Privacy Policy

Effective Date:March 1, 2025Last Updated:March 18, 2026Company:ChildSafe.dev Inc.
RoseShield Promise Icon
Our core promise:
RoseShield's Proprietary Edge AI architecture means all sensitive behavioral and content data is processed locally — on your device or within your network. It never leaves our servers. This is not a marketing claim. It is an architectural guarantee.

1. Who We Are

ChildSafe.dev Inc. ("RoseShield," "we," "us," or "our") is a digital family safety company incorporated in the State of Florida, with its principal place of business at 333 Sunset Dr, Suite 204, Fort Lauderdale, FL 33301, United States.

This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use any RoseShield product, service, application, or website (collectively, the "Services"). It applies to all users, including parents, guardians, educators, institutional administrators, telecom partners, and any other parties who interact with our Services.

By using the Services, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of the Services.

2. Edge AI Architecture — How Privacy Is Built In

Most digital safety products work by routing your internet traffic through a third-party cloud server for analysis. This means every website you visit, every search you make, and every link your child clicks is seen by the provider's infrastructure.

RoseShield does not work this way.

Our Proprietary Edge AI system deploys AI inference models directly to your device, home router, or carrier network node. All threat classification, content analysis, and behavioral pattern detection happens locally — within your device or network perimeter. No content, URLs, search queries, or behavioral data is transmitted to our servers for AI processing.

What this means for your privacy:

  • We cannot see what websites your family visits;
  • We cannot read the content of any communications;
  • We do not build behavioral profiles stored in our cloud;
  • Even our engineers cannot access your content data — because it never reaches our systems.

This is our Zero Cloud Footprint architecture. It is the foundation of everything we build.

3. What We Do Collect

We collect only the data that is strictly necessary to operate, improve, and support the Services:

Account Information. When you create an account, we collect your name, email address, password (hashed), and payment information (processed by our PCI-compliant payment provider — we do not store full card numbers).

Device Metadata. We collect non-identifying device metadata such as operating system version, app version, device type (e.g., "iOS device"), and installation identifiers — solely to ensure compatibility and deliver software updates.

Aggregated Threat Statistics. We receive category-level counts from your local Edge AI engine — for example, "3 threats blocked today" or "content category: adult content." These are aggregate summaries only. No URLs, domain names, or content details are included.

Usage Analytics. We collect anonymized, aggregated usage data (e.g., which features are used, session frequency) to improve the product experience. This data cannot be used to identify individual users.

Support Communications. If you contact our support team, we retain the content of those communications to resolve your issue and improve our services.

Carrier Partner Data. For telecom and ISP partners, we may process subscriber-level policy configurations and anonymized network event statistics under a separate Data Processing Agreement. We do not process individual subscriber content data.

4. What We Explicitly Never Collect

We want to be unambiguous about what we do not collect:

The content of any website, page, or URL your family visits;

The content of any message, email, or communication;

Real-time location coordinates (location zone features use geofences evaluated locally on the device);

Audio, video, or screenshots from any device;

Individual browsing histories or search queries;

Full text of any blocked content;

Any biometric data;

Social Security numbers, government ID numbers, or financial account numbers.

We will never sell, rent, or trade your personal information to third parties for advertising or marketing purposes.

5. How We Use Data

We use the data we collect solely for the following purposes:

Service Delivery: To activate, authenticate, and operate your subscription;

Billing: To process payments and manage your subscription;

Customer Support: To respond to your requests and resolve issues;

Product Improvement: To understand how features are used and improve the user experience (using aggregated, anonymized data only);

Security: To detect fraud, unauthorized access, and abuse of our platform;

Legal Compliance: To comply with applicable laws, regulations, and lawful requests from public authorities;

Communications: To send you important service notices, security alerts, and (with your consent) promotional communications. You may opt out of marketing communications at any time.

We do not use your data to train AI models. Our AI models are trained on curated, publicly available datasets and are subject to our Ethical AI Policy.

6. Children's Privacy (COPPA)

RoseShield is deeply committed to the protection of children's privacy. Our Services are designed for parents, guardians, and educators — not for direct use by children. We comply fully with the Children's Online Privacy Protection Act (COPPA), the EU General Data Protection Regulation Article 8, and equivalent laws globally.

We do not knowingly collect personal information from children under the age of 13 without verifiable parental consent. When a child's device is enrolled in the Services, the account is held by the parent or guardian. The child's device data (aggregated threat counts, policy compliance status) is associated with the parent's account — not the child's identity.

Specifically regarding children's data:

We do not create profiles of individual children's online behavior;

We do not share children's data with any third party for advertising purposes;

Parents and guardians may request deletion of all data associated with their child's enrolled device at any time by contacting privacy@childsafe.dev;

We use the minimum data necessary to enforce parental policies configured by the account holder.

