1. Scope and who operates GroupLock
This Privacy Policy applies to the GroupLock website, mobile applications, messaging features, Family features, Organization features, and related support services. “GroupLock,” “we,” “us,” and “our” refer to the GroupLock service and the developer or legal entity identified as the publisher in the applicable app-store or product listing.
If you have a privacy or data request, use our Support & Privacy Request form.
2. Information we collect
Account and identity data
We process your email address, display name, optional phone number and bio, account role, email-verification status, legal-policy acceptance records, and account creation information. GroupLock does not currently accept arbitrary external profile-image URLs; first-party avatar uploads may be added later with privacy controls.
Authentication and security data
Password accounts store a one-way password hash rather than the plain-text password. GroupLock also processes sessions, password-reset and email-verification tokens, login-attempt records, and Google or Microsoft account identifiers when you choose those sign-in methods.
Communication and consent data
We process circles and their names/descriptions, invitations, inviter and invitee relationships, proposed and accepted membership, Accept/Decline states, messages, message timestamps, read/typing state, attachments, mute/archive preferences, and privacy-rule outcomes needed to deliver consent-based messaging.
People and privacy controls
We process contacts you add to GroupLock, trusted and blocked people, Safe Circles, invite rules, spam-filter preferences, reports, and other privacy settings you configure. People discovery is intentionally limited: partial-email/domain enumeration is not supported, displayed email addresses are masked, and Invisible Mode users are excluded from discovery unless they have chosen to include the viewer in their contacts.
Family and Organization data
For Family features, we process plan ownership, membership invitations, accepted members, pending consent, roles, and Family settings. Guardian Protection may also process a family-approved child display name or nickname, broad age band, guardian relationship, guardian-verification status, private invite-code hash and hint, circle requests, guardian decisions, restricted consent receipts, revocations, notification-delivery records, activity-summary counts, participant-disclosure decisions, and child-safety audit events. To start the k-ID age gate, the guardian enters the child’s exact birth date; GroupLock sends that value directly to k-ID for the request and does not persist it in GroupLock’s database. For Organizations, we process organization identity, teams/departments, roles, membership invitations, organization circles, policy settings, and administrative audit records.
Billing data
For web subscriptions, Stripe processes payment details. GroupLock stores billing identifiers and subscription status such as Stripe customer, checkout, and subscription identifiers, plan type, and current billing period. GroupLock does not need to store your full payment-card number. Native iOS/Android store purchases will use the applicable platform-approved billing flow when that purchase path is enabled.
Push, files, and support
When you enable notifications, we store the device/browser push subscription needed to deliver alerts. Uploaded files are stored in GroupLock’s configured cloud object storage. Message attachments are delivered through GroupLock access checks tied to conversation membership. The production storage bucket must also be configured without direct public-read access so the application authorization layer cannot be bypassed with a raw object URL. If you contact support, we process the email address, category, message, status, and timestamps needed to handle the request.
3. How we use information
- Authenticate accounts, verify email ownership, and secure sessions.
- Show invitations before access and enforce Accept/Decline decisions.
- Deliver messages, attachments, notifications, Family/Organization features, and requested account settings.
- Apply blocking, trusted contacts, contacts-only rules, anti-spam settings, and other privacy choices.
- Process subscriptions, maintain entitlement state, and prevent overlapping or unauthorized billing.
- Investigate safety reports, abuse, spam, unauthorized access, or technical problems.
- Comply with applicable legal obligations and enforce GroupLock’s Terms.
4. Consent decisions and visibility
GroupLock is designed so an invitation is not the same as membership. A pending invite may show the group creator, purpose, and proposed participants so you can make an informed decision. You do not receive active conversation access until you accept.
Blocking is intentionally treated as a private safety choice. Where technically supported, GroupLock avoids creating a visible decline record merely because the inviter is blocked.
