PROTECT + PARENT · PRIVACY
Privacy Policy
This policy covers our parental monitoring apps. Read the separate Vela EV policy.
Last updated: September 23, 2026
Vela Fox is a visible, guardian-configured parental-safety tool for Android. Vela Fox Protect performs safety analysis on the protected phone. Vela Fox Parent can receive selected safety findings directly from a specifically approved nearby Protect phone. Vela Fox does not upload monitored content to a cloud analysis service or use it for advertising. Subscription verification is separate from local safety analysis.
Advanced's small website installer downloads 2.21 GB of static analysis data from velafox.com only when you choose Download & check my phone. Downloads use HTTPS, resume in bounded parts, and are verified against checksums embedded in the signed app before use. These requests contain no child content, findings, family code or subscription token. The hosting provider processes ordinary delivery metadata such as IP address and requested file ranges. Temporary download data stays in app-private storage and is removed after successful preparation; clearing app storage or uninstalling also removes it. The phone check uses invented samples. Subsequent content analysis runs locally. Downloading analysis data does not grant monitoring access; an active Premium family entitlement is still required.
The family owner subscribes through Google Play in Vela Fox Parent. Eligible new subscribers receive a seven-day free trial followed by the selected recurring price. Eligibility and localized prices come from Google Play. Essential covers one protected child phone; Premium covers up to five, adds Ask Vela Fox, and enables the optional Advanced website edition. Up to five parent/caregiver installations share the family subscription without a second purchase. Child and caregiver phones join using private, ten-minute, single-use codes; matching Google accounts are not required. Existing internal QA builds are not public subscription offers.
Subscription verification sends a Google Play purchase token/product, a random installation identifier and the app edition to Vela Fox LLC’s billing service at velafox.com over HTTPS. The service checks status with Google Play and retains only encrypted purchase tokens, token digests, random family/device identifiers, device role, plan/status/expiry and verification timestamps. It stores refresh credentials only as hashes. Phones encrypt their refresh credential using Android Keystore and retain an installation-bound signed access lease with backup disabled. No message, photo, alert, location, question, analysis, Google email, child name or payment-card details is included. A verified offline lease lasts no more than 72 hours and never beyond paid access; after reboot it needs an online refresh. Cancellation retains access until the verified paid period ends. Refunds, revocation and family removal take effect at the next successful check or lease expiry; they cannot instantly reach an offline phone. Linking does not copy evidence or Android permissions between editions.
The billing database uses our website hosting infrastructure. Expired invitation and rate-limit records are removed during scheduled or request-triggered cleanup. Rate limiting uses short-lived, salted network-address digests, not raw IP addresses; ordinary hosting/network logs may separately process network metadata. Inactive device credentials expire after 90 days. Family purchase records are removed after 90 days have passed since both paid access ended and the last verification. The family owner can remove individual phone links or delete family billing records in Vela Fox Parent → Settings → Family plan. Deletion is permanent for those service records and does not delete on-device evidence or cancel Google Play renewal. Cancel renewal separately in Google Play. Restoring an active purchase creates verified family access again. Contact support@velafox.com for deletion assistance; never send child evidence, passwords or purchase tokens.
When subscription access ends, new monitoring and analysis pause. Existing findings, deletion, disconnect and privacy controls remain available through Parent access. Local beta access codes cannot activate a commercial build. Installing Advanced pauses new collection in the updated Play edition to avoid duplicate monitoring; each edition keeps its own vault, permissions and pairing. Subscription and plan choices do not silently turn monitoring on.
Coverage diagnostics show app identities, useful/unavailable notification-preview counts and timestamps from the current listener session. They remain bounded and memory-only on Protect, are hidden when monitoring is inactive, and are not sent to Parent. They describe delivery rather than unique messages or completed AI analysis. Shared-item review lets the user confirm or edit the received text before analysis; edits are not saved as drafts. Vela Fox does not open shared links or download the content behind them. Findings can include flags explaining that only link text or truncated text was checked.
A guardian can run a notification delivery check from Protect's Parent mode. It posts one silent, content-free test notification with a short-lived random receipt token and waits up to 15 seconds for Android delivery. The test notification is removed after completion, cancellation or timeout. Its receipt stays in memory while the check view is open; it never enters app-preview counters, AI analysis, the finding vault or nearby transfer. A successful receipt tests only this notification path. Parent's update-age display uses the existing locally stored completed-sync timestamp, not a new feed of the protected phone's current health or location.
Parent conversation prompts are locally selected, code-authored suggestions and do not send messages. Optional app safety guides open a bundled official URL in an external browser without attaching findings or account details. These app safety guides do not link external accounts or verify settings made in those apps; the destination provider's own privacy practices apply.
Child support resources
Find support is available on the child phone without a parental PIN or paid subscription. It contains fixed educational guidance and a versioned directory of professional resources; no model generates advice or links. In Protect's PIN-protected Parent mode, a guardian may explicitly confirm a recent high-priority finding after reviewing its evidence and context, then offer a quiet child support notification. A model score, two agreeing image checks, or a generic reviewed flag cannot send it automatically. Low/medium, abstained, uncertain visual and older-than-24-hour findings are excluded. The notification contains no evidence, sender, topic, risk score or accusation, uses a generic lock-screen preview, and expires after 24 hours. At most one support notification is offered in 24 hours; Android notification settings can block delivery.
