Child safety standards

Who this app is for, and why this page exists

ShotDetect is a research prototype, used by students of school age and by their guardians. A student's phone is not protected until a guardian has connected to it and accepted the terms.

That gate is enforced. A phone will not arm unless a guardian has accepted on it — arm() requires the guardian's acceptance, so a student tapping through the disclaimer alone cannot open the microphone. This page said the opposite until 2026-08-18, describing a gap that had already been closed; the app cannot check who is tapping, which is a different and unavoidable limitation, and it says so on the screen that asks.

Three things a parent should know before reading further, because they change what this app is. It can now warn you when you are not at the school — that changed in August 2026, and this page previously said the opposite. A corroborated alert is encrypted on your child's phone and forwarded to the guardian they paired with, wherever you are. Nobody has yet measured how reliably that arrives between two real phones in different places.

And it now shares your child's live position with you, and yours with them. That is section 02a, and it is the change on this page that most deserves a parent's attention: until August 2026 a position left a child's phone only during an alert, and this page and our privacy policy said so. It now leaves for as long as the app is open on the phone — about once a minute while the phone is still, about every fifteen seconds while it is moving, and about every two seconds during an alert. Only the people that phone paired with in person can read it — it reaches them through a relay we operate, which carries it sealed and cannot open it — it goes in both directions, and closing the app stops it. Since 2026-08-30 that last clause has one exception, in section 02a: the fifteen minutes a phone shares where it is because somebody it paired with opened their own app, which has no switch at all. Since the same date a student's phone shares its position only inside the school zone, which narrows the clause rather than excepting it.

And it raises far more false alerts than it is meant to. Shown at the school, the current build misses its own design target — one false alert per school per year — by a wide margin, and it is a research prototype for that reason. Sent to a guardian who is not there it is deliberately much quieter, which it achieves by never forwarding a substantial share of the detections it would show at the school. Silence is not evidence that your child is safe. The measured figures are on how it performs, kept there rather than repeated here so that they stay current as the detector changes.

This app has never raised an alert from a real gunshot. It has been tested on recordings and on drills only, so every figure on that page describes recorded audio and not a building with children in it.

Google Play's formal Child Safety Standards policy applies to apps in the Social and Dating categories and, since 26 August 2026, to anonymous and random chat apps. ShotDetect is none of these. We publish this page anyway, because a parent deciding whether to put a listening app on a child's phone should not have to take the answer on trust.

There is nothing here for a predator to use

ShotDetect has no user profiles, no messaging, no comments, no photo or video sharing, and no user-generated content of any kind. There is no directory of users and no way to search for one.

A stranger cannot contact a child through this app. There is no messaging path of any kind — nothing in this app lets one person compose text that another person reads. Phones send each other exactly eight things, all fixed-format records generated by the software:

None of them carries a name or an account, and none of them is text a person composed. This list said "exactly two things" until August 2026, and that was true when it was written.

One field is typed by a person, and it is worth being exact about. When two phones pair, each side may give a name — a first name or a nickname — to be shown on the other's screen, and giving one is optional. It is handed over once, in the room, in the code the two phones show each other, and nothing in the app can send a second one. It is not a channel: there is no way to send a message, and no way to reach a phone you did not pair with in person.

The forwarded alert can only go to a guardian whose phone was physically present when the pairing was made: the two phones exchange keys by showing each other a code on screen, and both people then read the same eight characters aloud to confirm it. There is no directory, no search, and no way for one family's phone to discover another's. A person who is not in that room cannot become a recipient.

That same gate is the whole of what protects a child's live position, which the app has shared with paired adults since August 2026. Section 02a describes it. The list of people a phone has paired with is shown in the app, and it is the complete answer to who can see where that phone is — there is nothing else to check. A pairing can be removed from that list. This page said until August 2026 that it could not be, which was true when it was written and is not true now; it mattered, because it told a parent they could not revoke access they can in fact revoke.

Your child's live position is shared with the adults they paired with

This app is carried by school students — its declared audience is 13 to 17 and adults — and since August 2026 it shares a student's live location. That deserves a plain description on this page rather than a line in a privacy policy, so here it is.

What is shared. While the app is open on your child's phone, it sends where the phone is — about once a minute while the phone is still, every fifteen seconds while it moves, and every two seconds during an alert — together with how accurate the reading is, the time it was taken, and whether the phone is moving. On your phone it draws a dot on a map. It arrives with no notification and no sound, and no history of it is kept on either phone or on our relay.

