Privacy Policy
Last updated: 16 de agosto de 2026 · Version 1.0
1. Who we are
Tarefas Kids ("we") is operated by SynX — CNPJ 35.308.185/0001-80 ("Controller", under Law No. 13.709/2018 — LGPD). Contact for the person responsible for data processing (Data Protection Officer / DPO): privacidade@synxbr.com.
2. Who this policy applies to
- Legal guardian (father, mother or guardian) who creates the account and sets up the service;
- Child or adolescent under the guardian's parental authority, whose device is supervised.
3. What data we collect
| Category | Data | Purpose |
|---|---|---|
| Guardian account | Name, email, password (stored with bcrypt hash), WhatsApp number (optional) | Authentication, communication and reports |
| Child profile | Name/nickname, date of birth (optional), profile photo | Identification within the family account |
| Child's device | Model, Android version, battery, installed apps, usage time per app | Parental supervision and screen-time limits |
| Location | Periodic GPS coordinates and virtual fence (geofence) events | Safety: knowing where the child is and alerting on entries/exits of areas |
| Screen and content | Screenshots on the guardian's demand, live viewing, text read by the accessibility service for the content monitor | Detection of inappropriate content and active supervision by the guardian |
| Task photos | Photos and selfies sent by the child upon completing tasks | Proof and validation of the tasks |
| Facial biometrics (sensitive data) | Face photos registered by the guardian and the mathematical representations (embeddings) generated from them | Confirming that it is the child themselves completing the task (family anti-fraud) |
| Emergency | SOS triggers with location | Alerting the guardian immediately |
4. Legal basis (LGPD)
- Processing of children's and adolescents' data: specific and prominent consent from the legal guardian (art. 14, §1 of the LGPD), collected at sign-up and on the activation screens of each feature.
- Facial biometrics is sensitive personal data (art. 5, II and art. 11): it is only processed with specific consent from the guardian, given on a dedicated screen before the first face registration. The feature is optional — the app works without it.
- Guardian data: performance of a contract (art. 7, V) and legitimate interest for platform security (art. 7, IX).
5. Where data is processed
- Our own contracted servers: web hosting (Hostinger) and a private server (VPS) operated by us.
- Facial biometrics: 100% on our own infrastructure. Facial recognition (ArcFace) and liveness verification run on our private server. The images and embeddings are not sent to third-party facial-recognition services.
- AI validation of task photos: task photos (e.g. "made bed") may be analyzed by an AI provider contracted as a processor (Ollama) solely to validate the task. The provider does not receive the child's name or account data.
- Notifications: push via Firebase Cloud Messaging (Google) — it receives only the device token and the notification content.
- WhatsApp reports (optional): sent by our own system to the number registered by the guardian.
6. How long we keep it
- Account and child data: for as long as the account exists.
- Locations and screenshots: kept for a limited period for the guardian's review and removed by cleanup routines.
- Biometrics: while the feature is active; the guardian can delete the registered faces at any time from the panel.
- Closed account: data deleted or anonymized, except where legally required to retain it.
7. Who we share with
We do not sell or rent personal data. We share only with the processors listed in section 5, to the extent strictly necessary for operation, or pursuant to a court order / competent authority.
8. Data subject rights (art. 18)
The legal guardian may, at any time and on their own behalf or on behalf of the child:
- Confirm that processing exists and access the data;
- Correct incomplete or outdated data;
- Delete data (including the entire account and all of the child's data) — available in the panel or via privacidade@synxbr.com;
- Withdraw consent (e.g. disable biometrics or location), without prejudice to the use of the other functions;
- File a petition with the ANPD if they believe their rights have not been met.
Response time: up to 15 days.
9. Security
- Communication always over HTTPS/TLS;
- Passwords with bcrypt hash; sessions via tokens with expiration; login attempt limit (rate limit);
- Access to the child's data restricted to the guardian's account (ownership verification on every operation);
- Biometrics processed on our own server with token authentication, with no public exposure of the files;
- Uploads served without code execution.
10. Transparency with the child
We recommend — and the app was designed this way — that the child knows they are being supervised: the device clearly shows the app, the tasks and the blocks. Healthy parental supervision is not hidden surveillance.
11. Changes
This policy may be updated. Relevant changes are announced in the app and/or by email, with a new consent request when the law requires it.
12. Contact
Questions or requests: privacidade@synxbr.com