LexMatrix Guard

Parent & Mobile App User Guide

Version 1.7
โ† Back to Home Page
Parent Setup Dashboard Child Profiles Android App iOS App Troubleshooting

1 Introduction & Overview

LexMatrix Guard is a parental control system that protects children from harmful social media platforms and manages their screen time. It consists of two parts:

How it works in brief: You set policies on the parent dashboard โ†’ the changes sync through the cloud โ†’ your child's device receives the updates in real time and blocks or allows apps accordingly.
Screenshot #1

What platforms are blocked?

The system enforces 72 platforms โ€” 10 legally-banned platforms for children under 16 (in compliance with Australian, Brazilian, Danish, French, Greek, Indonesian, Malaysian, Spanish, UAE, and UK online safety legislation) plus 62 parent-controlled loophole platforms that children migrate to when banned apps are locked. The following platforms are monitored:

Legally-Banned Platforms (10)

PlatformCategoryLegal StatusDefault State
FacebookSocial MediaBanned (<16)LOCKED
InstagramSocial MediaBanned (<16)LOCKED
KickLive-StreamingBanned (<16)LOCKED
RedditSocial MediaBanned (<16)LOCKED
SnapChatSocial MediaBanned (<16)LOCKED
ThreadsSocial MediaBanned (<16)LOCKED
TikTokSocial MediaBanned (<16)LOCKED
TwitchLive-StreamingBanned (<16)TIMED
X (Twitter)Social MediaBanned (<16)LOCKED
YouTubeVideo/StreamingBanned (<16)TIMED

Parent-Controlled Platforms (62)

These platforms are not legally banned but are commonly used as loophole alternatives. They default to LOCKED and parents can change them to TIMED or ALLOWED at any time.

PlatformCategoryDefault State
BeRealSocial MediaLOCKED
BilibiliVideo/StreamingLOCKED
BitchatAnonymous SocialLOCKED
BlueskySocial MediaLOCKED
BOTIMMessagingLOCKED
BriarMessagingLOCKED
BridgefyMessagingLOCKED
CanvaProductivity/SocialLOCKED
Character.aiAI/SocialLOCKED
ChaiAI/SocialLOCKED
CivitaiAI/SocialLOCKED
DailymotionVideo/StreamingLOCKED
DiscordMessagingLOCKED
DLiveLive-StreamingLOCKED
FizzAnonymous SocialLOCKED
FortniteGaming/SocialLOCKED
GasAnonymous SocialLOCKED
GenevaMessaging/CommunityLOCKED
Habbo HotelGaming/SocialLOCKED
IMOMessagingLOCKED
IMVUGaming/SocialLOCKED
JanitorAIAI/SocialLOCKED
KikMessaging/SocialLOCKED
Lemon8Social MediaLOCKED
LemmySocial MediaLOCKED
LineMessaging/SocialLOCKED
LocketPhoto/SocialLOCKED
MastodonSocial MediaLOCKED
Matrix/ElementMessagingLOCKED
MinecraftGaming/SocialLOCKED
NGLAnonymous SocialLOCKED
PlatformCategoryDefault State
NostrDecentralized SocialLOCKED
NoteItPhoto/SocialLOCKED
PartifulSocial MediaLOCKED
PinterestSocial MediaLOCKED
PixivVideo/StreamingLOCKED
Poly.AIAI/SocialLOCKED
Rec RoomGaming/SocialLOCKED
RednoteSocial MediaLOCKED
ReplikaAI/SocialLOCKED
RetroSocial MediaLOCKED
RobloxGaming/SocialLOCKED
RumbleVideo/StreamingLOCKED
SarahahAnonymous SocialLOCKED
SenditAnonymous SocialLOCKED
SessionMessagingLOCKED
SignalMessagingLOCKED
SpicyChat AIAI/SocialLOCKED
Steam CommunityGaming/SocialLOCKED
TelegramMessagingALLOWED
ThreemaMessagingLOCKED
TrovoLive-StreamingLOCKED
ViberMessagingLOCKED
VRChatGaming/SocialLOCKED
VSCOSocial MediaLOCKED
WeChatMessaging/SocialLOCKED
WhatsAppMessagingALLOWED
WhisperAnonymous SocialLOCKED
WizzSocial MediaLOCKED
Yik YakAnonymous SocialLOCKED
YopeSocial MediaLOCKED
YuboSocial MediaLOCKED
Platform states explained:
  • LOCKED โ€” The app is completely blocked. The child cannot open it.
  • TIMED โ€” The app is allowed but limited by the Time Allocation Matrix (see Section 8).
  • ALLOWED โ€” The app is freely accessible (e.g. WhatsApp and Telegram, which are exempt and parent-controlled โ€” see Section 9).

