← glurpa
Privacy Policy
Glurpa is a parental-control service for children, so this notice is written to meet the Children's Online Privacy Protection Act (COPPA). It is meant to be read by a parent, not a lawyer.
Who we are
Glurpa is operated by an individual developer. A parent is the account holder; children never have their own account. An account can hold two parents, and a parent can hand a babysitter a short-lived code — see “Who else can reach your child’s screen” below for exactly what each of them sees. Questions, requests, or complaints: hello@glurpa.com. We answer every message about a child's data.
What we collect from the parent
- Email address — to sign you in and to send account and billing email.
- Password hash — if you set a password. We store a PBKDF2 hash, never the password itself.
- Sign-in with Google or Microsoft, if you choose it — when you approve the sign-in, Google or Microsoft sends us the email address on that account and whether they have verified it. What they send can also carry the name on the account, a link to its profile picture and their own identifier for it; we use the email address and keep nothing else from them. We never ask either company for your contacts, calendar or files. You can use a password or an emailed code instead and never involve either company.
- Plan and billing state — which plan you are on, and, if you pay, the customer ID Stripe gives us. Card numbers go to Stripe and never touch our servers.
- Feedback you send us — if you use the feedback link, the message you write and the email address on your account, so we can read it and reply. Kept while it is useful, then deleted.
- Which door you came in by — if you arrived from a link we tagged or from another website or app, a short label for it is stored on your account, so we know which doors families actually come through. For another website that label is its main domain only (for example “google.com” or “reddit.com”) — never the page you were on, never what you searched for; for an Android app it is the name Android gives the app (for example “com.google.android.gm”). For one of our own tagged links it is the tag, which names the link and, if another family shared their channel lineup with you, which shared lineup it was. The label waits in your own browser until you sign up or sign in; it travels with that request, and it is kept on your account only if that request creates a new account — otherwise it is deleted along with the sign-in link. Nothing is loaded from anyone to learn it.
- A second parent, if you invite one — the email address you type, so we can send the invitation and show you that it is pending. If they accept, they have their own sign-in record (their address, and a password hash if they set one) and are a parent on your account from then on. If they never accept, the invitation expires and the address goes with it. Cancel it any time and it is deleted at once.
- A sitter code, while one is live — a random 8-character code, when you created it, when it expires, and which of you made it. Nothing about the sitter is stored: they type the code, they never make an account, and we do not learn who they are. Ending it deletes the code immediately.
- Devices and the waitlist — the name you give each screen you pair and when you paired it, and the most recent day each screen was used, which your dashboard shows you, and, if you try to join while signups are paused, your email address and when you asked, so we can let you in later. Email us any time to be taken off the waitlist.
What we collect about your child
Everything below is entered by you, or triggered by your child pressing play or tapping an "ask a grown-up" topic. It is stored under your account, not under an account of the child's.
- Profile — a first name or nickname and an emoji avatar, both chosen by you.
- Watch history for that profile — the video ID, video title, channel name, a timestamp, and how many seconds were watched today.
- An age, if you choose to give one — a single number from 1 to 17, or nothing at all. The default is "Rather not say", nothing guesses or assumes it, and you can put it back to "Rather not say" at any time. It exists so channel suggestions can aim at the right age instead of guessing, it is used for nothing else, and it is an age, never a birth date. It is never sent to your child's screen — we test for exactly that.
- "Ask a grown-up" requests — your child's screen shows a small set of fixed topics ("Space", "Nature & Animals", "Art & Making"…). If your child taps one, we store which topic, which profile asked, and when, so it can appear on your dashboard. There is nothing to type; the topics are the whole vocabulary.
- Settings you set for the profile — the daily time limit, the bedtime window, any videos you block, any channels you have told us to skip when one video rolls into the next, whether you have paused the screen (including a pause you have set to begin when this video ends), and whether you have turned history recording off.
- A pairing token on the child's device — a random code stored on the TV or tablet (and in a cookie that can last up to 400 days) so the screen stays paired to your account. So you can tell a connected screen from a dead one, we also keep, on that same pairing record, the most recent day the screen checked in — a date, never a time of day — along with whether it used its stored code or its cookie to do so, and which version of our app it was running. You see the same date on your dashboard next to each screen (“used today”); it says nothing about what was watched, and it is deleted the moment you unpair the screen. The token itself identifies the device to us so the screen stays paired, and for nothing else — no advertising, no profiling, no sharing. The device also keeps its own local copy of the profile name and recent videos so it works smoothly; that copy stays on the device, and unpairing the screen makes its token useless immediately.
That is the complete list of what we hold about your child. We do not collect a child's email address, photos, voice, location, contacts, birth date, screen name, or any free-text the child types — the child's screen has nothing to type into. One housekeeping note, so the list above stays complete: like any server, ours sees the internet (IP) address of every device that connects, and requests from each address are counted to slow down abuse. That counting now happens in the hosting network's memory rather than in our database, so we no longer write the address or the count down ourselves, and the count is never linked to an account, a profile, or a child. One thing derived from the address we do keep: when you create an account we store the country it was made from, so we know which countries Glurpa is being used in. That is a country name, never the address itself, and it sits on your account, not your child's profile.
