Balance — Privacy Policy
Effective date: 19 July 2026 Last updated: 19 July 2026
This Privacy Policy explains what information Balance collects, how Balance uses it, who has access to it, and the choices you have. Balance is a parental-control service. The app has two real users in every household: a parent, who creates the account and configures everything, and a kid, whose Android device the parent pairs with the parent's account. The parent acts as the legal guardian for the kid throughout — every consent decision in the app is made by the parent on the kid's behalf.
Balance is provided by BabaYaga Program, TOO ("BabaYaga Program", "we", "us", "our"), a limited liability partnership organised under the laws of Kazakhstan. Wherever this Policy uses "your data" or "your kid's data", we mean the personal data of the parent who holds the account and the kid the parent has paired with that account.
1. Who we are and how to reach us
| Data controller | BabaYaga Program, TOO |
| Registered address | ul. Ongarsynova 10, kv. 175, Esil district, Astana 010000, Kazakhstan |
| Business identification number (BIN) | 260540024651 |
| General support | |
| Privacy / data-protection enquiries | () |
| Child-safety reports & security incidents | () |
| Telephone | |
| Authorised signatory | , Director |
EU representative (Article 27, GDPR). For users in the European Union and EEA, our appointed representative is Prighter EU Rep GmbH. Address: Schellinggasse 3, 1010 Vienna, Austria. EU users may contact Prighter through Prighter's published intake form: https://app.prighter.com/portal/12736305032. Prighter forwards your enquiry to us.
UK representative (Article 27, UK GDPR). For users in the United Kingdom, our appointed representative is also Prighter Ltd (UK). Address: 20 Mortlake High Street, London SW14 8JN, United Kingdom.
Other country regulators and complaint routes are listed in the country annexes that travel with this Privacy Policy — see Section 18.
2. Plain-language summary
We built Balance to help parents set healthy device habits for their kids — not to harvest data. In particular:
- There is no advertising in Balance, no ad SDKs, no behavioural profiling, no third-party data sharing for marketing.
- We do not collect your kid's location, contacts, SMS, call logs, browsing history, microphone audio outside of explicit proof-video recording, biometric data, health data, or any other special-category data.
- Photos and videos that the kid uploads as proof of completed tasks are end-to-end encrypted on the kid's device before any network call. Our servers and our storage provider only ever see encrypted bytes — we cannot view, recover, or hand over the plaintext.
- You can delete the account, a kid profile, and all associated data at any time, in-app or by email. Deletion is final and cascades across every collection we hold and every encrypted media object we store.
- You can ask for a copy of your data at any time. We will send it to you within the legal deadline applicable in your country (30 days under GDPR; 45 days under most US state laws).
The rest of this document is the long-form version of those promises, written for regulators and counsel.
3. What information Balance collects
This section is organised by category. Adding a new technical field to one of our databases does not change what you read here, unless that field introduces a new category (e.g. location data) — and we have no plans to introduce one.
3.1 Information the parent gives us directly
- Account information: email address, password (stored as a one-way bcrypt hash; never in the clear), display preferences (app language, theme, notification preferences).
- Family profile: a four-digit local unlock code (stored as a one-way SHA-256 hash; used as a parental override on the kid's device, not as a credential against our servers).
- Information about each kid you add: the name, age and (optionally) birthday and avatar you supply for them.
- Subscription information if you take a paid plan — see Section 14.
- If you sign in with Google: your Google account identifier and the email address Google has verified for you (we receive nothing else from Google).
3.2 Information from the kid's paired Android device
The kid does not sign up for an account. The kid uses the parent's account through a device the parent has paired. From that device we collect:
- A randomly-generated device identifier (so we can route data correctly between the parent and the kid's specific device).
- Per-app daily screen-time totals ("YouTube — 45 minutes today"). We use this to enforce the limits you set.
- The list of apps installed on the kid's device (app names + icons + system-app flag), so you can pick which ones to limit.
- Tasks and rewards data — the chores you assign, the title and description the kid writes when proposing a task, the short note the kid can attach when submitting a task, the kid's marks of completion, your approval or decline decisions, and the earned-time ledger.
- Push token for delivering operational notifications to the kid's device.
