GOT THAT
Privacy Policy
Effective 9 September 2026. Last updated 9 September 2026.
Got That sends short voice messages from a parent's phone to a paired family phone. Recordings are encrypted on the sending phone and can only be decrypted on a paired recipient's phone. We never receive the sound of your voice.
Who is responsible for your data
Got That is provided by Objektiv, based in Australia. Objektiv is the data controller for the information described in this policy.
Privacy questions, requests and complaints: info@objektiv.com.au.
The two roles in Got That
- Parent. Signs in with Google, Apple, or an email address and password. Creates the family, invites and approves devices, records and sends messages.
- Child. Receives messages, replays them from a private inbox, and can reply "Got it". A child does not need a Google account, an Apple ID, an email address or a phone number, and is never asked for one.
A child's phone is identified only by a restricted anonymous credential created on that device. Children cannot record or send messages, cannot contact anyone outside the family, and cannot see or reach other Got That users.
Information we collect
Parent account information
- Email address, and the display name supplied by your chosen sign-in provider.
- The account identifier issued by Google, Apple or Firebase Authentication.
- Whether your email address has been verified, and which sign-in methods you have linked.
We never receive or store your Google or Apple password. If you use email and password sign-in, your password is handled by Firebase Authentication and is not visible to us.
Family and device information
- A family identifier, and an identifier for each paired phone.
- A short display name for each person or phone, up to 40 characters, chosen by you or on the phone itself.
- Each device's role — owner, parent or child — and whether it is currently active.
- Public encryption keys and device-trust records used to verify that a message came from an approved phone.
- Invitation records used for one-time pairing, and the verification phrase shown on both phones.
Message information
- Encrypted audio. A recording of up to 15 seconds, encrypted on the sending phone before it is uploaded. We hold only the encrypted file.
- Delivery metadata. Message identifiers, which paired devices a message was addressed to, timestamps, whether the message was sent as normal or urgent, and its delivery state.
- Replies. Whether a recipient tapped "Got it", and when. This is a fixed acknowledgement, not free text.
Technical information needed to deliver a message
- Push notification tokens from Google (Firebase Cloud Messaging) and, on iPhone, Apple Push Notification service.
- Standard server request records, including IP address, timestamps and error information, produced by Google Cloud when your phone contacts our service.
- App integrity assessments from Google Play Integrity, used to confirm requests come from a genuine, unmodified copy of Got That.
What we do not collect
- We do not show ads, and we do not use any advertising SDK.
- We do not collect or transmit the Android advertising ID, IMEI, SIM serial or MAC address.
- We do not use analytics or crash-reporting SDKs. Got That contains no Google Analytics, no Firebase Analytics and no Crashlytics.
- We do not collect location, contacts, calendar entries, photos, files, health data, card numbers or bank account details.
- We do not receive the plaintext of any voice recording.
- We do not sell personal information, and we do not use your data for advertising, profiling or automated decision-making.
- We do not build advertising or behavioural profiles of any user, and never of a child.
Microphone and camera
Microphone. Got That requests microphone access only for the parent's record button, and records only while a parent is deliberately recording a message. Nothing is captured in the background and there is no continuous or ambient listening.
Camera. The camera is used only to scan a pairing QR code. The scan is processed on the device by Google Play services and the camera image is not uploaded or stored by us.
You can decline or later withdraw either permission in your phone's settings. Got That will explain what stops working rather than continuing without it.
How your voice messages are protected
Each recording is encrypted on the sending phone for the specific paired recipients before it leaves the device. The keys required to read it stay on family devices. Our servers, Google's storage, and anyone inspecting network traffic hold only ciphertext. The recording is decrypted on the recipient's phone immediately before playback.
Because encryption protects the content, not the fact that a message happened, we can still see the operational metadata listed above — who sent to whom, when, and whether it was delivered and acknowledged. We use that only to run and secure the service.
How we use information
Family subscriptions. If the family owner subscribes, Apple or Google handles payment. We receive and store subscription identifiers or purchase tokens, plan and billing-store information, expiry and renewal status, and the association with the owner's Got That account and family. We keep a trial-use record for the owner. We use this information to verify purchases, provide family access, handle renewals and refunds, and prevent one purchase being assigned to unrelated families. Invited parents and children do not provide payment information.
- To create a family and pair devices you have approved.
- To route, deliver, replay and acknowledge messages.
- To show delivery status and an explicit reply, kept visibly separate from one another.
- To keep the service secure — verifying approved devices, blocking abuse, and enforcing sending limits.
