GroupLock
Terms of Service

Permission comes before participation.

These Terms govern use of GroupLock and set expectations for accounts, consent-based messaging, Organizations, Family plans, paid features, safety, and account deletion.

Effective / version: 2026-08-28-child-safety-v3

1. Agreement and eligibility

By creating or using a GroupLock account after accepting these Terms, you agree to these Terms and acknowledge the current Privacy Policy. If you do not agree, do not use protected GroupLock features.

The general GroupLock account flow is for people age 13 or older. If you are under the age of legal majority where you live, you represent that you have any permission required by applicable law to use the service. Independent accounts for children under 13 are not supported through the general account flow. A child under 13 may be represented only through a separately enabled guardian-managed profile after the required parent or legal guardian authorization process.

2. What GroupLock provides

GroupLock is a communication-control and messaging service built around consent. A group invitation, Family invitation, or Organization invitation is a request for access—not automatic membership. GroupLock attempts to preserve that distinction throughout the product.

Features may include messaging, attachments, privacy rules, blocking/trusted lists, Family sharing, Organization administration, notifications, reporting, subscriptions, and other features made available in your version of the service.

3. Accounts and identity

You must provide accurate account information and protect your login credentials. Password accounts must verify control of their email before protected features are enabled. If you use Google or Microsoft sign-in, you authorize GroupLock to use the identity information returned by that provider for authentication.

You are responsible for activity performed through your account unless you promptly report unauthorized access and the activity is attributable to circumstances outside your reasonable control.

4. Consent-based invitations

  • You may not use GroupLock to evade another person’s block, decline, privacy rule, or other boundary.
  • Repeated unwanted invitations, harassment, intimidation, impersonation, or manipulative invitation practices are prohibited.
  • A recipient may accept or decline an invitation. Declining must not be treated as permission to add the recipient by another route.
  • Group creators and admins must not misrepresent who is proposed for a conversation or what the conversation is for.

5. User content and messaging

You keep ownership of content you lawfully own. You give GroupLock a limited, worldwide, non-exclusive license to host, store, transmit, reproduce, format, and display your content only as reasonably necessary to operate, secure, moderate, troubleshoot, and improve the service and to comply with law.

You must have the rights needed to upload or send content. Do not use GroupLock for illegal material, exploitation, credible threats, fraud, malicious code, unauthorized personal information, infringement, or other content that violates law or another person’s rights.

GroupLock does not currently represent that messages are end-to-end encrypted. Do not assume that GroupLock is suitable for secrets or regulated information merely because the product emphasizes privacy and consent.

6. Safety, blocking, and moderation

Users may block people, report conduct, and use available privacy controls. GroupLock may investigate reports, restrict features, remove content, suspend accounts, preserve evidence, or take other reasonable safety action when necessary to protect users, comply with law, or enforce these Terms.

Do not retaliate against another user for blocking, declining, reporting, leaving, or otherwise exercising a GroupLock boundary.

7. Organizations

Organization owners and admins may manage organizational structure, teams, roles, invitations, and permitted administrative settings. Administrative authority does not automatically grant access to private conversation content. An admin must personally have the conversation access required by the product before reading messages.

Organization membership is also consent-based. An admin may invite someone but may not silently enroll that person through the normal GroupLock workflow. Organizations are responsible for using GroupLock consistently with employment, education, privacy, recordkeeping, and other laws that apply to them.

8. Family plans

The Family plan owner controls the paid Family subscription and may invite eligible people to join. A Family invitation does not create membership until the invitee accepts. Accepted non-owner members may inherit Plus-level protections while the owner’s Family subscription remains active.

Family membership does not transfer ownership of another person’s account and must not create, overwrite, cancel, or otherwise alter a member’s independent Stripe subscription.

Guardian Protection is a distinct child-safety workflow within an eligible Family plan. A guardian who creates a managed child profile represents that the guardian is an adult with legal authority to make the relevant decisions. A private child invite code is not consent. Every circle request remains pending until the guardian approves it, and approval may be limited, suspended after material changes, expired, or revoked. Organization and school child deployments remain disabled until GroupLock expressly enables an appropriately reviewed workflow.