Apart from the two task-related fields above (the title/description the kid writes when proposing a task, and the short note the kid attaches when submitting one), Balance does not store, transmit, log, analyse, or transcribe what the kid types anywhere else on the device, what the kid sees on the screen, the kid's browser history, the kid's search queries, the kid's chat messages, or which websites the kid visits. Balance's parental-control component uses Android's Accessibility framework to detect which app is in the foreground and certain UI states (such as picture-in-picture) needed to enforce the limits you configured — none of that screen content leaves the kid's device and none of it is readable to us, our backend, or any sub-processor.
3.3 End-to-end-encrypted proof media
When you require photo or video proof of a completed task, the kid's device captures the photo/video, encrypts it with XChaCha20-Poly1305 using a per-file key, wraps that key to your device's public key, and uploads the resulting ciphertext directly to our storage provider. The encryption key never leaves the device unwrapped. Our backend mints a short-lived signed URL so the upload bypasses our servers entirely. Our servers never see the plaintext content of any photo or video, and neither does our storage provider.
3.4 Verification and security data
- One-time codes (OTPs) for signing up, resetting a password, inviting a kid, or reconnecting a kid on a new device. We store only a peppered hash; the plaintext code exists only briefly during the email send (Section 6).
- Authentication metadata: last login time, failed-login counters, password-change timestamps. Used to detect and slow down credential-stuffing.
3.5 Operational technical data
- IP address at the time of authentication-sensitive requests (used to throttle abuse).
- HTTP method, route, response status, error codes, request timings (in the server logs — see Section 6).
- Push-notification tokens (Section 6).
- Crash-diagnostics payloads — when the Balance app crashes (kid or parent), an anonymised report is sent to Firebase Crashlytics: stack trace, device model, OS version, locale, app version, Firebase installation identifier. No kid name, no email, no proof-media content, no task text, no screen content. Crashlytics runs always-on on both builds and is not user-toggleable (see Section 4 for the lawful basis).
- Product-analytics events (parent build only) — screen-view and feature-usage events sent to Firebase Analytics. Analytics is off by default. We collect these events only if the parent has given opt-in consent, which we request at parent registration and which the parent can withdraw or re-enable at any time in the in-app privacy settings. We record a dated consent receipt when the parent makes that choice.
3.6 We do not collect
For absolute clarity, Balance does not collect or process any of the following:
- Precise or coarse geolocation.
- Contacts, address book entries, SMS messages, call logs, or phone-number identifiers.
- Microphone audio outside of the active proof-video capture screen (audio is recorded only as the soundtrack of a proof-video the kid voluntarily records when a task explicitly requires video).
- Browsing history, web-search queries.
- Biometric identifiers (fingerprint, face, voice), health data, religion, ethnic origin, sexual orientation, political opinions, trade-union membership, criminal-record data.
- Any data used for behavioural advertising or profiling. Balance shows no advertising.
4. Why we use the information (purposes and lawful bases)
| Purpose | Categories used | Lawful basis (GDPR) | Equivalent basis elsewhere |
|---|---|---|---|
| Run the parental-control service you signed up for (account, family, kid profiles, limits, schedules, tasks, earned-time ledger, encrypted media) | §§ 3.1–3.3 | Contract (Art 6(1)(b)) | COPPA "verifiable parental consent" (US); equivalent local bases elsewhere |
| Deliver operational alerts to you and to the kid's device ("task completed", "limit reached", "new app installed") | §§ 3.1–3.2, 3.5 | Contract (Art 6(1)(b)) + Legitimate interest (Art 6(1)(f)) | COPPA service-provision |
| Detect, prevent and respond to security incidents, abuse, fraud, and unauthorised access | §§ 3.4, 3.5 | Legitimate interest (Art 6(1)(f)) + Legal obligation (Art 6(1)(c)) where applicable | COPPA security exception; equivalent worldwide |
| Comply with our legal obligations (tax, accounting, lawful requests from public authorities, mandatory child-safety reporting) | Subscription data; safety reports | Legal obligation (Art 6(1)(c)) | National law |
| Handle your enquiries, deletion requests, data-export requests, and complaints | Contact data + records of the request | Legal obligation (Art 6(1)(c)) + Legitimate interest | National law |
| Product-improvement analytics (parent build only) | § 3.5 (analytics events) | Consent (Art 6(1)(a)) — opt-in, off by default, withdrawable at any time | Opt-in consent under applicable US state and other local law |
| Crash diagnostics / app stability and security (kid and parent builds) | § 3.5 (crash payloads) | Legitimate interest (Art 6(1)(f)) — anonymised, always-on, no user toggle | Service-integrity / security basis |
We do not rely on consent as a lawful basis for the core parental-control function because the parental-control function is the contract between you and us — it is what you signed up for. The one exception is product-improvement analytics, which is opt-in only and based on your consent (off by default, withdrawable at any time in the in-app privacy settings); withdrawing it never affects the core service. We do document the parent's act of pairing a kid with the account as a Verifiable Parental Consent event under COPPA and as a record of parental authority under GDPR Article 8 — the parent acts on behalf of the kid throughout.
