Breaking Chains
App Safety Directory
Your kid has an app on their phone and you want a straight answer about it. Not a search results page, not a forum thread. Here is what we found, what we checked it against, and a link to every source so you can read it yourself.
Read the badge carefully, because it answers one question only. A badge is a statement about how severe the risks are, not about how much you can do about them. Some Caution apps give a parent nothing to set. Some High Risk apps have real, working parental controls. That is why every app below carries a “what you can actually do” line, and why you should read that line rather than the badge alone.
A low score is not a clean bill of health. It means the things we check for were not found on the evidence we could get. We tell you what we checked and show you the source; where we could not verify something, the entry says so instead of guessing.
High Risk Snapchat19 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: A parent can see WHO their child has been in contact with, and when, through the vendor's own supervision tool. Not what was said. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Family Center shows a parent who their teen has communicated with in the last seven days and not what was said, which is the limitation already verified in the fifth run. On the operator side the guide is more nuanced than Snapchat's ephemeral reputation suggests: Snap's servers are designed to delete a Snap once all recipients have opened it, but Memories is cloud storage that persists until the user deletes it, and disclosure runs under the Stored Communications Act. One carve-out matters for this directory and is the reason the hidden axis is now sourced here: content a user puts in My Eyes Only "is not accessible to Snap and cannot be decrypted by Snap", so the vault inside the app is outside the reach of the operator's own legal process.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | Quick Add surfaces accounts outside the friend graph; no random matching. Apple discloses Messaging and Chat plus User-Generated Content. Apple App Store product page (age rating |
| hidden | 2 | My Eyes Only is a passcode-protected area inside the app, separate from the camera roll, and Snap states the content in it is not accessible to Snap and cannot be decrypted by Snap. Snapchat Law Enforcement Guide |
| browser | 1 | In-app webview for links. Apple does not disclose Unrestricted Web Access. Apple App Store product page (age rating |
| Disappearing messages | 3 | Snaps auto-delete after viewing by default; this is the product, not a setting. Apple App Store product page (age rating |
| location | 3 | Snap Map shares live location with friends. App Privacy shows Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 2 | Corrected from 1 this run, and the old rationale had already said why: "underlying signup is still a self-attested birthdate" is band 2's definition sitting inside a band-1 score. Snap's k-ID verification is conditional and jurisdictional on Snap's own telling, and the Apple age range is self-set for anyone 13 or older. A US teen on their own device gets neither. Snapchat Support |
| dataharvest | 3 | Data Used to Track You: Contact Info and Identifiers. Precise Location, Contacts and Contact Info all linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | New Mexico AG suit over sextortion and exploitation, which is the enforcement action band 3 turns on under finding 51; 1,174,698 CyberTipline reports in 2024, which finding 4 says bands nothing on its own. REWRITTEN 2026-08-11 (twenty-sixth run) under the finding 66 decision, and the rewrite is the whole point of that decision: for ten passes this rationale asserted 'multiple DOJ convictions' and named none of them, in the shortest rationale attached to any band-3 app in the file and on the single most consequential entry in the directory. The convictions are real and this file already held five of them. Named, so a reader can check them: D. Conn., a New York man who used TikTok and Snapchat to prey on girls, guilty plea (DOJ_CT_TT_SNAP); S.D. Ind., Austin Ryan Lauless, 84 years, Snapchat one of five named platforms and at least 84 minor victims (DOJ_SDIN_68, with DOJ_SDIN_LAULESS_SENT the sentencing release in the same case, so they are one case and not two); W.D. Va., Jonathan Avery Shumate, 151 months, Snapchat and Grindr, victims aged 16 and 17 (DOJ_WDVA_GRINDR); E.D. Pa., David Dunn, 25 years, Snapchat and Likee, victim aged 10 (DOJ_EDPA_LIKEE); and a Virginia guilty plea to sexually exploiting more than 40 minor girls on Snapchat (DOJ_SNAP_VA). Four of those five sat in CROSSCITE_CLEARED marked subsumed, cleared by the twenty-second run on the ground that Snapchat's band was supported without them. That was the wrong test and finding 66 is why: a citation can be owed by the rationale's own CLAIM rather than by the score, and no amount of band support discharges a plural assertion a parent cannot check. New Mexico DOJ |
High Risk Telegram Messenger19 of 24
What you can actually do: Nothing for a parent to set, on the listing's own account. Apple's listing discloses no parental controls and no vendor check has been done. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Cloud chats, which are the default, are stored on Telegram's servers, so the record exists. What is unusual is the operator's stated willingness to produce it: section 8.3 commits only to disclosing IP address and phone number, on a valid judicial order, for a suspect in a case violating Telegram's own terms. So a record existing and a record being retrievable are further apart here than anywhere else in the dataset. Secret Chats are the exception in the other direction, not stored on Telegram's servers at all. The parent side is not established and is deliberately left unverified rather than assumed absent.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Public channels and groups, username search, and historically a People Nearby feature. Apple App Store product page (age rating |
| hidden | 2 | Secret Chats are a separate, device-bound thread type invisible in the normal chat list, and Telegram states it does not store them on its servers. Telegram Privacy Policy |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 2 | Self-destructing messages in Secret Chats. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 3 | Rated 13+ with no Age Assurance and no Parental Controls disclosed. Apple App Store product page (age rating |
| dataharvest | 3 | Corrected up from 2 on 2026-08-10 (finding 42), same defect as Messenger and found by the same mechanical sweep: the rationale listed two of band 3's three conjuncts and stopped. Contact Info (Name, Phone Number) is linked to identity alongside Precise Location and Contacts, so the second limb is satisfied. One honest difference from Messenger, recorded rather than smoothed over: Telegram declares all three under App Functionality and NOT under an advertising purpose, so on the axis's post-rename reading (it measures advertising practice) this 3 is doing work the axis does not claim to measure. The band text does not mention purpose, so the rule as written is applied; the mismatch feeds the open identifying-data item rather than being resolved here. Telegram was 18 and is 19, both High Risk, so no badge moves on it. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Telegram's founder was indicted in France in 2024 on six offences including complicity in the distribution of child sexual abuse material and refusal to cooperate with lawful requests. SECOND DOCUMENT ATTACHED 2026-08-11 (twenty-second run), and it was already in this file: Ofcom opened an investigation on 21 Apr 2026 into Telegram's compliance with its duties to prevent CSAM being shared, on evidence from the Canadian Centre for Child Protection. It is cited here as CONTEXT AND AS A SCHEDULED RE-SCORE TRIGGER, never as band support: INCIDENTS_ACTION_TEST ends with the sentence that an open investigation is not an enforcement action, and no conclusion has been reached. The band rests on the French indictment and is unchanged. The document sat in SOURCES cited by nothing for eleven passes because this app's cross-citation alias was its App Store title, 'Telegram Messenger', which no document contains; see finding 63. Forbes |
High Risk BIGO LIVE-Live Stream, Go Live16 of 24
What you can actually do: Nothing for a parent to set, on the listing's own account. Apple's listing discloses no parental controls and no vendor check has been done. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Broadcast to and from strangers with paid virtual gifting. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 2 | Live streams leave no user-accessible record. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 3 | Rated 18+ with no Age Assurance and no Parental Controls disclosed. Apple App Store product page (age rating |
| dataharvest | 2 | Data Used to Track You: Identifiers. Precise Location linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Investigative reporting documented child sexual abuse streamed on live-streaming apps distributed through the major app stores, with Bigo among those named. Bigo Technology filed 11 CyberTipline reports in 2024. Business & Human Rights Resource Centre |
High Risk Grindr - Gay Dating & Chat16 of 24
What you can actually do: Nothing for a parent to set, on the listing's own account. Apple's listing discloses no parental controls and no vendor check has been done. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Proximity-ordered grid of nearby strangers. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | Photo expiry options; message history persists. Apple App Store product page (age rating |
| location | 3 | Distance to other users is core to the interface; Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 2 | Rated 18+. Apple discloses Age Assurance, and finding 26 is why that is no longer scored as a real operating gate. Apple defines the flag as a disjunction satisfied by a "declared age range API" read, and the Declared Age Range API's own values include selfDeclared. Nothing has been shown about what this operator actually runs, so this is band 2, a self-attested birthdate with some enforcement, until a vendor check says otherwise. Apple |
| dataharvest | 3 | Tracking spans Location, Identifiers and Usage Data; Precise Location and Contacts linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | HELD at 3, see INCIDENTS_UNDERSOURCED, and the supported band moved 1 to 2 on 2026-08-11 (twenty-first run). Two federal prosecutions name Grindr, both read at source: C.D. Ill., Christopher Ohm, 458 months on 11 Apr 2022, identified after he 'met with a 13-year-old minor through a popular dating application, Grindr' and who approached a second 15-year-old 'also using Grindr'; and W.D. Va., Jonathan Avery Shumate, 151 months on 31 Oct 2022, who 'used both Snapchat and Grindr' to obtain sexually explicit images from sixteen- and seventeen-year-old boys at a Virginia boarding school. That is band 2's first limb. Band 3 additionally needs an enforcement action against the operator on child-safety grounds, and the search for one is now NAMED rather than assumed: Datatilsynet's NOK 65,000,000 fine, upheld on appeal 21 Oct 2025, is about behavioural-advertising consent and never mentions children; the FTC's own legal library holds no action against Grindr; no state AG action was found. 78,886 CyberTipline reports in 2024 from a platform that admits only adults remains a good argument that minors are present, and under the rewritten bands an argument carries no band on its own. DOJ C |
High Risk Instagram16 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: A parent can see WHO their child has been in contact with, and when, through the vendor's own supervision tool. Not what was said. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Family Center shows a parent the teen's contact list and recent interactions without message content, verified in the fifth run and unchanged. On the operator side a search warrant reaches "the stored contents of any account", which Meta's own guidelines enumerate as messages, photos, videos, timeline posts and location. Read the retention sentence with it, because it is the part that surprises people: Meta does not hold data FOR law enforcement, and content the user has deleted is gone unless a preservation request arrived first. So the record exists while the account does, and a parent who waits is not preserving anything by waiting.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | DMs and Explore expose accounts outside the follower graph. Teen Accounts default under-16s to private, which materially narrows this. Apple App Store product page (age rating |
| hidden | 1 | Vanish mode and archive obscure content without disguising the app. Apple App Store product page (age rating |
| browser | 2 | Full general-purpose in-app browser. Apple App Store product page (age rating |
| Disappearing messages | 2 | Vanish mode and Stories are prominent surfaces. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity; no default live sharing with other users. Apple App Store product page (age rating |
| ageverify | 1 | The app Meta's age-detection programme was built on and the source of every published figure. Band 1 earned on Meta's own documentation rather than on the Apple flag. Still a backstop layered on a self-reported birthday. Meta Newsroom |
| dataharvest | 3 | Tracking spans Contact Info, Identifiers and Other Data; Precise Location and Contacts linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Re-sourced 2026-08-10 (eighteenth run); already Supported, and now on far stronger evidence. State of New Mexico v. Meta reached final judgment 7 Aug 2026: 75,000 Unfair Practices Act violations found by a jury, $375M civil penalty, a public-nuisance holding, a rejected Section 230 defence, $567M and five years of court-supervised reforms to Facebook and Instagram including enhanced protections against sextortion and child sexual exploitation. The suit was filed 6 Dec 2023 after an undercover investigation using decoy accounts of children 14 and younger, which found adults soliciting sexually explicit images from those accounts. Prior evidence stands: 42 state attorneys general sued Meta in October 2023 over youth harms, naming Instagram as a subject of the case, and that release (NJAG_META) is CITED HERE FROM 2026-08-11 (twenty-second run) rather than merely described, having been an orphan document for eleven passes, finding 65; 3,320,008 CyberTipline reports in 2024; multiple DOJ sextortion prosecutions name the platform, and under the finding 66 decision of 2026-08-11 (twenty-sixth run) they are named rather than counted: D.D.C. 22cr150 (Pathmanathan, 33 years, 145 victims, primarily Instagram and Facebook Messenger) and S.D. Ind. (Austin Ryan Lauless, 84 years, Instagram first in a five-platform list, at least 84 minor victims, DOJ_SDIN_68, already cited here). The old wording said 'including' and then showed one, which is the milder half of the same defect as Snapchat's: a claim of multiple substantiated exactly once still leaves the second one unverifiable. Same five-year re-score trigger as Facebook. New Mexico DOJ |
High Risk MeetMe: Go Live & Meet People16 of 24