Guardian activity summaries show operational counts—such as recent message, file, report, participant, and administrator counts—without exposing message text or attachment contents. Optional guardian-visible transcript access is a separate, disclosed feature. It activates only after every current participant affirmatively agrees, covers future messages only, displays a persistent notice inside the circle, and ends after a participant or guardian revokes it, a material change occurs, the related guardian authorization ends, or the Family entitlement becomes inactive.
5. Messages are not currently represented as end-to-end encrypted
Important: GroupLock does not currently claim that chat content is end-to-end encrypted. The service and infrastructure providers must be able to process message and file data as necessary to store, transmit, secure, moderate, troubleshoot, and operate the service.
Use appropriate judgment before sharing highly sensitive information. If GroupLock later introduces a different encryption model, this policy and the product disclosures will be updated before that model is represented to users.
6. Service providers and data disclosures
We use service providers to operate GroupLock. Depending on the feature you use, these may include Floot-managed application, database, authentication, push, and transactional-email infrastructure, Cloudflare R2-compatible object storage for uploaded media, Stripe for web billing, Google or Microsoft for optional identity-provider sign-in, and k-ID for jurisdiction-aware age gating, trusted-adult verification, Family Connect consent, and permission management.
We may also disclose information when reasonably necessary to protect users or the service, investigate abuse, comply with valid legal process, or complete a business transaction subject to appropriate protections.
GroupLock does not currently use third-party advertising networks or sell personal information for advertising.
7. Retention and deletion
We generally keep account and service data while your account remains active and as needed to provide the feature for which it was collected. Some temporary security records and tokens expire automatically.
You can initiate permanent account deletion in Settings → Delete account. The deletion process is designed to cancel GroupLock-managed Stripe billing where applicable, remove the user’s uploaded-media prefix, remove authentication links, and delete/cascade associated GroupLock account records. If required external cleanup cannot be confirmed, GroupLock stops the destructive deletion rather than knowingly leave active billing or orphaned media.
Some safety records created by other people may remain in de-identified or structurally necessary form after your account is deleted—for example, a report about a deleted account may remain while the direct user reference is removed. We may also retain information when required by applicable law or necessary to establish, exercise, or defend legal claims.
A guardian can use the Child Data Center to review the GroupLock data held for a managed child, correct the nickname or age band, download a child-specific JSON export, and permanently delete that child’s GroupLock profile without deleting the adult account. The export includes the child’s own retained messages and attachment metadata but excludes other participants’ private message content. If k-ID provider-side deletion, media cleanup, or another required external deletion cannot be confirmed, GroupLock stops the destructive profile deletion and keeps child access revoked so the guardian can retry safely.
For an external browser-accessible deletion path, visit Account Deletion.
8. Your controls
- Accept or decline each group, Family, and Organization invitation addressed to you.
- Manage trusted/blocked people, contacts-only invites, auto-decline, visibility, anti-spam, and other available privacy settings.
- Enable or disable push notifications through device/browser controls and GroupLock settings.
- Update profile information and leave groups or Family memberships where supported.
- Manage web subscription billing through the Stripe billing portal when the subscription is Stripe-backed.
- Delete your account and associated data through GroupLock settings.
- For a guardian-managed child profile, review or decline every circle request, rotate the private invite code, revoke an approved circle, review the Child Data Center, correct the minimal profile, download a child-specific export, archive the profile, and permanently delete that child’s GroupLock data subject to a documented legal or active-safety hold.
Depending on where you live, applicable law may provide additional access, correction, deletion, portability, objection, or appeal rights. Submit a privacy request to exercise a right that is not already available in the product.
9. Security
GroupLock uses technical and organizational controls appropriate to the service, including account sessions, email verification, password hashing, permission checks, signed webhook verification, server-side entitlement checks, and access-control rules. No system can guarantee absolute security, and users should protect their credentials and devices.
10. Children and minors
GroupLock’s general direct-to-consumer account flow is intended for users age 13 and older. We do not enable independent accounts for children under 13 through the general account flow.