5. Children: how Balance handles your kid's data (COPPA, UK Children's Code, GDPR Art 8, and equivalent laws worldwide)
This section is the formal Direct Notice to Parents for COPPA-covered users and the "children" section of this Privacy Policy for all other jurisdictions.
5.1 Who decides
The parent is in charge of every aspect of the kid's data in Balance. The kid does not sign up, does not see this Privacy Policy at sign-up, and does not click any "I agree" button. When you create the kid profile and pair the kid's device, you exercise Verifiable Parental Consent under COPPA and parental authority under GDPR Article 8.
5.2 What we collect about the kid
The kid-data inventory is in Section 3.2 and 3.3. We do not collect anything not listed there.
5.3 What we do with the kid's data
Strictly: run the parental-control service the parent purchased — enforce limits, deliver task assignments, return decisions to the kid's device, store the encrypted proof media until the linked task is closed plus 30 days.
We do not: - show advertising to the kid; - profile the kid for marketing or for any other secondary purpose; - sell, rent, or trade the kid's data; - share the kid's data with any third party other than the sub-processors listed in Section 6 (and even there, the kid's encrypted proof media is opaque ciphertext to those sub-processors).
5.4 Parental rights over your kid's data
As the parent, at any time you can: - see every category of data we hold about your kid — through the app's family screens and via the data-export feature (Section 12); - correct any information that is wrong; - delete the kid profile and all the data attached to it — through the in-app "Delete kid" flow or by emailing ; - withdraw your consent to ongoing collection from the kid's device — by removing the kid profile, which immediately stops further collection and triggers the deletion cascade once the 1-hour in-app cool-off elapses (or under the statutory deadlines in Section 11 for email/manual requests); - refuse any new collection by simply not enabling a new feature (e.g. you can run Balance without ever requiring photo proof).
5.5 COPPA retention schedule (US)
We retain each category of children's data only for as long as necessary to provide the parental-control service the parent purchased, as set out in Section 8. Per-app daily usage rows are deleted after 90 days; notifications after 30 days; encrypted proof media 30 days after the linked task closes; all other kid data when the parent deletes the kid or the account (within 1 hour of the in-app confirmation, or under the statutory deadlines in Section 11 for email/manual requests). Operational database backups are retained on two layers: our hosting provider's own operational snapshots, governed by that provider's published backup-retention policy; and our own periodic (daily) backups of the operational database stored with Google Cloud, kept on a 30-day rolling window and then automatically deleted. A copy of deleted kid data may therefore persist in a backup until that backup rotates out (no more than 30 days), after which it becomes unrecoverable.
5.6 Consent-age thresholds around the world
Data-protection laws set different age thresholds below which a parent, guardian, or other legally competent person must consent to the processing of a child's personal data. For the countries where Balance is offered beyond the COPPA / UK Children's Code / GDPR Article 8 regimes already described above, the principal thresholds are:
| Country | Threshold under local law | Source |
|---|---|---|
| Brazil | processing of a kid's data anchored in parental consent for kids under 12; parent-account linkage for under-16s on digital services | LGPD (Lei 13.709/2018) art 14; ECA Digital (Lei 15.211/2025) |
| India | verifiable parental consent for every user under 18 | DPDP Act 2023 §9; DPDP Rules 2025 |
| Indonesia | no account for kids under 13 without parental consent; parental supervision for kids aged 13–17 | PDP Law 27/2022 arts 25–26; GR 17/2025 ("PP Tunas") |
| South Korea | legal-representative consent for kids under 14 | PIPA art 22-2 |
| Japan | guardian consent for minors per PPC practice (approximately under 15); statutory under-16 threshold introduced by the 2026 APPI amendment (expected in force 2027) | APPI; PPC guidance |
| Mexico | parental consent for minors | LFPDPPP (2025) |
| Egypt | parental consent for kids under 18 | PDPL 151/2020 |
| Türkiye | no statutory age threshold; parental consent for minors per KVKK Board guidance | KVKK 6698 |
| South Africa | competent-person (parental) consent for kids under 18 | POPIA §§34–35 |
| Kenya | parental consent plus a best-interests duty for kids under 18 | DPA 2019 §33 |
| Tanzania | parental consent for kids under 18 | PDPA 2022 |
| Bangladesh | guardian consent for kids under 18 | Personal Data Protection Act 2026 |
| Pakistan | no statutory data-protection threshold; parental authority under general law | — |
In Balance, the parent always consents and the kid never self-registers. The person giving consent is a verified adult exercising parental authority — so every threshold in the table above is satisfied by design, whatever the kid's age. The same reasoning applies in every other country where Balance is offered.
