Privacy
Effective October 7, 2026. ParentFilter is operated by All Things Considered LLC, 7101 Craig St, Overland Park, KS 66204.
The short version #
We collect your email address, the ratings you submit, and β if you choose to flag moments in a film β those flags; if you ask to be told when a film is covered, the address and title you typed for that request; and that is essentially it. There is no ad tracking on this site, no analytics scripts from ad companies, and we do not sell or share your personal data with anyone for their own use.
When you want your data gone, you email us and it goes.
What we collect #
- Your email address β it is your sign-in and the only identity your account has, apart from the Google identifier described just below if you sign in with Google. We never ask for your name, address, or phone number, and we never ask anything about your children. Beside it we keep one yes-or-no: whether the Monday letter is switched on for your account.
- If you sign in with Google β we ask Google for your email address and the identifier Google gives your Google account, and nothing else: not your name, your photo, or your contacts. Google must have verified the address, or we don't use it. We keep that identifier beside your address, so the same Google account always opens the same ParentFilter account; an address that already has an account here opens that one. We never see your Google password, and we keep no access to your Google account. Google, for its part, learns that you signed in to ParentFilter, which its own privacy policy covers. Deleting your account deletes the identifier with everything else.
- Your ratings β the film, and up to five numbers on a 0β3 scale. Ratings are shown publicly only in aggregate; no public page connects a rating to you.
- Subscription status, if you subscribe β our payment processor tells us whether your subscription is active. Your card details go to the processor directly; we never see or store them.
- That you agreed to our Terms β which version of the Terms of Service you agreed to, when, and where you ticked the box: as you signed in, on your account page, or as you subscribed (on our page, or on our payment processor's checkout page). Our box is also your confirmation that you are at least 13. We keep no IP address and nothing about your device with it.
- Filter guides β when you analyze a film while signed in, the finished guide is stored on the platform twice over: privately on your shelf with your household's filter choices, so the film loads itself next time; and in the shared guide library, so no family pays to analyze the same film twice. A guide is scene timestamps and category labels β never the film, which we never receive. Other families see only the guide, never your name, email, or account; we keep an internal record of which account contributed a guide (that is how abuse gets handled), and it is not shown to anyone. Your shelf copy and your choices stay private to your account: remove any of them on the analyzer page, or delete everything by closing your account.
- If you use the subscriber app β filter tracks it publishes to the shared library (scene timestamps and category labels for a film; other subscribers see the track, never who published it), and monthly totals of your account's AI analysis use, kept only to enforce your plan's monthly allowance.
- If you use the browser extension β it downloads the list of films our library has guides for, about once a day, and then does its matching on your own computer. That is deliberate: it means we do not learn what you are watching. We see a request when you tap to filter a particular film β that one guide being fetched by your account. We may see that request again when you play the same film another time: the extension remembers your choice unless you untick "Remember this choice for this film", and fetches the guide again if its copy is missing or out of date. We also see requests in the two cases below, each started only by a tap of yours. What the streaming service calls the film β its internal id β never leaves your computer, and neither does your viewing history.
- If you flag a moment β from the extension's "Flag this moment" button or the phone guide's Flag button, and then press Send β we receive the film's title and year, its runtime, and your flags: each a timestamp and, if you chose one, a category; the phone guide can also send a correction ("too late", "unnecessary", or "missed"). This is stored under your account as one record per film, and it is a record that you watched that film. No one outside ParentFilter can read your individual flags. Other families only ever see moments that our reconciliation has combined from several households' flags and a person has reviewed and published as a guide, and no published guide names who flagged what. People at ParentFilter see your flags only as aggregates in the review queue, or when investigating abuse. If you type a title for a film we do not list yet, that title, year, and runtime create the film's public catalog entry β not linked to you. Your flags are deleted outright when you delete your account.
- If you pair your phone as the remote β when you press "Pair your phone as the remote" in the extension or on the analyzer page, we open a session on our server and relay to your paired phone, over an encrypted connection, the film's title and runtime, the guide's moment list, and the player's position and paused state every few seconds; on the Full plan the phone's mute, blur, and skip commands travel back the same way. The session β including which account and which guide it was for β is erased after at most six hours. What we keep afterwards is a count, per guide, of how often each listed moment (or, for a command outside any listed moment, which 30-second stretch of the film) was muted, blurred, or skipped by remote, with no account, session, or time attached, used only to improve that guide.
- If you ask to be told when a film is covered β from the βIs your film covered?β search on the phone guide when we have no guide for the title you typed, or from the demo on /try: the email address you give, the title, which of those two pages you typed it on, and when you asked. That is a request, not a record of anything you watched, and it is not linked to an account. We use it to decide which guides to build first and to send one email when that guide is published. The email carries a link that deletes every request made with that address; a note to privacy@parentfilter.app does the same.