Only the latest notification time and fixed suggested-topic identifiers are kept in an Android-Keystore-encrypted, backup-disabled record on the child phone. Topics stop being suggested after 24 hours; expired metadata is deleted the next time support opens. No resource clicks, reading history, help requests or child responses are recorded or sent to a parent or server. Support can always be browsed without accepting a notification. Confirming a finding here is a guardian's judgment, not a clinical diagnosis or verified proof of an incident.
External resources open only after a separate user choice and notice. Vela Fox opens only a bundled HTTPS address, with no alert identifiers, evidence, query parameters or referral tracking attached. The external browser and organization then apply their own network, cookie and history practices. Crisis numbers are region-labeled. This is educational signposting, not counseling, emergency dispatch or continuous safety monitoring; inclusion does not imply endorsement by the resource provider.
Data Vela Fox processes
Depending on features a guardian enables, Vela Fox Protect may process:
- text, sender labels, app identifiers, and conversation labels exposed by Android notifications;
- source-supplied messaging-notification timestamps, group/direct markers, message direction, historic context, attachment descriptions, and temporary readable `content://` image references when an app exposes them through Android's structured notification APIs;
- up to 30 photos or videos explicitly selected through Android's photo picker; the Google Play edition has no automatic photo-library access. Only the separate Advanced or internal managed editions may use an independently enabled library permission for recurring photo checks or Parent-selected 1–1,000 newest/date-range shared-library photos;
- text extracted locally from those images;
- transient image pixels and local sexual/graphic/safe softmax class scores while an enabled photo scan is running;
- browser page titles, web addresses, and visit times from a bounded history-export file a parent explicitly selects through Android's document picker;
- aggregate foreground-app time and last-used time that Android provides only after the device owner enables special Usage Access and a parent opens the Activity screen;
- bounded foreground-session counts, longest-session duration, late-night duration, rapid returns, and hourly/daily interval charts derived from Android Usage Access events, plus separately labeled prior-period Android aggregates;
- normalized DNS domain names, best-effort originating app labels, first/last observed times, and aggregate lookup counts while a parent-enabled Local Web Shield is visibly active;
- Android network-number-verification state, call direction, and a salted process-memory repeated-attempt count when the user selects Vela Fox for the optional call-screening role; Vela Fox does not record call audio or read call history;
- text, images, video frames, or short audio files that a user deliberately sends to Vela Fox through Android's system media picker or Share sheet for a bounded local review;
- a Parent-selected 100–10,000 newest inbox/sent SMS rows, globally or within one existing SMS thread, during a user-confirmed temporary default-SMS handoff in the separately distributed managed build; while Vela Fox holds that role, Android also routes ordinary incoming SMS and user-initiated system reply-via-message SMS through Vela Fox;
- precise GPS fixes, speed, bearing, and timestamps while a visible, parent-enabled automatic trip detector remains active, including while the app UI is minimized or dismissed; force-stop, reboot, or loss of its visible foreground notification stops collection;
- Parent-created place-boundary names, categories, centers, radii, enabled state, and confirmed arrival/departure times;
- aggregate trip measurements and a short locally generated trip narrative; precise coordinates, addresses, place names, dates, and identities are not included in the narrative-model prompt;
- transient device-orientation readings while the decorative child-status logo is visible and motion is enabled;
- locally generated risk scores, categories, explanations, and limited evidence;
- cryptographic device identities, pairing records, delivery status, and minimal routing metadata needed for direct Bluetooth synchronization.
Vela Fox cannot bypass another app's encryption or sandbox. It cannot reliably see muted, hidden, deleted, disappearing, or redacted messages. The Google Play build does not read the Android SMS provider and does not become the default messaging app. Usage Access does not reveal screens, keystrokes, URLs, messages, or what happened inside another app.
Notification intake excludes SMS-capable apps, the default phone app, apps declaring SMS or Call Log permissions, and call/missed-call/voicemail notifications. Entire mixed SMS/RCS sources are excluded because their transport cannot be reliably separated from notification metadata. Vela Fox checks only the posting package's manifest and current default-handler information before reading preview extras or opening media references; it does not enumerate or store the installed-app inventory. If Android does not expose enough package information, that source is skipped. These exclusions also apply to reconnect catch-up and manual active-notification scans. They do not change the separately authorized Call Screening API or the managed edition's explicit SMS-role workflow. No accessibility capture, keyboard recording or automatic screen capture is implemented.
Android does not provide a general permission for Vela Fox to read modern browsers' private history databases. A browser-history scan therefore works only after the parent exports, downloads, and selects a file through Android's document picker. Vela Fox can recognize a supported standalone export or history file inside the selected archive, but it cannot automatically locate a file in Google Drive or Downloads. It normalizes each visit, removes credentials, fragments, and non-search query fields, then locally checks the hostname, URL path, retained search fields, and title with bounded safety rules and analysis. It does not fetch web pages, recover deleted or private/incognito visits, or retain a complete history database.
Optional Google account reviews
Setup and Parent Settings offer separate read-only Google permission flows for Gmail, Calendar, Drive/Docs, and Tasks. The Google account owner must authorize each scope; parental access to Vela Fox does not bypass Google's account consent. All sources on a phone use the same selected account until disconnected. Account subject, email, chosen source flags, and last-completed-review times are device-bound encrypted. They are not included in nearby transfers. Authorization tokens exist transiently in memory for the current request; Google Play services manages its own consent/token cache under Google's terms.
