Our constitution
What this platform refuses to do
Each was added on purpose. None of them describes your child — they describe us. This list only grows: we add commitments, we do not remove them.
As of 2026-05-29 our floor was 69 commitments. An automated check runs on every build, so a removed commitment would surface as a public failure. You don’t have to take our word for it — verify it below.
What we never read
No orphan writes — guest mode persists nothing
If you're just looking around, nothing is saved. Your setup only sticks once you have an account and a learner profile.
M1-R5 · module1 · added 1.0
The access profile is portable and family-owned
Your child's setup belongs to you. Download it and take it anywhere — to a new device, a sibling, or a teacher. You're never locked in.
M1-R12 · module1 · added 1.1
No free-text in adaptive_events
We never log what your child wrote — only that they tapped a setting. The settings have number IDs, not words.
M2-R3 · module2 · added 1.0
No raw audio storage
When your child says their name, we never save the recording. Only a text hint like 'JAY-son' if you choose to save one.
M2-R4 · module2 · added 1.0
No biometric enrollment for learners
Only you (the grown-up) ever enroll a fingerprint or face. The app never asks your child to do that.
M2-R14 · module2 · added 1.1
Guest mode persists nothing and never re-identifies
You can try everything without an account. Nothing is saved, nothing is tracked, and when you close it, it's gone — there's no quiet profile created in the background.
M2-R28 · module2 · added 1.2
Capture records settings + caregiver words only, never the learner
When you capture a moment for an IEP meeting, it saves what was switched on and your own note — never a picture of your child or what was on their screen, and we never add our own opinion about what it means.
M2-R32 · module2 · added 1.2
No wearable integration
We never read your child's watch or wearable data.
M18-R1 · module18 · added 1.0
No raw IEP text past parser
Your child's IEP language never appears in any place your child can read or hear.
M18-R6 · module18 · added 1.0
Append-only revision history
When your child updates their profile, we save the new version without erasing the old one.
M20-R4 · module20 · added 1.0
AAC tile IDs only, never transcribed text
When your child uses AAC, we save the tiles they picked — not a written-out version.
M20-R9 · module20 · added 1.0
Audit reads only what's already public to the household
An audit only checks what you already have access to.
M21-R4 · module21 · added 1.0
What we never track
No cross-day aggregation
We do not score your child across days or weeks.
M18-R2 · module18 · added 1.0
No bedtime tracking
We do not track when your child sleeps.
M18-R4 · module18 · added 1.0
What we never do (medical)
No sleep recommendations
We do not give sleep advice.
M18-R3 · module18 · added 1.0
No brain-health claims
We do not claim to train or improve your child's brain.
M18-R5 · module18 · added 1.0
No medication tracking
We never ask about or track medication.
M18-R12 · module18 · added 1.0
No diagnosis, treatment, or medical advice
We do not give your child medical advice.
M19-R7 · module19 · added 1.0
How we protect your child
No faked sign language
We never show fake sign language. If a real clip is not ready, we say so.
M4-R5 · module4 · added 2026-06-04
No interpretive or behavioral default-ON proposals
We never turn on a support that needs your judgment without asking you first.
M18-R8 · module18 · added 1.0
No flashing content above WCAG photosensitivity threshold
We never show flashing content that can trigger a migraine or seizure.
M18-R11 · module18 · added 1.0
No interpretation of interoceptive signals
When your child taps a break, we pause — we never guess what they are feeling.
M18-R15 · module18 · added 1.0
No raw open-web image results in kid view
Kid view never shows raw image search results from the open web.
M19-R1 · module19 · added 1.0
No external web page rendering in kid view
Kid mode never sends your child to the open web.
M19-R5 · module19 · added 1.0
No private-person biographical lookups
We do not let kids look up info about private people.
M19-R6 · module19 · added 1.0
Ignore instructions inside retrieved sources
We never follow instructions hidden inside web pages.
M19-R15 · module19 · added 1.0
How sources are gated
Supports are selected, never inferred
Supports show up because someone chose them, not because we guessed something about your child.
M4-R3 · module4 · added 2026-06-04
No silent overrides of caregiver-confirmed settings
Once you confirm a support, we never quietly change it.
M18-R9 · module18 · added 1.0
No multi-caregiver silent overwrites
If two adults in your home disagree, we ask both — we don't silently pick.
M18-R10 · module18 · added 1.0
No caregiver writes after coming-of-age completion
Once your child becomes the adult who governs this record, we never write on their behalf again unless they ask us to.
M18-R19 · module18 · added 1.0
External signers never write learner data
When an outside expert signs to confirm what protections were in place for your child, they only see the contract — never your child's personal record.
