Trust posture
Built family-safe — audited, gated, and on the record.
Plain-language pitch for parents, privacy-conscious users, and journalists. What we ship, what we don't, what's still in flight. Honesty + specificity over polish.
Children's data (COPPA)
Verifiable parental consent before any data is collected from a child account. A complete, parent-readable retention schedule — including the finite-bounding mechanism and the operational code path that enforces each window — is published as the Children's Data Retention Policy.
Take It Down Act compliance
The federal TAKE IT DOWN Act (2025) requires platforms hosting user content to act on takedown requests for non-consensual intimate imagery within 48 hours. ConKarma's public notice channel and procedure is documented and the 48-hour SLA is a hard commitment.
Family Shield — trusted-adult disclosure
Teens designate a non-parent trusted adult who can acknowledge a sensitive disclosure first. If they don't respond in a short window, escalation routes to parents per the cell's policy. No AI mediates the routing.
Zone isolation
The adult zone (Ember) is physically separated from the family zone (Serene). Children are blocked at the API by middleware. The adult zone is biometric-locked and screenshot-protected. The web variant excludes the adult zone entirely because the browser threat model doesn't carry those protections.
Agewall — self-attestation, no ID
Our public web Ember zone uses a self-attestation date-of-birth form + a 90-day cookie. We do not collect government ID, do not run a third-party age-assurance vendor, do not store your date of birth on our servers, and never share anything about the attestation. If Apple / Microsoft / jurisdictional law ever escalates, the architecture preserves a seam for a privacy-preserving age-assurance vendor (over-18 boolean only, never DOB revealed to us) — but we will never ask for your ID. Codified in ADR-114 and MINERVA-302; see Promise #16.
No cross-app tracking
No App Tracking Transparency prompt on iOS — there is nothing for the prompt to ask about. No behavioural ad networks. No third-party trackers on any surface. AdMob serves non-personalised ads to free-tier adult accounts only; child accounts see no ads of any kind.
Children and analytics
Server-side GA4 emission is gated on the child-user predicate — child accounts emit Prometheus operational metrics only, never product-analytics events that could profile them. Firebase Analytics on child accounts has ad-storage and analytics-storage disabled except for strictly necessary service telemetry.
Audit logs
Admin actions and security-relevant operations are written to a tamper-evident audit log with per-user-type retention windows. Child-account audit entries retain for seven years per the COPPA audit-trail requirement; adult-account entries retain per the corresponding statutory or operational ceiling.
Two-eye admin gates
Admin actions with high blast radius — impersonation, forcing a 2FA reset, publishing content from an admin surface — require dual super-admin approval. The audit log records both approvers; the action does not execute until both have signed.
Security disclosure
Vulnerability reports go to security@conkarma.app. A public bug-bounty program is in flight; it will be linked here once it goes live. Responsible-disclosure window is 90 days from acknowledgement; we publish a security advisory for any finding that ships a fix.
Transparency reports
We have committed to an annual transparency report covering law-enforcement requests, takedown volumes, and abuse-report outcomes. The first report's publication date is to-be-determined — we will not commit a fake cadence to look polished; we will commit a real one once the data collection for it has run for a full year.
Themed Nights — memory, not score
A Themed Night belongs to the family — or the couple — not to a leaderboard. The eleven principles, in plain language: the night becomes a memory (no points awarded, no success-rating, no public stats); no commercialization (we don't sell themed-night packs and there are no brand tie-ins inside the experience); cell-authored (the theme is yours; we don't push themes at you); opt-out at any moment without penalty; the Ember variant is adults-only, opt-in per couple, Mutual Deck-gated, safeword-overridden, asymmetry-soft-paused. ADR-095 on /build-in-public is the long-form; the practical how-tos are /help/themed-nights (Serene) and /help/ember-themed-evenings (couple-only). It's a composition layer over the existing toolkit (decks, captain, joysticks, workshop, ritual, lottery), not a new pillar.