Reviews run only when the parent taps **Connect & review** or **Review now**, and stop when the originating parent authorization expires or the screen closes. They are not continuous account monitoring. Gmail checks up to 25 recent messages from 7 days (supported plain-text bodies, subject and sender; no attachments or remote images). Calendar checks up to 50 primary-calendar events from the preceding 7 days through the following 7 days (summary, description, location, and event time). An event is not proof of attendance. Drive/Docs requests broad `drive.readonly` consent and checks text exports of up to 10 Google Docs modified in 7 days; it does not scan other file types, comments or embedded media. Tasks checks up to 50 incomplete tasks in the default list (title and notes). Limits, unsupported text, and incomplete passes are shown. Other calendars/task lists are outside this pass. Android's Share to Vela Fox remains an alternative for selected files without broad Drive access.
Supported source text is bounded to 16,000 characters per item and HTTPS responses to 2 MiB. Safe content is not persisted by Vela Fox. A concerning item can enter the existing encrypted finding vault and its approved nearby transfer queue; there is no upload of Google source content to a Vela Fox server or model-training service. Google receives ordinary authorization, account identity, read-only API, and revocation requests. Google-sourced findings remain subject to the same 90-day/1,000-finding retention and parent deletion controls. **Disconnect Google** requests access revocation and deletes local connection/receipt metadata; it does not delete findings already retained or transferred. Revocation failure is shown explicitly. Google Cloud app registration, enabled APIs, and required scope verification remain prerequisites for public availability.
Interactive analytics and appearance
Activity charts, service counters, and network exploration run locally behind Parent access. Usage reports remain ephemeral; Android's detailed event retention and lifecycle gaps can make session charts differ from aggregate app totals. The usage total includes all eligible reported apps even when only the top 50 rows are shown. Service failure/drop counters describe the current process lifetime. Interactive/import text-review telemetry retains cumulative completion/failure/cancellation counts, source-type counts, and the newest 120 completed review durations in memory. It contains no source text, account identifiers, event IDs, or timing history on disk; latency percentiles apply only to those retained samples and do not include the separate notification queues or image/audio pipeline. Missing observations do not establish zero activity or complete coverage.
Insight studio adds a parent-only saved-finding heatmap and source composition using the existing encrypted finding metadata. Its four-hour cells use saved-record time, which can reflect batch import or processing rather than incident time. A separately requested device snapshot reads battery level, power-saving state, thermal pressure, available memory/storage and the availability of motion/light sensors; it does not sample those sensors or inspect files. Choosing device and app signals additionally uses Usage Access for foreground reports and daily Wi-Fi/mobile byte totals for the current Android user. No subscriber identifier, network name, destination, packet body or browser URL is requested. Vela Fox may read install/update timestamps and version metadata for up to 32 apps already present in that usage report; it does not enumerate the full installed-app inventory. Snapshots stay in memory, are discarded on backgrounding/leaving, and are not stored, synchronized or converted into safety alerts.
The evidence network offers a three-axis layout with perspective, touch rotation, depth controls, selected-node labels and community isolation. Graph geometry is presentation, not a risk score or identity inference. Optional slow orbit runs only while resumed and pauses under power-saving or reported thermal pressure. Theme, severity, source, app, source-provided sender and time filters apply before selecting at most 72 findings for the graph. These filters also respect the existing Alerts search. Bounded app/sender labels already present in decrypted saved evidence remain in the unlocked graph's memory. Vela Fox does not read a contact book or verify these identities. Sender filter keys are scoped to source/app and, on Parent, authenticated protected-phone identity; matching names are not merged across these boundaries.
Parents can ask Vela Fox questions or request a summary of measured facts in Insight studio. This fact view supplies bounded code-derived counts, status, scope and limitations to the existing on-device engine. Vela Fox’s local analysis selects relevant fact references or declines an unsupported question; code supplies the displayed facts. This measured-fact path does not send questions to another phone or automatically add messages, identities, routes or browser URLs.
Separately, selecting a graph finding opens evidence-specific questions in both apps. The parent chooses that finding or up to four findings from its community (the selected finding, then the most recent others), and presses Ask or Summarize. This supplies the question (up to 400 characters), up to 600 characters of saved text per selected finding, saved app/sender labels, source, categories, severity and timestamp to Vela Fox’s local analysis. The screen explains truncation and scope before submission. It does not include images, audio, other messages or implicit access to the vault. Vela Fox may write a short interpretation citing only the supplied findings, or decline when evidence is insufficient. Code validates references and output bounds, but citations do not independently establish that the model's interpretation or a source claim is true. Answers are labeled as AI interpretations that require evidence review.
In Protect's Parent mode these questions run on that phone. In Vela Fox Parent, the selected received excerpts and question are sent back only to their authenticated protected phone through an already paired, active, visible live Bluetooth session; the answer returns through the same connection. The channel uses the existing ephemeral AES-256-GCM session encryption with direction/message-bound authentication and separate replay sequences from alert transfer. Both apps must support this optional capability. An old app, missing live connection, expired Protect trial, unavailable model or busy safety engine cannot silently fall back to a cloud service. Parent uses internet access only for Google Play and content-free family subscription verification; this question channel remains local. This question channel grants no remote vault browsing, permission changes or other device actions.
Questions, answers and intermediate evidence context are transient and are not written to a history, analytics system or Vela Fox server. The review clears on backgrounding, leaving or a changed evidence selection. Canceling, locking Parent or disconnecting drops late replies and requests cancellation of remote work when the connection remains available; work already running in native model initialization may take time to stop. Optional questions use the existing model engine only when it is idle, are bounded and rate limited over Bluetooth, and do not enter the alert vault or pause the alert-transfer protocol.