What you can actually do: Nothing for a parent to set, on the listing's own account. Apple's listing discloses no parental controls and no vendor check has been done. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. MeetMe holds private message content on its own servers, accesses it for moderation and legal process, and discloses on court order or subpoena, so the record exists and legal process reaches it. The parent half is deliberately left unverified rather than written as none: the privacy policy was read in full and describes no supervision feature, but absence from a privacy policy is the wrong document to prove absence of a product feature, and no MeetMe parent-facing page has been read. Recorded in TRAIL_SEARCHED so the next run knows a search already ran and what it did not settle.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Public discovery plus a nearby feed; contact from strangers is the product. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Message history persists. Apple App Store product page (age rating |
| location | 3 | Real-time geolocation passed to other users was the specific subject of the San Francisco City Attorney suit. App Privacy shows Precise Location linked to identity. Courthouse News |
| ageverify | 3 | Rated 18+ with no Age Assurance and no Parental Controls disclosed. Apple App Store product page (age rating |
| dataharvest | 3 | Data Used to Track You spans five categories including Location; precise location linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Settled the San Francisco City Attorney suit for $200,000 over enabling predators to target minors; 7,658 CyberTipline reports in 2024; a registered sex offender was given VIP streamer status. Courthouse News |
High Risk Messenger15 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: A parent can see WHO their child has been in contact with, and when, through the vendor's own supervision tool. Not what was said. Message content is end-to-end encrypted and the operator does not hold it. Account records do exist and legal process can reach those. The one app in this dataset where BOTH halves are limited by the same fact, which is why it is worth reading as a pair rather than as two rows. Default end-to-end encryption on friends-and-family chats means Meta "will no longer be able to provide unencrypted message content as part of any response to any legal process", and it follows that no supervision feature can show a parent what an operator cannot decrypt. Messenger's own FAQ says so to the teen directly: a parent cannot "See the content of actual messages you send or receive". What a parent DOES get is narrower than the Meta-wide description suggests and is worth quoting exactly, "who you've chatted with in the last 7 days", so a conversation that ended eight days ago is not in it. That list now includes AI chats alongside people. Message and call logs and IP data still reach legal process. Meta's own wording is "is rolling out", present tense, so a chat outside the rollout still yields content; metadata_only is the default state rather than a guarantee about every chat.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | Message requests from non-friends land in a separate inbox but do arrive. Apple App Store product page (age rating |
| hidden | 1 | Secret conversations sit in a separate thread type. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 2 | Vanish mode plus end-to-end encryption by default since 2023. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 1 | Same mechanism and evidence as Facebook: Messenger is named in Meta's Jun 2026 teen-safety update alongside Instagram and Facebook. Backstop rather than gate, same as Facebook, which matters more here because Messenger's whole risk is contact. Meta Newsroom |
| dataharvest | 3 | Corrected up from 2 on 2026-08-10 (finding 42). The old rationale enumerated TWO of band 3's three conjuncts, "Precise Location and Contacts are linked to identity", and stopped one short of reading the band it was quoting. Contact Info is linked too, under Physical Address, Email Address, Name and Phone Number, and all three sit under the Third-Party Advertising and Developer's Advertising or Marketing purposes rather than App Functionality. Band 3's second limb is precise location AND contacts AND contact info linked, and it is satisfied. This is the correction that moves Messenger from Caution to High Risk. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | SUPPORTED 2026-08-10 (nineteenth run) and this entry stops being a question for Jason. The eighteenth run escalated it as the first register gap where applying the supported band would be a research-backed DEMOTION of a major platform, because no enforcement action had been found that names Messenger. One names it, and a court has already made a finding on it. (a) Nevada AG Ford filed civil actions on 30 Jan 2024 'against, TikTok, Snapchat and three Meta-owned platforms, Instagram, Facebook and Messenger', so the service is named as a sued platform rather than swept in under a corporate parent, which is exactly the conjunct the 42-state complaint failed. (b) On 22 Jul 2026, 19 days before this run, the Eighth Judicial District Court found a reasonable likelihood that Meta violated the Nevada Deceptive Trade Practices Act over 'misrepresentations and material omissions the company made about the safety of its end-to-end encryption technology in its Messenger application', found that Meta 'did not disclose its knowledge of important child safety issues' about that technology, and entered a preliminary injunction whose own scope is 'Meta's users of the Messenger who are Nevadans under the age of 18'. All three conjuncts of INCIDENTS_ACTION_TEST hold, and the grounds conjunct holds on the court's own words rather than on a characterisation. This is a stronger citation than a filed complaint: it is an entered injunction on a judicial finding. THE EIGHTEENTH RUN'S ANALYSIS IS UNCHANGED AND STILL CORRECT, and is retained below because the refusal it records is the reason this entry is now safe. Prior text follows. The old rationale read 'Covered by the 42-state AG suit against Meta', and that stretch was tested at source and FAILED. The multistate complaint (N.D. Cal. 4:23-cv-05448, 233 pages) was downloaded and text-extracted: 'Messenger' occurs 5 times against 'Instagram' 290, and paragraph 1 defines the case's own scope as 'Meta -- itself and through its flagship Social Media Platforms Facebook and Instagram (its Social Media Platforms or Platforms)'. Messenger appears in the corporate description, in the common-enterprise allegation quoting Meta's financial disclosures, once substantively on Vanishing Mode, and once as a platform the practices are EXPANDING INTO, which is the opposite of being the subject. State of New Mexico v. Meta does not reach it either: its defendants are Meta Platforms, Zuckerberg, Instagram LLC and Facebook Holdings LLC, and the 7 Aug 2026 final judgment orders reforms to Facebook and Instagram. So no enforcement action names Messenger and band 3's naming conjunct fails. What DOES hold is band 2's first limb, established this run and read at source rather than from a search summary: D.D.C. 22cr150, Pathmanathan, 33 years, who 'used multiple social media accounts, primarily Instagram and Facebook Messenger, to establish contact with at least 145 young girls and boys'; and W.D. Va., Doss, CHARGED after using Facebook Messenger to solicit explicit images from a 13-year-old relative. Multiple documented cases naming the service. The default end-to-end encryption rollout reduces what can be detected and reported, which is an argument rather than a case and carries no band on its own. Nevada AG |
High Risk Calculator# Hide Photos Videos14 of 24
What you can actually do: Nothing for a parent to set, on the listing's own account. Apple's listing discloses no parental controls and no vendor check has been done. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 0 | No contact features. Apple App Store product page (age rating |
| hidden | 3 | The app's entire purpose is to look like a calculator and open a hidden gallery on a passcode. Several apps in this category also support a decoy passcode that opens an innocuous second vault. Apple App Store product page (age rating |
| browser | 3 | Apple discloses Unrestricted Web Access, a full browser inside an app disguised as a calculator, which routes around device and router-level filtering. Apple App Store product page (age rating |
| Disappearing messages | 1 | Stored content persists inside the vault. Apple App Store product page (age rating |
| location | 0 | No location collected. Apple App Store product page (age rating |
| ageverify | 3 | Rated 16+ with no Age Assurance and no Parental Controls disclosed. Apple App Store product page (age rating |
| dataharvest | 2 | Data Used to Track You: Contact Info. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | Documented case of a parent finding predator conversations hidden inside a calculator app on a child's phone; repeated law-enforcement and child-safety warnings about the category. First Coast News |
High Risk sendit - get it now14 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The vendor publishes a page in its navigation labelled parents, and the controls check read it: it carries a safety blurb and instructions for blocking a sender after the fact. A page addressed to parents is not a view for parents, and this is the app in the dataset where the distinction is easiest to miss. The operator half is where an anonymous-messaging app is most misread, so read the two documents together. The privacy policy collects "your posts, photos and other submissions" and undertakes to share "any or all categories of personal information to respond to a court order or subpoena", naming the US government specifically. The FTC's 2025 complaint then enumerates what was actually held on children: phone numbers, birthdates, photos, and usernames for Snapchat, Instagram and TikTok. What the product would not tell a paying child is a separate question from what the operator could tell a court, and the same complaint separates them: a user who bought the reveal got "generic information like location or phone type" for a real sender. That was a product decision, not an absence of records. No retention duration is stated anywhere in the policy.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Anonymous inbound messages from anyone, bolted onto a teen's Snapchat, Instagram or TikTok profile. Apple App Store product page (age rating |
| hidden | 1 | Sender identity is concealed by design. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | Message history persists in-app. Apple App Store product page (age rating |
| location | 0 | No location collected. Apple App Store product page (age rating |
| ageverify | 3 | Rated 13+ with no Age Assurance disclosed. The FTC alleges the operator knew many users were under 13 and collected their data anyway. FTC |
| dataharvest | 2 | Data Used to Track You: Usage Data. Contacts linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | FTC referral and DOJ complaint filed September 2025 alleging COPPA violations, fabricated provocative messages sent to drive subscriptions, and deceptive billing. FTC |
High Risk TextNow: Call + Text Unlimited14 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Read the two halves against each other, because this app is where they are furthest apart. A parent gets nothing: the Terms were already read in full for the controls axis and describe no supervision flow, and TextNow's own help centre returns no results at all for "parental controls". An investigator gets a great deal: the privacy policy has TextNow collecting message content itself, the law-enforcement pages disclose on a valid order, and TextNow voluntarily preserves records for 90 days on a preservation request. The 4+ age rating means no Screen Time restriction withholds this app, so the practical shape for a parent is that there is a full record of what happened and the only route to it runs through law enforcement.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | TextNow issues a real, working US phone number. There is no friend graph, no accept step and no mutual-contact requirement: anyone who has or guesses the number can call and text it, and inbound contact is unsolicited by design. That is band 3, default-open to strangers, reached without any matching feature at all. Apple App Store product page (age rating |
| hidden | 0 | Scored 0 deliberately, and the reason is a gap in the rubric rather than a fact about the app. The hidden axis measures a concealed area INSIDE the app, and TextNow has none. Its concealment is entirely outside the app: a second number does not appear on the family plan, in the carrier's records, or in the Messages app a parent checks. Stretching this axis to capture that would be finding 39's error running in the opposite direction, so the concealment is recorded in the flags and in the open second-number item instead. Apple App Store product page (age rating |
| browser | 1 | Apple declares no Unrestricted Web Access. Band 1 for ordinary link handling. Apple App Store product page (age rating |
| Disappearing messages | 0 | Message history persists in the app. Apple App Store product page (age rating |
| location | 2 | Precise Location is linked to identity on the App Privacy card, under App Functionality. Not exposed to other users, so not band 3. Apple App Store product page (age rating |
| ageverify | 3 | The sharpest rating mismatch in the dataset, and it is the vendor contradicting the store rather than the usual reverse. **Apple rates TextNow 4+.** TextNow's own Terms of Use, last updated 30 October 2025, require users to be "13 years of age or older, or if you live in the Province of Quebec, 14 years of age or older, or if you live in the State of California, Montana or Oregon, 16 years of age or older". The vendor's own contract bars the entire age band Apple's rating admits. No age-verification mechanism is described, the listing renders no In-App Controls subsection, and a 4+ rating means no age-based Screen Time content restriction a parent can select will withhold this app. Band 3's second limb: the stated rating does not match the actual content. TextNow Terms of Use |
| dataharvest | 3 | Band 3 on the second limb: Precise Location, Contacts and Contact Info are all linked to identity. Data Used to Track You lists Contact Info and Identifiers, which is band 2 on the count alone. The card additionally declares User Content "Emails or Text Messages" linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | Two federal prosecutions in which TextNow is named as the channel, both read at source in the Browser pane rather than from a search summary. SDTX, 24 Apr 2024: "Authorities executed a federal search warrant and discovered Jimenez was using the TextNow application to disguise himself as a teenage boy to engage in sexually explicit conversations with minors", guilty of coercion and enticement of a minor. D. Nev., 12 Dec 2022: the defendant contacted a supposed 14-year-old on Kik, then "exchanged messages via TextNow" the next day to discuss sexual activity, 84 months. Band 2, multiple documented cases; band 3 is withheld because no regulator, AG or DOJ action has been taken against the operator and no app-store removal has occurred. US Attorney |
High Risk Tinder Dating App: Date & Chat14 of 24
What you can actually do: Nothing for a parent to set in this age band. The vendor's controls are aimed at a younger band than the one this directory covers. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Distance-based matching with strangers is the product. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Match and message history persists. Apple App Store product page (age rating |