Allergens — filtered, not diagnosed
ConKarma filters food + contact + dietary suggestions based on what your cell declared. We are not a medical device. We filter; we don’t override your judgment. /help/allergies-and-dietary-restrictions covers the 3-level severity ladder, decline-to-state, and the four hard avoids (no photo-detection, no clinical advice, no insurer / employer / wellness-program sharing, no drug-allergy schema). ADR-100 is the long-form on /build-in-public.
Accessibility — adapt without requesting on your behalf
ConKarma adapts suggestions to the accessibility needs you declare — without filing accommodation requests for you. We are not a medical device. /help/accessibility-and-mobility covers the cell-composition defaults, the brief surfacing for sitters/coaches/teachers, and the five hard avoids (no clinical assessment, no auto-detect from photo/video, no insurer/employer share, etc.). ADR-101 is the long-form.
Crisis routing — we don’t dispatch
ConKarma routes notifications based on the preferences you set. We do not dispatch emergency services. In a life-threatening emergency, call your country’s emergency number. /help/emergency-contacts-and-crisis-routing covers per-context routing, sitter brief scoping, and the COPPA pattern; /help/emergency-checkin lists per-region helpline numbers. ADR-102 is the long-form.
Topic avoidance — less of, never more
When you tell ConKarma to avoid a topic, we never invert that into more of the topic. /help/topic-avoidance covers the two severity levels, the temporary-allow path, and the COPPA anti-stigma pattern. We don’t auto-detect from message content, we don’t make a therapy/clinical referral from a declaration, and we don’t override your declaration platform-side. ADR-103 is the long-form.
Recovery — respected, not treated
ConKarma respects recovery. We filter suggestions; we don’t override your judgment. We are not a treatment platform. /help/substance-recovery covers visibility levels, opt-in helpline discoverability (SAMHSA, SMART Recovery, Nar-Anon, GamblersAnon — pull-only, never pushed), and the Ember alcohol-pairing intersection. ADR-104 is the long-form.
Communication style — adaption, not deficit
ConKarma adapts to how you work best. We respect difference; we never frame it as deficit. /help/communication-style covers the two-layer declaration model, brief surfacing for coach/sitter/teacher, and Backpack IEP coexistence. No diagnosis, no IEP auto-fill, no pity framing, no capability-deficit language, no disability-pride auto-curation. ADR-105 is the long-form.
Pronouns + identity — honored, never inferred
ConKarma honors how you want to be addressed. Pronouns are asked early; gender identity is a separate, opt-in layer; decline-to-state is first-class on both. Kid voice is always honored; identity changes are trans-protective (history is never republished under a previous identity). /help/pronouns-and-identity is the long-form. ADR-106.
Heritage language — yours to declare
Heritage language is distinct from interface locale; you can declare multiple; we never infer. The declaration powers cross-generational features and Lingua qualification. /help/heritage-language is the long-form. ADR-107.
Quiet hours — respected, overrides transparent
ConKarma respects your quiet hours. Safety-critical notifications may override; when they do, we tell you why and log the reason so you can audit it. /help/quiet-hours-and-sleep covers cell-mate honor and the COPPA pattern. No non-safety-critical override, no ad targeting based on quiet-hours data, no clinical sleep tracking. ADR-108 is the long-form.
Household composition — we adapt, you label
ConKarma uses household composition to make suggestions more relevant. We never label your family for you. We never target ads based on this (we don’t target ads anyway). /help/household-composition covers multi-select declaration, decline-to-state, and friends-of-cell scoping. ADR-109 is the long-form.
Co-parenting — coordination, not adjudication
ConKarma coordinates co-parenting based on what you and your co-parent independently agree to share. We don’t replace court orders or legal advice. We are not court-admissible. In a safety emergency, call your country’s emergency number or a DV hotline. /help/co-parenting covers cross-cell consent, kid voice, and the family-law disclaimer in detail. ADR-110.
Pets — we coordinate; your vet treats
ConKarma helps your family coordinate pet care — vaccinations, vet contact, behavior alerts, sitter handoffs, Family Captain rotation. We don’t replace your vet. In a pet emergency, call your vet or pet-emergency service. /help/pets covers the sitter brief pet section + Family Captain rotation + the pet-loss-grief support pointer to /features/lookouts. ADR-111.