M18-R20 · module18 · added 1.0
Tier C never in kid view, never in Key facts
Kid view never shows community comments, forums, or social posts.
M19-R17 · module19 · added 1.0
Commercial/sponsored content cannot support Key facts
Ads and sponsored pages cannot become 'facts' on a card.
M19-R19 · module19 · added 1.0
Synthetic / low-integrity sources downgraded
Low-quality auto-generated pages can not support facts on a card.
M19-R20 · module19 · added 1.0
What we will not build
Out-of-scope roles are shown as coming soon, never a trap
Some sign-ins aren't ready yet. We show them, but they won't ask you for anything before they work.
M1-R4 · module1 · added 1.0
Profile is never required
Your child never has to fill anything in to use the app. Skipping is a real choice.
M2-R6 · module2 · added 1.0
No time pressure
There's no clock anywhere. Your child can take as long as they need. Nothing times out on them.
M2-R10 · module2 · added 1.0
No advisory framing in Help-me-choose (CD-05)
When the wizard helps your child get unstuck, it shows choices. It never tells them what's best for them.
M2-R19 · module2 · added 1.1
Re-prompts never auto-trigger mid-flow
If the wizard wants to check back in, it never interrupts your child while they're working. It waits for a calm moment.
M2-R21 · module2 · added 1.3
Onboarding is invitation, not gate (no-onboarding fast path)
Your child never has to do the setup wizard before they can use the app. You can skip it and customize later.
M2-R25 · module2 · added 1.3
Caregiver surfaces never assume the caregiver is non-disabled
These screens work for you too. If you need bigger text, read-aloud, or switch access, the grown-up screens have them — we never assume the grown-up doesn't need support.
M2-R26 · module2 · added 1.2
Context presets are explicit-pick, never auto-applied
Bedtime mode happens because someone taps it, not because the app decided it's bedtime. If you turn on the evening reminder, it only asks once — it never switches things on its own and never with a countdown.
M2-R31 · module2 · added 1.2
Re-traversal never interrogates, and exit is consequence-free
If we ever revisit your child's settings, it's calm: we never demand reasons, they can stop at any point and lose nothing, and nothing changes by surprise.
M2-R33 · module2 · added 1.2
Low-effort mode lowers effort, never a safety floor
When you're exhausted, you can set up something safe in one tap. 'Easier' never means 'less safe,' we never guess that you're tired, and you can always tune it later with no guilt.
M2-R34 · module2 · added 1.2
Community-authored provenance is a sort signal, never a gate
Choices written or checked by disabled people show up first — but nothing is ever hidden or locked because of who wrote it, and we never rank people.
M2-R37 · module2 · added 1.2
No recommendation feed on the home
Your child's home is not a feed. We do not push or rank content at them.
M4-R1 · module4 · added 2026-06-04
No nag loops or surprise interruptions
The home never interrupts your child or tries to pull them back in.
M4-R4 · module4 · added 2026-06-04
No streaks, points, or daily-goal pressure
There are no streaks, points, or daily goals pressuring your child here.
M4-R7 · module4 · added 2026-06-04
No diagnosis labels in learner UI
Your child never sees a label.
M18-R7 · module18 · added 1.0
No deficit framing on learner UI
Your child sees what they can do, not what is hard for them.
M18-R13 · module18 · added 1.0
No infinite scroll, autoplay, or algorithmic feed
We do not run an algorithmic feed or autoplay anything.
M19-R10 · module19 · added 1.0
No typing required end-to-end
Your child never has to type or talk to use this.
M19-R11 · module19 · added 1.0
No learner labels in UI
We never label your child in the app.
M19-R12 · module19 · added 1.0
No personalization signals from adult link-outs
Caregiver browsing does not change what your child sees.
M19-R14 · module19 · added 1.0
No engagement metrics on profile updates
We never push your child to update their profile.
M20-R6 · module20 · added 1.0
Profile is never required
Your child never has to write a profile to use anything.
M20-R7 · module20 · added 1.0
Therapist co-session surface is dormant in v1
We have the technical pieces ready for a therapist view someday. We have NOT turned that view on. No therapist sees your child's profile in this version.
M20-R15 · module20 · added 1.2
No platform-side analytics on audit usage
We don't track when or how often you audit us.
M21-R6 · module21 · added 1.0
First watch tick establishes baseline only — no alarms on day one
Turning watch mode on never alarms you about pre-existing state. It starts watching from when you turn it on, forward.
M21-R10 · module21 · added 1.1
What we never store
No idle, attention, or time-on-task monitoring
We do not watch how long your child stays, how fast they leave, or whether they are paying attention.
