Skip to the main content

What we will and won't do for your family

The Cubs Promise

Cubs is a family app for the AI era. The Cubs Promise lays out what the platform generates, how the harness keeps kids safe by construction, and how parents stay in control. It applies to every AI exchange — tutor, solver, assistant, and background cron.

The universal floor

The baseline every learning platform should hold. Cubs blocks these at multiple layers — input filter, model refusal, output filter — and logs every block with a typed category.

§01

Explicit & adult content

Cubs is built for families. The harness will not generate content that is sexually explicit, pornographic, or NSFW — for parents or kids. The kid-context safety layer is stricter and adds an output filter on top.

Examples

  • Pornographic or sexually explicit material
  • Erotic fiction or adult-only narratives
  • Content that sexualizes any individual
  • Explicit descriptions of sexual acts

§02

Violence & harm

We block content that promotes, glorifies, or instructs violence, self-harm, or dangerous activities that could cause physical harm. When a kid signals self-harm, Cubs escalates to the parent (see §12, Crisis escalations) — it does not handle it silently.

Examples

  • Instructions for creating weapons or explosives
  • Content promoting self-harm or suicide
  • Guides for dangerous or life-threatening activities
  • Graphic depictions of violence or torture

§03

Hate speech & discrimination

No content that promotes hatred, discrimination, or prejudice against individuals or groups based on protected characteristics. Refusals are logged with a category so families can see what was blocked and why.

Examples

  • Racist, sexist, or homophobic content
  • Religious intolerance or persecution
  • Ableist content targeting disabilities
  • Xenophobic or nationalist extremism

§04

Illegal activities

Cubs will not produce content that promotes, instructs, or facilitates illegal activity. This applies to background AI calls (cron jobs, summaries) the same as it does to direct chat.

Examples

  • Drug manufacturing or trafficking
  • Hacking for malicious purposes
  • Fraud, scams, or financial crimes
  • Theft, vandalism, or property crimes

§05

Dangerous misinformation

No content that spreads dangerous misinformation, especially around health, safety, or scientific topics. When a kid asks something that touches medical advice, the answer points back to a trusted adult or professional rather than guessing.

Examples

  • False medical advice that could harm health
  • Denial of well-established scientific facts
  • Conspiracy theories that endanger public safety
  • Fake news designed to manipulate or deceive

§06

Child safety

Zero tolerance — absolute and unconditional. Any content that exploits, endangers, or inappropriately involves minors is blocked at multiple layers (input filter, model refusal, output filter, kid-safety incident, parent escalation).

Examples

  • Any sexual content involving minors
  • Content that exploits or endangers children
  • Grooming or predatory behavior
  • Content encouraging harm to children
Cubs AI Harness Standard — kid-safety controls

What Cubs promises beyond the floor

The AI Harness Standard goes further than category-level blocking. These commitments apply to every AI call the platform makes, kid- or parent-facing, foreground or cron.

§07

COPPA, GDPR-K, and verifiable parental consent

Before any AI call runs on behalf of a child, Cubs verifies a current parental consent record. Stale or missing consent returns a 412 with a re-consent prompt for the parent — the call does not proceed. We log every grant and revocation immutably so families can see when consent was given, by whom, and under which version.

Examples

  • Verifiable parental consent before AI use (COPPA §312.5)
  • Separate consent for AI personalization (amended COPPA, effective 2026-04-22)
  • Right to access, rectify, and erase (GDPR Art. 15-17, COPPA §312.6)
  • Default-private kid profiles, no behavioral advertising to children

§08

AI transparency & visible reasoning

Every assistant turn is clearly identified as AI. Cubs streams a brief, age-appropriate summary of its reasoning before the answer — kids see "Cubs is figuring this out…", parents see the full chain-of-thought. Refusals carry a typed category (off-topic, inappropriate-for-age, pii-request, injection-attempt, …) and a confidence score so over-blocking can be tuned per age band.

Examples

  • Every assistant message is labelled and never impersonates a human
  • Chain-of-thought visible (kid-friendly summary or parent-facing detail)
  • Refusal taxonomy logged on every block
  • Idempotent tool calls — repeating the same action returns the cached result, never re-executes
Read the full AI Harness Standard

§09

Parent oversight, audit, and right to delete

Parents can review every AI exchange involving their child. The audit endpoint returns timestamp, skill, model, tokens, cost, refusal category, and feedback. CSV export is one click. A delete request cascades across messages, threads, AI calls, conversation log, and the solution cache, and the deletion itself is logged for the family's records.

Examples

  • View every AI call: model, latency, tokens, cost, refusal type
  • Export full history as CSV (COPPA right of access)
  • One-click cascade delete across all AI tables (right to erasure)
  • Daily retention cron honors per-family TTLs

§10

Healthy use & screen-time guardrails

Cubs is not designed to maximize engagement. Parents set per-child session-time limits and a module allowlist (which areas of the app a child can use); both are enforced at the request boundary. When a child reaches their limit, Cubs ends the session politely — no streaks-pressure, no infinite scroll, no addictive-by-design patterns.

Examples

  • Session-time-limit middleware on every kid-callable AI route
  • Module allowlist enforced at the route boundary
  • No dark-pattern engagement loops; parent-tunable per child
  • Quiet-hours-respecting parent notifications

§11

Educational integrity — teach, don't solve

Cubs helps kids learn, not cheat. The tutor flow defaults to hints; "Show Me" walks through a worked example; direct answers come last. Solver-style requests on homework problems route to teaching prompts. We index learning attempts (right and wrong) so the experience adapts to where each child actually is.

