Skip to main content

Trust posture

Built family-safe — audited, gated, and on the record.

Plain-language pitch for parents, privacy-conscious users, and journalists. What we ship, what we don't, what's still in flight. Honesty + specificity over polish.

Children's data (COPPA)

Verifiable parental consent before any data is collected from a child account. A complete, parent-readable retention schedule — including the finite-bounding mechanism and the operational code path that enforces each window — is published as the Children's Data Retention Policy.

Read the retention schedule →

Take It Down Act compliance

The federal TAKE IT DOWN Act (2025) requires platforms hosting user content to act on takedown requests for non-consensual intimate imagery within 48 hours. ConKarma's public notice channel and procedure is documented and the 48-hour SLA is a hard commitment.

Take It Down notice channel →

Family Shield — trusted-adult disclosure

Teens designate a non-parent trusted adult who can acknowledge a sensitive disclosure first. If they don't respond in a short window, escalation routes to parents per the cell's policy. No AI mediates the routing.

Family Shield feature page →

Zone isolation

The adult zone (Ember) is physically separated from the family zone (Serene). Children are blocked at the API by middleware. The adult zone is biometric-locked and screenshot-protected. The web variant excludes the adult zone entirely because the browser threat model doesn't carry those protections.

Zone-isolation technical posture →

Agewall — self-attestation, no ID

Our public web Ember zone uses a self-attestation date-of-birth form + a 90-day cookie. We do not collect government ID, do not run a third-party age-assurance vendor, do not store your date of birth on our servers, and never share anything about the attestation. If Apple / Microsoft / jurisdictional law ever escalates, the architecture preserves a seam for a privacy-preserving age-assurance vendor (over-18 boolean only, never DOB revealed to us) — but we will never ask for your ID. Codified in ADR-114 and MINERVA-302; see Promise #16.

See the agewall →

No cross-app tracking

No App Tracking Transparency prompt on iOS — there is nothing for the prompt to ask about. No behavioural ad networks. No third-party trackers on any surface. AdMob serves non-personalised ads to free-tier adult accounts only; child accounts see no ads of any kind.

Children and analytics

Server-side GA4 emission is gated on the child-user predicate — child accounts emit Prometheus operational metrics only, never product-analytics events that could profile them. Firebase Analytics on child accounts has ad-storage and analytics-storage disabled except for strictly necessary service telemetry.

Audit logs

Admin actions and security-relevant operations are written to a tamper-evident audit log with per-user-type retention windows. Child-account audit entries retain for seven years per the COPPA audit-trail requirement; adult-account entries retain per the corresponding statutory or operational ceiling.

Two-eye admin gates

Admin actions with high blast radius — impersonation, forcing a 2FA reset, publishing content from an admin surface — require dual super-admin approval. The audit log records both approvers; the action does not execute until both have signed.

Security disclosure

Vulnerability reports go to security@conkarma.app. A public bug-bounty program is in flight; it will be linked here once it goes live. Responsible-disclosure window is 90 days from acknowledgement; we publish a security advisory for any finding that ships a fix.

Transparency reports

We have committed to an annual transparency report covering law-enforcement requests, takedown volumes, and abuse-report outcomes. The first report's publication date is to-be-determined — we will not commit a fake cadence to look polished; we will commit a real one once the data collection for it has run for a full year.

Themed Nights — memory, not score

A Themed Night belongs to the family — or the couple — not to a leaderboard. The eleven principles, in plain language: the night becomes a memory (no points awarded, no success-rating, no public stats); no commercialization (we don't sell themed-night packs and there are no brand tie-ins inside the experience); cell-authored (the theme is yours; we don't push themes at you); opt-out at any moment without penalty; the Ember variant is adults-only, opt-in per couple, Mutual Deck-gated, safeword-overridden, asymmetry-soft-paused. ADR-095 on /build-in-public is the long-form; the practical how-tos are /help/themed-nights (Serene) and /help/ember-themed-evenings (couple-only). It's a composition layer over the existing toolkit (decks, captain, joysticks, workshop, ritual, lottery), not a new pillar.

