Most guides to parental control tools focus on one question: how to set them up. Fewer ask a more basic one. Once installed, where does your child’s data actually go, and who else might see it?
Parental controls tools promise a straightforward trade. You give up a bit of your child’s privacy in exchange for a safer online experience for them. That trade only works if the company behind the tool holds up its end. Several well-known parental monitoring apps have failed to do exactly that, leaking children’s locations, messages and even audio recordings to anyone who knew where to look, and each incident is a reminder that installing a tool is not the same as making a child safer by default.
This article looks at parental controls tools from that angle. We cover what these tools actually collect, what UK law requires of them, how official app store versions differ from sideloaded ones, and a short checklist to run through before you install anything on your child’s device. If you’re looking for step-by-step setup instructions across specific devices and UK broadband providers, or a comparison of named tools such as Qustodio and Bark, we link to dedicated guides for both further down this page.
Table of Contents
What Parental Controls Tools Actually Cover
Before weighing up the privacy side, it helps to be clear on what these tools do and why each function needs the level of access it asks for. Most parental controls tools bundle several distinct capabilities, and understanding each one makes it easier to judge which permissions are reasonable for what you’re trying to achieve.
Content Filtering and Screen Time
Content filtering blocks access to websites and apps based on category, keyword or age rating. It typically works at the device level, the network level through your router or broadband provider, or both together for wider coverage across every device in the house. Screen time management sits alongside this, letting you cap how long a child spends on specific apps or the device as a whole, and schedule downtime for homework or bedtime. Neither function needs to know precisely where a child is or what they’re saying to anyone, which is worth keeping in mind when a product bundles them with more invasive features by default.
Location Tracking and Message Monitoring
Location tracking uses GPS to show a child’s whereabouts in real time and can alert you when they enter or leave a set area, sometimes called geofencing. Message monitoring goes further still, giving visibility into texts, social media direct messages and sometimes call logs and full browsing history too. These two features collect the most sensitive data of the bunch, continuously, and often without the child seeing any indication that it’s happening. That combination is exactly why they deserve the closest look before you switch them on, and why the rest of this article focuses mainly on these two categories.
The Question Most Guides Skip: Who Else Sees This Data?
Every one of the features above depends on collecting personal data about your child, often continuously and in real time. That data has to be stored somewhere, transmitted somewhere and protected by someone. This section looks at what happens after collection, since that’s the part most buying guides leave out.
What These Apps Collect, and Where It Goes
A typical parental control tool with location tracking, message monitoring and web filtering enabled will gather GPS coordinates, browsing history, app usage patterns, message content, and sometimes audio from the device’s microphone. This data usually sits on the provider’s servers rather than the device itself, which means its security depends entirely on how well that provider has built and maintained its infrastructure, not on anything you can control once you’ve handed data over. A parent has no visibility into how well that infrastructure is run, and most privacy policies say very little about it beyond generic reassurance.
This is not a hypothetical risk. Kid Security, a parental monitoring app with more than a million downloads on Google Play, has been reported by security researchers at Cybernews twice since late 2023. The first incident exposed activity logs, including phone numbers and email addresses, after the developers failed to secure their database. The second exposed children’s live GPS locations and private messages, left accessible on the open internet for over a year through an unsecured data pipeline, and affected some children whose parents had never even installed the app themselves, because messages sent to those children by monitored friends were swept up too.
mSpy, another long-running monitoring app, has suffered breaches of its own, first in 2015 and again in 2024, each time exposing customer and device data. None of these companies was obscure or newly launched. Each had a substantial user base and years of operating history, which is worth remembering when “established” is used as a shorthand for “safe.”
What the UK’s Children’s Code Requires
UK law has something specific to say about this. The Information Commissioner’s Office enforces the Children’s Code, a set of standards that any online service likely to be used by children under 18 must follow, whether or not it’s specifically designed for them. The Code addresses parental controls directly: it requires that children be informed about monitoring in language appropriate to their age, rather than having it occur invisibly, and it explicitly recognises that parental controls can affect a child’s rights to association, play and freedom of expression, not just their safety.
