This Privacy Policy explains how Rostan Technologies Pvt. Ltd. (“OurShield”, “we”, “us”) processes personal data of parents and children who use the OurShield parental control platform. OurShield acts as a Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). You, the parent, are the Data Principal and also the verifiable lawful guardian of your child’s data.
1. Notice and lawful basis
We process personal data on the basis of your explicit consent given at sign-up and, where applicable, legitimate uses specified in §7 of the DPDP Act (including service provision, fraud prevention, and compliance with Indian law). You may review or withdraw consent at any time from Settings → Account in the parent app.
2. Categories of personal data we collect
- Parent account data: email address, hashed password (Argon2id), authentication tokens, IP address of sign-in, device user-agent.
- Child profile data: first name (or nickname), date of birth, avatar image chosen by the parent.
- Device identifiers: device install ID, OS version, FCM push token (for parent notifications only).
- DNS query summaries: aggregated category counts (e.g. “social: 12, gaming: 3”). We do not store full URLs or page content.
- Approximate location: only when you explicitly enable Real-Time Location; stored as latitude/longitude rounded to 3 decimal places.
3. Purposes of processing
Personal data is processed only for: (a) delivering the OurShield service to your family, (b) issuing safety alerts to you, (c) aggregated product analytics (fully de-identified), (d) billing through Razorpay, and (e) responding to lawful orders of Indian authorities under the DPDP Act and applicable criminal procedure.
4. AI content-safety monitoring (optional, per child)
If you separately opt in for a specific child, OurShield’s AI reviews on-screen message content in supported messaging and social apps for safety-relevant patterns — bullying, self-harm risk, grooming, hate speech, and explicit content. This monitoring is off by default and requires your explicit, per-child consent in addition to the account-level consent described in §1; you can turn it on or off at any time from that child’s settings. When it is off, no message content is ever sent to our AI processor or stored.
When it is on: message text is sent to our AI processor (see §6, Sharing) for classification only. We do not store the raw message, and we never quote or show you the underlying text — you receive a signal category (e.g. “possible bullying signal”) and a timestamp, by design. If a possible self-harm signal is detected, that alert also includes verified crisis-helpline numbers so you have somewhere to turn immediately.
5. Retention windows
- Raw activity events — 90 days (partitioned, auto-dropped).
- Daily aggregates — 365 days.
- Location pings — 90 days by default (parent-adjustable).
- AI content-safety alerts (§4) — 30 days; only the category and timestamp are retained, never the source message.
- Audit logs — 24 hours hot, 365 days cold for compliance.
- Deleted accounts — 30-day grace period, then cryptographic erasure.
6. Sharing and cross-border transfers
We do not sell personal data. Processors used: Razorpay (payments), Cloudflare (WAF + CDN, EU/US edge), AWS ap-south-1 (primary storage, Mumbai), Anthropic (Claude API, US) — prompts, including the optional content-safety scanning in §4, are tokenized and stripped of PII before transmission per our AI-01 rule. Cross-border transfers comply with §16 of the DPDP Act.
7. Your rights as Data Principal (incl. data deletion)
You may (a) access a machine-readable export of your family’s data, (b) request correction, (c) request erasure, (d) nominate a person to act on your behalf in the event of death or incapacity, and (e) file a grievance. Points (a) and (c) are self-service at /settings/account.
Account & data deletion: you can delete your account and your family’s associated data yourself, in-app, at Settings → Account (web: /settings/account), or by emailing privacy@shieldapp.rstglobal.in. On deletion we apply a 30-day grace period (during which you can cancel the request) and then perform cryptographic erasure, as described in §4 above.
8. Grievance Officer
Grievance Officer: Virender Kumar, grievance@shieldapp.rstglobal.in, Emaar The Palm Square, Unit No. # 09, 2nd Floor, Emaar MGF, Golf Course Ext Rd, Sector 66, Gurugram, Haryana 122002, India. Response SLA: 30 days per DPDP §13.
9. Contact
You may contact us about this policy at: privacy@shieldapp.rstglobal.in.