For regulators, journalists & school leaders

Safety architecture

Spark & Anvil is safe by construction, not by retrofit. The design laws below were built in from the start — before any regulator required them — which is why the 2026 wave of child-AI legislation finds nothing here to fix. This page is the authoritative reference; the parent-facing version lives on For parents & educators.

Last updated: 2026-09-16

The one-sentence version

There is no account, no server that receives a child's data, no free-text chat, and no AI companion — so the categories the 2026 laws regulate do not exist in our products, and the child data those laws protect is never collected in the first place.

The architecture — six design laws

On-device, nothing leaves the device

Progress, settings, and any AI-generated content stay on the child's device using Apple's SwiftData + FoundationModels. We do not operate user-facing servers that receive child data. On the web, state lives in on-device localStorage with no identifier. Any on-device AI is pinned to run on-device — never routed to Private Cloud Compute or a third-party model — so a child's inputs never leave the device.

No free-text chat surface

A child never types an open message to the AI. Every interaction is a structured choice. This removes the channel through which grooming, self-harm solicitation, and inappropriate content flow in the incidents that drove the 2026 laws.

Not a companion — a novice the child teaches

The deliberate anti-Character.AI: the AI is a "still-learning" cast member the child instructs and corrects (the protégé effect). There is nothing designed to form an emotional attachment to.

The mentor cannot hand over the answer

The AI is built to ask, never to answer — Socratic by construction. It surfaces the child's own reasoning and offers a faded hint, but it structurally cannot type the solution. "AI that guides reasoning helps; AI that supplies answers hurts" is our design law.

No accounts, no PII, no tracking

No sign-up, no email, no third-party analytics SDK in the apps. The website uses cookieless Plausible for visit counts only. Cross-user "kids also liked" recommendations come from anonymous aggregate counts, never a per-child profile.

Trauma-informed gates + external review

Heavier content passes SAMHSA TIP 57-aligned trauma-informed gates, with external sensitivity review for the most sensitive material; every generated illustration is reviewed for unintended inappropriate readings before it ships.

How two players connect — the four topologies

Every way a Spark & Anvil app connects two humans is one of exactly four connection types. None of them is an open lobby, and none routes a child's data through a server we operate.

Connection What travels What's kept
One device No network Nothing — the game never leaves the device; players hand it back and forth (pass-and-play). Nothing off-device.
Same room Local only, no internet Game moves over the local Wi-Fi only, from the host device to the players who joined by a four-emoji room code. No chat, no free text. Nothing persisted off the host; the room ends when everyone leaves.
By code Relay Only the room code, a curated-nickname index, and the moves transit the relay — nothing else, no identifiers. Zero retention; the room dies the moment both players leave.
By message Apple's Messages The game state rides inside your family's own Messages thread; we see no one and receive nothing. Nothing on our side; your family's Communication Limits govern who can play.

"By code" is the code-relay used by our web multiplayer; "same room" and "by message" keep everything on your own devices and pipes. Pass-and-play on one device needs no network at all.

How the architecture clears the 2026 regulatory wave

The incidents that drove this legislation — AI companions grooming children, soliciting self-harm, or supplying answers that offload thinking — trace to design choices we never made.

GUARD Act (S. 3062)

Advanced Senate Judiciary unanimously, Apr 30 2026

Requires: Bans AI "companion" chatbots for minors — an AI that simulates a sustained interpersonal relationship or emotional interaction — with an explicit exemption for educational use.

How we clear it by design: Our in-app AI is not a companion by definition: no sustained interpersonal/emotional-relationship simulation and no open-ended chat. It is a novice character the student teaches through structured choices. We fall in the educational exemption AND would clear the companion bar regardless.

COPPA — 2025 FTC amendments

Enforceable Apr 22 2026 (first update since 2013)

Requires: Expanded "personal information" (adds biometrics/voiceprints), separate verifiable-parental consent before sharing children's data with advertisers or AI-training systems, data minimization, transparency.

How we clear it by design: We collect no personal information from children — nothing leaves the device. No accounts, no server-side child data, no biometrics, no ad networks, no third-party SDKs, and no data used for AI training. There is nothing to disclose or gate because there is nothing collected.

California SB 243 — Companion Chatbot Law

Effective Jan 1 2026

Requires: Companion-chatbot operators must disclose non-human status, implement crisis protocols, block sexual content for minors, and enforce periodic breaks.

How we clear it by design: No companion surface exists to regulate. The teachable-novice cast is clearly a character in a learning activity, never presented as a person to confide in; there is no free-text channel through which harmful content could be solicited or produced.

New York S. 9051

Passed both chambers Jun 2026; awaiting Governor (deadline Dec 31 2026; effective Jan 1 2027 if signed)

Requires: Prohibits offering "companion" chatbots to minors under 18.

How we clear it by design: Same basis — we offer no companion chatbot to anyone. The AI is a Socratic, answer-refusing teaching aid inside a structured activity.

GDPR-K / global child-data norms

Standing

Requires: Data minimization, purpose limitation, and strong protection of children's personal data.

How we clear it by design: On-device-only by construction is the strongest possible posture: the data never exists off the device to be processed, transferred, or breached.

What we do not claim

This page describes our architecture and compliance posture — how the products are built and why they meet the law by design. It is not a claim of measured learning outcomes; our efficacy evidence is being built openly and honestly, and until independent studies exist we keep those claims modest. Safety-by-construction is a fact about the code; learning impact is a question we are still answering in public.

Privacy policy → How our apps teach → For parents & educators →