- To fix faults and respond to your support requests.
- To meet legal obligations.
If you are in the European Economic Area or the United Kingdom, we rely on performance of our contract with you for account, pairing and delivery data; your consent for microphone access and notifications; and our legitimate interests in keeping the service secure and working.
How long we keep it
- Encrypted recordings: deleted within 24 hours of upload, and normally sooner. An upload reservation that is never completed expires after 5 minutes.
- Family, device and message metadata: kept while your family exists, and removed when you delete your account or the family.
- Parent account records: kept until you delete your account.
- Subscription and trial records held by Got That: kept while the owner's account exists and removed during account deletion. Apple and Google retain their own payment records under their policies. Deleting Got That does not cancel store billing.
- Server and security logs: retained for a short period under Google Cloud's standard log retention, then deleted automatically.
A message that has been prepared on a recipient's phone may remain in that phone's protected on-device inbox until it expires. That copy is on the device, not on our servers, and is removed when the app is uninstalled or the account is deleted.
Who else is involved
We do not sell or rent personal information and we do not share it for advertising. We use a small number of service providers who process data on our instructions:
- Google (Firebase and Google Cloud) — authentication, database, temporary encrypted storage, server functions, push notifications via Firebase Cloud Messaging, and abuse prevention via App Check and Play Integrity.
- Apple — Apple Push Notification service, Sign in with Apple if you choose it, and App Store subscription billing and verification.
- Google Play — subscription billing and verification for purchases made on Android.
We may also disclose information if we are legally required to, or to protect the safety of users or the integrity of the service.
Where your data is processed
Got That runs on Google infrastructure. Message handling currently takes place in Google regions in Australia and in the United States. Push notifications are delivered through Google's and Apple's global networks. Where personal information is transferred out of your country, we rely on the safeguards offered by those providers, including standard contractual clauses where applicable.
Children's privacy
Got That is intended to be set up by a parent or guardian and used by their own family, including children. We deliberately designed the child role to need as little information as possible.
- A child is never asked for an email address, phone number, real name, date of birth, photo or location.
- A child's phone uses a restricted anonymous credential and does not hold the family's root key.
- A child cannot record or send messages, cannot add anyone to the family, and cannot communicate with anyone outside the family a parent approved.
- There are no ads, no advertising identifiers, no analytics and no profiling of children.
- The only information a child provides is a short nickname for their phone, so a parent can tell devices apart.
A child device can only join after a parent creates a single-use invitation, both phones display the same verification phrase, and the parent approves the device. A parent can revoke any paired device at any time from the app, which immediately stops delivery to it.
A parent or guardian may review, correct or delete the information associated with their child's device by removing the device in the app, deleting the family, or contacting info@objektiv.com.au. We do not knowingly collect personal information from a child except as described here, and we do not condition a child's use of Got That on disclosing more than is reasonably necessary.
If you believe a child has provided us information without a parent's involvement, contact us and we will delete it.
Your choices and rights
- Delete your account in the app. Open Got That, go to the account screen, choose Delete account, type the confirmation and re-authenticate. See account deletion.
- Revoke a device at any time from the family screen.
- Withdraw a permission — microphone, camera or notifications — in your phone's settings.
- Request access, correction, deletion or a copy of your information, or object to our processing, by emailing info@objektiv.com.au. We will respond within 30 days.
Australian users may complain to the Office of the Australian Information Commissioner. Users in the EEA or UK may complain to their local data protection authority.
Deleting your data
Deletion immediately revokes every paired phone in your family. The service then removes family metadata, encrypted recordings, child device identities and sign-in accounts, retrying automatically if a provider is briefly unavailable. If you are a parent member rather than the family owner, deletion removes your own account while the family and its other phones continue to work.
You do not need to install the app to ask us to delete your data. Full instructions, including an email route, are on the account deletion page.
Security
Voice recordings are end-to-end encrypted between family devices. All network traffic uses HTTPS; the apps refuse unencrypted connections. Requests are authenticated, senders are verified against approved device keys, and app data is excluded from device backups. No service can promise perfect security, but we work to protect your information and to fail safely when something goes wrong.
Not for emergencies
Got That is for everyday family coordination. Delivery and automatic playback depend on connectivity, permissions, notification settings and the phone's audio state, so Got That must not be relied on for emergencies or urgent safety needs.
Changes to this policy
If we change how we handle your information we will update this page and its effective date, and where the change is significant we will give notice in the app or by email before it takes effect.
Contact
Objektiv, Australia — info@objektiv.com.au. See also support.