2 Getting Started โ€” Parent Account Setup

2.1 Accessing the Parent Dashboard

The parent dashboard is a Progressive Web App (PWA). You don't need to install anything from an app store โ€” simply open your browser and go to:

https://lexmatrixguard.com/dashboard

Tip โ€” Install as an app: On your phone, open the URL in Chrome (Android) or Safari (iOS), tap the browser menu, and select "Add to Home Screen." This installs the PWA as a native app icon for quick access.
Screenshot #2

2.2 Creating Your Parent Account

Account creation is invitation-gated for security. You'll need an invitation code to register.

  1. Navigate to the dashboard URL above.
  2. Click "Create one" to switch to the sign-up form.
  3. Enter your Email address.
  4. Choose a Password.
  5. Select your Compliance Region (United Kingdom, Australia, United Arab Emirates, Brazil, Indonesia, or Malaysia) to ensure the proper age-regulation standards are loaded for your profiles.
  6. Set a 6-digit Security PIN โ€” this PIN is required for all sensitive actions (toggles, lockdowns, sign-out). Choose something your child cannot guess.
  7. Select your Device Setup mode:
    • Mobile + Desktop โ€” enables the Desktop Protection section (browser extension pairing, daemon download, heartbeat monitoring, desktop tamper alerts). Choose this if your family uses desktop or laptop computers.
    • Mobile Only โ€” hides the Desktop Protection section entirely and suppresses all desktop alerts. Choose this if your family only uses mobile devices (phones/tablets). You can switch to Mobile + Desktop later from the dashboard if you get a computer.
  8. Enter your Invitation Code (contact support if you don't have one).
  9. Click "Create account".
Important: Your Security PIN is the key to your child's protection. Do NOT share it with your child. If they know the PIN, they can sign out of the enforcement app on their device.
Screenshot #3

2.3 Email Verification

After creating your account, a verification email is sent to your inbox:

  1. Open your email and click the verification link.
  2. Return to the dashboard and click "I've Verified My Email".
  3. If you didn't receive the email, click "Resend Verification Email".
Screenshot #4

2.4 Selecting Your Device Setup Mode

During sign-up, you'll choose your Device Setup mode. This determines whether desktop protection features (browser extension, daemon, heartbeat monitoring, desktop alerts) are visible in your dashboard.

You can change this later: The Device Setup Mode can be toggled at any time from the dashboard using a PIN-gated switch (see Section 3.3). If you select Mobile Only now and later get a desktop or laptop computer, simply switch to Mobile + Desktop to reveal the Desktop Protection section.
Screenshot #5

2.5 Entering Your Security PIN

Once your email is verified, you'll be prompted to enter your 6-digit Security PIN to access the dashboard. This is the PIN you set during sign-up.

Screenshot #6

2.6 Signing In (Returning Users)

If you already have an account:

  1. Go to the dashboard URL.
  2. Enter your Email and Password.
  3. Click "Sign in".
  4. Enter your 6-digit Security PIN when prompted.

If you forgot your password, click "Forgot password?" on the sign-in screen to receive a reset email.

3 The Parent Dashboard (PWA)

After signing in, you'll see the main dashboard. This is your control centre. The dashboard is organised into the following sections, each explained in detail in the sections below:

Screenshot #7
Screenshot #8

3.1 Navigation Bar

The top navigation bar contains:

Screenshot #9

3.2 Curfew โ€” Quiet Hours

The Curfew card lets you schedule a nightly quiet period during which alerts are suppressed and child devices are locked. This ensures you wake up to a clean dashboard without overnight alert spam.

Per-child curfew: Each child profile can have its own curfew schedule. Switch between children using the child selector at the top of the dashboard to configure each one.
Overnight windows: Curfew supports overnight windows (e.g. 22:00โ€“06:00) where the start hour is greater than the end hour. The system correctly handles the midnight boundary.

3.2.1 How Curfew Enforcement Works

When curfew is active:

Screenshot #10

3.3 Device Setup Mode

The Device Setup Mode card lets you switch between Mobile Only and Mobile + Desktop modes. This controls whether the Desktop Protection section (browser extension pairing, daemon download, heartbeat monitoring, desktop tamper alerts) is visible in your dashboard.