M4-R2 · module4 · added 2026-06-04
No child-voice capture for search input
We do not record your child's voice or send it anywhere to run a search.
M4-R6 · module4 · added 2026-06-04
No caregiver-facing surveillance of focus or breaks
We never report to you how long your child focused or when they took a break.
M4-R8 · module4 · added 2026-06-04
We never analyze a sign-language clip your family records
If you record a sign-language clip for your child, we save it and play it back for them — we never run any recognition or analysis on it, and you can remove it anytime.
M4-R9 · module4 · added 2026-06-13
No raw passage retention beyond active session
We do not store the text of web pages we visited for your child.
M19-R3 · module19 · added 1.0
No personal info in queries
We block searches that include personal info like your child's name or address.
M19-R8 · module19 · added 1.0
No query logging by default
We do not store your child's searches by default.
M19-R13 · module19 · added 1.0
How we avoid plagiarism
No essay generator from web sources
We do not auto-write essays for your child.
M19-R2 · module19 · added 1.0
No verbatim text beyond tiny quotes
We do not copy long passages from sources.
M19-R4 · module19 · added 1.0
No invented facts or fabricated citations
We never make up facts or fake citations for your child.
M19-R9 · module19 · added 1.0
MLA generated from metadata, never copied
Citations are built from page info, not copied from the page.
M19-R16 · module19 · added 1.0
No silent contradiction resolution
If sources disagree, we say so. We do not pick one in secret.
M19-R18 · module19 · added 1.0
Who is allowed to do what
Focus/scan highlight never triggers state changes
Just moving over something never makes anything happen. Your child has to actually pick it.
M2-R9 · module2 · added 1.0
Caregiver-as-learner never relabels or de-powers the caregiver
You can walk through your child's setup as yourself. You stay the grown-up in charge — nothing treats you as the child or takes away your control.
M2-R27 · module2 · added 1.2
Only the learner writes the profile
Only your child writes their profile. You can read what they share but never change it.
M20-R3 · module20 · added 1.0
Learner-only Did-Not-Help gesture; entry stays in history
Your child can tell us a profile entry is no longer how they want to be seen. We stop showing it forward, but we never erase it.
M20-R14 · module20 · added 1.2
Learner is first-class initiator of Reverse Audit
Your child can run an audit on their own data anytime.
M21-R2 · module21 · added 1.0
What we never infer
No behavior-based inference about the learner
We never watch how your child uses the wizard to guess what they need. They tell us — we never guess.
M2-R1 · module2 · added 1.0
No pre-fill from prior session behavior
Each time the wizard runs, it starts blank. It never silently fills in answers based on what your child did last time.
M2-R20 · module2 · added 1.3
Code-switching is never inferred, corrected, or profiled
Your child can mix the languages they speak and we never mark it wrong, never guess their language from what they type, and never keep a tally of which language they use.
M2-R30 · module2 · added 1.2
No platform-side inference about profile content
We never read your child's profile to make decisions about them.
M20-R1 · module20 · added 1.0
No emotional state inference from profile
We never read your child's profile to figure out how they feel.
M20-R10 · module20 · added 1.0
Drawings and images are stored, never interpreted
We save your child's drawings and pictures the way they made them. We do not look at them with software to figure out what they show.
M20-R11 · module20 · added 1.2
Voice and sign clips are stored, never transcribed
When your child speaks or signs, we save the clip. We do not turn it into words behind your child's back.
M20-R12 · module20 · added 1.2
Who can see what
Caregiver denial never shown as denial to learner
If you decline a save, your child only sees 'We'll keep using this for now.' They never see 'Mom said no.'
M2-R8 · module2 · added 1.0
Cross-device resume re-runs caregiver gate
If your child opens the wizard on a different device, you have to confirm again there. Approval doesn't transfer between devices.
M2-R24 · module2 · added 1.3
Learner controls visibility
Your child decides who sees their profile.
M20-R8 · module20 · added 1.0
Multi-caregiver consent ladder governs propagation, never authorship
If you share a household with another caregiver and your child shares their profile with caregivers, both of you have to say yes before either of you sees it. One of you can decline without blocking the other.
M20-R13 · module20 · added 1.2
What we never label
No clinical labels on the welcome surface
Your child never sees a diagnosis word here. The choices are about what helps — pictures, sound off, bigger words — not labels.
M1-R1 · module1 · added 1.0
No clinical labels on learner surfaces
Your child never sees a diagnosis word on their screen. Even if you turn on clinical tags for your own notes, those words don't appear in their view.
