← The Family Perspective

How safe is your child's device?

39 child tracker and parental control brands were found sharing one server, with free access to children's data. The safest data is the data no one collects.

Two children sit back to back on a bench, each absorbed in a glowing phone, against the Allowed Online arch in teal and orange

What did security researchers find about parental-control apps?

At Black Hat and DEF CON 2026, researchers found 39 supposedly separate parental-control and child-tracker brands all storing data on a single server in China, with 45 distinct vulnerabilities and no real access controls. Anyone using the app could reach another child’s location, live audio, camera, and browsing. The tools meant to protect kids were exposing them.

39 parental app brands. One server. And an easy way in for anyone who wants your child’s data.

You download the parental safety app or buy the GPS device for simple reasons: to know that your child got to school safely. To reach them if something is wrong. To worry a little less. As a parent, it’s a good instinct. However, new research has shone a light on the parental control industry, estimated at well over a billion dollars in 2026,⁠[3] to show that some of these tools do exactly the opposite of what parents hoped.

39 Seemingly separate brands
1 Shared server located in China
45 Distinct vulnerabilities
$0 What it costs an attacker to reach a child's data

At this year’s Black Hat and DEF CON,⁠[4] two of the world’s largest and most prominent cybersecurity conferences, an investigation⁠[1] by Kumio researchers Vangelis Stykas and Felipe Solferini found that 39 supposedly separate parental control app brands and children’s trackers⁠[2] all store data on a single server in China. When they investigated, they found 45 distinct vulnerabilities and no real access controls. In plain terms, that means anyone who sets up the app or GPS device could reach a connected device and access everyone else’s data. What data, you ask? Location (current and past), live audio, camera, screens, apps and browsing activity, and personal identifying information. Data belonging to children.

To demonstrate, the team made a $30 children’s smartwatch place a call and stream live audio, with nothing on the watch to show a call was happening (a note to the reader, the researchers only worked on devices that they controlled). A later report⁠[2] put the wider reach at tens of millions of devices, across a handful of shared platforms.

For a parent whose child is using one of these 39 brands, that is a hard thing to sit with.

How does Allowed Online protect against these risks?

Every piece of data a safety tool collects is something that can be exposed. Allowed Online refuses that trade-off. It blocks harmful content at the network level, before it reaches a child’s device, without reading messages or mapping where they go. The safest data is the data we never collect. Made in Switzerland, privacy-first by design.

Most tools promise safety by collecting vast amounts of data. But what does this really mean? Every message. Every location. Every tap. But it’s important to know that every piece of data that is collected is also something that can be exposed, intentionally or unintentionally. This isn’t a password or an email address. It’s a child’s location and a live microphone. In the wrong hands, the safety device becomes the danger. Being cybersecurity veterans, we decided to go the other way and create something category defining: safety without surveillance.

A finding like this is exactly what we worried about. PCMag puts it perfectly:

“The line between parental monitoring and stalkerware depends entirely on who has access to a child’s data.”

Justyn Newman, Senior Writer, Security at PCMag

Let’s talk about why we have designed Allowed Online with exactly this in mind.

This is the trade-off we deliberately decided to refuse. We have built Allowed Online to block harmful content at the network level, before it reaches a child’s device. We don’t read their messages. We don’t map where they go. The safest data is the data we never collect. Made in Switzerland and privacy-first by design.

The detail that stays with us isn’t the vulnerability count in the Black Hat research findings. It’s the 39 seemingly different apps all doing things that reduce a child’s true safety. Thirty-nine separate brands, sold as competitors, running on one system. A parent comparing four watches in a shop may have been comparing four labels on one backend.

“If you have one of those devices for your kid. Burn it. Break it. I don’t care. It is compromised.”

Vangelis Stykas, CTO, Kumio

How do I check if my child’s parental-control app is compromised?

On Android, check the companion app’s name. If it is called SeTracker, or its package name reads com.tgelec, the device runs on one of the three compromised platforms the researchers examined. Changing the password will not help, because the flaw sits on the maker’s server. Look for whether the maker has shipped a fix.

If one of these apps or devices is already in your home, don’t just change the password. A password can’t fix a flaw on someone else’s server. Instead, find out which service runs behind it. We can’t list every affected brand, but there’s a quick check on Android: if the companion app is called SeTracker, or its package name reads com.tgelec, the device sits on one of the three platforms the researchers examined. It is not a complete test. It confirms one of the three platforms, so a device that doesn’t show these could still be on another. Either way, look for whether the maker has shipped a fix. The researchers say they warned the makers more than 30 times and heard nothing back, so don’t count on a fix arriving on its own.

Then ask the harder question. What is the device really for? The obvious answer is safety for your family. But we believe that no single tool can raise a child. Ours included. Our job is to hold the boundaries quietly, so the conversations that keep kids safe can happen at home, where we believe they belong.

Curious where your family stands? Our free two-minute screen-time quiz is a good place to start.

Get the next research-backed guide in your inbox.


Sources

[1] Newman, J. (edited by Henry, A.). (7 August 2026). 39 Popular Parental Control Apps Are Secretly Feeding Data to One Server. PCMag.

[2] (14 August 2026). Your child’s GPS watch tells everyone where they are. Notebookcheck.

[3] Parental Control Software Market Size. Fortune Business Insights (2026 estimate).

[4] DEF CON 34 Speakers. Research by Kumio researchers Vangelis Stykas (CTO) and Felipe Solferini, presented at Black Hat and DEF CON 34, Las Vegas, August 2026. The “tens of millions” reach is the researchers’ estimate.