Child safety standards

Who this app is for, and why this page exists

ShotDetect is a research prototype, used by students of school age and by their guardians. A student's phone is not protected until a guardian has connected to it and accepted the terms.

That gate is enforced. A phone will not arm unless a guardian has accepted on it — arm() requires the guardian's acceptance, so a student tapping through the disclaimer alone cannot open the microphone. This page said the opposite until 2026-08-18, describing a gap that had already been closed; the app cannot check who is tapping, which is a different and unavoidable limitation, and it says so on the screen that asks.

Three things a parent should know before reading further, because they change what this app is. It can now warn you when you are not at the school — that changed in August 2026, and this page previously said the opposite. A corroborated alert is encrypted on your child's phone and forwarded to the guardian they paired with, wherever you are. Nobody has yet measured how reliably that arrives between two real phones in different places.

And it now shares your child's live position with you, and yours with them. That is section 02a, and it is the change on this page that most deserves a parent's attention: until August 2026 a position left a child's phone only during an alert, and this page and our privacy policy said so. It now leaves about every five seconds for as long as the app is open on the phone. It goes to the people that phone paired with in person and to nobody else, it goes in both directions, and closing the app stops it.

And it is wrong more often than it is right. Shown at the school it produces roughly 30 false alerts per school year against a design target of one. Sent to a guardian who is not there it is deliberately much quieter — about one a year — which it achieves by never forwarding about two in every five of the detections it would show at the school. Silence is not evidence that your child is safe. The early access page sets out the numbers.

Google Play's formal Child Safety Standards policy applies to apps in the Social and Dating categories, and ShotDetect is neither. We publish this page anyway, because a parent deciding whether to put a listening app on a child's phone should not have to take the answer on trust.

There is nothing here for a predator to use

ShotDetect has no user profiles, no messaging, no comments, no photo or video sharing, and no user-generated content of any kind. There is no directory of users and no way to search for one.

A stranger cannot contact a child through this app. There is no messaging path of any kind — nothing in this app lets one person compose text that another person reads. Phones send each other exactly three things, all fixed-format records generated by the software: a short message over Bluetooth saying this phone heard something, where it was and how sure it is; when three phones agree, an alert forwarded to the guardian the student paired with; and, while the app is open, a position update sent to the people this phone paired with. None of the three carries a name or an account. This paragraph said "exactly two things" until August 2026, and that was true when it was written.

One field is typed by a person, and it is worth being exact about. When two phones pair, each side may give a name — a first name or a nickname — to be shown on the other's screen, and giving one is optional. It is handed over once, in the room, in the code the two phones show each other, and nothing in the app can send a second one. It is not a channel: there is no way to send a message, and no way to reach a phone you did not pair with in person.

The forwarded alert can only go to a guardian whose phone was physically present when the pairing was made: the two phones exchange keys by showing each other a code on screen, and both people then read the same eight characters aloud to confirm it. There is no directory, no search, and no way for one family's phone to discover another's. A person who is not in that room cannot become a recipient.

That same gate is the whole of what protects a child's live position, which the app has shared with paired adults since August 2026. Section 02a describes it. The list of people a phone has paired with is shown in the app, and it is the complete answer to who can see where that phone is — there is nothing else to check. What this version does not offer is a way to remove someone from that list, so pair deliberately.

Your child's live position is shared with the adults they paired with

This app has a child audience, and since August 2026 it shares a child's live location. That deserves a plain description on this page rather than a line in a privacy policy, so here it is.

What is shared. While the app is open on your child's phone, it sends where the phone is — about every five seconds — together with how accurate the reading is, the time it was taken, and whether the phone is moving. On your phone it draws a dot on a map. It arrives with no notification and no sound, and no history of it is kept on either phone or on our relay.

Who it is shared with, and this is the whole of it. Only people who paired with that phone in person, by holding two phones together and reading the same eight characters aloud to confirm the keys match. A student's position goes to that student's guardians. A guardian's position goes to their students. There is no directory of users, no search, no proximity list, no friend request, and no path by which one family's phone discovers another's. A person who was not in the room when the pairing was made cannot become a recipient, and there is nothing in the app that would let them ask.

Several adults per child is the ordinary case. A child paired with a mother, a father and a grandmother is visible to all three of them. That is the design rather than a leak — each of those pairings was made deliberately, in person — but it is worth knowing before you pair, because this version of the app has no way to un-pair someone. Uninstalling and re-pairing is the only route back, and that is a gap we should close rather than one we are defending.

It goes both ways. An alert travels one way, from a child's phone to a guardian's. A position does not. When you open the app, your children see where you are, on exactly the terms you see them.

When it stops. Closing the app stops it. Nothing is published while the app is not on the screen of the phone doing the publishing, so a phone in a pocket during a lesson, or one closed for the evening, is sending nothing at all. The one exception is an alert: during one, a position is sent whether the app is open or not. And a position that stops arriving is removed from the other phone's map after ninety seconds rather than being left there — "here an hour ago" must not be able to look like "here now".

