PaladinLegal

Privacy Policy

Last updated: March 11, 2026

1. Introduction

MBJR Creative, LLC ("Paladin," "we," "us," or "our") operates the Paladin gaming safety platform, including the Paladin Windows Agent, cloud backend, and parent dashboard (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service.

We are committed to protecting the privacy of children and comply with the Children's Online Privacy Protection Act ("COPPA") and applicable state privacy laws.

2. Information We Collect

2.1 Parent Account Information

  • Email address and password (managed by Supabase Auth)
  • Display name
  • Payment information (processed by Stripe; we do not store card numbers)
  • Notification preferences

2.2 Child Profile Information

  • Display name (first name or nickname only)
  • Age or date of birth
  • Sensitivity level preference (set by parent)

2.3 Gaming Activity Data

  • Game titles and session durations
  • In-game text communications captured during monitored gaming sessions
  • Screen time usage data
  • Device information (OS version, agent version)

2.4 AI-Processed Data

  • Threat classifications and severity scores
  • AI-generated summaries and recommended actions
  • Alert history and parent feedback

3. How We Use Information

We use collected information to:

  • Provide and maintain the Service, including monitoring gaming communications for safety threats
  • Generate alerts and safety recommendations for parents
  • Enforce screen time rules set by parents
  • Process payments and manage subscriptions
  • Send notifications about safety alerts and account updates
  • Improve the accuracy of our AI classification models
  • Provide customer support

4. AI Processing and Third-Party Services

Captured text communications are processed by OpenAI's GPT-4o-mini model for threat classification. Before sending data to OpenAI:

  • Child names are replaced with pseudonyms ("[CHILD]")
  • Specific ages are generalized to age ranges
  • Other personally identifiable information (PII) is scrubbed

OpenAI processes this data under their API terms of service, which prohibit using API data for model training. We do not share raw, unprocessed child data with any third party.

5. COPPA Compliance

Paladin is designed for use by parents and guardians to monitor their children's gaming activity. We comply with COPPA as follows:

  • Verifiable Parental Consent: We verify parental identity through a credit card transaction during account onboarding before any monitoring begins.
  • No Direct Child Accounts: Children do not create accounts or directly interact with the Service. All data is accessible only to the verified parent.
  • Data Minimization: We collect only the information necessary to provide safety monitoring. Text is analyzed for threats and discarded after processing unless it triggers an alert.
  • Parental Access and Control: Parents can view all collected data, modify monitoring settings, and delete their child's profile and associated data at any time through the dashboard.
  • Data Deletion: Upon account deletion or child profile removal, all associated gaming data, alerts, and AI-processed content are permanently deleted within 30 days.

6. Data Retention

  • Text communications: Raw text that does not trigger an alert is discarded after AI processing (typically within minutes).
  • Alerts and threat events: Retained for the duration of the subscription plus 90 days.
  • Gaming session data: Retained for 12 months for screen time reporting, then automatically purged.
  • Account data: Retained until account deletion is requested.

7. Data Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted using TLS 1.3
  • Stored data is protected by infrastructure-level disk encryption provided by our database host (Supabase)
  • Agent-to-cloud communication uses API key authentication
  • Dashboard access requires JWT authentication
  • Row-level security (RLS) policies prevent cross-account data access
  • Rate limiting protects against abuse

8. Data Sharing

We do not sell, rent, or trade personal information. We may share data with:

  • Service providers: Supabase (database hosting), OpenAI (AI classification), Stripe (payment processing), Resend (email notifications), Sentry (error monitoring) — each bound by their respective data processing agreements.
  • Law enforcement: If required by law or if we have a good-faith belief that disclosure is necessary to protect the safety of a child.
  • NCMEC: If our systems detect content that may constitute child sexual abuse material (CSAM), we are legally required to report it to the National Center for Missing & Exploited Children.

9. Your Rights

Parents have the right to:

  • Access all data collected about their child
  • Request correction of inaccurate data
  • Request deletion of their child's data
  • Opt out of non-essential data processing
  • Export their data in a machine-readable format
  • Withdraw consent and terminate monitoring at any time

To exercise any of these rights, contact us at privacy@getpaladin.gg.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For material changes affecting children's data, we will provide notice via email to the registered parent account.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at: