1. Guardian Protection is not independent child signup
GroupLock’s general account flow remains limited to people age 13 or older. A managed child profile is created and controlled by a verified parent or legal guardian. The initial Guardian Protection release does not give a child an independent password, email login, public profile, search listing, direct-contact pathway, or unsupervised messaging access.
2. Information requested for a managed child profile
GroupLock asks the guardian for a family-approved display name or nickname and an age band: age 5 or younger, ages 6–8, or ages 9–12. To start the k-ID jurisdiction-aware age gate, the guardian enters the child’s exact birth date in GroupLock’s protected interface. GroupLock sends that date directly to k-ID for that request and does not persist it in the GroupLock database. The service stores the age band, guardian relationship, provider status and permissions, circle requests, decisions, consent receipts, revocations, and safety audit events.
3. Why the information is used
- Create a private, guardian-controlled profile within the guardian’s Family plan.
- Route proposed circle participation to the guardian instead of adding the child automatically.
- Show the guardian the requester, stated purpose, participant count, risk findings, and restrictions before a decision.
- Issue, verify, suspend, expire, supersede, or revoke a scoped authorization receipt.
- Prevent public search, direct contacts, unsupported organization/school deployment, and circumvention of the guardian’s decision.
- Investigate safety problems and document guardian-controlled changes.
4. What approval permits—and what it does not
Approval permits only the limited circle association described in the request. Guardian Protection applies restrictions that prohibit direct messages, contact-detail disclosure, participant-list visibility to the managed profile, AI agents, recording, transcription, export, advertising, model training, and cross-platform bridging. Authorization expires after 90 days and is paused when a material change requires re-consent.
A guardian may decline privately, revoke an approved circle at any time, rotate the private invite code, or archive the managed child profile. GroupLock does not treat silence, a shared code, family membership, or an earlier approval as permission for a different circle or materially changed context.
Activity summaries may show the guardian counts for recent messages, files, reports, participants, administrators, and last activity. Activity summaries do not show message text or attachment contents. A guardian may separately request visible transcript oversight, but it activates only after every current participant agrees, covers future messages only, displays a continuing notice in the circle, and is revoked after a material change or any participant or guardian revocation.
5. Disclosure and service providers
Within an approved circle, the managed profile’s chosen display name may be shown as needed to represent membership. GroupLock does not provide the child’s synthetic internal account address, guardian contact details, age band, or verification details to other circle participants. When transcript oversight is proposed, current participants receive a direct disclosure and decide individually before any guardian access begins. GroupLock uses its hosting, database, private object-storage, email, and push providers as described in the Privacy Policy. GroupLock does not use third-party advertising networks or sell children’s personal information for advertising.
6. Guardian review, deletion, and further collection
The guardian may review managed profiles, active circle authorizations, and waiting requests in Settings → Guardian Protection. The Child Data Center lets the guardian review the retained-data inventory, correct the nickname or age band, download a child-specific export, and permanently delete only that child’s GroupLock profile and associated child data. Changing the age band revokes existing child consent, devices, circles, and school links so a fresh age gate and guardian approval are required.
Submit a privacy request to ask for access, correction, or deletion that is not already available in the product, or to stop further use of managed child information.
7. Production verification is a separate requirement
Recording these attestations does not by itself establish legally sufficient verifiable parental consent. GroupLock keeps production child access blocked until the commercial release connects a legally reviewed verification method, completes required privacy and safety review, and updates this notice if the production data flow changes. Internal pilot approval is only for controlled testing.
Qualified parental verification and child-specific consent
Production supervised-child access requires a current k-ID Family Connect session that identifies a trusted adult and records the child-specific GroupLock permissions approved by that adult. Verifying the adult does not by itself authorize a child to use every feature. GroupLock requires the configured child-chat and supervised-device permissions, the current child profile, each approved physical device, and each communication circle to remain independently authorized.
k-ID may collect age-gate, identity, and trusted-adult verification information directly under its own notice. GroupLock receives the resulting session status, jurisdiction, age category, enabled permission names, timestamps, and opaque provider references. GroupLock stores permission metadata and one-way references, not k-ID’s raw identity evidence, government-identification image, or the exact child birth date entered for the age gate.