Guardian activity summaries provide counts and safety metadata rather than private message content. Optional guardian-visible transcript access is never hidden: it is limited to messages sent after activation, requires affirmative permission from every current participant, remains visibly disclosed inside the circle, may be revoked by any participant or the guardian, and is automatically revoked after material changes. No earlier conversation history becomes visible through that feature.

9. Paid plans and recurring billing

Paid plans provide recurring access to the features described at purchase. Prices, billing frequency, renewal information, and included features are displayed in the purchase flow. Unless otherwise stated by the applicable payment provider, recurring subscriptions continue until canceled.

GroupLock’s web checkout uses Stripe where enabled. Stripe-backed customers manage an existing web subscription through the billing-management flow provided by Stripe. The iOS and Android store builds will use the billing method required or permitted for the applicable store/region before native purchases are enabled.

Cancellation affects future entitlement according to the payment provider’s subscription state and applicable law. Mandatory refund or cancellation rights under applicable law or platform rules are not waived by these Terms.

10. Free and paid feature changes

GroupLock may add, remove, change, or reorganize features, limits, plans, or prices. We will not intentionally charge a new recurring price without the notice or authorization required by the applicable billing provider and law.

If a paid entitlement expires, GroupLock may make associated premium features unavailable while retaining settings so they can be restored if the user later regains access.

11. Account deletion and termination

You may initiate account deletion through GroupLock settings. Account deletion may also delete spaces you own, including owned Organizations or a Family plan, so GroupLock shows an impact review before confirmation.

A verified guardian may separately review, correct, export, or permanently delete one managed child profile through the Child Data Center without deleting the adult account. A documented legal or active-safety hold may pause destructive deletion for only the affected child profile. Age-band correction is treated as a material change and revokes child-specific consent, devices, school relationships, and circles until fresh authorization is completed.

GroupLock may suspend or terminate an account for serious or repeated Terms violations, fraud, abuse, security threats, legal requirements, or conduct that creates material risk to users or the service. Where appropriate, we may provide notice or an opportunity to contact support.

12. Third-party services

GroupLock relies on third-party infrastructure and optional services such as identity providers, email delivery, cloud storage, payment processing, app stores, and hosting infrastructure. Their services may have separate terms and privacy practices. GroupLock is not responsible for a third party’s independent service outside GroupLock’s control.

13. Service availability

We work to provide a reliable service, but GroupLock may experience maintenance, outages, network failures, software defects, third-party failures, or security incidents. The service is provided on an “as available” basis to the extent permitted by applicable law.

14. Disclaimers and liability

To the maximum extent permitted by applicable law, GroupLock does not guarantee that every unwanted communication, abusive user, spam attempt, or security risk will be prevented. Privacy controls reduce risk but do not create an absolute guarantee.

Nothing in these Terms excludes or limits liability that cannot lawfully be excluded. To the extent the law permits limitations, GroupLock will not be responsible for indirect, incidental, special, consequential, or punitive losses arising from use of the service where such limitations are enforceable.

15. Changes and current versions

We may update these Terms. The version is shown at the top. If a material update requires renewed agreement, GroupLock may block protected features until the signed-in user reviews and accepts the current Terms and acknowledges the current Privacy Policy.

16. Contact

Questions about these Terms, billing, privacy, safety, or account deletion can be submitted through GroupLock Support. Any mandatory consumer rights under applicable law remain available regardless of these Terms.

Guardian-supervised child access

Ordinary GroupLock accounts are for users age 13 or older. A child under 13 may use a supervised GroupLock feature only when GroupLock has enabled that production feature, a qualified guardian verification and child-specific parental-consent grant are current, the guardian owns an active Family plan, and the guardian has approved the child profile, physical device, and specific circle.

A managed child does not receive a reusable GroupLock password or independent email login. The guardian is responsible for keeping guardian credentials secure, approving only devices under appropriate supervision, reviewing current circles and school relationships, responding to safety concerns, and revoking access that is no longer appropriate.

Provider verification and consent

GroupLock’s preferred production adapter uses k-ID Family Connect to perform jurisdiction-aware age gating, identify a trusted adult, and record child-specific permissions. GroupLock may use another clearly disclosed qualified service if the provider changes. Provider approval does not require GroupLock to enable access when another prerequisite is missing. GroupLock may suspend or terminate child access when provider consent or a required permission is denied, revoked, expired, ambiguous, unverifiable, or inconsistent with the current child or feature scope.

