Summary
BackToLife Parents is a companion app that lets a parent or legal guardian manage how their child uses social media through the BackToLife app installed on the child's device. Because this service involves processing data about children, we apply enhanced protections and full transparency.
Key points:
- Built for parents, about children: The parent is our user; the child's data is processed only so the parent can supervise their child's social media use
- Minimal child data: A nickname chosen by the parent, app usage time, device battery level, and BackToLife in-app activity — nothing else
- Screen time data is never monetized: We never sell, share, or use screen time or usage data for advertising or any commercial purpose other than providing the service itself
- No ads, no trackers: Neither the parent's nor the child's activity is monitored for advertising purposes
- Parental consent: All processing of the child's data is based on the consent and authority of the holder of parental responsibility
- Full GDPR compliance: Both parents' and children's rights are protected under EU data protection law, with special safeguards for minors
This Privacy Policy applies to the BackToLife Parents mobile application (iOS and Android) provided by ASOCIACIÓN JUNIOR EMPRESA SYNKRO, and complies with the EU General Data Protection Regulation (GDPR) and applicable national data protection laws, including Spanish Organic Law 3/2018 (LOPDGDD).
The main BackToLife app (used on the child's device) is covered by its own Privacy Policy at backtolife.site/privacy. This document governs the Parents app and the parent-child supervision features.
For questions about your data or your child's data, contact us at info@backtolife.site
Owner and Data Controller
ASOCIACIÓN JUNIOR EMPRESA SYNKRO
Plaza de San Martín, 1, Madrid, 28013 Madrid, Spain
VAT/Registration Number: ESG75285965
Data Controller contact: info@backtolife.site
Scope and Relationship With the BackToLife App
BackToLife Parents works together with the main BackToLife app:
- The parent or legal guardian installs BackToLife Parents on their own device and creates a parent account.
- The child uses the main BackToLife app on their own device, signed in to a BackToLife account. This may be the child's own account or an account created and managed by the parent. Any account on the child's device is governed by the BackToLife Privacy Policy; the supervision features described here are governed by this policy.
- Linking is established when the parent generates a linking code in BackToLife Parents and that code is entered in the BackToLife app on the child's device. The required permissions (including screen time permissions) are then requested and granted on the child's device.
Once linked, the parent can block or limit apps on the child's device, apply BackToLife's social media content filters to the child's use of Instagram and YouTube, and view usage information described below.
What Data We Collect
Parent Account Data
An account is required to use BackToLife Parents. When you create your account, we collect:
- Email address: To create your account, authenticate you, send you important app updates, and communicate with you about the service
- Name: To personalize your experience and communicate with you
- Authentication identifiers: Technical identifiers used to authenticate your account, managed through Firebase Authentication
- Push notification token: A device token (Firebase Cloud Messaging) used to deliver the notifications you enable
You cannot use BackToLife Parents without creating an account; providing your email and name is necessary to access the service.
Child Data (Supervised Device Data)
When you link your child's device, we process the following data about your child so that we can display it to you and apply your supervision settings:
- Nickname: A name for the child, chosen and entered by the parent. We do not ask the child for their name, age, date of birth, or any other identifying information.
- Device app usage time: Per-app usage totals from the linked device — which app was used, for how long, and on which day — together with the device's timezone, so the parent can view usage and apply app blocks or limits. We collect usage totals only: not message content, not browsing content, not keystrokes.
- Device battery level: The current battery level of the linked device
- BackToLife in-app activity: How much time the child has spent inside the BackToLife app and which social media platforms (e.g., Instagram, YouTube) they have accessed through it
- Supervision settings: The parental-control configuration you create — strict-schedule windows, per-network content filters, app blocks, and the child's link/passcode state
- Linking data: Technical identifiers necessary to associate the child's device with the parent's account
- BackToLife account data: Using BackToLife on the child's device requires a BackToLife account (email address and name, as described in the BackToLife Privacy Policy). Where this account belongs to the child, that email and name are personal data of the child, provided with the consent and involvement of the parent. Alternatively, the parent may create and use their own account on the child's device.