- Operational scraps β counters that limit abuse (attempts per connection, per network operator, per hashed address, or per account, for an hour, a day, or a week depending on the action; for flags, one marker per account per film that says the dayβs first save was already counted) and error logs. These exist to keep the service up, not to profile anyone. We also count, without identifying anyone, how often our own short links are followed, which page or link a new accountβs sign-in began from, how many fresh extension installs open the connect page, how many connected extensions refresh their guide list each day, how often the demo on /try is played, and β if you remove the browser extension and answer the one question on the page that opens β which answer you tapped, as a count for the day. The full list is on how we count.
How we use it #
- To sign you in β your email receives the one-time link, or, if you sign in with Google, Google confirms the address and which Google account it belongs to.
- To show and aggregate ratings β each film page publishes the median of what households reported, per category.
- As reference signals for our own AI analysis of films and the AI report cards, as the Terms of Service license describes β in aggregate, never attributed to you.
- To run your subscription, if you have one.
- To keep a record of which version of the Terms of Service you agreed to, and to ask you again when they change.
- To send one email when a film you asked about has a guide.
- To send the Monday letter β one question a week about films your family has seen β to accounts it is switched on for. A new account gets it only if you tick the box that asks; accounts made before we added that box kept the setting they had. One click in any letter stops it, and your account page turns it on or off.
Who processes data for us #
We run on other companies' infrastructure, and naming them beats a vague "trusted partners". Each one processes data only to provide its service to us:
- Cloudflare β hosting and our database. Everything the site stores lives there.
- Resend β delivers the sign-in email, the welcome note, the Monday letter, and the one βyour scene guide is readyβ email. It sees the address in order to send to it.
- Stripe β payments, when you subscribe. Stripe holds your card details; we hold only your subscription status and Stripe's reference IDs.
- xAI β the AI provider behind film analysis and report cards. Requests are about films, not about you: what reaches xAI is film titles, aggregate rating signals, and β for subscribers using playback analysis β the material your own app submits for analysis. We do not send xAI your email or your individual ratings history.
What we don't do #
- No ad networks and no cross-site trackers, ever.
- No selling or renting personal data, and no "sharing" it for advertising.
- No data brokers, in either direction.
- No profiles of your children. A rating is about a film, and that is the only thing we want to know about your household.
How long we keep things #
- Your account, ratings, and published filter tracks β until you delete them.
- The record that you agreed to the Terms β until you delete your account.
- Sign-in links β 15 minutes; expired links are swept from the database.
- Your flags on films β until you delete your account, then deleted outright.
- Phone-remote sessions β at most six hours, then erased; only the per-guide counts described above survive.
- Abuse counters β expire on their own within an hour, a day, or a week, depending on the action.
- Guide requests β thirty days after the one email, or six months after the request if no guide came; sooner if you use the link in the email or ask.
- Backups β up to 30 days, then gone.
- Withdrawn ratings β when a rating is removed, we may keep a record that it existed and was removed (with the content cleared) so abuse can't be un-done by deleting the evidence of it.
- Moderation and correction records β kept up to three years, because the corrections log is a public promise and has to be auditable.
The browser extension and Google's rules #
Our use of information received through the Parent Filter Chrome extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements: we use it only to provide and improve the filtering the extension exists for; we do not sell it, transfer it for advertising, or use it to judge creditworthiness; and no person reads your individual data except with your consent, in aggregate, or to investigate abuse.
Children #
ParentFilter accounts are for people 13 and older, and the site is built for parents, not children. We do not knowingly collect personal information from anyone under 13. If you believe a child has an account, tell us at privacy@parentfilter.app and we will delete the account and its data.
Deleting your data #
Delete your account yourself, on your account page β it takes effect immediately. Deletion removes your account, your email, your sign-in tokens, your ratings, your flags, and the record of which terms you agreed to, and every film's public aggregate is recomputed without your answers at the same moment. A live subscription must be cancelled first (the same page opens the billing portal). If you can't sign in, email privacy@parentfilter.app from your account's address and we will do it within 7 days. Backup copies age out within 30 days. Records Stripe keeps for its own books (past invoices) live with Stripe. That keeps β and beats β the promise the Terms of Service makes.
Changes and contact #
If this policy changes in a way that matters, we will say so on the site before the change takes effect β never quietly, and never retroactively. The current version always lives at this address with its effective date at the top. Questions: privacy@parentfilter.app.