| location | 3 | Distance to other users is shown; Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 2 | Rated 18+. Apple discloses Age Assurance, and finding 26 is why that is no longer scored as a real operating gate. Apple defines the flag as a disjunction satisfied by a "declared age range API" read, and the Declared Age Range API's own values include selfDeclared. Nothing has been shown about what this operator actually runs, so this is band 2, a self-attested birthdate with some enforcement, until a vendor check says otherwise. Tinder's own documentation is unreachable from this host, see BLOCKED_CHECKS. Apple |
| dataharvest | 3 | Precise Location, Contacts and Contact Info all linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | No app-specific US enforcement action sourced in this pass; the operator does not appear on NCMEC's 2024 ESP list. NCMEC 2024 ESP list |
High Risk X14 of 24
What you can actually do: Controls exist and they do not reach this app's main risk. Setting them is worth doing and it will not address what this score is about. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The parent half follows directly from finding 20 and needs no new reading: X's parental controls are real, parent-set and gated behind submitted proof of guardianship, and every one of them is about video. Nothing in them touches direct messages, which is the vector X scores 3 on, and nothing in them shows a parent a contact, a message or a list. That is what `scope_limited` records on the controls axis and it is why the parent view is none rather than partial. The operator half is a full public guide: content takes "a valid search warrant or equivalent", the US controller is "X Corp. based in Austin, Texas", and preservation is "a temporary snapshot of the relevant account records for 90 days". Two of its disclosures belong in front of a parent. "X doesn't require real name use, email verification, or identity authentication", so the account behind a message may not resolve to a person; and retention is stated with no durations plus an explicit warning that "some information (e.g., IP logs) may only be stored for a very brief period of time", with deleted posts "generally not available". Of the seven, X and Reddit are the two whose notice policy names child sexual exploitation as a reason to stay quiet. Finding 78.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Open DM settings, a public reply graph, and adult content permitted on the platform. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 2 | Full general-purpose in-app browser. Apple App Store product page (age rating |
| Disappearing messages | 0 | Posts and DMs persist and remain reviewable after the fact. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 2 | Apple discloses Age Assurance and Parental Controls, but the rating is 16+ while consensual adult content is allowed platform-wide. Apple App Store product page (age rating |
| dataharvest | 3 | The widest tracking profile in the seed set: seven categories including Browsing History, User Content and Location. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | DECIDED 2026-08-11 (twentieth run), finding 55: the eSafety penalty is REFUSED for band 3 and lands at band 1 under INCIDENT_OBSTRUCTION_RULE, in the same lane as CyberTipline volume. The PUBLISHED band stays 2 and is HELD, per the register's standing discipline of never lowering a published score to match a thin citation; what changed is that the register now records the supported band as 1 rather than 2, which is a correction to the nineteenth run rather than to the score. That run refused this citation for band 3 and, in the same paragraph, UPGRADED the supported band from 1 to 2 on it, while the question of whether it supports anything was expressly still open. Band 2's own text is 'multiple documented cases naming the service, OR the service was removed from an app store' and an obstruction outcome is neither, so the upgrade had no band text to rest on. Nothing about the badge moves: X is High Risk at 14 at every band on this axis. The prior run's argument is preserved below because the refusal is decided ON it, not against it. Prior text follows. HELD at 2 on 2026-08-10 (nineteenth run), and held deliberately in the FACE of a qualifying-looking action rather than for want of one. The Federal Court of Australia ordered by consent on 21 May 2026 that X Corp. pay a A$650,000 civil penalty after it 'failed to fully comply with an eSafety transparency notice seeking information about steps it took to combat child sexual exploitation and abuse material'. Conjuncts 1 and 3 hold cleanly: it is against the operator and it names the service. CONJUNCT 2 IS A CASE THE TEST HAS NEVER SEEN, and it is finding 55: the contravention adjudicated is a REPORTING failure. A court found that X did not answer the regulator, not that X mishandled the material. The whole instrument is a child-safety instrument, so the substance-over-authority reading that admits the Garante and the ICO points one way; but those two are findings about how children were actually treated, and this is a finding about obstructing the body that asks. Deciding a new conjunct-2 shape inside a run that is spending the rule is exactly what finding 25 forbids, so the citation is recorded, the argument is written down, and the band does not move. Nothing rides on the outcome: X is High Risk at 14 and is not tier-sensitive on this axis at any band, which is why this is the right place to leave a rule question rather than force it. 686,176 CyberTipline reports in 2024, which carries no band on its own. Australian eSafety Commissioner |
High Risk Kik Messaging & Chat App13 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Kik holds message content for 60 days and then deletes it permanently from its servers, which is the number a parent and an investigator both need and neither would guess. Two things follow that a summary of this app gets wrong in opposite directions. It is not true that Kik has nothing to give: a search warrant return has a content folder, and the operator's own FAQ explains that it is empty only when no preservation request preceded the warrant or the account is banned or inactive past 60 days. It is also not true that the record is durable: 60 days is shorter than most families take to notice. What the user sees is a third thing again, since on a new device previous chats appear as a list while "the content of the conversations will be deleted". The parent half is nothing, verified against Kik's own help centre for the controls axis.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Username-only identity with no phone number, plus public group discovery. Apple App Store product page (age rating |
| hidden | 1 | Username-only accounts make a second hidden account trivial to run. Apple App Store product page (age rating |
| browser | 2 | Kik has long shipped a general-purpose in-app browser, which routes around device and router-level filtering. Apple App Store product page (age rating |
| Disappearing messages | 0 | Message history persists. Apple App Store product page (age rating |
| location | 0 | No location collected. Apple App Store product page (age rating |
| ageverify | 2 | Corrected down from 3 on 2026-08-09. The old rationale, signup requires only a username, is no longer true: Kik has raised registration to 18+ globally, requires a date of birth, and verifies age through VerifyMy for UK users under the Online Safety Act. Outside the UK it is still a self-attested birthdate, which is band 2, not band 3. Kik Help Center |
| dataharvest | 2 | Data Used to Track You: Identifiers. Contacts linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | SUPPORTED 2026-08-10 (nineteenth run), and the register entry it clears had asserted the opposite. That entry read 'no action against the operator exists' and said the fix was to move two DOJ citations in and settle at band 2. An action existed and had existed for almost a year: Nevada AG Aaron D. Ford sued MediaLab.AI and Kik on 18 Aug 2025 in the Eighth Judicial District business court, alleging the anonymity model made the app a haven for child predators and a vehicle for CSAM, under the Nevada Deceptive Trade Practices Act plus negligence, products liability and unjust enrichment. All three conjuncts of INCIDENTS_ACTION_TEST hold: against the OPERATOR (MediaLab.AI and Kik are the defendants), on CHILD-SAFETY grounds (the harm pleaded is predation on minors, not a generic consumer wrong), and NAMING THE SERVICE. Band 2's first limb is independently satisfied and is now cited here rather than only in the Phase 3 draft: United States v. Shaw (D. Or., 120 months, sentenced 16 Jul 2025), Snapchat and Kik used together to coerce a child over eight months; United States v. Treat (N.D. Okla., 135 months, sentenced 9 Mar 2026), opened by Kik's own CyberTip. 114,155 CyberTipline reports in 2024, which under the rewritten bands carries no band on its own. See finding 53: the negative in the old entry came from a search aimed at prosecutions, and a prosecution search does not find an AG. Nevada AG Aaron D |
High Risk MonkeyCool - Make New Friends13 of 24
What you can actually do: Nothing for a parent to set, on the listing's own account. Apple's listing discloses no parental controls and no vendor check has been done. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Random one-to-one video pairing with strangers. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 2 | Live video leaves no record on either side by design. Apple App Store product page (age rating |
| location | 1 | No precise location linked to identity. Apple App Store product page (age rating |
| ageverify | 3 | Apple renders no In-App Controls block and no Contains block on this listing at all, so the page says nothing either way about an age gate, and finding 2 forbids reading that silence as a developer declaring none. What can be said is what a parent sees: a bare 16+ with Frequent Mature or Suggestive Themes and nothing indicating their child will be on camera with strangers. Scored 3 on band 3's second limb, the stated rating does not match the actual content. The operator's own mechanism is unverified and is owed a vendor check. Apple |
| dataharvest | 1 | Data Used to Track You: Identifiers only. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | The predecessor Monkey app was pulled from the App Store after sustained reports of sexual content shown to minors; the successor remains and the web version is reachable regardless. AppleInsider |
High Risk NGL: ask me anything13 of 24
What you can actually do: Nothing for a parent to set in this age band. The vendor's controls are aimed at a younger band than the one this directory covers. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The two halves point in opposite directions and that is the entry. NGL is anonymous to the RECIPIENT, which is what the product sells and what a teen believes; it is not anonymous to the OPERATOR, which collects the content, runs it through AI moderation and discloses to law enforcement on judicial order. So there is a record and a parent cannot see any of it: no supervision feature exists, and the vendor's position is that nobody under 18 should be there at all, which is the private-side echo of the FTC order that already sits on this app's controls state. For a family, the practical reading is that the sender of an abusive anonymous message is not beyond identification, but reaching that identification runs through legal process and never through the parent.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Anonymous inbound messages from anyone. Apple App Store product page (age rating |
| hidden | 1 | Sender identity is concealed by design. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | Message history persists in-app. Apple App Store product page (age rating |
| location | 1 | Location appears in the Data Used to Track You categories. Apple App Store product page (age rating |
| ageverify | 0 | Under a 2024 FTC order NGL must run a neutral age gate barring all under-18s, the first time the FTC required a business to block minors from an online service. This is the strongest age gate in the seed set and it exists only because a regulator imposed it. FTC |
| dataharvest | 3 | Data Used to Track You spans Location, User Content and Purchases. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | FTC and Los Angeles County DA action, $5M paid, permanent ban on offering anonymous messaging apps to under-18s, plus findings of fake messages and deceptive AI-moderation claims. FTC |
High Risk Reddit13 of 24
What you can actually do: Nothing for a parent to set. The protections are on by default, and a parent cannot set them, verify them, or restore them if they change. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Nothing on the parent side and the teen-safety document is unambiguous about why: the protections are global defaults the account applies to itself, locked for 13-to-15s, with the parental-approval flow still labelled coming soon. There is no linked account, so there is no list, no report and nothing to log in to. The operator half is the most precisely enumerated in the field and it cuts both ways, which is why Reddit's entry should not be read as reassurance in either direction. Non-public messages between users are a named category and take the top of the process ladder, "Reddit will only disclose the Contents of Communications pursuant to a valid search warrant". But Reddit also discloses, against its own interest, that it "generally collects minimal information from users and may have little or no non-public information available for many accounts", with no name, email or phone required to register. And it publishes the shortest clock in this dataset: "Reddit automatically deletes any IP addresses collected after 100 days, except for the IP address used to create an account". Content survives; the log that ties an anonymous account to a person is the part with a deadline on it, which makes a preservation request early worth more here than almost anywhere else in the file. Preserved records run 90 days by default.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Open DMs and chat from any account, plus adult communities. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Posts and comments persist and remain reviewable after the fact. Apple App Store product page (age rating |
| location | 1 | No precise location linked to identity. Apple App Store product page (age rating |
| ageverify | 3 | Rated 18+ with no Age Assurance and no Parental Controls disclosed. Access is pure self-attestation. Apple App Store product page (age rating |
