Privacy Policy
Last updated: August 2026
Halo Aware ("we", "us", "our") is committed to protecting the privacy and safety of families who use our services. This Privacy Policy explains how we collect, use, store, and protect personal data when parents use the Halo Aware app and related services.
Halo Aware is designed for parents or legal guardians. Children do not create accounts themselves. If you are a child whose chats Halo Aware monitors, section 12 is written for you.
1. Who We Are
Halo Aware is a parental safety tool that provides insights into a child's use of AI chat platforms. Our service helps parents identify potential risks and safeguard their children online.
Data Controller:
Halo Aware Ltd
Registered in England and Wales, company no. 17065814
Registered office: 23 Broadway, North Hykeham, Lincoln, LN6 8DP
Contact: hello@haloaware.com
2. Who This Policy Applies To
This policy applies to:
- Parents or legal guardians who create a Halo Aware account
- Children whose AI interactions are monitored through a parent-managed account
3. Information We Collect
3.1 Parent Information
We may collect the following information about parents:
- Email address
- Display name
- Profile photo (if signing in via Google)
- Timezone
- Last login timestamp
3.2 Child Profile Information
Parents choose what information to provide. This may include:
- Child display name (real or pseudonym)
- Age range
- Avatar colour (UI preference)
We do not require real names or identifying details for children, and we never ask for a date of birth.
3.3 Payment Information
If you subscribe to a paid plan, your payment is processed by Stripe. We receive limited billing details such as your name, billing address, card type, and the last four digits of your card, which we use to manage your subscription. We never see or store your full card number. Stripe handles your card details directly.
3.4 Extension and Device Information
When you link the browser extension to a child, we store: the name you give the device, a generated device identifier (a random fingerprint that recognises that browser install, not the person using it), when it was last active, which platforms it is set to monitor, and technical health reports about whether capture is working on each platform. These reports describe the extension's own workings, never page content.
3.5 Website Forms and Abuse Prevention
Three forms on this website are open to anyone: the support and complaints form, the form that asks us to assess an AI platform, and the form that emails you a setup link. None of them needs an account. So that one script cannot flood any of them, we count how many times each internet (IP) address has used a form in the last ten minutes and ask you to wait if that number gets high.
That count lives in our server's memory and nowhere else. Your address is never written to our database, our logs, or a file, it is never attached to what you sent, and the count is gone within ten minutes or whenever we next deploy the site. The record we keep of a platform request is still only the platform you named and the time. A support message is kept as a record because complaints law requires it, and section 11 says for how long.
3.6 Setup Links by Email
If you ask us to email you a setup link, we keep: your email address, whether you ticked the box asking for occasional notes from us, and, when you arrived from an advert, which campaign brought you. We use the address to send the link you asked for and one reminder a day later if you have not used it. That is the whole of it unless you ticked the box; if you did, we may occasionally send practical notes about children and AI, and every email carries a one-click way to stop them all. Section 11 says how long the record lasts.
4. AI Message Processing
Halo Aware monitors activity on supported AI chat platforms only.
What happens to messages?
- The words themselves are processed temporarily in memory only and analysed using automated AI classification
- The raw text of a conversation is then discarded; it is never stored, except for the short alert snippets described below
What we keep for every conversation
For each monitored conversation we keep the derived record that powers the dashboard, never the conversation itself:
- Topic categories (for example school, creative writing, feelings)
- A short machine-written summary of what the conversation was about
- A risk level (usually none)
- Platform and timestamps
These records age out on your plan's history window, described in section 11.
Stored alert data (limited cases only)
If a medium or high risk is identified, we additionally store:
- A short snippet of the conversation around the flagged content
- A short written description of what was detected and why it matters
- A suggested way to start the conversation with your child
Raw messages outside these limited alert snippets are discarded.
5. Information We Do NOT Collect
Halo Aware does not collect:
- Full chat logs
- General browsing history
- Keystroke data
- Screenshots
- Location or GPS data
- Child email addresses or passwords
- Login credentials for third-party services
- Messages outside supported AI platforms
6. Our Legal Grounds
UK data protection law requires a legal ground for every use of personal data. Ours are:
- Monitoring and safety insights (your child's data): legitimate interests. We rely on the shared interest, yours, your child's and ours, in protecting children from serious online harms. Because the person affected is a child, we have carried out and recorded a formal assessment that weighs their privacy against that protection. Our design choices, summaries rather than transcripts, fast deletion, and monitoring the child can always see, are what keep that balance fair.
