Privacy Policy
Last updated: September 14, 2026
Effective date: August 31, 2026
1. Introduction
GoodTube (“we”, “us”, “our”) is a parent-supervised video app that lets parents approve YouTube videos before children watch them. This Privacy Policy explains how we collect, use, store, and share information when you use the GoodTube mobile app, web app, and related services (collectively, the “Service”).
Developer / data controller: Cyberfork
App package: com.goodtube.cyberfork
Contact: support@cyberfork.eu
By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
Note: This document is provided for your app and store listings. It is not legal advice. Consider having a qualified lawyer review it for your jurisdiction and business structure before publication.
2. Who the Service is for
GoodTube is designed for parents and legal guardians (18+ or age of majority in your country) who manage video access for their children.
- Parents create and control the account.
- Children use Kid Mode under a parent’s account. Children do not register with their own email address.
- Parents are responsible for supervising their children’s use of the Service.
3. Information we collect
3.1 Parent account information
When a parent signs up or signs in, we may collect:
| Data | Purpose |
|---|---|
| Email address | Account creation, login, password reset, email verification |
| Password (hashed by Firebase Authentication) | Account security |
| Display name and profile photo | Account profile (including Google Sign-In) |
| Firebase user ID | Identify your account across the Service |
| Email verification status | Account security |
Sign-in methods: email/password and Google Sign-In (email and basic profile scope).
3.2 Child profile information (provided by the parent)
Parents may create up to 5 child profiles per account. We store:
| Data | Purpose |
|---|---|
| Child nickname | Display in the app |
| Optional avatar URL | Profile display |
| Preferred language | App language for that child |
| Linked device IDs | Pair kid devices to the parent account |
We do not require a child’s real name, date of birth, or email address.
3.3 Video requests, approvals, and viewing activity
| Data | Purpose |
|---|---|
| YouTube video URL, title, channel name/ID, thumbnail | Approval queue and approved video library |
| Request status (pending / approved / denied) | Parent supervision workflow |
| Device ID and device name (e.g. phone model) | Identify which device made a request |
| Viewing history (if enabled by parent) | Watch history, analytics for parents; includes video metadata and watch timestamps/duration |
Parents can disable viewing history in notification settings.
3.4 Device and app information
| Data | Purpose |
|---|---|
| Generated device identifier (UUID) | Pairing, session, and device management |
| Device name / model | Display in parent dashboard |
| App language and preferences | Localization and settings |
| Recent kid search queries (stored locally on device) | Search convenience |
3.4a Cookies, local storage, and similar technologies
GoodTube stores, accesses, and/or collects information from users’ devices (and may allow certain service providers to do so) using cookies and similar technologies, including:
| Technology | Examples | Purpose |
|---|---|---|
| Local / on-device storage | App preferences, pairing state, recent search queries, auth session tokens | Keep you signed in, remember settings, pair kid devices |
| Device / advertising identifiers | Advertising ID / similar device identifiers used by ad SDKs | Serve ads in parent-facing areas (AdMob) |
| Push notification tokens | FCM token | Deliver parent notifications about video requests |
| Cookies / browser storage (web) | Session or preference cookies / local storage if you use our website or web features | Authentication, security, and basic site functionality |
| Security / integrity signals | Firebase App Check and related device signals (when enabled) | Reduce abuse and unauthorized API use |
These technologies may be placed, accessed, or recognized on your device or browser by us and/or third parties listed in Section 5 (for example Google Firebase, Google AdMob, Google Sign-In, and YouTube/Google for embedded playback).
You can control some of this through device settings (notifications, advertising ID / “limit ad tracking”), by signing out, clearing app data, or deleting your account. Blocking certain storage or identifiers may limit features (for example staying signed in or receiving approval notifications).
3.5 Tokens, subscriptions, and ads (parent account)
| Data | Purpose |
|---|---|
| Token balance and daily usage | Free tier limits for approve/deny actions |
| Ad watch history (UTC day counts) | Enforce rewarded-ad limits |
| Subscription status, product ID, purchase token, expiry | Premium features via Google Play / Apple App Store |
| Parent PIN hash | Protect sensitive parent actions (stored hashed server-side) |
Rewarded and banner advertisements are shown in parent-facing areas of the app, not in Kid Mode search/playback screens.
3.6 Push notifications
With your permission, we collect and store an FCM push token to send notifications about video approval requests. You can control notification settings (including quiet hours) in the app.
3.7 Information we do not intentionally collect
- We do not knowingly collect personal information directly from children under 13 without parental involvement through a parent account.
- We do not collect precise GPS location.
- We do not read contacts, SMS, or phone call logs.
3.8 Analytics and crash reporting
The app includes the Firebase Analytics SDK as a dependency. We do not currently enable or use Firebase Analytics to track usage. If we enable analytics in the future, we will update this policy.
We do not currently use Firebase Crashlytics or a third-party crash reporting service. Errors may be logged locally during development.