The monitoring, screen-time limits, task, and reward features of Balance are performed at the parent's direction, strictly for the safety, well-being, and parental supervision of the kid, and are never used for advertising, profiling, or any other commercial purpose. This is the "safety of the child" purpose recognised by Part B of the Fourth Schedule to India's DPDP Rules 2025, the parental-supervision-tool framing of Indonesia's GR 17/2025 ("PP Tunas") and Brazil's ECA Digital (Lei 15.211/2025), and the child-protection purpose that South Africa's POPIA and the other statutes in the table contemplate.
6. Sub-processors — who else handles your data
We use a small number of service providers to run Balance. Each one is bound by a written data-processing agreement or other binding legal instrument that requires them to follow our instructions, keep your data secure, and not use it for their own purposes. For our primary hosting provider, Emergent Labs Inc., the binding legal instrument is Emergent's published Terms of Service and Privacy Policy at app.emergent.sh — Emergent does not provide a standalone signed DPA outside of its Enterprise tier (see Section 7 below for the transfer-mechanism implications and Section 9 for the technical supplementary measures we apply to compensate).
| Provider | Role | Region | What they can see |
|---|---|---|---|
| Emergent Labs Inc. (USA), using MongoDB Atlas (MongoDB, Inc., USA) for the production database and additional managed cloud providers operated by Emergent | Hosting our backend and database | United States | All of the data described in Section 3 except: plaintext media (never reaches the backend — end-to-end encrypted on your device before upload), plaintext passwords (we only hold salted bcrypt hashes), plaintext one-time codes (we only hold peppered SHA-256 hashes), and your media encryption keys (which never leave your device unwrapped). MongoDB Atlas (Emergent's underlying database provider) operates under its own published Data Processing Agreement with EU Standard Contractual Clauses, available at https://www.mongodb.com/legal/dpa. |
| Google LLC via Google Cloud Storage (USA) | Storage of the end-to-end-encrypted proof media | United States | Opaque ciphertext only — neither Google nor we can read it |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States | The operational data described in Section 3 (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form — your kid's proof media and your media encryption keys |
| Google LLC via Firebase Cloud Messaging (USA) | Delivering push notifications to your device | United States | The push token attached to each device, plus the short body+title of each push at the moment of send. We deliberately keep push bodies free of sensitive content |
| Google LLC via Firebase Crashlytics (USA) | Anonymised crash-diagnostics on both kid and parent builds | United States | Stack trace, device model, OS version, locale, Balance app version, Firebase installation identifier. No content from the device, no kid name, no email, no proof media. |
| Google LLC via Firebase Analytics for Google (USA) | Product-improvement analytics on the parent build only — never present on the kid build | United States | Screen views, feature-usage events, consent flags. Collected only with the parent's opt-in consent (off by default); the parent can withdraw consent at any time in the in-app privacy settings. |
| Resend, Inc. (USA) | Sending verification emails and family-invite emails | United States | Your email address, the email body, and the one-time code at the moment of send |
| Google LLC — Sign in with Google (USA) | Optional identity verification for signing into the parent account | Google global infrastructure | Your Google account ID and verified email address |
| Google LLC — Google Drive AppData (USA) | Optional cloud backup of the parent's encrypted media key, in the parent's own private Drive | Google infrastructure | Opaque encrypted blob only — neither Google nor we can read it |
| Google LLC — Google Play Billing (USA) | Processing your subscription payment | Google infrastructure | The purchase token and your Google account; we never see your card number or billing address |
| Prighter Group (Prighter EU Rep GmbH, Austria; Prighter Ltd (UK), United Kingdom) | Our EU and UK Article 27 representative | EU + UK | The contents of any DSAR or supervisory-authority enquiry you route through Prighter — Prighter then forwards it to us |
Our public legal-documents website (balance.babayagaprogram.com) is served via Cloudflare Pages. The site does not use cookies and does not run analytics. Cloudflare sees only the routine HTTP access logs (IP, page, timestamp) governed by Cloudflare's published retention.