- Risk classifications: safeguarding. A risk label about a child is sensitive information, so the law requires a further condition to process it. Ours is safeguarding children, a recognised ground of substantial public interest, and we maintain the policy document the law requires alongside it.
- Your account, subscription and billing: contract. We process your own details because we need them to provide the service you signed up for.
- Keeping our public forms usable: legitimate interests. The short-lived count described in section 3.5 is what stops a script filling our complaints route, or stuffing the ballot on which AI platform we assess next. We keep it to a counter held in memory precisely so it costs you as little as possible.
We deliberately do not rely on consent as the legal ground for monitoring itself. A monitored child could be pressured, or tempted at exactly the wrong moment, into switching their own protection off; a safety measure should not have that off-switch. What the child keeps instead is stronger: the right to object, explained in section 8, which we must always take seriously.
7. You Stay in Control
- Parents control all monitoring settings
- You can pause or disable monitoring for any child or device at any time
- You can delete alerts, snippets, or a child's profile at any time
- You can delete your account at any time. Your own details go immediately, and your children's data goes with them unless another parent shares the family (section 11 explains that case)
8. Your Right to Object
Because monitoring relies on legitimate interests, you and your child each have the right to objectto it. This applies to the child directly: a monitored child can object to their own monitoring, without needing their parent's account, using the form on our support page.
When someone objects, we do not ignore it, and we do not simply switch everything off either. We weigh the objection against the safeguarding purpose, taking the child's age and circumstances into account, we record what we decided and why, and we tell the person who objected the outcome.
9. Automated Classification
Halo Aware uses automated systems to:
- Classify AI messages
- Identify potential safety risks
No automated decision significantly affects a child on its own. Alerts go to a parent, a human, who decides what if anything to do; the system never blocks, restricts, or reports a child to anyone. If you or your child believe a classification is wrong, you can delete it, or challenge it through the support page and we will look at it properly.
10. Data Security and Storage
We take appropriate technical and organisational measures to protect data, including:
- Encryption in transit and at rest
- Access controls
- Monitoring and logging
- Regular security reviews
Where it is stored: our databases, backups and file storage run on Amazon Web Services in the United Kingdom and the European Union, encrypted at rest, and the connection between your browser and us is encrypted in transit. Section 11 sets out how long each kind of data is kept, section 13 covers where it is processed, and section 15 lists every provider we share it with.
11. Data Retention
Data is removed automatically once it has done its job. The current limits:
- Non-flagged message data is never stored
- An alert is kept whole for 12 months: the conversation snippet, the written summary, the kind of risk, how serious it was, when it happened, and any notes you added. Then it's deleted, whether you opened it or not. Reading or dismissing an alert never shortens that, so the details are still there if you come back to it later. If you want the words gone sooner, delete the alert or its snippet yourself at any time
- Conversation summaries and usage statistics follow your plan's insights window, from two weeks on the free plan up to 12 months on Premium. Usage counters may be kept up to six weeks on shorter plans, since pattern notices need a few weeks of history to spot a change. Nothing is kept past 12 months
- Behavioural pattern notices are deleted after 30 days to 6 months, depending on whether you have read them
- Parents may delete any of this sooner, at any time
These limits are enforced by an automated daily process, and the same numbers are shown in the Data Inventory in your Settings. Data removed by that process also leaves our encrypted backups within 30 days.
Messages sent through our support page are kept on their own clock: data-protection complaints for six years from their outcome, because that record is our evidence the complaint was handled properly, and ordinary support messages for two years. These are cleared at an annual review rather than by the daily process.
If you asked us to email you a setup link, that record is deleted automatically too: after 90 days unless you ticked the box asking for occasional notes, and after 12 months in every case. Unsubscribing stops all email straight away, and the record then leaves on the same schedule.
Closing your account doesn't wait for any of these windows. Your own account details are deleted immediately and your sign-in is removed. What happens to your children's data depends on whether another parent shares the family with you. If nobody else does, their profiles, conversations and alerts are deleted immediately too, and the family closes with you. If someone else does, the family stays with them: the children's profiles and history carry on under the remaining parent, who takes over the account, and the plan reverts to the free tier because your payment details leave with you. We do it that way because a parent shouldn't lose sight of their own children just because someone else closed their account. That parent can still delete the children, or close the family, whenever they want to.
The one thing that lasts longer is billing. Invoices and payment records are kept by Stripe, our payment processor, for up to six years after your membership ends, because UK tax law requires it. We don't keep a copy ourselves.