Allergens — filtered, not diagnosed

ConKarma filters food + contact + dietary suggestions based on what your cell declared. We are not a medical device. We filter; we don’t override your judgment. /help/allergies-and-dietary-restrictions covers the 3-level severity ladder, decline-to-state, and the four hard avoids (no photo-detection, no clinical advice, no insurer / employer / wellness-program sharing, no drug-allergy schema). ADR-100 is the long-form on /build-in-public.

Accessibility — adapt without requesting on your behalf

ConKarma adapts suggestions to the accessibility needs you declare — without filing accommodation requests for you. We are not a medical device. /help/accessibility-and-mobility covers the cell-composition defaults, the brief surfacing for sitters/coaches/teachers, and the five hard avoids (no clinical assessment, no auto-detect from photo/video, no insurer/employer share, etc.). ADR-101 is the long-form.

Crisis routing — we don’t dispatch

ConKarma routes notifications based on the preferences you set. We do not dispatch emergency services. In a life-threatening emergency, call your country’s emergency number. /help/emergency-contacts-and-crisis-routing covers per-context routing, sitter brief scoping, and the COPPA pattern; /help/emergency-checkin lists per-region helpline numbers. ADR-102 is the long-form.

Topic avoidance — less of, never more

When you tell ConKarma to avoid a topic, we never invert that into more of the topic. /help/topic-avoidance covers the two severity levels, the temporary-allow path, and the COPPA anti-stigma pattern. We don’t auto-detect from message content, we don’t make a therapy/clinical referral from a declaration, and we don’t override your declaration platform-side. ADR-103 is the long-form.

Recovery — respected, not treated

ConKarma respects recovery. We filter suggestions; we don’t override your judgment. We are not a treatment platform. /help/substance-recovery covers visibility levels, opt-in helpline discoverability (SAMHSA, SMART Recovery, Nar-Anon, GamblersAnon — pull-only, never pushed), and the Ember alcohol-pairing intersection. ADR-104 is the long-form.

Communication style — adaption, not deficit

ConKarma adapts to how you work best. We respect difference; we never frame it as deficit. /help/communication-style covers the two-layer declaration model, brief surfacing for coach/sitter/teacher, and Backpack IEP coexistence. No diagnosis, no IEP auto-fill, no pity framing, no capability-deficit language, no disability-pride auto-curation. ADR-105 is the long-form.

Pronouns + identity — honored, never inferred

ConKarma honors how you want to be addressed. Pronouns are asked early; gender identity is a separate, opt-in layer; decline-to-state is first-class on both. Kid voice is always honored; identity changes are trans-protective (history is never republished under a previous identity). /help/pronouns-and-identity is the long-form. ADR-106.

Heritage language — yours to declare

Heritage language is distinct from interface locale; you can declare multiple; we never infer. The declaration powers cross-generational features and Lingua qualification. /help/heritage-language is the long-form. ADR-107.

Quiet hours — respected, overrides transparent

ConKarma respects your quiet hours. Safety-critical notifications may override; when they do, we tell you why and log the reason so you can audit it. /help/quiet-hours-and-sleep covers cell-mate honor and the COPPA pattern. No non-safety-critical override, no ad targeting based on quiet-hours data, no clinical sleep tracking. ADR-108 is the long-form.

Household composition — we adapt, you label

ConKarma uses household composition to make suggestions more relevant. We never label your family for you. We never target ads based on this (we don’t target ads anyway). /help/household-composition covers multi-select declaration, decline-to-state, and friends-of-cell scoping. ADR-109 is the long-form.

Co-parenting — coordination, not adjudication

ConKarma coordinates co-parenting based on what you and your co-parent independently agree to share. We don’t replace court orders or legal advice. We are not court-admissible. In a safety emergency, call your country’s emergency number or a DV hotline. /help/co-parenting covers cross-cell consent, kid voice, and the family-law disclaimer in detail. ADR-110.

Pets — we coordinate; your vet treats

ConKarma helps your family coordinate pet care — vaccinations, vet contact, behavior alerts, sitter handoffs, Family Captain rotation. We don’t replace your vet. In a pet emergency, call your vet or pet-emergency service. /help/pets covers the sitter brief pet section + Family Captain rotation + the pet-loss-grief support pointer to /features/lookouts. ADR-111.

