State of the App

What GuardNIL University is, in plain words.

This is the whole app on one page. We wrote it so a parent can read it, and so it only describes what a launching family actually uses. If you only read one page, read this one.

What the app is

GuardNIL University helps a family turn a promise into a real agreement. A parent picks what their child will work on. The parent picks how much money backs it. When the work is done, the parent approves the payment, and the money moves into a savings balance we call the e-wallet.

That is the whole idea. A child does chores, studies, serves their community, and gets better at their sport. A parent already pays for some of that. We give the family one place to write it down, one place to track it, and one place to move the money.

What we are not

We are not a bank. We do not hold your money. A licensed payment company called Stripe holds it. Your balance is not insured by the government the way a bank account is.

We are not a place where companies pay kids. Nobody outside your family sends your child money here.

Your child has no account

This is the most important thing on the page, so we will say it first and say it plainly.

  • Your child never gets a password. There is no login for them to use.
  • Your child never types anything into the app. Every word about your child is typed by you.
  • We never ask your child a question. No surveys, no quizzes, no profile for them to fill in.

We built it this way on purpose, and it is the single decision that makes the rest of this document short. Most of the hard questions a school district asks about an app are questions about a child's account: how it is kept safe, who can reach the child through it, what the child might type into it. One adult account per family answers all of them the same way. There is no child account for any of that to happen in.

That is why a league or a district can adopt this without a review of how we handle a child's own data. There is none to handle.

There is a second layer underneath

We built a full set of children's privacy protections, and all of it still works: the permission flow, the age-range tool, the per-company consent records, and the erase pipeline.

What we are launching does not lean on any of it, because we never collect the thing it protects. That is two layers of safety instead of one. The machinery is described on the privacy page, because a reviewer will want to see it whether or not we depend on it.

What a parent does, start to finish

  1. 1

    Make an account with your email and a password.

    One grown-up sets it up. You pick a password of at least eight characters. You can add a second parent later, and that second parent can look but cannot move money.
  2. 2

    Tell us your birthday and where you live.

    We ask for your state because some states have extra rules for families. You pick your city from a list instead of typing it, so the state is always right.
  3. 3

    Say whether anyone on the account is under 13.

    If yes, we walk you through an extra permission step first. The law calls that step verifiable parental consent. It is explained on the privacy page.
  4. 4

    Build the family agreement.

    You pick the five things your child will work on, how much money backs the agreement, and how often it pays. You do this in a step-by-step form.
  5. 5

    Add your child by name.

    You type your child's name. Your child does not do this and never sees this screen.
  6. 6

    Link your bank, or skip it for now.

    You link your bank through Stripe. We never see or store your bank login or your account number. You can skip this step and come back to it.
  7. 7

    Watch the countdown and the balance.

    Your dashboard shows how long until the next payment and how much is in the e-wallet. Those are the two numbers families actually check.
  8. 8

    Approve the payment when the work is done.

    You press approve. Then our server checks everything again on its own before a single dollar moves. Pressing the button is not what makes it happen.

What we hold about you and your child

Here is the full list. If something is not on this list, we do not have it.

  • What
    Your name and email
    Whose
    The parent
    Why we have it
    So you can sign in and so we can email you.
  • What
    Your birthday
    Whose
    The parent
    Why we have it
    To confirm the account holder is an adult.
  • What
    Your city and state
    Whose
    The parent
    Why we have it
    Some states have extra rules for families. We follow the rules of your state.
  • What
    Your child's name
    Whose
    The child
    Why we have it
    So the app can say who the agreement is for. You type it, not them.
  • What
    Your child's birthday
    Whose
    The child
    Why we have it
    You type it during setup. We say plainly on the agreement page that we keep more of this than we want to, and what we are doing about it.
  • What
    The family agreement
    Whose
    The household
    Why we have it
    What your child is working on and how much money backs it.
  • What
    Progress on the agreement
    Whose
    The household
    Why we have it
    Which parts are done, so we know when a payment can go through.
  • What
    Your e-wallet balance and payment history
    Whose
    The household
    Why we have it
    So you can see the money.
  • What
    A yes-or-no flag that says your bank is linked
    Whose
    The parent
    Why we have it
    Stripe holds the real bank details. We hold the last four digits, the bank name, and whether it is verified.

What we are honest about

A review is worth more when we tell you the gaps instead of letting you find them. Four things we want you to know up front.

  • One feature uses AI, and you always decide. The encouragement screen writes a short note for your own child. You read it and you send it. It never reaches your child on its own.
  • Finishing one pillar does not release part of the money. Every part of the agreement has to be done before the payment can be approved. It is all or nothing, not a slice at a time.
  • Our safety tests found five real problems. We wrote thirteen tests that try to break into data they should not reach. Until 9 August only one of them was a real check and the rest could not fail. They now sign in as real people and run against the live database. The first honest run found five problems, one of them serious, and all five are closed. Every one is written out on the compliance page, including the fix that ran without error and changed nothing.
  • No outside lawyer has signed off yet. Our founder signed off. A children's privacy certification is written up and ready but has not been submitted.

Every section of this document

Each page below answers the same five questions in the same order: what it does, how it works step by step, what data it touches, what a parent sees, and what happens if something goes wrong. Each page has its own web address, so you can be sent straight to one part.

A note on the words we chose

We wrote these pages for a fifth-grade reading level on purpose. A school board should not need a lawyer to understand what our app does with a child's name.

Where a technical name matters, we put it in a box like row-level security right after the plain-word version, so an engineer can search our code for it. Simple words, exact facts.