privacy

Parental Control Apps Upload Your Child's Messages to Company Servers

Popular parental monitoring apps like Bark and Qustodio send your child's private messages to third-party servers. Here's what they collect and where it goes.

The Safety-Privacy Trade-Off Parents Did Not Know They Were Making

Parental control apps occupy a complicated space in the digital privacy landscape. Parents install them to protect children from online predators, cyberbullying, and harmful content. The apps then, with the best of intentions, create a comprehensive surveillance dossier on those same children — and store it on servers controlled by companies the parents know very little about.

This is not a hidden conspiracy. It is in the terms of service. Most parents simply do not read far enough to understand what they are consenting to on their children’s behalf.

What Parental Monitoring Apps Actually Collect

The data collection profiles of major parental control apps go significantly deeper than most parents realize when they sign up.

Location data is the most obvious. Apps like Life360, Bark, and Qustodio offer real-time GPS tracking with historical location logs. That data lives on their servers, not just on your phone.

Message content is where things become more sensitive. Bark, which markets itself as AI-powered cyberbullying detection, works by uploading copies of your child’s messages — texts, emails, and social media messages from connected platforms — to Bark’s servers. Bark’s AI analyzes those messages for warning signs. The analysis happens in the cloud, on Bark’s infrastructure, not on the child’s device or the parent’s phone.

That means every message Bark flags — and many it does not flag — passes through a third-party system hosted in the United States. It is processed and stored by a company that is a potential target for data breaches, legal requests, and ownership changes over time.

Screen time and app usage data is collected by virtually every major parental control tool. This builds a behavioral profile: which apps the child uses, for how long, at what times of day, and which categories of content they consume.

Web browsing history is routed through the apps’ servers in many implementations. In order to filter content in real-time, some apps use a DNS proxy or VPN configuration that tunnels your child’s web traffic through their infrastructure.

Location history patterns — not just where your child is now, but everywhere they have been over months or years — accumulate in these companies’ databases. Life360, for instance, maintains historical location data that builds a detailed map of a child’s movements over the lifetime of their subscription.

Where the Data Goes

These apps all have privacy policies. Most are written carefully enough to comply with COPPA (the Children’s Online Privacy Protection Act) and, for users in Europe, GDPR. Compliance with these regulations does not mean the data is not collected or stored. It means the companies must follow specific rules about how they handle it.

Bark states it does not sell personal information and gives users the ability to delete accounts. However, it processes message content on external servers to run its AI analysis. A US company subject to US law, Bark can receive legal requests — subpoenas, court orders — for data it holds. Content that felt private when your child sent a text message may not be private in a legal proceeding.

Qustodio processes behavioral and usage data on external servers and has faced questions about what it shares with third-party analytics services. Its privacy policy discloses data sharing with service providers and analytics partners, which is standard legal language but covers a broader range of data flows than most parents imagine.

Life360 drew significant attention in 2021 when reporting revealed it was selling precise location data to data brokers. The company subsequently changed its policy, but the episode demonstrated that location data — including a child’s daily movements — has commercial value and that companies under growth pressure may monetize it in ways their initial users did not expect.

The COPPA Gap

COPPA protects children under 13 from certain types of data collection without verified parental consent. Parents who install monitoring apps on their children’s devices are providing that consent themselves — but often without understanding what they are consenting to.

The law does not require these companies to collect less data. It requires them to get consent before collecting it. The consent is embedded in the Terms of Service that parents agree to during setup. Most setup flows are optimized to get parents through quickly, not to ensure they understand the data practices they are approving.

For children over 13, COPPA protections do not apply at all. A teenager’s messages, location history, and behavioral data collected through a parental monitoring app have the same level of regulatory protection as any adult’s commercial data — which is to say, minimal protection under current US federal law.

COPPA 2.0, which passed in 2025, extends some protections to users under 17 and strengthens requirements for apps directed at minors. But it does not prohibit the fundamental model: parental consent triggers data collection that parents may not fully understand.

The Data Breach Risk

Any database that stores children’s data is a high-value target for attackers.

Children’s personal information — names, ages, locations, communication patterns — is particularly valuable to identity thieves and data brokers because children rarely discover that their identity has been compromised until they are adults and attempt to open a credit account. A breach of a parental monitoring app database could expose years of a child’s location history, message content, and behavioral patterns to unauthorized parties.

Parental monitoring apps vary significantly in their security posture. Some have undergone third-party security audits; many have not published evidence of doing so. The combination of highly sensitive data and variable security practice creates meaningful exposure.

What Happens When the Company Changes Hands

Parental control companies are acquired regularly. Life360 acquired Tile in 2021, expanding its product portfolio and data collection scope. Smaller parental control apps are acquired by larger players in the family safety space, by security companies, or by advertising technology firms.

When an acquisition happens, the new owner may have a different interpretation of what can be done with the accumulated data. Privacy policies can be updated to reflect the acquirer’s practices. The child’s years of location history, message metadata, and behavioral data goes with the company when it is sold.

The data retention practices of these companies also vary. Some apps allow you to delete data on demand. Others retain it for extended periods after subscription cancellation. Understanding the specific retention policy of the app you use is not optional — it determines how long your child’s private data sits in someone else’s database after you stop paying for the service.

Questions to Ask Before Installing Any Monitoring App

Before installing a parental monitoring app, the following questions are worth answering:

Where is message content processed? On the child’s device, on your device, or on the company’s servers? If it is the company’s servers, that is a third-party custody of your child’s communications.

What is the data retention period after account deletion? Some apps retain data for 90 days after deletion; others retain it longer. Ask specifically.

Does the company sell or share data with third parties? “We do not sell personal information” does not mean the same thing as “we do not share data with data brokers.” The legal definitions differ, and some companies share under contracts that nominally exclude sale.

What happens to the data if the company is acquired? No company can guarantee what a future owner will do, but a company with genuine privacy commitments will have a specific policy on this point.

Has the app undergone a third-party security audit? Look for published SOC 2 reports or penetration testing results. If neither exists, the company’s security practices are unverified.

A Different Model for Family Privacy

The surveillance model — route your child’s data through a third-party company — is not the only available architecture for family safety.

Router-level content filtering, such as the tools built into many modern home routers or offered by services like Pi-hole combined with DNS blocking, filters content without sending that content to a third party. The filtering happens on hardware in your home. No company server ever sees what your child was trying to access.

Conversation-based oversight — knowing your children well enough to have direct conversations about what they encounter online — has no data footprint at all.

For families that do use parental monitoring apps, choosing apps that perform content analysis on-device rather than in the cloud significantly limits third-party data exposure. The tradeoff is usually reduced detection sophistication, but the privacy gain is meaningful.

Protecting Children’s Data Means Reading the Fine Print

The core issue is not that parental monitoring apps are malicious. Most are built by people who genuinely want to help families navigate a complicated digital landscape.

The issue is that the data model — cloud-based analysis of children’s private communications — creates a third-party custodian for some of the most sensitive information a family generates. That custodian may handle the data responsibly. It may face a data breach. It may be acquired by a company with different values. It may change its privacy policy in ways that change how the data is used.

Parents who understand what they are consenting to can make informed choices. Parents who do not understand it cannot. Reading the privacy policy before installing is not optional — it is the only way to know what trade-off you are actually making on behalf of your child.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts