🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
ParentLog

ParentLog Privacy Policy

How ParentLog handles private family records, encrypted Drive sync, operational metadata and sharing.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Local working copy Records begin in app-private storage on your device
Optional Drive sync Content artifacts are encrypted on-device before upload
Public verification Receipt metadata is public when someone has its packet details
Privacy requests [email protected]
On this page
  1. Overview
  2. Data we handle
  3. How we use data
  4. Sharing and processors
  5. Storage and residency
  6. Cloud and backups
  7. Public links
  8. Retention
  9. Security
  10. Your rights
  11. Children and minors
  12. International transfers
  13. Changes
  14. Contact

This policy explains ParentLog's local-first workspace, optional connected features and the choices available to adults who use the app and people whose information they record.

Overview

Blue Sparrow is a solo developer based in India and operates ParentLog. This policy covers the Android app, its optional synchronization and operational services, support intake and public packet-verification page. ParentLog follows data-minimisation, purpose-limitation, transparency and rights principles supported by the EU General Data Protection Regulation and comparable privacy requirements.

ParentLog is local-first, not exclusively offline. Its working SQLite database and selected files are held in app-private device storage. These local files are not currently encrypted by ParentLog at the database or file layer. Device access controls, optional biometric app lock and platform protections help restrict access, while optional Google Drive content artifacts are encrypted by ParentLog before upload.

The signed-in adult decides why family information is entered, how accurate it is and who receives an export. For information about children, co-parents and other contacts, that adult is generally responsible for appropriate notice, permission, minimisation and sharing choices. Blue Sparrow handles connected information to provide the requested service and separately decides how account, security, purchase, support and service-operation data is handled.

Data we handle

Depending on the features you use, ParentLog may handle:

  • Account details from Google and Firebase such as Firebase identifier, email address, display name and profile image. The operational API stores the Firebase identifier and a normalized email hash rather than the family content. Display name and profile image are sent during bootstrap but are not fields in the audited operational database schema.
  • Device and service details such as a device identifier and display name, platform, app version, build number, sign-in tokens, encrypted FCM token, notification state, last-seen time, Drive authorization state, sync generations, opaque Drive file identifiers and wrapped encryption keys.
  • Adult, child and co-parent profiles and the information you enter about schedules, exchanges, holiday or vacation rules, journal entries, parenting events, shared expenses, claims, settlements, requests and attachments.
  • Family information you choose to store, which can include contact details, emergency contacts, locations, medical profiles, medications, allergies, school and insurance information, activity contacts, document-vault items and parenting-plan notes.
  • Export information such as selected record ranges, redaction choices, PDF files, packet identifiers, cryptographic hashes, manifest hashes, generation time, app version, build number, schema version and device identifier.
  • Local app activity and support diagnostics such as coarse feature events, sync state, file counts and sizes, queued-operation counts, entitlement tier and sanitized error codes. Diagnostic exports are created locally and shared only when you choose; operational delivery diagnostics can be stored by the API.
  • Google Play and RevenueCat purchase information such as product, offer, receipt, transaction, renewal, cancellation and entitlement state. Blue Sparrow does not receive full payment-card credentials.
  • Support details you submit, including name, reply email, topic, message, app version, platform, locale, attestation and delivery metadata.

ParentLog does not include an advertising SDK, analytics SDK, crash-reporting SDK or attribution SDK in the audited app. It removes the Android advertising-ID permission. Image and file access occurs only through a user-selected import or attachment action. The visible voice-entry control currently uses simulated local phrases and does not ship a microphone permission or speech provider.

How we use data

Information is used only as reasonably necessary to:

  • Provide journals, schedules, family information, expenses, requests, attachments, reminders, search, exports and local app security.
  • Authenticate the adult user and coordinate authorized devices.
  • Encrypt, upload, download, restore, merge and prune optional Drive sync artifacts.
  • Route metadata-only synchronization nudges and local notifications.
  • Register and verify content-free packet integrity receipts.
  • Process purchases, restore entitlements and enforce the access level associated with an offer.
  • Receive support requests, provide requested help, diagnose failures, limit abuse and protect services.
  • Maintain security, service continuity and records required for applicable operational, accounting, privacy and consumer obligations.

ParentLog does not sell personal information, rent it, use family records for targeted advertising or train a general-purpose artificial-intelligence model on them.

