Skip to main content

Our constitution

What this platform refuses to do

135commitments
Growth-only promise: holdingacross 7 modules

Each was added on purpose. None of them describes your child — they describe us. This list only grows: we add commitments, we do not remove them.

As of 2026-05-29 our floor was 69 commitments. An automated check runs on every build, so a removed commitment would surface as a public failure. You don’t have to take our word for it — verify it below.

What we never read

  • No orphan writes — guest mode persists nothing

    If you're just looking around, nothing is saved. Your setup only sticks once you have an account and a learner profile.

    M1-R5 · module1 · added 1.0

  • The access profile is portable and family-owned

    Your child's setup belongs to you. Download it and take it anywhere — to a new device, a sibling, or a teacher. You're never locked in.

    M1-R12 · module1 · added 1.1

  • No free-text in adaptive_events

    We never log what your child wrote — only that they tapped a setting. The settings have number IDs, not words.

    M2-R3 · module2 · added 1.0

  • No raw audio storage

    When your child says their name, we never save the recording. Only a text hint like 'JAY-son' if you choose to save one.

    M2-R4 · module2 · added 1.0

  • No biometric enrollment for learners

    Only you (the grown-up) ever enroll a fingerprint or face. The app never asks your child to do that.

    M2-R14 · module2 · added 1.1

  • Guest mode persists nothing and never re-identifies

    You can try everything without an account. Nothing is saved, nothing is tracked, and when you close it, it's gone — there's no quiet profile created in the background.

    M2-R28 · module2 · added 1.2

  • Capture records settings + caregiver words only, never the learner

    When you capture a moment for an IEP meeting, it saves what was switched on and your own note — never a picture of your child or what was on their screen, and we never add our own opinion about what it means.

    M2-R32 · module2 · added 1.2

  • No wearable integration

    We never read your child's watch or wearable data.

    M18-R1 · module18 · added 1.0

  • No raw IEP text past parser

    Your child's IEP language never appears in any place your child can read or hear.

    M18-R6 · module18 · added 1.0

  • Append-only revision history

    When your child updates their profile, we save the new version without erasing the old one.

    M20-R4 · module20 · added 1.0

  • AAC tile IDs only, never transcribed text

    When your child uses AAC, we save the tiles they picked — not a written-out version.

    M20-R9 · module20 · added 1.0

  • Audit reads only what's already public to the household

    An audit only checks what you already have access to.

    M21-R4 · module21 · added 1.0

What we never track

  • No cross-day aggregation

    We do not score your child across days or weeks.

    M18-R2 · module18 · added 1.0

  • No bedtime tracking

    We do not track when your child sleeps.

    M18-R4 · module18 · added 1.0

What we never do (medical)

  • No sleep recommendations

    We do not give sleep advice.

    M18-R3 · module18 · added 1.0

  • No brain-health claims

    We do not claim to train or improve your child's brain.

    M18-R5 · module18 · added 1.0

  • No medication tracking

    We never ask about or track medication.

    M18-R12 · module18 · added 1.0

  • No diagnosis, treatment, or medical advice

    We do not give your child medical advice.

    M19-R7 · module19 · added 1.0

How we protect your child

  • No faked sign language

    We never show fake sign language. If a real clip is not ready, we say so.

    M4-R5 · module4 · added 2026-06-04

  • No interpretive or behavioral default-ON proposals

    We never turn on a support that needs your judgment without asking you first.

    M18-R8 · module18 · added 1.0

  • No flashing content above WCAG photosensitivity threshold

    We never show flashing content that can trigger a migraine or seizure.

    M18-R11 · module18 · added 1.0

  • No interpretation of interoceptive signals

    When your child taps a break, we pause — we never guess what they are feeling.

    M18-R15 · module18 · added 1.0

  • No raw open-web image results in kid view

    Kid view never shows raw image search results from the open web.

    M19-R1 · module19 · added 1.0

  • No external web page rendering in kid view

    Kid mode never sends your child to the open web.

    M19-R5 · module19 · added 1.0

  • No private-person biographical lookups

    We do not let kids look up info about private people.