M2-R2 · module2 · added 1.0
No sensory-profile screener language (CD-01)
The wizard doesn't act like a clinical questionnaire. It just asks how you want the screen to look.
M2-R11 · module2 · added 1.1
No diagnosis-coded chip labels (CD-02)
Buttons describe what they DO, not what your child IS.
M2-R12 · module2 · added 1.1
No coaching framing for caregiver overlays (CD-03)
We don't position ourselves as a parent coach or training program. Just suggestions for what to try.
M2-R13 · module2 · added 1.1
Glossary defines no clinical terms
If a word appears in the wizard with a definition, it's about settings — never about a diagnosis.
M2-R17 · module2 · added 1.1
No clinical categorization from profile
We never use your child's profile to assign a label or diagnosis.
M20-R2 · module20 · added 1.0
No demographic inference
We never use your child's profile to infer demographic information about them.
M20-R5 · module20 · added 1.0
How we show our work
Failure modes are surfaced, never silenced
If something fails, we say so. We never hide a failed check.
M21-R3 · module21 · added 1.0
Constitutional Diff Receipt cannot be suppressed
When we change the rules, we tell you. We can't turn that off.
M21-R5 · module21 · added 1.0
Watch-mode notifications are append-only and cannot be silenced
When watch mode tells you something changed, we cannot erase that notification. You acknowledge it; we never delete it.
M21-R9 · module21 · added 1.1
How you can verify us
Compliance receipts are signed; signature is verifiable outside the platform
Our compliance receipts can be checked by your lawyer without trusting us.
M21-R1 · module21 · added 1.0
All historical compliance receipts are append-only
Old audit receipts stay on file. We never edit them.
M21-R7 · module21 · added 1.0
Share links are receipt-scoped, time-bound, and revocable by secret rotation
When you share a receipt, the link only opens that one receipt, only until the expiry you picked, and only until we rotate the signing secret.
M21-R8 · module21 · added 1.1
How we honor history
No surprise quizzes or scored leaderboards
We never put your child on a leaderboard or surprise them with a quiz.
M18-R14 · module18 · added 1.0
Scripted communication is communication
When your child uses a script or repeats a phrase, we treat that as them talking — not as a behavior to fix.
M18-R16 · module18 · added 1.0
No command framing in learner UI
We never tell your child what they have to do. We invite — we never command.
M18-R17 · module18 · added 1.0
No timed math drills in learner UI
We never time your child on math. Math is not a race here.
M18-R18 · module18 · added 1.0
No speech-compulsion in learner UI
We never tell your child to speak. They can answer with their voice, their typing, their symbols, or stay quiet — all of those are real answers here.
M18-R21 · module18 · added 1.0
No comprehension-skipping in learner UI
We never assume your child understands a story just because they can read the words. Reading the words and getting the meaning are two different things, and our copy never confuses them.
M18-R22 · module18 · added 1.0
No stop-fidgeting framing in learner UI
We never tell your child to sit still or stop moving. If your child learns best while moving, we welcome that — we never correct it.
M18-R23 · module18 · added 1.0
No handwriting compulsion in learner UI
We never require your child to handwrite anything. Typing, drawing, dictating, and pointing are all real answers — and we never tell your child to use their best handwriting or write it neatly.
M18-R24 · module18 · added 1.0
No English-only compulsion in learner UI
We never tell your child to use English instead of your home language. Your home language is real language — and the platform shows your child their goals in both whenever you have translated them.
M18-R25 · module18 · added 1.0
No speech-clarity compulsion in learner UI
When speech is effortful for your child, we never tell them to say it more clearly. The platform takes the attempt — not the polish — as the answer.
M18-R26 · module18 · added 1.0
No single-tier compulsion in learner UI
When your child is way ahead in some areas and needs more support in others, we never use the strong areas as a reason to take away the supports. Strengths and needs live side by side — and the platform lets you choose a different tier per domain on the same goal.
M18-R27 · module18 · added 1.0
No suddenness-as-default in learner UI
When your child's nervous system is sensitized — by trauma, by a hard day, by anything — surprises and 'push through it' are the opposite of safe. We preview transitions, we ask before we proceed, we wait for your child to be ready. And a single-tap 'my body is checking in' affordance sits alongside the break buttons whenever you turn it on.
M18-R28 · module18 · added 1.0
identity
The learner is never an auth principal
Children don't make logins here. You sign in once, and your learner just uses the device.
M1-R2 · module1 · added 1.0
The platform adapts to the learner, not the reverse
We change the screen to fit your child. We never sort your child into a box.
M1-R9 · module1 · added 1.0
Self-authored content is never interpreted
If your child writes or draws something about themselves, we keep it because they made it — we never read it to size them up, and it stays on your device until you choose to save it.
