Privacy Policy

BackToLife Parents
Effective Date: 13/07/2026  |  Last Updated: 13/07/2026  |  Version: 1.0

Summary

BackToLife Parents is a companion app that lets a parent or legal guardian manage how their child uses social media through the BackToLife app installed on the child's device. Because this service involves processing data about children, we apply enhanced protections and full transparency.

Key points:

This Privacy Policy applies to the BackToLife Parents mobile application (iOS and Android) provided by ASOCIACIÓN JUNIOR EMPRESA SYNKRO, and complies with the EU General Data Protection Regulation (GDPR) and applicable national data protection laws, including Spanish Organic Law 3/2018 (LOPDGDD).

The main BackToLife app (used on the child's device) is covered by its own Privacy Policy at backtolife.site/privacy. This document governs the Parents app and the parent-child supervision features.

For questions about your data or your child's data, contact us at info@backtolife.site

Owner and Data Controller

ASOCIACIÓN JUNIOR EMPRESA SYNKRO
Plaza de San Martín, 1, Madrid, 28013 Madrid, Spain
VAT/Registration Number: ESG75285965

Data Controller contact: info@backtolife.site


Scope and Relationship With the BackToLife App

BackToLife Parents works together with the main BackToLife app:

Once linked, the parent can block or limit apps on the child's device, apply BackToLife's social media content filters to the child's use of Instagram and YouTube, and view usage information described below.


What Data We Collect

Parent Account Data

An account is required to use BackToLife Parents. When you create your account, we collect:

You cannot use BackToLife Parents without creating an account; providing your email and name is necessary to access the service.

Child Data (Supervised Device Data)

When you link your child's device, we process the following data about your child so that we can display it to you and apply your supervision settings:

Important: Unlike the standalone BackToLife app, where usage statistics stay on the user's own device, the supervision features of BackToLife Parents require that the usage data listed above be transmitted from the child's device to our servers so that it can be shown to the linked parent. This data is transmitted encrypted, stored on our servers in the EU, and is accessible only to the linked parent account. It is never made available to anyone else.

Diagnostics Data

To keep the app stable and fix bugs, we collect crash and error reports through Firebase Crashlytics and Sentry. These reports may include: device model, operating system version, app version, technical stack traces, and recent in-app actions leading up to an error. Diagnostics data is used exclusively for debugging and reliability — never for advertising or profiling.

Data We Do NOT Collect

We explicitly do not collect and technically cannot collect:

No Advertising Trackers

BackToLife Parents contains no advertising and no advertising trackers. Neither your activity nor your child's activity is monitored for advertising purposes. We do not engage in:


Screen Time and Family Controls Data

On iOS, BackToLife uses Apple's Screen Time technologies (including the Family Controls and Device Activity frameworks) on the child's device to measure app usage and enforce the limits and blocks configured by the parent. On Android, equivalent usage access permissions are used for the same purposes.

We commit that screen time and app usage data collected through these features is:


Legal Basis for Processing (GDPR Articles 6 and 8)

1. Contract Performance (Article 6(1)(b) GDPR) — Parent's Data

Processing the parent's email address and name is necessary to provide the BackToLife Parents service, including creating and maintaining the parent account, providing app functionality, and communicating about the account and subscription.

2. Parental Consent (Articles 6(1)(a) and 8 GDPR) — Child's Data

We process the child's data described above on the basis of the consent given by the holder of parental responsibility over the child. By linking a child's device, you confirm that:

In Spain, the age of digital consent is 14 (Article 7 of Organic Law 3/2018). For children under that age, the consent of the holder of parental responsibility is required; for supervised users aged 14 and over, we still rely on the parental relationship and the transparency of the supervision on the child's own device.

You may withdraw this consent at any time by unlinking the child's device or deleting your account (see "Data Retention, Unlinking and Deletion" below).

3. Legitimate Interest (Article 6(1)(f) GDPR)

We process strictly necessary technical data (such as linking identifiers and service logs) based on our legitimate interest in maintaining a stable, secure and functional product, preventing fraud and misuse, and identifying and fixing bugs. We have assessed that this minimal processing does not override the rights and freedoms of parents or children.

4. Consent (Article 6(1)(a) GDPR) — Marketing

Where we send the parent marketing communications about app updates or new features beyond essential service communications, we will first obtain explicit consent, which can be withdrawn at any time. We never send marketing communications to children.