    M19-R6 · module19 · added 1.0

  • Ignore instructions inside retrieved sources

    We never follow instructions hidden inside web pages.

    M19-R15 · module19 · added 1.0

How sources are gated

  • Supports are selected, never inferred

    Supports show up because someone chose them, not because we guessed something about your child.

    M4-R3 · module4 · added 2026-06-04

  • No silent overrides of caregiver-confirmed settings

    Once you confirm a support, we never quietly change it.

    M18-R9 · module18 · added 1.0

  • No multi-caregiver silent overwrites

    If two adults in your home disagree, we ask both — we don't silently pick.

    M18-R10 · module18 · added 1.0

  • No caregiver writes after coming-of-age completion

    Once your child becomes the adult who governs this record, we never write on their behalf again unless they ask us to.

    M18-R19 · module18 · added 1.0

  • External signers never write learner data

    When an outside expert signs to confirm what protections were in place for your child, they only see the contract — never your child's personal record.

    M18-R20 · module18 · added 1.0

  • Tier C never in kid view, never in Key facts

    Kid view never shows community comments, forums, or social posts.

    M19-R17 · module19 · added 1.0

  • Commercial/sponsored content cannot support Key facts

    Ads and sponsored pages cannot become 'facts' on a card.

    M19-R19 · module19 · added 1.0

  • Synthetic / low-integrity sources downgraded

    Low-quality auto-generated pages can not support facts on a card.

    M19-R20 · module19 · added 1.0

What we will not build

  • Out-of-scope roles are shown as coming soon, never a trap

    Some sign-ins aren't ready yet. We show them, but they won't ask you for anything before they work.

    M1-R4 · module1 · added 1.0

  • Profile is never required

    Your child never has to fill anything in to use the app. Skipping is a real choice.

    M2-R6 · module2 · added 1.0

  • No time pressure

    There's no clock anywhere. Your child can take as long as they need. Nothing times out on them.

    M2-R10 · module2 · added 1.0

  • No advisory framing in Help-me-choose (CD-05)

    When the wizard helps your child get unstuck, it shows choices. It never tells them what's best for them.

    M2-R19 · module2 · added 1.1

  • Re-prompts never auto-trigger mid-flow

    If the wizard wants to check back in, it never interrupts your child while they're working. It waits for a calm moment.

    M2-R21 · module2 · added 1.3

  • Onboarding is invitation, not gate (no-onboarding fast path)

    Your child never has to do the setup wizard before they can use the app. You can skip it and customize later.

    M2-R25 · module2 · added 1.3

  • Caregiver surfaces never assume the caregiver is non-disabled

    These screens work for you too. If you need bigger text, read-aloud, or switch access, the grown-up screens have them — we never assume the grown-up doesn't need support.

    M2-R26 · module2 · added 1.2

  • Context presets are explicit-pick, never auto-applied

    Bedtime mode happens because someone taps it, not because the app decided it's bedtime. If you turn on the evening reminder, it only asks once — it never switches things on its own and never with a countdown.

    M2-R31 · module2 · added 1.2

  • Re-traversal never interrogates, and exit is consequence-free

    If we ever revisit your child's settings, it's calm: we never demand reasons, they can stop at any point and lose nothing, and nothing changes by surprise.

    M2-R33 · module2 · added 1.2

  • Low-effort mode lowers effort, never a safety floor

    When you're exhausted, you can set up something safe in one tap. 'Easier' never means 'less safe,' we never guess that you're tired, and you can always tune it later with no guilt.

    M2-R34 · module2 · added 1.2

  • Community-authored provenance is a sort signal, never a gate

    Choices written or checked by disabled people show up first — but nothing is ever hidden or locked because of who wrote it, and we never rank people.

    M2-R37 · module2 · added 1.2

  • No recommendation feed on the home

    Your child's home is not a feed. We do not push or rank content at them.

    M4-R1 · module4 · added 2026-06-04

  • No nag loops or surprise interruptions

    The home never interrupts your child or tries to pull them back in.

    M4-R4 · module4 · added 2026-06-04

  • No streaks, points, or daily-goal pressure

    There are no streaks, points, or daily goals pressuring your child here.

