-notification statute. The procedural mechanics live in our breach-notification runbook § 5–§ 9; this Annex provides the cross-reference table that the Runbook draws from.
| State | Statute | Notification trigger | Resident-notice deadline | Authority-notice trigger and deadline |
|---|---|---|---|---|
| California | Cal. Civ. Code § 1798.82 | Unauthorised acquisition of computerised data that includes personal information | "In the most expedient time possible and without unreasonable delay" | Notify the California Attorney General if > 500 California residents affected (single incident) |
| Virginia | Va. Code § 18.2-186.6 | Unauthorised access to and acquisition of unencrypted and unredacted computerised data | "Without unreasonable delay" | Notify the Virginia Attorney General if any Virginia residents affected (no threshold) |
| Colorado | Colo. Rev. Stat. § 6-1-716 | Unauthorised acquisition of unencrypted computerised data | Within 30 days of determination of breach | Notify the Colorado Attorney General if > 500 Colorado residents affected |
| Connecticut | Conn. Gen. Stat. § 36a-701b | Unauthorised access to or acquisition of computerised data | Within 60 days | Notify the Connecticut Attorney General |
| Texas | Tex. Bus. & Com. Code § 521.053 | Unauthorised acquisition of computerised data | Within 60 days | Notify the Texas Attorney General if > 250 Texas residents affected |
| New York | N.Y. Gen. Bus. Law § 899-aa + § 899-bb (SHIELD Act) | Unauthorised access to or acquisition of computerised data, including access to private information | "In the most expedient time possible and without unreasonable delay" | Notify the New York Attorney General, the NY Department of State, and the NY State Police; consumer-reporting agencies if > 5,000 NY residents |
| Florida | Fla. Stat. § 501.171 | Unauthorised access to data in electronic form | Within 30 days, extendable by 15 | Notify the Florida Department of Legal Affairs if > 500 Florida residents affected |
| Illinois | 815 ILCS 530/10 | Unauthorised acquisition of computerised data | "In the most expedient time possible and without unreasonable delay" | Notify the Illinois Attorney General if > 500 Illinois residents affected |
| Massachusetts | Mass. Gen. Laws ch. 93H | Unauthorised acquisition or use of unencrypted computerised data | "As soon as practicable and without unreasonable delay" | Notify the Massachusetts Attorney General and the Director of Consumer Affairs (no threshold) |
| Maryland | Md. Code Ann., Com. Law § 14-3504 | Unauthorised acquisition of computerised data | Within 45 days | Notify the Maryland Attorney General |
| (every other U.S. state has its own breach-notification statute; the rows above are exemplars; the full table is in our breach-notification runbook § 9.5) |
If a Balance breach affects a U.S. resident regardless of state, we will follow the most protective applicable timeline and notify the affected resident and the relevant state authority simultaneously. The internal breach-decision SLA is at our breach-notification runbook § 5.4: a preliminary classification within one business day, a fuller assessment within seven days, and an authority-and-resident notification trigger no later than the earliest applicable statutory deadline above.
12. Data-broker registration
Balance is not a "data broker" within the meaning of California's Data Broker Registration Act (Cal. Civ. Code § 1798.99.80 et seq.), Vermont's data-broker statute (9 V.S.A. § 2446), Oregon's data-broker registration (ORS § 646A.604), or Texas's data-broker statute (Tex. Bus. & Com. Code § 509.001). The reason is that Balance does not knowingly collect, sell, or share the personal information of consumers with whom the business does not have a direct relationship — every parent and every kid in Balance has a direct relationship with the controller (BabaYaga Program, TOO), and we do not on-sell or on-share their data. Balance is therefore not registered as a data broker in any U.S. state and is not required to register.
If at any future point Balance's business model changes such that a data-broker registration is required, the relevant state's registration is completed within the statutory window and this row is updated.
13. Complaint routes (per regulator)
A U.S. resident who believes Balance has violated any right under §§ 2, 4, 8, 9, 10, or 11 above may complain to:
13.1 Federal
- U.S. Federal Trade Commission (FTC). Online:
https://reportfraud.ftc.gov/orhttps://www.ftc.gov/coppa-complaint. By mail: 600 Pennsylvania Avenue NW, Washington, DC 20580. By phone: 1-877-FTC-HELP. - National Center for Missing & Exploited Children (NCMEC) — CyberTipline (for CSAE matters only). Online:
https://report.cybertip.org/.