Why we collect it
The profile exists so a household with more than one child keeps their approved channels and their place in a video separate. The watch history exists so you can see what your child watched, so a video resumes where it stopped, and so daily screen-time limits can count down. The settings exist to enforce the rules you chose, the optional age exists to aim channel suggestions, the ask-a-grown-up requests exist to reach your dashboard, and the pairing token exists to keep the screen paired, together with a note of the most recent day each screen was used, so you — and we — can tell a connected screen from one that has silently stopped. Beyond that, the only other use is the aggregate counting described below, which is not linked to your child.
What the child's screen does not have
No advertising of any kind, no behavioral or targeted advertising, no advertising trackers, no tracking pixels, no externally hosted fonts, no social buttons. The one outside script that does run there is Cloudflare’s bot protection, described under Cloudflare below: a security check on the connection, not advertising. We do not sell, rent, or trade any personal information about a parent or a child, and we never use a child's information to build a profile for advertising. We currently run no analytics of any kind beyond what this page describes: the “which door” label on a parent’s account above, and the counts and screen reports under “Aggregate statistics” and “Error reports” below. If we ever measure page
visits, it will be a cookieless, identifier-free count on our parent-facing pages only — never on
a child's screen — and this policy will say so before it happens.
Third parties who receive data, and what each one gets
- Google / YouTube — video playback is YouTube's own embedded player. By default we load it from
youtube-nocookie.com, YouTube's privacy-enhanced mode, which limits the identifiers Google sets. Even so, playing a video means your device contacts Google, and Google receives the video requested, your IP address, and device information under Google's privacy policy. Premium mode: if — and only if — you turn on Premium mode, playback switches to youtube.com and the household's signed-in Google account is used, so Google can collect persistent identifiers tied to that account and associate viewing with it. Premium mode is off unless you separately consent to it; we ask for that consent on its own, not bundled with anything else, and you can turn it off at any time in parent settings.
- Anthropic — can power the “Glurpa Score” channel rating. That feature is switched off today, so Anthropic receives nothing from us. If we switch it on, it will receive only public information: the name of a YouTube channel and the public titles of that channel's recent videos, taken from the channel's public feed. It never receives your child's name, profile, watch history, or anything else about your family.
- Stripe — payment processing. Receives the parent's email and payment details when you subscribe. Nothing about a child is ever sent to Stripe.
- Resend — sends our sign-in and account emails. Receives the parent's email address and the content of those emails. Nothing about a child is ever sent to Resend.
- Cloudflare — hosts the site and the database where the above records are stored, so it holds the data on our behalf under contract and does not use it for its own purposes. Cloudflare also holds our aggregate counters (described below) and short-lived operational server logs. Cloudflare’s bot protection is also switched on for Glurpa: Cloudflare adds a small script of its own to every page we serve, including your child’s screen. It gathers signals about the browser and the device so Cloudflare can tell a person from an automated program, and requests it judges automated can be challenged or blocked before they reach Glurpa. Cloudflare says it can record the result in two security cookies,
__cf_bm and cf_clearance — see Cloudflare’s own description of them. It is there for security. We never receive the signals it gathers; we can see Cloudflare’s log of requests it challenged or blocked (time, page, country, browser type).
We do not disclose personal information to anyone else, except where the law requires it or to protect a child's safety.
Where your data lives, and how it gets there
Glurpa’s database is run for us by Cloudflare, a United States company, in its western North America region, and our email goes out through Resend, also a United States company. So whatever country you live in, our database and email records are stored in North America and handled by United States companies under United States law. When your device connects, the request is first answered at whichever Cloudflare data centre is nearest to you, which may be in your own country, and from there it reads and writes that database. Each company that processes data for us — Cloudflare and Resend today, and Anthropic if the Glurpa Score is ever switched on — does so under a written data-processing agreement that limits it to handling the data on our instructions and requires it to keep the data secure, including the European standard contractual clauses where those apply. Google and Microsoft are different: when you choose “Continue with Google” or “Continue with Microsoft”, and when a video plays in YouTube’s player, those companies handle your data under their own privacy policies, not under a contract with us. If the law where you live gives you rights about data leaving your country, this paragraph is the notice that it does.
Who else can reach your child’s screen
Two features hand real access to somebody who is not you. Both are yours to grant, both are yours to end, and neither happens unless you do it.
- A second parent. You can invite one other parent or guardian. They sign in as themselves, and from then on they see and can change everything you can on this account: the profiles, the channels, the screens, the controls, and your child’s watch history. That is the point of it — it is one family’s account, not two — but it means a second adult holds the same view of your child that you do. Either of you can end the link at any time from parent settings, and we email the other when it happens. Ending it changes nothing on a child’s screen.