Why use Mobile Only? Families in regions where desktop computers are less common can avoid unnecessary desktop alerts and dashboard clutter. If you later acquire a desktop or laptop, simply toggle to Mobile + Desktop to reveal all desktop protection features.
Screenshot #11

4 Managing Child Profiles

You can manage multiple children from a single parent account. Each child has their own profile, enforcement settings, and mobile app sign-in credentials.

4.1 Switching Between Children

Use the CHILD dropdown selector at the top of the dashboard to switch between child profiles. The dashboard updates to show the selected child's settings and device status.

Screenshot #12

4.2 Adding a New Child

  1. Click the "+ Add Child" button next to the child selector.
  2. Enter the child's name (e.g. "Emma").
  3. Set a password for the child's mobile app sign-in (at least 6 characters).
  4. Enter your 6-digit Security PIN when prompted (PIN-gated for security).
  5. Click "CREATE".

After creating the profile, a green notice box appears showing the child's generated email address and reminding you of the password you set. These are the credentials your child will use to sign in on their mobile device.

Copy Email button: Tap the "COPY EMAIL" button to copy the child's email address to your clipboard. The button shows "COPIED!" for 2 seconds to confirm. Paste it into a notes app or password manager for safekeeping.
Save these credentials! You will need the email and password to set up the enforcement app on your child's device. There is no way to recover the child's password without resetting it.
Screenshot #13
Screenshot #14

4.3 Deleting a Child Profile

  1. Select the child you want to delete from the dropdown.
  2. Click the "Delete" button.
  3. Confirm the deletion in the popup dialog.
Warning: Deleting a child profile is permanent and cannot be undone. You must keep at least one child profile.

5 Core Legislation Layer (Global Shield)

The Core Legislation Layer is the master switch for legally-banned platform enforcement. When active (toggle to the right, cyan colour), all banned platforms are locked down on your child's device.

Toggling the Global Shield

  1. Click the toggle switch in the Core Legislation Layer card.
  2. A Security PIN modal appears โ€” enter your 6-digit PIN.
  3. Click "VERIFY & ENFORCE" to confirm.
When ON: "SYSTEM ACTIVE: Banned platform sets are completely locked down on child hardware."
When OFF: "WARNING: Regulatory shields are temporarily inactive."
Legal protection: Even with the Global Shield off, legally-banned platforms (e.g. TikTok, Instagram) cannot be fully released. The system enforces a legal floor that cannot be bypassed.
Screenshot #15
Screenshot #16

6 Device Integrity Monitoring

The Device Integrity card shows the real-time status of your child's device. It displays:

If you see TAMPER_DETECTED: Your child has disabled the enforcement service on their device. A red Tamper Alert banner will appear at the top of the dashboard. See Section 10 for details.
If you see HEARTBEAT_STALE: An amber warning will appear noting the device hasn't reported in over 10 minutes. This may mean the device is offline, out of battery, or the app was force-killed.
Screenshot #17
Screenshot #18

7 Enforcement Kill Switch

The Enforcement Kill Switch is an emergency control that lets you remotely disable all platform blocking on your child's device. This is useful if you need to temporarily grant full access (e.g. for a school requirement).

Toggling the Kill Switch

  1. Click the toggle switch in the Enforcement Kill Switch card.
  2. Enter your 6-digit Security PIN in the modal.
  3. Click "VERIFY & ENFORCE".
Important โ€” Legal floor still applies: The kill switch only releases non-banned platforms. Legally-banned platforms (e.g. TikTok, Instagram, SnapChat) remain blocked even when the kill switch is OFF. This is by design and cannot be overridden.
Screenshot #19
Screenshot #20

8 Hourly Time Allocation Matrix

The Time Allocation Matrix controls how much time your child can spend on TIMED platforms (currently Twitch and YouTube). The time budget is shared across all timed apps.

How it works

Adding Time

Click "+15 MIN UPLINK" to add 15 minutes or "+1 HR UPLINK" to add 1 hour to the time budget. Both require your Security PIN โ€” all budget mutations are PIN-gated to prevent unauthorised time grants. The maximum allocation is 360 minutes (6 hours); both buttons are disabled once the cap is reached.

Force Lockdown

Click "FORCE LOCKDOWN" to immediately zero out the time budget and lock all timed apps. This requires your Security PIN.