The exact child birth date entered for the k-ID age gate is transmitted for that request and is not stored in GroupLock’s database. k-ID may process identity or trusted-adult evidence under its own notice. GroupLock stores opaque provider references, permission status, jurisdiction and age-category metadata, timestamps, and audit hashes needed to enforce and document consent.

You may not impersonate a parent or guardian, submit false identity or relationship information, reuse another family’s child code, intercept a provider callback, forge a webhook, manipulate a device-pairing secret, or use a fictional test profile for a real child.

Age-appropriate safety rules

Supervised-child circles are subject to stricter content, link, file, rate, reporting, retention, and access rules than ordinary adult circles. GroupLock may block a message before delivery when a configured child-safety rule identifies private information, grooming or unsafe secrecy, sexual solicitation, threats, self-harm language, drugs or weapons, bullying, unsafe links, or another age-inappropriate risk.

You may not ask a child to move the conversation to another platform, conceal a conversation from a trusted adult, share or request private contact information, send sexual content, threaten harm, evade child-safety checks, or retaliate against a child for making a safety report. GroupLock may notify the guardian and, in a separately authorized school workflow, appropriate verified safety staff.

Supervised-device restrictions

A child-device pairing code is temporary and is not a password or parental-consent artifact. The guardian must review the physical device and enter the code from the authenticated Guardian Protection center. GroupLock may limit the number of devices, replace an earlier session, revalidate access after backgrounding or cold launch, and revoke sessions after logout, inactivity, expiry, billing suspension, provider revocation, profile archive, circle revocation, material change, school revocation, or global safety shutdown.

Schools and education organizations

A school or youth-serving organization must complete the separate GroupLock school workflow before requesting a child relationship. Required controls may include an eligible organization type, active Organization plan, verified legal identity, signed data-protection agreement, direct guardian consent mode, and verified safety staff roles.

School approval establishes only the stated school relationship. It does not add the child to a classroom or school circle and does not give administrators silent message access. Each circle requires a separate guardian decision. Schools must use child information only for the authorized purpose, maintain accurate staff roles, respond to safety events, honor revocation and deletion, and comply with their own legal obligations.

Retention, audit, and investigation

GroupLock applies the supervised-child retention schedule described in the Privacy Policy and may retain consent receipts, revocation history, audit records, safety-event metadata, and documented legal or active-safety holds for the stated periods. GroupLock may preserve or review additional information when authorized by the guardian, required for an active safety response, legally required, or necessary to investigate abuse of the service.

Production availability and external review

The presence of code, a pilot profile, a draft store package, or a partially configured provider does not mean that production child access is available. GroupLock may keep the feature disabled until provider contracting and credentials, legal/privacy review, security review, physical iPhone and Android testing, store disclosures, school-workflow review, and other launch requirements are complete.

Administrator test profiles must be fictional, clearly labeled, and limited to synthetic testing. GroupLock may immediately disable production or pilot child access when evidence is incomplete, inaccurate, expired, or no longer matches the deployed application.

Guardian verification provider

Production under-13 features require a supported hosted parental-verification provider. You agree not to submit false identity, authority, payment, or verification information; evade provider checks; or use another adult’s verified status. GroupLock may suspend or revoke guardian status when verification expires, is disputed, appears compromised, or no longer meets the applicable provider or legal requirements.

Supervised child-device rules

A supervised device is paired and controlled by the verified guardian. The guardian is responsible for the physical device, pairing code, and appropriate use. The child may access only current guardian-approved circles and must complete the age-appropriate safety orientation. Child public search, direct contacts, direct messages, precise-location sharing, and independent account recovery are not provided through this workflow.

GroupLock may hold, block, warn on, or escalate content in a managed-child circle when child-safety rules detect private-information exchange, grooming, sexual content, threats, bullying, unsafe links, or other serious risks. Safety automation is not guaranteed to detect every concern and does not replace adult supervision, emergency services, or mandatory reporting.

Organization and school child programs

An organization must use the separate approved child-program workflow, maintain qualified staff, required agreements, background-check attestations, safety contacts, incident procedures, and appropriate privacy/education/healthcare contracts. Volunteers may not independently enroll or invite children. Program approval may be suspended at any time. Organization enrollment never creates automatic circle access; the guardian retains separate control over every child circle.