Important: Unlike the standalone BackToLife app, where usage statistics stay on the user's own device, the supervision features of BackToLife Parents require that the usage data listed above be transmitted from the child's device to our servers so that it can be shown to the linked parent. This data is transmitted encrypted, stored on our servers in the EU, and is accessible only to the linked parent account. It is never made available to anyone else.
Diagnostics Data
To keep the app stable and fix bugs, we collect crash and error reports through Firebase Crashlytics and Sentry. These reports may include: device model, operating system version, app version, technical stack traces, and recent in-app actions leading up to an error. Diagnostics data is used exclusively for debugging and reliability — never for advertising or profiling.
Data We Do NOT Collect
We explicitly do not collect and technically cannot collect:
- The child's real name, age, date of birth, or contact details (the nickname is chosen by the parent and may be anything)
- The child's browsing history, messages, chats, keystrokes, or the content they view within Instagram or YouTube — we collect usage totals only
- The child's or parent's contacts, photos, or other personal content
- Location data of either the parent or the child
- Biometric data
- Screenshots or recordings of the child's screen
- Any special categories of personal data (health, race, religion, politics, sexual orientation, etc.)
- Third-party product-analytics or advertising data — the App contains no advertising SDKs and no third-party product-analytics SDKs (no Mixpanel, Amplitude, Facebook SDK, or similar)
No Advertising Trackers
BackToLife Parents contains no advertising and no advertising trackers. Neither your activity nor your child's activity is monitored for advertising purposes. We do not engage in:
- Targeted advertising (to parents or to children)
- Profiling for advertising purposes
- Sale or sharing of personal data for advertising
- Cross-context behavioral advertising
Screen Time and Family Controls Data
On iOS, BackToLife uses Apple's Screen Time technologies (including the Family Controls and Device Activity frameworks) on the child's device to measure app usage and enforce the limits and blocks configured by the parent. On Android, equivalent usage access permissions are used for the same purposes.
We commit that screen time and app usage data collected through these features is:
- Used only to provide the parental supervision features described in this policy — displaying usage to the linked parent and enforcing the parent's settings
- Never sold to any third party
- Never used for advertising, marketing, or profiling of any kind
- Never shared with third parties, except with the service providers listed in this policy who host our infrastructure under strict Data Processing Agreements
- Never monetized in any way. Our revenue comes exclusively from the parent's subscription, not from data.
Legal Basis for Processing (GDPR Articles 6 and 8)
1. Contract Performance (Article 6(1)(b) GDPR) — Parent's Data
Processing the parent's email address and name is necessary to provide the BackToLife Parents service, including creating and maintaining the parent account, providing app functionality, and communicating about the account and subscription.
2. Parental Consent (Articles 6(1)(a) and 8 GDPR) — Child's Data
We process the child's data described above on the basis of the consent given by the holder of parental responsibility over the child. By linking a child's device, you confirm that:
- You are the parent or legal guardian of the child whose device you are linking, and you hold parental responsibility over them
- You consent to the processing of the child's data described in this policy for the purpose of parental supervision
- Where the child is old enough to understand, you have informed the child that their device usage will be visible to you (the BackToLife app on the child's device also makes the supervision visible to the child)
In Spain, the age of digital consent is 14 (Article 7 of Organic Law 3/2018). For children under that age, the consent of the holder of parental responsibility is required; for supervised users aged 14 and over, we still rely on the parental relationship and the transparency of the supervision on the child's own device.
You may withdraw this consent at any time by unlinking the child's device or deleting your account (see "Data Retention, Unlinking and Deletion" below).
3. Legitimate Interest (Article 6(1)(f) GDPR)
We process strictly necessary technical data (such as linking identifiers and service logs) based on our legitimate interest in maintaining a stable, secure and functional product, preventing fraud and misuse, and identifying and fixing bugs. We have assessed that this minimal processing does not override the rights and freedoms of parents or children.