Examples

  • Hint mode first, then bigger hint, then walked example
  • Off-topic input mid-quiz silently refocuses without scolding
  • Repeated misses surface to the parent without shaming the kid
  • Solver answers caches deterministic problems — but always shows the steps

§12

Crisis & safety escalations

If a child signals self-harm, abuse, or an unsafe situation, Cubs does not respond with a generic refusal. The call short-circuits to a kid-safety incident, the parent gets an in-app alert, and a follow-up todo lands in the parent's "Today" view. Cubs also blocks messages its safety classifier confirms are grooming, sexual content, self-harm coaching, or a credible threat — each of those creates a "Needs You" card you can see, and grooming or self-harm coaching, or two blocks for the same child inside a day, also sends an in-app alert. A question Cubs judges safe and answers — curiosity about weapons, drugs, death, growing up, or violence in games — is never blocked and never raises an alarm; it appears in a weekly "Topics Cubs talked about" summary instead, and you can opt in to a same-day heads-up in Settings → Privacy & data. Separately from anything Cubs notices, your child can tap "Tell a grown-up" inside the chat dock at any time. That one is the child's own decision, not a classifier verdict: it creates a "Needs You" card and an in-app alert to every parent and admin in your family, it links to the conversation, and — unlike every other pathway on this page — it shows you the child's own words, because they wrote them for you, under an on-screen statement of who would see them. It does not lock your child out of their chat. A crisis hotline is always offered above that button, for the case where telling the family is not the right answer. "Alert" means an in-app notification and a card in your inbox: push and email delivery are not built yet, so in-app is the only channel today, regardless of quiet hours. Cubs is never the only safety layer — it escalates to a real grown-up.

Examples

  • Self-harm signals → kid_safety_incident + in-app parent notification
  • Confirmed grooming / self-harm coaching block → Needs You card + in-app alert
  • Two confirmed blocks for one child in 24h → in-app alert
  • Child taps "Tell a grown-up" → Needs You card carrying their own note + urgent in-app alert to every parent/admin
  • A crisis hotline is always shown above that button — telling the family is never the only option
  • Allowed but sensitive topic → weekly summary, no alarm (opt in for same-day)
  • Repeated off-topic drift → flagged for parent review
  • Compliance violation (e.g. provider not ZDR) → AI call refused
  • Severe triggers bypass quiet hours
  • Push and email delivery for any of the above: not built yet

§13

Communication, calendar, and family data handling

Cubs reads the school inboxes and calendars you connect, but redacts child names to token IDs before any prompt leaves the family scope. Outputs are scanned for re-identified PII. The harness will not share your schedule, message contents, or child profile with another family without an explicit, in-app consent flow.

Examples

  • Child names → opaque token IDs before egress
  • Output scanned for re-identified PII before render and persistence
  • School-imported records carry a FERPA tag — refuse non-ZDR providers
  • Family-to-family connections require explicit consent on both sides

§14

No model training on your family's data

Every AI provider Cubs uses must be in zero-data-retention mode for kid-context calls. The harness checks the resolved model against a registry on every dispatch and refuses if the posture is unconfirmed. The model providers we route to are Anthropic (Claude) and Microsoft Azure OpenAI (GPT family); Google Gemini is available only to families who bring their own API key. The full list of every third party that may process family data — including hosting, database, and billing vendors — is detailed in our Privacy Policy.

Examples

  • Anthropic — zero data retention confirmed for Cubs traffic
  • Microsoft Azure OpenAI — no-training opt-out flag enforced per deployment
  • Google Gemini — opt-in only, families bring their own API key
  • New models are gated behind a CI check that blocks merge until the provider posture is confirmed

§15

What happens when content is blocked

When a request crosses the line, Cubs tells you which part of the Promise was triggered and links directly to the section above. The goal is not to restrict learning — it's to make sure the platform is used responsibly.

Instead of asking

“How do I make explosives?”

Try

“The chemistry of controlled demolition in engineering.”

If you believe your request was blocked in error, rephrase to focus on the educational angle, or use the in-app feedback button on any assistant message — every refusal is logged with a category and a confidence score, and your feedback feeds the eval pipeline.

§16

Reporting & appeals

Three paths, depending on what you want to do:

  1. Flag a specific message

    Tap the thumbs-down on any assistant message and pick a category (inaccurate, not helpful, felt unsafe, off-topic). The signal is persisted on the message and rolled into our eval pipeline next to the synthetic eval set.

  2. Appeal a block

    Refusal pills surface a Details disclosure with the underlying reason. If you believe a block was over-cautious, rephrase or use the feedback chip — refusal-confidence tuning is one of the inputs we look at per age band.

  3. Report a serious safety concern

    Email support@cubsfamily.app with the family ID (Settings → About) and we will respond within two business days. For child-safety incidents, the harness has already escalated to the parent in-app — this channel is for things the in-app pipeline missed.

The Cubs Promise is reviewed quarterly. Material changes are announced 30 days in advance via in-app notice and email.

Last updated 2026-05-05. The Cubs AI Harness Standard governs every AI call the platform makes — 16 non-negotiable rules spanning pre-flight checks, authorization gates, budget caps, safety filters, transparency, and observability.