Evidence networks compare text and timing patterns across recent eligible findings. Graph selection, layout and commentary remain in memory and clear with the parent session. Parent partitions graphs by authenticated protected-phone identity and excludes unknown-origin findings from cross-record relationships. Similarity reflects patterns in the available text; it is not a calibrated probability, proof of a shared person or cause, or confirmation of harm.
Both apps save palette, custom accent/surface, corner, aurora, and motion preferences only on their respective phones. Aurora can be disabled entirely or left static; animated drift pauses when backgrounded, when Android disables animations, or during Battery Saver. Vela Fox does not send these preferences or UI interactions to an analytics service.
Local processing and storage
In Vela Fox Parent, a guardian can keep an alert as New, Follow-up, or Reviewed. The decision and its time are encrypted using that parent phone's vault identity. These decisions are readable only in an unlocked vault, are not included in nearby transfers, and are not shared with the child or another parent. They are removed when the associated alert is deleted or expires under the same retention ceiling. Follow-up is a saved list status and does not schedule a reminder. Reviewed does not confirm an assessment or establish that a situation is safe. If a saved decision cannot be authenticated, Vela Fox shows the status as unavailable and keeps the alert needing review.
Both Vela Fox Parent and Protect request Internet and network-state access for minimal family subscription verification. Protect also uses them for its separately enabled DNS-only Local Web Shield and explicitly authorized Google API reviews. Child-content analysis remains local. Google Play Billing also communicates with Google for offers, purchases and subscription management. Google Identity Services handles account permission grants and revocation; supported source text is read directly over HTTPS from Google and analyzed on this phone. No Google access or refresh token is stored by Vela Fox. The shield creates an Android VPN interface that routes only a virtual DNS address, relays each supported DNS request to the resolver Android was already using on the underlying network, and analyzes the normalized domain locally. It has no Vela Fox server or remote VPN gateway and does not route or inspect general traffic. Safety rules, enhanced analysis, visual/audio classification, indexing, and English text recognition run on the protected phone using app-bundled models and runtimes. While visible Protection is active and Android's notification listener is connected, Vela Fox automatically processes useful preview text when Android delivers a new or updated notification. A bounded plaintext-free digest cache suppresses identical callback versions, and a bounded active-preview catch-up covers short service or listener-rebind gaps; it does not recover app history or content Android no longer exposes. The Google Play edition analyzes only selected or explicitly shared media and does not monitor new photo-library items automatically. Upgrading from a previous broad-access Play version turns off that library path and cancels its scheduled work; saved findings remain available. In the separate Advanced and internal managed editions only, optional automatic media intake has its own maximum of 250 images per worker run and checkpoints after each 25-photo batch; the Parent's 1–1,000 manual choice does not reduce that automatic bound. With full access, a debounced MediaStore observer requests a prompt newest-changed pass, but Android may delay, combine, or omit callbacks while the process is stopped, so a separate 30-minute cursor catch-up remains enabled. The two worker paths are serialized, and a bounded content-free media-version ledger suppresses unchanged duplicate decoding. Photo queries merge items from mounted Android shared-media volumes. Full Android photo access is required to cover all shared-library images; selected-photo access covers only the selected subset and does not provide an all-new-photo feed. App-private, disappearing, unsaved, or cloud-only media that Android does not expose is unavailable.
Web Shield stores at most 500 recent domain/app aggregates for 30 days in Android-Keystore-sealed app-private storage. A DNS lookup can be caused by an app, advertisement, notification, prefetch, or background service and is not proof that a person visited a page. Vela Fox does not receive a full URL, path, query, search text, HTTPS page body, password, or decrypted connection. Private DNS, DNS-over-HTTPS, cached results, IPv6 traffic outside the shield's IPv4 virtual-DNS route, another VPN, unsupported transport, and Android/OEM behavior can reduce coverage. A bundled, locally evaluated index of sites whose primary purpose is explicit adult content and conservative hostname rules may create a rate-limited review alert, but that alert states that the page and requesting person were not observed. Each canonical match has a six-hour in-process cooldown; attacker-controlled keyword hostname rules additionally share an eight-alert burst bucket that refills by one every six hours. The default control is Alert only. A guardian may choose Block + alert, which returns a local DNS name error only for a high-confidence indexed adult-domain suffix; keyword-only, self-harm, and drug-sale hostname findings are not blocked. Matching address-family requests wait on one serialized alert decision, and a matched indexed request is allowed normally unless its encrypted alert was already durably stored. The list and rules can become stale or make mistakes, and cached addresses or encrypted/private DNS can bypass a DNS response. If Android unexpectedly ends the local tunnel, Vela Fox keeps its foreground disclosure visible and retries locally with a delay capped at one minute; monitoring and blocking are unavailable during that window. The feature requires a prominent in-app disclosure, affirmative guardian consent, Android's VPN approval, a system VPN indicator, and Vela Fox's persistent Web Shield notification; it can be turned off without disabling normal device networking.
