The short version

PearGuard collects no personal data. Policies and activity live on the parent and child devices. Nothing readable is ever sent to a server. No account required.

What data is stored

All data is stored locally on the paired devices only:

  • App policies (allow, block, time limits, bedtime windows)
  • Activity logs from the child device
  • Time requests and approvals
  • Pairing keys that identify the parent and child devices to each other
  • App preferences

None of this data leaves the paired devices except to sync directly between them (see Peer Sync below).

Peer sync

PearGuard syncs policies and activity directly between the parent and child devices using the Hypercore Protocol, a peer-to-peer technology. There is no server storing your data and no account. On networks where a direct connection cannot be made, the connection can fall back to the PeerLoom relay described below, which forwards the encrypted traffic without being able to read it. Data is shared only with the specific devices that have been paired.

All sync traffic is encrypted end-to-end, and every policy update is cryptographically signed by the parent device. No third party ever receives or has access to your family's data.

When a direct connection cannot be made

Most of the time the parent and child devices connect to each other directly. On a small number of networks that direct connection cannot be made at all, which matters here because a parent and a child are often on different networks. In that case PearGuard can fall back to a relay that PeerLoom runs, which passes the encrypted traffic between the two devices.

The relay cannot read what passes through it. Your policies and your child's activity stay encrypted end to end and PeerLoom holds no key to them. What a relay unavoidably handles is the fact that two devices are talking, identified by random public keys rather than names or email addresses, along with the timing and the amount of data. The relay keeps no record of it and stores nothing.

The relay is a last resort and never the first choice. The relay can be turned off, in which case PearGuard is purely device to device and will not connect on the rare networks where a direct connection is impossible. Full detail: The PeerLoom relay.

Permissions

  • Accessibility Service (child device): Used to enforce app blocks, time limits and bedtime windows on the child device.
  • Usage access (child device): Used to record what apps have been used and for how long. Data is stored locally and synced only to the paired parent device.
  • Camera & photo library: Used to scan the pairing QR code and to set a profile avatar. Photos are stored locally on your device.
  • Notifications: Used to deliver local alerts such as time requests and approvals. Notification data never leaves the device.
  • Network access: Used for peer-to-peer connections between paired devices, and for the relay fallback described above. No readable data is sent to any server.

No tracking or analytics

PearGuard contains no analytics, no advertising SDKs, no crash reporting services and no third-party trackers of any kind.

No accounts

PearGuard does not require you to create an account or provide an email address. Each device's identity is a cryptographic key pair generated locally.

Children's privacy

PearGuard is designed for use by families. The child device stores activity data locally and syncs it only to the paired parent device. No data about children is transmitted to PeerLoom, Google, Apple or any third party.

Open source

PearGuard is fully open source. You can inspect the complete source code at github.com/peerloomllc/pearguard.

Contact

Questions about this privacy policy? Reach out at peerloomllc@proton.me.

Effective date: April 14, 2026