12. For Children: What Halo Aware Does
If Halo Aware is on your browser, someone who looks after you set it up, and you can always see it running. Here is the honest version of what it does:
- It looks at your chats with AIs (like ChatGPT) to check you're safe. If a chat is fine, the words are deleted almost straight away.
- Your parent does not read your conversations. They see short summaries and the topics you've been chatting about, and they get an alert only if something looks genuinely risky. An alert can include a few lines of that chat, so they understand what happened and can help.
- It never looks at your photos, schoolwork, games, other websites, or where you are.
- If you think something it flagged is unfair, or you don't want to be monitored, you can tell us yourself. You don't need your parent's account, we will listen, and we will reply to you.
Halo Aware follows the UK's Age Appropriate Design Code (Children's Code), which sets the rules for how services must treat children's data: collect as little as possible, be honest about what happens to it, and put the child's best interests first.
13. Where We Operate
Halo Aware Ltd is a United Kingdom company, and this policy is written to UK data protection law. We offer the service in the United Kingdom, New Zealand and Australia. Your child's conversation data is processed in the UK and EU only, wherever you live.
If you are outside the UK, your own country's data protection law applies to us as well, and you keep every right in section 14. The differences that matter to you are the regulator you can complain to, listed there, and the deadline we work to, which is the shortest of them for everybody.
14. Your Rights
You have the right to:
- Access a copy of your data
- Correct data that is wrong
- Have data deleted
- Restrict what we do with data while a question is resolved
- Receive your data in a portable format
- Object to the monitoring processing (section 8)
- Complain to us about how we handle personal data, using the form on our support page. We will confirm we have it, look into it, and tell you the outcome.
- Complain to your data protection regulator, at any time, whether or not you have come to us first:
- In the United Kingdom, the Information Commissioner's Office
- In New Zealand, the Office of the Privacy Commissioner
- In Australia, the Office of the Australian Information Commissioner
To use any of these rights, email hello@haloaware.com with the subject "Data rights request", or use the support form. The director responsible for data protection (James North) handles these personally. We'll acknowledge your request within 5 working days and respond fully within 20 working days. That is New Zealand's deadline, which is the shortest of the countries we serve, and we apply it to everyone rather than making you work out which one is yours. If a request is complex enough to need longer, we can extend it, and we'll tell you why before the first deadline passes.
Halo Aware Ltd is registered with the Information Commissioner's Office as a data controller, registration ZC194496.
These rights belong to the person the data is about. A child monitored by Halo Aware has them over their own data, and can use the same form to complain about being monitored.
15. Who We Share Data With
We do not sell your data. We share personal data only with the providers that help us run Halo Aware:
- Amazon Web Servicesfor hosting and email (Amazon SES), in the UK and EU. The AI safety check also runs here: conversation text is analysed by Anthropic's Claude model running inside AWS in the UK and EU, and is never used to train AI models
- Stripe for payment processing
- Google for account sign-in, and for analytics only if you accept analytics cookies
- Plausible Analytics for privacy-friendly website analytics. Plausible is cookieless, collects only aggregate, anonymous usage data that cannot identify you, and is hosted in the EU
Your child's conversation data never leaves the UK and EU. Some parent-side providers, such as Stripe and Google, may process data outside the UK; where they do, the transfer is protected by appropriate safeguards such as Standard Contractual Clauses. We may also disclose data where required by law.
16. The Browser Extension and Chrome Web Store Rules
The Halo Aware extension is distributed through the Chrome Web Store, and Google's programme policies limit what any extension may do with the data it handles. We follow those limits, and they match how the product was already built.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
In plain terms: what the extension collects is used only to provide the safeguarding features described in this policy. We do not use it for advertising, we do not sell it or pass it to data brokers, we do not use it to judge anyone's creditworthiness, and we do not use it to train AI models.
Nobody at Halo Aware reads your child's conversations as a matter of course, and our own staff tools are not built to show them: the admin screens we use to run the service cover accounts, billing and technical health, never conversation content. A person here looks at stored alert text only where you have asked us to look into something, where it is needed to investigate a security problem, or where the law requires it.
17. Cookies
We use a small number of cookies to keep you signed in and, only with your consent, to understand how the site is used. You can read the full details and change your choice at any time in our Cookie Policy.
18. Contact Us
If you have questions or concerns about this policy, please contact:
19. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated clearly within the app.