If you believe we have inadvertently collected information from a child under 13 without parental consent, please contact us immediately at privacy@childsafe.dev and we will take prompt action to delete such information.

7. Data Sharing & Disclosure

We do not sell personal information. We share data only in the following limited circumstances:

Service Providers. We engage trusted third-party vendors to assist in operating the Services, including payment processors (Stripe), cloud infrastructure providers (for account and billing data only), and email delivery services. These vendors are contractually bound to process data only as directed by us and in accordance with applicable privacy laws.

Carrier & ISP Partners. For white-label deployments, partners receive anonymized, aggregate statistics relevant to their subscriber base. Individual subscriber content data is never shared. Partners are subject to Data Processing Agreements.

Legal Requirements. We may disclose personal information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency). We will notify you of any such request where legally permitted to do so.

Business Transfers. In the event of a merger, acquisition, or sale of assets, personal information may be transferred. We will notify you via email and/or a prominent notice on our website at least 30 days prior to such a transfer, and you will have the opportunity to delete your account.

Protection of Rights. We may disclose information where we believe it is necessary to protect the safety, rights, or property of RoseShield, our users, or the public — particularly in cases involving potential harm to children.

8. Data Security

We implement industry-standard technical, administrative, and physical security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

AES-256 encryption of data at rest;

TLS 1.3 encryption of all data in transit;

Role-based access controls and multi-factor authentication for all staff with data access;

Regular penetration testing and vulnerability assessments;

ISO 27001-aligned information security management practices;

Annual third-party security audits.

However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

In the event of a data breach affecting your personal information, we will notify you and relevant regulatory authorities as required by applicable law, within the timeframes mandated by those laws.

9. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this policy, to maintain your account, to comply with our legal obligations, resolve disputes, and enforce our agreements.

Specifically:

Account data is retained for the duration of your subscription plus 90 days after account deletion, to allow for account recovery;

Billing records are retained for 7 years as required by financial regulations;

Aggregated analytics are retained indefinitely in anonymized form;

Support communications are retained for 3 years;

Children's device data is deleted upon account closure or earlier upon request.

You may request deletion of your personal data at any time. See Section 10 for your rights.

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal data we hold about you;
  • Correction: Request correction of inaccurate or incomplete data;
  • Deletion: Request deletion of your personal data ("right to be forgotten");
  • Portability: Receive your data in a structured, machine-readable format;
  • Objection: Object to processing based on legitimate interests;
  • Restriction: Request restriction of processing in certain circumstances;
  • Withdrawal of Consent: Withdraw consent at any time where processing is based on consent;
  • Non-Discrimination: California residents have the right not to be discriminated against for exercising CCPA rights.

To exercise any of these rights, please contact our Data Protection Officer at privacy@childsafe.dev. We will respond to verified requests within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

11. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to operate the site, remember your preferences, and understand how visitors interact with our content.

Essential Cookies: Required for the site to function (session management, authentication). Cannot be disabled.

Analytics Cookies: Used to understand aggregate usage patterns (e.g., page views, bounce rates). We use privacy-respecting analytics tools and do not share this data with advertising networks.

Preference Cookies: Remember your settings and preferences across visits.

We do not use advertising cookies, retargeting pixels, or tracking technologies from social media platforms on pages that children may access. You may manage cookie preferences through your browser settings or our cookie consent banner.

12. International Data Transfers

ChildSafe.dev Inc. is headquartered in the United States. If you are accessing the Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where our servers are located and our central database is operated.

For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure that any international transfer of personal data is subject to appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, where applicable.

For carrier and ISP partners in specific jurisdictions, we support data residency requirements through regional deployment of our Edge AI nodes, ensuring subscriber data stays within the required geographic boundary.

13. Data Protection Officer

We have appointed a Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and applicable data protection laws. If you have questions about how we handle your personal information, or wish to exercise your data rights, please contact our DPO:

Data Protection Officer — ChildSafe.dev Inc.

LocationChildSafe.dev Inc

333 Sunset Dr, Suite 204

Fort Lauderdale, FL 33301

United States

Email: privacy@childsafe.dev

For EU/UK GDPR inquiries: gdpr@childsafe.dev

You also have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal information in accordance with applicable law.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on this page with a revised "Last Updated" date, and where appropriate, by sending an email notification to your registered email address at least 30 days before the changes take effect.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us:

ChildSafe.dev Inc. — Privacy Team

LocationChildSafe.dev Inc

333 Sunset Dr, Suite 204

Fort Lauderdale, FL 33301

United States

Email: privacy@childsafe.dev