- A sitter code. You can create an 8-character code that lasts 12 hours and hand it to a babysitter or a grandparent. Whoever types it can see each child’s first name and avatar and whether that child’s screen is paused, and can pause or unpause a screen. That is the whole of it. A sitter cannot see your child’s watch history, cannot change channels or time limits, cannot see your email address, and cannot see anything else about your account. The code is the credential, so anyone holding it has that access until it expires — end it from parent settings and it stops working on their very next tap.
Neither of these is a sale, a share with a company, or an advertising use. They are access you chose to give to a person, and we would rather write it down here than let you find out from someone else’s screen.
Aggregate statistics
We count how often a channel is added or watched across all accounts, so we can improve the curated library and spot channels that have drifted. These counts are keyed only by the public YouTube channel — they are not linked to any account, profile, or child, and cannot be traced back to one. We do not build a profile of a child, and we never share these counts in any form that could identify anyone.
Error reports
When a page breaks — a fault in our own code, or a video YouTube refuses to play — that screen tells us so, because otherwise a child would be left looking at a broken screen and nobody would know. These reports go only to Glurpa's own servers; no analytics company, advertiser, or other outside party is involved, and nothing is stored on the device to recognise it later; the only thing it keeps is a count of blocked requests waiting to be reported, erased once sent. A report is a fixed code and nothing else: which kind of screen it was (the parent's dashboard or a child's screen), which sort of fault occurred, and — for a fault in our own code — the line of our own program that failed, a location in code we wrote, not in anything your child watched or you typed. It also says which version of our program that screen was running, so we can tell which line the number refers to. It carries no name, no email, no profile, no video, and no error text — error messages can quote whatever was on screen, so we deliberately never send them.
The same screen also tells us which step of setting itself up it has reached — one of seven fixed words, such as “showing the install instructions”, “showing the pairing code” or “ready to watch” — because when a TV stops part-way through setup, nothing else records where it stopped. That is a fact about the screen, not about your child: it carries no name, no email, no pairing code, no address, and nothing typed or watched.
Where Glurpa is available
Glurpa is offered to families in the United States, Australia, New Zealand, Mexico, Israel and Indonesia. We do not accept new accounts from other countries, and we would rather turn a family away than take their data before we can meet the children's-privacy obligations that apply where they live. If you sign up from a country we do not serve, we do not store your email address at all. Existing families keep working normally while travelling.
Your rights as a parent
COPPA gives you these rights, and the app gives you buttons for them:
- Review — see everything we hold about your child: open the History tab and read the watch history — free, on every plan — or email us and we will send you the full record.
- Delete — clear a profile's watch history with one button, delete the profile, or delete the whole account. Deleting a profile deletes that child's history and watch-time records with it, and account deletion wipes every record we hold about you and your children immediately. To be precise about the history button: clearing history deletes the viewing record, but it does not reset today's screen-time minutes — the day's count is a parental control, and clearing history must not become a way around a time limit.
- Refuse further collection — every profile has a "Stop recording" switch, free on every plan: turn it on and we record nothing further about what that child watches, while the profile, the channels, and playback all keep working. To be precise about what stops: with recording off there is nothing to resume from and the daily time limit has nothing to count, so both stop for that profile — but bedtime still works, because it needs only the clock. Deleting the profile also ends collection, and takes the existing records with it.
- Withdraw consent — turning Premium mode off, or deleting the account, withdraws the consent you gave.
We will never require a child to disclose more information than is reasonably necessary to watch a video.
How long we keep things
- Per-profile watch history is automatically deleted 90 days after it is recorded.
- Watch-time counters reset daily.
- Everything is deleted immediately when you delete the profile or the account.
- Ask-a-grown-up requests are kept until you clear them from your dashboard, at most 20 at a time.
- The optional age and the profile's settings last exactly as long as the profile.
- The pairing token lasts until you unpair the screen; unpairing makes it useless immediately, even if the device still remembers it. The note of the most recent day a screen was used lives on that pairing record and is deleted with it.
- Sign-in tokens expire after 15 minutes, pairing codes after 30 minutes, and sessions after 90 days.
We keep a child's information only as long as it is needed for the purpose it was collected for, and we do not keep it indefinitely.
Security
Traffic is encrypted in transit, passwords are stored only as PBKDF2 hashes, and access to the database is limited to the operator. No system is perfect; we will tell affected parents by email if we ever learn that account data was exposed, and we will notify the privacy regulator where the law where you live requires it (for example as soon as practicable in Australia and New Zealand). We keep a written record of every security incident, whether or not it had to be reported.
Changes
If we ever change what we collect about a child, what we do with it, or who receives it, we will email the parent and get consent again where the law requires it before the change applies.
Contact
Email hello@glurpa.com for any privacy question, to review or delete your child's information, or to withdraw consent.
This page is information about our practices, not legal advice. Last updated: 2026-09-26.