Privacy Policy

Last updated: September 14, 2026

Effective date: August 31, 2026


1. Introduction

GoodTube (“we”, “us”, “our”) is a parent-supervised video app that lets parents approve YouTube videos before children watch them. This Privacy Policy explains how we collect, use, store, and share information when you use the GoodTube mobile app, web app, and related services (collectively, the “Service”).

Developer / data controller: Cyberfork

App package: com.goodtube.cyberfork

Contact: support@cyberfork.eu

By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.

Note: This document is provided for your app and store listings. It is not legal advice. Consider having a qualified lawyer review it for your jurisdiction and business structure before publication.


2. Who the Service is for

GoodTube is designed for parents and legal guardians (18+ or age of majority in your country) who manage video access for their children.

  • Parents create and control the account.
  • Children use Kid Mode under a parent’s account. Children do not register with their own email address.
  • Parents are responsible for supervising their children’s use of the Service.

3. Information we collect

3.1 Parent account information

When a parent signs up or signs in, we may collect:

Data Purpose
Email address Account creation, login, password reset, email verification
Password (hashed by Firebase Authentication) Account security
Display name and profile photo Account profile (including Google Sign-In)
Firebase user ID Identify your account across the Service
Email verification status Account security

Sign-in methods: email/password and Google Sign-In (email and basic profile scope).

3.2 Child profile information (provided by the parent)

Parents may create up to 5 child profiles per account. We store:

Data Purpose
Child nickname Display in the app
Optional avatar URL Profile display
Preferred language App language for that child
Linked device IDs Pair kid devices to the parent account

We do not require a child’s real name, date of birth, or email address.

3.3 Video requests, approvals, and viewing activity

Data Purpose
YouTube video URL, title, channel name/ID, thumbnail Approval queue and approved video library
Request status (pending / approved / denied) Parent supervision workflow
Device ID and device name (e.g. phone model) Identify which device made a request
Viewing history (if enabled by parent) Watch history, analytics for parents; includes video metadata and watch timestamps/duration

Parents can disable viewing history in notification settings.

3.4 Device and app information

Data Purpose
Generated device identifier (UUID) Pairing, session, and device management
Device name / model Display in parent dashboard
App language and preferences Localization and settings
Recent kid search queries (stored locally on device) Search convenience

3.4a Cookies, local storage, and similar technologies

GoodTube stores, accesses, and/or collects information from users’ devices (and may allow certain service providers to do so) using cookies and similar technologies, including:

Technology Examples Purpose
Local / on-device storage App preferences, pairing state, recent search queries, auth session tokens Keep you signed in, remember settings, pair kid devices
Device / advertising identifiers Advertising ID / similar device identifiers used by ad SDKs Serve ads in parent-facing areas (AdMob)
Push notification tokens FCM token Deliver parent notifications about video requests
Cookies / browser storage (web) Session or preference cookies / local storage if you use our website or web features Authentication, security, and basic site functionality
Security / integrity signals Firebase App Check and related device signals (when enabled) Reduce abuse and unauthorized API use

These technologies may be placed, accessed, or recognized on your device or browser by us and/or third parties listed in Section 5 (for example Google Firebase, Google AdMob, Google Sign-In, and YouTube/Google for embedded playback).

You can control some of this through device settings (notifications, advertising ID / “limit ad tracking”), by signing out, clearing app data, or deleting your account. Blocking certain storage or identifiers may limit features (for example staying signed in or receiving approval notifications).

3.5 Tokens, subscriptions, and ads (parent account)

Data Purpose
Token balance and daily usage Free tier limits for approve/deny actions
Ad watch history (UTC day counts) Enforce rewarded-ad limits
Subscription status, product ID, purchase token, expiry Premium features via Google Play / Apple App Store
Parent PIN hash Protect sensitive parent actions (stored hashed server-side)

Rewarded and banner advertisements are shown in parent-facing areas of the app, not in Kid Mode search/playback screens.

3.6 Push notifications

With your permission, we collect and store an FCM push token to send notifications about video approval requests. You can control notification settings (including quiet hours) in the app.

3.7 Information we do not intentionally collect

  • We do not knowingly collect personal information directly from children under 13 without parental involvement through a parent account.
  • We do not collect precise GPS location.
  • We do not read contacts, SMS, or phone call logs.

3.8 Analytics and crash reporting

The app includes the Firebase Analytics SDK as a dependency. We do not currently enable or use Firebase Analytics to track usage. If we enable analytics in the future, we will update this policy.

We do not currently use Firebase Crashlytics or a third-party crash reporting service. Errors may be logged locally during development.


4. How we use information

We use collected information to:

  • Provide parent supervision features (approve/deny videos, channel lists, kid profiles)
  • Sync settings and approval status across parent and kid devices
  • Send push notifications to parents about video requests
  • Process subscriptions and in-app purchases
  • Enforce token limits and ad reward rules
  • Operate, maintain, and improve the Service
  • Prevent abuse, fraud, and unauthorized access (including Firebase App Check)
  • Comply with legal obligations

We do not sell your personal information.


