Our promise about children

Each of these is a design decision, not a policy statement. Where one is enforced in code, we say so.

A child never gives us contact details

There is no email address, no phone number, no surname and no date of birth anywhere in a child profile. There is no field for them, so there is nothing that could be collected by mistake or leaked later. A rule in our database refuses a first name that looks like a full name.

Nothing is collected before an adult is verified

The screen for adding a child cannot be reached until your account has been verified. That check is enforced at the point the record would be written, not only in the interface.

The private setting is the default

Learning from what a child enjoys is off until you turn it on. Sharing anything they make is off until you turn it on. Neither is presented as something to enable to get the most out of the product, because that is how a default gets undone.

Nothing is designed to keep a child on the app

No streak, no daily reward, no notification, no counter that resets. Pip speaks once when a screen opens and then stops. When a daily limit is reached, the app says so plainly and offers nothing to extend it.

Re-reading is encouraged, because re-reading a book genuinely helps a child read it better. It is not counted towards anything.

A child can always tell someone

Every shared book has a report button that a child can use themselves. Reports reach a person.

What a child is told

Pip explains things in short sentences a young child can follow, and never claims to be a friend, a pet, or a person. When something cannot be done, the child is told plainly and offered something else, without being made to feel they did something wrong.