Pairings — mocktail always equal

When we suggest pairings inside the Ember zone, we always suggest a zero-proof option co-equal with any alcoholic one. We never sell alcohol, never push it, never claim it's good for you, never tell you how much. A partner in recovery can set the cell to mocktail-only structurally. The Ember-internal /help walks through the abstainer-first defaults and the recovery commitment; ADR-096 is the long-form on /build-in-public.

Mixed families — assumed by default

ConKarma assumes your family is mixed until you tell us otherwise. No primary-religion field on a cell. No proselytizing surface. No platform-interpretation of your traditions — the app surfaces conflicts when traditions clash on a date, but never picks a side. Declared religion is special-category PII (GDPR Art. 9), field-encrypted at rest, never trained on. /help/mixed-families covers the inclusive defaults and the decline-to-state first-class option; ADR-097 is the long-form.

Your wall — pull discovery, never push

Your widget wall is yours: per-zone (Serene + Ember separate), persona-aware on first run, kid-safe-filtered for under-13. No engagement metrics on customization, no escalating suggestion cadence, no 'feature adoption' score, no cell-mate force-set of another adult's wall. The one strip we never let you hide is the safety strip — structural backstop, not optional. /help/customizing-your-base covers it; ADR-098 is the long-form.

Updates — honest changelog, rare force-block

When there's a new version, we'll tell you what changed (by category: security / safety / compliance / feature). When we have to block an old version, we'll tell you why — and we'll keep that rare. Force-block is security/safety/compliance only, never for feature adoption, two-eye-gated. Data export and account cancellation always work, including on a blocked version. /build-in-public publishes a per-quarter count of force-block invocations (anonymous reason summaries, never per-user). /help/updates is the long-form.

Lotteries, not auctions

ConKarma uses lotteries. We don't run auctions. Family decisions shouldn't be won by whoever has the most chips. The mechanic is random with a fair-share floor — over time, every cell-mate is guaranteed at least N/M of the wins, and any kid can opt out at any time without penalty. /help/lotteries walks through the three scenarios and the guard rails; ADR-094 on /build-in-public is the long-form decision.

Rupture and transition

We're built for the family you have, the family you become, and the family you carry forward. Families change shape — bereavement, crisis, separation, identity change, the slow work of becoming someone new. The app changes with you. The eight principles, in plain language: (1) data follows the person, not the cell, so what you build travels with you; (2) bereavement gets a soft path — memory without forced forgetting, no surprise anniversary nudges; (3) a crisis mode (soft-mode) quiets the daily loop when life needs your attention more than the app does; (4) identity changes — name, pronouns, family role — are supported without losing your history; (5) safe exit from a cell that's no longer right for you is a structural part of the app, on your terms; (6) divorce and re-forming get plain mechanics — splitting a cell, forming new ones, sharing kids across two households; (7) carry-forward — what you build in one chapter of family life isn't trapped there; (8) the surfaces respect the chapter you're in — soft-mode tones things down, identity changes propagate quietly, bereavement keeps memory available without enforcing it. The full architecture decision is ADR-092 in /build-in-public; the practical how-to articles for each scenario live in /help.

Common questions

How is my child's data protected?
Verifiable parental consent before any data is collected. A complete retention schedule with operational backing — including which scheduled worker enforces each window — is published at /legal/coppa-data-retention. Server-side analytics emission is gated for under-13s. Adult-zone surfaces are blocked at the API for child accounts.
What happens if my child reports something scary?
Family Shield routes the disclosure to a designated trusted adult first; if they don't acknowledge in a short window, escalation reaches parents per the cell's policy. No AI mediates — the disclosure path is human-to-human. Where local law requires mandatory reporting, the trusted adult is responsible for their own legal obligation; ConKarma is a routing surface, not a custodian.
What user data do you sell?
None. We do not sell personal information, we do not 'share' it as defined by the CCPA/CPRA, and we do not participate in behavioural ad networks. The web companion at conkarma.app has no third-party trackers; the mobile clients carry no behavioural-ad SDKs.

Reach us

Trust questions, takedown requests, parent escalations, security disclosures — every channel is human-staffed and we answer.

Privacy and trust: legal@conkarma.app