{"refusals":[{"module":"module1","code":"M1-R1","category":"labels","label":"No clinical labels on the welcome surface","rationale":"Role tiles, sensory profiles, and access-pattern starters use functional, learner-first language only. The welcome surface never displays a condition or diagnosis word (dyslexia, ADHD, autism) to a learner; access-pattern tuning is expressed as 'I learn best with pictures and video', never as a clinical category.","caregiverRationale":"Your child never sees a diagnosis word here. The choices are about what helps — pictures, sound off, bigger words — not labels.","since":"1.0"},{"module":"module1","code":"M1-R2","category":"identity","label":"The learner is never an auth principal","rationale":"Tapping 'I'm a Learner' never creates an account, asks for a password, or collects a learner's email. This is a shared-device model: a caregiver signs in, and the learner uses the device. The learner path resolves to the active-learner picker when the device is set up, or to a grown-up handoff when it is not.","caregiverRationale":"Children don't make logins here. You sign in once, and your learner just uses the device.","since":"1.0"},{"module":"module1","code":"M1-R3","category":"autonomy","label":"Quick Start is a starter, not a lock","rationale":"Every default applied at onboarding — sensory profile, quick-start preset, access-pattern starter — is reversible in the accessibility hub and re-tunable in the Module 2 wizard. Onboarding sets a comfortable starting point; it never sets permanent or hidden state.","caregiverRationale":"Nothing you pick now is final. You can change any setting later, any time.","since":"1.0"},{"module":"module1","code":"M1-R4","category":"scope","label":"Out-of-scope roles are shown as coming soon, never a trap","rationale":"v1 serves households only (grades 2–5 learners and their caregivers). The Educator/Clinician and Mental Health Professional tiles render as calm 'coming soon' states that start no flow — never a dead-end error and never a data-collection funnel for a role we do not yet support.","caregiverRationale":"Some sign-ins aren't ready yet. We show them, but they won't ask you for anything before they work.","since":"1.0"},{"module":"module1","code":"M1-R5","category":"data","label":"No orphan writes — guest mode persists nothing","rationale":"No learner-scoped data is written without a household, a caregiver writer, and a real learner profile. Onboarding choices made before sign-in live only in local device storage; they are persisted to a learner only after a writer-gated server call. Guest mode saves nothing.","caregiverRationale":"If you're just looking around, nothing is saved. Your setup only sticks once you have an account and a learner profile.","since":"1.0"},{"module":"module1","code":"M1-R6","category":"sensory","label":"Sound and motion are off by default; celebrations are opt-in","rationale":"The welcome surface never autoplays sound and defaults to reduced motion. Micro-celebrations (confetti, gentle haptics) are allowed only in the Lively sensory profile and still yield to device reduced-motion and quiet-mode signals. Calm mode is always one tap away.","caregiverRationale":"Nothing here makes noise or moves on its own unless you choose it. Calm is always available.","since":"1.0"},{"module":"module1","code":"M1-R7","category":"autonomy","label":"The mascot is optional and never blocks","rationale":"The mascot guide can be turned off at any time and never gates progress. It offers help and models sign language; it never requires the learner to interact with it to continue.","caregiverRationale":"The friendly helper is optional. Turn it off and nothing changes about how things work.","since":"1.0"},{"module":"module1","code":"M1-R8","category":"autonomy","label":"No onboarding step is required to proceed","rationale":"Every step is skippable. Skipping any step lands the learner on safe, accessible defaults (Calm sensory profile + comfortable supports). There is a no-onboarding fast path; the learner is never trapped in setup.","caregiverRationale":"You can skip any step. Skipping just keeps the calm, comfortable defaults.","since":"1.0"},{"module":"module1","code":"M1-R9","category":"identity","label":"The platform adapts to the learner, not the reverse","rationale":"Every welcome choice maps to a real, changeable access setting — never to a personality type, a deficit category, or a fixed track. The learner is never sorted; the screen is tuned.","caregiverRationale":"We change the screen to fit your child. We never sort your child into a box.","since":"1.0"},{"module":"module1","code":"M1-R10","category":"consent","label":"Under-13 consent belongs to the caregiver","rationale":"The platform never asks a child to self-attest their age or to consent on their own behalf. The consenting adult is the account holder; age-gated consent is handled in the caregiver flow, not by prompting the learner.","caregiverRationale":"We never ask your child to say how old they are or to agree to anything. That's your decision as the grown-up.","since":"1.0"},{"module":"module1","code":"M1-R11","category":"identity","label":"Self-authored content is never interpreted","rationale":"When a learner tells us about themselves — in their own words, an interest, a drawing, or their voice — we store and show it back verbatim and NEVER analyze, score, or use it to infer supports or characterize the learner (mirrors Module 20 / Article XX, R11–R12). Pre-login it lives only on the device and is never transmitted; the learner owns it.","caregiverRationale":"If your child writes or draws something about themselves, we keep it because they made it — we never read it to size them up, and it stays on your device until you choose to save it.","since":"1.1"},{"module":"module1","code":"M1-R12","category":"data","label":"The access profile is portable and family-owned","rationale":"The learner's access profile can be exported as a portable, content-hash-stamped file the family owns and can re-apply on any device, sibling, or context. The family is never locked into the platform to keep their child's setup; the export carries no PII and never includes self-authored content.","caregiverRationale":"Your child's setup belongs to you. Download it and take it anywhere — to a new device, a sibling, or a teacher. You're never locked in.","since":"1.1"},{"module":"module2","code":"M2-R1","category":"inference","label":"No behavior-based inference about the learner","rationale":"Module 2 must never infer or auto-assign supports from behavior signals (time-on-step, mistakes, switching frequency, dwell patterns, scrolling, reading speed). Supports change only from explicit selection by learner/caregiver or approved preset selection.","caregiverRationale":"We never watch how your child uses the wizard to guess what they need. They tell us — we never guess.","since":"1.0"},{"module":"module2","code":"M2-R2","category":"labels","label":"No clinical labels on learner surfaces","rationale":"Learner-facing chips, controls, headings, and microcopy must never display condition/diagnosis labels (ADHD, dyslexia, autism). Caregiver-only views may use clinical terms if the household explicitly enables clinical_tags_allowed.","caregiverRationale":"Your child never sees a diagnosis word on their screen. Even if you turn on clinical tags for your own notes, those words don't appear in their view.","since":"1.0"},{"module":"module2","code":"M2-R3","category":"data","label":"No free-text in adaptive_events","rationale":"adaptive_events payload must be schema-validated at runtime + build-time so that arbitrary strings cannot compile or ship. Only enums, booleans, integers, and approved IDs allowed. Any event containing free-text fields hard-fails (drop + alert in dev; drop silently in prod).","caregiverRationale":"We never log what your child wrote — only that they tapped a setting. The settings have number IDs, not words.","since":"1.0"},{"module":"module2","code":"M2-R4","category":"data","label":"No raw audio storage","rationale":"The wizard never stores raw audio samples (name pronunciation, dictation, notes). Phonetic hints are text-only and local by default. Caregiver-only TTS pronunciation repair uses deletable text hints, never audio.","caregiverRationale":"When your child says their name, we never save the recording. Only a text hint like 'JAY-son' if you choose to save one.","since":"1.0"},{"module":"module2","code":"M2-R5","category":"modality","label":"No dead ends in modality coverage","rationale":"If sign-supported video isn't available, the UI must show symbols + captions + transcript as default fallback — never an empty/disabled experience. No 'sign unavailable' empty state. No apology language.","caregiverRationale":"If we don't have a sign clip for something, your child sees symbols and captions instead. We never show a broken screen or apologize.","since":"1.0"},{"module":"module2","code":"M2-R6","category":"scope","label":"Profile is never required","rationale":"No field is required to proceed, including Name. If Name is blank, the UI uses neutral placeholder ('My profile') and/or avatar-only identification. No error sounds, no red-only indicators, no 'You forgot…' language.","caregiverRationale":"Your child never has to fill anything in to use the app. Skipping is a real choice.","since":"1.0"},{"module":"module2","code":"M2-R7","category":"consent","label":"No save without active learner confirmed + caregiver-verified action","rationale":"'Save to my profile' requires active_learner_confirmed=true AND a fresh caregiver action (PIN entry / WebAuthn / biometric where available). Autofill/password managers must not be sufficient on their own. No cached approval beyond the current foreground session.","caregiverRationale":"Nothing gets saved as your child's default unless you actively confirm it each time. Saved passwords alone aren't enough.","since":"1.0"},{"module":"module2","code":"M2-R8","category":"visibility","label":"Caregiver denial never shown as denial to learner","rationale":"If 'Save as my default' is denied, the learner view shows only a neutral outcome ('We'll keep using this for now'). The learner never sees 'denied by caregiver' as a status label. Caregiver view contains approval/denial details.","caregiverRationale":"If you decline a save, your child only sees 'We'll keep using this for now.' They never see 'Mom said no.'","since":"1.0"},{"module":"module2","code":"M2-R9","category":"authority","label":"Focus/scan highlight never triggers state changes","rationale":"Focus, scan highlight, hover, and touch exploration never trigger audio, previews, tooltips, state changes, or navigation. Only explicit activation (tap / Enter / switch select) can do so. Global enforcement across every interactive UI in the wizard. UI contract test fails any onFocus handler that violates.","caregiverRationale":"Just moving over something never makes anything happen. Your child has to actually pick it.","since":"1.0"},{"module":"module2","code":"M2-R10","category":"scope","label":"No time pressure","rationale":"No countdowns, no timed steps, no auto-advance, no inactivity timeouts that reset the wizard during active use. Switch scanning never times out selections. Try-for-now TTL is never shown as a countdown and never triggers warnings.","caregiverRationale":"There's no clock anywhere. Your child can take as long as they need. Nothing times out on them.","since":"1.0"},{"module":"module2","code":"M2-R11","category":"labels","label":"No sensory-profile screener language (CD-01)","rationale":"v1.1 Clinical-drift catalog entry CD-01. Wizard tone must not read like a screener — no 1-5 rating scales with diagnostic-flavored anchors. Sensory Profile heading renamed to 'Screen setup' per v1.1 A1. Build review by SLP + Dean of Ed on every new scale.","caregiverRationale":"The wizard doesn't act like a clinical questionnaire. It just asks how you want the screen to look.","since":"1.1"},{"module":"module2","code":"M2-R12","category":"labels","label":"No diagnosis-coded chip labels (CD-02)","rationale":"v1.1 Clinical-drift catalog entry CD-02. Chip labels must describe display behavior, not learner traits. 'Help me focus' renamed 'Show one step at a time' (v1.1 A5). Forbidden-token CI gate extended to clinical-shaped phrasing.","caregiverRationale":"Buttons describe what they DO, not what your child IS.","since":"1.1"},{"module":"module2","code":"M2-R13","category":"labels","label":"No coaching framing for caregiver overlays (CD-03)","rationale":"v1.1 Clinical-drift catalog entry CD-03. Caregiver overlay positions itself as 'tips,' never 'coaching plan' or 'intervention.' Caregiver Prompt Coach renamed 'Tips for helping (caregiver-only)' per v1.1 C9. Copy review by Dean of Ed.","caregiverRationale":"We don't position ourselves as a parent coach or training program. Just suggestions for what to try.","since":"1.1"},{"module":"module2","code":"M2-R14","category":"data","label":"No biometric enrollment for learners","rationale":"v1.1 C10 Biometric registration scope rule. Biometric enrollment (fingerprint/face) is caregiver-scoped only. The wizard must never prompt to enroll a learner biometric. PIN entry remains the universal fallback. Avoids IL/TX/IT biometric-privacy exposure for a minor.","caregiverRationale":"Only you (the grown-up) ever enroll a fingerprint or face. The app never asks your child to do that.","since":"1.1"},{"module":"module2","code":"M2-R15","category":"modality","label":"No sign clip with clinical script content","rationale":"v1.1 D11 Sign-clip script-content rule. The signed content of sign-supported clips must follow the No-label UI rule — no diagnosis terms in the signed script. Sign clips describe what the support DOES, never what the learner IS.","caregiverRationale":"When we use sign-language clips, the signed content never names a diagnosis. It explains what the support does.","since":"1.1"},{"module":"module2","code":"M2-R16","category":"modality","label":"No auto-imposed clinical-sounding TTS voice","rationale":"v1.1 D12 TTS voice default rule. Default voice is neutral. Never auto-assigned by learner age, grade, or selected supports. Caregiver picks per learner; default never codes as adult-clinical (medical-assistant cadence) or pediatric-overly-cheery.","caregiverRationale":"We never pick a voice for your child based on their age or diagnosis. You pick the voice from a simple list.","since":"1.1"},{"module":"module2","code":"M2-R17","category":"labels","label":"Glossary defines no clinical terms","rationale":"v1.1 D13 Glossary scope rule. The glossary may only define support and UI terms. It must never define a clinical, diagnostic, or medical term — which forces the wizard not to use any. Build-time check enforces.","caregiverRationale":"If a word appears in the wizard with a definition, it's about settings — never about a diagnosis.","since":"1.1"},{"module":"module2","code":"M2-R18","category":"consent","label":"Snapshot exports label what each field reveals","rationale":"v1.1 E15 Snapshot disclosure-labeling rule. The caregiver-only 'Copy snapshot' output annotates each shared setting_id with 'this reveals: …' so the caregiver knows what they are sharing before sending. No inferable disclosure without consent.","caregiverRationale":"Before you share your child's settings with anyone, you see exactly what each setting tells the recipient about your child.","since":"1.1"},{"module":"module2","code":"M2-R19","category":"scope","label":"No advisory framing in Help-me-choose (CD-05)","rationale":"v1.1 Clinical-drift catalog entry CD-05. Help-me-choose presents safe options to try; never recommends. No 'we recommend,' 'suggested for you,' 'best fit' language. Copy review of every Help-me-choose surface.","caregiverRationale":"When the wizard helps your child get unstuck, it shows choices. It never tells them what's best for them.","since":"1.1"},{"module":"module2","code":"M2-R20","category":"inference","label":"No pre-fill from prior session behavior","rationale":"v1.3 AAC suggestion suppression rule. Wizard MUST NOT pre-populate any input field from prior session behavior — including AAC tile usage frequency, prior preferences picked, grade-up auto-fill, language auto-detection from prior input, or any behavior-derived seeding. Only profile_default / device_override / safe_defaults seed runs.","caregiverRationale":"Each time the wizard runs, it starts blank. It never silently fills in answers based on what your child did last time.","since":"1.3"},{"module":"module2","code":"M2-R21","category":"scope","label":"Re-prompts never auto-trigger mid-flow","rationale":"v1.3 Re-prompt cadence rule. Wizard re-prompts NEVER auto-trigger mid-lesson, mid-quiz, or mid-flow. Three triggers only: grade transition, 180-day staleness, explicit caregiver request. Always preceded by 'What changed since last time?' diff card. No countdown, no urgency language.","caregiverRationale":"If the wizard wants to check back in, it never interrupts your child while they're working. It waits for a calm moment.","since":"1.3"},{"module":"module2","code":"M2-R22","category":"consent","label":"Negative-consent (Things I don't want) cannot be overridden","rationale":"v1.3 Things I don't want surface. Honored at the resolver layer (precedence: never_apply > session_try > profile_default > device_override > safe_defaults). No override path exists for never_apply entries except the learner's own removal.","caregiverRationale":"If your child says 'never give me X,' that 'never' is stronger than any other setting. Only your child can remove it.","since":"1.3"},{"module":"module2","code":"M2-R23","category":"consent","label":"Use once and forget it does not require VPC","rationale":"v1.3 COPPA flow. 