Transparency and Good Faith
Safety N3T is a social platform for adults (18 and over). Many of the harms people associate with social media come from specific product choices. The table below lists the situations we saw in the wider industry, why we consider each one a problem, and what we changed in this app to close the gap. Every row can be checked against the live app and its published policies.
| The Objective Situation | Why It's a Problem | What We Did to Close the Gap |
|---|---|---|
| Age and audience | ||
| Age gates that only run on the phone. | If the age check lives only in the app, it can be bypassed by editing what the phone sends or by reinstalling and answering differently. | The birth date is checked and stored by the server, not just the app. A birth date can be set once and cannot be edited afterwards. Adults who joined before the current rule was in place were kept as members, not locked out. |
| Age screens that hint at the "right" answer. | When a screen states the minimum age before asking for a birth date, it turns the check into a quiz that a determined person can guess. | The age screen asks for a full date of birth first, without stating any threshold, so the answer is a fact rather than a hint. |
| Retrying the age question until it passes. | If the app lets the same device try again after a failed age check, the check does not really block anyone. | After a failed age check the device is locked out from retrying. |
| No way for members to flag an apparently under-age account. | If the option to report a suspected under-18 account is hidden inside a generic "report" list, or missing altogether, such accounts rarely get reviewed. | A dedicated "Report user under 18" option is offered wherever the "Report fake user" option appears, and it is also included in the generic report dialogs. |
| A single report can restrict someone's account. | Letting one report (or one person's repeated reports) restrict an account invites harassment and mistakes. | An account is placed under review only after three different people have reported it as under 18. The server counts the reports; the app cannot set the flag on its own; the same person cannot report the same account twice. The account is not deleted; a human reviewer decides. |
| Accounts under age review keep posting and messaging. | If nothing changes while a report is being reviewed, the review is not really protecting anyone. | While an account is under age review, new posts and messages are refused by the server. The person sees a neutral explanation of what is happening, not a raw error code. |
| Feeds and engagement | ||
| Ranked feeds with no way to opt out. | When the only feed is one that a ranking system chooses for you, you cannot see the community as it actually is. | A one-tap switch to a non-personalized, newest-first feed is available at all times. |
| Nobody knows why they see what they see. | If the feed is opaque, people cannot judge whether it is showing them what they wanted or what someone else wanted them to see. | An "About this feed" explanation is reachable directly from the feed and describes, in plain language, what the ranking uses. |
| Endless scrolling. | Feeds that load forever remove any natural stopping point and are linked to worse sleep and compulsive use. | The feed ends with a clear "You're all caught up" boundary instead of loading indefinitely. |
| Push notifications at any hour. | Notifications sent through the night interrupt sleep and pull attention back into the app. | Quiet hours are enforced by the server, with a default of 10 pm to 6 am for new accounts. Only genuine safety alerts (emergency, check-in, calls) come through during quiet hours; other pushes are held and delivered later, not lost. |
| No sense of time spent in the app. | Without any signal that time is passing, sessions can grow far beyond what the person intended. | An optional in-session reminder can be enabled at 30, 60, or 90 minutes. It is off by default and never blocks the app. |
| "Come back" nudges designed to pull people back in. | Notifications whose only purpose is to re-engage someone (like "you haven't opened the app" or "your friend just did something") serve the app rather than the person. | An internal audit found exactly one such notification (a birthday nudge). It was removed, and none remain. |
| Engagement features shipped without asking whether they harm people. | New feeds, streaks, counters, and notification patterns often ship with no check on the harm they might cause. | An internal design-review checklist and decision log must be filled in and signed off before any change to a feed, notification, or counter can ship. This is an internal process and not visible in the app itself. |
| AI quietly rewriting what people wrote. | When an assistant silently changes a post, the reader sees something the author never approved, and the author's voice is lost. | When an AI feature adjusts a post's text, the author sees the change and must confirm or revert it before posting. Posts whose text was adjusted are shown with an "AI-adjusted" label. |
| Reporting and moderation | ||
