← All legal documents

Balance — Privacy Policy

Effective date: 19 July 2026 Last updated: 19 July 2026

This Privacy Policy explains what information Balance collects, how Balance uses it, who has access to it, and the choices you have. Balance is a parental-control service. The app has two real users in every household: a parent, who creates the account and configures everything, and a kid, whose Android device the parent pairs with the parent's account. The parent acts as the legal guardian for the kid throughout — every consent decision in the app is made by the parent on the kid's behalf.

Balance is provided by BabaYaga Program, TOO ("BabaYaga Program", "we", "us", "our"), a limited liability partnership organised under the laws of Kazakhstan. Wherever this Policy uses "your data" or "your kid's data", we mean the personal data of the parent who holds the account and the kid the parent has paired with that account.


1. Who we are and how to reach us

Data controller BabaYaga Program, TOO
Registered address ul. Ongarsynova 10, kv. 175, Esil district, Astana 010000, Kazakhstan
Business identification number (BIN) 260540024651
General support
Privacy / data-protection enquiries ()
Child-safety reports & security incidents ()
Telephone
Authorised signatory , Director

EU representative (Article 27, GDPR). For users in the European Union and EEA, our appointed representative is Prighter EU Rep GmbH. Address: Schellinggasse 3, 1010 Vienna, Austria. EU users may contact Prighter through Prighter's published intake form: https://app.prighter.com/portal/12736305032. Prighter forwards your enquiry to us.

UK representative (Article 27, UK GDPR). For users in the United Kingdom, our appointed representative is also Prighter Ltd (UK). Address: 20 Mortlake High Street, London SW14 8JN, United Kingdom.

Other country regulators and complaint routes are listed in the country annexes that travel with this Privacy Policy — see Section 18.


2. Plain-language summary

We built Balance to help parents set healthy device habits for their kids — not to harvest data. In particular:

The rest of this document is the long-form version of those promises, written for regulators and counsel.


3. What information Balance collects

This section is organised by category. Adding a new technical field to one of our databases does not change what you read here, unless that field introduces a new category (e.g. location data) — and we have no plans to introduce one.

3.1 Information the parent gives us directly

3.2 Information from the kid's paired Android device

The kid does not sign up for an account. The kid uses the parent's account through a device the parent has paired. From that device we collect:

Apart from the two task-related fields above (the title/description the kid writes when proposing a task, and the short note the kid attaches when submitting one), Balance does not store, transmit, log, analyse, or transcribe what the kid types anywhere else on the device, what the kid sees on the screen, the kid's browser history, the kid's search queries, the kid's chat messages, or which websites the kid visits. Balance's parental-control component uses Android's Accessibility framework to detect which app is in the foreground and certain UI states (such as picture-in-picture) needed to enforce the limits you configured — none of that screen content leaves the kid's device and none of it is readable to us, our backend, or any sub-processor.

3.3 End-to-end-encrypted proof media

When you require photo or video proof of a completed task, the kid's device captures the photo/video, encrypts it with XChaCha20-Poly1305 using a per-file key, wraps that key to your device's public key, and uploads the resulting ciphertext directly to our storage provider. The encryption key never leaves the device unwrapped. Our backend mints a short-lived signed URL so the upload bypasses our servers entirely. Our servers never see the plaintext content of any photo or video, and neither does our storage provider.

3.4 Verification and security data

3.5 Operational technical data

3.6 We do not collect

For absolute clarity, Balance does not collect or process any of the following:


4. Why we use the information (purposes and lawful bases)

Purpose Categories used Lawful basis (GDPR) Equivalent basis elsewhere
Run the parental-control service you signed up for (account, family, kid profiles, limits, schedules, tasks, earned-time ledger, encrypted media) §§ 3.1–3.3 Contract (Art 6(1)(b)) COPPA "verifiable parental consent" (US); equivalent local bases elsewhere
Deliver operational alerts to you and to the kid's device ("task completed", "limit reached", "new app installed") §§ 3.1–3.2, 3.5 Contract (Art 6(1)(b)) + Legitimate interest (Art 6(1)(f)) COPPA service-provision
Detect, prevent and respond to security incidents, abuse, fraud, and unauthorised access §§ 3.4, 3.5 Legitimate interest (Art 6(1)(f)) + Legal obligation (Art 6(1)(c)) where applicable COPPA security exception; equivalent worldwide
Comply with our legal obligations (tax, accounting, lawful requests from public authorities, mandatory child-safety reporting) Subscription data; safety reports Legal obligation (Art 6(1)(c)) National law
Handle your enquiries, deletion requests, data-export requests, and complaints Contact data + records of the request Legal obligation (Art 6(1)(c)) + Legitimate interest National law
Product-improvement analytics (parent build only) § 3.5 (analytics events) Consent (Art 6(1)(a)) — opt-in, off by default, withdrawable at any time Opt-in consent under applicable US state and other local law
Crash diagnostics / app stability and security (kid and parent builds) § 3.5 (crash payloads) Legitimate interest (Art 6(1)(f)) — anonymised, always-on, no user toggle Service-integrity / security basis