Every successfully decoded photo is orientation-corrected and bounded to one in-memory bitmap, then receives an attempted three-class local-model pass before OCR. Every sexual-content candidate, including a strong score, requires an additional contextual image check before medium/high-priority alerting. That check distinguishes ordinary skin, arms, foreheads and other nonsexual close-ups from visible sexual evidence. An ordinary result creates no visual alert. Unclear, conflicting, unavailable and over-budget reviews remain low-priority findings that parents can filter separately. Strong graphic-content findings may still stand on the first check. Uncertain photos continue through attempted text recognition so independent text risk can remain higher. At most 12 candidates per photo scan may receive an enhanced local image label under a 45-second coroutine cancellation deadline. That deadline requests native cancellation, but synchronous native initialization is not proven interruptible and remains a device-qualification requirement. Vela Fox’s enhanced analysis uses a GPU image path with one image per conversation; it is never allowed to author stored image descriptions, identity, age, or evidence facts. Decode and classifier failures are counted. An item whose second review is unavailable, failed, or timed out is reported as incomplete and is not promoted to medium/high visual priority. A medium/high visual finding skips OCR, which is reported as an intentional text-coverage omission; any encrypted-storage failure is separately reported. A stale authorization or background-generation fence stops the scan before its cursor advances. Scheduled decode, classifier, or storage failure preserves the prior cursor and requests bounded retry rather than silently skipping that batch. Vela Fox attempts visible-English-text recognition on safe and low-priority visual items. OCR initialization failure does not disable the independent visual check and is disclosed as partial text coverage. Ambiguous visual candidates receive a bounded second review when available, with an approved label and matching visible-evidence basis. Ordinary skin, foreheads, limbs, shoes, or an unclear crop alone do not support a sexual-content label. Strong sexual signals never retain a medium/high visual rating without a supporting second check; unresolved sexual candidates are kept at Low and conflicting checks are not promoted to Medium. Image confidence is shown as a qualitative support level with its validation result, not as a probability of harm. Older alerts retain their original ratings and may have no recorded confidence. These models can miss unsafe content and can flag benign material. Vela Fox does not detect or determine CSAM and does not infer whether a depicted person is a child.
Decoded pixels, classifier tensors, and the bounded in-memory image encoding used by Vela Fox’s enhanced analysis are recycled or wiped after each item and are not persisted. Raw content that does not cross the safety threshold is not added to the alert vault. Only a threshold-crossing finding can cause the existing reduced, size-limited evidence image to be encrypted in the vault. For escalation analysis, up to ten recent previews from one conversation may remain in volatile memory for at most fifteen minutes; at most 64 conversations are retained, each preview is clipped to 1,200 characters, and each temporary analysis context is capped at 8,000 characters. Urgent deterministic work uses a separate 128-item memory queue. Up to 32 selected deeper reviews, including their bounded context, may wait encrypted on this phone for up to 24 hours measured from the oldest included preview. This temporary queue uses authenticated encryption with a separate Android Keystore key in app-private storage excluded from backups. Waiting content is decoded only briefly for storage recovery or an allowed idle review. App-process restarts preserve the original expiry; a phone reboot or unavailable clock identity invalidates the queue. Completed items are removed. Expired or invalid files are removed when Vela Fox next runs and cannot be analyzed. Turning protection off, losing notification access or monitoring entitlement, or purging alert history erases waiting reviews and destroys their encryption key. A temporary service/listener restart pauses work without granting new access. Overflow is counted and dropped; expired, dropped or unprocessed items are never marked safe. The separate live context buffer remains memory-only and is cleared on listener changes or process exit.
The Parent-only App activity view queries Android only while that screen is opened or refreshed. It offers today, seven-day, and thirty-day aggregate foreground-time and timing-pattern views, excludes common operating-system surfaces, and may show a package identifier when Android does not expose an application label. Vela Fox does not save, place in the alert vault, or transfer the resulting list. The child-facing status screen visibly reports when Usage Access is enabled. Session timing is not classified as harmful content.
Content deliberately selected or shared to Vela Fox is bounded before review: at most 30 system-picker media items or ten Share-sheet items, 24,000 text characters, or 30 seconds/24 MiB of audio. A selected/shared video must be no larger than 512 MiB and no longer than 20 minutes. Vela Fox deterministically chooses at most 24 small still frames, one from each evenly distributed time stratum, and uses exact-nearest frame decoding against a best-effort 90-second soft budget. Authorization and time are checked around each native extraction and classification call, but synchronous native work may return after the soft boundary. A video is skipped below 20% battery unless the phone is charging. At most two candidate frames, including strong sexual signals, receive enhanced local review; unconfirmed sexual findings stay low priority. Safe frames are recycled after analysis; only a threshold-crossing sampled frame can become the existing size-limited encrypted evidence image. The original video, its URI, and video audio are not saved or analyzed by this frame path. Vela Fox does not request broad video-library access, and picker/Share-sheet review does not grant continuing access to the originating app or its private database.
In the managed SMS workflow, the parent chooses a global or one-conversation scope and a discrete 100–10,000 limit. A focused-thread picker exists only after Parent authorization plus Android's SMS role/read grant. It loads no message bodies and keeps at most 500 thread/address/date snapshots derived from the newest 10,000 inbox/sent rows in memory. Vela Fox does not request Contacts permission, so it shows SMS numbers or sender addresses rather than claiming contact names. The picker list, query, and thread selection are not persisted and are dropped on cancellation, selection, lock, background, role/permission loss, restoration, or process loss. Every selected row receives local deterministic screening; at most 32 deduplicated context windows receive enhanced review, and up to 256 additional strong rules-only windows can be handled before an explicitly reported per-pass cap. A Parent timeout cancels the scan rather than extending the vault session. Safe history-scan content is not copied into Vela Fox's alert vault. Only a threshold-crossing finding may encrypt the code-grounded SMS address, direction, timestamp, exact focused excerpt, and bounded same-thread context. Enhanced analysis supplies structured classification fields; app code renders the displayed explanation from approved category phrases, so model-authored identity, quote, date, time, and number claims cannot replace or enter the grounded evidence fields. Classification can still be wrong.
