Cubs is a family app for the AI era. The Cubs Promise lays out what the platform generates, how the harness keeps kids safe by construction, and how parents stay in control. It applies to every AI exchange — tutor, solver, assistant, and background cron.
The baseline every learning platform should hold. Cubs blocks these at multiple layers — input filter, model refusal, output filter — and logs every block with a typed category.
§01
Explicit & adult content
Cubs is built for families. The harness will not generate content that is sexually explicit, pornographic, or NSFW — for parents or kids. The kid-context safety layer is stricter and adds an output filter on top.
Examples
Pornographic or sexually explicit material
Erotic fiction or adult-only narratives
Content that sexualizes any individual
Explicit descriptions of sexual acts
§02
Violence & harm
We block content that promotes, glorifies, or instructs violence, self-harm, or dangerous activities that could cause physical harm. When a kid signals self-harm, Cubs escalates to the parent (see §12, Crisis escalations) — it does not handle it silently.
Examples
Instructions for creating weapons or explosives
Content promoting self-harm or suicide
Guides for dangerous or life-threatening activities
Graphic depictions of violence or torture
§03
Hate speech & discrimination
No content that promotes hatred, discrimination, or prejudice against individuals or groups based on protected characteristics. Refusals are logged with a category so families can see what was blocked and why.
Examples
Racist, sexist, or homophobic content
Religious intolerance or persecution
Ableist content targeting disabilities
Xenophobic or nationalist extremism
§04
Illegal activities
Cubs will not produce content that promotes, instructs, or facilitates illegal activity. This applies to background AI calls (cron jobs, summaries) the same as it does to direct chat.
Examples
Drug manufacturing or trafficking
Hacking for malicious purposes
Fraud, scams, or financial crimes
Theft, vandalism, or property crimes
§05
Dangerous misinformation
No content that spreads dangerous misinformation, especially around health, safety, or scientific topics. When a kid asks something that touches medical advice, the answer points back to a trusted adult or professional rather than guessing.
Examples
False medical advice that could harm health
Denial of well-established scientific facts
Conspiracy theories that endanger public safety
Fake news designed to manipulate or deceive
§06
Child safety
Zero tolerance — absolute and unconditional. Any content that exploits, endangers, or inappropriately involves minors is blocked at multiple layers (input filter, model refusal, output filter, kid-safety incident, parent escalation).
The AI Harness Standard goes further than category-level blocking. These commitments apply to every AI call the platform makes, kid- or parent-facing, foreground or cron.
§07
COPPA, GDPR-K, and verifiable parental consent
Before any AI call runs on behalf of a child, Cubs verifies a current parental consent record. Stale or missing consent returns a 412 with a re-consent prompt for the parent — the call does not proceed. We log every grant and revocation immutably so families can see when consent was given, by whom, and under which version.
Examples
Verifiable parental consent before AI use (COPPA §312.5)
Separate consent for AI personalization (amended COPPA, effective 2026-04-22)
Right to access, rectify, and erase (GDPR Art. 15-17, COPPA §312.6)
Default-private kid profiles, no behavioral advertising to children
§08
AI transparency & visible reasoning
Every assistant turn is clearly identified as AI. Cubs streams a brief, age-appropriate summary of its reasoning before the answer — kids see "Cubs is figuring this out…", parents see the full chain-of-thought. Refusals carry a typed category (off-topic, inappropriate-for-age, pii-request, injection-attempt, …) and a confidence score so over-blocking can be tuned per age band.
Examples
Every assistant message is labelled and never impersonates a human
Chain-of-thought visible (kid-friendly summary or parent-facing detail)
Refusal taxonomy logged on every block
Idempotent tool calls — repeating the same action returns the cached result, never re-executes
Parents can review every AI exchange involving their child. The audit endpoint returns timestamp, skill, model, tokens, cost, refusal category, and feedback. CSV export is one click. A delete request cascades across messages, threads, AI calls, conversation log, and the solution cache, and the deletion itself is logged for the family's records.
Examples
View every AI call: model, latency, tokens, cost, refusal type
Export full history as CSV (COPPA right of access)
One-click cascade delete across all AI tables (right to erasure)
Daily retention cron honors per-family TTLs
§10
Healthy use & screen-time guardrails
Cubs is not designed to maximize engagement. Parents set per-child session-time limits and a module allowlist (which areas of the app a child can use); both are enforced at the request boundary. When a child reaches their limit, Cubs ends the session politely — no streaks-pressure, no infinite scroll, no addictive-by-design patterns.
Examples
Session-time-limit middleware on every kid-callable AI route
Module allowlist enforced at the route boundary
No dark-pattern engagement loops; parent-tunable per child
Quiet-hours-respecting parent notifications
§11
Educational integrity — teach, don't solve
Cubs helps kids learn, not cheat. The tutor flow defaults to hints; "Show Me" walks through a worked example; direct answers come last. Solver-style requests on homework problems route to teaching prompts. We index learning attempts (right and wrong) so the experience adapts to where each child actually is.