| dataharvest | 2 | Data Used to Track You: Identifiers and Usage Data. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | MOVED 2 to 3 on 2026-08-10 (nineteenth run), on the strongest evidentiary form available on this axis: a final adjudicated penalty, not a filed suit and not an open investigation. The UK Information Commissioner issued a Penalty Notice to Reddit, Inc. on 23 Feb 2026 for £14,472,500 under s.155(1) DPA 2018, for infringements of Articles 5(1)(a), 6 and 8 and Article 35 UK GDPR. The 335,000-character notice was downloaded and text-extracted rather than read through a summary: 'Until July 2025, Reddit had no form of age assurance that users were required to pass through in order to access the Platform', adult-content access was 'by self-declaration' with 'no form of verification' asked 'at the moment at which users wishing to view such content had the greatest incentive to be dishonest', and 'As a result of Reddit's failure to conduct a timely impact assessment, and/or to introduce appropriate age assurance measures, children, including very young children, were potentially exposed to this content', the content being pornography and discussions of suicide, self-harm, substance abuse and eating disorders. All three conjuncts of INCIDENTS_ACTION_TEST hold. The grounds conjunct is the Replika/Garante precedent applied a second time and it is the same shape, not a looser one: a data-protection authority, an absent age gate, minors exposed as a result. Conjunct 2's own text says the test is what the action turned on, never which authority brought it. The Texas AG matter stays what it was, an INVESTIGATION and not a finding, and is retained only as a flag. 334,597 CyberTipline reports in 2024, which carries no band on its own. NO BADGE MOVES: Reddit is already High Risk at 14 and is not tier-sensitive on this axis. UK Information Commissioner |
High Risk Text Free: Second Phone Number13 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The most explicit retention statement in the dataset, and it points the opposite way from what the category's reputation suggests. Pinger publishes a table with durations, and message content, which it defines as the text messages you send and receive plus voicemails, is held "Indefinitely for active account and 6 months for inactive accounts". Call detail records run two years and registration information indefinitely. The policy names the reason: as a communications company it retains for longer "in part to honor the needs of law enforcement". A burner number is not a burner record.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Pinger issues a real, working US phone number. No friend graph, no accept step, no mutual-contact requirement: anyone who has, guesses or inherits the number can call and text it, and inbound contact is unsolicited by design. Band 3 reached with no matching feature at all, the same route as TextNow. Apple App Store product page (age rating |
| hidden | 0 | 0 on this axis and the reason is a rubric gap, not a fact about the app: the hidden axis measures a concealed area INSIDE the app and Text Free has none. Its concealment is entirely outside the app, on the carrier bill, in the Messages app and in the call log, none of which show a Pinger number. Recorded here rather than scored, per the open concealment item and finding 47. Apple App Store product page (age rating |
| browser | 1 | Apple declares no Unrestricted Web Access. Band 1 for ordinary link handling. Apple App Store product page (age rating |
| Disappearing messages | 0 | Message history persists in the app. Apple App Store product page (age rating |
| location | 2 | Precise Location is linked to identity on the App Privacy card. Not exposed to other users, so not band 3. Apple App Store product page (age rating |
| ageverify | 3 | Apple rates Text Free **13+**. Pinger's own Terms and Conditions, last updated 30 April 2026, say the apps "are not intended for children under the age of 16, so children under the age of 16 should not use them at any time." The vendor bars the entire 13-15 band the store rating admits. This is TextNow's mismatch in a milder form and it points the same way: the store rating is the number a parent's Screen Time setting reads, and it is three years below the publisher's own floor. No age-verification mechanism is described and the listing renders no In-App Controls subsection. Pinger |
| dataharvest | 3 | Band 3 on the second limb, read in full per finding 42: Precise Location, Contacts and Contact Info (email, name, phone number) are all linked to identity under third-party advertising. Data Used to Track You lists Location, Identifiers and Usage Data, which is band 2 on the count alone. The card additionally declares User Content "Emails or Text Messages" linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 1 | Pinger, Inc. filed **2** CyberTipline reports in the whole of 2024. No documented case naming the service and no enforcement action against the operator were found this run. Band 1, isolated reports and no action, per the band text as rewritten this run. Read the direction warning with it (finding 4): a count of 2 on a service carrying SMS between people with no relationship describes what Pinger detects and reports, not what happens on the service. NCMEC |
High Risk Azar: Chat, Meet Friends12 of 24
What you can actually do: Nothing for a parent to set, on the listing's own account. Apple's listing discloses no parental controls and no vendor check has been done. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Random video pairing with strangers, filterable by country. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 2 | Live video leaves no record by design. Apple App Store product page (age rating |
| location | 1 | Country-level matching. No precise location linked to identity. Apple App Store product page (age rating |
| ageverify | 1 | MOVED 2 to 1 on 2026-08-11 (twenty-second run), and the old rationale's own closing words were 'until a vendor check says otherwise'. The vendor check was run and it says otherwise. Band 1 is 'the operator runs age estimation or verification, VERIFIED against the vendor or a regulator', and Azar's help centre documents two mechanisms read at source: an automated facial scan of every user just before a call starts, everywhere it operates, and an additional Yoti/FaceTec video-selfie check in a region list that NAMES THE USA. That last point is the whole of the move: the Kik and Reddit precedent caps a UK-only mechanism at regional_only because a US parent gets the policy and not the check, and this one is not UK-only. Failure is a ban, not a warning, and appeal escalates to an ID check. NO TIER MOVES AND THAT IS NOT A COINCIDENCE: Azar is High Risk on R3, R4 and R5, none of which reads the age axis, so a working age gate on an 18+ random-video app lowers a score without making the app safer for a child who is on it. Total 13 to 12, still High Risk. Read the parent lever, never the number. Azar Help Center |
| dataharvest | 2 | Data Used to Track You: Identifiers and Usage Data. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | No app-specific US case sourced. Category-level: the A.M. v. Omegle settlement, which required Omegle to shut down permanently, turned on a design that paired minors with adults. CBC News |
High Risk Yubo: Chat Meet & Make Friends12 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. This does not carry the whole answer: Yubo holds uploads, comments and messages, and states in the same guide that it does not store recordings of live videos, and live discovery is the surface this app is flagged for; if something happens on a live stream, a screenshot or screen recording taken by the family at the time is the only copy that will ever exist. Yubo runs the strongest age gate in the dataset and gives a parent no view at all, which is the pair worth reading rather than either half alone. The safety documentation read for the controls axis puts it directly: there is nothing for a parent to link to, set or review. The operator side is the best-documented in the dataset and it does not answer the same way for every surface. Uploads, comments and messages are held and reachable with a subpoena, search warrant or court order; live video is not held at all, and Yubo says so in terms: "We do not store recordings of live videos." On an app whose signature feature is going live, that is the half of the record most likely to matter and the half that does not exist. Two further conditions decide whether a US case reaches even the part that does: content is excluded from a response by default "unless explicitly requested and legally justified", so an investigator who does not name it does not receive it, and a non-French agency ordinarily arrives by MLAT or letter rogatory. Yubo's guide names crimes involving minors among the situations where it will cooperate directly instead, which is the shortest route in this file and the one a parent's case is most likely to qualify for. Accounts are "generally deleted after two years of inactivity", so the clock is long by the standards of this dataset.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Core loop is live group video rooms and swipe-matching with strangers filtered by proximity. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | Live streams leave no user-accessible record; text history persists. Apple App Store product page (age rating |
| location | 2 | Matching is proximity-driven. App Privacy does not show precise location linked to identity. Apple App Store product page (age rating |
| ageverify | 1 | Yoti facial age estimation on 100% of signups against the stated date of birth, ID verification as fallback, account removal on failure, and Yubo is now 18+. Sourced to Yubo's own safety documentation rather than to the Apple flag. The strongest operating gate in the dataset, and finding 15 is why it still does not rescue the tier. Yubo Safety Hub |
| dataharvest | 1 | Data Used to Track You: Usage Data only. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | HELD at 3, see INCIDENTS_UNDERSOURCED, supported band 1. UPDATED 2026-08-11 (twenty-first run): a documented case naming Yubo is now cited, and it was already in this file's own source registry under Instagram. Ryan Austin Lauless, S.D. Ind., 84 years on 17 Dec 2025 after a 4 Sep 2025 guilty plea, 'used social media applications such as Instagram, Snapchat, Discord, Yubo, Purp, and others' to coerce and threaten at least 84 minor victims aged 13 to 17, posing as a teenager called 'Cason Fredrickson'. The plea release and the sentencing release are ONE case, so this is band 1's single documented case rather than band 2's multiple. Also cited, and weaker for this app than the file implied: a Florida man received a life sentence after using a fake teen profile on 'a social app', which does not name Yubo. 1,714 CyberTipline reports in 2024, which carries no band on its own. DOJ S |
High Risk Wizz App - chat now11 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Mandatory age estimation, ID fallback, face-matching and age-banded communities, all vendor-documented and none of it parent-facing. The controls check read the safety documentation in full and found no supervision surface, so there is no contact list or history a parent can be shown. The operator holds direct-message content and lists it by name among the data a valid law-enforcement request can reach, gated behind "a domestic court or judicial order, warrant, or equivalent" rather than a subpoena. Wizz and Yubo are the same country, the same age-assurance vendor and nearly the same product, and their guides differ in one way worth carrying: Wizz names no exception to the MLAT and European Investigation Order route, not even for crimes involving minors, so a US request has no documented fast path. The published retention table compounds it. It gives a duration for account data, purchases and analytics and no duration at all for message content, which is the one category the same operator offers to produce.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Swipe-to-chat with strangers is the entire product. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | Chat history persists inside the app. Apple App Store product page (age rating |
| location | 1 | No precise location linked to identity in App Privacy. Apple App Store product page (age rating |
| ageverify | 1 | Mandatory Yoti age estimation before account creation, ID fallback, and the first profile photo is face-matched to the verification selfie. Sourced to Wizz's own safety documentation rather than to the Apple flag, and adopted as a post-removal safeguard after the Jan 2024 store removal. Wizz Safety Hub |
| dataharvest | 1 | Data Used to Track You: Usage Data only. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Removed from both the Apple App Store and Google Play in January 2024 after reports of use in sextortion of minors; later reinstated after a safeguards review. CNBC |
High Risk Character AI: Chat, Talk, Text10 of 24
What you can actually do: Apple's listing says this app has parental controls and no vendor check has confirmed it. Look for them, and treat the tier as provisional. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 0 | No human-to-human contact. The risk here is not a stranger reaching the child. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Conversation history persists. Apple App Store product page (age rating |
| location | 1 | Location appears in the Data Used to Track You categories. Apple App Store product page (age rating |
| ageverify | 2 | Rated 18+. Apple discloses Age Assurance, and finding 26 is why that is no longer scored as a real operating gate. Apple defines the flag as a disjunction satisfied by a "declared age range API" read, and the Declared Age Range API's own values include selfDeclared. Nothing has been shown about what this operator actually runs, so this is band 2, a self-attested birthdate with some enforcement, until a vendor check says otherwise. Character.AI's own pages are DNS-blocked from this host, see BLOCKED_CHECKS. Does not affect the tier, which is the R6 editorial override. Apple |
| dataharvest | 3 | Tracking spans four categories: Contact Info, Location, Identifiers and Usage Data. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Garcia v. Character Technologies, brought after the suicide of a 14-year-old user; in May 2025 the court allowed most chatbot-harm claims to proceed, the first federal ruling that a conversational AI can plausibly owe a duty of care to minor users. Character.AI and Google later agreed to settle teen-harm suits. Tech Policy Press case tracker |
High Risk Talkatone: WiFi Text & Calls10 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The privacy policy counts "in-app messages and image, video, or other files" and voice calls as personal information it holds, and it discloses customer specific information in response to subpoenas and court orders, reserving the right to "access, read, preserve, and disclose" information to comply with a court order. Retention is stated as a set of criteria with no duration attached, which is the same silence as Text Me. The parent half was settled by the Terms of Use already read in full for the controls axis: a 16+ eligibility floor, no supervision flow and no age-verification mechanism.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Talkatone issues a "Company Number", a real US telephone number reachable from the public network by anyone who dials it. Its own Terms add a second-order vector the other three share and only Talkatone documents: the user does not own the number and Talkatone may reclaim it after inactivity, so numbers are recycled, and an inherited number carries the previous holder's inbound traffic. Band 3. Apple App Store product page (age rating |
| hidden | 0 | 0 for the rubric-gap reason recorded across this category. Finding 47. Apple App Store product page (age rating |
| browser | 1 | Apple declares no Unrestricted Web Access. Band 1 for ordinary link handling. Apple App Store product page (age rating |
| Disappearing messages | 0 | Message history persists in the app. Apple App Store product page (age rating |