We do not rely on consent as a lawful basis for the core parental-control function because the parental-control function is the contract between you and us — it is what you signed up for. The one exception is product-improvement analytics, which is opt-in only and based on your consent (off by default, withdrawable at any time in the in-app privacy settings); withdrawing it never affects the core service. We do document the parent's act of pairing a kid with the account as a Verifiable Parental Consent event under COPPA and as a record of parental authority under GDPR Article 8 — the parent acts on behalf of the kid throughout.


5. Children: how Balance handles your kid's data (COPPA, UK Children's Code, GDPR Art 8, and equivalent laws worldwide)

This section is the formal Direct Notice to Parents for COPPA-covered users and the "children" section of this Privacy Policy for all other jurisdictions.

5.1 Who decides

The parent is in charge of every aspect of the kid's data in Balance. The kid does not sign up, does not see this Privacy Policy at sign-up, and does not click any "I agree" button. When you create the kid profile and pair the kid's device, you exercise Verifiable Parental Consent under COPPA and parental authority under GDPR Article 8.

5.2 What we collect about the kid

The kid-data inventory is in Section 3.2 and 3.3. We do not collect anything not listed there.

5.3 What we do with the kid's data

Strictly: run the parental-control service the parent purchased — enforce limits, deliver task assignments, return decisions to the kid's device, store the encrypted proof media until the linked task is closed plus 30 days.

We do not: - show advertising to the kid; - profile the kid for marketing or for any other secondary purpose; - sell, rent, or trade the kid's data; - share the kid's data with any third party other than the sub-processors listed in Section 6 (and even there, the kid's encrypted proof media is opaque ciphertext to those sub-processors).

5.4 Parental rights over your kid's data

As the parent, at any time you can: - see every category of data we hold about your kid — through the app's family screens and via the data-export feature (Section 12); - correct any information that is wrong; - delete the kid profile and all the data attached to it — through the in-app "Delete kid" flow or by emailing ; - withdraw your consent to ongoing collection from the kid's device — by removing the kid profile, which immediately stops further collection and triggers the deletion cascade once the 1-hour in-app cool-off elapses (or under the statutory deadlines in Section 11 for email/manual requests); - refuse any new collection by simply not enabling a new feature (e.g. you can run Balance without ever requiring photo proof).

5.5 COPPA retention schedule (US)

We retain each category of children's data only for as long as necessary to provide the parental-control service the parent purchased, as set out in Section 8. Per-app daily usage rows are deleted after 90 days; notifications after 30 days; encrypted proof media 30 days after the linked task closes; all other kid data when the parent deletes the kid or the account (within 1 hour of the in-app confirmation, or under the statutory deadlines in Section 11 for email/manual requests). Operational database backups are retained on two layers: our hosting provider's own operational snapshots, governed by that provider's published backup-retention policy; and our own periodic (daily) backups of the operational database stored with Google Cloud, kept on a 30-day rolling window and then automatically deleted. A copy of deleted kid data may therefore persist in a backup until that backup rotates out (no more than 30 days), after which it becomes unrecoverable.