4. Consent (Article 6(1)(a) GDPR) — Marketing
Where we send the parent marketing communications about app updates or new features beyond essential service communications, we will first obtain explicit consent, which can be withdrawn at any time. We never send marketing communications to children.
How Your Data is Stored
Parent account data and child supervision data are stored securely on our servers located in Europe (France). We implement the following security measures:
- Encryption in transit: All data transmitted to/from our servers — including usage data from the child's device — uses HTTPS encryption
- Encryption at rest: Data is encrypted using AES-256
- Access controls: Strict access controls limit who can access data. Child supervision data is accessible in the app only to the linked parent account.
How We Use Your Data
Parent Account Data
We use the parent's email address and name to:
- Create and maintain the parent account and authenticate logins
- Send essential service communications (e.g., security alerts, critical updates)
- Send optional updates about new features (with consent)
- Manage the subscription and respond to support requests
- Comply with legal obligations
Child Supervision Data
The child's data described in this policy is used solely to:
- Display the child's app usage, battery level, and BackToLife activity to the linked parent
- Apply and enforce the app blocks, time limits, and content filters configured by the parent
- Maintain the link between the parent account and the child's device
We do NOT use any parent or child data for:
- Advertising or marketing purposes
- Selling or renting to third parties
- Profiling or behavioral analysis
- Automated decision-making that produces legal or similarly significant effects
- Any purpose unrelated to providing the parental supervision service
Data Sharing and Third Parties
Third-Party Service Providers (Data Processors)
We use the following third-party services that process data on our behalf as Data Processors under GDPR Article 28, with Data Processing Agreements (DPAs) in place:
Cloud Hosting: Hostinger
- Purpose
- Hosting parent account data and child supervision data
- Data processed
- Parent email and name; child nickname, usage data, battery level, supervision settings
- Location
- Europe (France)
- DPA in place
- Yes
Hostinger Privacy Policy: hostinger.com/legal/privacy-policy
Authentication, Notifications & Crash Reporting: Google Firebase (Google Ireland Ltd. / Google LLC)
- Purpose
- Account authentication (Firebase Authentication), push notifications (Firebase Cloud Messaging), crash reporting (Firebase Crashlytics)
- Data processed
- Authentication identifiers, push notification tokens, crash and error diagnostics (device model, OS/app version, stack traces)
- Location
- EU and United States (transfers safeguarded under the EU-US Data Privacy Framework and/or Standard Contractual Clauses)
- DPA in place
- Yes (Google Cloud/Firebase Data Processing Terms)
Firebase Privacy: firebase.google.com/support/privacy
Error Diagnostics: Functional Software, Inc. (Sentry)
- Purpose
- Error and crash diagnostics to identify and fix bugs
- Data processed
- Device model, OS/app version, technical stack traces, recent in-app actions leading up to an error
- Location
- United States (transfers safeguarded under the EU-US Data Privacy Framework and/or Standard Contractual Clauses)
- DPA in place
- Yes
Sentry Privacy Policy: sentry.io/privacy
Subscription Management: RevenueCat, Inc.
- Purpose
- Managing and verifying subscription status for the parent account
- Data processed
- Anonymous app user identifiers, subscription status, product identifiers, purchase/renewal dates, anonymized receipt data. No child data is ever sent to RevenueCat.
- Location
- United States (transfers safeguarded under the EU-US Data Privacy Framework and/or Standard Contractual Clauses)
- DPA in place
- Yes
RevenueCat Privacy Policy: revenuecat.com/privacy
No Data Sales or Sharing
We do not sell, rent, or trade personal data — of parents or of children — to anyone. We do not engage in sale of personal data (as defined by GDPR, CCPA, and other privacy laws), sharing for cross-context behavioral advertising, data brokerage, or any monetization of personal information.