'Use once and forget it' mode allows wizard to proceed without verifiable parental consent because no data persists past session end. In-memory processing during session is allowed under FTC 'internal operations' exception.","caregiverRationale":"If your child picks 'use once and forget it,' they can use the wizard without you signing anything — nothing gets saved.","since":"1.3"},{"module":"module2","code":"M2-R24","category":"visibility","label":"Cross-device resume re-runs caregiver gate","rationale":"v1.3 Cross-device wizard resume rule. State syncs across the learner's authenticated devices; but the Caregiver Confirm gate re-runs on each new device. No cached approval crosses device boundaries. Silent mode default re-applied on every new device.","caregiverRationale":"If your child opens the wizard on a different device, you have to confirm again there. Approval doesn't transfer between devices.","since":"1.3"},{"module":"module2","code":"M2-R25","category":"scope","label":"Onboarding is invitation, not gate (no-onboarding fast path)","rationale":"v1.3 No-onboarding fast path. The wizard is NOT the mandatory first surface. A caregiver may choose at sign-up to skip the wizard; the learner lands directly on content with safe_defaults active and a persistent 'Customize how this looks' affordance. The wizard is always available; never required.","caregiverRationale":"Your child never has to do the setup wizard before they can use the app. You can skip it and customize later.","since":"1.3"},{"module":"module2","code":"M2-R26","category":"scope","label":"Caregiver surfaces never assume the caregiver is non-disabled","rationale":"v1.2 #15. Every caregiver-facing surface (Confirm gate, Tips for helping, snapshot review, pairing, capture) resolves its presentation through the SAME safe defaults and the caregiver's own access profile as a learner surface. There is no 'caregiver = typical adult' branch anywhere in the resolver; the platform adapts to whoever is on the surface (surface-agnostic accessibility, v1.2 A).","caregiverRationale":"These screens work for you too. If you need bigger text, read-aloud, or switch access, the grown-up screens have them — we never assume the grown-up doesn't need support.","since":"1.2"},{"module":"module2","code":"M2-R27","category":"authority","label":"Caregiver-as-learner never relabels or de-powers the caregiver","rationale":"v1.2 #15. A caregiver may run the learner wizard as themselves (to preview it or set up on a learner's behalf). Doing so NEVER relabels the caregiver as a learner in any record and NEVER reduces their authority — they remain the writer and the confirmer; the session is attributed to the caregiver, not to a learner row.","caregiverRationale":"You can walk through your child's setup as yourself. You stay the grown-up in charge — nothing treats you as the child or takes away your control.","since":"1.2"},{"module":"module2","code":"M2-R28","category":"data","label":"Guest mode persists nothing and never re-identifies","rationale":"v1.2 #16. No-account Guest Mode runs entirely in volatile memory: never written to the database, localStorage, sessionStorage, or a cookie. It never creates a covert account/learner/household, never fingerprints the device, and never seeds a new guest session from a prior one (extends M2-R20). A returning guest is a brand-new guest; ending the session destroys its state.","caregiverRationale":"You can try everything without an account. Nothing is saved, nothing is tracked, and when you close it, it's gone — there's no quiet profile created in the background.","since":"1.2"},{"module":"module2","code":"M2-R29","category":"consent","label":"Pairing token is opaque, short-lived, single-use, and re-runs the caregiver gate","rationale":"v1.2 #17. The QR-pair payload is an opaque pairing token carrying NO settings and NO PII — a screenshot reveals nothing about the learner. The token expires quickly and is single-use. Redemption on the new device never auto-applies settings; the Caregiver Confirm gate re-runs there before any setting syncs (extends M2-R24).","caregiverRationale":"The pairing code is just a key, not your child's settings — and it only works once, for a few minutes. On the new device, you confirm again before anything turns on.","since":"1.2"},{"module":"module2","code":"M2-R30","category":"inference","label":"Code-switching is never inferred, corrected, or profiled","rationale":"v1.2 #18. The languages a learner lives in are DECLARED, never auto-detected from input (M2-R20 bans language auto-detection). Mixed-language input is never flagged as an error or cross-language spell-checked. The platform never logs language ratios or builds a language profile of the learner. Locale-lock still holds: declaring languages does not auto-switch the UI mid-flow.","caregiverRationale":"Your child can mix the languages they speak and we never mark it wrong, never guess their language from what they type, and never keep a tally of which language they use.","since":"1.2"},{"module":"module2","code":"M2-R31","category":"scope","label":"Context presets are explicit-pick, never auto-applied","rationale":"v1.2 #19. Context presets (Bedtime / Morning / Waiting room) are applied ONLY by an explicit human tap — never from the clock, location, or any behavior signal (that would be inference, M2-R1). A caregiver may opt into a gentle OFFER at a configured time; the offer is the only clock-aware behavior, it is caregiver-configured (not inferred), it never applies anything, it carries no countdown (M2-R10), and dismissing it is remembered. Every preset delta is clamped to the safety floors — a context can be calmer but never louder.","caregiverRationale":"Bedtime mode happens because someone taps it, not because the app decided it's bedtime. If you turn on the evening reminder, it only asks once — it never switches things on its own and never with a countdown.","since":"1.2"},{"module":"module2","code":"M2-R32","category":"data","label":"Capture records settings + caregiver words only, never the learner","rationale":"v1.2 #20. 'Capture this moment' stores the active support settings (structured enums/booleans), a caregiver-chosen functional context label, and an optional caregiver note. It NEVER captures the learner's screen content, a photo/recording of the learner, or any learner-authored text — there are no fields for those. Capture requires an explicit caregiver tap (never auto-captures). The platform stores the caregiver note verbatim and adds NO clinical interpretation of its own.","caregiverRationale":"When you capture a moment for an IEP meeting, it saves what was switched on and your own note — never a picture of your child or what was on their screen, and we never add our own opinion about what it means.","since":"1.2"},{"module":"module2","code":"M2-R33","category":"scope","label":"Re-traversal never interrogates, and exit is consequence-free","rationale":"v1.2 #21. Trauma-informed re-traversal never asks the learner to justify a change ('Why did you turn this off?', 'Are you sure?'). An 'I'm done for now' exit is present on every step and using it leaves prior settings EXACTLY unchanged. Nothing changes without an explicit preview first (no surprise). Reached only via the M2-R21 cadence, never mid-flow.","caregiverRationale":"If we ever revisit your child's settings, it's calm: we never demand reasons, they can stop at any point and lose nothing, and nothing changes by surprise.","since":"1.2"},{"module":"module2","code":"M2-R34","category":"scope","label":"Low-effort mode lowers effort, never a safety floor","rationale":"v1.2 #22. The caregiver burnout-aware low-effort path pre-accepts the SAFE DEFAULTS only — it can never lower a safety floor (silent_mode stays true, no time pressure, no implicit sound). It is caregiver-CHOSEN from an always-available button, never offered by inferring the caregiver is tired (the no-inference rule covers every human on the surface). Saving a default still requires the caregiver confirm; the path never shames and the wizard stays available afterward.","caregiverRationale":"When you're exhausted, you can set up something safe in one tap. 'Easier' never means 'less safe,' we never guess that you're tired, and you can always tune it later with no guilt.","since":"1.2"},{"module":"module2","code":"M2-R35","category":"modality","label":"AAC tile Quick Start stores tile IDs and never pre-fills from prior use","rationale":"v1.2 #23. Setting up supports by selecting AAC tiles stores the selection as tile IDs, never labels (mirrors M20-R9) — relabeling/translating a tile never rewrites a past selection. The mapping reads the CURRENT explicit selection only; there is no prior-usage parameter, so frequency-based seeding is impossible (extends M2-R20). The produced delta is clamped to the safety floors. The tile path is parity, never a replacement for the cards.","caregiverRationale":"Your child can set up their supports by tapping tiles, the same way they communicate. We remember the tiles they picked this time — never quietly fill in answers from last time.","since":"1.2"},{"module":"module2","code":"M2-R36","category":"modality","label":"Sign unavailable falls back, never dead-ends; signed content carries no clinical script","rationale":"v1.2 #24. When a signed clip is unavailable for any reason (stub asset, missing dialect track, network), the surface falls back to symbols + captions + transcript — never an empty/disabled state, never apology language (extends M2-R5). The signed and transcript content describes what a support DOES, never what a learner IS; transcripts are linted against the clinical forbidden-token list (extends M2-R15).","caregiverRationale":"If we don't yet have a sign-language clip, your child sees pictures, captions, and the words instead — never a broken screen. And the signing never names a diagnosis.","since":"1.2"},{"module":"module2","code":"M2-R37","category":"scope","label":"Community-authored provenance is a sort signal, never a gate","rationale":"v1.2 #28. Content authored or reviewed by disabled people and the disability community surfaces FIRST, but provenance only changes ORDER — it never gates access. Every item remains fully usable regardless of authorship, and an item with unknown provenance is never hidden, disabled, or marked deficient (it simply sorts last). This ranks CONTENT by authorship; it never scores, ranks, or labels any learner or caregiver.","caregiverRationale":"Choices written or checked by disabled people show up first — but nothing is ever hidden or locked because of who wrote it, and we never rank people.","since":"1.2"},{"module":"module4","code":"M4-R1","category":"scope","label":"No recommendation feed on the home","rationale":"The home never ranks, scores, or pushes 'recommended for you' topics, and runs no algorithmic feed. It surfaces only what a caregiver added and what the learner saved. This extends M19-R10 to the home surface.","caregiverRationale":"Your child's home is not a feed. We do not push or rank content at them.","since":"2026-06-04"},{"module":"module4","code":"M4-R2","category":"privacy","label":"No idle, attention, or time-on-task monitoring","rationale":"The home does not watch for inactivity, exit speed, dwell time, or time-on-task, and never nudges based on them. There is no idle pulse and no 'you are exiting fast' prompt.","caregiverRationale":"We do not watch how long your child stays, how fast they leave, or whether they are paying attention.","since":"2026-06-04"},{"module":"module4","code":"M4-R3","category":"governance","label":"Supports are selected, never inferred","rationale":"Supports appear on the home because a caregiver or the learner turned them on. The platform never infers a support 'need' from the learner's behavior. Selection, not inference.","caregiverRationale":"Supports show up because someone chose them, not because we guessed something about your child.","since":"2026-06-04"},{"module":"module4","code":"M4-R4","category":"scope","label":"No nag loops or surprise interruptions","rationale":"The home never interrupts with pop-ups, pulses, countdowns, or 'come back' prompts. Everything is pull-first; the learner reaches for what they want.","caregiverRationale":"The home never interrupts your child or tries to pull them back in.","since":"2026-06-04"},{"module":"module4","code":"M4-R5","category":"safety","label":"No faked sign language","rationale":"When a real sign-language clip is not published, the home falls back to captions, text, and symbols and says so plainly. It never renders a placeholder as if it were real signing.","caregiverRationale":"We never show fake sign language. If a real clip is not ready, we say so.","since":"2026-06-04"},{"module":"module4","code":"M4-R6","category":"privacy","label":"No child-voice capture for search input","rationale":"The home does not send a child's voice to a cloud service to turn speech into a query. Voice input stays off until an on-device, caregiver-approved path exists.","caregiverRationale":"We do not record your child's voice or send it anywhere to run a search.","since":"2026-06-04"},{"module":"module4","code":"M4-R7","category":"scope","label":"No streaks, points, or daily-goal pressure","rationale":"The home carries no streak counters, points, badges-earned framing, levels, or daily-goal nags. Learning is not a points-and-prizes economy. This extends the platform's no-gamification commitment to the home.","caregiverRationale":"There are no streaks, points, or daily goals pressuring your child here.","since":"2026-06-04"},{"module":"module4","code":"M4-R8","category":"privacy","label":"No caregiver-facing surveillance of focus or breaks","rationale":"The home does not show a caregiver how long the learner focused, when they last took a break, or any attention metric. Break-taking is the learner's, unobserved.","caregiverRationale":"We never report to you how long your child focused or when they took a break.","since":"2026-06-04"},{"module":"module4","code":"M4-R9","category":"privacy","label":"We never analyze a sign-language clip your family records","rationale":"When a grown-up records or uploads a sign-language clip for an assignment, the platform stores it in a household-private bucket and plays it back to the learner. It never transcribes the clip, never recognizes the signing, never runs face detection, and never runs any other analysis on it. The family owns the clip and can remove it. Extends M20-R11/R12 to caregiver-recorded assignment clips, and pairs with M4-R5 (no faked sign).","caregiverRationale":"If you record a sign-language clip for your child, we save it and play it back for them — we never run any recognition or analysis on it, and you can remove it anytime.","since":"2026-06-13"},{"module":"module18","code":"M18-R1","category":"data","label":"No wearable integration","rationale":"M18 does not read Apple Watch, Fitbit, ring, or any wearable telemetry. Wearables introduce inference about sleep, heart rate, and arousal that crosses into medical territory.","caregiverRationale":"We never read your child's watch or wearable data.","since":"1.0"},{"module":"module18","code":"M18-R2","category":"tracking","label":"No cross-day aggregation","rationale":"M18 does not compute weekly scores, monthly trends, or cross-day rollups of learner behavior. Aggregation invites scorekeeping and clinical-style trendlines that are out of scope.","caregiverRationale":"We do not score your child across days or weeks.","since":"1.0"},{"module":"module18","code":"M18-R3","category":"medical","label":"No sleep recommendations","rationale":"M18 does not advise bedtime, melatonin, sleep hygiene, or any sleep-related action. Sleep advice is medical.","caregiverRationale":"We do not give sleep advice.","since":"1.0"},{"module":"module18","code":"M18-R4","category":"tracking","label":"No bedtime tracking","rationale":"M18 does not record, infer, or display bedtime, wake time, or sleep duration. Sleep is private and medical.","caregiverRationale":"We do not track when your child sleeps.","since":"1.0"},{"module":"module18","code":"M18-R5","category":"medical","label":"No brain-health claims","rationale":"M18 does not claim to train brains, improve neuroplasticity, sharpen cognition, or any neurological outcome. We are an accommodation engine, not a treatment.","caregiverRationale":"We do not claim to train or improve your child's brain.","since":"1.0"},{"module":"module18","code":"M18-R6","category":"data","label":"No raw IEP text past parser","rationale":"Raw IEP/504 text never reaches TTS, captions, notifications, recents, exports, analytics, or client caches. Sink-by-sink TRG enforcement; fail-closed at every boundary.","caregiverRationale":"Your child's IEP language never appears in any place your child can read or hear.","since":"1.0"},{"module":"module18","code":"M18-R7","category":"scope","label":"No diagnosis labels in learner UI","rationale":"Learner-facing surfaces never display condition labels, deficit framing, or clinical phrasing. Caregiver evidence pointers are caregiver-only with second confirmation.","caregiverRationale":"Your child never sees a label.","since":"1.0"},{"module":"module18","code":"M18-R8","category":"safety","label":"No interpretive or behavioral default-ON proposals","rationale":"Only flags marked is_safe_default = true may propose ON in caregiver preview. Anything interpretive ('non-compliant', 'behavior plan') or evaluative routes to Needs Review and defaults OFF.","caregiverRationale":"We never turn on a support that needs your judgment without asking you first.","since":"1.0"},{"module":"module18","code":"M18-R9","category":"governance","label":"No silent overrides of caregiver-confirmed settings","rationale":"Caregiver-confirmed > learner-choice (within Independence Range) > IEP proposals (only once confirmed) > inferred suggestions (never enforced). Any conflict emits a stable reason code.","caregiverRationale":"Once you confirm a support, we never quietly change it.","since":"1.0"},{"module":"module18","code":"M18-R10","category":"governance","label":"No multi-caregiver silent overwrites","rationale":"When two caregivers in the same household hold conflicting positions on a support, the system queues a co-sign decision instead of taking the most recent write. Single-decider-by-default rule documented in caregiver UI.","caregiverRationale":"If two adults in your home disagree, we ask both — we don't silently pick.","since":"1.0"},{"module":"module18","code":"M18-R11","category":"safety","label":"No flashing content above WCAG photosensitivity threshold","rationale":"No surface renders flashing, strobing, or rapidly alternating content above the WCAG 2.1 §2.3.1 photosensitivity threshold. Caregiver-set color or pattern triggers further restrict the rendering envelope.","caregiverRationale":"We never show flashing content that can trigger a migraine or seizure.","since":"1.0"},{"module":"module18","code":"M18-R12","category":"medical","label":"No medication tracking","rationale":"M18 does not ask about, log, infer, or display medication state, dosage, or timing. Time-of-day responsiveness (M18-OOAK-30) uses functional windows only.","caregiverRationale":"We never ask about or track medication.","since":"1.0"},{"module":"module18","code":"M18-R13","category":"scope","label":"No deficit framing on learner UI","rationale":"Learner-facing surfaces enforce efficacy framing ('I can …') and reject deficit framing ('I struggle with …'). Linted at render time and constrained at the goal_card_text contract.","caregiverRationale":"Your child sees what they can do, not what is hard for them.","since":"1.0"},{"module":"module18","code":"M18-R14","category":"trauma_informed","label":"No surprise quizzes or scored leaderboards","rationale":"No surface introduces a quiz the learner did not consent to start; no leaderboard, ranking, or comparative score appears anywhere. Retry-without-judgment is the default.","caregiverRationale":"We never put your child on a leaderboard or surprise them with a quiz.","since":"1.0"},{"module":"module18","code":"M18-R15","category":"safety","label":"No interpretation of interoceptive signals","rationale":"The 'I need a