How Your Data is Stored

Parent account data and child supervision data are stored securely on our servers located in Europe (France). We implement the following security measures:


How We Use Your Data

Parent Account Data

We use the parent's email address and name to:

Child Supervision Data

The child's data described in this policy is used solely to:

We do NOT use any parent or child data for:


Data Sharing and Third Parties

Third-Party Service Providers (Data Processors)

We use the following third-party services that process data on our behalf as Data Processors under GDPR Article 28, with Data Processing Agreements (DPAs) in place:

Cloud Hosting: Hostinger
Purpose
Hosting parent account data and child supervision data
Data processed
Parent email and name; child nickname, usage data, battery level, supervision settings
Location
Europe (France)
DPA in place
Yes

Hostinger Privacy Policy: hostinger.com/legal/privacy-policy

Authentication, Notifications & Crash Reporting: Google Firebase (Google Ireland Ltd. / Google LLC)
Purpose
Account authentication (Firebase Authentication), push notifications (Firebase Cloud Messaging), crash reporting (Firebase Crashlytics)
Data processed
Authentication identifiers, push notification tokens, crash and error diagnostics (device model, OS/app version, stack traces)
Location
EU and United States (transfers safeguarded under the EU-US Data Privacy Framework and/or Standard Contractual Clauses)
DPA in place
Yes (Google Cloud/Firebase Data Processing Terms)

Firebase Privacy: firebase.google.com/support/privacy

Error Diagnostics: Functional Software, Inc. (Sentry)
Purpose
Error and crash diagnostics to identify and fix bugs
Data processed
Device model, OS/app version, technical stack traces, recent in-app actions leading up to an error
Location
United States (transfers safeguarded under the EU-US Data Privacy Framework and/or Standard Contractual Clauses)
DPA in place
Yes

Sentry Privacy Policy: sentry.io/privacy

Subscription Management: RevenueCat, Inc.
Purpose
Managing and verifying subscription status for the parent account
Data processed
Anonymous app user identifiers, subscription status, product identifiers, purchase/renewal dates, anonymized receipt data. No child data is ever sent to RevenueCat.
Location
United States (transfers safeguarded under the EU-US Data Privacy Framework and/or Standard Contractual Clauses)
DPA in place
Yes

RevenueCat Privacy Policy: revenuecat.com/privacy

No Data Sales or Sharing

We do not sell, rent, or trade personal data — of parents or of children — to anyone. We do not engage in sale of personal data (as defined by GDPR, CCPA, and other privacy laws), sharing for cross-context behavioral advertising, data brokerage, or any monetization of personal information.

International Data Transfers

Parent account data and child supervision data are primarily processed within the EU. Limited technical data (authentication identifiers, notification tokens, crash diagnostics) is processed by Google/Firebase and Sentry, and limited subscription-related data (relating to the parent only) is processed by RevenueCat; these may involve transfers to the United States under the safeguards described above.


Data Retention, Unlinking and Deletion


Your Rights Under GDPR

As a user in the EU/EEA (or UK), you have the following rights regarding your personal data. These rights also protect your child: as the holder of parental responsibility, you may exercise them on your child's behalf, and a child who is old enough to do so may also exercise their own rights by contacting us.

1. Right of Access (Article 15)

You may obtain confirmation of whether we process your or your child's personal data and request a copy of that data at any time.

2. Right to Rectification (Article 16)

You may correct inaccurate data. You can update your email, name, and your child's nickname in the app, or contact us for assistance.

3. Right to Erasure / 'Right to be Forgotten' (Article 17)

You may delete your parent account at any time through the app settings, and you may unlink your child's device at any time, which stops supervision and removes supervision data as described in the retention section above. The child's account data is deleted by deleting the BackToLife account on the child's device. You may also request full erasure of any data — yours or your child's — by contacting us.

4. Right to Restriction of Processing (Article 18)

You may request restriction of processing in certain circumstances (e.g., while we verify data accuracy).

5. Right to Data Portability (Article 20)

You may receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV) and transmit it to another controller.

6. Right to Object (Article 21)

You may object to processing based on legitimate interest at any time.

7. Right to Withdraw Consent (Article 7(3))

Where processing is based on consent — including the parental consent for processing your child's data — you can withdraw it at any time by unlinking the device, deleting your account, or contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.

8. Right to Lodge a Complaint

You may lodge a complaint with your local data protection supervisory authority. In Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es. Find other EU authorities at edpb.europa.eu.

To exercise any of these rights, contact us at info@backtolife.site. We will respond within 30 days (1 month as required by GDPR).


Your Rights Under Other Privacy Laws

United States — COPPA and State Laws

If you are a parent in the United States, the Children's Online Privacy Protection Act (COPPA) applies to the collection of personal information from children under 13. BackToLife Parents is designed so that all child data collection occurs with the direct involvement and consent of the parent, who initiates the linking, configures the supervision, and can review and delete the child's data at any time. Parents may review, delete, or refuse further collection of their child's information by unlinking the device or contacting us at info@backtolife.site.

