Privacy built around families and trust.
This Privacy Policy explains how BeMe collects, uses, protects, retains and deletes personal data when parents, guardians and children use our website, applications and related services.
Safety insights without commercialising a child's data.
- No sale of children's personal data
- No targeted advertising to children
- No cross-app behavioural advertising profiles
- Verified parental consent before child onboarding
Consent first
A parent or lawful guardian must actively consent before a child's data is processed through BeMe.
Purpose limited
Data is processed for child-safety functionality, account operation, security and legal compliance—not unrelated advertising.
Data minimised
We aim to process only the information reasonably required to provide and secure the service.
Parent controlled
Verified parents can request access, correction, erasure or withdrawal of consent, subject to applicable law.
BeMe is designed to help parents identify potential online-safety risks affecting their children. We do not use children's personal data for targeted advertising, sell it to data brokers, or permit minors to independently provide the parental consent required for onboarding.
Overview and scope
This Privacy Policy describes how BeMe Labs (“BeMe”, “we”, “us” or “our”) handles personal data in connection with the BeMe website, mobile applications, parent dashboard, child-safety features, communications, support channels and related services (collectively, the “Services”).
This policy applies to parents, legal guardians, children whose devices or accounts are configured through the Services, website visitors and other individuals who communicate with us. It should be read together with our Terms of Use, Child Safety Policy and Parent Consent documentation.
Our processing is intended to follow applicable privacy and data-protection law, including India's Digital Personal Data Protection Act, 2023 and rules brought into force under it. Where another jurisdiction applies, additional rights or obligations may also arise.
Our role and key terms
For personal data for which BeMe determines the purpose and means of processing, BeMe acts as the Data Fiduciary under Indian data-protection law. A person to whom personal data relates is referred to as a Data Principal. For a child, the child's parent or lawful guardian may exercise applicable rights on the child's behalf.
“Personal data” means data about an identifiable individual. “Processing” includes collecting, recording, organising, storing, analysing, using, sharing, retrieving, deleting or otherwise handling personal data through automated means.
Information we collect
The information collected depends on how the Services are used, which features are enabled, the permissions granted, and the final technical configuration of the BeMe application.
Parent or guardian information
- Name, email address and mobile number
- Account credentials and account preferences
- Parent or guardian declarations and confirmations
- OTP status and identity-verification outcome
- Support requests and communications
Consent and compliance records
- Unique consent reference
- Server timestamp and accepted document version
- Checkbox confirmations and consent status
- Technical audit information, such as IP address and user agent
- Consent withdrawal, correction or deletion requests
Child and device information
- Child profile details provided by the parent
- Age or age bracket where required for service configuration
- Device identifiers, operating system and app version
- Enabled permissions and supported-app configuration
- Safety signals, classifications, alert status and related metadata
Website and operational information
- Browser, device type and approximate network information
- Pages viewed, interactions and referral information
- Security logs, diagnostics and error reports
- Subscription and transaction status where paid services are offered
- Information required to prevent fraud or misuse
Where identity verification is provided through DigiLocker or another approved provider, BeMe intends to receive only the verification result and permitted identity attributes required for the consent record. We do not intend to retain copies of government identity documents unless this becomes legally necessary and is clearly disclosed before collection.
Children's data
BeMe is a child-safety service, but a child is not authorised to independently create the parent account, accept the Parent Consent Agreement, or represent that legally valid parental consent has been provided.
Before child-related processing begins, we require an adult to affirm that they are at least 18 years old and are the child's biological parent or lawful guardian with authority to provide consent. BeMe may require OTP and identity verification to establish verifiable parental consent.
We aim not to undertake processing likely to cause a detrimental effect on a child's wellbeing. We also prohibit targeted advertising directed at children and cross-service tracking or behavioural profiling for advertising or commercial data-monetisation purposes.