Supervised child-device access
A managed child does not receive a reusable GroupLock password or independent email login. A child device creates a short-lived pairing code and a separate secret retained on that device. The signed-in guardian selects the child profile, reviews the physical device and current consent status, and approves the exact pairing code. The device then receives a revocable, time-limited supervised session.
GroupLock rechecks parental consent, Family billing, child-profile status, device approval, circle permission, and the active signed consent receipt whenever the child uses a protected feature. Guardian revocation, provider revocation, billing suspension, a material circle change, receipt expiration, child-profile archive, device logout, or a systemwide child-safety shutdown pauses or terminates access.
Age-appropriate messaging and reporting
The first supervised-child release hides attachments and disables child uploads and active external links. It checks child and adult outbound text for private contact information, unsafe secrecy or grooming, sexual solicitation, threats, self-harm language, drugs or weapons, bullying, and other configured safety risks. A blocked message is not delivered. GroupLock records a cryptographic content hash and high-level finding codes rather than retaining the blocked raw text in the safety event.
Children may report concerns using plain-language choices and an optional description. The guardian receives the safety alert. A high or critical event in a separately authorized school circle may also notify verified school safety personnel who have an appropriate role. Lock-screen and email alerts minimize child and message details. GroupLock is not an emergency service; immediate danger should be reported to a nearby trusted adult or emergency services.
Children’s data retention
The default supervised-child schedule retains child-scope messages for 90 days, child-scope attachments for 30 days, resolved child reports for 180 days, resolved child-safety events for 365 days, provider event hashes for 365 days, and consent/audit records for 1,095 days. A documented legal or active-safety hold may pause deletion only for the affected profile. GroupLock runs automated cleanup and records the result.
The guardian may revoke devices, provider permissions, school relationships, and circle permissions, or archive the managed child profile. Archiving disables future use and initiates the applicable deletion and retention workflow.
Separate school and organization workflow
A school must have a verified school profile, active organization billing, a signed data-protection agreement, guardian-direct consent mode, and verified staff roles before requesting a child relationship. A private child code creates only a guardian review request; it does not disclose a searchable child record or grant access.
Approving the school relationship does not add the child to a classroom or school circle. Every circle requires a separate guardian review of the purpose, final people, administrators, risk findings, restrictions, duration, and signed receipt. School or organization authority never becomes silent message access and never overrides the guardian or child-safety controls.
Production launch boundary
GroupLock keeps production supervised-child access disabled until qualified provider configuration, privacy and retention review, moderation and reporting review, supervised-device review, physical iPhone and Android testing, App Store and Google Play disclosures, school-workflow review, independent legal review, and independent security review are all complete. Administrator test profiles must be fictional and are labeled pilot-only.
8. Production verification provider
For production supervised child access, GroupLock uses a contracted hosted parental-verification provider. The provider may use an approved method such as a payment-card transaction, identity-document check, knowledge-based verification, video verification, or another method appropriate to the use case and applicable law. GroupLock receives a signed result and stores only minimized evidence of the method and outcome—not the provider’s raw identity documents or answers.
9. Supervised child device
After production verification, the guardian may create a 10-minute, single-use pairing code for a child’s iPhone, iPad, Android device, or controlled test device. The child must complete an online-safety orientation. Only current guardian-approved circles appear. The guardian can revoke the device or session at any time, and access also stops when the Family plan, guardian verification, profile, or consent receipt is no longer active.
10. Safety moderation and reporting
GroupLock applies age-appropriate safety rules in managed-child circles and may hold, block, warn on, or escalate concerning content. The child can use Get Help, report a concern, and ask to leave a circle immediately. Serious categories notify the guardian and GroupLock’s human safety-review process. GroupLock does not promise that automated rules detect every harmful message.
11. Organization and school requests
An organization cannot rely on its administrative role alone. It must operate an approved child program with current agreements, qualified staff, a safety lead, incident response, retention controls, and a documented privacy role. You separately decide whether to approve program enrollment and whether to approve each linked circle.
