# Kid-safe technology, in the AI era

**A KIDIGLOO whitepaper · v0.1 · June 2026 · by Quarlabs**

> KIDIGLOO is a kid-safe technology company. We build the trust layer for children's apps —
> safe-by-default identity and consent, a voluntary kid-safe certification standard, and AI
> guardrails — and we prove it with our own apps. This paper explains what "kid-safe" means,
> why the AI era makes it urgent, what we're building, and how we keep the standard honest.
> *Written for parents and for developers. Not legal advice.*

---

## 1. What "kid-safe technology" means

Kid-safe technology is **technology that is safe for a child by default — without a parent
having to lock it down first.** Concretely, a kid-safe product:

1. **Puts the child's best interests ahead of engagement or revenue.**
2. **Collects the least data possible**, with high-privacy defaults and **no profiling or
   targeted advertising to children.**
3. **Shows only age-appropriate content and features.**
4. **Anticipates and removes foreseeable harms** before they reach the child.
5. **Is transparent**, and gives parents real visibility and control.

The burden of safety sits with the maker, not the family. This is the principle behind the
world's leading child-safety and age-appropriate-design frameworks and international guidance on
AI and children — and it is the principle behind KIDIGLOO.

## 2. Why now — the AI era changed the stakes

For a decade, "online safety for kids" meant screen time, strangers, and inappropriate content.
Generative AI added a new, faster-moving class of harm that the headlines of 2024–2026 make
impossible to ignore:

- **AI "companion" chatbots.** Most teens have now used them; independent assessors rate social
  AI companions an **unacceptable risk for minors**, and AI chatbots have been linked to teen
  tragedies and a wave of lawsuits, settlements, and regulator inquiries.
- **Synthetic abuse material.** AI-generated child sexual abuse material has exploded — by some
  measures **hundreds-fold year over year** — straining every existing safeguard.
- **Engagement engines** that recommend self-harm and eating-disorder content to children.
- **Data exploitation and dark patterns**, now supercharged by personalised generation.

At the same time, regulators everywhere are moving from "tell us your age" to **real age
assurance**, and from voluntary guidance to enforceable duties. The gap between what's technically
possible and what's safe for a child has never been wider. **That gap is what KIDIGLOO exists to
close** — practically, as a tech company, not as a think-tank.

## 3. What we're building (three focus areas)

**A. Safe-by-default identity & consent infrastructure.** The hard, unglamorous plumbing, done
once and shared. A child is **never** given a login; they're a *data-minimised profile* a guardian
manages. Parental consent is verifiable and revocable. Apps ask our **entitlements API** "is this
child allowed X?" instead of holding children's data themselves. (Live today, behind Nook and Piggy.)

**B. KIDIGLOO Certified — a voluntary kid-safe standard.** A published framework apps **self-attest**
to, a trust mark parents can look for, and **community monitoring** with teeth: certified apps must
let the public flag concerns, and KIDIGLOO investigates evidenced complaints and can revoke the mark.
(See §4–5.)

**C. AI guardrails for kids' apps.** Concrete requirements — *AI must disclose it is AI; no
unsupervised companion bots for children; crisis/self-harm escalation; never generate harmful or
sexualised-minor content; resist manipulation* — baked into the standard, and tooling over time.

We **prove all three with our own apps**: **Nook** (a bilingual kids' reading magazine) and
**Piggy** (a kids' money-skills app) are reference implementations, not just slideware.

## 4. The KIDIGLOO Kid-Safe Framework (v0.1)

Five principles an app self-attests to:

- **P1 Best interests first** — wellbeing over engagement; no dark patterns or pressure to spend.
- **P2 Privacy by default** — minimal data, high-privacy defaults, profiling/geolocation off,
  **no behavioural tracking or targeted ads to children**, verifiable parental consent, easy deletion.
- **P3 Age-appropriate content & contact** — suitable content; UGC/chat controls + reporting;
  parent-gated links and purchases.
- **P4 AI guardrails** — disclose AI; no unsupervised child "companions"; crisis escalation;
  refuse harmful/abusive generation (incl. synthetic CSAM); resist manipulation.
- **P5 Transparency & parental control** — a plain-language data/AI "nutrition label", real parental
  controls, honest marketing, and a working public complaint channel.

The framework borrows its floor from the strictest credible children's-privacy standards in the world
— high-privacy defaults and a ban on tracking or targeting children — so that meeting it once satisfies
the toughest requirements anywhere.

## 5. How we keep the standard honest

**Register → self-attest → community-monitor → investigate → act.** A developer signs a
participation agreement and self-attests, with evidence links (privacy policy, data/SDK disclosure,
age-gate, and a public complaint channel). We list the app in a **public registry**. The public can
flag concerns **with evidence**; we notify the developer, give a right to respond and a cure period,
and can issue a cure notice, **suspend, or revoke** — updating the registry. Annual re-attestation;
best-effort random spot-checks; material changes require re-attestation.

**What the mark means — and doesn't.** *KIDIGLOO Certified* means a developer **has self-attested**
to the framework and accepted community monitoring. It is **not** an audit, a test, or a guarantee,
and KIDIGLOO does **not** independently examine apps. It is a **trust base built on the developer's
declaration plus public accountability** — honest about its limits on purpose. Parents should still
use their judgement; the value is transparency and a real path to flag and remove bad actors.

## 6. Built for children everywhere

KIDIGLOO is **not tied to any one market**. The framework is designed to the **highest credible bar**
for children's privacy and safety, so an app that meets it is safe for children wherever they live.
Where local law is strict, the framework already aligns with it; where local law is silent, it **raises
the floor** voluntarily. We grow our coverage as resources allow — but the standard itself is global
from day one.

## 7. Who we are — and how to take part

KIDIGLOO is part of **Quarlabs**, a private lab that also does voluntary work on **enterprise AI
safety**. We are **self-funded** — this is the founders' own money and time. We chose to start now,
voluntarily, because the harms are here now.

- **Parents:** look for the KIDIGLOO Certified mark, and tell us when something's wrong.
- **Developers:** adopt the framework and get listed — `https://kidigloo.com/certified`.
- **Investors & partners** who want to help us cover more ground, faster: **hello@quarlabs.com**.

*This document is informational, not legal advice. The certification framework, agreements, and
public claims are being reviewed with legal counsel before reliance.*