The kid's Balance build embeds Firebase Crashlytics (Google LLC) for crash-diagnostics only — when the app crashes on the kid's device, an anonymised crash report (stack trace, device model, OS version, locale, Balance app version, and a Firebase installation identifier) is sent to Google so we can detect and fix bugs. Crashlytics on the kid build does not collect what the kid types, the screen content, browsing data, the kid's name, the kid's email, the proof media, or any identifier we use to recognise the family. We do not log any custom data into Crashlytics. The kid build embeds no analytics SDK, no advertising SDK, no attribution SDK, and no social-login SDK.
The parent's Balance build embeds Firebase Crashlytics under the same crash-only configuration, plus Firebase Analytics for Google (also Google LLC) for product-improvement metrics on the parent side (screen views, feature usage, consent flags). Firebase Analytics is not present on the kid build. Firebase Crashlytics runs always-on on both the kid and parent builds and is not user-toggleable — we keep it on a legitimate-interest basis so that we can detect and fix crashes and protect app stability and security. Only Firebase Analytics is consent-gated: it is off by default, collected on the parent build only if the parent opts in, and the parent can withdraw or re-enable that consent at any time from the in-app privacy settings, which we honour on every subsequent app launch.
7. International data transfers
Balance is built and operated from Kazakhstan; our backend runs in the United States; some of our sub-processors operate from the United States or globally. If you are in the EU, EEA, UK, or any other country whose law restricts the transfer of personal data abroad, your data is transferred outside your country.
The United States does not have a European Commission adequacy decision in respect of personal-data protection. By creating a Balance account and using the Service, you explicitly consent to the transfer of your information to the United States, after having been informed of the absence of an adequacy decision and of the fact that, in principle, US public authorities may seek access to information that is technically accessible to our hosting provider under US law (most notably under Section 702 of the US Foreign Intelligence Surveillance Act and Executive Order 12333). The categories of information that are technically accessible to our hosting provider in plaintext are limited as described in Sections 6 and 9 — most importantly, your kid's proof media is end-to-end encrypted on your device before upload and is never accessible in plaintext to our hosting provider, our database storage provider, our cloud-object-storage provider, or any other layer below your device.
Our transfer mechanisms are:
- From BabaYaga Program, TOO (Kazakhstan controller) to Emergent Labs Inc. (United States processor): Emergent does not provide a standalone signed Data Processing Agreement outside of its Enterprise tier. Our controller-to-processor relationship is governed by Emergent's published Terms of Service (last updated 22 December 2025) and Privacy Policy (last updated 28 May 2026), treated as the "other legal act" under GDPR Article 28(3). We supplement this by relying, in combination, on (a) your explicit transfer-disclosure consent at signup under Article 49(1)(a); (b) contract-performance necessity under Article 49(1)(b) for occasional service-delivery transfers; (c) the Article 46(2) chain via MongoDB Atlas's published Customer Data Processing Agreement with EU Standard Contractual Clauses Module 2 (and the UK International Data Transfer Addendum for users in the UK), which covers the storage layer where your data actually sits at rest (Emergent operates our production database on MongoDB Atlas); and (d) a set of controller-side technical and organisational supplementary measures — most importantly the end-to-end encryption of proof media, the field-level AES-256-GCM encryption of your email address, the salted bcrypt hashing of your password, the peppered SHA-256 hashing of one-time codes, the strict logging-discipline rule that forbids any plaintext credentials, keys, or one-time codes in our application logs, and short-lived (5-minute) signed URLs for media access. Further detail on these measures is available on request.
- From the controller to Google Cloud Storage, Google Cloud (operational database backups), Firebase Cloud Messaging, Google Sign-In, Google Drive AppData, Google Play Billing: Google's Data Privacy Framework certification with EU SCCs as a fallback.
- From the controller to Resend, Inc.: EU SCCs Module 2 under Resend's published DPA.