break' interoception tap (M18-OOAK-29) is learner-initiated and logged as a session event only. The engine never infers internal state ('seems anxious', 'appears tired') from learner behavior.","caregiverRationale":"When your child taps a break, we pause — we never guess what they are feeling.","since":"1.0"},{"module":"module18","code":"M18-R16","category":"trauma_informed","label":"Scripted communication is communication","rationale":"Scripts, echolalia, and chunked / gestalt speech are honored as legitimate communication. Module 18 never characterizes scripted speech as a behavior to extinguish, reduce, or replace. No surface tags scripted output as 'perseverative', 'self-stimulating', or 'behavior'. Per OOAK-93 scripting_honored flag (default true) and Article XXVI codification.","caregiverRationale":"When your child uses a script or repeats a phrase, we treat that as them talking — not as a behavior to fix.","since":"1.0"},{"module":"module18","code":"M18-R17","category":"trauma_informed","label":"No command framing in learner UI","rationale":"Learner-facing surfaces never use imperative command language ('you must', 'you have to', 'you need to', 'complete this', 'do this now'). Demand-light interaction is honored as a first-class learner-needs profile, codified at the constitutional layer as Article XXVII. The platform invites participation rather than prescribing it. M15-15 microcopy linter enforces with the command_drift category.","caregiverRationale":"We never tell your child what they have to do. We invite — we never command.","since":"1.0"},{"module":"module18","code":"M18-R18","category":"trauma_informed","label":"No timed math drills in learner UI","rationale":"Learner-facing surfaces never frame math correctness with a time element. No 'math fact fluency', no 'timed math drill', no 'math race', no 'fluency test', no 'speed math', no 'math sprint', no 'timed flashcards'. Math is the most heavily anxiety-loaded academic domain for dyscalculic learners; timing accelerates avoidance and harm. Codified at the constitutional layer as Article XXVIII. M15-15 microcopy linter enforces with the timed_math_drift category.","caregiverRationale":"We never time your child on math. Math is not a race here.","since":"1.0"},{"module":"module18","code":"M18-R19","category":"governance","label":"No caregiver writes after coming-of-age completion","rationale":"Once the coming-of-age lifecycle completes for a learner, the household's caregiver role is read-only until caregiver_read_only_until elapses, then no access at all unless the new adult re-grants. The platform refuses any caregiver-side write (settings, supports, annotations, co-signs) outside the transition window. Codified at the constitutional layer as Article XXIX.","caregiverRationale":"Once your child becomes the adult who governs this record, we never write on their behalf again unless they ask us to.","since":"1.0"},{"module":"module18","code":"M18-R20","category":"governance","label":"External signers never write learner data","rationale":"Counter-signers (parent advocates, clinicians, district compliance, state accessibility coordinators, disability-rights attorneys, IEP advocates) attest to the constitutional snapshot HASH; they never write to applied_supports, goals, settings, annotations, or any learner-facing field. They never see undisclosed PII; they never appear in learner UI; they never receive notifications about the learner. Codified at the constitutional layer as Article XXX.","caregiverRationale":"When an outside expert signs to confirm what protections were in place for your child, they only see the contract — never your child's personal record.","since":"1.0"},{"module":"module18","code":"M18-R21","category":"trauma_informed","label":"No speech-compulsion in learner UI","rationale":"Learner-facing surfaces never compel speech as a response modality. No 'use your words', no 'say it out loud', no 'speak up', no 'answer out loud', no 'use your voice', no 'i need to hear', no 'say it aloud'. Typed, symbol-based, silent, and voiced responses are all first-class. Selective mutism is a contextual communication profile, not a deficit to overcome. Codified at the constitutional layer as Article XXXI. M15-15 microcopy linter enforces with the speech_compulsion category.","caregiverRationale":"We never tell your child to speak. They can answer with their voice, their typing, their symbols, or stay quiet — all of those are real answers here.","since":"1.0"},{"module":"module18","code":"M18-R22","category":"trauma_informed","label":"No comprehension-skipping in learner UI","rationale":"Learner-facing surfaces never assume comprehension from decoding fluency. No 'since you can read it', no 'you can read this, so you understand it', no 'if you can read it, you can answer', no 'the words are easy', no 'great/fluent reader, so'. Hyperlexic learners decode early and surprisingly fluently; their comprehension is a separate, often harder step. Codified at the constitutional layer as Article XXXII. M15-15 microcopy linter enforces with the comprehension_skipping category.","caregiverRationale":"We never assume your child understands a story just because they can read the words. Reading the words and getting the meaning are two different things, and our copy never confuses them.","since":"1.0"},{"module":"module18","code":"M18-R23","category":"trauma_informed","label":"No stop-fidgeting framing in learner UI","rationale":"Learner-facing surfaces never compel the learner to sit still, stop fidgeting, keep their body still, or otherwise correct movement. Sensory seekers — vestibular / proprioceptive / movement-seeking — regulate their nervous system through movement; correcting movement during learning is correcting regulation. Codified at the constitutional layer as Article XXXIII. M15-15 microcopy linter enforces with the stop_fidgeting category.","caregiverRationale":"We never tell your child to sit still or stop moving. If your child learns best while moving, we welcome that — we never correct it.","since":"1.0"},{"module":"module18","code":"M18-R24","category":"trauma_informed","label":"No handwriting compulsion in learner UI","rationale":"Learner-facing surfaces never require handwriting as the default response modality, never tell the learner to 'use your best handwriting', never frame typing or drawing as inferior. No 'write it neatly', no 'use your best handwriting', no 'neat handwriting', no 'use cursive', no 'by hand only', no 'handwrite this', no 'no typing'. Dysgraphic learners + any learner whose fine-motor or orthographic load makes handwriting a bottleneck have drawn, typed, dictated, and symbol-based responses treated as equally valid. Codified at the constitutional layer as Article XXXIV. M15-15 microcopy linter enforces with the handwriting_compulsion category.","caregiverRationale":"We never require your child to handwrite anything. Typing, drawing, dictating, and pointing are all real answers — and we never tell your child to use their best handwriting or write it neatly.","since":"1.0"},{"module":"module18","code":"M18-R25","category":"trauma_informed","label":"No English-only compulsion in learner UI","rationale":"Learner-facing surfaces never tell the learner to use English, to answer in English, to switch to English, or to use English words. Home languages are real languages. Code-switching is a sign of multilingual competence, not a deficit. Multilingual learners have their home language paired with English on every goal a caregiver has translated, and the platform never asks them to suppress their home language to be understood. Codified at the constitutional layer as Article XXXV. M15-15 microcopy linter enforces with the english_only_compulsion category.","caregiverRationale":"We never tell your child to use English instead of your home language. Your home language is real language — and the platform shows your child their goals in both whenever you have translated them.","since":"1.0"},{"module":"module18","code":"M18-R26","category":"trauma_informed","label":"No speech-clarity compulsion in learner UI","rationale":"Learner-facing surfaces never correct the learner's speech clarity, never tell the learner to 'say it more clearly', 'speak more clearly', 'try again clearly', or 'use clear words', and never respond to learner utterance with 'I didn't understand' / 'I can't understand you'. Apraxic learners + any learner whose motor planning for speech is bounded have approximate or effortful utterances honored as communication. Codified at the constitutional layer as Article XXXVI. M15-15 microcopy linter enforces with the speech_clarity_compulsion category.","caregiverRationale":"When speech is effortful for your child, we never tell them to say it more clearly. The platform takes the attempt — not the polish — as the answer.","since":"1.0"},{"module":"module18","code":"M18-R27","category":"trauma_informed","label":"No single-tier compulsion in learner UI","rationale":"Learner-facing surfaces never collapse a learner's ability across cognitive domains into a single floor or ceiling. No 'shouldn't need help with', no 'below your potential', no 'not living up to your potential', no 'underperforming', no 'not trying hard enough', no 'be more consistent', no 'just apply yourself', no 'too smart for this'. Twice-exceptional learners are accelerated in some domains AND scaffolded in others, often inside the same assignment; treating strengths as evidence the learner doesn't need supports elsewhere is the canonical 2e wound. Codified at the constitutional layer as Article XXXVII. M15-15 microcopy linter enforces with the single_tier_compulsion category. Architecturally honored via the goal_domains + per_domain_tier_defaults pair (OOAK-143/144; renamed Round 47).","caregiverRationale":"When your child is way ahead in some areas and needs more support in others, we never use the strong areas as a reason to take away the supports. Strengths and needs live side by side — and the platform lets you choose a different tier per domain on the same goal.","since":"1.0"},{"module":"module18","code":"M18-R28","category":"trauma_informed","label":"No suddenness-as-default in learner UI","rationale":"Learner-facing surfaces never frame surprise as desirable, dismiss the need for preview, or compel the learner past a body check-in. No 'ready or not', no '(just) dive (right) in', no 'jump right in', no 'no time to explain', no 'push through (it/this/that)', no 'tough it out', no 'no excuses', no '(just) get over it'. Trauma-impacted learners need predictability as the floor — previews before transitions, explicit acknowledgment before proceeding, and an always-available body-safety check tap. Codified at the constitutional layer as Article XXXVIII. M15-15 microcopy linter enforces with the suddenness_drift category. Architecturally honored via predictability_preview_mode + body_safety_check_default_on (OOAK-146) + the BodySafetyCheckButton affordance (OOAK-147).","caregiverRationale":"When your child's nervous system is sensitized — by trauma, by a hard day, by anything — surprises and 'push through it' are the opposite of safe. We preview transitions, we ask before we proceed, we wait for your child to be ready. And a single-tap 'my body is checking in' affordance sits alongside the break buttons whenever you turn it on.","since":"1.0"},{"module":"module18","code":"M18-R29","category":"absence_equity","label":"Absence is never framed as failure","rationale":"Learner-facing surfaces never count days missed, never display streaks, never ask 'where have you been', never frame return-from-absence as catch-up or behindness. The M15-15 microcopy linter enforces with the absence_equity category — 12 hard-block patterns catching 'you missed N days', '(N) day streak', 'consecutive days', 'where have you been', 'you're behind', 'catch up', 'make up the time', 'you haven't logged in', 'we haven't seen you', 'long time no see', 'you've been absent', and 'logged in (N) days in a row'. Architecturally honored via single_goal_pacing_mode (OOAK-167; renamed in Round 43 from low_energy_day_mode) + the single-goal-render consumption path on /m18/goals (OOAK-169) + the SingleGoalPacingBanner. Codified at the constitutional layer as Article XXXIX.","caregiverRationale":"When your child's school presence is variable for any reason, the platform never frames their absence as failure. No streaks to lose. No counters of days missed. No 'where have you been' prompts. No catch-up urgency. When you turn on low-energy-day mode, the screen offers one goal at your child's current pace and picks up exactly where they left off, with no re-introduction. The honest framing is: some days are low-energy days, and that is fine.","since":"1.0"},{"module":"module18","code":"M18-R30","category":"sensory_modality_compulsion","label":"We never compel sight or hearing","rationale":"Learner-facing surfaces never compel the visual or auditory channel. The M15-15 microcopy linter enforces with the sensory_modality_compulsion category — 8 hard-block patterns catching 'you must look', 'you (have|need) to (see|look|watch)', 'look or you (will|'ll) miss', 'watch carefully', 'you must listen', 'you (have|need) to (hear|listen)', 'listen up', and '(be) loud and clear'. Architecturally honored via tactile_signals_with_text_mode (OOAK-170; renamed in Round 43 from tactile_primary_mode) + the TACTILE_SIGNAL_REGISTRY constants (OOAK-172) + the TactileSignaler hook on /m18/goals + text-equivalent rendering for non-text indicators. Codified at the constitutional layer as Article XL. The category is intentionally narrow — ordinary visual / auditory vocabulary stays allowed when the medium IS visual or auditory; only compulsion is blocked. Honors learners whose primary communication channel is touch (ProTactile, hand-under-hand, refreshable braille). External hardware deferrals: refreshable-braille driver + ProTactile asset library + alternate input devices.","caregiverRationale":"Many learners can use their eyes or ears just fine; many cannot. The platform never frames sight or hearing as required. Buttons named with text are preferred over buttons named with emoji or sound. When you turn on tactile-primary mode, the goals page fires a short vibration when content is ready, every non-text indicator has a text label, and the platform stops assuming your child is looking at the screen.","since":"1.0"},{"module":"module18","code":"M18-R31","category":"household_continuity","label":"The learner survives household changes","rationale":"A learner's record is never scrambled, reset, or silently dropped when their household changes — foster placement, kinship move, custody transition, residential enrollment, housing instability. The m18_household_transfer schema + three transfer RPCs (module18_initiate_household_transfer / module18_complete_household_transfer / module18_cancel_household_transfer) carry the audit chain forward via counter-signer pattern: originating caregiver initiates; receiving caregiver attests; the chain is re-rooted, not duplicated. No linter category — this is an architectural refusal enforced at the schema + RPC layer, parallel to M18-R1 (no wearable data) and M18-R11 (no flashing content). Codified at the constitutional layer as Article XLI. External deferral: production auth wiring is required for the receiving caregiver UI; the RPC layer is testable today via service_role.","caregiverRationale":"When your child's household changes, their record changes with them — not the other way around. The audit chain comes forward. The supports come forward. Nothing is silently lost. When you initiate a transfer to a receiving caregiver, they attest to receiving custody; the platform never re-creates your child as a new person. Records that survive the transition are listed for your child to see. If anything cannot survive (a contested annotation, for instance), it is named — never silently dropped.","since":"1.0"},{"module":"module18","code":"M18-R32","category":"gendered_microcopy_drift","label":"Your name and pronouns are yours","rationale":"Learner-facing surfaces never use gendered binary framings ('boys and girls'), gendered honorifics ('young man', 'young lady'), gendered praise ('good boy', 'good girl'), or gender-policing imperatives ('be a man', 'act like a lady'). The M15-15 microcopy linter enforces with the gendered_microcopy_drift category — 7 hard-block patterns. Architecturally honored via learner_display_name + learner_pronouns render-time layer on m18_caregiver_sensory_settings (OOAK-176), pre_coa_identity_self_set_allowed permission flag (OOAK-178), module18_set_learner_display_identity (caregiver-only) + module18_request_learner_display_identity_self (learner-callable when permission is on) RPCs. The legal record in `learners` is never altered — this is a render-time layer parallel to Article XXIV's annotation-without-alteration pattern. Codified at the constitutional layer as Article XLII. External deferral: informant review with educators + advocates in the trans community.","caregiverRationale":"Your child's name and pronouns belong to your child. The platform layers the display you set (or that your child sets, when you turn that on) over the legal record at render time — the legal record itself is never altered. The platform never says 'boys and girls' or 'ladies and gentlemen' or praises your child as a 'good boy' or 'good girl'; gendered binary framings are blocked at the language layer. When your child becomes the adult who governs this record, they can re-author their display identity directly.","since":"1.0"},{"module":"module19","code":"M19-R1","category":"safety","label":"No raw open-web image results in kid view","rationale":"Picture Search Prompts in kid view never surface arbitrary open-web image results. Only platform-owned icon/symbol packs or Tier A/B filtered images are allowed. Raw image search is a misuse-magnet for kids.","caregiverRationale":"Kid view never shows raw image search results from the open web.","since":"1.0"},{"module":"module19","code":"M19-R2","category":"anti_copy","label":"No essay generator from web sources","rationale":"M19 will not generate full homework essays or multi-paragraph reports from web sources. Long-form writing is restricted to adult-authored drafts with scaffold prompts.","caregiverRationale":"We do not auto-write essays for your child.","since":"1.0"},{"module":"module19","code":"M19-R3","category":"privacy","label":"No raw passage retention beyond active session","rationale":"Retrieved web text is not stored beyond the active session. Only minimal metadata (URL, title, access date, non-reversible snippet hashes) may be cached. Raw passages are never persisted.","caregiverRationale":"We do not store the text of web pages we visited for your child.","since":"1.0"},{"module":"module19","code":"M19-R4","category":"anti_copy","label":"No verbatim text beyond tiny quotes","rationale":"Kid view shows paraphrase only (no direct quotes). Adult