    M4-R7 · module4 · added 2026-06-04

  • No diagnosis labels in learner UI

    Your child never sees a label.

    M18-R7 · module18 · added 1.0

  • No deficit framing on learner UI

    Your child sees what they can do, not what is hard for them.

    M18-R13 · module18 · added 1.0

  • No infinite scroll, autoplay, or algorithmic feed

    We do not run an algorithmic feed or autoplay anything.

    M19-R10 · module19 · added 1.0

  • No typing required end-to-end

    Your child never has to type or talk to use this.

    M19-R11 · module19 · added 1.0

  • No learner labels in UI

    We never label your child in the app.

    M19-R12 · module19 · added 1.0

  • No personalization signals from adult link-outs

    Caregiver browsing does not change what your child sees.

    M19-R14 · module19 · added 1.0

  • No engagement metrics on profile updates

    We never push your child to update their profile.

    M20-R6 · module20 · added 1.0

  • Profile is never required

    Your child never has to write a profile to use anything.

    M20-R7 · module20 · added 1.0

  • Therapist co-session surface is dormant in v1

    We have the technical pieces ready for a therapist view someday. We have NOT turned that view on. No therapist sees your child's profile in this version.

    M20-R15 · module20 · added 1.2

  • No platform-side analytics on audit usage

    We don't track when or how often you audit us.

    M21-R6 · module21 · added 1.0

  • First watch tick establishes baseline only — no alarms on day one

    Turning watch mode on never alarms you about pre-existing state. It starts watching from when you turn it on, forward.

    M21-R10 · module21 · added 1.1

What we never store

  • No idle, attention, or time-on-task monitoring

    We do not watch how long your child stays, how fast they leave, or whether they are paying attention.

    M4-R2 · module4 · added 2026-06-04

  • No child-voice capture for search input

    We do not record your child's voice or send it anywhere to run a search.

    M4-R6 · module4 · added 2026-06-04

  • No caregiver-facing surveillance of focus or breaks

    We never report to you how long your child focused or when they took a break.

    M4-R8 · module4 · added 2026-06-04

  • We never analyze a sign-language clip your family records

    If you record a sign-language clip for your child, we save it and play it back for them — we never run any recognition or analysis on it, and you can remove it anytime.

    M4-R9 · module4 · added 2026-06-13

  • No raw passage retention beyond active session

    We do not store the text of web pages we visited for your child.

    M19-R3 · module19 · added 1.0

  • No personal info in queries

    We block searches that include personal info like your child's name or address.

    M19-R8 · module19 · added 1.0

  • No query logging by default

    We do not store your child's searches by default.

    M19-R13 · module19 · added 1.0

How we avoid plagiarism

  • No essay generator from web sources

    We do not auto-write essays for your child.

    M19-R2 · module19 · added 1.0

  • No verbatim text beyond tiny quotes

    We do not copy long passages from sources.

    M19-R4 · module19 · added 1.0

  • No invented facts or fabricated citations

    We never make up facts or fake citations for your child.

    M19-R9 · module19 · added 1.0

  • MLA generated from metadata, never copied

    Citations are built from page info, not copied from the page.

    M19-R16 · module19 · added 1.0

  • No silent contradiction resolution

    If sources disagree, we say so. We do not pick one in secret.

    M19-R18 · module19 · added 1.0

Who is allowed to do what

  • Focus/scan highlight never triggers state changes

    Just moving over something never makes anything happen. Your child has to actually pick it.

    M2-R9 · module2 · added 1.0

  • Caregiver-as-learner never relabels or de-powers the caregiver

    You can walk through your child's setup as yourself. You stay the grown-up in charge — nothing treats you as the child or takes away your control.

    M2-R27 · module2 · added 1.2

  • Only the learner writes the profile

    Only your child writes their profile. You can read what they share but never change it.

    M20-R3 · module20 · added 1.0

  • Learner-only Did-Not-Help gesture; entry stays in history

    Your child can tell us a profile entry is no longer how they want to be seen. We stop showing it forward, but we never erase it.

    M20-R14 · module20 · added 1.2

  • Learner is first-class initiator of Reverse Audit

    Your child can run an audit on their own data anytime.