Guardian Protection is a separate, guardian-controlled workflow. The initial release creates a non-discoverable managed profile with a nickname and age band, routes circle requests to the guardian, and keeps the child from independent login or direct-contact features. The profile is not added to a circle until the guardian approves a scoped, restricted authorization. Material changes suspend that authorization for review. Critical requests and security changes may be delivered by in-app alert, privacy-preserving push, and account-email backup according to guardian settings.
GroupLock’s internal pilot attestation is not represented as legally sufficient verifiable parental consent for production. The production adapter uses k-ID Family Connect to identify a trusted adult and record the specific supervised-child permissions approved for the child. Production child access remains blocked until the live provider configuration, required direct notice and consent process, privacy review, safety controls, retention rules, physical-device evidence, and applicable app-store disclosures are complete. See the Guardian Direct Notice.
Schools or other organizations must not deploy GroupLock for children under 13 until GroupLock expressly enables a documented child-specific organization/school process appropriate to that deployment. GroupLock does not claim that the general account flow or internal pilot satisfies COPPA, FERPA, or every school/student privacy requirement.
If you believe a child under 13 created an account through the general flow, submit a privacy request.
11. International processing
GroupLock and its service providers may process information in locations different from where you live. Where applicable law requires protections for cross-border data transfers, the responsible parties will use legally recognized safeguards appropriate to the transfer.
12. Changes to this policy
We may update this policy as GroupLock changes. The version date appears at the top of this page. If a change is material enough to require renewed agreement or acknowledgment, GroupLock’s versioned legal-consent system can require signed-in users to review the updated documents before continuing to protected features.
13. Contact
For privacy, deletion, billing, or safety questions, submit a request through GroupLock Support. The publisher/developer identity for the commercial release will also be identified in the applicable app-store or product listing.
Supervised children and qualified parental consent
GroupLock’s ordinary account flow remains limited to people age 13 or older. Under-13 access, where enabled after the production launch gates are complete, is available only through a verified guardian-managed profile and a separately approved device. GroupLock uses k-ID Family Connect for jurisdiction-aware age gating, trusted-adult verification, child-specific consent, and permission management.
The guardian enters the child’s exact birth date to begin the age gate. GroupLock transmits that value directly to k-ID and does not persist it. k-ID may collect identity, age, and trusted-adult evidence directly under its own privacy notice. GroupLock receives and stores provider session status, jurisdiction, age category, approved permission names, timestamps, permission snapshots, and opaque or one-way provider references. GroupLock does not store k-ID’s raw identity file, government-identification image, exact child birth date, or complete provider webhook payload.
Child profile and supervised-device data
A managed child profile contains a guardian-approved nickname, an age band, the guardian relationship, privacy and retention settings, child-specific consent status, circle receipts, and safety/audit records. It does not include an independent child email login, password, public profile, contact-search listing, direct contact fields, billing relationship, advertising identifier, or precise-location collection.
Supervised-device records contain opaque hashes of device and session identifiers, platform and app version, device label supplied during pairing, guardian and child-profile associations, creation and last-access times, expiration, and revocation state. Session tokens are random, sent in a Secure HttpOnly SameSite cookie, and stored only as server-side hashes.
Child messages, moderation, and reports
The initial child interface shows only messages created after the guardian approved that circle. It hides attachments and disables child uploads and active external links. GroupLock checks child and adult outbound messages in a supervised-child circle for configured risks such as private information, unsafe secrecy or grooming, sexual solicitation, threats, self-harm language, drugs or weapons, bullying, and unsafe links.
When a message is blocked, it is not delivered. The safety event stores a cryptographic content hash, finding codes, actor and circle references, timestamps, and a high-level summary rather than the blocked raw message. A child report stores the selected category, optional description, related message/circle identifiers where supplied, severity, notification state, and resolution history.
Guardian and school safety notifications
The guardian receives child-safety, consent, device, billing, expiration, and material-change alerts through enabled in-app, push, and email channels. Push and email text is minimized so child names, school names, message text, and detailed allegation content are not unnecessarily exposed on a lock screen or inbox preview.