5. How we share information

We share information only as described below:

5.1 Service providers (processors)

Provider What they process Why
Google Firebase (Auth, Firestore, Cloud Functions, Cloud Messaging, Hosting, App Check) Account, app data, notifications Core backend infrastructure
Google / YouTube Video metadata via YouTube Data API; embedded video playback Search metadata and in-app playback
Google AdMob Ad serving, device/ad identifiers for ads Parent-mode advertisements
Google Play / Apple App Store Purchase and subscription data Premium subscriptions
Google Sign-In Authentication Optional login method
Google Fonts Font delivery (if used) App typography

These providers process data under their own privacy policies:

  • Google Privacy Policy
  • YouTube Terms of Service
  • Google Play Terms

5.2 Legal requirements

We may disclose information if required by law, court order, or government request, or to protect rights, safety, and security of users and the Service.

5.3 Business transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to this policy.

We do not share child profile data with other users except within your family account under your control.


6. YouTube and third-party content

GoodTube is not affiliated with, endorsed by, or sponsored by YouTube or Google.

  • Video search uses the YouTube Data API for titles, channels, and thumbnails.
  • Approved videos play through YouTube’s embedded player inside the app.
  • When a child watches a video, YouTube and Google may collect information according to their own policies.
  • Parents choose which videos children may watch; we do not guarantee the safety or appropriateness of third-party YouTube content.

6.1 YouTube API Data storage, refresh, and deletion

To reduce quota use and improve performance, we may temporarily store YouTube API Data (such as video/channel titles, IDs, thumbnails, and search result lists) in our Firebase/Firestore cache and, for some preferences, on the device:

API Data type How often we refresh / update How / when we delete
Video and channel metadata Refreshed from the YouTube Data API when needed after cache expiry (7 days) Expired cache entries are removed when accessed or during cleanup; also deleted when a parent deletes related content or their account
Search results (video/channel) Refreshed after cache expiry (6 hours) Expired search cache is discarded; also removed with account deletion / cleanup
Parent-approved / denied video records and channel lists Updated when parents approve, deny, or edit lists Deleted when the parent removes the item or deletes the account

We do not keep expired YouTube API search/metadata cache indefinitely. Account deletion removes associated stored API-derived records as described in Section 9.


7. Data storage, retention, and security

  • Data is stored on Google Cloud / Firebase servers. The region is configured in our Firebase project settings.
  • We use industry-standard measures including authentication, Firestore security rules, server-side token/subscription validation, and hashed parent PINs.
  • Retention: We keep account data while your account is active. Old video request records may be cleaned up automatically after a short period. You may delete your account at any time (see Section 9).
  • No method of transmission or storage is 100% secure.

8. International transfers

If you are located outside the country where our servers are hosted, your information may be transferred to and processed in other countries, including the United States, where Google/Firebase operates. We rely on appropriate safeguards where required by law (e.g. EU Standard Contractual Clauses through Google’s terms).


9. Your rights and choices

Depending on your location, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information (via profile settings)
  • Delete your account and associated data
  • Withdraw consent for optional features (e.g. push notifications via device settings)
  • Object to or restrict certain processing
  • Data portability (where applicable under GDPR)
  • Lodge a complaint with your local data protection authority (EEA/UK users)

Account deletion

Parents can delete their account in Parent Mode → Profile → Delete account. Deletion permanently removes:

  • Parent account and authentication
  • All child profiles
  • Video requests, approvals, channel lists, and related settings
  • Subscription records tied to the account

Some data may remain in encrypted backups for a limited time per Firebase/Google retention practices.

To request help with access or deletion, contact: support@cyberfork.eu


10. Children’s privacy

Information about children is collected only through a parent-controlled account. See our Children’s Privacy Policy for additional details about how we handle child-related data and parental controls.

We comply with applicable children’s privacy laws, including COPPA (United States) where applicable, by requiring parental account creation and parental control over child profiles.


11. EEA / UK users (GDPR)

Legal bases for processing:

Processing Legal basis
Account and core service Contract performance
Security and fraud prevention Legitimate interests
Push notifications (with permission) Consent
Legal compliance Legal obligation

You have GDPR rights listed in Section 9. Contact us to exercise them.


12. California residents (CCPA/CPRA)

California residents may have the right to know, delete, and correct personal information, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information for cross-context behavioral advertising as defined under California law.


13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date. Material changes may be notified in the app or by email where appropriate. Continued use after changes means you accept the updated policy.


14. Contact us

Cyberfork — GoodTube

Email: support@cyberfork.eu

Website: https://goodtubev2.web.app

For privacy-specific requests, use the subject line: GoodTube Privacy Request