Halo ("we", "us", or "our") is operated by Amos Whitewolf Webb. This Privacy Policy explains how we collect, use, and protect information when you use the Halo mobile application.
What Halo does
Halo is a parental safety app that helps parents monitor voice chat and in-game text in their children's games. When a child starts a gaming session, the app captures game and voice audio on the child's device, transcribes it there, analyses the transcript text for safety concerns with Halo's AI safety model (by default through our secure processing service, or entirely on the device if you choose), and presents a safety report to the parent. The audio itself never leaves the child's device.
Information we collect
Account information
- Email address (from Google or Apple Sign-In)
- Name (if provided via Apple Sign-In)
Family information
- Child nicknames (entered by parent)
Session data
- Session timestamps (when a session started and ended)
- Safety flags (green, orange, or red status)
- Category scores (numeric risk levels for safety categories)
- AI-generated summaries (paraphrased descriptions of concerning moments, written by Halo's AI safety model; these are not direct quotes or raw transcripts)
Device information
- Device pairing token (to link child device to parent account)
- Device model and OS version (for compatibility and support)
- Last seen timestamp (when child device was last active)
- Push notification token (APNs token, used to send safety alerts to the parent's device)
Information we do NOT collect
- Audio recordings: Audio is transcribed on the child's device and is never uploaded to our servers
- Raw transcripts: We never store transcripts. In cloud analysis mode the transcript text is processed in memory by our secure processing service and immediately discarded (see "How audio processing works"); in on-device mode it never leaves the device
- Location: we do not use GPS or device location services
- Contacts, photos, or other personal files
- Browsing or search history
How we use information
We use collected information to:
- Create and manage your account
- Link parent and child devices within a family
- Display session history and safety summaries to parents
- Send push notifications to the parent's device when a session is flagged for review
- Send transactional emails (welcome, safety reports, pairing reminders)
How audio processing works
- The child starts a session on their device before gaming
- Audio is captured on the child's device via Apple's ReplayKit framework
- Audio is transcribed on the child's device using Apple's speech recognition
- The transcript text is then analysed for safety concerns by Halo's AI safety model, in one of two modes chosen by the parent:
- Cloud analysis (default): the transcript text is sent over an encrypted connection to our secure processing service, analysed in memory, and immediately discarded. It is never stored, logged, or used for any other purpose, and it travels without any identifier linking it to your family or device
- On-device analysis: after a one-time model download, the analysis runs entirely on the child's device and the transcript text never leaves it. You can switch any device to on-device analysis from its settings in the parent app
- AI-generated summaries of any concerning moments are paraphrased descriptions, not direct quotes, and our software checks that before anything is stored
- Safety scores and AI-generated summaries are stored for the parent to review; recordings and transcripts are not
- Audio files and transcripts are deleted from the device after processing
Data storage and security
Your account, family, and session data (safety scores and paraphrased summaries) is stored securely using Supabase, a cloud database platform with encryption at rest and in transit. Transcript text processed in cloud analysis mode is never written to our database or logs. We do not sell your data. We may share limited data with the third-party service providers described below to operate the app, measure marketing performance, and manage subscriptions.
Third-party services
- Supabase: Database hosting and authentication
- Apple / Google: Sign-in authentication
- Resend: Transactional email delivery
- Sentry: Crash reporting and error tracking (EU data center)
- PostHog: Product and website analytics, including masked session replay (hosted in the European Union)
- RunPod (United States): Secure AI processing for cloud analysis mode (SOC 2 Type II). Receives transcript text transiently, with no identifier linking it to a family or device, processes it in memory, and discards it. Stores nothing
- Hugging Face (United States): AI model downloads for on-device analysis mode only; no personal data is sent
- Appstack: Install attribution and ad measurement (parent devices only; see below)
- Superwall: Paywall presentation
- RevenueCat: Subscription and purchase processing (App Store transactions, entitlements)
Sentry crash reporting
We use Sentry to identify and fix app crashes and errors. When an error occurs, Sentry may collect:
- Crash data (stack traces, error messages)
- Device info (device model, OS version, app version)
- Breadcrumbs (a trail of app events before the crash, e.g. "recording started", "user signed in")
Sentry does NOT collect:
- IP addresses (we have disabled this)
- Email addresses or names
- Audio, transcripts, or any content from monitoring sessions
Sentry data is stored in the EU and is used solely to improve app stability.
Product and website analytics
We use PostHog, hosted in the European Union, to understand how the app and our website are used (e.g. which features are popular, where users drop off in onboarding). PostHog collects app and website usage events and device metadata. It does not receive audio, transcripts, or safety report content.
On parent devices, PostHog may record app screens as session replays to help us improve the product. Text input and images are masked on the device before upload. Session replay never runs on child devices. Our website uses PostHog to measure visits and may record website sessions in the same masked form.
Advertising, attribution, and paywalls
We use Appstack, a mobile measurement partner, to measure the effectiveness of our marketing (e.g. installs and subscriptions attributed to campaigns), and it may forward conversion events to the advertising networks we advertise on (currently Meta) for the same purpose. We use Superwall to present paywalls and determine subscription access. These services only run on the parent's device, not on child devices.
These services may process:
- IP address and connection information (such as OS version, timezone, and locale) to match your install to a recent ad
- Your device's advertising identifier, only if you allow tracking when iOS asks
- App events (e.g. sign up completed, onboarding completed, subscription started)
- Purchase / subscription metadata (such as product identifier, currency, and amount) for attribution and analytics
Where available, we also use Apple's SKAdNetwork for privacy-preserving install attribution. This data is used exclusively for ad measurement and is not sold or shared for any other purpose. To stop this processing, delete your account from the in-app Settings menu or contact us at hello@halosafe.app.
Children's privacy
Halo is designed for parents to monitor their children's online safety. The parent account holder is responsible for:
- Setting up and authorising monitoring on the child's device
- Pairing the child device via QR code
- Explaining to their child that monitoring is active
Children do not create accounts. The child device operates in a limited monitoring mode controlled by the parent. Advertising and attribution SDKs do not run on child devices.
Data retention and deletion
- Session data is retained while your account is active
- You can delete your account and all associated data directly within the app (Settings menu)
- You may also request deletion by emailing hello@halosafe.app
- Upon deletion, all data (account, family, children, devices, sessions, and email records) is permanently removed
Your rights
You may:
- Access your data within the app
- Request a copy of your data via email
- Delete your account and data from within the app
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the app or email.
Contact us
If you have questions about this Privacy Policy, contact us at:
Email: hello@halosafe.app
Amos Whitewolf Webb
Halo Safe