The default-SMS role also carries ordinary message-routing duties during the handoff. Android delivers incoming carrier SMS to Vela Fox; Vela Fox saves each one in Android's Telephony SMS inbox and submits its text for local safety analysis so the message is not silently lost. If the user invokes an Android reply-via-message action while Vela Fox is default, Vela Fox may send that SMS, save its status in Android's Telephony store, and analyze its text locally. Safe routed SMS can therefore remain in Android's normal SMS provider even though it is not copied into Vela Fox's encrypted alert vault. These duties end after the parent restores the usual SMS app. Vela Fox has no MMS/RCS inbox, so MMS, RCS, and some group-message delivery may be delayed or lost during the handoff. Every terminal result keeps an explicit Restore action visible and the recovery notification remains until Android reports that Vela Fox no longer holds the role; Default Apps still requires the parent to select the desired SMS app.
Decorative logo orientation readings are used only in process memory to create a small layered offset while the child-status screen is resumed. They are not stored or transferred; sensor registration stops when the screen pauses, and motion is disabled when Android animations are disabled or no suitable sensor exists.
Optional practice uses fixed, invented messages, not personal conversations. Protect can run its safety rules and, if explicitly selected and available, enhanced local AI for an example. Rules and model results are shown separately. Practice never creates an alert, updates real analysis-history counters or transfers a result to Parent. Parent's example review choices are kept only in the practice screen's memory and do not change stored review decisions. Practice is discarded when closed or when the app is backgrounded. The separate silent delivery check tests Android's notification callback only; these exercises do not establish other-app coverage, model accuracy or receipt by another phone.
Protect's optional device-fit screen reads coarse current RAM, Android's low-memory flag, available app-filesystem storage, Battery Saver, thermal status and Bluetooth LE hardware availability when practice opens or is refreshed. The same resource conditions are checked before optional enhanced-AI practice. These readings need no new permission, contain no hardware identifier or app inventory, and are not stored, logged or synchronized. They help explain resource limits, not infer a child's activity, health or wellbeing. No automatic positive/wholesome interaction detector or benign-message history is enabled.
Vela Fox Parent is a dedicated parent app: alerts open automatically without a separate parental PIN. Its vault identity is encrypted with a non-exportable, app-installation-bound Android Keystore key. Use the parent phone’s screen lock to protect access. Private alert contents and search state are cleared when the app leaves its foreground session and reopen on return. Existing Android Parent installations require their old PIN or password once to migrate the existing identity; paired phones and saved alerts are preserved. The child’s Vela Fox Protect app still requires the parental PIN for Parent mode, with its existing inactivity timeout and failed-attempt backoff.
Concerning findings are stored in an encrypted local vault. A small amount of routing metadata—such as time, source, severity, categories, risk score, and delivery state—is stored separately so the locked app can manage its queue. Evidence images are reduced and size-limited before encrypted storage. Completed alerts are retained for no more than 90 days and the vault is capped at 1,000 findings on each phone. A parent can delete individual findings or purge the local vault. Sensitive reads and mutations use the exact active vault session; a closed or replaced session cannot finish the operation. Protect additionally requires its PIN-gated Parent-mode session.
Browser-history source files are capped at 16 MiB. The importer can recognize and normalize at most 5,000 visits from the most recent 365 days within a 512 KiB transient working set; one authorized scan analyzes at most the newest 64 recognized visits. Each analyzed visit is isolated as its own record so a concerning visit cannot cause neighboring benign history to be copied into an alert. Credentials, URL fragments, and non-search query parameters are removed. Safe normalized records and Vela Fox's transient copy are discarded after the scan; the external Takeout/Drive/Downloads source remains under the selected document provider and Vela Fox does not delete or wipe it. Only an individual threshold-crossing visit may be encrypted in the alert vault.
Trip detection keeps only a bounded 90-second pre-confirmation window in memory. After sustained speed/displacement confirms travel, the active crash journal and route are encrypted separately in Android no-backup storage. Each saved point includes its timestamp, coordinates, Android-reported accuracy, optional bearing, phone-GPS speed estimate, and whether that estimate was reported, displacement-derived, fused, stationary-filtered, unavailable, or from an older record without provenance. Encrypted aggregates include start/end time, duration, distance, and phone-GPS average and peak estimates. This is sampled phone GPS, not continuous coverage or vehicle telemetry. Live speed expires to zero after 20 seconds without a fix. Arrival requires three accurate fixes in an accuracy-sized destination cluster, a three-minute dwell, and a fresh final confirmation; this is intended to reject stationary drift, a stale provider speed, and GPS loss rather than invent an end point. A valid partial route may still be preserved when GPS continuity is lost for more than 15 minutes or the visible session stops, but its stored end reason and Parent UI identify the endpoint as the last trustworthy recorded point—not a confirmed destination. Routes shorter than 500 feet are discarded rather than added to completed history. Completed trips are retained for no more than 90 days or 200 trips, whichever limit is reached first. A parent can delete one trip or purge all trip history. Automatic trip detection never starts at boot and runs only as a visible Android foreground session enabled by a parent. That same session supplies fixes for place-boundary checks; creating or enabling a boundary by itself does not start location collection.