It also requires geolocation to be switched off by default unless there’s a clear reason to enable it, and sets a general principle of data minimisation, meaning services should collect only what they genuinely need rather than everything they’re technically able to. You can read the Children’s Code standards in full on the ICO’s website.
Compliance is not universal. A 2023 study by the consumer research group Comparitech reviewed over 400 children’s apps on Google Play and found that nearly one in four had privacy policies suggesting a breach of the Children’s Code in some way, most often through unclear or missing details on how a child’s personal data was collected and used. That study covered children’s apps generally rather than parental monitoring tools specifically, but it points to a broader pattern worth being aware of before you trust any app with a child’s data by default, since a polished app store listing tells you very little about what’s happening behind the scenes.
When Monitoring Apps Get It Wrong
Beyond outright breaches, there’s a category of behaviour that sits closer to overreach than protection. Some apps marketed for parental use share technical traits with stalkerware, software designed to secretly monitor a person without their knowledge, most commonly associated with domestic abuse rather than parenting. A 2025 study from University College London compared official parental control apps available through Google Play with sideloaded versions distributed outside app stores, and found that sideloaded apps were considerably more likely to hide their presence on a child’s device altogether, offering features such as disguised icons or the ability to run with no visible notification.
The researchers behind the study noted that once an app removes the safeguards official stores require, such as visibility to the device user, there’s little practical difference between a parenting tool and surveillance software, regardless of how the product is marketed.
Official Store Apps vs Sideloaded Apps
Not all parental controls tools carry the same level of oversight, and where you download one from matters more than most buying guides suggest. This distinction is one of the simplest ways to reduce risk before you’ve even chosen a specific product.
What Official Store Review Actually Checks
Apps available through the Google Play Store or Apple’s App Store must meet baseline privacy and security requirements before being listed, and both platforms conduct at least some review of app behaviour, including whether an app discloses what it collects and whether it can be uninstalled or detected by the device’s user. This is not the same as a full security audit, and listing in an official store is no guarantee that a company’s servers are properly secured, as the Kid Security incidents show. It does, however, rule out some of the more obviously deceptive behaviour that turns a monitoring tool into something closer to surveillance software.
Why Sideloading Removes Those Safeguards
Sideloaded apps, installed directly from a website rather than an official store, skip that review entirely. The 2025 UCL study referenced above found that sideloaded parental control apps were more likely to run without the child’s knowledge, more likely to request permissions beyond what their stated function required, and less likely to disclose their data practices in a clear privacy policy.
None of this means every sideloaded app is unsafe, but it does mean official store apps start from a stronger baseline, and any product that asks you to sideload it or markets itself as invisible to the person being monitored is worth questioning directly before you install it.
A Security Checklist Before You Choose
Choosing a parental control tool doesn’t need to be complicated, but it does benefit from a few minutes spent checking the basics before you hand over a child’s data. The checklist below covers the questions worth asking of any product, regardless of which specific tool you’re considering.
Questions to Ask Before You Install
Ask whether the company publishes a clear and specific privacy policy that names exactly what data it collects, why, and how long it keeps it, rather than a generic statement that could apply to any app. Check whether data is encrypted both in transit and at rest, since this determines what an attacker can actually read if the company’s servers are ever breached, and whether the provider states this explicitly rather than leaving it to be assumed.
Look at how long the company has operated and whether it has a public record of past incidents. Somewhat counterintuitively, a company that has already suffered and publicly disclosed a breach has at least demonstrated it will tell you when something goes wrong, which is not something every provider does. Confirm the app is available through an official app store rather than only sideloaded, and check what happens to the data collected, including your child’s location history and messages, if you cancel your subscription or delete the app.
