Privacy Policy
The full policy, in plain words.
Last updated: August 23, 2026
Our commitment
Pedium is built on the belief that parental visibility and children's privacy are not mutually exclusive. This policy explains how we collect, process, and protect data for every member of your family.
What we collect
Pedium only collects data for features a parent has enabled. When a parent sets up a child's device they choose what to include, and everything except app usage and web visits starts off. Those two are the baseline the product exists for, and they are shown and confirmed during setup rather than assumed. Nothing else is collected until someone deliberately turns it on. The categories are:
- App usage: which apps are used and for how long
- Web visits: sites visited, with AI-generated summaries
- Search queries: search terms, redacted of PII
- Typed text context: contextual hints, PII redacted, never raw keystrokes
- Location: GPS coordinates (optional, schedule-aware)
What an iPhone or iPad can actually collect
That list is what Pedium supports across every kind of device it runs on. No single device does all of it, and we would rather tell you the limits than let you assume otherwise.
On an iPhone or iPad, only three of them are possible: app usage, web visits, and location. Apple gives an app like ours no way to read search terms or typed text in the background, so those two are not offered on an iOS device and could not be collected there even if they were. A toggle that reads "on" while nothing is collected would be worse than not having the feature, so we do not show one.
Web visits on iOS are also narrower than the word suggests. Pedium sees the domain your child's device looked up ("example.com"), not the specific page, because the only thing available to us is the name resolution, not the browsing. Our summaries for an iOS device therefore describe the site's home page, not the page that was actually read, and we cannot see anything inside an app that talks to its own servers. For the same reason, iOS web visits carry no duration: a name lookup is an instant, not a session.
Names you choose to give us
Separately from the activity above, a parent may type a name for a device, a first name for the child or children who use it, and the name those children call them (for example "Dad"). They exist so a parent can tell their devices apart, and so that when Pedium speaks to a child it uses a name that child recognizes.
A device name usually contains a person's name too. Devices are commonly called things like "Emma's iPhone", and a phone often reports its own name that way before anyone types anything. So although it reads like a label for a piece of hardware, a device name is personal information in the same way the others are, and we treat it the same. If you would rather not have a name in there, call the device something else. It is only ever used to help you tell your devices apart, so "Upstairs iPad" works exactly as well.
All of these names, device, child, and what a child calls a parent, are stored as typed and are not redacted, because a redacted name cannot do the job it exists for. That is a deliberate exception to the redaction described below, which applies to activity content. They are never sent to an AI model, never written to our logs, and never placed in a notification that could appear on a locked screen.
Naming the people who share a device does not tell us who did what. Activity is recorded for a device, and nothing in Pedium can attribute it to one person among several who use that device.
Blocked sites, and what your child can write back
A parent can choose to block specific sites on a child's device. The list starts empty, so nothing is blocked until a parent adds a site, and it is only ever sites the parent typed themselves. Pedium never adds one, and our safety classifier never blocks anything on its own. We store the domain, the reason the parent wrote (if any), which parent added it, and when.
Your child sees that list. Every blocked site is shown to them on their own device, along with who blocked it and why, because a restriction a child cannot see is one they cannot talk to you about.
They can also write back. A child can ask for a site to be unblocked and leave a short note saying why. That note is text your child wrote, so we store it as typed and show it to the parent who set the block. It is not redacted, is never sent to an AI model, and is never placed in a notification that could appear on a locked screen. Answering it, whether by keeping the block or removing it, is the parent's decision, and we record which they chose.
How we protect data
- PII redaction: names, emails, phone numbers and similar details are stripped out of activity content. Where a device can do that itself it does, and where it cannot, the raw text is sent to us over an encrypted connection, redacted the moment it arrives, and the redacted version is what gets stored. We would rather say that plainly than imply nothing raw ever crosses the network.
- Encryption: everything is encrypted in transit (HTTPS, TLS 1.2 or 1.3) and at rest by our database provider. The most sensitive fields get a second layer we apply ourselves, using libsodium's authenticated encryption (XSalsa20-Poly1305), so they are unreadable even with database access.
- Short retention: raw activity content is deleted after 24 hours. The record of which sites were visited is kept for 7 days, and AI-generated summaries for 30 days, both by default. Nothing is kept indefinitely.
- Consent-first: nothing is collected unless a parent turns it on, and children can see everything that is active at any time.
Consent and transparency
Pedium requires explicit consent for every data-collection feature. Parents configure which features are active and can set time-based schedules (for example, only during school hours). Children always have a "What Pedium Sees" view showing exactly what is being tracked.
Data subject rights
You can access, export, correct, or delete your family's data at any time. A deletion request is scheduled, not immediate: we hold it for 30 days so that an account cannot be wiped by accident or by someone else in the family, you can cancel it during that window, and after it the data is removed. If you would rather it happened sooner than that, write to us and we will do it. We support:
- Right to access: view all stored data via the dashboard
- Right to export: download your data in a machine-readable format
- Right to deletion: request complete removal of all data
- Right to rectification: correct any inaccurate information
Regulatory compliance
Pedium is built to the principles behind the laws below, and the specific things we do about each are these:
- GDPR: data minimization (only app usage and web visits are on at setup, everything else off until enabled, short retention), the right to access and export your data from the dashboard, and the right to erasure described above. Privacy questions and data requests go to a real person at [email protected].
- CCPA/CPRA: we do not sell or share personal information, and there is nothing to opt out of, because there is no sale. Access and deletion work as above.
- COPPA: a parent creates the account, sets up the device, and turns on each kind of collection individually; a child cannot enroll themselves or widen what is collected. Collection is limited to what the parent enabled, and a parent can see, export and delete all of it. We do not use children's data for advertising or sell it, and we run no ad or analytics SDKs in the apps at all.
Pedium is a small independent product. We describe what we actually do rather than claiming a certification we do not hold; if you need something specific for your own compliance, ask us and we will answer honestly.
Third-party services
Pedium uses a third-party AI provider to generate summaries and to judge whether a page looks unsuitable. What we send it is: redacted activity content (app names, site domains, already-redacted search terms) and, when summarizing a site, the text of that public web page as fetched from our own servers.
What we never send it: your name, your child's name, what your child calls you, the device's name, your email, or any account identifier. Those are excluded by design: the code that builds these requests has no way to reach them.
We do not sell, share, or monetize your data, and the apps contain no advertising or analytics SDKs. On iOS the only outside code in the app is Apple's own frameworks.
Contact
For privacy questions, data requests, or concerns, contact [email protected].