The recorded-GPS route map and replay use the encrypted points locally in PIN-gated Parent mode. Vela Fox does not automatically send those points to a map service. If a parent chooses the Google Maps preview and accepts its separate disclosure, Vela Fox hands the external app or browser the trip's start, its confirmed destination or last recorded point, and up to three ordered representative coordinates. Those coordinates then leave Vela Fox and are handled under Google Maps' or the selected browser's policies. Google recalculates an approximate driving route; Vela Fox does not export the recorded GPS polyline.
When a parent opens a trip, Vela Fox can derive bounded measurements such as duration, distance, measured speeds, sustained pauses, and route directness. Only those aggregates—not the trip identifier, coordinates, bearings, address, place-boundary names, date, or time—are supplied to the bundled local model. Code renders all numeric facts; the model is allowed to add only a short qualitative movement observation. A successful enhanced narrative is stored inside the same encrypted trip record and follows that trip's deletion and retention. If enhanced analysis is unavailable, Vela Fox shows a deterministic measured summary and may retry later.
Place-boundary definitions, stable inside/outside state, and confirmed visit history are stored in a separate Android-Keystore-backed AES-256-GCM no-backup vault. Vela Fox supports at most 50 circular boundaries with radii from 75 metres through 10 kilometres; the minimum reduces consumer-GPS edge noise. An arrival or departure requires several time-separated accurate readings, dwell time, an accuracy-aware entry/exit margin, and plausible movement; a single fix or boundary jitter cannot create an event. Initial monitoring inside a boundary is labeled as a first confirmed location rather than an exact arrival. Visit history is retained for no more than 90 days or 5,000 events. A parent can edit or delete a boundary and clear visit history; deleting a boundary also deletes its events.
Direct parent-device transfer
Optional coverage sharing is off by default and requires an unlocked Parent-mode choice on Protect. When enabled, a completed nearby sync can deliver a snapshot to each approved parent phone: protection enabled, notification access, listener connection, visible monitoring service, and coarse ages of the latest completed automatic notification rules and optional-model checks. No message text, app inventory, counts, or child timestamps are included. Completion markers are held only in Protect's process memory while sharing is enabled; disabling or changing the preference clears them. Practice, manual scans, failed model calls, and notification-delivery probes do not advance these markers. A completed AI response can still be uncertain; it does not establish safety.
The snapshot is signed by the paired child identity inside the existing encrypted, session-bound manifest and accepted only after the full queue cycle completes. Parent keeps only the latest snapshot per paired child in its existing Android-Keystore-sealed pairing store; it is displayed inside Vela Fox Parent when its encrypted storage is open. Parent also stores local receive time, elapsed time, and its own Android boot count to avoid misrepresenting an old snapshot as recent after clock changes or restart. These local clock values are not sent to Protect. Status becomes old after one hour, and age is unverified after a reboot or significant clock change. Older snapshots remain explicitly historical until replaced or the paired phone is forgotten. Turning sharing off stops future snapshots and interrupts queued sends when detected; an in-flight snapshot may already have arrived. The parent's prior snapshot is cleared by the next completed compatible sync, or by forgetting the paired phone. This is not a remote monitoring or emergency-delivery channel.
Family learning moments use fixed, invented situations about listening, context, and caring actions. Choices and feedback exist only in the current activity's memory; the activity closes and forgets choices when dismissed or when the app leaves the foreground. No score, completion history, notification, AI analysis, or transfer is created. No positive-interaction detector is enabled.
Vela Fox can send approved, queued findings directly over nearby Bluetooth to an approved Vela Fox Parent phone. Initial approval requires matching-code confirmation on both phones and can queue up to 50 recent findings; future findings queue automatically for that parent until either phone revokes trust. After pairing, a parent can enable automatic nearby receiving once, or start one-time retrieval from Vela Fox Parent; on Android 12+ the child-visible Protect service can find and authenticate that short window without another child-side prompt. A family may instead explicitly start a visible live-alert session on both phones. By default, live sync remains active while the approved phones stay connected and ends after five continuous disconnected minutes or an explicit Stop; a family can instead choose an absolute timer in five-minute increments. Live mode transfers newly saved encrypted concern alerts and their saved local analysis, plus an optional coverage snapshot when a queue cycle begins; it does not transmit safe results, raw ordinary messages, aggregate scan receipts, app-activity reports, Web Shield history, trip routes/narratives, or place-boundary definitions/history. An optional NFC tap uses a fresh one-time signed challenge and binds discovery to the later authenticated Bluetooth offer; alert bodies never cross NFC. Protocol v2 negotiates required security capabilities, derives a fresh session key with P-256 ECDH/HKDF, and AES-GCM protects manifests and alert metadata in addition to the alert body/evidence encryption for that parent's identity. Monotonic sequence numbers, signed batch completion, acknowledgments, durable delivery checkpoints, duplicate rejection, and bounded reconnect backoff prevent replay, premature delivery marking, and duplicate loss while allowing interrupted transfer to resume. Nearby delivery requires proximity, Bluetooth, retained permission, and visible foreground protection; Android or radio conditions can interrupt it, and it is not a remote connection.