Sharing and processors

Blue Sparrow does not disclose family information for independent advertising. Limited information may be processed by:

  • Google and Firebase for Google sign-in, Firebase Authentication, app attestation, Firebase Cloud Messaging, optional Google Drive sync, Google Play distribution and billing.
  • Blue Sparrow's ParentLog operational API and infrastructure providers for account references, device coordination, encrypted push-token storage, opaque sync pointers, wrapped keys, entitlement mirrors, diagnostics, deletion state and integrity receipts.
  • Blue Sparrow's notification gateway and Firebase Cloud Messaging for enabled sync nudges and account updates.
  • RevenueCat, Google Play and Blue Sparrow's subscription gateway for product, receipt, renewal and entitlement handling.
  • Blue Sparrow's attested support intake and mail-delivery services when you submit a support request.
  • The operating system and any application, storage destination or recipient you select when importing, exporting, printing or sharing a file or request summary.

These third-party providers handle limited information under their own terms, controls and privacy notices. Blue Sparrow may also make a limited disclosure when required by applicable rules or reasonably needed to address fraud, abuse or a serious security threat.

Storage and residency

The working SQLite database, attachments, generated PDFs, diagnostic exports and caches are stored in app-private areas on the device. ParentLog does not currently set Android backup exclusions or disable Android system backup, so the operating system or a device backup service may copy eligible app data according to platform and account settings. Local storage is not a substitute for device encryption, a secure screen lock or an independent backup.

The ParentLog API stores operational metadata and integrity receipts, not decrypted family records or PDF bytes. Blue Sparrow-controlled operational metadata is intended to remain in European Union infrastructure, subject to verification of the production datacentre, backup regions, worker configuration and retention operations. This is a qualified infrastructure commitment, not a claim that every ParentLog-related datum remains exclusively in the EU.

Google, Firebase, RevenueCat, Google Play, notification, attestation, mail, support and user-selected storage providers may process limited information in other regions under their own infrastructure and transfer arrangements. Google controls the physical location of Drive data. Blue Sparrow support access may occur from India when needed to answer a request or operate the service.

Cloud and backups

Optional private synchronization uses the hidden app-data area of the Google Drive account you authorize. ParentLog requests the narrow drive.appdata scope and does not use it to browse ordinary visible Drive files. Supported records, mutation batches, snapshots, attachment media and recovery artifacts are encrypted on the device using versioned authenticated encryption before upload. Generic filenames and an allowlisted set of operational properties can remain visible to Google.

The ParentLog API receives opaque Drive file identifiers, artifact type, generation, source-device identifier, timestamps, size and encryption-version metadata. It also stores wrapped account sync keys for approved devices, but does not receive the clear content-encryption key or decrypted family records.

Drive synchronization and pruning are best-effort. The app keeps a recent recovery history and deletes eligible older artifacts only after safety checks; failed deletion can leave an encrypted artifact until a later successful retry or explicit account purge. Google controls Drive availability and infrastructure. Losing every authorized device or key can make an encrypted copy unrecoverable, so keep the Google account secure and maintain another suitable copy of irreplaceable information.

Files exported or shared through the device become ordinary user-controlled copies. Their destination and recipient control retention, onward sharing and deletion. Removing the ParentLog copy cannot retrieve a file already sent elsewhere.

Public links

ParentLog can create a public verification URL containing a packet identifier and packet hash. Anyone with those values can query the unauthenticated verification service. A matching response can show the packet identifier and hash, generation and registration times, app version, build number and receipt schema version. It does not provide the PDF, manifest, names, notes, expenses, filenames or attachment bytes.

Verification confirms only that matching receipt metadata was registered; it does not establish authorship, identity, accuracy, completeness, context or a particular interpretation of the underlying records. The public verification page does not currently add a page-specific noindex instruction. Integrity receipts have no implemented expiry or revocation flow in the audited service, and account deletion does not currently remove them. Share packet details only with intended recipients and avoid publishing them unnecessarily.

Schedule-change requests are shared as locally generated text or PDF through the device's share tools rather than hosted as public ParentLog pages. Once sent, the chosen recipient controls their copy.

Retention

Local records remain until you delete them, run a deletion action, clear app storage or uninstall in a way that removes local data. App activity events and temporary exports follow local cleanup behavior. User-created exports and recipient copies have independent lifecycles.