| location | 1 | Coarse Location only, linked to identity, under third-party advertising, product personalisation and app functionality. Band 2 requires PRECISE location and the card names Coarse under every purpose, which finding 42 established are distinct literals Apple uses reliably. Apple App Store product page (age rating |
| ageverify | 3 | Band 3's first limb, self-attested only. Talkatone's Terms of Use (8 January 2025) state "The Service is available only to individuals who are at least 16 years old" and Apple rates the app 16+, so this is the one app in the category where the store rating and the vendor's floor AGREE, and that agreement is worth naming because the other three disagree. What is absent is any mechanism: no age estimation, no verification, nothing disclosed to Apple, and no In-App Controls subsection on the listing. Talkatone Terms of Use |
| dataharvest | 2 | Band 2 on the count: Data Used to Track You lists Location, Identifiers and Usage Data. The second limb of band 3 fails on precision, since only Coarse Location is linked. Apple App Store product page (age rating |
| Documented harm and enforcement | 0 | TALKATONE, INC. does not appear in NCMEC's 2024 ESP list, so it filed no CyberTipline reports in 2024, and no documented case or enforcement action naming the service was found this run. Band 0 records a search that returned nothing, with finding 4's direction warning attached. NCMEC 2024 ESP list |
High Risk Replika - AI Companion Chat9 of 24
What you can actually do: Nothing for a parent to set in this age band. The vendor's controls are aimed at a younger band than the one this directory covers. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 0 | No human-to-human contact. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Conversation history persists. Apple App Store product page (age rating |
| location | 1 | Corrected up from 0 on 2026-08-10 by the screening layer's positive control, the same defect found on Roblox in the same pass. The old rationale read "No location collected" and Replika's App Privacy card lists Location, Coarse Location under Data Linked to You (product personalisation and app functionality) and again under Data Not Linked to You. Coarse location tied to identity is band 1; no precise location is declared, so it is not band 2. Apple App Store product page (age rating |
| ageverify | 2 | Rated 18+ with no Age Assurance and no Parental Controls disclosed. Apple App Store product page (age rating |
| dataharvest | 2 | Data Used to Track You: Identifiers and Usage Data. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Sourced 2026-08-09, and the recollection was right. Italy's data-protection authority ordered an urgent limitation on Replika's processing of Italian users' data on 2 Feb 2023, finding the platform ran no age verification at account creation and served minors responses it called "assolutamente inidonee", against a backdrop of user reviews reporting sexually inappropriate content. The same authority fined Luka Inc. EUR 5,000,000 on 19 May 2025 and held that the age verification implemented since remains deficient. MOVED 2 to 3 on 2026-08-10 (eighteenth run) as the ONE badge the finding 51 decision moves, Caution to High Risk, and it is the decision's hardest case rather than an incidental consequence. There are still no documented human-predator cases, so under the old band 3 ("multiple recent documented cases AND an action") the absence of the first conjunct capped it at 2. All three conjuncts of INCIDENTS_ACTION_TEST hold: two actions against the OPERATOR, Luka Inc., on grounds that are child safety in substance (absent age verification, sexual content served to minors) even though the Garante is a data-protection authority, and both name Replika. The consistency argument is what makes it right rather than merely rule-following: Character.AI, its direct category peer, publishes High Risk on Garcia v. Character Technologies, which this same file records as PRIVATE litigation and not an enforcement action. Handing a parent Caution for the app with two adjudicated regulator findings and High Risk for the app with a private suit was a distinction the evidence never supported. Garante per la protezione dei dati personali |
High Risk Text Me - Phone Call + Texting9 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The privacy policy puts "messages sent and received using TextMe services" inside the Usage Data it collects, and the law-enforcement notice accepts subpoenas, warrants and court orders, so the record exists and legal process reaches it. Two qualifications belong on the same line rather than in a footnote. TextMe states no retention duration anywhere, so unlike Text Free nobody outside the company knows how long the record lasts. And retrieval is priced: subscriber information costs a requesting agency $75 for up to three numbers, with notarised documents $200 more. The record existing and the record being obtained are different questions, and this is the app where a fee sits between them.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | TextMe issues a real, working US phone number. No friend graph and no accept step: anyone who has, guesses or inherits the number can call and text it. Band 3, default-open to strangers, by the same route as TextNow and Text Free. Apple App Store product page (age rating |
| hidden | 0 | 0 for the same rubric-gap reason recorded on TextNow and Text Free: the axis measures a concealed area inside the app and there is none. The concealment is the number itself, which appears on no bill and in no Messages thread. Finding 47. Apple App Store product page (age rating |
| browser | 1 | Apple declares no Unrestricted Web Access. Band 1 for ordinary link handling. Apple App Store product page (age rating |
| Disappearing messages | 0 | Message history persists in the app. Apple App Store product page (age rating |
| location | 0 | No Location of any kind appears anywhere on the App Privacy card, under any purpose. The direction check finding 32 established applies: this is a card that renders and simply carries no Location entry, not a card that failed to render. Apple App Store product page (age rating |
| ageverify | 3 | **Apple rates Text Me 4+.** TextMe's own Terms and Conditions, effective 15 October 2025, require a user to be "at least thirteen (13) years old in order to use Our Products and Services", with a parent or guardian required to enter into the contract for anyone under 18. This is TextNow's finding repeating on a second app in the same category, which is what makes it a property of the category rather than one vendor's filing error: **4+ is the floor of Apple's rating scale, so no age-based Screen Time content restriction a parent can select will withhold this app**, while the publisher's own contract bars every user under 13. No age-verification mechanism is described anywhere. TextMe |
| dataharvest | 2 | Band 2 on the count: Data Used to Track You lists Purchases, Identifiers and Usage Data, three categories. The second limb of band 3 fails cleanly, since the card carries no Location entry at all. Contact Info (email, phone number) and User Content "Emails or Text Messages" are linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 0 | TextMe, Inc. does not appear in NCMEC's 2024 ESP list, so it filed no CyberTipline reports in 2024, and no documented case or enforcement action naming the service was found this run. Band 0 means a search was run and returned nothing, which is not the same claim as "nothing happens here": finding 4's direction warning is at its strongest on a service that carries SMS between strangers and reports zero. NCMEC 2024 ESP list |
High Risk Peek: Secret Compliment8 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The vendor's Safety Center and privacy policy were both read in full for the controls axis and neither contains a parent-facing feature of any kind: no supervision, no linked account, no setting a parent can reach. On an anonymous compliment app, nothing a parent can see means nothing about who is sending. The operator half rests on a thinner document than any other entry in this field and the thinness is itself the thing to report. Peek names AWS as its cloud provider and Twilio for user communications, so the pool of who picked whom sits on the operator's servers rather than on the phones, and a US company holding US-hosted records is reachable by ordinary legal process whatever its policy says. What is missing is the vendor's own account of it: the privacy policy contains no legal-process clause at all, no mention of law enforcement, court orders or subpoenas, and the sharing section runs to vendors and business transfers and stops. Retention is capped at the life of the account and stated no more precisely than that. This is the weakest-evidenced determination in the field and finding 71 is where that is argued rather than hidden inside a state that reads identical to Yubo's.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | No direct messaging, confirmed in the vendor's own words: "you cannot directly message each other within the app". Contact is the school-and-grade pool plus a school-wide "School Board". Band 2 rather than 1 because the pool is not a mutually-confirmed graph and the vendor says so: school membership is self-asserted, and "If you join a school that you do not attend, strangers might add you as a friend". Not band 3: no random matching, no geo or nearby surface. Peek Safety Center (Dyve Studios) |
| hidden | 1 | Voter identity is concealed by design, and partial reveals ("hints") are the paid upgrade. Obscures rather than disguises, so band 1, the same reading as sendit and NGL. Apple App Store product page (age rating |
| browser | 0 | The Contains section is rendered and does not declare Unrestricted Web Access. Per finding 2 the section exists, so this is a real non-declaration rather than a missing section. No in-app browser is described in the vendor's own documentation either. Apple App Store product page (age rating |
| Disappearing messages | 0 | Picks and the personal feed persist; no disappearing-content feature is disclosed or described. Note the deletion lag the vendor states: "Peek account deletion is processed immediately after 120 hours." Apple App Store product page (age rating |
| location | 1 | Apple's App Privacy card declares no Location category, and the card IS rendered, so that is a real non-declaration. The vendor's own privacy policy nonetheless lists "location" among the device data it automatically collects, at IP-derived coarse granularity. Band 1 (coarse) on the vendor's document, not band 0 on Apple's silence. This is a difference of scope between two of the developer's own documents and is NOT scored as a false disclosure. Dyve Studio Inc |
| ageverify | 3 | Rated 9+ on the product page (the iTunes lookup API still returns 4+, finding 1 again). The listing renders a Contains section but no In-App Controls subsection at all, so neither Age Assurance nor Parental Controls is declared. Signup verifies a phone number by SMS, which establishes a handset and not an age, and neither the Safety Center nor the privacy policy states a minimum age. Band 3 on both limbs: self-attested only, and a 9+ rating on a school-wide anonymous peer-rating board. Apple App Store product page (age rating |
| dataharvest | 1 | One category under Data Used to Track You (Identifiers), which is band 1 by the axis's own mechanical definition. The privacy policy corroborates it: IDFA access under AppTrackingTransparency, shared with AppsFlyer for attribution. Apple App Store product page (age rating |
| Documented harm and enforcement | 0 | No documented incident found in any tier-2 or tier-3 source. Read this with finding 3: the app first shipped 24 August 2024, so the absence is a young app rather than a clean record, and App Store reviews alleging bullying are explicitly not a source under this file's own rules. Peek Safety Center (Dyve Studios) |
High Risk Valid - Compliment Classmates6 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Terms of Service and privacy policy, both read in full for the controls axis, describe no parental control and no supervision flow. Read this beside the open item on identifying-data collection: the app takes a child's phone number, name, age, school, grade, photos and address book, and shows a parent none of it. The operator half needs no inference, because the collection list names the anonymity machinery itself: "Poll, vote, invite, reveal, subscription, purchase, and app activity information". The reveal is a paid feature, so the identity behind an anonymous vote is a thing the operator holds and prices, and the same sentence that establishes the product establishes the record. Legal disclosure is one unelaborated clause and no retention duration is given.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | Apple declares no Messaging and Chat for this listing, so this score is read off the vendor's own documents rather than an Apple flag. The pool is contacts plus classmates at the same high school, with school-wide activity browsable, and votes arrive anonymously from people who are not mutually-confirmed contacts. Band 2 for a public discovery surface without direct messaging. Not band 3: no random matching, no geo or nearby surface. Valid Privacy Policy (RevueAI |
| hidden | 1 | Anonymity is the product, and the privacy policy names "reveal" as its own category of collected activity data, alongside subscriptions and purchases. Obscures rather than disguises, so band 1. Valid Privacy Policy (RevueAI |
| browser | 0 | The Contains section is rendered, declaring only User-Generated Content, and does not declare Unrestricted Web Access. Finding 2: the section exists, so this is a real non-declaration. Apple App Store product page (age rating |
| Disappearing messages | 0 | A personal feed of received votes and browsable school-wide activity. No disappearing-content feature is disclosed or described. Apple App Store product page (age rating |
| location | 0 | No Location category on Apple's App Privacy card, which is rendered, and no location collection described in the vendor's privacy policy. See the flags: the app collects the child's school and grade, which this axis is not built to measure. Apple App Store product page (age rating |
| ageverify | 3 | Rated 13+ on the product page (the iTunes lookup API returns 12+, finding 1 again). The listing renders no In-App Controls subsection, so no Age Assurance is declared. The Terms state "You must be at least 13 years old to use Valid" and the privacy policy states "Valid is not intended for children under 13", with no verification method described in either document. Band 3: self-attested only. Valid Terms of Service (RevueAI |
| dataharvest | 0 | Apple's App Privacy card renders no "Data Used to Track You" section at all, which is band 0 by the axis's own mechanical definition. That is the honest mechanical read and it is also why this axis under-describes the app: see the flags and finding 39. Apple App Store product page (age rating |
| Documented harm and enforcement | 0 | No documented incident found in any tier-2 or tier-3 source. Finding 3 applies with more force than usual: the app first shipped 11 December 2025 and has 479 ratings, so this is a new and small app, not a cleared one. Valid Terms of Service (RevueAI |