CCPA/CPRA (California Residents)

California residents have rights under CCPA/CPRA including the right to know, delete, correct, opt out of sale (we do not sell), and non-discrimination. We do not sell personal information, including that of consumers under 16, and we do not share personal information for cross-context behavioral advertising.

UK GDPR (United Kingdom)

UK users have the same rights as EU/EEA users under UK GDPR. UK supervisory authority: Information Commissioner's Office (ICO) — ico.org.uk. The ICO's Age Appropriate Design Code may apply to the supervised child experience.

LGPD (Brazil)

Brazilian users have rights under LGPD similar to GDPR. LGPD Article 14 requires that children's data be processed in their best interest and with specific consent from a parent or legal guardian, which is how BackToLife Parents operates by design.


Children's Privacy

Unlike the standalone BackToLife app, BackToLife Parents intentionally processes data about children — that is the purpose of the product. We therefore apply the following principles and safeguards:

Intended use: BackToLife Parents may only be used by a parent or legal guardian to supervise a child under their parental responsibility. Using the app to monitor adults, or any person over whom you do not hold parental responsibility, is prohibited by our terms and may be unlawful.


App Permissions

BackToLife Parents (parent's device) requests:

BackToLife (child's device), when linked, requests:

We do NOT request access to: contacts, photos/media, microphone, location, calendar, or SMS — on either device.


Data Protection by Design and Default

Security Measures

Technical Measures

Organizational Measures

Your Responsibilities

As the parent account holder, you are responsible for:

Data Breach Notification

In the unlikely event of a data breach affecting personal data:


Our Business Model and Subscriptions

BackToLife Parents is offered on a paid subscription basis. The features included, the applicable price, billing period, renewal conditions, and any free trial period are clearly displayed in the App before you complete your purchase.

Subscription Payments

Subscriptions are purchased and managed through the platform from which you downloaded the App (Apple App Store or Google Play Store). Payments are processed by the applicable app store in accordance with their own terms and privacy policies. BackToLife Parents does not directly collect, process, or store your payment card details, banking information, or other sensitive payment credentials.

Subscription-Related Data

To manage access to paid features, we receive limited subscription information from the app store via our subscription management provider (RevenueCat), such as: subscription status (active, expired, cancelled, trial), plan or product identifier, purchase or renewal date, expiration date, and anonymous transaction or receipt identifiers. This information relates to the parent's account only and is used solely to verify subscription status, provide access to paid features, prevent fraud, handle support requests, and comply with legal obligations.

Refunds and Cancellations

Cancellations and refunds are handled by Apple or Google according to their own policies. Deleting your account or uninstalling the App does not automatically cancel your subscription; you must cancel through the relevant app store.

No Monetization of Personal Data

Our revenue comes exclusively from subscriptions. We never monetize personal data — and in particular, we never monetize, sell, or use for advertising any screen time or usage data, whether it relates to a parent or a child. If our business model ever changes in a way that affects how we process personal data, we will update this Privacy Policy and, where required, seek your consent before the changes take effect.


Automated Decision-Making and Profiling

We do not engage in automated decision-making that produces legal or similarly significant effects (GDPR Article 22), profiling for advertising or behavioral manipulation, or any processing requiring special safeguards under GDPR beyond those described in this policy. The app blocks and filters applied to the child's device are configured and controlled by the parent, not by automated profiling.

Business Transfers

If BackToLife is acquired, merged, or sells assets, this Privacy Policy will continue to apply. We will notify you of any ownership change via email and in-app notification, give you the option to delete your data (including your child's data) before the transfer, ensure the new entity complies with this Privacy Policy, and obtain your consent if the new entity wants to use data for new purposes.

Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, legal requirements, or new features. Material changes — including any change in what child data is collected or how it is used — will be communicated through an in-app notification, via email to your registered address, and by updating the 'Last Updated' date. For significant changes affecting children's data, we will request your explicit consent before the changes take effect. Previous versions will be archived and available upon request.


Contact Us & Data Protection Contact

Data Controller:
ASOCIACIÓN JUNIOR EMPRESA SYNKRO
Plaza de San Martín, 1, Madrid, 28013 Madrid, Spain

General inquiries and data protection requests: info@backtolife.site

We will respond within 30 days (1 month as required by GDPR). For complex requests, we may extend this by an additional 2 months, in which case we will notify you.

Supervisory Authorities

Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es
EU/EEA: edpb.europa.eu
UK: Information Commissioner's Office (ICO) — ico.org.uk


Definitions

Acknowledgment

This Privacy Policy was last updated on 13/07/2026. By creating a BackToLife Parents account and linking a child's device, you confirm that you hold parental responsibility over that child and that you have read, understood, and agree to this Privacy Policy, including the processing of your child's data as described.

You may request a copy of this policy in alternative formats by contacting us at info@backtolife.site.