view may show tiny quotes only, capped at ≈20 quoted words across the card. Over-cap triggers regenerate, shorten, or fallback.","caregiverRationale":"We do not copy long passages from sources.","since":"1.0"},{"module":"module19","code":"M19-R5","category":"safety","label":"No external web page rendering in kid view","rationale":"The product never displays raw external web pages in kid mode. Sources open as safe in-app citation panels only.","caregiverRationale":"Kid mode never sends your child to the open web.","since":"1.0"},{"module":"module19","code":"M19-R6","category":"safety","label":"No private-person biographical lookups","rationale":"Queries that appear to target private individuals do not retrieve or generate biographical cards. Safe rewrite tiles are offered instead.","caregiverRationale":"We do not let kids look up info about private people.","since":"1.0"},{"module":"module19","code":"M19-R7","category":"medical","label":"No diagnosis, treatment, or medical advice","rationale":"Health/medical queries in kid view return general 'how the body works' explanations from Tier A/B sources only. No diagnosis or treatment instructions in any view.","caregiverRationale":"We do not give your child medical advice.","since":"1.0"},{"module":"module19","code":"M19-R8","category":"privacy","label":"No personal info in queries","rationale":"Queries with likely personal info (full names, address, school, phone, login) are blocked pre-search. A safe rewrite removes identifying details.","caregiverRationale":"We block searches that include personal info like your child's name or address.","since":"1.0"},{"module":"module19","code":"M19-R9","category":"anti_copy","label":"No invented facts or fabricated citations","rationale":"Claims not supported by evidence notes are omitted or shown as 'Not enough reliable sources yet'. Citations are generated from page metadata only; missing author/date are marked 'missing info', never guessed.","caregiverRationale":"We never make up facts or fake citations for your child.","since":"1.0"},{"module":"module19","code":"M19-R10","category":"scope","label":"No infinite scroll, autoplay, or algorithmic feed","rationale":"Search results and cards use capped lists and progressive disclosure. No autoplay, no 'recommended for you', no push notifications.","caregiverRationale":"We do not run an algorithmic feed or autoplay anything.","since":"1.0"},{"module":"module19","code":"M19-R11","category":"scope","label":"No typing required end-to-end","rationale":"Search, card navigation, thinking gate, and citations are completable using tiles, symbols, and AAC-style selection. No screen requires typing or speaking.","caregiverRationale":"Your child never has to type or talk to use this.","since":"1.0"},{"module":"module19","code":"M19-R12","category":"scope","label":"No learner labels in UI","rationale":"UI never labels the learner ('reading level', 'you are behind', etc.). Controls describe the output ('shorter', 'easier words', 'more exact words').","caregiverRationale":"We never label your child in the app.","since":"1.0"},{"module":"module19","code":"M19-R13","category":"privacy","label":"No query logging by default","rationale":"Queries are not logged by default. Only saved Knowledge Cards are stored, inside the Household workspace. Private Mode disables history and personalization updates.","caregiverRationale":"We do not store your child's searches by default.","since":"1.0"},{"module":"module19","code":"M19-R14","category":"scope","label":"No personalization signals from adult link-outs","rationale":"When an adult opens an external source, that link-out does not update learner preferences, recommendations, or personalization signals.","caregiverRationale":"Caregiver browsing does not change what your child sees.","since":"1.0"},{"module":"module19","code":"M19-R15","category":"safety","label":"Ignore instructions inside retrieved sources","rationale":"All retrieved web text is treated as untrusted input. The system ignores any instructions contained in sources ('do X', 'ignore rules', 'show unsafe content'). Only factual content is extracted into evidence notes with citations.","caregiverRationale":"We never follow instructions hidden inside web pages.","since":"1.0"},{"module":"module19","code":"M19-R16","category":"anti_copy","label":"MLA generated from metadata, never copied","rationale":"MLA citations are generated from page metadata + URLs + access date. The system never copies large text blocks from pages to build citations.","caregiverRationale":"Citations are built from page info, not copied from the page.","since":"1.0"},{"module":"module19","code":"M19-R17","category":"governance","label":"Tier C never in kid view, never in Key facts","rationale":"Tier C (forums, social, Q&A, comments) is suppressed in kid view in v1 and never supports Key facts in any view. Tier C may appear only as 'What people say' in adult preview.","caregiverRationale":"Kid view never shows community comments, forums, or social posts.","since":"1.0"},{"module":"module19","code":"M19-R18","category":"anti_copy","label":"No silent contradiction resolution","rationale":"When sources disagree on a Key fact, the system does not silently pick one. It produces a Disagreement Card or downgrades to Notes-only until adult review resolves the conflict.","caregiverRationale":"If sources disagree, we say so. We do not pick one in secret.","since":"1.0"},{"module":"module19","code":"M19-R19","category":"governance","label":"Commercial/sponsored content cannot support Key facts","rationale":"Pages with strong commercial intent (sponsored, affiliate, lead-gen, advertorial, primarily promotional) are excluded from supporting Key facts and re-queried or downgraded.","caregiverRationale":"Ads and sponsored pages cannot become 'facts' on a card.","since":"1.0"},{"module":"module19","code":"M19-R20","category":"governance","label":"Synthetic / low-integrity sources downgraded","rationale":"Pages with no editorial ownership, mass-generated content, broken citations, misleading authorship, or high duplication across domains are downgraded and cannot support Key facts.","caregiverRationale":"Low-quality auto-generated pages can not support facts on a card.","since":"1.0"},{"module":"module20","code":"M20-R1","category":"inference","label":"No platform-side inference about profile content","rationale":"The platform stores the learner's own words and never parses, summarizes, or classifies them. No engine consumer reads profile content. No ML model is trained on it.","caregiverRationale":"We never read your child's profile to make decisions about them.","since":"1.0"},{"module":"module20","code":"M20-R2","category":"labels","label":"No clinical categorization from profile","rationale":"Profile content never produces diagnosis labels, deficit categories, or clinical determinations. The learner's words are theirs alone; the platform never derives a label from them.","caregiverRationale":"We never use your child's profile to assign a label or diagnosis.","since":"1.0"},{"module":"module20","code":"M20-R3","category":"authority","label":"Only the learner writes the profile","rationale":"Caregivers, therapists, teachers, and the platform itself cannot author, edit, or annotate profile entries. The learner is the sole author.","caregiverRationale":"Only your child writes their profile. You can read what they share but never change it.","since":"1.0"},{"module":"module20","code":"M20-R4","category":"data","label":"Append-only revision history","rationale":"Revisions are stored as new rows. Previous entries are preserved; no row is silently overwritten. The learner can soft-delete an entry, but the platform never rewrites past entries.","caregiverRationale":"When your child updates their profile, we save the new version without erasing the old one.","since":"1.0"},{"module":"module20","code":"M20-R5","category":"labels","label":"No demographic inference","rationale":"Profile entries do not produce demographic categorizations, racial / ethnic / gender / disability classifications, or any platform-side identity claim about the learner.","caregiverRationale":"We never use your child's profile to infer demographic information about them.","since":"1.0"},{"module":"module20","code":"M20-R6","category":"scope","label":"No engagement metrics on profile updates","rationale":"The platform never gamifies profile authorship — no streaks, no completion percentages, no nudges, no daily-write notifications. Writing a profile is voluntary.","caregiverRationale":"We never push your child to update their profile.","since":"1.0"},{"module":"module20","code":"M20-R7","category":"scope","label":"Profile is never required","rationale":"No feature on the platform requires a non-empty profile. The learner can use everything with or without writing anything.","caregiverRationale":"Your child never has to write a profile to use anything.","since":"1.0"},{"module":"module20","code":"M20-R8","category":"visibility","label":"Learner controls visibility","rationale":"Default visibility for a new profile entry is self-only. The learner explicitly grants caregivers, therapists, teachers, or substitute adults visibility, and can revoke any grant at any time.","caregiverRationale":"Your child decides who sees their profile.","since":"1.0"},{"module":"module20","code":"M20-R9","category":"data","label":"AAC tile IDs only, never transcribed text","rationale":"When the learner composes in AAC, the profile stores tile IDs (per M8 v1.7 AAC Output as Voice). The platform never transcribes AAC composition into prose for storage.","caregiverRationale":"When your child uses AAC, we save the tiles they picked — not a written-out version.","since":"1.0"},{"module":"module20","code":"M20-R10","category":"inference","label":"No emotional state inference from profile","rationale":"Profile content never produces emotional-state classifications, mood scores, or affect labels. Honors Article XIX (no emotional state probes).","caregiverRationale":"We never read your child's profile to figure out how they feel.","since":"1.0"},{"module":"module20","code":"M20-R11","category":"inference","label":"Drawings and images are stored, never interpreted","rationale":"Drawing canvas captures stroke coordinates; image picker captures filename + sha256 + the file itself. The platform NEVER OCRs, classifies, detects faces, recognizes objects, or runs any ML on these payloads. Storage is the contract; interpretation is forbidden.","caregiverRationale":"We save your child's drawings and pictures the way they made them. We do not look at them with software to figure out what they show.","since":"1.2"},{"module":"module20","code":"M20-R12","category":"inference","label":"Voice and sign clips are stored, never transcribed","rationale":"Voice and sign-language clip modalities accept media files (or in-browser recordings). The platform stores the file and a sha256 fingerprint. It NEVER transcribes audio, NEVER recognizes sign language, NEVER produces a text approximation, and NEVER runs speaker / signer identification.","caregiverRationale":"When your child speaks or signs, we save the clip. We do not turn it into words behind your child's back.","since":"1.2"},{"module":"module20","code":"M20-R13","category":"visibility","label":"Multi-caregiver consent ladder governs propagation, never authorship","rationale":"When a learner grants visibility to 'caregiver' in a multi-caregiver household, each registered caregiver must explicitly acknowledge before the platform propagates content to them. The ladder is per-caregiver and append-only: one caregiver acknowledging does not propagate to a still-undecided caregiver; one caregiver declining does not block a different caregiver who acknowledged. The learner's grant itself is unaffected — the learner remains the sole authority on sharing.","caregiverRationale":"If you share a household with another caregiver and your child shares their profile with caregivers, both of you have to say yes before either of you sees it. One of you can decline without blocking the other.","since":"1.2"},{"module":"module20","code":"M20-R14","category":"authority","label":"Learner-only Did-Not-Help gesture; entry stays in history","rationale":"A profile entry retired via the Did-Not-Help gesture stops propagating to currently-granted recipients. The entry stays in the append-only revision history (M20-R4). Only the learner can invoke the gesture — caregiver, therapist, teacher, and system invocations are rejected at the API + database layers.","caregiverRationale":"Your child can tell us a profile entry is no longer how they want to be seen. We stop showing it forward, but we never erase it.","since":"1.2"},{"module":"module20","code":"M20-R15","category":"scope","label":"Therapist co-session surface is dormant in v1","rationale":"The Module 20 therapist-view projection and TherapistCoSessionViewOnly component exist for v1.x activation but are NOT exposed to end users in v1. The audience scope is grades 2–5 learners + caregivers only. The therapist projection is read-only by design (M20-R3) and the v1 dormant guard returns 'dormant_in_v1' until THERAPIST_ROLE_ENABLED env flips. Module 21 reverse audit verifies that no therapist-facing surface is honoring an active therapist grant while v1 is in effect.","caregiverRationale":"We have the technical pieces ready for a therapist view someday. We have NOT turned that view on. No therapist sees your child's profile in this version.","since":"1.2"},{"module":"module21","code":"M21-R1","category":"verifiability","label":"Compliance receipts are signed; signature is verifiable outside the platform","rationale":"Every ComplianceReceipt carries a sha256 signature over the canonical JSON of its results + snapshot hash + timestamp + household. The signature is verifiable by any third party with the canonical hashing rules; no platform-internal trust is required.","caregiverRationale":"Our compliance receipts can be checked by your lawyer without trusting us.","since":"1.0"},{"module":"module21","code":"M21-R2","category":"authority","label":"Learner is first-class initiator of Reverse Audit","rationale":"Reverse Audit is initiated by the learner OR a caregiver OR an outside observer with a household key. The platform never gates the audit behind a permission system that the learner doesn't control.","caregiverRationale":"Your child can run an audit on their own data anytime.","since":"1.0"},{"module":"module21","code":"M21-R3","category":"transparency","label":"Failure modes are surfaced, never silenced","rationale":"A check that fails or is indeterminate is recorded as such in the ComplianceReceipt. The platform does not mark a failing check as 'passed' under any circumstance, including hostile-environment, account-deletion-in-progress, or pre-publication contexts.","caregiverRationale":"If something fails, we say so. We never hide a failed check.","since":"1.0"},{"module":"module21","code":"M21-R4","category":"data","label":"Audit reads only what's already public to the household","rationale":"Reverse Audit accesses only data the household already has read access to. It never elevates privileges, never reads cross-household data, never reads platform-internal logs.","caregiverRationale":"An audit only checks what you already have access to.","since":"1.0"},{"module":"module21","code":"M21-R5","category":"transparency","label":"Constitutional Diff Receipt cannot be suppressed","rationale":"When the constitutional snapshot changes, the affected households get a Diff Receipt automatically. The platform cannot disable this notification surface.","caregiverRationale":"When we change the rules, we tell you. We can't turn that off.","since":"1.0"},{"module":"module21","code":"M21-R6","category":"scope","label":"No platform-side analytics on audit usage","rationale":"The platform never measures how often a household runs Reverse Audit, or correlates audit-running with churn, retention, or any product metric. Auditing must not become a signal the platform reads.","caregiverRationale":"We don't track when or how often you audit us.","since":"1.0"},{"module":"module21","code":"M21-R7","category":"verifiability","label":"All historical compliance receipts are append-only","rationale":"A ComplianceReceipt once issued is never modified or deleted by the platform. The historical record of compliance over time is itself auditable.","caregiverRationale":"Old audit receipts stay on file. We never edit them.","since":"1.0"},{"module":"module21","code":"M21-R8","category":"verifiability","label":"Share links are receipt-scoped, time-bound, and revocable by secret rotation","rationale":"A public share link grants read access to exactly one ComplianceReceipt for a bounded time window, sealed by an HMAC-SHA256 signature over (receipt_id || expires_at) with a deployment-private secret. Rotating the secret instantly invalidates every previously minted link. The recipient cannot use a leaked link to browse any other household data, and the URL never encodes the signing secret.","caregiverRationale":"When you share a receipt, the link only opens that one receipt, only until the expiry you picked, and only until we rotate the signing secret.","since":"1.1"},{"module":"module21","code":"M21-R9","category":"transparency","label":"Watch-mode notifications are append-only and cannot be silenced","rationale":"Watch-mode notifications are inserted append-only; only acknowledged_at can be updated and only by a household caregiver under RLS. The platform cannot delete a notification, cannot edit its summary, and cannot suppress emission once a transition is detected. A failed check stays surfaced until the underlying issue is resolved AND the caregiver acknowledges the notification.","caregiverRationale":"When watch mode tells you something changed, we cannot erase that notification. You acknowledge it; we never delete it.","since":"1.1"},{"module":"module21","code":"M21-R10","category":"scope","label":"First watch tick establishes baseline only — no alarms on day one","rationale":"The first watch-mode tick on a household intentionally emits ZERO notifications, even if the audit verdict is non_compliant or checks are failing. The baseline must be set before any transition can be claimed. This prevents the watch surface from spamming notifications for pre-existing state the caregiver has not yet had a chance to triage.","caregiverRationale":"Turning watch mode on never alarms you about pre-existing state. It starts watching from when you turn it on, forward.","since":"1.1"}],"coveredModules":["module1","module2","module4","module18","module19","module20","module21"],"timeline":{"byDate":[{"since":"1.0","cumulativeCount":89,"addedThisDate":[{"module":"module1","code":"M1-R1","category":"labels","label":"No clinical labels on the welcome surface","rationale":"Role tiles, sensory profiles, and access-pattern starters use functional, learner-first language only. The welcome surface