International Data Transfers
Parent account data and child supervision data are primarily processed within the EU. Limited technical data (authentication identifiers, notification tokens, crash diagnostics) is processed by Google/Firebase and Sentry, and limited subscription-related data (relating to the parent only) is processed by RevenueCat; these may involve transfers to the United States under the safeguards described above.
Data Retention, Unlinking and Deletion
- Parent account data: Retained while your account is active. Deleting your account removes all associated personal data immediately.
- Child usage data: Detailed usage data is retained for 6 months and then automatically deleted. Anonymized, aggregated statistics that contain no per-child identifiers and cannot be linked back to any individual may be kept for longer, for our own product decisions.
- On unlinking: When you unlink a child's device or delete your parent account, your supervision settings stop applying and you lose access to that child's data. Unlinking does not itself delete the child's usage history, which is tied to the child's own BackToLife account.
- Deleting the child's data: The child's account data and usage history are deleted by deleting the BackToLife account used on the child's device (in the BackToLife app: Settings > Account > Delete Account). Deletion removes all associated personal data immediately. This is performed from the child's device with the account credentials; it cannot be triggered remotely from the Parents app. You may also request erasure at any time by contacting us at info@backtolife.site.
Your Rights Under GDPR
As a user in the EU/EEA (or UK), you have the following rights regarding your personal data. These rights also protect your child: as the holder of parental responsibility, you may exercise them on your child's behalf, and a child who is old enough to do so may also exercise their own rights by contacting us.
1. Right of Access (Article 15)
You may obtain confirmation of whether we process your or your child's personal data and request a copy of that data at any time.
2. Right to Rectification (Article 16)
You may correct inaccurate data. You can update your email, name, and your child's nickname in the app, or contact us for assistance.
3. Right to Erasure / 'Right to be Forgotten' (Article 17)
You may delete your parent account at any time through the app settings, and you may unlink your child's device at any time, which stops supervision and removes supervision data as described in the retention section above. The child's account data is deleted by deleting the BackToLife account on the child's device. You may also request full erasure of any data — yours or your child's — by contacting us.
4. Right to Restriction of Processing (Article 18)
You may request restriction of processing in certain circumstances (e.g., while we verify data accuracy).
5. Right to Data Portability (Article 20)
You may receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV) and transmit it to another controller.
6. Right to Object (Article 21)
You may object to processing based on legitimate interest at any time.
7. Right to Withdraw Consent (Article 7(3))
Where processing is based on consent — including the parental consent for processing your child's data — you can withdraw it at any time by unlinking the device, deleting your account, or contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
8. Right to Lodge a Complaint
You may lodge a complaint with your local data protection supervisory authority. In Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es. Find other EU authorities at edpb.europa.eu.
To exercise any of these rights, contact us at info@backtolife.site. We will respond within 30 days (1 month as required by GDPR).
Your Rights Under Other Privacy Laws
United States — COPPA and State Laws
If you are a parent in the United States, the Children's Online Privacy Protection Act (COPPA) applies to the collection of personal information from children under 13. BackToLife Parents is designed so that all child data collection occurs with the direct involvement and consent of the parent, who initiates the linking, configures the supervision, and can review and delete the child's data at any time. Parents may review, delete, or refuse further collection of their child's information by unlinking the device or contacting us at info@backtolife.site.
CCPA/CPRA (California Residents)
California residents have rights under CCPA/CPRA including the right to know, delete, correct, opt out of sale (we do not sell), and non-discrimination. We do not sell personal information, including that of consumers under 16, and we do not share personal information for cross-context behavioral advertising.
UK GDPR (United Kingdom)
UK users have the same rights as EU/EEA users under UK GDPR. UK supervisory authority: Information Commissioner's Office (ICO) — ico.org.uk. The ICO's Age Appropriate Design Code may apply to the supervised child experience.
LGPD (Brazil)
Brazilian users have rights under LGPD similar to GDPR. LGPD Article 14 requires that children's data be processed in their best interest and with specific consent from a parent or legal guardian, which is how BackToLife Parents operates by design.