- For users in the UK: the UK International Data Transfer Addendum to the SCCs (IDTA).
For users in the additional countries where Balance is offered, the explicit transfer-disclosure consent you give at signup remains the umbrella mechanism, and the country-specific statutory basis for the transfer is:
- Brazil — LGPD arts 33–36, with the standard contractual clauses of ANPD Resolution CD/ANPD No. 19/2024 and your specific consent where applicable.
- India — DPDP Act 2023 §16: transfers are permitted to any country the Government of India has not restricted by notification; no such restriction applies to our transfer destinations at the effective date of this Policy.
- Indonesia — PDP Law 27/2022 arts 55–56 (equivalent-protection assessment, appropriate safeguards, or your consent).
- Türkiye — KVKK art 9 as amended in 2024 (adequacy decisions and standard contractual clauses, with explicit consent as the fallback). We currently rely on your explicit consent, given at signup after you have been informed of the possible risks.
- Egypt — the cross-border regime of PDPL 151/2020 and its Executive Regulations (Decree 816/2025); we rely on your explicit consent.
- Tanzania — the transfer regime of the PDPA 2022; we rely on your explicit consent.
- South Africa — POPIA §72(1)(b): your consent, supported by contractual safeguards with each sub-processor. Additional detail is in the South Africa annex.
- Kenya — DPA 2019 §§48–49: your consent plus appropriate safeguards.
- South Korea — PIPA art 28-8 requires separate consent to the overseas transfer of personal data. The transfer-disclosure consent you give at signup is that separate consent, given after the information PIPA requires (what is transferred, to which country, to whom, for what purpose, and for how long it is retained).
- Japan — APPI art 28: your consent to the transfer to a third party in a foreign country, given after we have provided the information the APPI requires about the destination country's data-protection regime.
- Mexico — LFPDPPP (2025): transfers carried out under the terms of the privacy notice communicated to you.
- Pakistan and Bangladesh — consent-based transfers under the applicable general law and, in Bangladesh, the Personal Data Protection Act 2026.
For media specifically, end-to-end encryption operates as a supplementary technical measure — even a perfect compromise of any sub-processor's storage layer yields ciphertext only.
You can request a copy of the SCCs, IDTA, or other transfer documents from .
8. How long we keep your data
We do not keep your data longer than necessary. Below are maximum retention periods — we delete sooner when a parent initiates deletion or the data is no longer needed.
| Category | Maximum retention |
|---|---|
| Parent account record (email, settings) | Until you delete the account; then within 1 hour of the in-app confirmation (or under statutory deadlines for email requests). |
| Kid account record (name, age, avatar, settings, ledger) | Until the parent deletes the kid; then within 1 hour of the in-app confirmation (or under statutory deadlines for email requests). |
| Per-app daily screen-time totals | 90 days, then automatically deleted |
| Notifications | 30 days, then automatically deleted |
| Installed-apps catalogue on the kid's device | Refreshed continuously; deleted when the kid is deleted |
| Encrypted proof media (photos/videos) and their thumbnails | 30 days after the linked task is closed, then automatically deleted; you can delete sooner from the app |
| Encrypted media keys (per-device, per-pair) | Deleted alongside the kid or account they belong to |
| Verification one-time codes, invite codes, reconnect codes | 1 hour at most (verification); 24 hours at most (invites); 15 minutes (reconnect codes) — single-use, automatically deleted |
| Subscription / billing records | As required by Kazakhstan tax and accounting law (typically 5 years for invoices) |
| Operational server logs | Retained by our hosting provider Emergent Labs Inc. according to Emergent's published content-deletion and log-retention policy (Emergent Terms of Service §§ 3.3 and 9.4). We never log plaintext passwords, plaintext one-time codes, raw invite codes, or your media encryption keys. |
| Operational database backups | Two layers: (a) our hosting provider's own operational snapshots, governed by that provider's published backup-retention policy; and (b) our periodic (daily) backups of the operational database stored with Google Cloud, kept on a 30-day rolling window and then automatically deleted. Once a backup rotates out, deleted personal data in it becomes unrecoverable. |
| Crash-diagnostics payloads (Firebase Crashlytics) | 90 days (Firebase default) |
| Product-analytics events (Firebase Analytics, parent build) | Retained by Google per the Firebase Analytics data-retention policy in force on the controller's Firebase project |
Account dormancy. We may close and delete accounts that have been inactive for a long period. If we decide to do so for your account, we will email you a notice before any deletion and give you a reasonable opportunity to log in and keep the account active.
