Skip to content
Back to product overview

Oh No! Parent Control

Privacy notice

A clear explanation of what the app handles, what stays on the computer, and the choices available to families.

Last updated: September 10, 2026

Oh No! Parent Control's parent-control features operate locally on the computer where the app is installed, without an online account or internet connection. If you choose to send feedback or an editable error report from the Parent App, Child App, or Kiosk App, the information described below is sent to Puffy Slippers Tech LLC.

A quick note for children

This app helps a parent manage how much time you can use the computer and which apps you can open. It uses information already on the computer, such as your account name, time used today, and the apps available to you. Your parent can see your remaining time and the rules set for your account.

The app does not read your messages, watch your screen, record your typing, track your location, or keep a history of the websites you visit. If you have a question about a rule, ask your parent or another trusted adult.

What stays on your computer

The parent-control features use the following local information:

  • Local account information: the account name, profile picture, local user identifier, and whether an account is a child or an administrator. This lets the app show the right accounts and keep each child's settings separate.
  • Parent-control settings: whether screen-time control is on, the daily allowance, app access rules, and the last choices made on the request form.
  • Time information: sign-in and computer-use intervals supplied by Ubuntu, the time remaining today, and the start and length of an approved extra-time grant. The app uses detailed intervals to calculate remaining time; it does not add them to its saved settings or show parents a detailed activity timeline.
  • App information: the names, descriptions, icons, and launch information for apps available to the child. The app may check which programs are currently running when it needs to apply an app rule. It does not keep a history of apps the child opened.
  • Troubleshooting logs: timestamps, the part of the app involved, whether an action succeeded, settings such as a requested duration, counts, and technical error details. Routine logs are designed not to include account names, passwords, app titles, browsing content, or the contents of personal files.

This information is stored and processed locally by the app and Ubuntu's built-in account, sign-in, and screen-time services. Diagnostic logs and any local information you choose to include in feedback leave the computer when you send that feedback.

What we do not collect

Apart from optional feedback, the parent-control features do not send information to Puffy Slippers Tech LLC. The app has no analytics, advertising, tracking pixels, cloud sync, or remote parent dashboard. We do not sell, rent, or use app information for advertising or profiling.

The parent-control features do not automatically collect or keep the following. Feedback may contain personal content you choose to write or attach:

  • passwords;
  • message, document, photo, audio, or video contents;
  • keystrokes or screenshots;
  • web browsing or search history;
  • location, contacts, camera, or microphone data; or
  • a history of apps opened.

The selected parent's password is entered into Ubuntu's own authentication prompt. Oh No! Parent Control does not receive or store it.

Optional feedback

Sending feedback or an editable error report from the Parent App, Child App, or Kiosk App is optional and is not required to use parent-control features. Opening a report sends nothing: you can review and edit it, and only explicit Send Feedback submits it. Cancelling an editable error report before sending sends nothing. When you send feedback, we receive:

  • your message and any optional rich-text formatting;
  • the app version;
  • a reply email address, if you provide one; and
  • the filenames and contents of attachments you select.

Recent diagnostic logs are included by default when available. They come from the three newest available local log dates, which may not be consecutive calendar days. In the Parent App and Child App, you can save a copy to review. All three apps let you remove the logs before sending. If logs cannot be prepared or exceed the upload limit, you can send without them.

The dedicated Kiosk App does not offer arbitrary file attachments, saving diagnostic ZIPs, or an external privacy-page launch. It shows an in-app privacy disclosure and can attach the broker-provided diagnostic ZIP.

The app sends attachment filenames, not their original folder paths. Administrator passwords are handled by Ubuntu's authentication prompt and are not sent with feedback. Text and files you choose to submit are sent as content, so review them and the logs for personal information before sending.

Logs are not automatically anonymized: the log writer does not redact arbitrary text. Leaving the reply email blank does not guarantee anonymity, because the message, filenames, or attachments may identify you. See the feedback walkthrough and upload limits.

Feedback is sent over HTTPS to our portal for forwarding by email to our support inbox. We use it to review problems, improve the app, and reply if you provide an email address.

The portal's feedback handler processes submission contents in memory, with no feedback database or persistent queue. It does not write messages, reply addresses, attachments, or diagnostic contents to its application logs. Hosting and email services also process operational/request metadata; these application-level statements do not establish those services' logging or retention settings.