Drive artifacts remain in the authorized Google account until successful pruning, explicit Drive purge or provider-side deletion. Failed cleanup may extend retention. Operational account, device, sync, wrapped-key, notification, entitlement, support, security and deletion information is kept while reasonably needed for its purpose and applicable records. No fixed production period is promised where live cleanup evidence has not been verified. Provider-held records follow provider controls and applicable requirements.

The in-app account deletion flow first attempts to remove every object in ParentLog's Drive app-data area, then deletes most account-scoped API metadata, purges selected local rows and app-private folders, deletes the Firebase Authentication user and signs out of Google and RevenueCat. The backend keeps a minimal deletion-pending user row, deletion request and subscription tombstone, and it currently retains public integrity receipts. The local purge implementation does not yet explicitly clear every newer Drift table, including parenting-plan, family information, document, request and integrity tables. Until that coverage is corrected and verified on a physical device, use Android's app-storage controls or uninstall after the flow if you need to remove remaining local app data. Email [email protected] for connected-service deletion follow-up.

Deleting the ParentLog account does not cancel a Google Play subscription. Cancel it separately in Google Play.

Security

ParentLog uses proportionate safeguards including app-private device storage, optional biometric app lock, app-switcher preview hiding, secure storage for key material, HTTPS, Firebase Authentication, Firebase App Check for public support, encrypted FCM-token storage, scoped Drive access, AES-256-GCM content envelopes, wrapped device keys and integrity hashes.

The local SQLite database and attachment files are not currently application-encrypted, and Android system backup is not currently excluded. Protect the device with current software, device encryption and a strong screen lock. Protect the Google account, shared files and packet details. No device, transmission, account, key or connected service can be guaranteed completely secure.

Your rights

Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal information, correct it, receive a portable copy, delete it, restrict or object to processing, and withdraw consent where consent is the basis. You may also have a right to contact your local data-protection authority. These protections include, where applicable, the EU GDPR and EEA rules, UK GDPR, India's Digital Personal Data Protection framework, California and other US state privacy rules, Brazil's LGPD, Canada's privacy rules and comparable requirements elsewhere.

Adults using ParentLog can edit many records, control notifications, create exports, manage Drive sync and start deletion in the app. A child, co-parent or other person whose information was entered by a ParentLog user should normally contact that user first; Blue Sparrow will assist a verified user or respond directly where required.

Email [email protected] with ParentLog in the subject and enough information to identify the account or request. Blue Sparrow may request proportionate verification and will respond within the period required where you live. Provider-held information or subscriptions may also need to be managed through Google, Google Drive, Google Play, RevenueCat or another selected service.

Children and minors

ParentLog is intended for adult account holders and is not directed to children as users. It does not create child sign-in accounts or invite children to operate the service. An adult may enter extensive information about a child, including identity, schedules, locations, health, medication, allergy, school, insurance, activity, expense, contact, journal and attachment details.

The adult user is responsible for collecting only what is genuinely needed, providing any notice and obtaining any permission or other valid basis required where the family lives. Use extra care before entering a child's sensitive information or placing it in an export. Confirm recipients, apply supported redaction choices and do not share packet details publicly. Contact [email protected] if you believe a child's information has been handled inappropriately.

International transfers

Blue Sparrow-controlled operational metadata is intended for EU infrastructure subject to the production verification described above. Google, Firebase, RevenueCat, Google Play, notification, attestation, Drive, mail, support and user-selected file providers may process limited information outside the user's or affected person's country.

Where safeguards are required for an international transfer, Blue Sparrow and relevant providers rely on appropriate contractual, adequacy or other valid mechanisms and apply data-minimisation and security measures. EU users retain the protections required by the EU GDPR when a necessary provider connection crosses a regional boundary.

Changes

This policy may change when ParentLog, its providers or applicable requirements change. Material updates will be presented in the app or at https://bluesparrow.dev where appropriate, and the updated date will be revised. Earlier handling remains subject to the version applicable at that time unless a change must apply sooner for security or compliance.

Contact

Blue Sparrow is the developer and privacy contact for ParentLog. For privacy questions, rights requests or deletion follow-up, email [email protected]. For general help, email [email protected]. Product and policy information is available at https://bluesparrow.dev.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.