M1-R11 · module1 · added 1.1
autonomy
Quick Start is a starter, not a lock
Nothing you pick now is final. You can change any setting later, any time.
M1-R3 · module1 · added 1.0
The mascot is optional and never blocks
The friendly helper is optional. Turn it off and nothing changes about how things work.
M1-R7 · module1 · added 1.0
No onboarding step is required to proceed
You can skip any step. Skipping just keeps the calm, comfortable defaults.
M1-R8 · module1 · added 1.0
sensory
Sound and motion are off by default; celebrations are opt-in
Nothing here makes noise or moves on its own unless you choose it. Calm is always available.
M1-R6 · module1 · added 1.0
consent
Under-13 consent belongs to the caregiver
We never ask your child to say how old they are or to agree to anything. That's your decision as the grown-up.
M1-R10 · module1 · added 1.0
No save without active learner confirmed + caregiver-verified action
Nothing gets saved as your child's default unless you actively confirm it each time. Saved passwords alone aren't enough.
M2-R7 · module2 · added 1.0
Snapshot exports label what each field reveals
Before you share your child's settings with anyone, you see exactly what each setting tells the recipient about your child.
M2-R18 · module2 · added 1.1
Negative-consent (Things I don't want) cannot be overridden
If your child says 'never give me X,' that 'never' is stronger than any other setting. Only your child can remove it.
M2-R22 · module2 · added 1.3
Use once and forget it does not require VPC
If your child picks 'use once and forget it,' they can use the wizard without you signing anything — nothing gets saved.
M2-R23 · module2 · added 1.3
Pairing token is opaque, short-lived, single-use, and re-runs the caregiver gate
The pairing code is just a key, not your child's settings — and it only works once, for a few minutes. On the new device, you confirm again before anything turns on.
M2-R29 · module2 · added 1.2
modality
No dead ends in modality coverage
If we don't have a sign clip for something, your child sees symbols and captions instead. We never show a broken screen or apologize.
M2-R5 · module2 · added 1.0
No sign clip with clinical script content
When we use sign-language clips, the signed content never names a diagnosis. It explains what the support does.
M2-R15 · module2 · added 1.1
No auto-imposed clinical-sounding TTS voice
We never pick a voice for your child based on their age or diagnosis. You pick the voice from a simple list.
M2-R16 · module2 · added 1.1
AAC tile Quick Start stores tile IDs and never pre-fills from prior use
Your child can set up their supports by tapping tiles, the same way they communicate. We remember the tiles they picked this time — never quietly fill in answers from last time.
M2-R35 · module2 · added 1.2
Sign unavailable falls back, never dead-ends; signed content carries no clinical script
If we don't yet have a sign-language clip, your child sees pictures, captions, and the words instead — never a broken screen. And the signing never names a diagnosis.
M2-R36 · module2 · added 1.2
absence_equity
Absence is never framed as failure
When your child's school presence is variable for any reason, the platform never frames their absence as failure. No streaks to lose. No counters of days missed. No 'where have you been' prompts. No catch-up urgency. When you turn on low-energy-day mode, the screen offers one goal at your child's current pace and picks up exactly where they left off, with no re-introduction. The honest framing is: some days are low-energy days, and that is fine.
M18-R29 · module18 · added 1.0
sensory_modality_compulsion
We never compel sight or hearing
Many learners can use their eyes or ears just fine; many cannot. The platform never frames sight or hearing as required. Buttons named with text are preferred over buttons named with emoji or sound. When you turn on tactile-primary mode, the goals page fires a short vibration when content is ready, every non-text indicator has a text label, and the platform stops assuming your child is looking at the screen.
M18-R30 · module18 · added 1.0
household_continuity
The learner survives household changes
When your child's household changes, their record changes with them — not the other way around. The audit chain comes forward. The supports come forward. Nothing is silently lost. When you initiate a transfer to a receiving caregiver, they attest to receiving custody; the platform never re-creates your child as a new person. Records that survive the transition are listed for your child to see. If anything cannot survive (a contested annotation, for instance), it is named — never silently dropped.
M18-R31 · module18 · added 1.0
gendered_microcopy_drift
Your name and pronouns are yours
Your child's name and pronouns belong to your child. The platform layers the display you set (or that your child sets, when you turn that on) over the legal record at render time — the legal record itself is never altered. The platform never says 'boys and girls' or 'ladies and gentlemen' or praises your child as a 'good boy' or 'good girl'; gendered binary framings are blocked at the language layer. When your child becomes the adult who governs this record, they can re-author their display identity directly.
M18-R32 · module18 · added 1.0