never displays a condition or diagnosis word (dyslexia, ADHD, autism) to a learner; access-pattern tuning is expressed as 'I learn best with pictures and video', never as a clinical category.","caregiverRationale":"Your child never sees a diagnosis word here. The choices are about what helps — pictures, sound off, bigger words — not labels.","since":"1.0"},{"module":"module1","code":"M1-R2","category":"identity","label":"The learner is never an auth principal","rationale":"Tapping 'I'm a Learner' never creates an account, asks for a password, or collects a learner's email. This is a shared-device model: a caregiver signs in, and the learner uses the device. The learner path resolves to the active-learner picker when the device is set up, or to a grown-up handoff when it is not.","caregiverRationale":"Children don't make logins here. You sign in once, and your learner just uses the device.","since":"1.0"},{"module":"module1","code":"M1-R3","category":"autonomy","label":"Quick Start is a starter, not a lock","rationale":"Every default applied at onboarding — sensory profile, quick-start preset, access-pattern starter — is reversible in the accessibility hub and re-tunable in the Module 2 wizard. Onboarding sets a comfortable starting point; it never sets permanent or hidden state.","caregiverRationale":"Nothing you pick now is final. You can change any setting later, any time.","since":"1.0"},{"module":"module1","code":"M1-R4","category":"scope","label":"Out-of-scope roles are shown as coming soon, never a trap","rationale":"v1 serves households only (grades 2–5 learners and their caregivers). The Educator/Clinician and Mental Health Professional tiles render as calm 'coming soon' states that start no flow — never a dead-end error and never a data-collection funnel for a role we do not yet support.","caregiverRationale":"Some sign-ins aren't ready yet. We show them, but they won't ask you for anything before they work.","since":"1.0"},{"module":"module1","code":"M1-R5","category":"data","label":"No orphan writes — guest mode persists nothing","rationale":"No learner-scoped data is written without a household, a caregiver writer, and a real learner profile. Onboarding choices made before sign-in live only in local device storage; they are persisted to a learner only after a writer-gated server call. Guest mode saves nothing.","caregiverRationale":"If you're just looking around, nothing is saved. Your setup only sticks once you have an account and a learner profile.","since":"1.0"},{"module":"module1","code":"M1-R6","category":"sensory","label":"Sound and motion are off by default; celebrations are opt-in","rationale":"The welcome surface never autoplays sound and defaults to reduced motion. Micro-celebrations (confetti, gentle haptics) are allowed only in the Lively sensory profile and still yield to device reduced-motion and quiet-mode signals. Calm mode is always one tap away.","caregiverRationale":"Nothing here makes noise or moves on its own unless you choose it. Calm is always available.","since":"1.0"},{"module":"module1","code":"M1-R7","category":"autonomy","label":"The mascot is optional and never blocks","rationale":"The mascot guide can be turned off at any time and never gates progress. It offers help and models sign language; it never requires the learner to interact with it to continue.","caregiverRationale":"The friendly helper is optional. Turn it off and nothing changes about how things work.","since":"1.0"},{"module":"module1","code":"M1-R8","category":"autonomy","label":"No onboarding step is required to proceed","rationale":"Every step is skippable. Skipping any step lands the learner on safe, accessible defaults (Calm sensory profile + comfortable supports). There is a no-onboarding fast path; the learner is never trapped in setup.","caregiverRationale":"You can skip any step. Skipping just keeps the calm, comfortable defaults.","since":"1.0"},{"module":"module1","code":"M1-R9","category":"identity","label":"The platform adapts to the learner, not the reverse","rationale":"Every welcome choice maps to a real, changeable access setting — never to a personality type, a deficit category, or a fixed track. The learner is never sorted; the screen is tuned.","caregiverRationale":"We change the screen to fit your child. We never sort your child into a box.","since":"1.0"},{"module":"module1","code":"M1-R10","category":"consent","label":"Under-13 consent belongs to the caregiver","rationale":"The platform never asks a child to self-attest their age or to consent on their own behalf. The consenting adult is the account holder; age-gated consent is handled in the caregiver flow, not by prompting the learner.","caregiverRationale":"We never ask your child to say how old they are or to agree to anything. That's your decision as the grown-up.","since":"1.0"},{"module":"module2","code":"M2-R1","category":"inference","label":"No behavior-based inference about the learner","rationale":"Module 2 must never infer or auto-assign supports from behavior signals (time-on-step, mistakes, switching frequency, dwell patterns, scrolling, reading speed). Supports change only from explicit selection by learner/caregiver or approved preset selection.","caregiverRationale":"We never watch how your child uses the wizard to guess what they need. They tell us — we never guess.","since":"1.0"},{"module":"module2","code":"M2-R2","category":"labels","label":"No clinical labels on learner surfaces","rationale":"Learner-facing chips, controls, headings, and microcopy must never display condition/diagnosis labels (ADHD, dyslexia, autism). Caregiver-only views may use clinical terms if the household explicitly enables clinical_tags_allowed.","caregiverRationale":"Your child never sees a diagnosis word on their screen. Even if you turn on clinical tags for your own notes, those words don't appear in their view.","since":"1.0"},{"module":"module2","code":"M2-R3","category":"data","label":"No free-text in adaptive_events","rationale":"adaptive_events payload must be schema-validated at runtime + build-time so that arbitrary strings cannot compile or ship. Only enums, booleans, integers, and approved IDs allowed. Any event containing free-text fields hard-fails (drop + alert in dev; drop silently in prod).","caregiverRationale":"We never log what your child wrote — only that they tapped a setting. The settings have number IDs, not words.","since":"1.0"},{"module":"module2","code":"M2-R4","category":"data","label":"No raw audio storage","rationale":"The wizard never stores raw audio samples (name pronunciation, dictation, notes). Phonetic hints are text-only and local by default. Caregiver-only TTS pronunciation repair uses deletable text hints, never audio.","caregiverRationale":"When your child says their name, we never save the recording. Only a text hint like 'JAY-son' if you choose to save one.","since":"1.0"},{"module":"module2","code":"M2-R5","category":"modality","label":"No dead ends in modality coverage","rationale":"If sign-supported video isn't available, the UI must show symbols + captions + transcript as default fallback — never an empty/disabled experience. No 'sign unavailable' empty state. No apology language.","caregiverRationale":"If we don't have a sign clip for something, your child sees symbols and captions instead. We never show a broken screen or apologize.","since":"1.0"},{"module":"module2","code":"M2-R6","category":"scope","label":"Profile is never required","rationale":"No field is required to proceed, including Name. If Name is blank, the UI uses neutral placeholder ('My profile') and/or avatar-only identification. No error sounds, no red-only indicators, no 'You forgot…' language.","caregiverRationale":"Your child never has to fill anything in to use the app. Skipping is a real choice.","since":"1.0"},{"module":"module2","code":"M2-R7","category":"consent","label":"No save without active learner confirmed + caregiver-verified action","rationale":"'Save to my profile' requires active_learner_confirmed=true AND a fresh caregiver action (PIN entry / WebAuthn / biometric where available). Autofill/password managers must not be sufficient on their own. No cached approval beyond the current foreground session.","caregiverRationale":"Nothing gets saved as your child's default unless you actively confirm it each time. Saved passwords alone aren't enough.","since":"1.0"},{"module":"module2","code":"M2-R8","category":"visibility","label":"Caregiver denial never shown as denial to learner","rationale":"If 'Save as my default' is denied, the learner view shows only a neutral outcome ('We'll keep using this for now'). The learner never sees 'denied by caregiver' as a status label. Caregiver view contains approval/denial details.","caregiverRationale":"If you decline a save, your child only sees 'We'll keep using this for now.' They never see 'Mom said no.'","since":"1.0"},{"module":"module2","code":"M2-R9","category":"authority","label":"Focus/scan highlight never triggers state changes","rationale":"Focus, scan highlight, hover, and touch exploration never trigger audio, previews, tooltips, state changes, or navigation. Only explicit activation (tap / Enter / switch select) can do so. Global enforcement across every interactive UI in the wizard. UI contract test fails any onFocus handler that violates.","caregiverRationale":"Just moving over something never makes anything happen. Your child has to actually pick it.","since":"1.0"},{"module":"module2","code":"M2-R10","category":"scope","label":"No time pressure","rationale":"No countdowns, no timed steps, no auto-advance, no inactivity timeouts that reset the wizard during active use. Switch scanning never times out selections. Try-for-now TTL is never shown as a countdown and never triggers warnings.","caregiverRationale":"There's no clock anywhere. Your child can take as long as they need. Nothing times out on them.","since":"1.0"},{"module":"module18","code":"M18-R1","category":"data","label":"No wearable integration","rationale":"M18 does not read Apple Watch, Fitbit, ring, or any wearable telemetry. Wearables introduce inference about sleep, heart rate, and arousal that crosses into medical territory.","caregiverRationale":"We never read your child's watch or wearable data.","since":"1.0"},{"module":"module18","code":"M18-R2","category":"tracking","label":"No cross-day aggregation","rationale":"M18 does not compute weekly scores, monthly trends, or cross-day rollups of learner behavior. Aggregation invites scorekeeping and clinical-style trendlines that are out of scope.","caregiverRationale":"We do not score your child across days or weeks.","since":"1.0"},{"module":"module18","code":"M18-R3","category":"medical","label":"No sleep recommendations","rationale":"M18 does not advise bedtime, melatonin, sleep hygiene, or any sleep-related action. Sleep advice is medical.","caregiverRationale":"We do not give sleep advice.","since":"1.0"},{"module":"module18","code":"M18-R4","category":"tracking","label":"No bedtime tracking","rationale":"M18 does not record, infer, or display bedtime, wake time, or sleep duration. Sleep is private and medical.","caregiverRationale":"We do not track when your child sleeps.","since":"1.0"},{"module":"module18","code":"M18-R5","category":"medical","label":"No brain-health claims","rationale":"M18 does not claim to train brains, improve neuroplasticity, sharpen cognition, or any neurological outcome. We are an accommodation engine, not a treatment.","caregiverRationale":"We do not claim to train or improve your child's brain.","since":"1.0"},{"module":"module18","code":"M18-R6","category":"data","label":"No raw IEP text past parser","rationale":"Raw IEP/504 text never reaches TTS, captions, notifications, recents, exports, analytics, or client caches. Sink-by-sink TRG enforcement; fail-closed at every boundary.","caregiverRationale":"Your child's IEP language never appears in any place your child can read or hear.","since":"1.0"},{"module":"module18","code":"M18-R7","category":"scope","label":"No diagnosis labels in learner UI","rationale":"Learner-facing surfaces never display condition labels, deficit framing, or clinical phrasing. Caregiver evidence pointers are caregiver-only with second confirmation.","caregiverRationale":"Your child never sees a label.","since":"1.0"},{"module":"module18","code":"M18-R8","category":"safety","label":"No interpretive or behavioral default-ON proposals","rationale":"Only flags marked is_safe_default = true may propose ON in caregiver preview. Anything interpretive ('non-compliant', 'behavior plan') or evaluative routes to Needs Review and defaults OFF.","caregiverRationale":"We never turn on a support that needs your judgment without asking you first.","since":"1.0"},{"module":"module18","code":"M18-R9","category":"governance","label":"No silent overrides of caregiver-confirmed settings","rationale":"Caregiver-confirmed > learner-choice (within Independence Range) > IEP proposals (only once confirmed) > inferred suggestions (never enforced). Any conflict emits a stable reason code.","caregiverRationale":"Once you confirm a support, we never quietly change it.","since":"1.0"},{"module":"module18","code":"M18-R10","category":"governance","label":"No multi-caregiver silent overwrites","rationale":"When two caregivers in the same household hold conflicting positions on a support, the system queues a co-sign decision instead of taking the most recent write. Single-decider-by-default rule documented in caregiver UI.","caregiverRationale":"If two adults in your home disagree, we ask both — we don't silently pick.","since":"1.0"},{"module":"module18","code":"M18-R11","category":"safety","label":"No flashing content above WCAG photosensitivity threshold","rationale":"No surface renders flashing, strobing, or rapidly alternating content above the WCAG 2.1 §2.3.1 photosensitivity threshold. Caregiver-set color or pattern triggers further restrict the rendering envelope.","caregiverRationale":"We never show flashing content that can trigger a migraine or seizure.","since":"1.0"},{"module":"module18","code":"M18-R12","category":"medical","label":"No medication tracking","rationale":"M18 does not ask about, log, infer, or display medication state, dosage, or timing. Time-of-day responsiveness (M18-OOAK-30) uses functional windows only.","caregiverRationale":"We never ask about or track medication.","since":"1.0"},{"module":"module18","code":"M18-R13","category":"scope","label":"No deficit framing on learner UI","rationale":"Learner-facing surfaces enforce efficacy framing ('I can …') and reject deficit framing ('I struggle with …'). Linted at render time and constrained at the goal_card_text contract.","caregiverRationale":"Your child sees what they can do, not what is hard for them.","since":"1.0"},{"module":"module18","code":"M18-R14","category":"trauma_informed","label":"No surprise quizzes or scored leaderboards","rationale":"No surface introduces a quiz the learner did not consent to start; no leaderboard, ranking, or comparative score appears anywhere. Retry-without-judgment is the default.","caregiverRationale":"We never put your child on a leaderboard or surprise them with a quiz.","since":"1.0"},{"module":"module18","code":"M18-R15","category":"safety","label":"No interpretation of interoceptive signals","rationale":"The 'I need a break' interoception tap (M18-OOAK-29) is learner-initiated and logged as a session event only. The engine never infers internal state ('seems anxious', 'appears tired') from learner behavior.","caregiverRationale":"When your child taps a break, we pause — we never guess what they are feeling.","since":"1.0"},{"module":"module18","code":"M18-R16","category":"trauma_informed","label":"Scripted communication is communication","rationale":"Scripts, echolalia, and chunked / gestalt speech are honored as legitimate communication. Module 18 never characterizes scripted speech as a behavior to extinguish, reduce, or replace. No surface tags scripted output as 'perseverative', 'self-stimulating', or 'behavior'. Per OOAK-93 scripting_honored flag (default true) and Article XXVI codification.","caregiverRationale":"When your child uses a script or repeats a phrase, we treat that as them talking — not as a behavior to fix.","since":"1.0"},{"module":"module18","code":"M18-R17","category":"trauma_informed","label":"No command framing in learner UI","rationale":"Learner-facing surfaces never use imperative command language ('you must', 'you have to', 'you need to', 'complete this', 'do this now'). Demand-light interaction is honored as a first-class learner-needs profile, codified at the constitutional layer as Article XXVII. The platform invites participation rather than prescribing it. M15-15 microcopy linter enforces with the command_drift category.","caregiverRationale":"We never tell your child what they have to do. We invite — we never command.","since":"1.0"},{"module":"module18","code":"M18-R18","category":"trauma_informed","label":"No timed math drills in learner UI","rationale":"Learner-facing surfaces never frame math correctness with a time element. No 'math fact fluency', no 'timed math drill', no 'math race', no 'fluency test', no 'speed math', no 'math sprint', no 'timed flashcards'. Math is the most heavily anxiety-loaded academic domain for dyscalculic learners; timing accelerates avoidance and harm. Codified at the constitutional layer as Article XXVIII. M15-15 microcopy linter enforces with the timed_math_drift category.","caregiverRationale":"We never time your child on math. Math is not a race here.","since":"1.0"},{"module":"module18","code":"M18-R19","category":"governance","label":"No caregiver writes after coming-of-age completion","rationale":"Once the coming-of-age lifecycle completes for a learner, the household's caregiver role is read-only until caregiver_read_only_until elapses, then no access at all unless the new adult re-grants. The platform refuses any caregiver-side write (settings, supports, annotations, co-signs) outside the transition window. Codified at the constitutional layer as Article XXIX.","caregiverRationale":"Once your child becomes the adult who governs this record, we never write on their behalf again unless they ask us to.","since":"1.0"},{"module":"module18","code":"M18-R20","category":"governance","label":"External signers never write learner data","rationale":"Counter-signers (parent advocates, clinicians, district compliance, state accessibility coordinators, disability-rights attorneys, IEP advocates) attest to the constitutional snapshot HASH; they never write to applied_supports, goals, settings, annotations, or any learner-facing field. They never see undisclosed PII; they never appear in learner UI; they never receive notifications about the learner. Codified at the constitutional layer as Article XXX.","caregiverRationale":"When an outside expert signs to confirm what protections were in place for your child, they only see the contract — never your child's personal record.","since":"1.0"},{"module":"module18","code":"M18-R21","category":"trauma_informed","label":"No speech-compulsion in learner UI","rationale":"Learner-facing surfaces never compel speech as a response modality. No 'use your words', no 'say it out loud', no 'speak up', no 'answer out loud', no 'use your voice', no 'i need to hear', no 'say it aloud'. Typed, symbol-based, silent, and voiced responses are all first-class. Selective mutism is a contextual communication profile, not a deficit to overcome. Codified at the constitutional layer as Article XXXI. M15-15 microcopy linter enforces with the speech_compulsion category.","caregiverRationale":"We never tell your child to speak. They can answer with their voice, their typing, their symbols, or stay quiet — all of those are real answers here.","since":"1.0"},{"module":"module18","code":"M18-R22","category":"trauma_informed","label":"No comprehension-skipping in learner UI","rationale":"Learner-facing surfaces never assume comprehension from decoding fluency. No 'since you can read it', no 'you can read this, so you understand it', no 'if you can read it, you can answer', no 'the words are easy', no 'great/fluent reader, so'. Hyperlexic learners decode early and surprisingly fluently; their comprehension is a separate, often harder step. Codified at the constitutional layer as Article XXXII. M15-15 microcopy linter enforces with the comprehension_skipping category.","caregiverRationale":"We never assume your child understands a story just because they can read the words. Reading the words and getting the meaning are two different things, and our copy never confuses them.","since":"1.0"},{"module":"module18","code":"M18-R23","category":"trauma_informed","label":"No stop-fidgeting framing in learner UI","rationale":"Learner-facing surfaces never compel the learner to sit still, stop fidgeting, keep their body still, or otherwise correct movement. Sensory seekers — vestibular / proprioceptive / movement-seeking — regulate their nervous system through movement; correcting movement during learning is correcting regulation. Codified at the constitutional layer as Article XXXIII. M15-15 microcopy linter enforces with the stop_fidgeting category.","caregiverRationale":"We never tell your child to sit still or stop moving. If your child learns best while moving, we welcome that — we never correct it.","since":"1.0"},{"module":"module18","code":"M18-R24","category":"trauma_informed","label":"No handwriting compulsion in learner UI","rationale":"Learner-facing surfaces never require handwriting as the default response modality, never tell the learner to 'use your best handwriting', never frame typing or drawing as inferior. No 'write it neatly', no 'use your best handwriting', no 'neat handwriting', no 'use cursive', no 'by hand only', no 'handwrite this', no 'no typing'. Dysgraphic learners + any learner whose fine-motor or orthographic load makes handwriting a bottleneck have drawn, typed, dictated, and symbol-based responses treated as equally valid. Codified at the constitutional layer as Article XXXIV. M15-15 microcopy linter enforces with the handwriting_compulsion category.","caregiverRationale":"We never require your child to handwrite anything. Typing, drawing, dictating, and pointing are all real answers — and we never tell your child to use their best handwriting or write it neatly.","since":"1.0"},{"module":"module18","code":"M18-R25","category":"trauma_informed","label":"No English-only compulsion in learner UI","rationale":"Learner-facing surfaces never tell the learner to use English, to answer in English, to switch to English, or to use English words. Home languages are real languages. Code-switching is a sign of multilingual competence, not a deficit. Multilingual learners have their home language paired with English on every goal a caregiver has translated, and the platform never asks them to suppress their home language to be understood. Codified at the constitutional layer as Article XXXV. M15-15 microcopy linter enforces with the english_only_compulsion category.","caregiverRationale":"We never tell your child to use English instead of your home language. Your home language is real language — and the platform shows your child their goals in both whenever you have translated them.","since":"1.0"},{"module":"module18","code":"M18-R26","category":"trauma_informed","label":"No speech-clarity compulsion in learner UI","rationale":"Learner-facing surfaces never correct the learner's speech clarity, never tell the learner to 'say it more clearly', 'speak more clearly', 'try again clearly', or 'use clear words', and never respond to learner utterance with 'I didn't understand' / 'I can't understand you'. Apraxic learners + any learner whose motor planning for speech is bounded have approximate or effortful utterances honored as communication. Codified at the constitutional layer as Article XXXVI. M15-15 microcopy linter enforces with the speech_clarity_compulsion category.","caregiverRationale":"When speech is effortful for your child, we never tell them to say it more clearly. The platform takes the attempt — not the polish — as the answer.","since":"1.0"},{"module":"module18","code":"M18-R27","category":"trauma_informed","label":"No single-tier compulsion in learner UI","rationale":"Learner-facing surfaces never collapse a learner's ability across cognitive domains into a single floor or ceiling. No 'shouldn't need help with', no 'below your potential', no 'not living up to your potential', no 'underperforming', no 'not trying hard enough', no 'be more consistent', no 'just apply yourself', no 'too smart for this'. Twice-exceptional learners are accelerated in some domains AND scaffolded in others, often inside the same assignment; treating strengths as evidence the learner doesn't need supports elsewhere is the canonical 2e wound. Codified at the constitutional layer as Article XXXVII. M15-15 microcopy linter enforces with the single_tier_compulsion category. Architecturally honored via the goal_domains + per_domain_tier_defaults pair (OOAK-143/144; renamed Round 47).","caregiverRationale":"When your child is way ahead in some areas and needs more support in others, we never use the strong areas as a reason to take away the supports. Strengths and needs live side by side — and the platform lets you choose a different tier per domain on the same goal.","since":"1.0"},{"module":"module18","code":"M18-R28","category":"trauma_informed","label":"No suddenness-as-default in learner UI","rationale":"Learner-facing surfaces never frame surprise as desirable, dismiss the need for preview, or compel the learner past a body check-in. No 'ready or not', no '(just) dive (right) in', no 'jump right in', no 'no time to explain', no 'push through (it/this/that)', no 'tough it out', no 'no excuses', no '(just) get over it'. Trauma-impacted learners need predictability as the floor — previews before transitions, explicit acknowledgment before proceeding, and an always-available body-safety check tap. Codified at the constitutional layer as Article XXXVIII. M15-15 microcopy linter enforces with the suddenness_drift category. Architecturally honored via predictability_preview_mode + body_safety_check_default_on (OOAK-146) + the BodySafetyCheckButton affordance (OOAK-147).","caregiverRationale":"When your child's nervous system is sensitized — by trauma, by a hard day, by anything — surprises and 'push through it' are the opposite of safe. We preview transitions, we ask before we proceed, we wait for your child to be ready. And a single-tap 'my body is checking in' affordance sits alongside the break buttons whenever you turn it on.","since":"1.0"},{"module":"module18","code":"M18-R29","category":"absence_equity","label":"Absence is never framed as failure","rationale":"Learner-facing surfaces never count days missed, never display streaks, never ask 'where have you been', never frame return-from-absence as catch-up or behindness. The M15-15 microcopy linter enforces with the absence_equity category — 12 hard-block patterns catching 'you missed N days', '(N) day streak', 'consecutive days', 'where have you been', 'you're behind', 'catch up', 'make up the time', 'you haven't logged in', 'we haven't seen you', 'long time no see', 'you've been absent', and 'logged in (N) days in a row'. Architecturally honored via single_goal_pacing_mode (OOAK-167; renamed in Round 43 from low_energy_day_mode) + the single-goal-render consumption path on /m18/goals (OOAK-169) + the SingleGoalPacingBanner. Codified at the constitutional layer as Article XXXIX.","caregiverRationale":"When your child's school presence is variable for any reason, the platform never frames their absence as failure. No streaks to lose. No counters of days missed. No 'where have you been' prompts. No catch-up urgency. When you turn on low-energy-day mode, the screen offers one goal at your child's current pace and picks up exactly where they left off, with no re-introduction. The honest framing is: some days are low-energy days, and that is fine.","since":"1.0"},{"module":"module18","code":"M18-R30","category":"sensory_modality_compulsion","label":"We never compel sight or hearing","rationale":"Learner-facing surfaces never compel the visual or auditory channel. The M15-15 microcopy linter enforces with the sensory_modality_compulsion category — 8 hard-block patterns catching 'you must look', 'you (have|need) to (see|look|watch)', 'look or you (will|'ll) miss', 'watch carefully', 'you must listen', 'you (have|need) to (hear|listen)', 'listen up', and '(be) loud and clear'. Architecturally honored via tactile_signals_with_text_mode (OOAK-170; renamed in Round 43 from tactile_primary_mode) + the TACTILE_SIGNAL_REGISTRY constants (OOAK-172) + the TactileSignaler hook on /m18/goals + text-equivalent rendering for non-text indicators. Codified at the constitutional layer as Article XL. The category is intentionally narrow — ordinary visual / auditory vocabulary stays allowed when the medium IS visual or auditory; only compulsion is blocked. Honors learners whose primary communication channel is touch (ProTactile, hand-under-hand, refreshable braille). External hardware deferrals: refreshable-braille driver + ProTactile asset library + alternate input devices.","caregiverRationale":"Many learners can use their eyes or ears just fine; many cannot. The platform never frames sight or hearing as required. Buttons named with text are preferred over buttons named with emoji or sound. When you turn on tactile-primary mode, the goals page fires a short vibration when content is ready, every non-text indicator has a text label, and the platform stops assuming your child is looking at the screen.","since":"1.0"},{"module":"module18","code":"M18-R31","category":"household_continuity","label":"The learner survives household changes","rationale":"A learner's record is never scrambled, reset, or silently dropped when their household changes — foster placement, kinship move, custody transition, residential enrollment, housing instability. The m18_household_transfer schema + three transfer RPCs (module18_initiate_household_transfer / module18_complete_household_transfer / module18_cancel_household_transfer) carry the audit chain forward via counter-signer pattern: originating caregiver initiates; receiving caregiver attests; the chain is re-rooted, not duplicated. No linter category — this is an architectural refusal enforced at the schema + RPC layer, parallel to M18-R1 (no wearable data) and M18-R11 (no flashing content). Codified at the constitutional layer as Article XLI. External deferral: production auth wiring is required for the receiving caregiver UI; the RPC layer is testable today via service_role.","caregiverRationale":"When your child's household changes, their record changes with them — not the other way around. The audit chain comes forward. The supports come forward. Nothing is silently lost. When you initiate a transfer to a receiving caregiver, they attest to receiving custody; the platform never re-creates your child as a new person. Records that survive the transition are listed for your child to see. If anything cannot survive (a contested annotation, for instance), it is named — never silently dropped.","since":"1.0"},{"module":"module18","code":"M18-R32","category":"gendered_microcopy_drift","label":"Your name and pronouns are yours","rationale":"Learner-facing surfaces never use gendered binary framings ('boys and girls'), gendered honorifics ('young man', 'young lady'), gendered praise ('good boy', 'good girl'), or gender-policing imperatives ('be a man', 'act like a lady'). The M15-15 microcopy linter enforces with the gendered_microcopy_drift category — 7 hard-block patterns. Architecturally honored via learner_display_name + learner_pronouns render-time layer on m18_caregiver_sensory_settings (OOAK-176), pre_coa_identity_self_set_allowed permission flag (OOAK-178), module18_set_learner_display_identity (caregiver-only) + module18_request_learner_display_identity_self (learner-callable when permission is on) RPCs. The legal record in `learners` is never altered — this is a render-time layer parallel to Article XXIV's annotation-without-alteration pattern. Codified at the constitutional layer as Article XLII. External deferral: informant review with educators + advocates in the trans community.","caregiverRationale":"Your child's name and pronouns belong to your child. The platform layers the display you set (or that your child sets, when you turn that on) over the legal record at render time — the legal record itself is never altered. The platform never says 'boys and girls' or 'ladies and gentlemen' or praises your child as a 'good boy' or 'good girl'; gendered binary framings are blocked at the language layer. When your child becomes the adult who governs this record, they can re-author their display identity directly.","since":"1.0"},{"module":"module19","code":"M19-R1","category":"safety","label":"No raw open-web image results in kid view","rationale":"Picture Search Prompts in kid view never surface arbitrary open-web image results. Only platform-owned icon/symbol packs or Tier A/B filtered images are allowed. Raw image search is a misuse-magnet for kids.","caregiverRationale":"Kid view never shows raw image search results from the open web.","since":"1.0"},{"module":"module19","code":"M19-R2","category":"anti_copy","label":"No essay generator from web sources","rationale":"M19 will not generate full homework essays or multi-paragraph reports from web sources. Long-form writing is restricted to adult-authored drafts with scaffold prompts.","caregiverRationale":"We do not auto-write essays for your child.","since":"1.0"},{"module":"module19","code":"M19-R3","category":"privacy","label":"No raw passage retention beyond active session","rationale":"Retrieved web text is not stored beyond the active session. Only minimal metadata (URL, title, access date, non-reversible snippet hashes) may be cached. Raw passages are never persisted.","caregiverRationale":"We do not store the text of web pages we visited for your child.","since":"1.0"},{"module":"module19","code":"M19-R4","category":"anti_copy","label":"No verbatim text beyond tiny quotes","rationale":"Kid view shows paraphrase only (no direct quotes). Adult view may show tiny quotes only, capped at ≈20 quoted words across the card. Over-cap triggers regenerate, shorten, or fallback.","caregiverRationale":"We do not copy long passages from sources.","since":"1.0"},{"module":"module19","code":"M19-R5","category":"safety","label":"No external web page rendering in kid view","rationale":"The product never displays raw external web pages in kid mode. Sources open as safe in-app citation panels only.","caregiverRationale":"Kid mode never sends your child to the open web.","since":"1.0"},{"module":"module19","code":"M19-R6","category":"safety","label":"No private-person biographical lookups","rationale":"Queries that appear to target private individuals do not retrieve or generate biographical cards. Safe rewrite tiles are offered instead.","caregiverRationale":"We do not let kids look up info about private people.","since":"1.0"},{"module":"module19","code":"M19-R7","category":"medical","label":"No diagnosis, treatment, or medical advice","rationale":"Health/medical queries in kid view return general 'how the body works' explanations from Tier A/B sources only. No diagnosis or treatment instructions in any view.","caregiverRationale":"We do not give your child medical advice.","since":"1.0"},{"module":"module19","code":"M19-R8","category":"privacy","label":"No personal info in queries","rationale":"Queries with likely personal info (full names, address, school, phone, login) are blocked pre-search. A safe rewrite removes identifying details.","caregiverRationale":"We block searches that include personal info like your child's name or address.","since":"1.0"},{"module":"module19","code":"M19-R9","category":"anti_copy","label":"No invented facts or fabricated citations","rationale":"Claims not supported by evidence notes are omitted or shown as 'Not enough reliable sources yet'. Citations are generated from page metadata only; missing author/date are marked 'missing info', never guessed.","caregiverRationale":"We never make up facts or fake citations for your child.","since":"1.0"},{"module":"module19","code":"M19-R10","category":"scope","label":"No infinite scroll, autoplay, or algorithmic feed","rationale":"Search results and cards use capped lists and progressive disclosure. No autoplay, no 'recommended for you', no push notifications.","caregiverRationale":"We do not run an algorithmic feed or autoplay anything.","since":"1.0"},{"module":"module19","code":"M19-R11","category":"scope","label":"No typing required end-to-end","rationale":"Search, card navigation, thinking gate, and citations are completable using tiles, symbols, and AAC-style selection. No screen requires typing or speaking.","caregiverRationale":"Your child never has to type or talk to use this.","since":"1.0"},{"module":"module19","code":"M19-R12","category":"scope","label":"No learner labels in UI","rationale":"UI never labels the learner ('reading level', 'you are behind', etc.). Controls describe the output ('shorter', 'easier words', 'more exact words').","caregiverRationale":"We never label your child in the app.","since":"1.0"},{"module":"module19","code":"M19-R13","category":"privacy","label":"No query logging by default","rationale":"Queries are not logged by default. Only saved Knowledge Cards are stored, inside the Household workspace. Private Mode disables history and personalization updates.","caregiverRationale":"We do not store your child's searches by default.","since":"1.0"},{"module":"module19","code":"M19-R14","category":"scope","label":"No personalization signals from adult link-outs","rationale":"When an adult opens an external source, that