Families & teens
How Savor protects teenagers
Savor is for people 13 and older. This page documents the guardrails we enforce for everyone and the additional controls we can apply when Apple or Google Play supplies a 13–17 range.
The short version
Our approach is data-minimizing and enforcement-based: rely on the stores where they require an age check, collect no birth date, and apply a teen-safe AI path when a 13–17 range is available.
- Known under 13: a store-reported range stops before sign-in or online features.
- Known ages 13–17: the app retains a broad band—not a birth date—and applies additional AI output safeguards.
- No range shared: Savor saves no age band and applies its universal privacy, reporting, and sharing safeguards.
- Age 18+: the same privacy, sharing, advertising, and deletion controls still apply.
Store-led age assurance, where required
On a fresh install, Savor consults the platform's age service. Apple's age-range sheet appears only where Apple identifies a legally required check; Google Play supplies signals in the regions and accounts where its service applies.
Savor uses Apple's Declared Age Range or Google Play's Age Signals service. Savor never asks for a birth date or shows its own age question.
- 1The store decides whether a check is required.
A required verification or parental step cannot fall through to a Savor question or be bypassed inside the app.
- 2A shared range is intentionally broad.
Apple or Google Play can report under 13, 13–17, or 18+ without Savor receiving a birth date or identity document.
- 3Store metadata stays out of Savor.
Install identifiers, declaration methods, approval dates, and parental-control details are not written to Savor storage, analytics, logs, crash reports, support tools, API requests, or account records.
- 4A store-reported under-13 range stops access.
The under-13 band is not a valid server value, and Savor has no parent-managed under-13 account path.
- 5Eligible accounts keep only minimal proof.
When a range is shared, the device and account may retain
13_17or18_plus, the assessment time, and the policy version. Teen records expire after 365 days and require another store check. - 6No requirement and no range means no saved age.
Savor opens without inferring that the person is an adult. Universal safeguards still apply, but age-specific controls cannot activate without a known band.
Teen AI output is checked before display
OpenAI's moderation endpoint checks Take action input separately from the model that writes the answer. That input check applies to every account and does not change when Savor uses Claude Sonnet 5.5 for the response.
For Take action, the authenticated Savor API reads the account's age-assurance record. A current 13–17 record selects the teen-safety route. A failed account-profile read, or a malformed or stale age record, also selects that safer route instead of silently weakening the protection.
The API marks the request for minor-safety handling.
Partial model-written stages are not streamed onto the teen's screen.
OpenAI's moderation endpoint checks the complete Sonnet answer, including lookups and research.
A flagged result is blocked. If screening is unavailable or cannot be verified, the answer is withheld and the app receives an error instead.
OpenAI receives the finished Sonnet text and a stable, pseudonymous safety identifier created with a keyed one-way hash. Savor does not send the raw account ID for that purpose. This safety layer is enforced in the service path; it is not merely an instruction asking the model to behave.
A generated answer can be reported
Every visible Take action answer has a Report this answercontrol. The person selects one of six fixed reasons: dangerous or violent, sexual content, self-harm concern, hateful or harassing, incorrect or misleading, or another problem. There is no free-text box that could invite a teenager to disclose more personal information.
The client builds the evidence only from the model-written answer visible on the screen, capped at 4,000 characters. It leaves out the person's prompt, card, answers, history, and surrounding context. The authenticated API rejects unexpected fields, prevents duplicate submissions, and rate-limits the route.
Savor Support receives the answer, fixed reason, and the minimum account, intention, surface, and timing information needed to review it. Dangerous, sexual, and self-harm concerns enter the queue as high priority. The target is review by the next business day, not live or 24/7 monitoring. Evidence is not copied into application logs or sent to an AI provider. Reports expire after 90 days and account deletion removes them sooner, unless counsel approves a legal hold. If the request cannot be sent, no background report is queued on the phone—the panel stays available for a manual retry. This is not an emergency service.
Technical control map
This is the practical difference between a written safety promise and a guardrail in the product: each control below has an enforcement point and a defined failure behavior.
| Control | Where enforced | Failure behavior |
|---|---|---|
| 13+ minimum | Store listing and Terms, plus required platform age checks | A store-reported under-13 range cannot continue; no under-13 band is accepted by the server |
| Age-data minimization | Native store bridge | No exact age, birth date, store install ID, declaration method, or parental-control detail is persisted or transmitted |
| Teen recheck | Local age-record validation | A known 13–17 record older than 365 days is invalid and the store is consulted again |
| Teen AI routing | Authenticated API account lookup | Unreadable, stale, or malformed age state takes the teen-safe route |
| No early AI reveal | Model-response buffering | No model-written partial stages are shown before screening completes |
| Output screening | Provider result plus Savor API verification | Flagged, missing, or unverifiable screening means no answer is released |
| Provider identifier | Server-side keyed hashing | The raw Savor account ID is not used as the provider safety identifier |
| Generated-answer reporting | Authenticated, rate-limited Savor API and private human-review queue | The displayed answer is the only content evidence; the fixed reason and minimum review metadata accompany it, unexpected fields are rejected, operational alerts contain no answer text, and a failed connection stays available for manual retry |
Private and low-pressure by design
No public performance layer
No public profile, follower count, feed, leaderboard, or streak. Savor is not built to turn everyday life into a public score.
Private content stays out of ads
Advertising measurement starts off and is unavailable for a current 13–17 band. Savor never sends Meta the content of cards, voice recordings, photos, or scans. Product analytics are pseudonymous and content-free.
Sharing has boundaries
Sharing is deliberate and invitation-only. There is no public directory, a card is limited to 12 participants, photos do not travel with it, and blocking is silent and absolute.
Deletion is available in the app
Settings → Account → Delete Account removes the account and the data Savor keeps for it. A deletion request can also be made by email.
Why this is personal to us
Our teenage son has ADHD, and he has genuinely enjoyed using Savor to help him throughout his day: putting a thought somewhere safe, seeing the next step, and spending less energy trying to hold everything in mind.
His experience is part of why we care about calm language, low-pressure design, clear choices, and privacy that does not depend on reading fine print. This is our family's experience, not evidence of a clinical outcome.
Limits, accountability, and what Savor is not
- Stores do not share an age range for every person. If the store reports no legal requirement and shares no range, Savor asks no age question and keeps no age band. Universal safeguards still apply, but Savor cannot activate age-specific controls or prevent every under-13 person from misrepresenting eligibility.
- No automated safeguard is perfect. Output screening reduces risk; it does not make every AI answer correct, suitable, or harmless.
- Savor is not a monitoring service. We do not provide live human review of every private card or conversation.
- Savor is not for children under 13. We do not offer parent-managed accounts or a consent path for under-13 use.
- 13+ is not a universal consent rule. We use store age signals, parental controls, disclosures, and country availability first. If a mandatory local exception cannot be enforced by the stores, teen availability or the affected feature may be restricted there.
- Savor is not medical care. It does not diagnose or treat ADHD or another condition, and it is not an emergency or crisis service.
- Sharing creates another copy. A card shared with another person can remain with that recipient after the original account is deleted.
Read the full children and teens privacy disclosure, or email support@savorapp.ai with a safety or privacy question.
