Watch Cub

UPDATED SEPTEMBER 5, 2026

Your family's data.

Watch Cub is a parent-operated family watchlist with an optional Chrome companion. Public account registration is not open. This notice covers the website and companion used with an existing family account.

What Watch Cub uses

The website uses the parent's email and account authentication, a hashed parent PIN, child nicknames and chosen symbols, approved titles and public links, selected services and country, shelf schedules, connected computers, and minimal playback events. Children do not create accounts. We do not ask for their birthdates, contact details, location, camera, microphone, or advertising identifiers.

What the companion can access

The companion communicates with Watch Cub to follow the selected family profile and check that a timed pick is still allowed. It uses short-lived authorization tokens, the selected profile's label, the approved destination, and its return address. It does not read parent passwords, PINs, account cookies, provider logins, page contents, or video streams.

Chrome local storage remembers selected sites, browser setup, the selected profile, and its server-checked authorization token. Profile state can survive a restart, but expired or revoked permission cannot unlock sites. Playback tokens and temporary parent browsing exceptions use session storage, which clears when Chrome exits. Alarms recheck permission and end timed windows. Optional access to sites you select lets Chrome redirect top-level visits to the shelf and lets the companion return already-open tabs on those sites. Their URLs are used for this operation, without saving a browsing history. No provider content scripts are installed.

The separate private navigation-testing build can request Chrome's navigation permission. It checks only its tracked tab and may send a candidate YouTube video ID to Watch Cub to verify approved collection membership. The Chrome Web Store package does not request this permission.

Services that process data

Vercel hosts the website and Supabase provides account authentication and database storage. Requests to these services necessarily include network information such as an IP address. Watch Cub uses bounded request keys for abuse prevention. Parent catalog searches send search text and country to the official catalog sources, without child nicknames or household IDs.

Selecting an approved YouTube video loads YouTube's embedded player. Google then handles that connection under its own privacy policy and YouTube terms. External streaming services handle their own playback, accounts, recommendations, and advertising. Watch Cub does not sell family data or use it for advertising, credit decisions, or behavioral analytics.

Retention and removal

Playback activity expires after 30 days. Profiles, shelves, approvals, and saved picks remain until the parent removes them. YouTube titles and images refresh on parent access or are removed before 30 days; approved public links remain. The family account can be remembered for up to 30 days, while parent access expires after 30 minutes.

In Parent controls, use Child settings to disconnect computers or delete a child and their associated data. Parent account → Delete all family data removes shelves, picks, approvals, connections, and activity. This leaves the parent sign-in available to start again. Removing the Chrome companion clears its local setup; it does not delete the website's family data. For account access or data questions contact support@watchcub.com.

Companion setup and limitations · How playback works