Parents control onboarding, supported-app permissions, consent and account-level decisions. BeMe's alerts are intended to support—not replace—parental judgement, communication and appropriate professional or emergency assistance.
How we use information
We may process personal data for the following specified purposes:
- Creating, verifying, securing and administering parent accounts
- Obtaining and maintaining evidence of verifiable parental consent
- Configuring supported devices, applications and child-safety preferences
- Performing automated analysis intended to identify potential online-safety risks
- Generating alerts, contextual insights and safety-related information for the verified parent
- Providing customer support and responding to privacy or grievance requests
- Maintaining service reliability, debugging, fraud prevention and cybersecurity
- Processing subscriptions or payments through authorised providers
- Improving service performance using appropriately minimised or de-identified information
- Complying with law, lawful requests and regulatory obligations
- Establishing, exercising or defending legal claims
Where consent is the applicable ground for processing, consent must be free, specific, informed, unconditional, unambiguous and demonstrated through clear affirmative action. We will seek fresh consent where a material new purpose is not reasonably covered by the existing notice and consent.
Automated and AI-assisted processing
BeMe uses automated systems and artificial-intelligence techniques to analyse permitted safety signals and identify patterns that may indicate risks such as cyberbullying, grooming, sextortion, threats, coercion, harmful content or other online-safety concerns supported by the product.
Where the product architecture supports on-device analysis, relevant content is analysed locally on the device. Safety classifications, alerts or limited contextual information may then be made available to the verified parent as required to deliver the service. Exact data flows can vary by feature, operating system and supported application.
Automated analysis can make mistakes, miss risks or interpret context incorrectly. BeMe does not claim that every harmful interaction will be detected. Parents should review alerts thoughtfully, communicate with their child and contact appropriate emergency, law-enforcement, medical or safeguarding professionals where immediate danger is suspected.
BeMe is designed to operate through automated processing. BeMe employees and routine support personnel are not intended to read or manually monitor a child's private message content. Any exceptional access required for security, legal compliance or user-authorised support must be restricted, logged and handled under appropriate safeguards.
What we do not do
We do not sell or rent children's personal data.
We do not use children's personal data for targeted advertising.
We do not create cross-service behavioural advertising profiles of children.
We do not allow a minor to provide the required parental consent independently.
We do not monetise private child communications through data brokers.
We do not intentionally process more child data than reasonably required for the stated safety purpose.
Parent consent and consent evidence
Before proceeding to identity verification, the parent or guardian is required to actively confirm the applicable consent statements and accept the relevant legal documents. The production backend should create a tamper-resistant consent record linked to a unique consent reference.
The consent evidence may include:
- Consent reference and server-generated timestamp
- Parent contact details and verified account identifier
- Accepted checkbox states
- Version and cryptographic hash of the accepted legal documents
- IP address, user agent and relevant security information
- OTP verification result and timestamp
- Identity-verification result and timestamp
- Records of later withdrawal, renewal or modification of consent
A browser cookie or secure session token may be used to link the onboarding session to the consent record. The server record—not the cookie alone—constitutes the primary audit evidence.
Sharing and service providers
We may engage carefully selected service providers to perform functions on our behalf. Depending on the final service configuration, these may include:
- Cloud hosting, storage, database and cybersecurity providers
- OTP, SMS, email or communication providers
- DigiLocker or other approved identity-verification providers
- Payment processors and subscription-management providers
- Analytics, error-reporting and service-performance providers
- Professional advisers, auditors and legal representatives
Service providers may process personal data only for contracted purposes and subject to appropriate confidentiality, security and data-protection requirements. We may also disclose information where required by law, to respond to valid legal process, to protect a person from serious harm, or to investigate fraud, abuse or security threats.
If BeMe undergoes a merger, financing, restructuring, acquisition or transfer of assets, information may be transferred subject to applicable law and continued privacy protections.
Cookies and website data
Our website may use cookies, local storage and similar technologies for essential site operation, security, session management, preference storage, consent-reference continuity, performance measurement and analytics.