| Reports that disappear into a queue with no clock. | When reports sit indefinitely, urgent safety issues wait alongside routine complaints and nobody is accountable for the delay. | Every report is given a priority (safety-critical first) and a response deadline. Overdue reports are flagged to reviewers, and every reviewer decision is recorded with a reason. |
| Reporters never hear back. | If a person files a report and never learns whether anything happened, they lose trust in the process and stop reporting. | The person who reported is told the outcome of their report along with a reason category. |
| Punishment with no explanation and no appeal. | When content is removed or an account is restricted with no reason given and no way to challenge it, honest mistakes cannot be corrected. | Someone whose content is removed or account restricted sees the reason category and an "Appeal" button. Appeals go to a reviewer queue, and the decision is recorded. |
| Blocked devices or emails with a blank "error". | A silent block with no explanation leaves someone with no way to understand or challenge what happened. | A blocked person sees the reason category, the date, and a contact to appeal, together with a non-personal reference number they can quote. |
| Emergency and alert tools turned into spam or harassment. | Broadcast features that anyone can use without limits get weaponized to flood or harass other members. | Sending is rate-limited by the server; every send is audited (without exposing the message content); recipients can "Report misuse"; and administrators can revoke a sender's ability to trigger alerts. |
| Secret reputation scores. | Numbers that sit next to a person's name and shape how others treat them should not be private to the platform. | How the trust score works, including what it uses, how it moves, and its limits, is published in plain language in the user manual. |
| Self-harm | ||
| Someone in crisis posts or messages and gets nothing back. | An app that stays silent while a person composes concerning content misses the moment when a quiet nudge toward help can matter most. | Before a post or message is sent, on-device detection of self-harm language shows region-aware crisis resources. The person can still send whatever they wrote; nothing about this check leaves the device. |
| Search leading to pro-self-harm or eating-disorder content. | Search results that reinforce self-harm or eating-disorder behaviour make the harm worse. | Those searches return crisis resources instead of results. |
| Self-harm reports treated like any other report. | If a self-harm report sits in the same queue as spam, response time is measured in days when it needs to be measured in minutes. | A dedicated self-harm report reason exists and is handled at the highest priority. |
| Illegal content | ||
| Evidence of child sexual abuse material deleted before authorities can act. | If an offender can delete their account and take the evidence with them, investigations cannot proceed. | Reported material is placed under a 90-day preservation hold that account deletion and routine cleanup cannot remove, and there is a written procedure for escalating to the national reporting center. Proactive matching against known-material databases is not yet in place; we say so openly. |
| Location and Inner Circle | ||
| Location shared without knowing who sees it, or how to stop. | If a person cannot tell who is currently seeing their location or how to turn it off, they are not really in control of it. | A visible "Sharing location with N people" indicator, per-person and global pause controls, and a review prompt every 90 days are all built in. |
| Consent enforced only by the app's screen, not by the server. | If a screen is the only thing stopping someone from reading another person's location, a modified app can read it anyway. | Live location lives in its own record that only the people the sharer has actually agreed to share with can read. The server, not the app, enforces the list, and the profile record itself carries no live coordinates. The same rule now covers location-history trails. |
| Emergencies used as a reason to expose everyone's location. | When an "emergency" mode opens up everyone's location, the exception quickly becomes the norm. | When someone triggers an emergency, the server picks the nearest responders and records an audit entry that contains no coordinates. No phone ever reads another person's location for this. |
| Ride and delivery tracking that lasts beyond the trip. | Location visibility that continues after a trip is finished normalizes long-lived tracking. | A driver's location is written to the trip itself, visible only to the trip's participants, and stops with the trip. Choosing the nearest driver happens on the server. |
| Privacy text that promises more than the product enforces. | Reassuring words in a policy that the software does not actually back up are worse than saying nothing, because they mislead. | The location-sharing disclosures were rewritten to match exactly what the server enforces, including what emergency alerts actually reveal. |
| Personal data | ||
