Store Compliance

Families Policy Compliance

Apple & Google Families / Children's Policy — implementation audit

6/6

Policy Areas Implemented

All 6 core Families Policy requirements are built into the app. Review the action items below for submission-readiness steps.

Child Account Controls
Implemented
  • Children (ages 6–13) are identified as 'child' role — access is parent-configured
  • Athletes (ages 14+) identified as 'athlete' role with appropriate permissions
  • Parent must explicitly enable app access for each child (app_access_enabled flag)
  • Granular per-feature permissions: teams, calendar, messaging, marketplace, etc.
  • Messaging restricted to parent-only by default for child accounts
Parental Consent (COPPA)
Implemented
  • COPPA consent gate enforced before child account is created
  • Parental consent stored on Child entity (app_access_consent_given)
  • Parent email verification required before granting child app access
  • sendCoppaConsentEmail function sends verifiable consent confirmation
  • Parents can revoke access at any time from their dashboard
Parental Monitoring & Controls
Implemented
  • Parent Monitor Mode available — parents can view child's activity
  • Child content visibility guard wraps sensitive content
  • Analytics events blocked/logged for child accounts (logAnalyticsBlock)
  • ParentMonitorMode component provides real-time oversight
  • Child profiles show parent name, email, and phone for accountability
Data Collection Restrictions
Implemented
  • No behavioral advertising or third-party ad SDKs integrated
  • No analytics tracking for child accounts (blocked by AnalyticsBlocklist)
  • Minimal data collection: only name, age, sport, and emergency contact
  • No social media sharing features available to child-labeled accounts
  • Profile images optional — not required for child accounts
Content Safety
Implemented
  • AI-powered chat content filtering (filterChatContent function)
  • Content report system with urgency auto-flagging for minors
  • Messaging child guard prevents unsolicited contacts
  • Background check status tracked for trainers who work with children
  • Community posts/media reviewed before visible to child accounts
Transparency & Deletion
Implemented
  • Privacy Policy discloses all child data collection and usage
  • Full account deletion flow available in-app and at /DeleteAccount
  • Child data deletion handled via ChildDataDeletionDialog
  • Data retention policy: deletion completed within 30 days
  • Sign in with Apple token revocation on account deletion
Pre-Submission Action Items
high

Ensure your App Store listing specifies the age rating correctly (4+ or 9+ with parental guidance notes)

high

Submit the Google Play Data Safety form — use the DataSafetySummary page for pre-filled answers

high

Add your Privacy Policy URL (must be a live public URL) to both store listings

medium

Apple: If your app targets children as the primary audience, it must comply with the Children's category — no third-party analytics SDKs allowed

medium

Confirm the age gate (ImprovedAgeGate) is shown before any account creation flow

low

Consider adding a dedicated 'Parent's Guide' page or help center article explaining all parental controls

YPP Logo

Youth Portal & Programs