Collect less
Every sensitive field needs a product reason, an owner, and a deletion rule.
GetZ is being engineered so families can see what is protected, what permission enables it, when a device last reported, and when the system needs attention.
Read the standard ↓Safe WebVerified 18 seconds ago
ACTIVELocationAllowed while app is in use
LIMITEDRoutine syncDevice has not checked in
OFFLINENotificationsPermission was disabled
ATTENTIONThese are product requirements for the new GetZ applications. Detailed controls, retention windows, and independent testing evidence will be published as the implementation matures.
Every sensitive field needs a product reason, an owner, and a deletion rule.
Camera, location, notifications, and device-management permissions must have visible purpose and state.
Parent, child, support, and service access should be scoped to the smallest useful capability.
Sensitive family data is designed to be encrypted in transit and at rest with managed secrets outside app code.
The app should distinguish active protection from stale, offline, limited, and needs-attention states.
Families need understandable retention choices and a real account-deletion path before public launch.
A simple architecture is easier to defend. GetZ separates the child device, parent account, family service, and AI learning boundary so access can be narrowed and audited.
No hidden camera or microphone accessProtection should never mean secret recording.
No advertising profile of a childFamily behavior is not inventory to sell.
No pretending offline means protectedUnknown state must be shown as unknown.
No permanent child role by defaultControls should adapt as capability and trust grow.