Pairings — mocktail always equal
When we suggest pairings inside the Ember zone, we always suggest a zero-proof option co-equal with any alcoholic one. We never sell alcohol, never push it, never claim it's good for you, never tell you how much. A partner in recovery can set the cell to mocktail-only structurally. The Ember-internal /help walks through the abstainer-first defaults and the recovery commitment; ADR-096 is the long-form on /build-in-public.
Mixed families — assumed by default
ConKarma assumes your family is mixed until you tell us otherwise. No primary-religion field on a cell. No proselytizing surface. No platform-interpretation of your traditions — the app surfaces conflicts when traditions clash on a date, but never picks a side. Declared religion is special-category PII (GDPR Art. 9), field-encrypted at rest, never trained on. /help/mixed-families covers the inclusive defaults and the decline-to-state first-class option; ADR-097 is the long-form.
Your wall — pull discovery, never push
Your widget wall is yours: per-zone (Serene + Ember separate), persona-aware on first run, kid-safe-filtered for under-13. No engagement metrics on customization, no escalating suggestion cadence, no 'feature adoption' score, no cell-mate force-set of another adult's wall. The one strip we never let you hide is the safety strip — structural backstop, not optional. /help/customizing-your-base covers it; ADR-098 is the long-form.
Updates — honest changelog, rare force-block
When there's a new version, we'll tell you what changed (by category: security / safety / compliance / feature). When we have to block an old version, we'll tell you why — and we'll keep that rare. Force-block is security/safety/compliance only, never for feature adoption, two-eye-gated. Data export and account cancellation always work, including on a blocked version. /build-in-public publishes a per-quarter count of force-block invocations (anonymous reason summaries, never per-user). /help/updates is the long-form.
Lotteries, not auctions
ConKarma uses lotteries. We don't run auctions. Family decisions shouldn't be won by whoever has the most chips. The mechanic is random with a fair-share floor — over time, every cell-mate is guaranteed at least N/M of the wins, and any kid can opt out at any time without penalty. /help/lotteries walks through the three scenarios and the guard rails; ADR-094 on /build-in-public is the long-form decision.
Rupture and transition
We're built for the family you have, the family you become, and the family you carry forward. Families change shape — bereavement, crisis, separation, identity change, the slow work of becoming someone new. The app changes with you. The eight principles, in plain language: (1) data follows the person, not the cell, so what you build travels with you; (2) bereavement gets a soft path — memory without forced forgetting, no surprise anniversary nudges; (3) a crisis mode (soft-mode) quiets the daily loop when life needs your attention more than the app does; (4) identity changes — name, pronouns, family role — are supported without losing your history; (5) safe exit from a cell that's no longer right for you is a structural part of the app, on your terms; (6) divorce and re-forming get plain mechanics — splitting a cell, forming new ones, sharing kids across two households; (7) carry-forward — what you build in one chapter of family life isn't trapped there; (8) the surfaces respect the chapter you're in — soft-mode tones things down, identity changes propagate quietly, bereavement keeps memory available without enforcing it. The full architecture decision is ADR-092 in /build-in-public; the practical how-to articles for each scenario live in /help.
Common questions
- How is my child's data protected?
- Verifiable parental consent before any data is collected. A complete retention schedule with operational backing — including which scheduled worker enforces each window — is published at /legal/coppa-data-retention. Server-side analytics emission is gated for under-13s. Adult-zone surfaces are blocked at the API for child accounts.
- What happens if my child reports something scary?
- Family Shield routes the disclosure to a designated trusted adult first; if they don't acknowledge in a short window, escalation reaches parents per the cell's policy. No AI mediates — the disclosure path is human-to-human. Where local law requires mandatory reporting, the trusted adult is responsible for their own legal obligation; ConKarma is a routing surface, not a custodian.
- What user data do you sell?
- None. We do not sell personal information, we do not 'share' it as defined by the CCPA/CPRA, and we do not participate in behavioural ad networks. The web companion at conkarma.app has no third-party trackers; the mobile clients carry no behavioural-ad SDKs.
Reach us
Trust questions, takedown requests, parent escalations, security disclosures — every channel is human-staffed and we answer.
Privacy and trust: legal@conkarma.app