    M21-R2 · module21 · added 1.0

What we never infer

  • No behavior-based inference about the learner

    We never watch how your child uses the wizard to guess what they need. They tell us — we never guess.

    M2-R1 · module2 · added 1.0

  • No pre-fill from prior session behavior

    Each time the wizard runs, it starts blank. It never silently fills in answers based on what your child did last time.

    M2-R20 · module2 · added 1.3

  • Code-switching is never inferred, corrected, or profiled

    Your child can mix the languages they speak and we never mark it wrong, never guess their language from what they type, and never keep a tally of which language they use.

    M2-R30 · module2 · added 1.2

  • No platform-side inference about profile content

    We never read your child's profile to make decisions about them.

    M20-R1 · module20 · added 1.0

  • No emotional state inference from profile

    We never read your child's profile to figure out how they feel.

    M20-R10 · module20 · added 1.0

  • Drawings and images are stored, never interpreted

    We save your child's drawings and pictures the way they made them. We do not look at them with software to figure out what they show.

    M20-R11 · module20 · added 1.2

  • Voice and sign clips are stored, never transcribed

    When your child speaks or signs, we save the clip. We do not turn it into words behind your child's back.

    M20-R12 · module20 · added 1.2

Who can see what

  • Caregiver denial never shown as denial to learner

    If you decline a save, your child only sees 'We'll keep using this for now.' They never see 'Mom said no.'

    M2-R8 · module2 · added 1.0

  • Cross-device resume re-runs caregiver gate

    If your child opens the wizard on a different device, you have to confirm again there. Approval doesn't transfer between devices.

    M2-R24 · module2 · added 1.3

  • Learner controls visibility

    Your child decides who sees their profile.

    M20-R8 · module20 · added 1.0

  • Multi-caregiver consent ladder governs propagation, never authorship

    If you share a household with another caregiver and your child shares their profile with caregivers, both of you have to say yes before either of you sees it. One of you can decline without blocking the other.

    M20-R13 · module20 · added 1.2

What we never label

  • No clinical labels on the welcome surface

    Your child never sees a diagnosis word here. The choices are about what helps — pictures, sound off, bigger words — not labels.

    M1-R1 · module1 · added 1.0

  • No clinical labels on learner surfaces

    Your child never sees a diagnosis word on their screen. Even if you turn on clinical tags for your own notes, those words don't appear in their view.

    M2-R2 · module2 · added 1.0

  • No sensory-profile screener language (CD-01)

    The wizard doesn't act like a clinical questionnaire. It just asks how you want the screen to look.

    M2-R11 · module2 · added 1.1

  • No diagnosis-coded chip labels (CD-02)

    Buttons describe what they DO, not what your child IS.

    M2-R12 · module2 · added 1.1

  • No coaching framing for caregiver overlays (CD-03)

    We don't position ourselves as a parent coach or training program. Just suggestions for what to try.

    M2-R13 · module2 · added 1.1

  • Glossary defines no clinical terms

    If a word appears in the wizard with a definition, it's about settings — never about a diagnosis.

    M2-R17 · module2 · added 1.1

  • No clinical categorization from profile

    We never use your child's profile to assign a label or diagnosis.

    M20-R2 · module20 · added 1.0

  • No demographic inference

    We never use your child's profile to infer demographic information about them.

    M20-R5 · module20 · added 1.0

How we show our work

  • Failure modes are surfaced, never silenced

    If something fails, we say so. We never hide a failed check.

    M21-R3 · module21 · added 1.0

  • Constitutional Diff Receipt cannot be suppressed

    When we change the rules, we tell you. We can't turn that off.

    M21-R5 · module21 · added 1.0

  • Watch-mode notifications are append-only and cannot be silenced

    When watch mode tells you something changed, we cannot erase that notification. You acknowledge it; we never delete it.

    M21-R9 · module21 · added 1.1

How you can verify us

  • Compliance receipts are signed; signature is verifiable outside the platform

    Our compliance receipts can be checked by your lawyer without trusting us.

    M21-R1 · module21 · added 1.0

  • All historical compliance receipts are append-only

    Old audit receipts stay on file. We never edit them.

