Parental Consent
Last updated: 1 June 2026
This is the consent text shown to parents during signup. It must be actively accepted (e.g., an unchecked checkbox that the parent ticks) before an account is created. Email-only confirmation is not sufficient for COPPA-covered users.
On-screen consent text (short form)
I confirm that:
- I am at least 18 years old.
- I am the parent or legal guardian of any child whose information I add to this App.
- I have read the Privacy Policy, the Terms of Service, and the Children's Privacy Notice.
- I consent, on behalf of myself and my child, to the collection and processing of personal information as described in those documents.
- I understand that I can withdraw my consent and delete the account at any time from Settings → Account.
☐ I agree (must be ticked to continue)
The "I agree" checkbox must be unchecked by default. Tapping "Create Account" without it should fail with a clear error.
What we record at signup (consent log)
For every signup we permanently store:
- The exact text shown (versioned)
- The version number of each policy in effect
- Timestamp (UTC)
- IP address
- Device and OS version
- The parent's email address (already in the account record)
This log is the legal record proving informed consent was given. Never delete it for the duration of the account plus the legally required retention period.
When renewed consent is required
You must re-prompt for consent and block further app use until the parent re-accepts when:
- The Privacy Policy or Children's Privacy Notice changes in a material way (e.g., a new sub-processor, a new category of data collected, a change in data use)
- A new feature processes a new category of child data
- The child crosses an age threshold that changes legal requirements (e.g., turns 13 in the US)
- The parent changes the linked child or adds a new child
Material change = anything that would affect a reasonable parent's decision to consent. When in doubt, re-prompt.
COPPA-specific verifiable parental consent
If you target children under 13 in the United States, simple checkbox consent is not enough. You must use one of the FTC-approved methods:
- Credit-card or debit-card verification — a small charge (often $0.50) immediately refunded
- Government-issued ID — checked and then deleted
- Signed consent form — emailed, scanned, or e-signed back
- Video conference — short call with the parent
- Knowledge-based authentication — questions only the parent would know
Recommended approach: avoid US under-13 users entirely until you are certified under an FTC-approved Safe Harbor program. This means either:
- Geo-blocking US users
- Setting a minimum child age of 13 in the US
- Working with a Safe Harbor program (e.g., kidSAFE, iKeepSafe, ESRB Privacy Certified)
GDPR-K specific (EU/UK)
The age below which parental consent is required varies by member state (13–16). Default to 16 unless you have legal advice for each market. Use the same consent flow above; the consent log must include the legal basis (Article 6(1)(a) consent + Article 8 parental authorization).
Hebrew translation
The Hebrew version of the on-screen consent text must convey identical legal meaning. Use a professional legal translator. Do not auto-translate.
Changes to this document
When the on-screen consent text or the consent log fields change, increment the version number, update the Last updated date, and re-prompt all existing users on next login.