Caution Facebook14 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: A parent can see WHO their child has been in contact with, and when, through the vendor's own supervision tool. Not what was said. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The same two documents as Instagram and the same answer on both halves, which is worth stating rather than leaving implied: one supervision invitation covers both apps, and one warrant standard covers both. The asymmetry inside this family is at Messenger, not here. The 90-day preservation window and the deleted-content caveat apply identically.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | Friend requests and message requests from non-friends; public groups. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 2 | Full general-purpose in-app browser. Apple App Store product page (age rating |
| Disappearing messages | 1 | Stories; main content persists. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 1 | Meta runs AI age detection that catches accounts listing an adult birthday and moves them into Teen Account settings, in the US since Apr 2025, with visual age analysis added Jun 2026. A real operating mechanism, so band 1 is earned on evidence rather than on Apple's flag. It is a backstop rather than a gate: signup is still a self-reported birthday and Meta lets people change the setting if it gets one wrong. Meta Newsroom |
| dataharvest | 3 | Tracking spans Contact Info, Identifiers and Other Data; Precise Location and Contacts linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Re-sourced 2026-08-10 (eighteenth run) and the register entry clears. The band did not move; what changed is that it now rests on a final judgment instead of a pending suit. State of New Mexico v. Meta reached FINAL JUDGMENT on 7 Aug 2026, three days before this run and uncited anywhere in the build: a jury found 75,000 violations of New Mexico's Unfair Practices Act with a $375M maximum civil penalty, and the Court held Meta's platforms a public nuisance, rejected a Section 230 defence, ordered $567M and five years of court-supervised reforms to Facebook and Instagram including enhanced protections against sextortion and child sexual exploitation, with semiannual compliance reports. All three conjuncts of INCIDENTS_ACTION_TEST hold and the grounds are child safety in the strongest form available. Prior evidence stands: the October 2023 42-state AG suit, whose paragraph 1 names Facebook and Instagram as its subject; 8,590,357 CyberTipline reports in 2024, the largest single figure on NCMEC's list, which under the rewritten bands carries no band on its own. CITATION ATTACHED 2026-08-11 (twenty-second run), not new evidence: this rationale had relied on that 42-state suit in prose for eleven passes while NJAG_META, the operative release, was cited by no app in the file. The claim was publishing without its citation, which is finding 65 and is why --orphan-sources now exists. Read at source this run and it holds; it also names only Instagram and Facebook, never Messenger or WhatsApp. RE-SCORE TRIGGER: the ordered reforms run five years with public compliance reports, so this axis has a scheduled input rather than a static citation. New Mexico DOJ |
Caution TikTok - Videos, Shop & LIVE13 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. This does not carry the whole answer: TikTok does show a parent a list of named accounts, the people their teen follows and is followed by plus accounts they blocked, so check it; the gap is that a stranger reaches a teen by message request and accepting one creates no follow, so the conversation that matters appears on no list a parent is shown and the list will look clean. The hardest parent call in the dataset so far, and the one most likely to be re-litigated, so read the reason before changing it. TikTok is one of only two apps in this field whose supervision tool shows a parent a LIST of named accounts: Family Pairing lets a parent "View who your teen is following on TikTok, and who follows them, along with accounts they blocked". That is the follow graph, and the DM graph is not the same set. TikTok's own messaging documentation establishes the gap: "To message someone who doesn't follow you, you'll need to send a request for them to accept", and accepting a request creates no follow, so the conversation a parent most needs to see is the one least likely to appear on the list they are shown. Recorded as 'none' because the field's question is who the child has been in contact with, and telling a parent they can see that when a stranger's accepted message request is invisible is the error direction finding 18 says never to make. What TikTok does give is real and is stated here rather than hidden by the state: a follower and following list, a blocked list, and a privacy-settings overview. Finding 75 argues the vocabulary gap this exposes and deliberately does not patch it. The age floor also belongs in front of a parent: direct messaging "isn't available to teens under 16 years old", so for a 13-to-15-year-old the DM vector this entry is about is closed by default. The operator half needs no argument. Content is a named category requiring "a domestic court / judicial order, warrant or equivalent", preservation runs 90 days and may be extended exactly once, and unlike Yubo and Wizz the US route is domestic: US users are served by TikTok USDS Joint Venture LLC in Culver City, so no MLAT stands between a US investigator and the record.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | DMs are restricted for under-16s; the For You feed and comments still expose accounts to strangers. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 2 | Full general-purpose in-app browser. Apple App Store product page (age rating |
| Disappearing messages | 0 | Posted content persists. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 1 | TikTok runs age inference, confirmed by a regulator rather than by the Apple flag: Ofcom's s.12 investigation is premised on it and Ofcom's Age Assurance report discusses age inference models such as TikTok's. Band 1 stays exactly as finding 25 decided, and for the reason finding 25 gave: an open investigation into whether the mechanism is highly effective is evidence about the question, not an answer to it. Re-score at Ofcom's October 2026 update. Ofcom |
| dataharvest | 3 | Tracking spans Contact Info and Identifiers; Precise Location and Contacts linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Utah's suit alleges TikTok's internal 'Project Meramec' review found hundreds of thousands of under-18 LIVE creators receiving concerning messages from adults, with virtual gifting incentivising sexualised content; the court denied TikTok's motion to dismiss. 1,359,806 CyberTipline reports in 2024. Utah Dept |
Caution WhatsApp Messenger13 of 24
What you can actually do: Nothing for a parent to set in this age band. The vendor's controls are aimed at a younger band than the one this directory covers. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. Message content is end-to-end encrypted and the operator does not hold it. Account records do exist and legal process can reach those. Content is end-to-end encrypted and WhatsApp states it does not retain messages in the ordinary course and deletes them from its servers once delivered, holding undelivered messages encrypted for up to 30 days. Account records exist and legal process reaches them. The parent side is none for the reason already verified on the controls axis: Meta's parent-managed accounts are a pre-teen product and do not reach a 13+ app.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | Anyone holding the phone number can message; public group invite links are indexable. Apple App Store product page (age rating |
| hidden | 1 | Archived chats and disappearing messages obscure without disguising. Apple App Store product page (age rating |
| browser | 0 | No in-app browser; links open in the device browser where filtering still applies. Apple App Store product page (age rating |
| Disappearing messages | 2 | Disappearing messages and view-once media are prominent. Apple App Store product page (age rating |
| location | 2 | Live Location sharing is a built-in feature; Contacts linked to identity. Apple App Store product page (age rating |
| ageverify | 3 | Rated 13+ with no Age Assurance and no Parental Controls disclosed. Apple App Store product page (age rating |
| dataharvest | 1 | No Data Used to Track You disclosed. Contacts linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | DECIDED BY JASON 2026-08-11 (twenty-fifth run): moved 3 to 2, the band its citation supports, and WhatsApp publishes Caution. This was the last NEEDS JASON entry in the file and the only tier-sensitive incidents gap. The decision is the rubric applied rather than an exception granted, which is the whole argument for it: finding 51 defines band 3 as an enforcement action against the OPERATOR on CHILD-SAFETY grounds NAMING THE SERVICE, no such action exists for WhatsApp, and holding it at 3 would have meant overriding the rubric for one app on the strength of a CyberTipline count that finding 4 already establishes cannot band anything. The downward move is not a statement that WhatsApp is safer than it was; it is a statement about what is documented. Read it beside the evidence trail, which is where the decision-useful fact lives: content is end-to-end encrypted, `operator_hold` is metadata_only, and there is nothing for an investigator to subpoena. A parent is not under-warned by Caution here, because Caution carries the mandatory lever sentence and the trail says the thing that actually matters. Prior rationale retained in full below, and every fact in it still holds. Re-sourced 2026-08-10 (sixteenth run) and the band was HELD rather than confirmed, see INCIDENTS_UNDERSOURCED. For nine passes this score rested on a single number, 1,851,086 CyberTipline reports in 2024, second only to Facebook, on a platform where message content is end-to-end encrypted. Under the rewritten bands a report count cannot reach band 2 or 3 on its own, because it measures what an operator detects and reports (finding 4). One search this run found two federal prosecutions naming WhatsApp as the channel: SDTX, 13 Jan 2023, a complaint charging coercion and enticement of a minor "through the use of the WhatsApp messaging application"; and D. Md., Scott Lee Dye, 270 months, guilty plea 16 Jun 2025, who used WhatsApp and Kik to attempt to meet people he believed to be minors. That is band 2's first limb, multiple documented cases. Band 3 additionally requires an action against the operator about child safety and none was found: the Texas AG suit of 21 May 2026 against Meta and WhatsApp concerns encryption and privacy representations and must NOT be cited here. Tier-sensitive, High Risk at 3 and Caution at 2, so the band is held pending a decision rather than moved by an unattended run. UPDATED 2026-08-10 (nineteenth run): the Texas refusal is now POSITIVELY ESTABLISHED at source instead of asserted, and it survived the strongest available challenge. The challenge is real: Nevada obtained a finding on 22 Jul 2026 that Meta misrepresented the safety of end-to-end encryption in MESSENGER on child-safety grounds, so 'it is only an encryption case' is not by itself a reason to refuse an encryption case. The petition was therefore downloaded and text-extracted in full (Harrison County 26-0393, 63,920 characters, defendants Meta Platforms, Inc. and WhatsApp, LLC, one cause of action, the Texas DTPA). 'child' occurs 7 times, 'minor' once, 'youth' 4 times, and EVERY occurrence sits in the background section arguing Meta has a pattern of misrepresentation, citing the FTC's 2019 and 2023 proceedings, the Facebook Papers and the social-media MDL. Not one concerns WhatsApp's own conduct toward children. The petition's own paragraph 58 states the direction of travel: 'Meta's documented misrepresentations are not limited to risks to youth posed by its platform.' The pleaded wrong is that Meta told 3 billion users 'not even WhatsApp' can read their messages while running an internal system that could. SAME TECHNOLOGY, SAME KIND OF CLAIM, DIFFERENT GROUNDS, and finding 54 is that pair. Nevada's injunction is scoped to Messenger users under 18; Texas's requested relief is scoped to all Texans' message privacy. Also checked and also negative: Nevada's own list of pending suits is 'Meta, TikTok, Snapchat, YouTube, Discord and Kik' and does not reach WhatsApp. STILL NEEDS JASON, and it is now the only such entry. US Attorney |
Caution Likee - Video, Live, Chat12 of 24
What you can actually do: Apple's listing says this app has parental controls and no vendor check has confirmed it. Look for them, and treat the tier as provisional. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Recommendation feed plus open messaging with strangers. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | Posted content persists; live is ephemeral. Apple App Store product page (age rating |
| location | 1 | No precise location linked to identity. Apple App Store product page (age rating |
| ageverify | 2 | Apple discloses Age Assurance, and finding 26 is why that is no longer scored as a real operating gate. Apple defines the flag as a disjunction satisfied by a "declared age range API" read, and the Declared Age Range API's own values include selfDeclared. Nothing has been shown about what this operator actually runs, so this is band 2, a self-attested birthdate with some enforcement, until a vendor check says otherwise. Likee's documentation estate is unreachable from this host, see BLOCKED_CHECKS. Apple |
| dataharvest | 2 | Data Used to Track You: Identifiers. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | HELD at 2, see INCIDENTS_UNDERSOURCED, supported band 1. UPDATED 2026-08-11 (twenty-first run): a federal prosecution names Likee, which the entry previously said did not exist. David Dunn, 57, E.D. Pa., sentenced to 25 years on 18 Sep 2023, 'used the mobile applications Snapchat and Likee to coerce and entice a 10-year-old female to engage in sexually explicit conduct', having told her he was 11 years old. One documented case is band 1. Likee Pte. Ltd. filed one CyberTipline report in the whole of 2024, and the pair is the point: a single report a year alongside a 25-year federal sentence for conduct on the app measures what the operator detects and reports, not what happens there. DOJ Office of Public Affairs |
Caution YouTube12 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Confirmed against the supervision document itself rather than inferred from the product: a parent sets a content level, blocks channels, pauses history, disables autoplay, caps Shorts and sets bedtime reminders, and no setting reaches comments or the ability to message the child. This is the app in the dataset where a parent is most likely to assume otherwise, because YouTube's supervision is set up through the same Family Link flow that carries contact controls elsewhere, so the entry has to say the limit out loud rather than let the badge imply coverage. The operator half is Google-wide rather than YouTube-specific, the same shape as META_LE settling three apps at once, and the US provider is "Google LLC, a US company operating under US law". Content takes a warrant, "Get a search warrant to compel disclosure of the content of communications, such as email messages, documents, and photos", non-content records take a court order, subscriber information takes a subpoena. Google's notice default is the strongest of the seven and its exception is an emergency one rather than a category one: notice is withheld in emergencies "such as threats to a child's safety", which is not the same promise Reddit and X make. Finding 78.