    M21-R7 · module21 · added 1.0

  • Share links are receipt-scoped, time-bound, and revocable by secret rotation

    When you share a receipt, the link only opens that one receipt, only until the expiry you picked, and only until we rotate the signing secret.

    M21-R8 · module21 · added 1.1

How we honor history

  • No surprise quizzes or scored leaderboards

    We never put your child on a leaderboard or surprise them with a quiz.

    M18-R14 · module18 · added 1.0

  • Scripted communication is communication

    When your child uses a script or repeats a phrase, we treat that as them talking — not as a behavior to fix.

    M18-R16 · module18 · added 1.0

  • No command framing in learner UI

    We never tell your child what they have to do. We invite — we never command.

    M18-R17 · module18 · added 1.0

  • No timed math drills in learner UI

    We never time your child on math. Math is not a race here.

    M18-R18 · module18 · added 1.0

  • No speech-compulsion in learner UI

    We never tell your child to speak. They can answer with their voice, their typing, their symbols, or stay quiet — all of those are real answers here.

    M18-R21 · module18 · added 1.0

  • No comprehension-skipping in learner UI

    We never assume your child understands a story just because they can read the words. Reading the words and getting the meaning are two different things, and our copy never confuses them.

    M18-R22 · module18 · added 1.0

  • No stop-fidgeting framing in learner UI

    We never tell your child to sit still or stop moving. If your child learns best while moving, we welcome that — we never correct it.

    M18-R23 · module18 · added 1.0

  • No handwriting compulsion in learner UI

    We never require your child to handwrite anything. Typing, drawing, dictating, and pointing are all real answers — and we never tell your child to use their best handwriting or write it neatly.

    M18-R24 · module18 · added 1.0

  • No English-only compulsion in learner UI

    We never tell your child to use English instead of your home language. Your home language is real language — and the platform shows your child their goals in both whenever you have translated them.

    M18-R25 · module18 · added 1.0

  • No speech-clarity compulsion in learner UI

    When speech is effortful for your child, we never tell them to say it more clearly. The platform takes the attempt — not the polish — as the answer.

    M18-R26 · module18 · added 1.0

  • No single-tier compulsion in learner UI

    When your child is way ahead in some areas and needs more support in others, we never use the strong areas as a reason to take away the supports. Strengths and needs live side by side — and the platform lets you choose a different tier per domain on the same goal.

    M18-R27 · module18 · added 1.0

  • No suddenness-as-default in learner UI

    When your child's nervous system is sensitized — by trauma, by a hard day, by anything — surprises and 'push through it' are the opposite of safe. We preview transitions, we ask before we proceed, we wait for your child to be ready. And a single-tap 'my body is checking in' affordance sits alongside the break buttons whenever you turn it on.

    M18-R28 · module18 · added 1.0

identity

  • The learner is never an auth principal

    Children don't make logins here. You sign in once, and your learner just uses the device.

    M1-R2 · module1 · added 1.0

  • The platform adapts to the learner, not the reverse

    We change the screen to fit your child. We never sort your child into a box.

    M1-R9 · module1 · added 1.0

  • Self-authored content is never interpreted

    If your child writes or draws something about themselves, we keep it because they made it — we never read it to size them up, and it stays on your device until you choose to save it.

    M1-R11 · module1 · added 1.1

autonomy

  • Quick Start is a starter, not a lock

    Nothing you pick now is final. You can change any setting later, any time.

    M1-R3 · module1 · added 1.0

  • The mascot is optional and never blocks

    The friendly helper is optional. Turn it off and nothing changes about how things work.

    M1-R7 · module1 · added 1.0

  • No onboarding step is required to proceed

    You can skip any step. Skipping just keeps the calm, comfortable defaults.

    M1-R8 · module1 · added 1.0

sensory

  • Sound and motion are off by default; celebrations are opt-in

    Nothing here makes noise or moves on its own unless you choose it. Calm is always available.

    M1-R6 · module1 · added 1.0

  • Under-13 consent belongs to the caregiver

    We never ask your child to say how old they are or to agree to anything. That's your decision as the grown-up.