Who it is shared with, and this is the whole of it. Only people who paired with that phone in person, by holding two phones together and reading the same eight characters aloud to confirm the keys match. A student's position goes to that student's guardians. A guardian's position goes to their students, and to any co-guardian they paired with — two guardians of the same child may pair with each other, which shares their positions and online status with each other and nothing else, and does not pass on the child's alerts. There is no directory of users, no search, no proximity list, no friend request, and no path by which one family's phone discovers another's. A person who was not in the room when the pairing was made cannot become a recipient, and there is nothing in the app that would let them ask.

Several adults per child is the ordinary case. A child paired with a mother, a father and a grandmother is visible to all three of them. That is the design rather than a leak — each of those pairings was made deliberately, in person — but it is worth knowing before you pair. A pairing can be removed. The app lists everyone a phone is paired with, and an entry can be taken off that list, which stops the position going to them. This page said until August 2026 that there was no way to un-pair; that was true when it was written, it is not true now, and it was the wrong thing to be wrong about — it told a parent they could not revoke access they can in fact revoke.

It goes both ways. An alert travels one way, from a child's phone to a guardian's. A position does not. When you open the app, your children see where you are, on exactly the terms you see them.

When it stops. Closing the app stops your position being published, and that used to be the whole of it. There are now four exceptions, and the last two of them are streams. The first is an alert: during one, a position is sent whether the app is open or not. The second is a note saying the phone has reached school or has left it — a time and which side of the boundary the phone is on, with no position of any kind in it — and that note is sent with the app closed. So on the settings a phone arrives with, a phone in a pocket during a lesson is not sending where your child is; on an ordinary day it announces two crossings, and repeats each announcement for an hour so that a guardian's phone that was off does not miss it. It can be switched off. The setting lives on the phone doing the publishing and applies to one paired person at a time, so "stop telling my father" and "stop telling anybody" are different requests; it starts on, because the adult who most needs to know a child arrived is the one not looking at a map. And a position that stops arriving is removed from the other phone's map after ninety seconds rather than being left there — "here an hour ago" must not be able to look like "here now".

The third item is a limit rather than an exception, and it replaced a setting a parent should know about. Since 2026-08-30 a student's phone publishes where it is only while it is inside the school zone. What follows is the whole of it.

The fourth exception has no switch, and a parent should know that before installing. Also added on 2026-08-29: when somebody your child paired with opens the app, your child's phone shares where it is with that person, whether or not the app is open at your child's end. What follows is the whole of it.

What the server can read: nothing. Each update is encrypted on the sending phone with a key only the two paired phones can compute, and addressed to a random token. Our relay holds a block of bytes it has no key to open. Positions, alerts, replies, place notes, the requests that open a fifteen-minute share and a person's answer to the app's own question are all the same length. Since August 2026 a position, a place note and a request are written to a different address there, so the operator can see that a message is not one of those without being able to read any of it. A position or a place note it is holding is held for fifteen minutes. An undelivered alert is discarded after ninety minutes.

What this is not. It is not a tracker, and it should not be relied on as one. A phone with no signal, a denied location permission, a poor fix or a flat battery shows nothing or shows something vague. An empty map is not evidence that your child is safe, and a dot is not evidence that they are where it says. Section 05 of our Privacy Policy sets out every field that is sent.

No advertising

The app contains no advertising network, no ad SDK, and no tracking for advertising purposes. No data from any user, child or adult, is sold or shared with advertisers.

Child sexual abuse and exploitation

Child sexual abuse and exploitation material is abhorrent, and it is prohibited in any connection with this app or this company.

The app provides no surface on which such material could be created, uploaded, stored or shared — the only thing a user writes is a display name, which is shown to the person they pair with and to nobody else. Should we become aware of any misuse of the app connected to the exploitation of a child, we will investigate it and refer it to the appropriate authorities — in the Philippines, the PNP Women and Children Protection Center and the NBI, and internationally the NCMEC CyberTipline.

Reporting a concern

Email contact@shotdetect.com. Child safety reports are acknowledged within 3 business days.

In the Philippines, child abuse can be reported to the Philippine National Police Women and Children Protection Center. If a child is in immediate danger, call 911.

