Safety by design

Children should be visible for their creativity—not exposed through their data.

This project is intentionally designed to provide creative participation without requiring minors to create public profiles, reveal contact information or communicate privately with unknown adults.

1
No minor-to-stranger private messaging.

Communication happens through moderated public prompts or through responsible adults such as parents and teachers.

2
Under-18 submissions are adult-mediated.

A parent, guardian, teacher or approved youth organization submits youth work and manages consent.

3
Collect the minimum.

No child email, phone number, home address, exact school, birth date or live location is needed for a public gallery.

4
Moderate before publishing.

Artwork, captions, comments and links are reviewed before they go live.

5
Use privacy-protective display data.

Artist nickname or first name, age band, broad location and medium are enough.

6
Separate adult professional contact.

Artists offering courses or partnerships use an adult-only channel that is never attached to a minor’s profile or submission.

7
Make removal easy.

Parents/guardians and adult contributors should have a clear way to request removal of work and associated data.

8
Review every new feature.

Accounts, live video, comments, analytics, maps and third-party embeds all get a child-safety/privacy review before launch.

International baseline

Build to a high standard from the beginning.

This starter framework is deliberately more protective than simply applying the minimum age rule in one country.

United States — COPPA

For covered services, U.S. rules protect personal information of children under 13 and generally require notice and verifiable parental consent before collecting personal information from them.

FTC children’s privacy guidance →

European Union — GDPR

Where processing relies on consent for online services offered directly to children, the age at which a child can consent varies by member state from 13 to 16; younger children require authorization from the holder of parental responsibility.

European Commission guidance →

United Kingdom — Children’s Code

Services likely to be accessed by children should put the child’s best interests first, minimize data, use high-privacy defaults and treat geolocation and profiling with special care.

ICO Children’s Code →
Important: This is a design framework, not legal advice. Before a global launch that collects or publishes children’s data/content, obtain a qualified privacy/legal review for the jurisdictions you intend to serve.