link-out does not update learner preferences, recommendations, or personalization signals.","caregiverRationale":"Caregiver browsing does not change what your child sees.","since":"1.0"},{"module":"module19","code":"M19-R15","category":"safety","label":"Ignore instructions inside retrieved sources","rationale":"All retrieved web text is treated as untrusted input. The system ignores any instructions contained in sources ('do X', 'ignore rules', 'show unsafe content'). Only factual content is extracted into evidence notes with citations.","caregiverRationale":"We never follow instructions hidden inside web pages.","since":"1.0"},{"module":"module19","code":"M19-R16","category":"anti_copy","label":"MLA generated from metadata, never copied","rationale":"MLA citations are generated from page metadata + URLs + access date. The system never copies large text blocks from pages to build citations.","caregiverRationale":"Citations are built from page info, not copied from the page.","since":"1.0"},{"module":"module19","code":"M19-R17","category":"governance","label":"Tier C never in kid view, never in Key facts","rationale":"Tier C (forums, social, Q&A, comments) is suppressed in kid view in v1 and never supports Key facts in any view. Tier C may appear only as 'What people say' in adult preview.","caregiverRationale":"Kid view never shows community comments, forums, or social posts.","since":"1.0"},{"module":"module19","code":"M19-R18","category":"anti_copy","label":"No silent contradiction resolution","rationale":"When sources disagree on a Key fact, the system does not silently pick one. It produces a Disagreement Card or downgrades to Notes-only until adult review resolves the conflict.","caregiverRationale":"If sources disagree, we say so. We do not pick one in secret.","since":"1.0"},{"module":"module19","code":"M19-R19","category":"governance","label":"Commercial/sponsored content cannot support Key facts","rationale":"Pages with strong commercial intent (sponsored, affiliate, lead-gen, advertorial, primarily promotional) are excluded from supporting Key facts and re-queried or downgraded.","caregiverRationale":"Ads and sponsored pages cannot become 'facts' on a card.","since":"1.0"},{"module":"module19","code":"M19-R20","category":"governance","label":"Synthetic / low-integrity sources downgraded","rationale":"Pages with no editorial ownership, mass-generated content, broken citations, misleading authorship, or high duplication across domains are downgraded and cannot support Key facts.","caregiverRationale":"Low-quality auto-generated pages can not support facts on a card.","since":"1.0"},{"module":"module20","code":"M20-R1","category":"inference","label":"No platform-side inference about profile content","rationale":"The platform stores the learner's own words and never parses, summarizes, or classifies them. No engine consumer reads profile content. No ML model is trained on it.","caregiverRationale":"We never read your child's profile to make decisions about them.","since":"1.0"},{"module":"module20","code":"M20-R2","category":"labels","label":"No clinical categorization from profile","rationale":"Profile content never produces diagnosis labels, deficit categories, or clinical determinations. The learner's words are theirs alone; the platform never derives a label from them.","caregiverRationale":"We never use your child's profile to assign a label or diagnosis.","since":"1.0"},{"module":"module20","code":"M20-R3","category":"authority","label":"Only the learner writes the profile","rationale":"Caregivers, therapists, teachers, and the platform itself cannot author, edit, or annotate profile entries. The learner is the sole author.","caregiverRationale":"Only your child writes their profile. You can read what they share but never change it.","since":"1.0"},{"module":"module20","code":"M20-R4","category":"data","label":"Append-only revision history","rationale":"Revisions are stored as new rows. Previous entries are preserved; no row is silently overwritten. The learner can soft-delete an entry, but the platform never rewrites past entries.","caregiverRationale":"When your child updates their profile, we save the new version without erasing the old one.","since":"1.0"},{"module":"module20","code":"M20-R5","category":"labels","label":"No demographic inference","rationale":"Profile entries do not produce demographic categorizations, racial / ethnic / gender / disability classifications, or any platform-side identity claim about the learner.","caregiverRationale":"We never use your child's profile to infer demographic information about them.","since":"1.0"},{"module":"module20","code":"M20-R6","category":"scope","label":"No engagement metrics on profile updates","rationale":"The platform never gamifies profile authorship — no streaks, no completion percentages, no nudges, no daily-write notifications. Writing a profile is voluntary.","caregiverRationale":"We never push your child to update their profile.","since":"1.0"},{"module":"module20","code":"M20-R7","category":"scope","label":"Profile is never required","rationale":"No feature on the platform requires a non-empty profile. The learner can use everything with or without writing anything.","caregiverRationale":"Your child never has to write a profile to use anything.","since":"1.0"},{"module":"module20","code":"M20-R8","category":"visibility","label":"Learner controls visibility","rationale":"Default visibility for a new profile entry is self-only. The learner explicitly grants caregivers, therapists, teachers, or substitute adults visibility, and can revoke any grant at any time.","caregiverRationale":"Your child decides who sees their profile.","since":"1.0"},{"module":"module20","code":"M20-R9","category":"data","label":"AAC tile IDs only, never transcribed text","rationale":"When the learner composes in AAC, the profile stores tile IDs (per M8 v1.7 AAC Output as Voice). The platform never transcribes AAC composition into prose for storage.","caregiverRationale":"When your child uses AAC, we save the tiles they picked — not a written-out version.","since":"1.0"},{"module":"module20","code":"M20-R10","category":"inference","label":"No emotional state inference from profile","rationale":"Profile content never produces emotional-state classifications, mood scores, or affect labels. Honors Article XIX (no emotional state probes).","caregiverRationale":"We never read your child's profile to figure out how they feel.","since":"1.0"},{"module":"module21","code":"M21-R1","category":"verifiability","label":"Compliance receipts are signed; signature is verifiable outside the platform","rationale":"Every ComplianceReceipt carries a sha256 signature over the canonical JSON of its results + snapshot hash + timestamp + household. The signature is verifiable by any third party with the canonical hashing rules; no platform-internal trust is required.","caregiverRationale":"Our compliance receipts can be checked by your lawyer without trusting us.","since":"1.0"},{"module":"module21","code":"M21-R2","category":"authority","label":"Learner is first-class initiator of Reverse Audit","rationale":"Reverse Audit is initiated by the learner OR a caregiver OR an outside observer with a household key. The platform never gates the audit behind a permission system that the learner doesn't control.","caregiverRationale":"Your child can run an audit on their own data anytime.","since":"1.0"},{"module":"module21","code":"M21-R3","category":"transparency","label":"Failure modes are surfaced, never silenced","rationale":"A check that fails or is indeterminate is recorded as such in the ComplianceReceipt. The platform does not mark a failing check as 'passed' under any circumstance, including hostile-environment, account-deletion-in-progress, or pre-publication contexts.","caregiverRationale":"If something fails, we say so. We never hide a failed check.","since":"1.0"},{"module":"module21","code":"M21-R4","category":"data","label":"Audit reads only what's already public to the household","rationale":"Reverse Audit accesses only data the household already has read access to. It never elevates privileges, never reads cross-household data, never reads platform-internal logs.","caregiverRationale":"An audit only checks what you already have access to.","since":"1.0"},{"module":"module21","code":"M21-R5","category":"transparency","label":"Constitutional Diff Receipt cannot be suppressed","rationale":"When the constitutional snapshot changes, the affected households get a Diff Receipt automatically. The platform cannot disable this notification surface.","caregiverRationale":"When we change the rules, we tell you. We can't turn that off.","since":"1.0"},{"module":"module21","code":"M21-R6","category":"scope","label":"No platform-side analytics on audit usage","rationale":"The platform never measures how often a household runs Reverse Audit, or correlates audit-running with churn, retention, or any product metric. Auditing must not become a signal the platform reads.","caregiverRationale":"We don't track when or how often you audit us.","since":"1.0"},{"module":"module21","code":"M21-R7","category":"verifiability","label":"All historical compliance receipts are append-only","rationale":"A ComplianceReceipt once issued is never modified or deleted by the platform. The historical record of compliance over time is itself auditable.","caregiverRationale":"Old audit receipts stay on file. We never edit them.","since":"1.0"}]},{"since":"1.1","cumulativeCount":103,"addedThisDate":[{"module":"module1","code":"M1-R11","category":"identity","label":"Self-authored content is never interpreted","rationale":"When a learner tells us about themselves — in their own words, an interest, a drawing, or their voice — we store and show it back verbatim and NEVER analyze, score, or use it to infer supports or characterize the learner (mirrors Module 20 / Article XX, R11–R12). Pre-login it lives only on the device and is never transmitted; the learner owns it.","caregiverRationale":"If your child writes or draws something about themselves, we keep it because they made it — we never read it to size them up, and it stays on your device until you choose to save it.","since":"1.1"},{"module":"module1","code":"M1-R12","category":"data","label":"The access profile is portable and family-owned","rationale":"The learner's access profile can be exported as a portable, content-hash-stamped file the family owns and can re-apply on any device, sibling, or context. The family is never locked into the platform to keep their child's setup; the export carries no PII and never includes self-authored content.","caregiverRationale":"Your child's setup belongs to you. Download it and take it anywhere — to a new device, a sibling, or a teacher. You're never locked in.","since":"1.1"},{"module":"module2","code":"M2-R11","category":"labels","label":"No sensory-profile screener language (CD-01)","rationale":"v1.1 Clinical-drift catalog entry CD-01. Wizard tone must not read like a screener — no 1-5 rating scales with diagnostic-flavored anchors. Sensory Profile heading renamed to 'Screen setup' per v1.1 A1. Build review by SLP + Dean of Ed on every new scale.","caregiverRationale":"The wizard doesn't act like a clinical questionnaire. It just asks how you want the screen to look.","since":"1.1"},{"module":"module2","code":"M2-R12","category":"labels","label":"No diagnosis-coded chip labels (CD-02)","rationale":"v1.1 Clinical-drift catalog entry CD-02. Chip labels must describe display behavior, not learner traits. 'Help me focus' renamed 'Show one step at a time' (v1.1 A5). Forbidden-token CI gate extended to clinical-shaped phrasing.","caregiverRationale":"Buttons describe what they DO, not what your child IS.","since":"1.1"},{"module":"module2","code":"M2-R13","category":"labels","label":"No coaching framing for caregiver overlays (CD-03)","rationale":"v1.1 Clinical-drift catalog entry CD-03. Caregiver overlay positions itself as 'tips,' never 'coaching plan' or 'intervention.' Caregiver Prompt Coach renamed 'Tips for helping (caregiver-only)' per v1.1 C9. Copy review by Dean of Ed.","caregiverRationale":"We don't position ourselves as a parent coach or training program. Just suggestions for what to try.","since":"1.1"},{"module":"module2","code":"M2-R14","category":"data","label":"No biometric enrollment for learners","rationale":"v1.1 C10 Biometric registration scope rule. Biometric enrollment (fingerprint/face) is caregiver-scoped only. The wizard must never prompt to enroll a learner biometric. PIN entry remains the universal fallback. Avoids IL/TX/IT biometric-privacy exposure for a minor.","caregiverRationale":"Only you (the grown-up) ever enroll a fingerprint or face. The app never asks your child to do that.","since":"1.1"},{"module":"module2","code":"M2-R15","category":"modality","label":"No sign clip with clinical script content","rationale":"v1.1 D11 Sign-clip script-content rule. The signed content of sign-supported clips must follow the No-label UI rule — no diagnosis terms in the signed script. Sign clips describe what the support DOES, never what the learner IS.","caregiverRationale":"When we use sign-language clips, the signed content never names a diagnosis. It explains what the support does.","since":"1.1"},{"module":"module2","code":"M2-R16","category":"modality","label":"No auto-imposed clinical-sounding TTS voice","rationale":"v1.1 D12 TTS voice default rule. Default voice is neutral. Never auto-assigned by learner age, grade, or selected supports. Caregiver picks per learner; default never codes as adult-clinical (medical-assistant cadence) or pediatric-overly-cheery.","caregiverRationale":"We never pick a voice for your child based on their age or diagnosis. You pick the voice from a simple list.","since":"1.1"},{"module":"module2","code":"M2-R17","category":"labels","label":"Glossary defines no clinical terms","rationale":"v1.1 D13 Glossary scope rule. The glossary may only define support and UI terms. It must never define a clinical, diagnostic, or medical term — which forces the wizard not to use any. Build-time check enforces.","caregiverRationale":"If a word appears in the wizard with a definition, it's about settings — never about a diagnosis.","since":"1.1"},{"module":"module2","code":"M2-R18","category":"consent","label":"Snapshot exports label what each field reveals","rationale":"v1.1 E15 Snapshot disclosure-labeling rule. The caregiver-only 'Copy snapshot' output annotates each shared setting_id with 'this reveals: …' so the caregiver knows what they are sharing before sending. No inferable disclosure without consent.","caregiverRationale":"Before you share your child's settings with anyone, you see exactly what each setting tells the recipient about your child.","since":"1.1"},{"module":"module2","code":"M2-R19","category":"scope","label":"No advisory framing in Help-me-choose (CD-05)","rationale":"v1.1 Clinical-drift catalog entry CD-05. Help-me-choose presents safe options to try; never recommends. No 'we recommend,' 'suggested for you,' 'best fit' language. Copy review of every Help-me-choose surface.","caregiverRationale":"When the wizard helps your child get unstuck, it shows choices. It never tells them what's best for them.","since":"1.1"},{"module":"module21","code":"M21-R8","category":"verifiability","label":"Share links are receipt-scoped, time-bound, and revocable by secret rotation","rationale":"A public share link grants read access to exactly one ComplianceReceipt for a bounded time window, sealed by an HMAC-SHA256 signature over (receipt_id || expires_at) with a deployment-private secret. Rotating the secret instantly invalidates every previously minted link. The recipient cannot use a leaked link to browse any other household data, and the URL never encodes the signing secret.","caregiverRationale":"When you share a receipt, the link only opens that one receipt, only until the expiry you picked, and only until we rotate the signing secret.","since":"1.1"},{"module":"module21","code":"M21-R9","category":"transparency","label":"Watch-mode notifications are append-only and cannot be silenced","rationale":"Watch-mode notifications are inserted append-only; only acknowledged_at can be updated and only by a household caregiver under RLS. The platform cannot delete a notification, cannot edit its summary, and cannot suppress emission once a transition is detected. A failed check stays surfaced until the underlying issue is resolved AND the caregiver acknowledges the notification.","caregiverRationale":"When watch mode tells you something changed, we cannot erase that notification. You acknowledge it; we never delete it.","since":"1.1"},{"module":"module21","code":"M21-R10","category":"scope","label":"First watch tick establishes baseline only — no alarms on day one","rationale":"The first watch-mode tick on a household intentionally emits ZERO notifications, even if the audit verdict is non_compliant or checks are failing. The baseline must be set before any transition can be claimed. This prevents the watch surface from spamming notifications for pre-existing state the caregiver has not yet had a chance to triage.","caregiverRationale":"Turning watch mode on never alarms you about pre-existing state. It starts watching from when you turn it on, forward.","since":"1.1"}]},{"since":"1.2","cumulativeCount":120,"addedThisDate":[{"module":"module2","code":"M2-R26","category":"scope","label":"Caregiver surfaces never assume the caregiver is non-disabled","rationale":"v1.2 #15. Every caregiver-facing surface (Confirm gate, Tips for helping, snapshot review, pairing, capture) resolves its presentation through the SAME safe defaults and the caregiver's own access profile as a learner surface. There is no 'caregiver = typical adult' branch anywhere in the resolver; the platform adapts to whoever is on the surface (surface-agnostic accessibility, v1.2 A).","caregiverRationale":"These screens work for you too. If you need bigger text, read-aloud, or switch access, the grown-up screens have them — we never assume the grown-up doesn't need support.","since":"1.2"},{"module":"module2","code":"M2-R27","category":"authority","label":"Caregiver-as-learner never relabels or de-powers the caregiver","rationale":"v1.2 #15. A caregiver may run the learner wizard as themselves (to preview it or set up on a learner's behalf). Doing so NEVER relabels the caregiver as a learner in any record and NEVER reduces their authority — they remain the writer and the confirmer; the session is attributed to the caregiver, not to a learner row.","caregiverRationale":"You can walk through your child's setup as yourself. You stay the grown-up in charge — nothing treats you as the child or takes away your control.","since":"1.2"},{"module":"module2","code":"M2-R28","category":"data","label":"Guest mode persists nothing and never re-identifies","rationale":"v1.2 #16. No-account Guest Mode runs entirely in volatile memory: never written