Automatic nearby receiving remains visible with a persistent notification and accepts only approved phones. It reconnects between visits and may resume after a process restart, reboot after unlock, or app update if previously enabled. Its Stop control turns off the saved choice. Bluetooth, notification access, Android restrictions and force-stop can delay or stop delivery. Newly received findings may trigger a generic local notification; alert details are shown only inside Vela Fox Parent. This is a direct, guardian-enabled transfer, not an upload to Vela Fox. Pairing records—including device identity, displayed name, public keys, paired time, last-seen state, and last completed-sync time—remain until a parent uses the revoke/forget control or uninstalls the app. Revoking from Protect requires its Parent-mode PIN; forgetting a phone in the dedicated Parent app does not require a separate PIN. Once an alert reaches a parent phone, that phone keeps its own encrypted copy subject to the same alert retention ceiling. It also retains the authenticated protected-phone identifier and ciphertext digest with a bounded received-event marker, for attribution and duplicate/collision rejection; those markers are retained for no more than 90 days and capped at 5,000. Removing a paired phone stops future transfer but does not remotely erase copies already received.
Permissions and visibility
Vela Fox requests Android permissions only for features the guardian chooses. Monitoring remains visible through the installed app, the protected-device disclosure, Android permission surfaces, and a persistent status notification. Automatic trip detection and Local Web Shield have their own public persistent notifications; Web Shield also displays Android's system VPN indicator. Their enable and disable controls remain inside PIN-gated Parent mode, while Android system controls can still stop a service or app. Disabling a required permission reduces coverage; Vela Fox reports that condition instead of claiming protection is complete.
Sharing, sale, advertising, and analytics
Vela Fox does not sell personal data. It does not use content for advertising, profiling by Vela Fox, model training, or third-party analytics. The only designed disclosure of a safety finding is the direct encrypted transfer to a parent device the guardian explicitly approves. Separately, the optional parent-confirmed Google Maps action discloses the bounded route coordinates described above. When Web Shield is enabled, DNS queries are transmitted to the resolver Android reports for the current underlying network, as they ordinarily would be without Vela Fox; they are not sent to a Vela Fox service. Google Play separately handles ordinary app and model-pack delivery under Google's terms. None of these paths uploads alert contents to Vela Fox.
Deletion and control
A guardian can delete alerts, purge alert history, delete trips and their cached narratives, purge trip history, create/edit/delete place boundaries, clear visit history, revoke a paired parent phone, turn off and clear Web Shield activity, turn off location monitoring, disable optional broad-photo scanning, disconnect Google account access, or pause protection from PIN-gated Parent mode. Uninstalling an app removes its app-private data under Android's normal uninstall behavior. Deletion is not represented as forensic erasure, and a payload already materialized for an active Bluetooth transfer may complete.
Security and limitations
Vela Fox uses Android app-private storage, Android Keystore wrapping for vault identities and trip keys, authenticated encryption, device-protected Parent vault access, PIN-gated Protect sessions, persisted failed-PIN backoff, disabled backups, and blocked screenshots. No software can guarantee detection of every safety concern or defend against a rooted or compromised operating system. Text and visual classifiers can produce false positives and false negatives. The bundled image classifier's publisher reports results from a proprietary dataset; Vela Fox has not independently established production calibration, subgroup performance, or child-safety accuracy. Findings are signals for human review, not proof of abuse, identity, age, criminal conduct, CSAM, illegality, intent, or a medical diagnosis.
Children and guardian responsibility
Vela Fox must be configured by an authorized guardian and used consistently with applicable child-privacy, consent, monitoring, school, employment, and communications laws. The protected-device user must not be deceived about monitoring. Guardians are responsible for responding safely and appropriately to findings, including contacting qualified emergency services when immediate danger is suspected.
Publisher, privacy requests and contact
Publisher: Vela Fox LLC, the publisher of Vela Fox Protect and Vela Fox Parent. Contact support@velafox.com for support, privacy questions, correction requests or deletion assistance. The public policy is available at https://velafox.com/protect/privacy and the same text is packaged in both apps for offline reading. The separate Vela EV vehicle app has its own policy at https://velafox.com/privacy.
Use the Parent controls described above to review or delete data held on your phones. Vela Fox has no cloud copy of your findings, trips or Google-source reviews to retrieve or delete remotely. Delete a received copy separately on each paired phone. For information you deliberately send in a support request, contact the same support address to request access, correction or deletion; do not attach a child's messages, photos, exact location, credentials or other sensitive evidence. Support correspondence is used to answer the request and is not used for advertising or model training.
Your privacy rights depend on where you live. Contact us to exercise applicable access, correction, deletion, restriction or objection rights, or for help contacting the appropriate data-protection authority. A guardian should explain monitoring to the protected child and help them raise privacy concerns. Material changes to these practices will be reflected by updating this policy's date and the app's disclosures. Google's and other user-directed providers' own policies apply to their services.
Website audience measurement
Our Protect marketing pages count page views and selected button actions by day, page and a fixed campaign label. These are aggregate counts, not unique visitors. We do not use analytics cookies, advertising IDs, session replay or fingerprinting. We do not save IP addresses, browser details, full URLs, referrers, query strings, names or family content in this analytics table. The website host necessarily handles network information to serve requests.
Counts are stored on our website hosting service for up to 390 days. Enable Global Privacy Control or Do Not Track in your browser to stop this optional measurement. Only approved campaign labels are counted; custom URL values are discarded. These website counts are separate from the local safety analysis in the apps. Google Play provides its own acquisition, subscription and Android quality reports under Google’s terms and device choices; we add no marketing analytics SDK to either app.