Privacy Policy
Effective date: 2 July 2026
Version: 1.0
Data controller: Individual entrepreneur Aleksandr Viktorovich Popov, INN 343700251016, OGRNIP 320344300015828.
Contact: app@gardion.io
1. Who we are and what this covers
Gardion is parental-control software for Windows and Android devices. It consists of:
- A parent web dashboard (
https://gardion.io) - An agent installed on the child's device (the Windows agent and/or the Android app
io.gardion.kids) - A parent mobile app (
io.gardion.family, used for notifications)
We act as the data controller under Russian Federal Law No. 152-FZ "On Personal Data". Please note that Gardion is operated from Russia and your data is stored on servers in Russia. We do not claim compliance with the GDPR or with any data-protection regime outside Russia. Read section 5 before you decide to use the service.
2. What we collect
2.1 From the parent (dashboard user)
| Category | Specific fields | Source | Purpose |
|---|---|---|---|
| Identification | Email, password hash (bcrypt) | Sign-up | Authentication |
| Payment information | We never store card numbers. Only the payment ID from the payment provider | Payment provider webhook | Payment records |
| Contact | Sign-up | Support, notifications | |
| Technical | IP address, User-Agent, session timestamps | HTTP requests | Security, abuse prevention |
2.2 From the child's device (Windows agent)
| Category | Specific fields | Purpose |
|---|---|---|
| Device identification | Hostname, machine_uid (a stable hash), platform | Linking the device to the parent account |
| App usage | List of running programs and time spent in each | Screen-time accounting, enforcing limits |
| Browser history | URLs and page titles in Chrome, Edge, Firefox, Yandex | Understanding usage context (optional, can be switched off by the parent) |
| Screenshots | Screen captures taken at the parent's request | Supervision (optional, only when the parent presses the button) |
| Device state | CPU, RAM, battery level, current user | Diagnostics, dashboard display |
| Logs | Technical agent events, bypass attempts | Security, debugging |
2.3 From the child's device (Android app)
| Category | Specific fields | Purpose |
|---|---|---|
| Device identification | Android ID, device name | Linking the device to the parent account |
| App usage | Package names and usage time (UsageStats API) | Screen-time accounting |
| Web filter (URLs) | The address of the page open in the browser, read through AccessibilityService and checked against the parent's block list. The URL is not kept as history; only blocking events are sent to the server | Enforcing the web filter |
| Location | GPS coordinates, accuracy, speed, battery percentage | Location in the dashboard, geofences, SOS |
| Geofence events | Enter and exit events for zones set by the parent | Push notifications to the parent |
| SOS signal | Coordinates at the moment the SOS button is pressed | Emergency notification to the parent |
2.4 Error logs (Sentry)
If the software crashes, we may send:
- The error type and stack trace
- The application version
- The operating-system version
- We do not send message contents, coordinates, or user names
This is optional and is switched off by setting SENTRY_DSN= (an empty value) in the agent settings.
3. What we do not collect and do not do
- We do not record keystrokes (no keylogger)
- We do not read the contents of messengers (Telegram, VK, WhatsApp and others)
- We do not activate the microphone
- We turn on the camera only for the duration of a motion-recognition warm-up break, and only if the parent has enabled that break level. The frames are processed on the device itself, are never sent to our servers and are not stored anywhere. Outside the warm-up the camera is not used
- We do not pass data to third parties for marketing
- We do not show advertising
- We do not use cookies for analytics (only a session cookie for login)
- We do not permit the agent to be used to monitor adults, spouses, or anyone other than the user's own minor children
- We do not run hidden on the child's device: the icon is always visible
4. Special rules for children's data
The software is designed to supervise devices of children up to and including the age of 14, and may extend to ages 15 to 17 with consent.
4.1 Parent consent
When the agent is first installed, the parent explicitly confirms, by ticking a box:
- That they are the parent or legal guardian of the child
- That they have read this Policy
- That they consent to processing the minor's personal data under Article 9 of 152-FZ
- The age of the child
The consent is written to an audit log with a timestamp, the parent's IP address and the version of the Policy.
4.2 Consent of children aged 10 and over
If the child's age is given as 10 or above, the parent separately confirms that the child has been told that parental-control software is being installed on their device.
4.3 Withdrawing consent
Consent can be withdrawn at any time by deleting the account (Settings, then Delete account, in the dashboard). After deletion:
- All of the child's data is erased within 30 days
- Paid access ends
- Unused days are refunded if an annual plan was paid for
5. Where and how we store data
- Server: Russia, Timeweb Cloud
- Database: SQLite on an isolated server, accessible only to the administrator over an SSH key
- Encryption in transit: HTTPS / TLS 1.3
- Encryption at rest: Passwords use bcrypt with 12 rounds. Agent API keys are stored as SHA-256 hashes, and the key itself is never kept after it is issued.
- Backups: daily, encrypted, retained for 30 days
- Retention of active data: for as long as the account exists, plus 30 days after deletion
- Browser history: kept for 3 days, then deleted automatically. Advertising and tracking URLs are not stored.
Because the servers are located in Russia, using Gardion means your data and your child's data are processed in Russia under Russian law. If that is unacceptable to you, please do not use the service.
6. Data sharing
6.1 Who receives data
| Recipient | What we share | Basis |
|---|---|---|
| The payment provider | Payment amount, email | Contract with the payment provider |
| Sentry GmbH (Germany) | Error logs without personal data | User consent (optional). Sentry is based in Germany, so this is a cross-border transfer. It is active only if the parent or administrator configures SENTRY_DSN. |
| Russian state authorities | On a properly issued request | 152-FZ, Russian Code of Criminal Procedure |
6.2 Who does not receive data
Any other third party. We share nothing with marketing services, analytics providers or advertisers.
7. Your rights
Under 152-FZ you have the right to:
- Obtain a copy of your data (request it at app@gardion.io)
- Correct inaccurate data
- Delete your data (Delete account in the dashboard, or a request to app@gardion.io)
- Restrict processing
- Complain to Roskomnadzor (address in Russia: Kitaygorodsky proezd 7, building 2, Moscow, 109074)
We respond to requests within 30 days.
8. Cookies
We use exactly one technical cookie:
session— HttpOnly, Secure, SameSite=Lax, valid for 30 days- Used only to keep you signed in to the dashboard
- Not shared with third parties
- Not used for analytics or advertising
9. Changes to this policy
We will notify you by email 14 days before any change takes effect.
10. Contact
- Email: app@gardion.io
- Postal address available on request at app@gardion.io
This document is a public offer. You accept it by registering an account or by installing the agent on a child's device.