Data-protection laws set different age thresholds below which a parent, guardian, or other legally competent person must consent to the processing of a child's personal data. For the countries where Balance is offered beyond the COPPA / UK Children's Code / GDPR Article 8 regimes already described above, the principal thresholds are:

Country Threshold under local law Source
Brazil processing of a kid's data anchored in parental consent for kids under 12; parent-account linkage for under-16s on digital services LGPD (Lei 13.709/2018) art 14; ECA Digital (Lei 15.211/2025)
India verifiable parental consent for every user under 18 DPDP Act 2023 §9; DPDP Rules 2025
Indonesia no account for kids under 13 without parental consent; parental supervision for kids aged 13–17 PDP Law 27/2022 arts 25–26; GR 17/2025 ("PP Tunas")
South Korea legal-representative consent for kids under 14 PIPA art 22-2
Japan guardian consent for minors per PPC practice (approximately under 15); statutory under-16 threshold introduced by the 2026 APPI amendment (expected in force 2027) APPI; PPC guidance
Mexico parental consent for minors LFPDPPP (2025)
Egypt parental consent for kids under 18 PDPL 151/2020
Türkiye no statutory age threshold; parental consent for minors per KVKK Board guidance KVKK 6698
South Africa competent-person (parental) consent for kids under 18 POPIA §§34–35
Kenya parental consent plus a best-interests duty for kids under 18 DPA 2019 §33
Tanzania parental consent for kids under 18 PDPA 2022
Bangladesh guardian consent for kids under 18 Personal Data Protection Act 2026
Pakistan no statutory data-protection threshold; parental authority under general law

In Balance, the parent always consents and the kid never self-registers. The person giving consent is a verified adult exercising parental authority — so every threshold in the table above is satisfied by design, whatever the kid's age. The same reasoning applies in every other country where Balance is offered.

The monitoring, screen-time limits, task, and reward features of Balance are performed at the parent's direction, strictly for the safety, well-being, and parental supervision of the kid, and are never used for advertising, profiling, or any other commercial purpose. This is the "safety of the child" purpose recognised by Part B of the Fourth Schedule to India's DPDP Rules 2025, the parental-supervision-tool framing of Indonesia's GR 17/2025 ("PP Tunas") and Brazil's ECA Digital (Lei 15.211/2025), and the child-protection purpose that South Africa's POPIA and the other statutes in the table contemplate.


6. Sub-processors — who else handles your data

We use a small number of service providers to run Balance. Each one is bound by a written data-processing agreement or other binding legal instrument that requires them to follow our instructions, keep your data secure, and not use it for their own purposes. For our primary hosting provider, Emergent Labs Inc., the binding legal instrument is Emergent's published Terms of Service and Privacy Policy at app.emergent.sh — Emergent does not provide a standalone signed DPA outside of its Enterprise tier (see Section 7 below for the transfer-mechanism implications and Section 9 for the technical supplementary measures we apply to compensate).

Provider Role Region What they can see
Emergent Labs Inc. (USA), using MongoDB Atlas (MongoDB, Inc., USA) for the production database and additional managed cloud providers operated by Emergent Hosting our backend and database United States All of the data described in Section 3 except: plaintext media (never reaches the backend — end-to-end encrypted on your device before upload), plaintext passwords (we only hold salted bcrypt hashes), plaintext one-time codes (we only hold peppered SHA-256 hashes), and your media encryption keys (which never leave your device unwrapped). MongoDB Atlas (Emergent's underlying database provider) operates under its own published Data Processing Agreement with EU Standard Contractual Clauses, available at https://www.mongodb.com/legal/dpa.
Google LLC via Google Cloud Storage (USA) Storage of the end-to-end-encrypted proof media United States Opaque ciphertext only — neither Google nor we can read it
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States The operational data described in Section 3 (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form — your kid's proof media and your media encryption keys
Google LLC via Firebase Cloud Messaging (USA) Delivering push notifications to your device United States The push token attached to each device, plus the short body+title of each push at the moment of send. We deliberately keep push bodies free of sensitive content
Google LLC via Firebase Crashlytics (USA) Anonymised crash-diagnostics on both kid and parent builds United States Stack trace, device model, OS version, locale, Balance app version, Firebase installation identifier. No content from the device, no kid name, no email, no proof media.
Google LLC via Firebase Analytics for Google (USA) Product-improvement analytics on the parent build only — never present on the kid build United States Screen views, feature-usage events, consent flags. Collected only with the parent's opt-in consent (off by default); the parent can withdraw consent at any time in the in-app privacy settings.
Resend, Inc. (USA) Sending verification emails and family-invite emails United States Your email address, the email body, and the one-time code at the moment of send
Google LLC — Sign in with Google (USA) Optional identity verification for signing into the parent account Google global infrastructure Your Google account ID and verified email address
Google LLC — Google Drive AppData (USA) Optional cloud backup of the parent's encrypted media key, in the parent's own private Drive Google infrastructure Opaque encrypted blob only — neither Google nor we can read it
Google LLC — Google Play Billing (USA) Processing your subscription payment Google infrastructure The purchase token and your Google account; we never see your card number or billing address
Prighter Group (Prighter EU Rep GmbH, Austria; Prighter Ltd (UK), United Kingdom) Our EU and UK Article 27 representative EU + UK The contents of any DSAR or supervisory-authority enquiry you route through Prighter — Prighter then forwards it to us