Parental consent

ShotDetect is for students aged 13 and over. It is not offered to children under 13. This page said until August 2026 that use by a child under 13 required verifiable parental consent, which implied the app was available to them at all. It is not, and the reason is the app's own design rather than paperwork: it reads a precise position and puts it into an unencrypted Bluetooth broadcast that anything in radio range can read (section 02), and that is not something we are prepared to do for a younger child's phone. The app's declared audience is 13 to 17 and adults.

The person who accepts must be 18 or over, and must be the student's parent or legal guardian. A guardian must accept on the device before a student's phone will listen, whatever the student's age. That acceptance gate is section 01, and it is enforced in the app rather than merely asked for.

Since wording 0.21.0 the acceptor also has to say they are that person. The screen carries the statement "I am 18 or over and this student's parent or guardian", and acceptance is not recorded until it is ticked. Two things follow, and both matter. The app still asks for no birthdate and stores none, so this is an assertion and not an age check, and it cannot see who is holding the phone. And this page said until 2026-09-11 that the age requirement itself was enforced in the app; it was not, and the sentence above now says which half is.

Raising the floor to 13 does not make the student an adult. In the Philippines a person is a minor until 18, so for a student aged 13 to 17 the consent for processing their personal information still has to come from a parent or legal guardian under the Data Privacy Act. That is what the guardian's acceptance is. It is compliance with the Act's treatment of minors, not an exemption from it, and it does not end when a student turns 13. Section 12.11 of our Privacy Policy sets out what that means in practice.

This page previously said the app collects no personal data from any user, of any age. That was true until August 2026. Pairing changed it. The app now keeps two things on the phone itself: the name your child asked to be called, and the people they paired with. Neither is ever sent to us. Our relay receives a random routing token, a sealed block of bytes it has no key to open, and the IP address of the phone that connected. It receives no name, no account, no email address and no phone number, and it cannot tell whose alert it is carrying or which school anyone attends. Sections 05, 06, 07 and 11 of our Privacy Policy list every field.

Consenting on a child's behalf now includes consenting to section 02a. A guardian accepting the terms on a student's phone is agreeing to that phone sharing the child's live position with every phone it is paired with whenever the app is open, and with any one of them who opens their own app, for about fifteen minutes at a time, whether or not the app is open at the child's end. It is not agreement to any sharing outside the school zone, because there is none. That was not part of what an earlier guardian agreed to, so the in-app wording version was raised. It is 0.29.0 today. It was raised in August 2026 for the arrival and departure notes, and again on 2026-08-30 when the all-day setting described above was withdrawn. It was raised on 2026-09-11 for four more: where the measured figures are published, that no alert has ever come from a real gunshot, who a guardian's position reaches, and the statement the acceptor now has to tick. It was raised twice on 2026-09-12. The app puts a question on the screen of a phone that reported hearing something — did you just hear gunfire? — and sends that person's yes or no to the phones it is paired with. Nobody has to answer, answering nothing holds nothing back, and one phone is asked at most once in any seven days. The first of the two raises said all of that in the future tense, because none of it was built; the second, hours later, took the tense out when it was. It was written down ahead of the build on purpose, because a person should be holding it before the question first appears, not after. The second was a correction: one clause of the privacy document still described the per-person switch for arrival notes that was withdrawn on 2026-08-30, and a document promising a control that is not there sends a reader looking for it. It was raised again on 2026-09-13, for two things a family phone does not do and is told about anyway. The workplace and agency roles are not available in the version on Google Play; they appear on the first screen as "Not available in this version" and cannot be selected, and the wording describes them so that it is complete. The first is storage: a workplace using the app now keeps its site on the manager's phone rather than only in memory. A site means the boundary somebody walked, the floors, the zone names, and the surveyed position of each fixed listening device, together with the workplace's police-agency enrolment. The second is a new message: a fixed device at a workplace can report how loud a sound was where it stands, so that an alarm can say which floor. Neither reaches a family: no family phone stores a site, and no family phone sends or receives a loudness report. They are written into the wording because the list of what the locked channel can carry has to be complete to be worth reading. It was raised on 2026-09-20 for one thing the phone now keeps. A pairing code is meant to work once. Until now the phone remembered the codes it had used only until it was next restarted, so a code could be used a second time after that — inside the few minutes the code stays valid at all. The phone now writes that short list down, so a used code stays used. The list holds a scrambled fingerprint of each code and nothing else, no name and no key, and each entry is dropped as soon as the code it stands for has expired. It is on the phone, it is never sent anywhere, and uninstalling erases it. Everyone is asked again rather than carried silently onto a different app. That is what the version number on the in-app documents is for: a guardian can tell which wording they actually agreed to, and we cannot change what the app does without asking again.