13.2 State (by statute alphabetical — selected; the full list mirrors the table in § 3)
- California Privacy Protection Agency (CPPA). Online:
https://cppa.ca.gov/contact/. By mail: 2101 Arena Boulevard, Sacramento, CA 95834. - California Attorney General — Privacy. Online:
https://oag.ca.gov/contact/consumer-complaint-against-business-or-company. Submit a CCPA/CPRA complaint at:https://oag.ca.gov/privacy/ccpa. - Virginia Attorney General — Consumer Protection. Online:
https://www.oag.state.va.us/consumercomplaintform. - Colorado Attorney General — Privacy Section. Online:
https://coag.gov/file-complaint/file-privacy-complaint/. - Connecticut Attorney General — Privacy Section. Online:
https://portal.ct.gov/AG/Consumer-Issues/Consumer-Complaint-Form. - Utah Division of Consumer Protection. Online:
https://dcp.utah.gov/file-a-complaint/. - Texas Attorney General — Consumer Protection Division. Online:
https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint. - Oregon Attorney General — Consumer Protection Section. Online:
https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/file-a-privacy-complaint/. - Montana Office of Consumer Protection. Online:
https://dojmt.gov/consumer/consumer-complaints/. - Florida Attorney General — Consumer Protection. Online:
https://www.myfloridalegal.com/contact-us/consumer-complaint. - Delaware Department of Justice — Consumer Protection. Online:
https://attorneygeneral.delaware.gov/fraud/cpu/complaint/. - Iowa Attorney General — Consumer Protection. Online:
https://www.iowaattorneygeneral.gov/for-consumers/file-a-consumer-complaint. - New Hampshire Department of Justice — Consumer Protection. Online:
https://www.doj.nh.gov/consumer/complaints.htm. - New Jersey Division of Consumer Affairs. Online:
https://www.njconsumeraffairs.gov/Pages/FileAComplaint.aspx. - Nebraska Attorney General — Consumer Affairs. Online:
https://protectthegoodlife.nebraska.gov/file-complaint. - Tennessee Attorney General — Consumer Affairs. Online:
https://www.tn.gov/attorneygeneral/working-for-tennessee/consumer/file-a-consumer-complaint.html. - Minnesota Attorney General — Consumer Affairs. Online:
https://www.ag.state.mn.us/Office/Complaint.asp. - Maryland Attorney General — Consumer Protection. Online:
https://www.marylandattorneygeneral.gov/Pages/CPD/complaint.aspx. - Indiana Attorney General — Consumer Protection. Online:
https://www.in.gov/attorneygeneral/consumer-protection-division/file-a-complaint/. - Kentucky Attorney General — Consumer Protection. Online:
https://ag.ky.gov/Resources/Consumer-Resources/Pages/file-a-complaint.aspx. - Rhode Island Attorney General — Consumer Protection Unit. Online:
https://riag.ri.gov/consumer-protection/file-consumer-complaint.
The URLs above are recorded as they appeared at the Last updated date above. If a regulator changes its URL between annual reviews, the FTC's general consumer-complaint route (§ 13.1) remains a backstop and we will direct any complaint to the right state regulator on receipt.
A U.S. resident may always first raise the matter with us at (DSAR; named individual: ). We will respond within the statutory window in § 8.1. Raising the matter with us first is not a precondition to complaining to a regulator; many state regulators encourage but do not require the consumer to attempt resolution with the operator first.
14. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — U.S. is the destination jurisdiction; the controller in Kazakhstan is the data exporter.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
15. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–13 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A new U.S. state comprehensive privacy law that takes effect before the next annual review triggers an off-cycle update to § 3 and § 13 (and § 8, § 11 as applicable).
- A new U.S. state child-specific overlay that takes effect before the next annual review triggers an off-cycle update to § 4 (and § 8 if a new right is added).
- A material federal-level change (e.g., the long-pending federal American Privacy Rights Act or its successor; an FTC COPPA Rule amendment) triggers an off-cycle update to § 2 and a re-evaluation of every state row in § 3.
- The annual review is by 9 June. The Privacy Officer signs the review off; the Designated Child Safety Officer co-signs any change to § 2.6 (CSAE / NCMEC) or to § 4 (state child-specific overlays).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference.
End of United States Country Annex.