Examples
Hint mode first, then bigger hint, then walked example
Off-topic input mid-quiz silently refocuses without scolding
Repeated misses surface to the parent without shaming the kid
Solver answers caches deterministic problems — but always shows the steps
§12
Crisis & safety escalations
If a child signals self-harm, abuse, or an unsafe situation, Cubs does not respond with a generic refusal. The call short-circuits to a kid-safety incident, the parent gets an in-app alert, and a follow-up todo lands in the parent's "Today" view. Cubs also blocks messages its safety classifier confirms are grooming, sexual content, self-harm coaching, or a credible threat — each of those creates a "Needs You" card you can see, and grooming or self-harm coaching, or two blocks for the same child inside a day, also sends an in-app alert. A question Cubs judges safe and answers — curiosity about weapons, drugs, death, growing up, or violence in games — is never blocked and never raises an alarm; it appears in a weekly "Topics Cubs talked about" summary instead, and you can opt in to a same-day heads-up in Settings → Privacy & data. Separately from anything Cubs notices, your child can tap "Tell a grown-up" inside the chat dock at any time. That one is the child's own decision, not a classifier verdict: it creates a "Needs You" card and an in-app alert to every parent and admin in your family, it links to the conversation, and — unlike every other pathway on this page — it shows you the child's own words, because they wrote them for you, under an on-screen statement of who would see them. It does not lock your child out of their chat. A crisis hotline is always offered above that button, for the case where telling the family is not the right answer. "Alert" means an in-app notification and a card in your inbox: push and email delivery are not built yet, so in-app is the only channel today, regardless of quiet hours. Cubs is never the only safety layer — it escalates to a real grown-up.
Two confirmed blocks for one child in 24h → in-app alert
Child taps "Tell a grown-up" → Needs You card carrying their own note + urgent in-app alert to every parent/admin
A crisis hotline is always shown above that button — telling the family is never the only option
Allowed but sensitive topic → weekly summary, no alarm (opt in for same-day)
Repeated off-topic drift → flagged for parent review
Compliance violation (e.g. provider not ZDR) → AI call refused
Severe triggers bypass quiet hours
Push and email delivery for any of the above: not built yet
§13
Communication, calendar, and family data handling
Cubs reads the school inboxes and calendars you connect, but redacts child names to token IDs before any prompt leaves the family scope. Outputs are scanned for re-identified PII. The harness will not share your schedule, message contents, or child profile with another family without an explicit, in-app consent flow.
Examples
Child names → opaque token IDs before egress
Output scanned for re-identified PII before render and persistence
School-imported records carry a FERPA tag — refuse non-ZDR providers
Family-to-family connections require explicit consent on both sides
§14
No model training on your family's data
Every AI provider Cubs uses must be in zero-data-retention mode for kid-context calls. The harness checks the resolved model against a registry on every dispatch and refuses if the posture is unconfirmed. The model providers we route to are Anthropic (Claude) and Microsoft Azure OpenAI (GPT family); Google Gemini is available only to families who bring their own API key. The full list of every third party that may process family data — including hosting, database, and billing vendors — is detailed in our Privacy Policy.
Examples
Anthropic — zero data retention confirmed for Cubs traffic
Microsoft Azure OpenAI — no-training opt-out flag enforced per deployment
Google Gemini — opt-in only, families bring their own API key
New models are gated behind a CI check that blocks merge until the provider posture is confirmed
§15
What happens when content is blocked
When a request crosses the line, Cubs tells you which part of the Promise was triggered and links directly to the section above. The goal is not to restrict learning — it's to make sure the platform is used responsibly.
Instead of asking
“How do I make explosives?”
Try
“The chemistry of controlled demolition in engineering.”
If you believe your request was blocked in error, rephrase to focus on the educational angle, or use the in-app feedback button on any assistant message — every refusal is logged with a category and a confidence score, and your feedback feeds the eval pipeline.
§16
Reporting & appeals
Three paths, depending on what you want to do:
Flag a specific message
Tap the thumbs-down on any assistant message and pick a category (inaccurate, not helpful, felt unsafe, off-topic). The signal is persisted on the message and rolled into our eval pipeline next to the synthetic eval set.
Appeal a block
Refusal pills surface a Details disclosure with the underlying reason. If you believe a block was over-cautious, rephrase or use the feedback chip — refusal-confidence tuning is one of the inputs we look at per age band.
Report a serious safety concern
Email support@cubsfamily.app with the family ID (Settings → About) and we will respond within two business days. For child-safety incidents, the harness has already escalated to the parent in-app — this channel is for things the in-app pipeline missed.
The Cubs Promise is reviewed quarterly. Material changes are announced 30 days in advance via in-app notice and email.
Last updated 2026-05-05. The Cubs AI Harness Standard governs every AI call the platform makes — 16 non-negotiable rules spanning pre-flight checks, authorization gates, budget caps, safety filters, transparency, and observability.
Made with Cubshttps://cubs-family.vercel.app/promise