9. Security
Some of the technical safeguards we use:
- TLS for everything in transit. All traffic between your devices and our backend, between your devices and our storage provider, and between our backend and our sub-processors is encrypted in transit.
- End-to-end encryption for proof media. Photos and videos are encrypted on the device with XChaCha20-Poly1305 before upload, with per-file keys wrapped to each authorised device's X25519 public key. The wrap key is derived from your password using Argon2id — our servers never see your password and never see the unwrapped key.
- Field-level encryption for your stored email using AES-256-GCM with a server-only key, in addition to the database's own at-rest protections.
- Password hashing with bcrypt; we never store passwords in the clear.
- OTP hashing with SHA-256 plus a server-only pepper; one-time codes expire in 10 minutes, are single-use, and are burned after 5 incorrect attempts.
- Strict logging discipline: keys, passwords, one-time codes, and plaintext media bytes are forbidden in our logs by code-review rule.
- Short-lived signed URLs (5 minutes) for direct uploads to and downloads from our storage provider.
- Family-PIN gate for the parental override on the kid's device — a four-digit code stored only as a one-way hash.
No system is perfectly secure. If a personal-data breach affects your data, we will notify the competent supervisory authority and, where required by law, you, in line with Article 33–34 GDPR and equivalent rules elsewhere.
10. Your rights
Depending on where you are, you have all or most of the following rights:
- Access — ask for a copy of the personal data we hold about you and your kid.
- Rectification — ask us to correct anything that is wrong.
- Erasure / "right to be forgotten" — ask us to delete the account, a kid, or any specific category of data. Use the in-app "Delete account" / "Delete kid" flows for the fastest route.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — ask for a copy of the data you provided to us in a structured, machine-readable format.
- Object — object to processing carried out on the legitimate-interest basis.
- Withdraw consent at any time, without affecting the lawfulness of past processing — including withdrawing your consent to product-improvement analytics, which you can turn off (or back on) at any time in the in-app privacy settings.
- Lodge a complaint with a supervisory authority in your country — see Section 18 for the regulator in your country. EU users may complain to the supervisory authority where they live, where they work, or where the alleged infringement occurred. UK users may complain to the Information Commissioner's Office (ICO).
- For US users: depending on your state, you may have additional rights under COPPA (for your kid's data), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, and other state laws. These include the right to access, delete, correct, opt out of sale (we do not sell data), opt out of targeted advertising (we do not show advertising), and not be discriminated against for exercising your rights.
- Additional country-specific rights — for example, the ARCO rights (access, rectification, cancellation, opposition) in Mexico; the grievance-redressal and nomination rights under India's DPDP Act 2023; the objection rights under South Africa's POPIA; and the rights catalogue of South Korea's PIPA — are set out in the country annex for your country (Section 18).
We do not sell personal data and we do not "share" personal data for cross-context behavioural advertising as defined in any applicable US state privacy law.
11. How to exercise your rights
The fastest way is the in-app privacy settings, where you can: - export your family's data (delivered as a downloadable archive); - give or withdraw your consent to product-improvement analytics (off by default); - delete a kid; - delete the parent account.
Alternatively, write to . We will reply within 30 days under GDPR/UK GDPR, and within 45 days under most US state laws.
We may ask for proof of identity before we act on a deletion or access request, to make sure we are talking to the actual account holder.
12. Push notifications and emails
- Push notifications. We use Firebase Cloud Messaging (Google) to deliver operational push notifications to the parent's device and the kid's device. The push contains only an operational message ("task completed", "limit reached", "new app installed"). You can turn pushes off in Android Settings.
- Verification and invite emails. We use Resend to deliver one-time codes and family invitation emails. We do not use email for marketing.
13. Cookies, web analytics, and SDKs
- Balance the app does not use cookies (it is a native Android app and does not embed a browser for the parental-control function).
- Our public legal-documents website at balance.babayagaprogram.com does not use cookies and does not run analytics.
- We do not embed any third-party advertising SDK or behavioural-profiling SDK in the Balance app. The only Google diagnostic SDKs we use are Firebase Crashlytics (on both kid and parent builds, crash-diagnostics only, always-on, not user-toggleable) and Firebase Analytics (on the parent build only, off by default and enabled only with your opt-in consent, which you can withdraw at any time in the in-app privacy settings) — see § 6 for the sub-processor disclosure.