The app is on Google Play and needs no email address to install. It ran a closed test before that, which people joined by giving us one; the test is closed and we are not collecting addresses any more. Anyone who joined it had to be 18 or over. A student's phone can take part, but the app is installed and accepted on the device by their parent or guardian — we never put a child's email address on any list. Delete your data sets out what happens to an address given during that test, and how to have it erased.

What the microphone actually does

This is the part parents ask about, so it is repeated here rather than left on another page. While the app is armed, the microphone is open and the phone listens for the sound of gunfire. That sound is examined in your child's phone's memory and overwritten within seconds. It is not recorded, not saved and not uploaded, and no one — including us — can play it back.

The shared detection code is built without access to storage or the network, and an automated test fails the build if anyone gives it either. That test now covers both the shared detection library and the Android service that captures the audio and hands it over. This page said until August 2026 that the capture service was outside the check and that you had our word for it rather than a test; that was true when it was written and the exemption has ended. When the app is dormant it releases the microphone at the operating-system level, so the phone's own microphone indicator goes out.

When it listens, and when it does not. The phone listens only while the app is armed, only inside a listening window, and only while the phone is at the school. It closes at the end of a window and when the phone leaves. A schedule that is empty or that the app cannot read means the microphone stays shut, deliberately: an app that listens because it could not read its own settings is the failure that rule exists to prevent. The school test is not exact — it needs clear evidence that the phone has left before it closes the microphone, because a phone indoors often cannot tell where it is — so the microphone can stay open for a while after the phone leaves.

The guardian sets the hours, and this page said the opposite until August 2026. There is still no screen on a student's phone for editing the listening hours, switching a window off, or changing the school. Those controls are on the guardian's own handset — and this page said they "govern nothing, because no setting travels between two phones". That is false. The school, its coordinates, the listening windows and whether the phone is armed all travel from the guardian's handset to the student's, over the same sealed channel that carries an alert, and the student's phone applies them and sends no setting back. Arming from a guardian's own handset is also a second route through the consent gate in section 01, alongside accepting on the student's phone. Until a guardian's settings arrive, the student's phone uses school days, 7:00 AM to 4:30 PM, at the school chosen during setup. A guardian can also connect a phone to be warned, and can turn protection off entirely.

Why that correction matters more than most. The old wording told a parent that the controls on their own screen were decorative, and that leaving protection off was the only option if the default hours were wrong for their school. Both were untrue of the shipped app, and both pointed a parent away from a control that works.

One honest caveat, and one correction. The listening service now closes the microphone itself at the end of a window — it re-reads the schedule as it runs, rather than relying on the app's screen being open — so a phone left armed with the app swiped away does stop on time. This page previously said it did not, which was true when written. What the service cannot do is start itself again at the beginning of the next window; that needs the app opened. This paragraph said until August 2026 that a phone which reboots comes back listening by itself once a window is open, and that is not true. Android will not let a background component open a microphone, and it names the microphone specifically among the things a boot handler may not start, so the app tries and is refused. Whether the app was armed is remembered across a restart, so protection is not switched off by a reboot — but the phone has to be opened once, inside the listening hours, before it listens again. That is true every day, not only after a reboot: a day on which the student's phone is not opened during its listening hours is a day without protection. The app asks the student for that when the school day starts, and tells the guardian if it does not happen. Switching protection off closes the microphone at once and is remembered too, so a restart after that starts nothing.

Eight things leave the phone over the network, and none of them is audio. This page said two until August 2026, then three, then four, then five, then six, then seven, and each was true when it was written.

Until August 2026 this page said the search and the map went to OpenStreetMap directly, and they no longer do.

All of those requests carry the phone's IP address to us. The search and the map are the two we can read: the sealed traffic we cannot, and moving the map behind our own server does not extend that guarantee to it. OpenStreetMap now sees our server rather than your child's phone. The Bluetooth broadcast described in section 02 also leaves the phone, but it is a radio broadcast rather than a network request and it reaches only what is in range. Our Privacy Policy sets out exactly what is sent in each case and links to the other services' policies.