Last updated: 6 September 2026
Paxio ("we," "us," "the app") is a parental control app that helps a parent manage a child's Android device through the parental-control features it offers, which may be added, removed, or changed over time. This policy explains what data Paxio collects, why, and where it goes. Paxio is installed and configured by a parent or guardian; it does not create a separate account for the child.
| Data | Purpose | Where it's stored |
|---|---|---|
| Parent email (Google or email sign-in) | Identify the parent account; sign in on a new device | Firebase Authentication (Google) |
| Child profile (name, age, avatar, daily limit) | Personalize the dashboard; survive a reinstall | Firebase Firestore (Google), tied to the parent account |
| Parent PIN | Protect settings from being changed by the child | Salted PBKDF2 hash only — never plaintext |
| App usage duration, per app | Show progress; enforce daily limits; let a parent see this from a separate device | Local device database, and synced to Firebase Firestore (Google) so it's visible from the parent's own device — never shared beyond that |
| Blocked/allowed app list, blocked-site visits, blocked-app attempts | Enforce app blocking and content filtering; let a parent review this history from a separate device | Local device database, and synced to Firebase Firestore (Google) — never shared beyond that |
| DNS requests, while filtering is on | Block sites matching selected categories | Processed on-device via local VPN; never sent anywhere. Only the resulting decision (a site was blocked, and which category) is synced, not full browsing activity |
| Foreground app package name | Detect when a blocked app opens | Read in memory on-device only |
| App install/uninstall events (package name only) | Power the optional "app installed/uninstalled" email alert, if a parent turns it on | Local device, and synced to Firebase Firestore (Google) |
| Crash & diagnostic reports | Find and fix bugs — includes device model, OS version, app version, and the crash stack trace; no personal information is intentionally included | Firebase Crashlytics (Google) |
| Product usage analytics (screens viewed, features used — e.g. a control turned on, an onboarding step completed — and enforcement events like a limit or bedtime lock triggering) | Understand which features are actually used, so we can fix what's broken and improve what matters, rather than guessing | Firebase Analytics/Google Analytics and Mixpanel, tied to the parent's account ID (not name or email); never includes app content, visited URLs, or child names |
The Paxio app itself does not collect location data, does not read screen content, keystrokes, messages, photos, or full browsing history (only whether a specific site visit was blocked, and its category). The analytics SDKs described above only receive the specific event names and properties listed in this policy — not raw device data, screen recordings, or ad identifiers, and they are not used for advertising.
This website (paxio.in) — separate from the Paxio app — uses Cloudflare Web Analytics to understand traffic to our marketing pages. It's a privacy-friendly analytics service: it doesn't use cookies, doesn't set any persistent identifier, and doesn't track individual visitors across sites. It only aggregates anonymous traffic counts. This applies to browsing paxio.in and does not apply to, or collect data from, the Paxio app itself.
We don't sell data or share it with advertisers. Data above is processed by Google/Firebase solely to provide sign-in, profile sync, crash reporting, and product analytics, and by Mixpanel solely to provide product analytics, each under their own privacy terms. Both store data on servers primarily located in the United States. By using Paxio, the parent consents to this cross-border transfer. Firebase's data processing terms are available at firebase.google.com/terms/data-processing-terms, and Mixpanel's at mixpanel.com/legal/dpa.
Paxio uses the following third-party services to operate, each governed by their own privacy terms:
No ad networks process your data, and analytics data is never sold or used to serve ads.
Child profile and PIN data are kept until the parent deletes the child profile or account. Usage history, blocked-site visits, and blocked-app attempts are automatically deleted after 30 days on the Free plan, or 1 year on Paxio Pro, both locally and in Firestore. Local, on-device data is also removed when Paxio is uninstalled. A parent can delete a single child's data, or their whole account, at any time directly in the app — see Delete Your Data and Delete Your Account for exactly what's removed.
Paxio protects your data using industry-standard measures:
Paxio is installed and configured by a parent or guardian aged 18 or over. The child does not create an account, sign in, or provide information directly to Paxio. We do not knowingly collect personal data from children — data about a child's device usage is collected on behalf of, and accessible only to, their parent or guardian.
If you believe a child under 13 has created a parent account without parental consent, contact us at support@paxio.in and we will delete the account within 7 days.
Paxio requests Android permissions only as needed to support its parental-control features, and each is explained in-app before use. The specific permissions requested may change over time as features are added, removed, or changed; the current permissions requested by the app are also listed on its Google Play Store listing.
We may update this policy from time to time. For material changes — those affecting what data we collect or how it's used — we will notify you via the email address on your account at least 14 days before the changes take effect. For minor changes (corrections, clarifications) we will update the "Last updated" date without prior notice. Continued use after the effective date constitutes acceptance.
Questions about this policy or your data: support@paxio.in.