Children's Privacy
Unlike the standalone BackToLife app, BackToLife Parents intentionally processes data about children — that is the purpose of the product. We therefore apply the following principles and safeguards:
- The parent is always in control: Child data is only ever collected after a parent or legal guardian deliberately links the child's device and grants the necessary permissions on that device. There is no way for us to collect a child's data without a parent initiating it.
- Data minimization: We collect the minimum data needed for supervision: a parent-chosen nickname, app usage time, battery level, and BackToLife in-app activity. We never ask the child for personal information, and we do not collect the child's real identity, age, contacts, location, or the content they view.
- Transparency towards the child: The supervision is visible in the BackToLife app on the child's device. BackToLife Parents is a supervision tool, not a covert surveillance tool, and must not be used to monitor any person without their knowledge where the law requires it.
- No profiling, no advertising: Children's data is never used for profiling, advertising, or any commercial purpose, and is never sold or shared.
- Best interests of the child: The product exists to protect children's digital wellbeing by limiting exposure to addictive social media mechanics, in line with GDPR Recital 38's recognition that children merit specific protection.
- Erasure: Parents can delete their child's data at any time by unlinking the device or contacting us. A child may also contact us directly at info@backtolife.site regarding their data.
Intended use: BackToLife Parents may only be used by a parent or legal guardian to supervise a child under their parental responsibility. Using the app to monitor adults, or any person over whom you do not hold parental responsibility, is prohibited by our terms and may be unlawful.
App Permissions
BackToLife Parents (parent's device) requests:
- Internet access: Required to sync with the linked child's device and display supervision data
- Notifications: To alert you about relevant supervision events
BackToLife (child's device), when linked, requests:
- Screen Time / usage access: On iOS, Family Controls / Screen Time permissions; on Android, usage access permission — required to measure app usage and enforce the blocks and limits configured by the parent
- Internet access, local storage, notifications: As described in the BackToLife Privacy Policy
We do NOT request access to: contacts, photos/media, microphone, location, calendar, or SMS — on either device.
Data Protection by Design and Default
- Data minimization: Only the data strictly necessary for parental supervision is collected.
- Purpose limitation: Child data is used only to provide the supervision features to the linked parent.
- Storage limitation: Data is deleted when no longer needed and when devices are unlinked.
- Privacy by default: No supervision occurs until a parent explicitly links a device and grants permissions on it.
- Security by design: Encryption, access controls, and secure storage are built into our architecture.
Security Measures
Technical Measures
- HTTPS/TLS encryption for all data in transit, including usage data from the child's device
- AES-256 encryption for data at rest
- Secure device storage (Keychain/Keystore) for sensitive local data
- Regular security updates and patches
Organizational Measures
- Strict access controls limiting internal access to personal data, with child data treated as high-sensitivity
- Data Processing Agreements with all processors
- Training on data protection and security
- Incident response procedures
Your Responsibilities
As the parent account holder, you are responsible for:
- Only linking devices of children over whom you hold parental responsibility
- Securing your own device and keeping your account credentials confidential — anyone with access to your account can see your child's usage data
- Keeping both devices' operating systems updated
- Informing your child about the supervision in an age-appropriate way
Data Breach Notification
In the unlikely event of a data breach affecting personal data:
- We will notify the relevant supervisory authority within 72 hours (GDPR Article 33)
- We will notify affected users without undue delay if the breach poses a high risk to their rights and freedoms (GDPR Article 34). Given that this service processes children's data, we treat any breach involving child data as high-priority by default.
- Notification will include: nature of the breach, categories and number of affected users, likely consequences, and measures taken
Our Business Model and Subscriptions
BackToLife Parents is offered on a paid subscription basis. The features included, the applicable price, billing period, renewal conditions, and any free trial period are clearly displayed in the App before you complete your purchase.
Subscription Payments
Subscriptions are purchased and managed through the platform from which you downloaded the App (Apple App Store or Google Play Store). Payments are processed by the applicable app store in accordance with their own terms and privacy policies. BackToLife Parents does not directly collect, process, or store your payment card details, banking information, or other sensitive payment credentials.