Our public legal-documents website (balance.babayagaprogram.com) is served via Cloudflare Pages. The site does not use cookies and does not run analytics. Cloudflare sees only the routine HTTP access logs (IP, page, timestamp) governed by Cloudflare's published retention.

The kid's Balance build embeds Firebase Crashlytics (Google LLC) for crash-diagnostics only — when the app crashes on the kid's device, an anonymised crash report (stack trace, device model, OS version, locale, Balance app version, and a Firebase installation identifier) is sent to Google so we can detect and fix bugs. Crashlytics on the kid build does not collect what the kid types, the screen content, browsing data, the kid's name, the kid's email, the proof media, or any identifier we use to recognise the family. We do not log any custom data into Crashlytics. The kid build embeds no analytics SDK, no advertising SDK, no attribution SDK, and no social-login SDK.

The parent's Balance build embeds Firebase Crashlytics under the same crash-only configuration, plus Firebase Analytics for Google (also Google LLC) for product-improvement metrics on the parent side (screen views, feature usage, consent flags). Firebase Analytics is not present on the kid build. Firebase Crashlytics runs always-on on both the kid and parent builds and is not user-toggleable — we keep it on a legitimate-interest basis so that we can detect and fix crashes and protect app stability and security. Only Firebase Analytics is consent-gated: it is off by default, collected on the parent build only if the parent opts in, and the parent can withdraw or re-enable that consent at any time from the in-app privacy settings, which we honour on every subsequent app launch.


7. International data transfers

Balance is built and operated from Kazakhstan; our backend runs in the United States; some of our sub-processors operate from the United States or globally. If you are in the EU, EEA, UK, or any other country whose law restricts the transfer of personal data abroad, your data is transferred outside your country.

The United States does not have a European Commission adequacy decision in respect of personal-data protection. By creating a Balance account and using the Service, you explicitly consent to the transfer of your information to the United States, after having been informed of the absence of an adequacy decision and of the fact that, in principle, US public authorities may seek access to information that is technically accessible to our hosting provider under US law (most notably under Section 702 of the US Foreign Intelligence Surveillance Act and Executive Order 12333). The categories of information that are technically accessible to our hosting provider in plaintext are limited as described in Sections 6 and 9 — most importantly, your kid's proof media is end-to-end encrypted on your device before upload and is never accessible in plaintext to our hosting provider, our database storage provider, our cloud-object-storage provider, or any other layer below your device.

Our transfer mechanisms are:

For users in the additional countries where Balance is offered, the explicit transfer-disclosure consent you give at signup remains the umbrella mechanism, and the country-specific statutory basis for the transfer is:

For media specifically, end-to-end encryption operates as a supplementary technical measure — even a perfect compromise of any sub-processor's storage layer yields ciphertext only.

You can request a copy of the SCCs, IDTA, or other transfer documents from .


8. How long we keep your data

We do not keep your data longer than necessary. Below are maximum retention periods — we delete sooner when a parent initiates deletion or the data is no longer needed.