Feedback, reply email addresses, attachments, and diagnostic logs are emailed to support. Retention depends on our support mailbox and service providers, including their backup policies. We do not currently guarantee deletion within a fixed period.

Drafts, attachment contents, and pending submissions remain in the memory of the relevant Parent App, Child App, or Kiosk App process. Closing the feedback dialog preserves the draft and may leave sending and retries active while that app process remains open. Automatic retries use the same submission for up to 15 minutes. There is no persistent submission queue: drafts and pending retries do not survive exiting that app process. Closing a dialog is not the same as exiting the process. Copies of logs you explicitly save from the Parent App or Child App remain where you saved them.

Cancelling a report or exiting the app cannot recall a submission already accepted by the service.

Who can see local information

Children can see their own remaining time and request options. Local administrators can view and change a child's limits, app rules, and current remaining time. Other standard users cannot use the Parent App or directly read protected log files or saved parent-control preferences.

Local administrators, eligible children, and the configured kiosk account can explicitly obtain the same diagnostic archive through the app's broker. The archive can include logs from all four product components: Parent App, Child App, Kiosk App, and broker. This authorized access through the app is separate from direct filesystem permissions and does not grant access to saved parent-control preferences.

The dedicated request station shows eligible child and approving parent accounts so a request can be addressed to the right people. It can show a remaining-time estimate for the selected child's request. It does not provide access to private settings files or parent-management controls, and approval still requires the selected parent's authentication.

Anyone with administrator or physical access to a computer may already have broad access to information on that computer. Families should protect administrator accounts with strong passwords and keep the computer updated.

How long information is kept

Parent-control settings stay on the computer so they continue to work after a restart or update. Ordinary package removal retains the product's central saved settings and troubleshooting logs. Purging the package additionally deletes those product-owned records. Ubuntu may retain its own account, usage, journal, or crash information under its own settings. Diagnostic ZIPs you saved elsewhere and feedback already sent to support are not removed by uninstalling or purging the app.

Remembered request selections in a child's local user state can remain after purge. The package removes the request account and its home only when it verifies that the package created them; this does not remove child users' local files. Follow the removal guidance.

Troubleshooting logs are limited to the newest 10 dated log files per component. Pruning happens when that component first logs on a new day, so this is not a promise to delete logs after 10 elapsed days.

For information sent to support, see the optional-feedback retention disclosure.

Your choices

A parent or device administrator can:

  • change or disable a child's screen-time controls;
  • change app access rules;
  • revoke approved extra time;
  • review the information shown in the Parent App;
  • remove or purge the app using the package manager, with the data distinctions described above.

Users of all three apps can choose whether to send feedback or an editable error report, provide a reply email, or include diagnostic logs. Parent App and Child App users can also choose files to attach and save diagnostic ZIPs; those file operations are not available in the dedicated kiosk.

Follow the user guide's removal steps so the package can clear its restrictions and request station. Purge does not erase every local trace or copies already sent elsewhere.

Network access and other services

The installed app does not need an internet connection for its parent-control features. Sending optional feedback requires an internet connection and transmits the information described in “Optional feedback.” The computer's operating system or package manager may connect to services configured by the computer owner, for example to download software updates. Where external links are available, choosing a website or email link opens the user's browser or email program. The dedicated Kiosk App shows an in-app privacy disclosure instead of launching an external privacy page. Those services have their own privacy practices.

This policy covers the installed Oh No! Parent Control app and optional feedback and editable error reports submitted through its Parent App, Child App, and Kiosk App. Website visits are covered separately by the Puffy Slippers Tech website privacy policy. Services reached through external links have their own policies.

Security

The app keeps each child's settings separate, stores its private records so standard users cannot read them directly, and checks administrator permission before protected changes. Extra-time approval uses the operating system's authentication prompt. App rules and process checks are limited to the selected child account.

No software can promise perfect security. Keeping Ubuntu and Oh No! Parent Control updated, protecting administrator passwords, and limiting physical access to the computer all help protect local information.

Changes to this policy

If the app's privacy practices change, this notice will be updated with its publication date. A new feature that sends information off the computer would be described here before release.

Contact

Oh No! Parent Control is provided by Puffy Slippers Tech LLC. Questions about this privacy notice can be sent through our contact page.