4. How we use information
We use collected information to:
- Provide parent supervision features (approve/deny videos, channel lists, kid profiles)
- Sync settings and approval status across parent and kid devices
- Send push notifications to parents about video requests
- Process subscriptions and in-app purchases
- Enforce token limits and ad reward rules
- Operate, maintain, and improve the Service
- Prevent abuse, fraud, and unauthorized access (including Firebase App Check)
- Comply with legal obligations
We do not sell your personal information.
5. How we share information
We share information only as described below:
5.1 Service providers (processors)
| Provider | What they process | Why |
|---|---|---|
| Google Firebase (Auth, Firestore, Cloud Functions, Cloud Messaging, Hosting, App Check) | Account, app data, notifications | Core backend infrastructure |
| Google / YouTube | Video metadata via YouTube Data API; embedded video playback | Search metadata and in-app playback |
| Google AdMob | Ad serving, device/ad identifiers for ads | Parent-mode advertisements |
| Google Play / Apple App Store | Purchase and subscription data | Premium subscriptions |
| Google Sign-In | Authentication | Optional login method |
| Google Fonts | Font delivery (if used) | App typography |
These providers process data under their own privacy policies:
5.2 Legal requirements
We may disclose information if required by law, court order, or government request, or to protect rights, safety, and security of users and the Service.
5.3 Business transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to this policy.
We do not share child profile data with other users except within your family account under your control.
6. YouTube and third-party content
GoodTube is not affiliated with, endorsed by, or sponsored by YouTube or Google.
- Video search uses the YouTube Data API for titles, channels, and thumbnails.
- Approved videos play through YouTube’s embedded player inside the app.
- When a child watches a video, YouTube and Google may collect information according to their own policies.
- Parents choose which videos children may watch; we do not guarantee the safety or appropriateness of third-party YouTube content.
6.1 YouTube API Data storage, refresh, and deletion
To reduce quota use and improve performance, we may temporarily store YouTube API Data (such as video/channel titles, IDs, thumbnails, and search result lists) in our Firebase/Firestore cache and, for some preferences, on the device:
| API Data type | How often we refresh / update | How / when we delete |
|---|---|---|
| Video and channel metadata | Refreshed from the YouTube Data API when needed after cache expiry (7 days) | Expired cache entries are removed when accessed or during cleanup; also deleted when a parent deletes related content or their account |
| Search results (video/channel) | Refreshed after cache expiry (6 hours) | Expired search cache is discarded; also removed with account deletion / cleanup |
| Parent-approved / denied video records and channel lists | Updated when parents approve, deny, or edit lists | Deleted when the parent removes the item or deletes the account |
We do not keep expired YouTube API search/metadata cache indefinitely. Account deletion removes associated stored API-derived records as described in Section 9.
7. Data storage, retention, and security
- Data is stored on Google Cloud / Firebase servers. The region is configured in our Firebase project settings.
- We use industry-standard measures including authentication, Firestore security rules, server-side token/subscription validation, and hashed parent PINs.
- Retention: We keep account data while your account is active. Old video request records may be cleaned up automatically after a short period. You may delete your account at any time (see Section 9).
- No method of transmission or storage is 100% secure.
8. International transfers
If you are located outside the country where our servers are hosted, your information may be transferred to and processed in other countries, including the United States, where Google/Firebase operates. We rely on appropriate safeguards where required by law (e.g. EU Standard Contractual Clauses through Google’s terms).
9. Your rights and choices
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information (via profile settings)
- Delete your account and associated data
- Withdraw consent for optional features (e.g. push notifications via device settings)
- Object to or restrict certain processing
- Data portability (where applicable under GDPR)
- Lodge a complaint with your local data protection authority (EEA/UK users)
Account deletion
Parents can delete their account in Parent Mode → Profile → Delete account. Deletion permanently removes:
- Parent account and authentication
- All child profiles
- Video requests, approvals, channel lists, and related settings
- Subscription records tied to the account
Some data may remain in encrypted backups for a limited time per Firebase/Google retention practices.
To request help with access or deletion, contact: support@cyberfork.eu
10. Children’s privacy
Information about children is collected only through a parent-controlled account. See our Children’s Privacy Policy for additional details about how we handle child-related data and parental controls.
We comply with applicable children’s privacy laws, including COPPA (United States) where applicable, by requiring parental account creation and parental control over child profiles.
11. EEA / UK users (GDPR)
Legal bases for processing:
| Processing | Legal basis |
|---|---|
| Account and core service | Contract performance |
| Security and fraud prevention | Legitimate interests |
| Push notifications (with permission) | Consent |
| Legal compliance | Legal obligation |
You have GDPR rights listed in Section 9. Contact us to exercise them.
12. California residents (CCPA/CPRA)
California residents may have the right to know, delete, and correct personal information, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information for cross-context behavioral advertising as defined under California law.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date. Material changes may be notified in the app or by email where appropriate. Continued use after changes means you accept the updated policy.
14. Contact us
Cyberfork — GoodTube
Email: support@cyberfork.eu
Website: https://goodtubev2.web.app
For privacy-specific requests, use the subject line: GoodTube Privacy Request