What the server can see: nothing. Each update is encrypted on the sending phone with a key only the two paired phones can compute, and addressed to a random token. Our relay holds a block of bytes it has no key to open. Positions and alerts are the same length, so the relay cannot even tell which kind it is carrying. An undelivered message is discarded after twenty minutes.

What this is not. It is not a tracker, and it should not be relied on as one. A phone with no signal, a denied location permission, a poor fix or a flat battery shows nothing or shows something vague. An empty map is not evidence that your child is safe, and a dot is not evidence that they are where it says. Section 05 of our Privacy Policy sets out every field that is sent.

No advertising

The app contains no advertising network, no ad SDK, and no tracking for advertising purposes. No data from any user, child or adult, is sold or shared with advertisers.

Child sexual abuse and exploitation

Child sexual abuse and exploitation material is abhorrent, and it is prohibited in any connection with this app or this company.

The app provides no surface on which such material could be created, uploaded, stored or shared — there is no content of any kind for a user to submit. Should we become aware of any misuse of the app connected to the exploitation of a child, we will investigate it and refer it to the appropriate authorities.

Reporting a concern

Email contact@shotdetect.com. Child safety reports are acknowledged within 3 business days.

In the Philippines, child abuse can be reported to the Philippine National Police Women and Children Protection Center. If a child is in immediate danger, call 911.

Parental consent

Use by a child under 13 requires verifiable parental consent.

This page previously said the app collects no personal data from any user, of any age. That was true until August 2026. Pairing changed it. The app now keeps two things on the phone itself: the name your child asked to be called, and the people they paired with. Neither is ever sent to us. Our relay receives a random routing token, a sealed block of bytes it has no key to open, and the IP address of the phone that connected. It receives no name, no account, no email address and no phone number, and it cannot tell whose alert it is carrying or which school anyone attends. Sections 05, 06, 07 and 11 of our Privacy Policy list every field.

Consenting on a child's behalf now includes consenting to section 02a. A guardian accepting the terms on a student's phone is agreeing to that phone sharing the child's live position with every phone it is paired with, whenever the app is open. That was not part of what an earlier guardian agreed to, so the in-app wording version was raised — to 0.7.0 — and everyone is asked again rather than carried silently onto a different app.

The app is in an early access test, which people join by giving us an email address. Testers must be 18 or over. A student's phone can take part, but the place belongs to their parent or guardian, who installs the app and accepts on the device — we do not put a child's email address on a tester list. Early access sets out what happens to that address.

What the microphone actually does

This is the part parents ask about, so it is repeated here rather than left on another page. While the app is armed, the microphone is open and the phone listens for the sound of gunfire. That sound is examined in your child's phone's memory and overwritten within seconds. It is not recorded, not saved and not uploaded, and no one — including us — can play it back.

The shared detection code is built without access to storage or the network, and an automated test fails the build if anyone gives it either. That test covers the shared detection library. The Android service that captures the audio and hands it to that library is not covered by it — it writes no audio anywhere, but there you have our word rather than a test. When the app is dormant it releases the microphone at the operating-system level, so the phone's own microphone indicator goes out.

When it listens, and when it does not. The phone listens only inside a listening window — school days, 7:00 AM to 4:30 PM — and only while the app is armed. It closes at the end of a window. A schedule that is empty or that the app cannot read means the microphone stays shut, deliberately: an app that listens because it could not read its own settings is the failure that rule exists to prevent.

A limitation a parent should know about before installing. On the phone that listens, none of that can be changed. There is no screen on a student's phone for editing the hours, switching a window off, or changing the school — those controls exist only on a guardian's own handset, where they govern nothing, because no setting travels between two phones. A guardian can connect a phone to be warned, and can turn protection off entirely. If 7:00 AM to 4:30 PM is wrong for your school, leaving protection off is the only honest option this version offers.

One honest caveat, and one correction. The listening service now closes the microphone itself at the end of a window — it re-reads the schedule as it runs, rather than relying on the app's screen being open — so a phone left armed with the app swiped away does stop on time. This page previously said it did not, which was true when written. What the service cannot do is start itself again at the beginning of the next window; that needs the app opened. And whether the app was armed is remembered across a restart, so a phone that reboots comes back listening by itself once a window is open. Switching protection off closes the microphone at once and is remembered too, so a restart after that starts nothing.

Four things leave the phone over the network, and none of them is audio. This page said two until August 2026, then three, and each was true when it was written. The name of a school typed into the search box goes to OpenStreetMap's Nominatim service; map images come from the OpenStreetMap Foundation's tile servers; a corroborated, high-confidence alert goes to our relay, sealed, for the guardian your child paired with; and, while the app is open, a sealed position update goes to the same relay every few seconds for the people your child paired with — section 02a. All of those requests carry the phone's IP address to whoever receives them. The Bluetooth broadcast described in section 02 also leaves the phone, but it is a radio broadcast rather than a network request and it reaches only what is in range. Our Privacy Policy sets out exactly what is sent in each case and links to the other services' policies.