angelOS Privacy at angelOS

Privacy Policy

How we handle your and your child's data

Version 1.0 · Concept · August 2026 · Download the Dutch source (PDF)

Why this document exists

angelOS gives children their own, safe computing environment. Children use angelOS, parents decide about it. That means we process data almost exclusively about children, and that's the category the law, and we ourselves, are strictest about. This policy describes what data angelOS processes, why, where it lives, and what your rights are as a parent.

In plain language

This document explains what happens to your child's data. In short: it stays on our own servers, we never sell anything, we show no ads, and you as a parent always stay in control.

What angelOS is, and where our responsibility ends

angelOS is an application that behaves like a complete operating system for children. It is platform-independent and works on nearly any modern device: a laptop, a tablet, a desktop computer.

This policy describes how our software handles data. The device angelOS runs on, the host, remains yours: your own laptop or iPad. How that device itself handles data, what other software is installed on it, and whether it's kept up to date, is outside our control and therefore outside this policy.

Want the device itself taken care of too? That's angelPad: a complete solution where the device itself is managed by us (MDM). We do have oversight there, under additional terms.

In plain language

angelOS is software, not a device. We stand behind what our software does with data. What happens on your own laptop or tablet beyond that, we can't see and can't promise. Want us to manage the device too? Choose angelPad.

Our commitments

These principles are non-negotiable and apply to everything angelOS does.

  • A child's data is never sold and never shared with third parties.
  • angelOS shows no ads and does no tracking or profiling.
  • Your child's conversations and creations are never used to train AI models.
  • All data stays on infrastructure we run ourselves.
  • We keep no more than we need to make angelOS work.

In plain language

Your child is not a product or an audience to us. Whatever your child tells Angel or makes in angelOS stays your child's, and you as a parent can always view it or delete it.

What data angelOS processes

angelOS works with a child account and a parent account. We process:

Account details
Your child's name or nickname, the parent's email address, PIN, and login details.
Conversations with Angel
The chats between your child and Angel, so Angel can remember the conversation and you as a parent can review it.
Creations and files
Drawings, writing, and other things your child makes and saves in angelOS.
Settings and screen time
The rules you set as a parent: screen time, allowed apps, filters.
Technical logging
Limited system logs to detect outages and abuse.

We collect nothing beyond that. No location tracking, no advertising identifiers, no linking to social networks.

In plain language

We only keep what's needed to make angelOS work for your child and to give you, as a parent, insight and control. Nothing beyond that.

Angel's AI

Angel, the AI companion in angelOS, runs on our own hardware. Your child's conversations never go to large third-party AI cloud services; there is no external AI provider in the path between your child and Angel. Every message also passes through a safety filter built specifically for children.

In plain language

Angel "lives" on our own computers. What your child tells Angel never leaves those computers and is never used for anything else.

Where the data lives

angelOS's infrastructure is operated by ITARR B.V., an independent Dutch company with no outside owners or investors. Data is stored in ITARR's own, self-managed servers in the Netherlands (EU), under European privacy law (GDPR), one of the strictest privacy regimes in the world:

  • data is encrypted at rest and encrypted in transit;
  • access is limited to what's strictly necessary for operations;
  • backups stay on ITARR's own equipment;
  • nothing is resold, and nothing is used to train someone else's AI models on your family.

ITARR maintains its own information-security and data-protection practices, built around GDPR principles and the NEN 7510 and ISO/IEC 27001 standards.

In plain language

Your data doesn't sit "somewhere in the cloud" — it's on concrete, encrypted systems we run ourselves, under some of the strongest privacy law in the world.

Your control as a parent

Children can't give consent themselves; you do that on their behalf. That's why every decision runs through the parent account:

  • You can review your child's conversations and creations through the parent dashboard.
  • You can have data deleted, in part or entirely.
  • You can request a copy of all of your child's data.
  • Filters, screen time, and allowed apps are set by you, and only you.

Requests about access, deletion, or export can be made through the parent dashboard or via the contact form. We respond within thirty days, usually much sooner.

In plain language

You're in charge of your child's data. Reviewing it, deleting it, or taking it with you: one request is all it takes.

If something goes wrong

Should a security incident nonetheless affect your or your child's data, we will actively inform you, and report it to the relevant Dutch data protection authority (Autoriteit Persoonsgegevens) where required. We follow our infrastructure partner's incident and breach-notification procedure.

In plain language

If something goes wrong, you'll hear it from us. We don't wait for you to find out on your own.

About this document

This policy is revised whenever angelOS materially changes what it does with data. The version and date above are authoritative; older versions remain available on request.

Product
angelOS
Infrastructure & operations
ITARR B.V., Netherlands
Version
1.0 (concept, August 2026)
Supervisory authority
Dutch DPA (Autoriteit Persoonsgegevens)