    M1-R10 · module1 · added 1.0

  • No save without active learner confirmed + caregiver-verified action

    Nothing gets saved as your child's default unless you actively confirm it each time. Saved passwords alone aren't enough.

    M2-R7 · module2 · added 1.0

  • Snapshot exports label what each field reveals

    Before you share your child's settings with anyone, you see exactly what each setting tells the recipient about your child.

    M2-R18 · module2 · added 1.1

  • Negative-consent (Things I don't want) cannot be overridden

    If your child says 'never give me X,' that 'never' is stronger than any other setting. Only your child can remove it.

    M2-R22 · module2 · added 1.3

  • Use once and forget it does not require VPC

    If your child picks 'use once and forget it,' they can use the wizard without you signing anything — nothing gets saved.

    M2-R23 · module2 · added 1.3

  • Pairing token is opaque, short-lived, single-use, and re-runs the caregiver gate

    The pairing code is just a key, not your child's settings — and it only works once, for a few minutes. On the new device, you confirm again before anything turns on.

    M2-R29 · module2 · added 1.2

modality

  • No dead ends in modality coverage

    If we don't have a sign clip for something, your child sees symbols and captions instead. We never show a broken screen or apologize.

    M2-R5 · module2 · added 1.0

  • No sign clip with clinical script content

    When we use sign-language clips, the signed content never names a diagnosis. It explains what the support does.

    M2-R15 · module2 · added 1.1

  • No auto-imposed clinical-sounding TTS voice

    We never pick a voice for your child based on their age or diagnosis. You pick the voice from a simple list.

    M2-R16 · module2 · added 1.1

  • AAC tile Quick Start stores tile IDs and never pre-fills from prior use

    Your child can set up their supports by tapping tiles, the same way they communicate. We remember the tiles they picked this time — never quietly fill in answers from last time.

    M2-R35 · module2 · added 1.2

  • Sign unavailable falls back, never dead-ends; signed content carries no clinical script

    If we don't yet have a sign-language clip, your child sees pictures, captions, and the words instead — never a broken screen. And the signing never names a diagnosis.

    M2-R36 · module2 · added 1.2

absence_equity

  • Absence is never framed as failure

    When your child's school presence is variable for any reason, the platform never frames their absence as failure. No streaks to lose. No counters of days missed. No 'where have you been' prompts. No catch-up urgency. When you turn on low-energy-day mode, the screen offers one goal at your child's current pace and picks up exactly where they left off, with no re-introduction. The honest framing is: some days are low-energy days, and that is fine.

    M18-R29 · module18 · added 1.0

sensory_modality_compulsion

  • We never compel sight or hearing

    Many learners can use their eyes or ears just fine; many cannot. The platform never frames sight or hearing as required. Buttons named with text are preferred over buttons named with emoji or sound. When you turn on tactile-primary mode, the goals page fires a short vibration when content is ready, every non-text indicator has a text label, and the platform stops assuming your child is looking at the screen.

    M18-R30 · module18 · added 1.0

household_continuity

  • The learner survives household changes

    When your child's household changes, their record changes with them — not the other way around. The audit chain comes forward. The supports come forward. Nothing is silently lost. When you initiate a transfer to a receiving caregiver, they attest to receiving custody; the platform never re-creates your child as a new person. Records that survive the transition are listed for your child to see. If anything cannot survive (a contested annotation, for instance), it is named — never silently dropped.

    M18-R31 · module18 · added 1.0

gendered_microcopy_drift

  • Your name and pronouns are yours

    Your child's name and pronouns belong to your child. The platform layers the display you set (or that your child sets, when you turn that on) over the legal record at render time — the legal record itself is never altered. The platform never says 'boys and girls' or 'ladies and gentlemen' or praises your child as a 'good boy' or 'good girl'; gendered binary framings are blocked at the language layer. When your child becomes the adult who governs this record, they can re-author their display identity directly.

    M18-R32 · module18 · added 1.0

Verify it yourself

Advocates, attorneys, journalists, researchers, and families can check this without trusting us. The same data — every commitment, the date each was added, and the growth-only floor — is public as JSON.

Open the public feed →