Skip to content

Draft, pending legal review. This page describes how the product is being built. It has not yet been reviewed by our lawyers or our data protection officer, and the wording will change before launch. The rules themselves are settled; the phrasing is not.

Safeguarding

This product is used by 11 to 18 year olds and involves adults confirming things about them. That combination deserves to be designed carefully rather than moderated afterwards, so most of the safeguarding here is structural: the risky feature does not exist, rather than existing and being policed.

Our safeguarding rules

There is no messaging between users. Ever.

Not a chat, not comments, not a direct message, not a reply box. There is no route through this product by which one person can contact another. A verifier writes a statement about one achievement and that is the only free text anyone can send, and it goes to the young person's own record — not to them as a message.

There is no student directory and no search

You cannot look a young person up. There is no browse, no suggested people, no friends-of-friends, no handle you can type in to find a child. The handle every account gets is an internal identifier and a way of crediting a share; for anyone under 18 it does not resolve to a public page at all.

Verifiers can only respond, never initiate

An adult cannot go looking for a young person to confirm something about. They can only act on a request that a student sent them, using a single-use link or a QR code shown to them in person. Opening that link shows them exactly one achievement, and nothing else about the student — no other achievements, no school, no contact details, and no way through to the rest of their story.

Every story is private by default

Nothing is public until the young person deliberately makes it so, and for younger users a parent has to approve it. Sharing is per-item and revocable. A parent has a single control that switches off all sharing at once, and it takes effect immediately across links that have already been sent.

Built to the ICO Age Appropriate Design Code

High privacy by default, data minimisation, and settings that vary by age band rather than a single adult-shaped default. No nudge techniques, no streaks, no leaderboards, no engagement-farming notifications, and no dark patterns pushing a child toward lower privacy. No third-party analytics, advertising or profiling touches any screen a child can see.

Younger children and parent control

An account for a child under 13 is created and held by a parent, not by the child. Under-13 accounts cannot generate share cards at all. Where a young person’s name appears on anything shared, the default is a first name and an initial, full names are opt-in, and for under-16s that opt-in needs an adult. A school name is never shown next to a photograph of a child.

When something is wrong

A confirmation can be withdrawn by the adult who gave it, and anything shared publicly carries a way to dispute it. We keep the withdrawal on the record rather than quietly deleting it, because a record that can be silently edited is not evidence of anything. Free text is screened before it is published, and a person reviews anything flagged.

You can delete the account and take a full export of everything in it from inside the product, without asking us. See our privacy page for what we hold and for how long.