Don't Bug Dad CS

Effective 1 September 2026

Privacy policy

Applies to the app Don't Bug Dad / Nezlob tátu (package cz.eadg.parental_screen_control).

The app exists so a parent can manage screen time on their child's phone. It collects only what that needs, stores it in the European Union, and shows it to nobody else. Here is the complete list, with no small print.

What we process and why

DataWhat it is forHow long we keep it
Parent's e-mail and passwordSigning in to the parent account (the password is stored only as a hash by Google Firebase)Until the account is deleted
The list of apps on the child's phoneSo the parent can choose what to block and what to allowUntil the child is unpaired / the account deleted
Time spent in apps (minutes per app and per hour)Enforcing the daily limit and the parent's overviewUntil the child is unpaired / the account deleted
The child phone's locationThe “where is the phone” map and arrival/departure alerts for saved places (Home, School)History is deleted automatically after 24 hours
Messages between the child and parentsSo a child with a blocked phone can still reach their parentsDeleted automatically after 24 hours
Phone status (battery, permission health)So the parent can see monitoring is workingContinuously overwritten, until the account is deleted
Device push tokensDelivering notifications (time requests, messages, place alerts)Until sign-out / account deletion

Where the data lives

In Google Firebase (Firestore) in the europe-west3 region (Frankfurt, EU). The processor is Google Ireland Ltd. through the Firebase services (database, sign-in, notification delivery). All transfers are encrypted.

Who can see it

Only the parents of the family, in their own app. Data is not shared with or sold to any third party. The app contains no ads and no analytics or tracking tools. The operator has technical access as the database administrator and uses it solely to resolve a problem at a parent's request.

Children's data

The child's side of the app is installed and set up by the parent, who thereby consents to the processing of their child's data. The child signs in nowhere and enters no name or e-mail — the child's phone acts under an anonymous technical account. Data from the child's phone is shown exclusively to the parents of that family. The child can see in the app that monitoring is on, how much time remains, and that the parent can see the phone's location.

Permissions the app uses (on the child's phone)

PermissionWhy
AccessibilityLets the app see which app is on screen so it can block the ones the parent chose. It does not read messages, passwords or content of other apps — only on system Settings screens does it look for its own name, to recognise the page where monitoring could be switched off. Nothing it sees is stored or transmitted.
Background locationReporting the phone's location to the parent (~every 15 minutes) and arrival/departure alerts for saved places.
Usage accessMeasuring time spent in apps, so the daily limit works.
Display over other appsShowing the block screen over a blocked app.
Device adminWith no powers over the phone at all — the app claims no data wipe, no password rules, no camera lock. The registration exists only so Android asks for one more confirmation before the app is uninstalled. The app neither configures nor reads anything through it.

Security

Transfers are encrypted (TLS) and access is guarded by server-side security rules bound to specific accounts. Pairing codes are stored only as SHA-256 hashes, as are sign-in restore keys. The unlock code is never stored anywhere: both phones work it out from a shared key and the clock, so there is no code to leak.

Delete your account and data

In the app: parent dashboard → ⋮ menu → Delete account. Unpair the children's phones first (that safely stops the blocking on them), confirm with your password — and the parent account and all the family's data are deleted: rules, usage history, location, messages, everything.

By e-mail: if you no longer have the app, write from the e-mail the account was created with to nezlobtatu@eadg.cz and we will delete the account and data within 30 days.

Your rights

Under the GDPR you have the right to access, rectify, erase and port your data, and to lodge a complaint with your data-protection authority. Use the contact below for any request.

Changes to this policy

If this policy changes, the new version is published on this page with a new effective date. The page's history is available in the app's repository.

Contact

Operator of Don't Bug Dad
E-mail: nezlobtatu@eadg.cz