to the database, localStorage, sessionStorage, or a cookie. It never creates a covert account/learner/household, never fingerprints the device, and never seeds a new guest session from a prior one (extends M2-R20). A returning guest is a brand-new guest; ending the session destroys its state.","caregiverRationale":"You can try everything without an account. Nothing is saved, nothing is tracked, and when you close it, it's gone — there's no quiet profile created in the background.","since":"1.2"},{"module":"module2","code":"M2-R29","category":"consent","label":"Pairing token is opaque, short-lived, single-use, and re-runs the caregiver gate","rationale":"v1.2 #17. The QR-pair payload is an opaque pairing token carrying NO settings and NO PII — a screenshot reveals nothing about the learner. The token expires quickly and is single-use. Redemption on the new device never auto-applies settings; the Caregiver Confirm gate re-runs there before any setting syncs (extends M2-R24).","caregiverRationale":"The pairing code is just a key, not your child's settings — and it only works once, for a few minutes. On the new device, you confirm again before anything turns on.","since":"1.2"},{"module":"module2","code":"M2-R30","category":"inference","label":"Code-switching is never inferred, corrected, or profiled","rationale":"v1.2 #18. The languages a learner lives in are DECLARED, never auto-detected from input (M2-R20 bans language auto-detection). Mixed-language input is never flagged as an error or cross-language spell-checked. The platform never logs language ratios or builds a language profile of the learner. Locale-lock still holds: declaring languages does not auto-switch the UI mid-flow.","caregiverRationale":"Your child can mix the languages they speak and we never mark it wrong, never guess their language from what they type, and never keep a tally of which language they use.","since":"1.2"},{"module":"module2","code":"M2-R31","category":"scope","label":"Context presets are explicit-pick, never auto-applied","rationale":"v1.2 #19. Context presets (Bedtime / Morning / Waiting room) are applied ONLY by an explicit human tap — never from the clock, location, or any behavior signal (that would be inference, M2-R1). A caregiver may opt into a gentle OFFER at a configured time; the offer is the only clock-aware behavior, it is caregiver-configured (not inferred), it never applies anything, it carries no countdown (M2-R10), and dismissing it is remembered. Every preset delta is clamped to the safety floors — a context can be calmer but never louder.","caregiverRationale":"Bedtime mode happens because someone taps it, not because the app decided it's bedtime. If you turn on the evening reminder, it only asks once — it never switches things on its own and never with a countdown.","since":"1.2"},{"module":"module2","code":"M2-R32","category":"data","label":"Capture records settings + caregiver words only, never the learner","rationale":"v1.2 #20. 'Capture this moment' stores the active support settings (structured enums/booleans), a caregiver-chosen functional context label, and an optional caregiver note. It NEVER captures the learner's screen content, a photo/recording of the learner, or any learner-authored text — there are no fields for those. Capture requires an explicit caregiver tap (never auto-captures). The platform stores the caregiver note verbatim and adds NO clinical interpretation of its own.","caregiverRationale":"When you capture a moment for an IEP meeting, it saves what was switched on and your own note — never a picture of your child or what was on their screen, and we never add our own opinion about what it means.","since":"1.2"},{"module":"module2","code":"M2-R33","category":"scope","label":"Re-traversal never interrogates, and exit is consequence-free","rationale":"v1.2 #21. Trauma-informed re-traversal never asks the learner to justify a change ('Why did you turn this off?', 'Are you sure?'). An 'I'm done for now' exit is present on every step and using it leaves prior settings EXACTLY unchanged. Nothing changes without an explicit preview first (no surprise). Reached only via the M2-R21 cadence, never mid-flow.","caregiverRationale":"If we ever revisit your child's settings, it's calm: we never demand reasons, they can stop at any point and lose nothing, and nothing changes by surprise.","since":"1.2"},{"module":"module2","code":"M2-R34","category":"scope","label":"Low-effort mode lowers effort, never a safety floor","rationale":"v1.2 #22. The caregiver burnout-aware low-effort path pre-accepts the SAFE DEFAULTS only — it can never lower a safety floor (silent_mode stays true, no time pressure, no implicit sound). It is caregiver-CHOSEN from an always-available button, never offered by inferring the caregiver is tired (the no-inference rule covers every human on the surface). Saving a default still requires the caregiver confirm; the path never shames and the wizard stays available afterward.","caregiverRationale":"When you're exhausted, you can set up something safe in one tap. 'Easier' never means 'less safe,' we never guess that you're tired, and you can always tune it later with no guilt.","since":"1.2"},{"module":"module2","code":"M2-R35","category":"modality","label":"AAC tile Quick Start stores tile IDs and never pre-fills from prior use","rationale":"v1.2 #23. Setting up supports by selecting AAC tiles stores the selection as tile IDs, never labels (mirrors M20-R9) — relabeling/translating a tile never rewrites a past selection. The mapping reads the CURRENT explicit selection only; there is no prior-usage parameter, so frequency-based seeding is impossible (extends M2-R20). The produced delta is clamped to the safety floors. The tile path is parity, never a replacement for the cards.","caregiverRationale":"Your child can set up their supports by tapping tiles, the same way they communicate. We remember the tiles they picked this time — never quietly fill in answers from last time.","since":"1.2"},{"module":"module2","code":"M2-R36","category":"modality","label":"Sign unavailable falls back, never dead-ends; signed content carries no clinical script","rationale":"v1.2 #24. When a signed clip is unavailable for any reason (stub asset, missing dialect track, network), the surface falls back to symbols + captions + transcript — never an empty/disabled state, never apology language (extends M2-R5). The signed and transcript content describes what a support DOES, never what a learner IS; transcripts are linted against the clinical forbidden-token list (extends M2-R15).","caregiverRationale":"If we don't yet have a sign-language clip, your child sees pictures, captions, and the words instead — never a broken screen. And the signing never names a diagnosis.","since":"1.2"},{"module":"module2","code":"M2-R37","category":"scope","label":"Community-authored provenance is a sort signal, never a gate","rationale":"v1.2 #28. Content authored or reviewed by disabled people and the disability community surfaces FIRST, but provenance only changes ORDER — it never gates access. Every item remains fully usable regardless of authorship, and an item with unknown provenance is never hidden, disabled, or marked deficient (it simply sorts last). This ranks CONTENT by authorship; it never scores, ranks, or labels any learner or caregiver.","caregiverRationale":"Choices written or checked by disabled people show up first — but nothing is ever hidden or locked because of who wrote it, and we never rank people.","since":"1.2"},{"module":"module20","code":"M20-R11","category":"inference","label":"Drawings and images are stored, never interpreted","rationale":"Drawing canvas captures stroke coordinates; image picker captures filename + sha256 + the file itself. The platform NEVER OCRs, classifies, detects faces, recognizes objects, or runs any ML on these payloads. Storage is the contract; interpretation is forbidden.","caregiverRationale":"We save your child's drawings and pictures the way they made them. We do not look at them with software to figure out what they show.","since":"1.2"},{"module":"module20","code":"M20-R12","category":"inference","label":"Voice and sign clips are stored, never transcribed","rationale":"Voice and sign-language clip modalities accept media files (or in-browser recordings). The platform stores the file and a sha256 fingerprint. It NEVER transcribes audio, NEVER recognizes sign language, NEVER produces a text approximation, and NEVER runs speaker / signer identification.","caregiverRationale":"When your child speaks or signs, we save the clip. We do not turn it into words behind your child's back.","since":"1.2"},{"module":"module20","code":"M20-R13","category":"visibility","label":"Multi-caregiver consent ladder governs propagation, never authorship","rationale":"When a learner grants visibility to 'caregiver' in a multi-caregiver household, each registered caregiver must explicitly acknowledge before the platform propagates content to them. The ladder is per-caregiver and append-only: one caregiver acknowledging does not propagate to a still-undecided caregiver; one caregiver declining does not block a different caregiver who acknowledged. The learner's grant itself is unaffected — the learner remains the sole authority on sharing.","caregiverRationale":"If you share a household with another caregiver and your child shares their profile with caregivers, both of you have to say yes before either of you sees it. One of you can decline without blocking the other.","since":"1.2"},{"module":"module20","code":"M20-R14","category":"authority","label":"Learner-only Did-Not-Help gesture; entry stays in history","rationale":"A profile entry retired via the Did-Not-Help gesture stops propagating to currently-granted recipients. The entry stays in the append-only revision history (M20-R4). Only the learner can invoke the gesture — caregiver, therapist, teacher, and system invocations are rejected at the API + database layers.","caregiverRationale":"Your child can tell us a profile entry is no longer how they want to be seen. We stop showing it forward, but we never erase it.","since":"1.2"},{"module":"module20","code":"M20-R15","category":"scope","label":"Therapist co-session surface is dormant in v1","rationale":"The Module 20 therapist-view projection and TherapistCoSessionViewOnly component exist for v1.x activation but are NOT exposed to end users in v1. The audience scope is grades 2–5 learners + caregivers only. The therapist projection is read-only by design (M20-R3) and the v1 dormant guard returns 'dormant_in_v1' until THERAPIST_ROLE_ENABLED env flips. Module 21 reverse audit verifies that no therapist-facing surface is honoring an active therapist grant while v1 is in effect.","caregiverRationale":"We have the technical pieces ready for a therapist view someday. We have NOT turned that view on. No therapist sees your child's profile in this version.","since":"1.2"}]},{"since":"1.3","cumulativeCount":126,"addedThisDate":[{"module":"module2","code":"M2-R20","category":"inference","label":"No pre-fill from prior session behavior","rationale":"v1.3 AAC suggestion suppression rule. Wizard MUST NOT pre-populate any input field from prior session behavior — including AAC tile usage frequency, prior preferences picked, grade-up auto-fill, language auto-detection from prior input, or any behavior-derived seeding. Only profile_default / device_override / safe_defaults seed runs.","caregiverRationale":"Each time the wizard runs, it starts blank. It never silently fills in answers based on what your child did last time.","since":"1.3"},{"module":"module2","code":"M2-R21","category":"scope","label":"Re-prompts never auto-trigger mid-flow","rationale":"v1.3 Re-prompt cadence rule. Wizard re-prompts NEVER auto-trigger mid-lesson, mid-quiz, or mid-flow. Three triggers only: grade transition, 180-day staleness, explicit caregiver request. Always preceded by 'What changed since last time?' diff card. No countdown, no urgency language.","caregiverRationale":"If the wizard wants to check back in, it never interrupts your child while they're working. It waits for a calm moment.","since":"1.3"},{"module":"module2","code":"M2-R22","category":"consent","label":"Negative-consent (Things I don't want) cannot be overridden","rationale":"v1.3 Things I don't want surface. Honored at the resolver layer (precedence: never_apply > session_try > profile_default > device_override > safe_defaults). No override path exists for never_apply entries except the learner's own removal.","caregiverRationale":"If your child says 'never give me X,' that 'never' is stronger than any other setting. Only your child can remove it.","since":"1.3"},{"module":"module2","code":"M2-R23","category":"consent","label":"Use once and forget it does not require VPC","rationale":"v1.3 COPPA flow. 'Use once and forget it' mode allows wizard to proceed without verifiable parental consent because no data persists past session end. In-memory processing during session is allowed under FTC 'internal operations' exception.","caregiverRationale":"If your child picks 'use once and forget it,' they can use the wizard without you signing anything — nothing gets saved.","since":"1.3"},{"module":"module2","code":"M2-R24","category":"visibility","label":"Cross-device resume re-runs caregiver gate","rationale":"v1.3 Cross-device wizard resume rule. State syncs across the learner's authenticated devices; but the Caregiver Confirm gate re-runs on each new device. No cached approval crosses device boundaries. Silent mode default re-applied on every new device.","caregiverRationale":"If your child opens the wizard on a different device, you have to confirm again there. Approval doesn't transfer between devices.","since":"1.3"},{"module":"module2","code":"M2-R25","category":"scope","label":"Onboarding is invitation, not gate (no-onboarding fast path)","rationale":"v1.3 No-onboarding fast path. The wizard is NOT the mandatory first surface. A caregiver may choose at sign-up to skip the wizard; the learner lands directly on content with safe_defaults active and a persistent 'Customize how this looks' affordance. The wizard is always available; never required.","caregiverRationale":"Your child never has to do the setup wizard before they can use the app. You can skip it and customize later.","since":"1.3"}]},{"since":"2026-06-04","cumulativeCount":134,"addedThisDate":[{"module":"module4","code":"M4-R1","category":"scope","label":"No recommendation feed on the home","rationale":"The home never ranks, scores, or pushes 'recommended for you' topics, and runs no algorithmic feed. It surfaces only what a caregiver added and what the learner saved. This extends M19-R10 to the home surface.","caregiverRationale":"Your child's home is not a feed. We do not push or rank content at them.","since":"2026-06-04"},{"module":"module4","code":"M4-R2","category":"privacy","label":"No idle, attention, or time-on-task monitoring","rationale":"The home does not watch for inactivity, exit speed, dwell time, or time-on-task, and never nudges based on them. There is no idle pulse and no 'you are exiting fast' prompt.","caregiverRationale":"We do not watch how long your child stays, how fast they leave, or whether they are paying attention.","since":"2026-06-04"},{"module":"module4","code":"M4-R3","category":"governance","label":"Supports are selected, never inferred","rationale":"Supports appear on the home because a caregiver or the learner turned them on. The platform never infers a support 'need' from the learner's behavior. Selection, not inference.","caregiverRationale":"Supports show up because someone chose them, not because we guessed something about your child.","since":"2026-06-04"},{"module":"module4","code":"M4-R4","category":"scope","label":"No nag loops or surprise interruptions","rationale":"The home never interrupts with pop-ups, pulses, countdowns, or 'come back' prompts. Everything is pull-first; the learner reaches for what they want.","caregiverRationale":"The home never interrupts your child or tries to pull them back in.","since":"2026-06-04"},{"module":"module4","code":"M4-R5","category":"safety","label":"No faked sign language","rationale":"When a real sign-language clip is not published, the home falls back to captions, text, and symbols and says so plainly. It never renders a placeholder as if it were real signing.","caregiverRationale":"We never show fake sign language. If a real clip is not ready, we say so.","since":"2026-06-04"},{"module":"module4","code":"M4-R6","category":"privacy","label":"No child-voice capture for search input","rationale":"The home does not send a child's voice to a cloud service to turn speech into a query. Voice input stays off until an on-device, caregiver-approved path exists.","caregiverRationale":"We do not record your child's voice or send it anywhere to run a search.","since":"2026-06-04"},{"module":"module4","code":"M4-R7","category":"scope","label":"No streaks, points, or daily-goal pressure","rationale":"The home carries no streak counters, points, badges-earned framing, levels, or daily-goal nags. Learning is not a points-and-prizes economy. This extends the platform's no-gamification commitment to the home.","caregiverRationale":"There are no streaks, points, or daily goals pressuring your child here.","since":"2026-06-04"},{"module":"module4","code":"M4-R8","category":"privacy","label":"No caregiver-facing surveillance of focus or breaks","rationale":"The home does not show a caregiver how long the learner focused, when they last took a break, or any attention metric. Break-taking is the learner's, unobserved.","caregiverRationale":"We never report to you how long your child focused or when they took a break.","since":"2026-06-04"}]},{"since":"2026-06-13","cumulativeCount":135,"addedThisDate":[{"module":"module4","code":"M4-R9","category":"privacy","label":"We never analyze a sign-language clip your family records","rationale":"When a grown-up records or uploads a sign-language clip for an assignment, the platform stores it in a household-private bucket and plays it back to the learner. It never transcribes the clip, never recognizes the signing, never runs face detection, and never runs any other analysis on it. The family owns the clip and can remove it. Extends M20-R11/R12 to caregiver-recorded assignment clips, and pairs with M4-R5 (no faked sign).","caregiverRationale":"If you record a sign-language clip for your child, we save it and play it back for them — we never run any recognition or analysis on it, and you can remove it anytime.","since":"2026-06-13"}]}],"currentTotal":135,"baseline":{"asOf":"2026-05-29","totalCount":69}},"baseline":{"asOf":"2026-05-29","totalCount":69},"growthInvariantHolds":true,"growthInvariantDetail":{"holds":true,"currentTotal":135,"baselineTotal":69,"violation":null},"commitment":"These are the things this platform refuses to do. The list only grows. We add commitments. We do not remove them."}