| What we checked | Score | Why |
|---|---|---|
| stranger | 1 | Direct messaging was removed in 2019. Comments remain a contact surface. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Uploaded videos and comments persist and remain reviewable after the fact. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 2 | Apple discloses Age Assurance, and finding 26 is why that is no longer scored as a real operating gate. Apple defines the flag as a disjunction satisfied by a "declared age range API" read, and the Declared Age Range API's own values include selfDeclared. Nothing has been shown about what this operator actually runs, so this is band 2, a self-attested birthdate with some enforcement, until a vendor check says otherwise. Supervised experiences and YouTube Kids are parental-control features, not an age gate, and they were doing work on this axis that they do not do. Apple |
| dataharvest | 3 | Tracking spans Contact Info and Identifiers; Precise Location and Contacts linked to identity. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | MOVED 2 to 3 on 2026-08-10 (nineteenth run). The old rationale's own words were 'No YouTube-specific AG action sourced in this pass', and one exists: Nevada AG Ford filed a civil action on 16 Jun 2025 'against social media platform YouTube, as well as its corporate parents Google LLC and Alphabet Inc.', alleging deliberate design choices and public misrepresentations that target Nevada's youth, and naming 'ineffective parental controls' among them. All three conjuncts of INCIDENTS_ACTION_TEST hold, and conjunct 3 holds in its strong form: the service is a named defendant and the corporate parents are additional, which is the reverse of the corporate-parent problem that sank the 42-state suit for Messenger. THE GROUNDS CONJUNCT IS THE JUDGMENT CALL HERE and it is decided on consistency rather than on taste: Nevada's YouTube suit pleads addictive design and mental-health harm, not predator contact, and the file already counts an addictive-design AG action toward band 3 for Instagram (the 42-state suit). Refusing it for YouTube while allowing it for Instagram would be a distinction the evidence does not support. NO BADGE MOVES and the blast radius was measured before the edit rather than after: YouTube's verified parental controls mean R4 cannot fire, R2 bumps only to Caution, and YouTube is already Caution at 11. Only four apps in the dataset are tier-sensitive to an upward incidents move at all, and YouTube is not one of them. Google filed 1,175,084 CyberTipline reports in 2024 across its products, which is a Google-wide figure and carries no band on its own. Nevada AG Aaron D |
Caution Discord - Talk, Play, Hang Out11 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: A parent can see WHO their child has been in contact with, and when, through the vendor's own supervision tool. Not what was said. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. Family Center shows a parent the names of friends added and who their teen has messaged or called, without message content, alongside the parent-set contact controls verified in the fourth run. Discord retains the messages sent and its end-to-end encryption claim is scoped to voice and video by its own wording, so text content sits on Discord's servers and legal process reaches it. This is the pair that makes the case against ranking these states: Discord scores the most retrievable combination in the dataset and is not the safest app in it.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Any member of a shared public server can open a DM under default settings; no prior relationship required. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | Link previews and an in-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | History persists; messages can be deleted manually. Apple App Store product page (age rating |
| location | 0 | No location collected or exposed. App Privacy shows no location data. Apple App Store product page (age rating |
| ageverify | 2 | Apple discloses Parental Controls but NOT Age Assurance. Signup is a self-attested birthdate. Apple App Store product page (age rating |
| dataharvest | 1 | Data Used to Track You: Identifiers only. No location, no contacts. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | SOURCED 2026-08-10 (eighteenth run), closing what the sixteenth run called the largest single missing citation in the build. Discord published band 3 for nine passes on one DOJ case plus a report count, while a state AG enforcement action existed and was cited nowhere in the file. New Jersey AG Platkin and the Division of Consumer Affairs sued Discord, Inc. on 17 Apr 2025 in Superior Court, Chancery Division, Essex County, under the New Jersey Consumer Fraud Act, after a multiyear investigation. All three conjuncts of INCIDENTS_ACTION_TEST hold: against the OPERATOR (Discord, Inc. is the named defendant), on CHILD-SAFETY grounds (the complaint alleges the Safe Direct Messaging feature was represented as scanning and deleting explicit DMs when the default 'My friends are nice' setting scanned nothing between friends, and that Discord requires only a typed date of birth), and NAMING the service. Supporting evidence unchanged and now secondary rather than load-bearing: 241,354 CyberTipline reports in 2024; NCMEC recorded a 474% rise in Discord CSAM reports 2021-2022; the DOJ's Greggy's Cult indictment describes a network that organised on Discord servers, which is a prosecution of OFFENDERS and is band 2 evidence, not band 3. SECOND ACTION ADDED 2026-08-10 (nineteenth run), 17 days old and it changes nothing about the band but adds a dated obligation the file should be watching: Texas AG Paxton obtained an Agreed Temporary Injunction on 24 Jul 2026 requiring Discord to give Texas children 'the same age-assurance and default safety protections it already provides to its users in the United Kingdom', with 90 days to enable them for every Texas user. That deadline falls around 22 Oct 2026 and is a scheduled re-score input for the age and parental-controls axes, not for this one. The release also supplies a 2025 NCMEC figure ahead of NCMEC's own publication, 489,782 reports from Discord, and it should NOT be mixed into the 2024 ESP table: comparing one platform's 2025 count against everyone else's 2024 is finding 4's error with a date attached. NJ AG Platkin and the Division of Consumer Affairs sue Discord |
Caution Pinterest11 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The parental passcode is the strongest lock in the dataset and it has no parent side at all. It is set up by logging in to the child's account, "Log in to your teen's Pinterest account", so there is no linked parent account, no dashboard and no surface on which a parent could be shown anything; the passcode is bound to the parent's email purely so the teen cannot change it back. The deliberate asymmetry is in the right direction and worth keeping in the parent-facing copy: the code "won't be required when adjusting settings that increase the privacy of your teen's account". The operator half is the fullest public guide of the seven and it goes further than the field's question in one direction and less far in another. Content takes a warrant, "To compel Pinterest to provide any user's content, you must obtain a valid search warrant", and private messaging exists. Beyond message content, "All search terms that a user inputs can be recovered and presented as a list to law enforcement", which is a record most parents would not guess exists. Against that, "Pinterest doesn't necessarily maintain a copy of the image, audio, or video file a user saves", so the image at the centre of a report may live somewhere else entirely. Read the notice policy in finding 78 before advising anyone here.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | Messaging plus recommendation-driven exposure to accounts outside the follow graph. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Pins and messages persist and remain reviewable after the fact. Apple App Store product page (age rating |
| location | 2 | Precise Location linked to identity. Apple App Store product page (age rating |
| ageverify | 2 | Apple discloses Age Assurance, and finding 26 is why that is no longer scored as a real operating gate. Apple defines the flag as a disjunction satisfied by a "declared age range API" read, and the Declared Age Range API's own values include selfDeclared. Nothing has been shown about what this operator actually runs, so this is band 2, a self-attested birthdate with some enforcement, until a vendor check says otherwise. Apple |
| dataharvest | 3 | Tracking spans Contact Info, Location, Identifiers and Purchases; Precise Location and Contacts linked. Apple App Store product page (age rating |
| Documented harm and enforcement | 1 | 65,810 CyberTipline reports in 2024. No enforcement action found. NCMEC |
Caution Threads11 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The parent half is the one worth reading, because Threads is a supervised app and the supervision shows a parent no people at all. Meta's own Threads-specific page enumerates the whole of it, time spent, time limits, sleep mode, tagging and approval over some privacy settings, and nothing in that list is a contact list, a message view or a follower list. This is the Twitch shape rather than the Zangi shape: a real parental surface exists, a parent who opens it sees hours and settings, and the people are not on it. The operator half runs the other way and is as retrievable as the Meta family gets. Meta's law-enforcement guidelines never name Threads, so they are reached through Meta's own bridging statement that "Threads is a service provided by Instagram and is part of the Instagram platform", and Instagram is named throughout them: a search warrant compels "the stored contents of any account". Threads DMs are outside the end-to-end-encryption carve-out, which the guidelines state for Messenger alone.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | A public text feed with public replies and algorithmic recommendation, plus DMs. Read the whole Meta post rather than the sentence everyone quotes: DMs launched 1 Jul 2025 restricted to "followers or mutual followers from Instagram who are ages 18 and older", and the SAME page's 12 Sep 2025 update announces DMs to people you do not follow. Threads' own product account documents the live setting on 13 Nov 2025, with non-follower messages routed to a requests folder, rate-limited, and stripped of photos, videos and links. Band 2, DMs plus public discovery surfaces. Not band 3: no random matching, no geo or nearby matching. Meta newsroom |
| hidden | 0 | No vault, no secret-chat area, no disguised icon. Apple App Store product page (age rating |
| browser | 1 | Links open in an in-app webview. Apple declares no Unrestricted Web Access. Apple App Store product page (age rating |
| Disappearing messages | 0 | Posts and DMs persist; no disappearing-message surface. Apple App Store product page (age rating |
| location | 2 | Precise Location is linked to identity on the App Privacy card. Nothing exposes it to other users: no map, no distance, no nearby matching, so not band 3. Apple App Store product page (age rating |
| ageverify | 2 | Apple discloses Age Assurance, which finding 26 is the reason not to score as an operating gate. Meta's AI age detection is real and documented, and every Meta document retrieved names Instagram, Facebook and Messenger; NONE names Threads. Instagram is band 1 on that evidence and Threads is not the same app, so extending the gate to a product the vendor's own pages do not mention would be finding 22's error in miniature. Band 2 until a vendor read says otherwise, and that read is owed. Apple |
| dataharvest | 3 | Band 3's second limb, and the clearest instance of it in the dataset: Precise Location, Contacts, and Contact Info (Physical Address, Email Address, Name, Phone Number) are ALL linked to identity, under the Third-Party Advertising and Developer's Advertising or Marketing purposes. On the axis's FIRST limb Threads scores 0, because its App Privacy card renders no "Data Used to Track You" section at all. A 0 and a 3 from the same card, and the 0 is the one a mechanical reader would have taken. Apple App Store product page (age rating |
| Documented harm and enforcement | 1 | 3,354 CyberTipline reports in 2024, filed under its own name "Threads" and listed separately from Instagram, Inc.'s 3,320,008. No enforcement action against Threads found. The October 2023 42-state AG suit named Facebook and Instagram; Threads launched in July 2023 and is not named in it, and stretching an AG action onto a product it does not name is exactly what finding 22 punishes. Band 1 follows the Pinterest precedent: a real report volume with no enforcement action found. NCMEC |
Caution Roblox10 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. This does not carry the whole answer: Roblox does show a parent their child's Connections as usernames with block and report on each, so check it; the gap is that Experience Chat is a live in-game feed open to all age-appropriate players, so a child can be spoken to by someone who never becomes a Connection, and the view carries no timestamps even for the people it does show. The second app whose supervision tool shows a named list, and the same argument lands the same way for a different reason. Roblox's parental controls include "Review friends list": "You can view, block, and report your child's Roblox Connections from within parental controls", and "Your child's Connections will be displayed as usernames alongside their avatar", with block and report on each. That is more than TikTok gives and it is genuinely useful, which is why the note says it plainly. It is still not the contact list. Roblox's Experience Chat is a live feed inside a game "visible to all age-appropriate users" in that game, so a child can be spoken to by someone who is not a Connection and never becomes one, and nothing in the Connections view records that it happened or when. Two further limits belong with it: the view carries no timestamps, so the "and when" half of the question is unanswered even for Connections, and parental controls exist for Roblox Kids and Roblox Select accounts with most settings ending at 12 and the rest at 15, so a 16-year-old has none of this. Notably, the same document was read in full for the controls check in the fourth run and the Connections view was not recorded, because nobody had asked the parent question of it: finding 67's shape a third time. The operator half is the vendor's own words in the weaker tier of finding 71, no law-enforcement guide being published: Roblox "may also share the contents of your communications as permitted or required by law" and will disclose "the content of your communications on the Service, to comply with legal process, including court orders and subpoenas". No retention duration is given for message content.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Open chat inside experiences that any account can join. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Chat is logged and filtered. Apple App Store product page (age rating |
| location | 1 | Corrected up from 0 on 2026-08-10 by the screening layer's positive control. The old rationale read "No location collected" and Roblox's own App Privacy card contradicts it: Location, Coarse Location appears under Data Linked to You, under both the advertising and the analytics purpose groupings. Coarse location tied to identity is band 1 by the band's own wording. Not band 2, which requires precise location, and Roblox declares none. Apple App Store product page (age rating |
| ageverify | 1 | Verified against Roblox's own support page: Persona captures a selfie-style video and estimates an age band, placing the user in one of six age groups, and it is required to unlock all chat and trusted friends. Users are re-prompted periodically. A genuine operating mechanism, so band 1 is earned. Note the shape for a parent: it gates CHAT, not entry, so a child who never age-checks keeps a more restricted account. Roblox Support |
| dataharvest | 1 | No Data Used to Track You disclosed. Apple App Store product page (age rating |
| Documented harm and enforcement | 3 | Texas sued Roblox over child safety, joined by suits from Louisiana, Kentucky and Iowa, consolidated into an MDL in December 2025; the DOJ's Greggy's Cult indictment describes victims being recruited on Roblox; 24,522 CyberTipline reports in 2024. Texas AG Paxton sues Roblox over child safety |
Caution Strava: Run, Bike, Walk10 of 24
What you can actually do: Nothing for a parent to set. The protections are on by default, and a parent cannot set them, verify them, or restore them if they change. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. This does not carry the whole answer: Strava shows a parent nothing, and for a teen account it has already removed the thing a parent would be watching for: Strava's own minor-defaults page states that athletes under 18 will not have access to the Messaging feature at all, so on Strava the check is not a dashboard but a one-time question, and it is the condition that makes this worth a sentence rather than reassurance: the defaults attach to accounts created with an under-18 birthdate, Strava runs no age assurance, so a teen who typed an adult birthdate at signup has adult messaging and adult map visibility and no parent surface will ever say so. Strava gives a parent nothing to look at, and for an under-18 account the thing a parent would look FOR has been removed: the same help-centre document that sets the minor defaults states that athletes under 18 will not have access to the Messaging feature at all. That is why the parent half is none without this being the usual bad news. The operator half is the stronger tier, because Strava publishes an actual law-enforcement guide rather than a first-person privacy policy: content shared through the Services including messages is collected, stored, and reachable by legal process whose depth depends on whether a subpoena or a search warrant is served. Read this alongside the location axis rather than on its own; Strava's risk was never the message.