| Logs and location history kept forever. | Data that never expires becomes a target for breaches and a temptation to reuse it for purposes it was never collected for. | Diagnostic logs expire after 90 days, raw location history after 30 days, and ban records after 365 days. The retention schedule is published, and automatic deletion is enabled by operators as part of deployment. |
| Security data reused for tracking. | Identifiers gathered to stop fraud can quietly be reused to profile or follow people. | Device and email identifiers are used only for fraud prevention and ban-evasion checks. They are stored hashed, are readable only by the server and administrators, and expire after 365 days. |
| Face processing without asking. | Face matching or liveness checks that start before anyone has agreed to them normalize a very intrusive form of processing. | No face check runs until the person has seen a consent screen and agreed. Declining means non-biometric checks only; no face geometry is stored; the retention rule is published. |
| Consent that cannot be proven later. | If a platform cannot show what exactly a person agreed to and when, "consent" is impossible to defend. | Every consent choice is stored with the exact wording shown (as a fingerprint of the text), its version, the time, the language, and the app version. The history is append-only and the person can export it. |
| Analytics on by default, one master switch. | A single toggle bundling analytics, crash reports, diagnostics, background location, and biometric checks means nobody is really choosing any one of them. | Five separate switches (analytics and crash reports, diagnostic logs, face check, location history, background location) are each wired to the real code path. Analytics, crash reporting, and diagnostics are off until turned on. |
| No way to get your own data. | If a person cannot see what a service holds about them, they cannot judge what to do about it. | A "Download my data" option in Privacy settings exports everything, including messages and consent history. |
| Delete account leaves data behind. | When account deletion misses adjacent collections and backups, the promise of deletion is not kept. | Deletion was audited collection by collection and storage folder by storage folder. Gaps were fixed, the few legal-hold exceptions were documented, and the privacy policy's backup window was corrected to match reality. |
| Hidden third-party processors. | If the full list of vendors receiving data is not disclosed, users cannot judge the risk and regulators cannot verify the safeguards. | Every processor is named in the privacy policy, including AI providers (which perform inference only, with no training on user content), and the data-transfer safeguards are stated per vendor. |
| Payments | ||
| Subscription traps. | Renewal dates, cancellation paths, and pre-renewal reminders that are missing or buried lead to charges people did not intend. | Price, billing cycle, renewal date, and how to cancel are shown and acknowledged before purchase. Manage, cancel, and refund are one tap away in the app. Yearly plans get a reminder about a week before renewal. |
| Marketing that overclaims safety. | Marketing that promises more than the product delivers erodes the very trust the product is trying to build. | Marketing copy and Terms wording were audited and softened wherever they promised more than the product actually does. |
| Language and governance | ||
| Safety and consent text only in English. | Safety-critical text that only some users can read is not really safety-critical text at all. | Every safety, consent, age-gate, appeal, and report string is available in Spanish, Hindi, and Chinese, and the legal pages are mirrored in those languages. |
| No accountable safety process. | Without named owners, an incident-handling procedure, and a regular review cadence, safety commitments cannot be kept over time. | Written safety governance artifacts exist internally, covering owners, incident handling, and the review cadence. This is an internal process and not visible in the app itself. |
Note on audience for the age-and-audience rows: Safety N3T is available to adults only (18 and over). A separate companion app for children, Safety N3T Jr., is planned as a future product and has not been built.
What is still open
We publish this page in good faith, which means being honest about the gaps that remain. The following items are known and being tracked, and they will move into the table above when they ship:
- Third-party age verification. Today the app relies on the age gate described in the table plus self-attested birth date. Independent age assurance from a specialist vendor is not yet in place and requires a signed vendor agreement before any integration can begin.
- Proactive matching against known child sexual abuse material. Reported material is preserved and escalated as described in the table, but automated matching of uploaded media against a known-material database is not yet in place; it likewise requires a vendor agreement first.
- Trust-score fairness audit. The trust score's inputs, weights, and limits are published in plain language in the user manual. A statistical audit for disparate impact needs a meaningful amount of production data before it can be run, and is scheduled for after that data has accumulated.