Securing Any Connected Hardware You Add
Some families extend monitoring beyond apps to physical devices such as GPS trackers, smart cameras or baby monitors, and these carry a separate set of risks worth checking before use. Since April 2024, the Product Security and Telecommunications Infrastructure Act has required manufacturers of these connected devices to stop shipping them with default passwords that can be easily guessed or found online, and to provide a public way to report security flaws.
If you’re adding hardware such as a child-tracking device to your setup, checking that it meets this baseline, and setting a unique password immediately if it doesn’t ship with one, closes off one of the more common ways these devices get compromised. This matters just as much for older devices bought before the law came into effect, since many will never receive a security update that brings them up to the current standard.
Where to Go Next
This article has focused on evaluating parental controls tools before you commit to one, rather than on setting a specific product up or comparing named brands. Both of those next steps are covered elsewhere on this site, and it’s worth reading whichever applies to where you are in the process.
If you’ve already decided what to look for and want a comparison of specific tools, including Qustodio, Bark and Norton Family, see our guide to the best parental control tools and how to use them effectively. If you want step-by-step setup instructions across UK broadband providers, mobile networks, gaming consoles and streaming services, our full guide on using parental controls effectively for internet safety covers that in detail, including age-appropriate ways to talk to your child about why controls are in place.
For the wider context on why children’s data deserves this level of care in the first place, our guides to safeguarding children’s privacy and children’s online safety are good next reads. If encryption and data storage are unfamiliar territory, our explainer on data encryption covers the basics referenced in the checklist above, and our guide to strong passwords is worth reading before securing any connected tracking device, since a weak password undoes most of the other precautions in this article. Keeping any app or device updated matters too, not just at setup but for as long as your child uses it.
Our piece on regular software updates explains why patches matter as much as the initial configuration, and applies equally to the parental controls tools covered here and to the devices they run on.
FAQs
These are the questions that come up most often once parents have decided to look into parental controls tools properly, rather than just how to switch them on.
Can parental control apps be hacked?
Yes. Several well-known apps, including Kid Security and mSpy, have suffered data breaches that exposed children’s locations, messages and account details, in some cases for over a year before anyone noticed. Choosing an app with a clear security track record and encrypted data storage reduces this risk but does not remove it entirely, since no company can guarantee it will never be breached.
Is my child’s data shared with third parties?
This depends entirely on the app’s privacy policy, which is why checking it before installing matters more than checking a star rating. Under the Children’s Code, UK services should not share a child’s data unless there’s a clear reason to do so, but not every provider complies fully, so it’s worth reading the policy yourself rather than assuming the app store listing has already checked this for you.
Are official app store versions always safer than sideloaded ones?
Generally, yes. Official store apps go through some level of review and must meet baseline requirements before they’re listed. A 2025 UCL study found that sideloaded parental control apps were more likely to hide their presence on a device and to request permissions beyond what their functions required, though being listed in an official store is not a guarantee of complete safety on its own, as the breaches covered above make clear.
Do parental control apps need my child’s consent?
Under UK GDPR, children aged 13 and over are generally able to give or withhold consent for their own data to be processed. In practice, most parental control apps are installed by a parent on a device the parent owns or manages, so the legal position can be less clear-cut than it first appears. Having an open conversation with your child about what’s being monitored, and why, is worth doing regardless of where the legal minimum sits.
What should I do if I think a parental control app has leaked my child’s data?
Change any passwords linked to the account, including on any other service where your child reused the same password, and check whether the company has published a statement about the incident. Consider switching to an alternative with a stronger security record if the company’s response is slow or vague. You can also report concerns to the ICO directly if you believe a UK data protection obligation has been breached.
How can I tell if a parental control app is hiding on my child’s device?
A legitimate parental control app should be visible in the device’s app list and should notify the child it’s installed, in line with the Children’s Code requirement covered earlier. If an app has no icon, cannot be found in settings, or is marketed specifically as undetectable, treat that as a warning sign rather than a feature, since those are the same characteristics security researchers use to identify stalkerware.