| What we checked | Score | Why |
|---|---|---|
| stranger | 1 | The strongest minor-side contact restriction in the dataset and none of it is visible on the App Store listing. For an account created after 3 Sep 2021 with an under-18 birthdate: profile and activities Followers-only, mentions Followers-only, Flyby "No One", and "Athletes under 18 years old will not have access to the Messaging feature on Strava", named as an exception the athlete cannot change. Apple's Contains section declares Messaging and Chat and that flag is true of the app and false of the child's account. Band 1, contact only with confirmed followers. Strava Help Center |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | Links open in an in-app webview. Apple declares no Unrestricted Web Access. Apple App Store product page (age rating |
| Disappearing messages | 0 | Activity history persists indefinitely and is the product. Apple App Store product page (age rating |
| location | 3 | Band 3 is "location exposed to other users" and a completed route map shown to followers is exactly that, on the same reading that scores Snap Map 3 for sharing with approved friends. A route is arguably worse than a live dot for the purpose a parent cares about, because it reveals a routine rather than a moment. The mitigation is real and is recorded rather than netted off: an under-18 account hides the first and last 400 m of every activity, is excluded from Flyby, Local Legends, Strava Metro and the Global Heatmap. The App Privacy card independently declares Precise Location linked to identity. Strava Help Center |
| ageverify | 2 | Every under-18 protection Strava ships keys off a birthdate the user typed at signup, and nothing in Strava's own documentation describes age estimation or verification of any kind. Band 2, self-attested with some enforcement, where the enforcement is the automatic privacy lockdown rather than a gate at the door. Note the failure mode this creates: a minor who enters an adult birth year gets the ADULT defaults, which includes working messaging and Flyby. Strava Help Center |
| dataharvest | 3 | Band 3 on both limbs, reached by the second: Data Used to Track You lists Purchases and Identifiers, which is band 2 on the count, and Precise Location, Contacts and Contact Info are all linked to identity, which is band 3's conjunction. Apple App Store product page (age rating |
| Documented harm and enforcement | 0 | None found. Strava does not appear in NCMEC's 2024 ESP list, so it filed no CyberTipline reports in 2024, and no US enforcement action or documented child-exploitation case naming Strava was found this run. The well-documented Strava location stories (the 2018 military heatmap, the nearby-athlete exposure reporting) are privacy incidents involving adults and are not scored here. NCMEC 2024 ESP list |
Caution Twitch: Live Streaming10 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The cleanest of the seven, because the vendor answers the parent question in the affirmative and about the wrong noun. Parental Controls, launched 21 July 2026 for linked 13-to-17 accounts, do send a parent a recurring report: they "will be able to understand how and when their teen uses Twitch by receiving a weekly email summarizing their teen's activity, including channels and hours watched". Channels and hours, not people and messages. On the contact vector the control is a switch and not a window: "Teens can be blocked from sending or receiving Whispers (direct messages)", which a parent can turn off but cannot read. So a parent gets a weekly email that looks like supervision and contains nothing about who spoke to their child. The operator half is the privacy notice, the same first-person tier as Roblox: a user provides "the content you create and upload, your chats and communications", and Twitch discloses to "respond to a court order, judicial or other government request, subpoena, or warrant". No duration anywhere, only "for as long as it is required to fulfill the relevant purposes".
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Whispers from any account and open chat in any channel. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | Live streams are ephemeral unless the streamer saves them. Apple App Store product page (age rating |
| location | 0 | No location collected. Apple App Store product page (age rating |
| ageverify | 2 | Apple discloses Age Assurance but no Parental Controls; signup is a self-attested birthdate. The Parental Controls half of that is now known to be wrong, see the vendor-verified note, but the age gate itself is still self-attested so the score stands. Apple App Store product page (age rating |
| dataharvest | 1 | Data Used to Track You: Identifiers only. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | 2,301 CyberTipline reports in 2024, low for the platform's scale. NCMEC |
Caution Hoop - make new friends9 of 24
What you can actually do: Nothing for a parent to set. The protections are on by default, and a parent cannot set them, verify them, or restore them if they change. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: Nobody has checked whether this vendor gives a parent any view of contacts or messages. Treat it as not established, not as absent. Nobody has checked what this operator retains or what legal process reaches. Not established, in either direction.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | Corrected down from 3 on 2026-08-09 against Hoop's own parent guide, which states: "Teenagers aged 13 to 17 do not have access to chat and cannot send or receive messages. Chat is available only to adults aged 18 or older." Adults and minors never see each other, the separation "cannot be changed by users", and teen profiles are private by default. That is not band 3 (default-open, random or geo matching). It is band 2: a public discovery surface a teen can opt into, banded to within a year or two of their own age, with no in-app DMs. Hoop |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 1 | In-app history persists; the conversation it hands off to does not. Apple App Store product page (age rating |
| location | 1 | Country only, self-selected at signup. Hoop states cities, regions and precise location are never collected or shown. Hoop |
| ageverify | 2 | Raised from 1 on 2026-08-09. Apple discloses Age Assurance, but nothing in Hoop's own safety documentation describes age estimation or verification of any kind: it describes a date of birth entered at signup that cannot later be changed, plus removal of accounts reported as underage. That is band 2, self-attested with some enforcement, and the Apple flag is not corroborated by the vendor. Hoop |
| dataharvest | 2 | Corrected up from 1 on 2026-08-10 by the screening layer's positive control. The rationale already listed the evidence that contradicts the number: Identifiers and Usage Data are TWO categories under Data Used to Track You, and band 1 is one category while band 2 is two to three. Replika carries the identical disclosure text and was correctly scored 2, so this was an isolated slip against the band definition rather than a disagreement about the evidence. Apple App Store product page (age rating |
| Documented harm and enforcement | 0 | Corrected 1 to 0 on 2026-08-10 (sixteenth run) as the decision on the 0-versus-1 open item, finding 45. Nothing was found in any direction: Hoop does not appear in NCMEC's 2024 ESP list, so it filed no CyberTipline reports, and no documented case and no enforcement action naming the service were found. Band 1 requires that something exists, and the rationale as written said the opposite, which is band 0's definition. Peek, Valid, Strava and Locket already scored 0 on materially the same evidence, so this makes the axis self-consistent at its bottom end. No tier moves: Hoop is Caution at every band below 3. The band-0 direction warning travels with it (finding 4). NCMEC 2024 ESP list |
Caution Steam Chat9 of 24
What you can actually do: There is something to set. A parent can configure controls that reach the risk driving this score, verified against the vendor.
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The clearest case in the dataset of a real parental control that answers a different question. Steam Families lets an adult RESTRICT store, community and chat access and see playtime reports, and it shows nothing about who a child chatted with or what was said, so the record question and the control question come apart completely. Valve does hold the content: chat is named in its own list of what it collects. A parent's route to a Steam conversation is therefore the child's own logged-in client or legal process, never a supervision dashboard, and the lever that IS available is a switch rather than a window.
| What we checked | Score | Why |
|---|---|---|
| stranger | 3 | Friend requests and group chat invitations from any account. Apple App Store product page (age rating |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | In-app webview only. Apple App Store product page (age rating |
| Disappearing messages | 0 | Chat history persists. Apple App Store product page (age rating |
| location | 0 | No location collected. Apple App Store product page (age rating |
| ageverify | 3 | Apple renders no In-App Controls block and no Contains block on this listing, so a parent sees a bare 13+ and nothing else. An earlier rationale here faulted Valve for omitting a chat flag despite shipping a chat client; that was the finding 2 error surviving its own correction, because this listing has no flags section for any flag to be missing from. Scored 3 on Steam account creation taking a self-attested date of birth, which is the mechanism Steam Families sits on top of. Owed a vendor check on the age gate specifically. Apple |
| dataharvest | 0 | No Data Used to Track You disclosed. Apple App Store product page (age rating |
| Documented harm and enforcement | 2 | The DOJ's Greggy's Cult indictment describes victims being recruited from gaming platforms including Counter-Strike: Global Offensive. Valve filed no CyberTipline reports in 2024. DOJ indictment of the 'Greggy's Cult' network |
Caution Locket Widget8 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. The operator holds message content on its own servers, so a court order or search warrant can reach what was actually said. The Terms require parental approval for under-18s and describe no mechanism by which a parent could give, withhold or exercise it, and the privacy policy describes no supervision feature and no linked-account flow. Both were read in full for the controls axis. The operator half is settled by the privacy policy in the vendor's own words: sending a photo or video means "you provide Locket with the photo or video taken and associated metadata", sending a message means "you provide Locket with the message or reaction sent", and the operator states it reads content when something is reported or detected. Disclosure to law enforcement is promised in the broadest terms in this file, with no process type named. Retention carries no duration. The document's own warning points the other way and belongs in front of a parent for a different reason: once a photo is sent, deleting it "from your own" phone does not remove it from anyone else's.
| What we checked | Score | Why |
|---|---|---|
| stranger | 2 | Contact requires an accepted friend request, which is the gate, and discovery is wide open, which is the exposure. Locket's own help centre lists five routes in: contact-name search, USERNAME search, an invite link it tells users to post "via Instagram, Snapchat, Messages, or other apps", an inbound link, and a Suggestions list. A teen who posts the link publicly, which is the behaviour Locket's own instructions describe, converts a friends-only widget into an open request surface. Band 2, a public discovery surface with an accept step, the same shape scored on Hoop. Locket Help Center |
| hidden | 0 | No vault or disguise feature. Apple App Store product page (age rating |
| browser | 1 | Links open in an in-app webview. Apple declares no Unrestricted Web Access. Apple App Store product page (age rating |
| Disappearing messages | 0 | Sent photos persist in an in-app history; the widget shows the most recent. Apple App Store product page (age rating |
| location | 1 | Coarse Location only under Data Linked to You, with no Precise Location anywhere on the card and nothing exposing location to other users. Apple App Store product page (age rating |
| ageverify | 3 | Pure self-attestation, and the vendor's two documents do not even agree on who the app is for. The Terms (effective 25 May 2022) say "If you are under 13 years of age, you are not authorized to use the Service, with or without registering" and require parental approval under 18; the privacy policy (27 Nov 2023) says the Services "are not directed to children". No verification mechanism is described in either, and the listing renders no In-App Controls subsection, which on a listing that renders the flags block means the developer declared neither control. Locket Labs Inc |
| dataharvest | 1 | Data Used to Track You lists Identifiers only, one category. Band 3's conjunction fails on the first term: the card declares Coarse Location and no Precise Location. Apple App Store product page (age rating |
| Documented harm and enforcement | 0 | None found. Locket Labs, Inc. does not appear in NCMEC's 2024 ESP list, so it filed no CyberTipline reports in 2024, and no enforcement action or documented case was found. NCMEC 2024 ESP list |
Caution Signal - Private Messenger7 of 24
What you can actually do: Nothing for a parent to set. Checked against the vendor's own documentation and there are no parental controls at all. The levers that remain are the install decision itself, the conversation, and device-level limits outside the app (Screen Time, app removal).
If something goes wrong, what record exists: There is no vendor feature that shows a parent who their child has been talking to, or when. Message content is end-to-end encrypted and the operator does not hold it. Account records do exist and legal process can reach those. Signal publishes its own answer and it is the narrowest in the dataset: the only data it can produce is the registration date and the last connection date, and it states it does not have messages, calls, profile information, group information, contacts, stories or call logs. The account is still reached BY a phone number, which is the difference from Zangi and the reason this is metadata_only rather than none.
| What we checked | Score | Why |
|---|---|---|
| stranger | 1 | Contact requires knowing the phone number or username; no discovery surface. Apple App Store product page (age rating |
| hidden | 1 | Disappearing messages; no vault or disguise. Apple App Store product page (age rating |
| browser | 0 | No in-app browser; links open in the device browser where filtering still applies. Apple App Store product page (age rating |
| Disappearing messages | 2 | Disappearing messages are a prominent per-thread setting. Apple App Store product page (age rating |
| location | 0 | No location collected. Apple App Store product page (age rating |
| ageverify | 3 | Rated 13+ with no Age Assurance and no Parental Controls disclosed. Apple App Store product page (age rating |
| dataharvest | 0 | No Data Used to Track You and no data linked to identity, the cleanest privacy card in the seed set. Apple App Store product page (age rating |
| Documented harm and enforcement | 0 | Corrected 1 to 0 on 2026-08-10 (sixteenth run), finding 45, for the same reason as Hoop: nothing was found, and band 1 requires that something exists. Signal does not appear in NCMEC's 2024 ESP list and no platform-specific case set was found. The direction warning is unusually load-bearing here and must be published with the score: Signal holds no message content server-side, so it has nothing to detect and nothing to report, and a zero on this axis is a property of the architecture rather than a finding about the service. Total drops 8 to 7, one point above the Safe threshold, and the tier is unchanged at Caution. NCMEC 2024 ESP list |
How we score
Every app is scored 0 to 3 on eight things, where 0 is best and 3 is worst, and every score carries a link to the document it came from. We use the app's own App Store disclosures, the vendor's own safety and law-enforcement documentation read directly rather than summarised, NCMEC CyberTipline data, and court and regulator records. We do not use parent forums or law firm advertising.
Two rules matter more than the arithmetic. A single severe finding on stranger contact, hidden functionality, or documented harm pushes an app to at least Caution regardless of its total. And where we could not verify something, we say so on the entry rather than scoring it as absent.
Found something wrong?
Tell us and we will re-check it. We would rather correct an entry than defend one. Every score on this page has moved at least once because someone opened the vendor's own documentation and found something the automated check could not see.