This Privacy Policy explains how Rostan Technologies Pvt. Ltd. (“OurShield”, “we”, “us”) processes personal data of parents and children who use the OurShield parental control platform. OurShield acts as a Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). You, the parent, are the Data Principal and also the verifiable lawful guardian of your child’s data.
1. Notice and lawful basis
We process personal data on the basis of your explicit consent given at sign-up and, where applicable, legitimate uses specified in §7 of the DPDP Act (including service provision, fraud prevention, and compliance with Indian law). You may review or withdraw consent at any time from Settings → Account in the parent app.
2. Categories of personal data we collect
The OurShield child-device app uses several Android system capabilities to enforce the rules you set. Each one is described below in plain terms, together with what it reads, why, and where that data goes.
- Parent account data: email address, hashed password (Argon2id), authentication tokens, IP address of sign-in, device user-agent.
- Child profile data: first name (or nickname), date of birth, avatar image chosen by the parent.
- Mood check-ins and family tasks: if the child uses the optional check-in, we store the mood they picked (one of great / good / okay / tired / sad / anxious), an optional short note, and the time, so the parent can see it. Family tasks, rewards and screen-time requests the child submits are stored the same way. These are wellbeing signals shared only with the parent; OurShield does not diagnose, treat or provide any clinical service.
- Device identifiers: device install ID, OS version, FCM push token (for parent notifications only).
- Precise location: with your permission, the child device reports full-precision GPS coordinates (not rounded or approximated) to power the family map and safe-zone (geofence) arrival/departure alerts. While the app detects the child is driving, it samples location roughly every 45 seconds — more frequently than routine tracking — specifically to detect trip start/end, speeding, hard braking, and phone use while driving (see Driving detection below). Background location is optional per child; turning it off still leaves DNS filtering and app-time limits working.
- Foreground app detection (Accessibility Service): OurShield uses Android’s Accessibility API to detect which app is currently in the foreground on the child’s device, so it can enforce app blocks, per-app time limits, and bedtime/school-hours lockdowns in real time. This reads only the foreground app’s package name (via the
typeWindowStateChangedevent) — it does not read on-screen text or content. Separately, if you opt in per child to AI content-safety scanning (§4), the same Accessibility Service can read message text in a fixed list of supported messaging apps for safety classification only; that capture path is off by default and is not enabled in the current release of the app. - Device Admin & tamper signals: once you enable Device Admin during setup, Android prevents the child from uninstalling OurShield or disabling enforcement without your PIN. We log tamper events (e.g. accessibility or device-admin being disabled, usage-access being revoked) so you’re alerted if protection is removed.
- DNS/domain activity via an on-device VPN: OurShield uses Android’s VpnService API to run a local, on-device DNS filter. Only DNS queries are routed through this local tunnel and resolved over DNS-over-HTTPS against OurShield’s resolver; all other traffic goes out normally. We do not proxy, inspect, or store the content of your child’s web/app traffic — only the domain/category of each DNS lookup is recorded, for content-category filtering and activity reports. We do not store full URLs or page content.
- Installed apps and per-app screen time: OurShield reads the list of apps installed on the child’s device (install/uninstall events) and, via Usage Access, each app’s daily foreground time. This powers the parent’s app-block/ time-limit configuration screen, install/uninstall alerts, and screen-time reports.
- SIM/carrier signal: OurShield reads carrier name and SIM country/count (never the phone number or SIM ID) to detect a SIM swap on the child’s device and alert you — a tamper-resistance signal, not a way to identify the child’s phone number.
- Driving detection: when enabled for your plan, OurShield detects likely driving and reports trip start/end location, speed, hard-braking/rapid-acceleration events, and phone-use-while-driving events, so you can see driving and phone-use alerts.
We never request SMS, call log, contacts, or microphone access on the child device, and we do not collect any of those categories.
3. Purposes of processing
Personal data is processed only for: (a) delivering the OurShield service to your family, (b) issuing safety alerts to you, (c) aggregated product analytics (fully de-identified), (d) billing through Razorpay, and (e) responding to lawful orders of Indian authorities under the DPDP Act and applicable criminal procedure.
4. AI content-safety monitoring (optional, per child)
If you separately opt in for a specific child, OurShield’s AI reviews on-screen message content in supported messaging and social apps for safety-relevant patterns — bullying, self-harm risk, grooming, hate speech, and explicit content. This monitoring is off by default and requires your explicit, per-child consent in addition to the account-level consent described in §1; you can turn it on or off at any time from that child’s settings. When it is off, no message content is ever sent to our AI processor or stored.
When it is on: message text is sent to our AI processor (see §6, Sharing) for classification only. We do not store the raw message, and we never quote or show you the underlying text — you receive a signal category (e.g. “possible bullying signal”) and a timestamp, by design. If a possible self-harm signal is detected, that alert also includes verified crisis-helpline numbers so you have somewhere to turn immediately.
5. Retention windows
- Raw activity events (DNS/domain activity, app foreground-time records) — 90 days (partitioned, auto-dropped).
- Daily aggregates — 365 days.
- Location pings — 90 days by default (parent-adjustable).
- Driving trips and driving events — 90 days.
- Device-admin / tamper events — 365 days.
- Installed-app (install/uninstall) records and SIM-swap events — retained while the child profile exists; deleted when the child profile or account is deleted.
- AI content-safety alerts (§4) — 30 days; only the category and timestamp are retained, never the source message.
- Audit logs — 24 hours hot, 365 days cold for compliance.
- Deleted accounts — 30-day grace period, then cryptographic erasure.
6. Sharing and cross-border transfers
We do not sell personal data. Processors used: Razorpay (payments), Cloudflare (WAF + CDN, EU/US edge), AWS ap-south-1 (primary storage, Mumbai), Anthropic (Claude API, US) — prompts, including the optional content-safety scanning in §4, are tokenized and stripped of PII before transmission per our AI-01 rule. Cross-border transfers comply with §16 of the DPDP Act.
7. Your rights as Data Principal (incl. data deletion)
You may (a) access a machine-readable export of your family’s data, (b) request correction, (c) request erasure, (d) nominate a person to act on your behalf in the event of death or incapacity, and (e) file a grievance. Points (a) and (c) are self-service at /settings/account.
Account & data deletion: you can delete your account and your family’s associated data yourself, in-app, at Settings → Account (web: /settings/account), or by emailing privacy@shieldapp.rstglobal.in. On deletion we apply a 30-day grace period (during which you can cancel the request) and then perform cryptographic erasure, as described in §4 above.
8. Grievance Officer
Grievance Officer: Virender Kumar, grievance@shieldapp.rstglobal.in, Emaar The Palm Square, Unit No. # 09, 2nd Floor, Emaar MGF, Golf Course Ext Rd, Sector 66, Gurugram, Haryana 122002, India. Response SLA: 30 days per DPDP §13.
9. Contact
You may contact us about this policy at: privacy@shieldapp.rstglobal.in.