Subscription-Related Data
To manage access to paid features, we receive limited subscription information from the app store via our subscription management provider (RevenueCat), such as: subscription status (active, expired, cancelled, trial), plan or product identifier, purchase or renewal date, expiration date, and anonymous transaction or receipt identifiers. This information relates to the parent's account only and is used solely to verify subscription status, provide access to paid features, prevent fraud, handle support requests, and comply with legal obligations.
Refunds and Cancellations
Cancellations and refunds are handled by Apple or Google according to their own policies. Deleting your account or uninstalling the App does not automatically cancel your subscription; you must cancel through the relevant app store.
No Monetization of Personal Data
Our revenue comes exclusively from subscriptions. We never monetize personal data — and in particular, we never monetize, sell, or use for advertising any screen time or usage data, whether it relates to a parent or a child. If our business model ever changes in a way that affects how we process personal data, we will update this Privacy Policy and, where required, seek your consent before the changes take effect.
Automated Decision-Making and Profiling
We do not engage in automated decision-making that produces legal or similarly significant effects (GDPR Article 22), profiling for advertising or behavioral manipulation, or any processing requiring special safeguards under GDPR beyond those described in this policy. The app blocks and filters applied to the child's device are configured and controlled by the parent, not by automated profiling.
Business Transfers
If BackToLife is acquired, merged, or sells assets, this Privacy Policy will continue to apply. We will notify you of any ownership change via email and in-app notification, give you the option to delete your data (including your child's data) before the transfer, ensure the new entity complies with this Privacy Policy, and obtain your consent if the new entity wants to use data for new purposes.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or new features. Material changes — including any change in what child data is collected or how it is used — will be communicated through an in-app notification, via email to your registered address, and by updating the 'Last Updated' date. For significant changes affecting children's data, we will request your explicit consent before the changes take effect. Previous versions will be archived and available upon request.
Contact Us & Data Protection Contact
Data Controller:
ASOCIACIÓN JUNIOR EMPRESA SYNKRO
Plaza de San Martín, 1, Madrid, 28013 Madrid, Spain
General inquiries and data protection requests: info@backtolife.site
We will respond within 30 days (1 month as required by GDPR). For complex requests, we may extend this by an additional 2 months, in which case we will notify you.
Supervisory Authorities
Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es
EU/EEA: edpb.europa.eu
UK: Information Commissioner's Office (ICO) — ico.org.uk
Definitions
- Parent / You: The adult holder of parental responsibility who creates a BackToLife Parents account.
- Child / Supervised User: The minor whose device is linked to a parent account and whose social media use is supervised through BackToLife.
- Linked Device: The child's device on which the BackToLife app is installed and linked to the parent's account via a linking code.
- Personal Data: Any information relating to an identified or identifiable natural person (GDPR Article 4(1)) — including the child's usage data, which we treat as personal data of the child.
- Data Controller: ASOCIACIÓN JUNIOR EMPRESA SYNKRO.
- Data Processor: An entity that processes personal data on our behalf (e.g., our hosting provider, our subscription management provider).
- Holder of Parental Responsibility: The person(s) legally responsible for a child (patria potestad or legal guardianship under Spanish law).
- Screen Time Data: Data about device and app usage collected through Apple's Screen Time / Family Controls frameworks or Android usage access permissions.
- Consent: Freely given, specific, informed, and unambiguous indication of agreement to data processing (GDPR Article 4(11)).
- Service: The BackToLife Parents mobile application and associated parental supervision features.
Acknowledgment
This Privacy Policy was last updated on 13/07/2026. By creating a BackToLife Parents account and linking a child's device, you confirm that you hold parental responsibility over that child and that you have read, understood, and agree to this Privacy Policy, including the processing of your child's data as described.
You may request a copy of this policy in alternative formats by contacting us at info@backtolife.site.