For a separately authorized school circle, a high or critical child-safety event may notify verified school safety administrators or counselors. General organization administration does not automatically receive message content. Any content review must be authorized and logged under the relevant safety workflow.
Children’s retention and deletion schedule
Default supervised-child retention is 90 days for child-scope messages, 30 days for child-scope attachments, 180 days for resolved child reports, 365 days for resolved child-safety events, 365 days for provider event hashes, and 1,095 days for consent and audit records. Pairing requests expire after approximately 15 minutes, and device sessions expire after no more than 30 days and never later than the applicable provider grant.
An automated cleanup job removes eligible records and private objects and records the result. A documented legal or active-safety hold may pause deletion only for the affected child profile. The guardian can revoke a device, child-specific provider grant, school relationship, or circle authorization, archive the child profile, and use GroupLock’s deletion controls.
Verified schools and education organizations
The separate school workflow stores a verified school profile, legal and district/network names, region, privacy and safety contacts, school-year dates, data-protection-agreement status, staff safety roles, guardian requests, optional hashed internal student reference, signed school-relationship receipt, circle requests, and safety audit records.
GroupLock initially supports only direct guardian authorization. School approval does not grant circle membership. Each classroom or school circle requires a separate guardian decision and signed receipt. School identity or staff authority does not override guardian consent, child device controls, message access boundaries, or revocation.
Store disclosures, testing, and production controls
GroupLock maintains platform-specific child-audience disclosure packages and a physical iPhone and Android test ledger. These records support accurate App Store and Google Play submissions but do not replace the live questionnaires, SDK review, physical test execution, independent legal review, independent security review, or store approval.
Production child access remains remotely disabled until every required launch component is ready. Administrator-only test profiles must use fictional information and synthetic messages and are clearly marked pilot-only.
Production parental verification
When production Guardian Protection is enabled, GroupLock redirects the adult to a contracted hosted parental-verification provider. GroupLock does not intentionally retain the provider’s identity documents, full payment-card information, or knowledge-based answers. GroupLock retains a minimized record of the provider, verification method, result, country, timestamps, hashed provider/session references, and cryptographic evidence needed to enforce and document the guardian authorization.
Failed or cancelled verification sessions are scheduled for deletion after 30 days. Minimized successful verification evidence is scheduled for deletion or further minimization after 730 days, subject to applicable law, fraud, dispute, incident, or legal-hold requirements.
Supervised child devices and safety processing
A production-verified guardian may pair a supervised child device using a short-lived, single-use code. GroupLock processes a pseudonymous device identifier, platform, guardian-managed device name, pairing/session timestamps, expiration, safety-orientation acknowledgement, and revocation status. This does not create a public independent child account.
In guardian-approved child circles, GroupLock may analyze message text before delivery for age-appropriate safety categories such as private contact or location sharing, grooming and secrecy, sexual content, threats, bullying, unsafe links, and self-harm signals. GroupLock records a message hash, category, severity, decision, and rule version rather than copying blocked message text into the moderation log. High-risk events may create a guardian-visible safety incident and a human-review case. A child asking for help about self-harm is not intentionally silenced; the message may be delivered with crisis guidance and urgent escalation to trusted adults.
Child Data Center and retention enforcement
A verified guardian can review a child-data inventory, download a structured copy, correct the child’s nickname or age band, stop further collection, revoke devices and authorizations, or permanently delete the managed child profile. Stopping collection immediately pauses the profile and schedules deletion after a 30-day recovery period. GroupLock runs automated retention enforcement for expired sessions, pairing codes, verification records, closed requests, moderation signals, and child-safety incidents.
Organization and school child programs
Organizations may use the separate child-program workflow only after documenting a specific program purpose, age range, privacy role, retention, safety contact, incident response, mandatory-reporting procedure, current agreements, qualified staff, and GroupLock administrative approval. Organization or school authority does not replace the guardian. Program enrollment and each linked circle require separate guardian decisions and signed receipts.
