Child Safety Standards

Effective date: April 26, 2026

Published by Layer One IT Consultants LLC, in partnership with Ghostweave Labs LLCin connection with the Tag, You’re It mobile application and website (the “Service”). We review these standards at least annually and whenever applicable law or platform policy materially changes.

1. Our commitment

Tag, You’re It is a social platform for people 13 and older. We build on the principle that a young person’s first social-media experience should not be optimized for attention capture. Our commitment to child safety is not an afterthought; it shapes the product. This document describes the standards we hold ourselves to, the controls we operate, and how we respond when something goes wrong.

2. Minimum age and parental consent

You must be at least 13 years old to create an account. Users between 13 and 17 require verifiable parental (or legal-guardian) consent before their account is usable. We do not knowingly permit users under 13 to register or use the Service. If we learn that an account was created by a child under 13, we disable that account and delete associated personal data within 30 days unless a law or legal process requires retention.

Parental consent is recorded through a structured in-app flow: the parent or guardian creates their own account, generates a single-use invite code, and links it to the minor’s account. The consent timestamp, the linking parent’s account identifier, and related audit data are retained for the life of the minor’s account. The relationship data itself is stored using authenticated encryption at rest.

To satisfy COPPA’s “verifiable” standard, the parent also completes a one-time card check (a $0.50 charge that is refunded immediately) through Stripe before they can issue invite codes for an under-16 account. The card number is handled by Stripe; we keep only the timestamps and Stripe transaction ids. See Trust & Safety for why we use a third party for this single step.

3. Age-appropriate defaults

Accounts for users under 18 launch with the following defaults:

  • Public discovery is limited; profile visibility is restricted unless a parent approves otherwise.
  • Direct messaging is limited to mutual friends; unsolicited contact from adults is not permitted.
  • Ephemeral posts (our “24” feature) are never public and are restricted to friends or an explicit allowlist.
  • Wall-post images, direct-message media, and ephemeral-post media are served behind per-request authorization aligned with the post’s audience.
  • Precise location, phone number, and financial data are not collected from minors.
  • Advertising networks and third-party behavioral trackers are not integrated.
  • Optional third-party music integrations (for example Spotify) are off unless the account connects them; when connected, listening indicators may be visible to approved friends as described in our Privacy Policy. Parents and teens should review those settings together.

4. Parental oversight

Linked parent accounts have access to an oversight surface for their child. Depending on the control level the parent selects, this can include viewing recent friend requests and wall activity, managing the child’s allowlist for selected-audience posts, and receiving automated safety alerts when our filters block a minor’s content. Every parental action is recorded in an immutable audit log.

A child cannot sever the parent link on their own. Removal requires the parent’s action or the child reaching the age of majority in their jurisdiction. If a parent believes the link has been compromised (for example, the parent account was taken over), they can contact us at [email protected].

5. Content moderation

Our content moderation operates at three layers.

  • Automated image scanning. Uploaded avatars, profile media, wall-post images, ephemeral-post media, and custom wallpapers are scanned by a commercial image-moderation service before they are accepted. Uploads flagged for explicit nudity, graphic violence, or other prohibited categories are rejected at ingest. Every scan produces an immutable audit record.
  • Automated text filters. User-authored text in bios, wall posts, direct messages to and from minors, and other surfaces is passed through filters tuned for hate speech, sexual content involving minors, self-harm promotion, and grooming language. The filter is tighter for accounts marked as under 16.
  • Human review.Reports submitted through the in-app “Report” surface, or escalations from the automated systems, are triaged by trained reviewers. Reviewers operate against documented standards; outcomes and the reviewer identity are recorded.

We fail closed on moderation errors: if a scan cannot complete, the upload is rejected rather than allowed. No moderation system is perfect; we expect errors in both directions and we publish appeals channels below.

