This page was written by reading the app's own source code and listing every outbound network call it can make. It is not a template. If something below turns out to be wrong, that is a bug and we want to hear about it.
Draft โ not yet reviewed by a lawyer. This is an accurate engineering description of what the software does. It is not yet a legal privacy policy, and it has not been reviewed against COPPA (US), UK GDPR, or the EU GDPR provisions covering children. If you are reading this as a prospective beta family: that review is happening before the app is offered to anyone outside a small group who know us personally.
With the settings the app ships with, nothing about your child leaves your computer. No account, no sign-up, no email address, no analytics, no crash reporting, no advertising identifiers. We do not have a server that stores anything about your child, because we do not collect anything to store.
Three things do go out over the network, and none of them is about your child specifically. They are listed in full below.
This is the complete list for the app's default settings. Each row says what triggers it and exactly what is in it.
| What | When | What is actually sent |
|---|---|---|
| Ad and tracker filter lists | Every time the app starts | A request to a public file host for the filter rules used to strip ads out of pages. Your computer's IP address and browser identification are visible to that host, as they are for any web request. Nothing about your child, and nothing about which sites they visit, is included. |
| Update check | Every time the app starts, Windows only | A request to our own server asking "is there a newer version?". It contains your IP address and the version you are running. It does not contain an account, a device identifier, or anything about your child. On macOS this does not happen at all. |
| The websites your child opens | When they use the browser | Exactly what any browser sends: the request goes to the site itself. PBS Kids can see that someone visited PBS Kids. That traffic goes to those sites, not to us โ we never see which sites are opened. |
What is deliberately not on that list. No analytics or telemetry of any kind. No crash reporting. No remote configuration. No account system or email capture. No advertising or attribution SDKs. The app has never had any of these, and the absence is checked rather than assumed.
The app can use an AI service to help judge whether a page is suitable. In the version you download, that is switched off, and a parent has to turn it on deliberately. While it is off, no page content and no web address is ever sent anywhere.
If a parent turns it on, page addresses and some page text are sent to an AI provider (Anthropic or OpenAI) to be assessed. We think most families should leave it off, and we would rather say that plainly than bury it.
The children's learning panel used to send the address of every page to an AI service as your child browsed. That was removed. It now works entirely from content built into the app, and makes no network request at all.
Everything the app records stays on the machine it runs on. Nothing is uploaded.
To delete all of it, uninstall the app and delete its folder. There is currently no in-app "delete everything" button โ also on the list, and also not something we will pretend already exists.
On Windows, the encryption depends on user accounts. The parent password is protected using Windows' built-in encryption, which is tied to the Windows user account. If your child uses the same Windows account as you, or has administrator access, that protection does not hold. Give your child their own standard (non-administrator) Windows account.
We would rather you find these here than discover them later.
This app is designed for children roughly five to ten years old. That places it squarely inside the rules that exist specifically to protect children's data โ COPPA in the United States, and the children's provisions of UK and EU data protection law.
Our position is that the safest way to comply with all of them is to not collect anything in the first place, which is what the default configuration does. We are not relying on that being enough: the formal review against those rules is happening before the app is offered beyond people we know personally.
If any statement on this page does not match what the app does, we want to
know โ that is a bug in the software or a bug in this page, and both matter.
Security issues have their own reporting route in the project's
SECURITY.md.
This page describes the app as of the current beta release. When the app's behaviour changes, this page changes in the same release โ it is written from the source, so it is not allowed to drift.