Category Maximum retention
Parent account record (email, settings) Until you delete the account; then within 1 hour of the in-app confirmation (or under statutory deadlines for email requests).
Kid account record (name, age, avatar, settings, ledger) Until the parent deletes the kid; then within 1 hour of the in-app confirmation (or under statutory deadlines for email requests).
Per-app daily screen-time totals 90 days, then automatically deleted
Notifications 30 days, then automatically deleted
Installed-apps catalogue on the kid's device Refreshed continuously; deleted when the kid is deleted
Encrypted proof media (photos/videos) and their thumbnails 30 days after the linked task is closed, then automatically deleted; you can delete sooner from the app
Encrypted media keys (per-device, per-pair) Deleted alongside the kid or account they belong to
Verification one-time codes, invite codes, reconnect codes 1 hour at most (verification); 24 hours at most (invites); 15 minutes (reconnect codes) — single-use, automatically deleted
Subscription / billing records As required by Kazakhstan tax and accounting law (typically 5 years for invoices)
Operational server logs Retained by our hosting provider Emergent Labs Inc. according to Emergent's published content-deletion and log-retention policy (Emergent Terms of Service §§ 3.3 and 9.4). We never log plaintext passwords, plaintext one-time codes, raw invite codes, or your media encryption keys.
Operational database backups Two layers: (a) our hosting provider's own operational snapshots, governed by that provider's published backup-retention policy; and (b) our periodic (daily) backups of the operational database stored with Google Cloud, kept on a 30-day rolling window and then automatically deleted. Once a backup rotates out, deleted personal data in it becomes unrecoverable.
Crash-diagnostics payloads (Firebase Crashlytics) 90 days (Firebase default)
Product-analytics events (Firebase Analytics, parent build) Retained by Google per the Firebase Analytics data-retention policy in force on the controller's Firebase project

Account dormancy. We may close and delete accounts that have been inactive for a long period. If we decide to do so for your account, we will email you a notice before any deletion and give you a reasonable opportunity to log in and keep the account active.


9. Security

Some of the technical safeguards we use:

No system is perfectly secure. If a personal-data breach affects your data, we will notify the competent supervisory authority and, where required by law, you, in line with Article 33–34 GDPR and equivalent rules elsewhere.


10. Your rights

Depending on where you are, you have all or most of the following rights:

We do not sell personal data and we do not "share" personal data for cross-context behavioural advertising as defined in any applicable US state privacy law.


11. How to exercise your rights

The fastest way is the in-app privacy settings, where you can: - export your family's data (delivered as a downloadable archive); - give or withdraw your consent to product-improvement analytics (off by default); - delete a kid; - delete the parent account.

Alternatively, write to . We will reply within 30 days under GDPR/UK GDPR, and within 45 days under most US state laws.

We may ask for proof of identity before we act on a deletion or access request, to make sure we are talking to the actual account holder.


12. Push notifications and emails


13. Cookies, web analytics, and SDKs


14. Subscriptions (Google Play Billing)

Paid features in Balance are sold as auto-renewing subscriptions through Google Play Billing. When you subscribe:

We are not a card processor and do not store payment-card data.


15. Automated decision-making

Balance does not subject you or your kid to any decision based solely on automated processing that produces a legal or similarly significant effect. Limit enforcement is configured by you and applied mechanically against your settings — it is not a profiling decision in the GDPR Art 22 sense. The same commitment holds under the equivalent provisions elsewhere — including the right to review of automated decisions under Brazil's LGPD art 20, the safeguards for automated decisions under South Korea's PIPA art 37-2, and the extension of the ARCO rights to automated processing under Mexico's LFPDPPP (2025). Balance performs no such processing; where those laws grant you rights over automated decisions, you may exercise them through the channels in Section 11.


16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make a material change — for example, if we add a new sub-processor that can see your data, or if we change how long we retain a category — we will notify you in the app at next launch, by email, or both, and we will update the "Last updated" date at the top.

We will never roll back the protections that apply to data we already hold about you without an opt-in from you first.


17. Disputes and complaints

We hope to resolve any concern by talking to us first — write to . If we cannot resolve it together, you have the right to lodge a complaint with the supervisory authority of your country (Section 18). For users in the EU and UK, the relevant authority is named in Section 18 and in the country annex for your country. For US users, the Federal Trade Commission (FTC) handles COPPA complaints (https://www.ftc.gov/), and your state attorney-general may handle state-specific complaints.


18. Country annexes

This Privacy Policy is the global, universal version. For each country we publish a short annex that names the country's regulator, the complaint route, and any additional country-specific rights you have. The current country-annex set is:

The annex set is published alongside this Policy at privacy.html and is incorporated by reference. Inherited territories (e.g. Puerto Rico, Guam, US Virgin Islands; Bermuda, Cayman Islands, Channel Islands, Isle of Man, Gibraltar; the French overseas departments and territories; Greenland; Aruba and the BES; Åland) follow the privacy regime of their parent country and the parent-country annex applies.


19. Quick-reference contacts


End of Privacy Policy.

International country annexes

The annexes below add the country-specific disclosures, rights, and contact channels required by local law on top of this document. They form part of this Policy and are incorporated by reference. Open the annex for your country of residence.