Essential cookies may be required for the website or account features to function. Non-essential analytics or marketing technologies should be activated only in accordance with applicable consent requirements and the choices presented through any cookie-management tool.
Browser settings can be used to block or delete cookies, but doing so may prevent parts of the website or onboarding journey from operating correctly. A separate Cookie Policy may provide additional details once the final website technology audit is complete.
Security safeguards
We use reasonable technical and organisational safeguards appropriate to the nature and risk of the personal data processed. These safeguards may include:
- Encryption in transit and, where appropriate, at rest
- Role-based access controls and least-privilege access
- Secure authentication and verification controls
- Audit logging and consent-record integrity measures
- System monitoring, vulnerability management and incident response
- Vendor assessment and contractual security obligations
- Data minimisation, retention controls and secure deletion
No system is completely secure. Parents are responsible for protecting account credentials, securing their devices and promptly reporting suspected unauthorised access.
Retention and deletion
We retain personal data only for as long as reasonably necessary to fulfil the stated purpose, operate and secure the Services, maintain legally required consent and transaction records, resolve disputes, enforce agreements and comply with applicable law.
Retention periods may differ by data category. For example, active account information may be retained while the account remains open, security logs may be retained for a limited risk-based period, and consent evidence may need to be retained for a longer period to demonstrate compliance.
When consent is withdrawn or the purpose is no longer being served, applicable personal data will be deleted or de-identified without undue delay unless continued retention is required by law, necessary for fraud prevention, required to establish or defend legal claims, or otherwise permitted under applicable law.
Information stored locally on a device may need to be removed through application controls, account disconnection or uninstallation. Backup copies may persist temporarily until they are overwritten through routine backup cycles.
Your privacy rights
Subject to applicable law and identity verification, a parent, guardian or other Data Principal may have the right to:
- Obtain information about personal data being processed and relevant processing activities
- Request correction, completion or updating of inaccurate or incomplete personal data
- Request erasure of personal data no longer required for the stated purpose
- Withdraw consent with comparable ease to the method used to provide it
- Nominate another individual to exercise applicable rights in the event of death or incapacity
- Raise a grievance with BeMe and, where available, approach the competent regulatory authority
Withdrawal of consent does not affect processing lawfully completed before withdrawal. If required data can no longer be processed, some or all child-safety functionality may stop and the associated account or device connection may need to be closed.
To protect families, we may request reasonable information to verify the identity and authority of the person making a request. We will not ordinarily disclose a child's information to an unverified requester.
Personal data incidents
If we become aware of a personal data breach, we will investigate, contain and remediate the incident and provide notifications to affected individuals and competent authorities where required by applicable law.
Notifications may describe the nature of the incident, likely consequences, measures taken or proposed, recommended protective steps and appropriate contact information.
International processing and transfers
Some providers or infrastructure used by BeMe may process information from locations outside the individual's state or country. Where personal data is transferred or made accessible across borders, we will seek to use lawful transfer mechanisms and appropriate contractual, technical and organisational safeguards.
BeMe will comply with any restrictions notified by the Government of India regarding transfer of personal data to particular countries or territories.
Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in the Services, technology, providers, data practices or law. The revised policy will display a new “Last updated” date.
Where a change materially affects the purpose or manner in which personal data—particularly a child's data—is processed, we may provide additional notice and obtain fresh consent where required before the change applies.
Contact, privacy requests and grievances
For privacy questions, consent withdrawal, correction or erasure requests, complaints or child-data concerns, contact us using the details below.
Do not send passwords, OTPs or unnecessary government identity documents by email. We may contact you through a secure method if further verification is required.
This policy should be reviewed against BeMe's final technical architecture, contracted providers and legal-entity details before commercial launch.
Understand consent before beginning verification.
Review how verified parental consent works and what you authorise during onboarding.