6. Preventing child sexual abuse material (CSAM)

CSAM has no place on Tag, You’re It. We treat every suspected case as a priority incident. Our controls include:

  • Blocking known CSAM at upload using hash-matching against industry databases maintained by the National Center for Missing and Exploited Children (NCMEC) and partner organizations, and through commercial image-classification services.
  • Reviewing every user report categorized as “child safety” on an expedited path, ahead of other report categories.
  • Reporting apparent CSAM to the NCMEC CyberTipline in accordance with 18 U.S.C. § 2258A. Reports include the content and associated account metadata as required by statute.
  • Preserving relevant records for the period required by law, and cooperating in good faith with duly authorized law-enforcement requests.
  • Not notifying the reported account of the referral, as premature notice could destroy evidence or endanger a victim.

We do not, and will not, scan or decrypt any private content except where an automated scan is disclosed in these standards or where required by law. We do not re-share reported material with parties beyond NCMEC or law enforcement.

7. Preventing grooming and unsolicited adult contact

  • Direct messaging between minors and adults who are not mutual friends is blocked by default. Friend requests directed at minors from unknown adult accounts are subject to additional screening.
  • Parental oversight surfaces include recent friend requests on a minor’s account and may include friend-request approval where the parent has enabled it.
  • Language filters tuned for grooming-risk patterns operate on messages to and from minors; flagged conversations are escalated for human review.
  • Public discovery of minor accounts is limited and does not surface minors to searchers based on demographics or inferred attributes.

8. Reporting a safety concern

Every post, comment, profile, and message has a “Report” action. Reports include the content, the reporting user’s optional notes, and a category selection. Anonymous reports are accepted; the reporter’s identity is not shared with the reported user.

You can also reach our safety team directly at [email protected]. For imminent threats to life, please also contact your local emergency services.

Our current response targets are:

  • Suspected CSAM or imminent-harm reports: reviewed within a few hours.
  • Other child-safety reports: reviewed within 24 hours on a best-effort basis, measured on business days.
  • General community reports: reviewed within 72 hours on a best-effort basis.

These are targets, not contractual guarantees. Where we miss a target we record the reason and include it in our transparency reporting.

9. Enforcement actions

Based on the severity of a violation, we may take any of the following actions: remove the content, issue a warning, mute messaging, temporarily suspend the account, permanently ban the account, preserve records for law-enforcement inquiry, and refer the matter to the appropriate authority. Enforcement decisions that affect access are logged. Affected users may appeal through the process described in our Code of Conduct.

10. Data minimization for minors

  • We do not collect precise geolocation, phone numbers, or payment data from accounts marked as minors.
  • Any moderation records that personally identify a minor are retained only as long as needed for safety, compliance, and legal purposes, and then removed on the schedule disclosed in our Privacy Policy.
  • Behavioral advertising identifiers are never assigned to minors’ sessions.
  • User-supplied “creative” profile embeds operate in a sandboxed frame that cannot execute third-party tracking on the parent page. Embedded content still has access to anonymous network requests; we are evaluating a stricter default for minor accounts.

11. Moderator training and safeguarding

Team members with access to moderation surfaces receive a written training pack on our standards, applicable law (including COPPA and NCMEC obligations), trauma-informed review practice, and the limited situations in which material may be retained for reporting. Moderators who review CSAM reports rotate through other work so no individual is exposed continuously to the hardest content. All moderation actions are logged against the reviewer’s identity.

12. Cooperation with law enforcement

We respond to valid legal process (subpoena, court order, search warrant, emergency disclosure request under 18 U.S.C. § 2702(b)(8) / (c)(4)) consistent with applicable law. We do not voluntarily disclose user content except for the purposes described in these standards or our Privacy Policy, including NCMEC CyberTipline reports and credible emergency circumstances.

13. Transparency reporting

We will publish a transparency report at least annually, beginning with our first full year of operation. The report will cover: the volume of user reports by category, the volume of enforcement actions taken, the volume of NCMEC CyberTipline reports submitted, and the volume of valid legal-process requests received and complied with. Aggregate numbers only; no identifying data will be published.

14. Continuous improvement

Child safety is a discipline, not a feature set. We expect to improve these standards as our research, our partner organizations, and our community identify new risks. We participate in industry information-sharing where appropriate, including with NCMEC and the Tech Coalition when we qualify for membership.

15. Contact

Reach our safety team at [email protected]. General inquiries: [email protected]. Mail: Layer One IT Consultants LLC.