14. Subscriptions (Google Play Billing)
Paid features in Balance are sold as auto-renewing subscriptions through Google Play Billing. When you subscribe:
- Google handles the payment — we never see your card number or billing address.
- We receive a purchase token from Google, which we verify against the Google Play Developer API to confirm the subscription is active.
- The subscription terms (price, renewal cadence, cancellation, refunds) are governed by our Subscription Terms and by Google Play's terms.
- You can cancel any time in Google Play → Subscriptions; cancellation takes effect at the end of the current billing period.
We are not a card processor and do not store payment-card data.
15. Automated decision-making
Balance does not subject you or your kid to any decision based solely on automated processing that produces a legal or similarly significant effect. Limit enforcement is configured by you and applied mechanically against your settings — it is not a profiling decision in the GDPR Art 22 sense. The same commitment holds under the equivalent provisions elsewhere — including the right to review of automated decisions under Brazil's LGPD art 20, the safeguards for automated decisions under South Korea's PIPA art 37-2, and the extension of the ARCO rights to automated processing under Mexico's LFPDPPP (2025). Balance performs no such processing; where those laws grant you rights over automated decisions, you may exercise them through the channels in Section 11.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make a material change — for example, if we add a new sub-processor that can see your data, or if we change how long we retain a category — we will notify you in the app at next launch, by email, or both, and we will update the "Last updated" date at the top.
We will never roll back the protections that apply to data we already hold about you without an opt-in from you first.
17. Disputes and complaints
We hope to resolve any concern by talking to us first — write to . If we cannot resolve it together, you have the right to lodge a complaint with the supervisory authority of your country (Section 18). For users in the EU and UK, the relevant authority is named in Section 18 and in the country annex for your country. For US users, the Federal Trade Commission (FTC) handles COPPA complaints (https://www.ftc.gov/), and your state attorney-general may handle state-specific complaints.
18. Country annexes
This Privacy Policy is the global, universal version. For each country we publish a short annex that names the country's regulator, the complaint route, and any additional country-specific rights you have. The current country-annex set is:
- United States (federal + applicable state laws).
- United Kingdom.
- All 27 EU member states + Iceland, Liechtenstein, Norway (EU/EEA).
- Argentina, Chile, Colombia, Peru, Uruguay.
- Canada, Australia, New Zealand, Singapore, Philippines, Israel, Hong Kong (SAR), Malaysia, Thailand, Taiwan.
- Andorra, Monaco, San Marino.
- Brazil, India, Indonesia, Pakistan, Bangladesh, Mexico, Japan, Egypt, Türkiye, Tanzania, South Africa, Kenya, South Korea.
The annex set is published alongside this Policy at privacy.html and is incorporated by reference. Inherited territories (e.g. Puerto Rico, Guam, US Virgin Islands; Bermuda, Cayman Islands, Channel Islands, Isle of Man, Gibraltar; the French overseas departments and territories; Greenland; Aruba and the BES; Åland) follow the privacy regime of their parent country and the parent-country annex applies.
19. Quick-reference contacts
- Account, billing, or general help:
- Privacy / DSAR / data export / deletion:
- Child safety reports and security incidents:
- EU representative: Prighter EU Rep GmbH, Schellinggasse 3, 1010 Vienna, Austria
- UK representative: Prighter Ltd (UK), 20 Mortlake High Street, London SW14 8JN, United Kingdom
- Postal address: BabaYaga Program, TOO, ul. Ongarsynova 10, kv. 175, Esil district, Astana 010000, Kazakhstan
- Telephone:
End of Privacy Policy.
International country annexes
The annexes below add the country-specific disclosures, rights, and contact channels required by local law on top of this document. They form part of this Policy and are incorporated by reference. Open the annex for your country of residence.
- United States
- United Kingdom
- European Union / EEA
- Canada
- Australia
- New Zealand
- Argentina
- Chile
- Colombia
- Peru
- Uruguay
- Singapore
- Philippines
- Israel
- Hong Kong
- Malaysia
- Thailand
- Taiwan
- Brazil
- India
- Indonesia
- Pakistan
- Bangladesh
- Mexico
- Japan
- Egypt
- Türkiye
- Tanzania
- South Africa
- Kenya
- South Korea
- Andorra · Monaco · San Marino