Server-side tracking: Time usage is tracked on the server (reported every 5 minutes by the mobile app, with a final report on session end), so your child cannot reset the timer by clearing app data or restarting their device. On every policy sync, the server seeds the local usage counter from the authoritative server-side total, preventing local storage clearing from resetting the countdown. Usage is accounted per-device, so multiple devices cannot double-drain a single time budget.
Monotonic clock enforcement: All enforcement clients (Android, iOS, and browser extension) use monotonic clocks (SystemClock.elapsedRealtime(), ProcessInfo.systemUptime, and performance.now() respectively) instead of wall-clock time. This prevents your child from extending timed access by changing the device clock. iOS also detects backward clock jumps greater than 60 seconds and triggers a re-sync.
Screenshot #21

9 Parent-Controlled Platforms

While legally-banned platforms (Facebook, Instagram, TikTok, etc.) are enforced automatically by the server-side legal list, 62 platforms are exempt from the legal ban and fully parent-controllable. These include messaging apps (WhatsApp, Telegram, Discord, Signal, Session, WeChat, Viber, Threema, Line, IMO, BOTIM, Kik), gaming/social hubs (Roblox, Fortnite, Minecraft, VRChat, Rec Room, IMVU, Habbo Hotel, Steam Community), niche social apps (Rednote, Lemon8, Yope, BeReal, Pinterest, Bluesky, Mastodon, Lemmy, Nostr), anonymous apps (Whisper, NGL, Yik Yak, Sarahah, Sendit, Fizz), AI companion apps (Character.ai, Replika, Chai), video/streaming platforms (Bilibili, Dailymotion, Rumble, Trovo, DLive), and photo/utility apps (Canva, Locket, NoteIt, Geneva, Matrix/Element).

Most of these default to LOCKED to close loophole migration gaps. WhatsApp and Telegram default to ALLOWED for family communication. You can toggle each one between three states at any time. Every change requires your 6-digit Security PIN and is verified server-side.

9.1 Available States

StateBadgeEffect
ALLOWALLOWEDThe platform is freely accessible โ€” no blocking on any device.
BLOCKLOCKEDThe platform's app and web domains are blocked on all enforcement clients (mobile + desktop extension).
TIMEDTIMEDThe platform is allowed only while the Time Wallet has remaining budget. When the budget exhausts, the platform is automatically blocked.

9.2 How to Toggle a Platform

  1. Scroll to the "Parent-Controlled Platforms" section in the dashboard (below the Time Allocation Matrix).
  2. Find the platform you want to change (e.g. WhatsApp, Telegram, Discord, Roblox, Rednote, or any of the 62 parent-controlled platforms).
  3. Click the desired state button: ALLOW, BLOCK, or TIMED.
  4. A Security PIN modal appears โ€” enter your 6-digit Security PIN.
  5. Click "VERIFY & ENFORCE" to confirm.
  6. The change syncs to your child's device in real time via Firestore.
Note โ€” TIMED requires a time budget: If you set a platform to TIMED but the Time Wallet is at zero, the platform will be blocked immediately. Set a time budget first (see Section 8) before using TIMED.
How it works behind the scenes: Your toggle calls the PIN-gated updatePolicy Cloud Function with platformStates: { [platformName]: state }. The syncActiveBlocks trigger then updates active_blocks/current, which mobile apps and the desktop browser extension read in real time. All changes are audit-logged to policy_audit/{timestamp}.
Screenshot #22

10 Live Platform Interaction Audit

This table shows every monitored platform, its category, legal status, and current enforcement state. It gives you a quick at-a-glance view of what's blocked, timed, or allowed on your child's device.

Screenshot #23

Compliance Region Pills

Below the platform table, region pills are organized into 5 continent groups indicating which legal frameworks are being enforced:

๐Ÿ‡ช๐Ÿ‡บ European Union (4 Regions) โ€” Denmark, France, Greece, Spain
  • DENMARK_DSA_2024 โ€” Denmark Digital Safety & EU Digital Services Act compliance
  • FRANCE_SREN_DSA_2024 โ€” France SREN Law & EU Digital Services Act compliance
  • GREECE_DSA_2024 โ€” Greece Child Protection & EU Digital Services Act compliance
  • SPAIN_DSA_2024 โ€” Spain Child Protection & EU Digital Services Act compliance
๐ŸŒ Asia-Pacific (3 Regions) โ€” Australia, Indonesia, Malaysia
  • AUSTRALIA_ESAFETY_2026 โ€” Australian eSafety Commissioner compliance
  • INDONESIA_GR17_2026 โ€” Indonesian Ministry of Communication and Digital (Kemenkomigi) Government Regulation No. 17 of 2025 compliance
  • MALAYSIA_ONSA_2025 โ€” Malaysian Communications and Multimedia Commission (MCMC) Online Safety Act 2025 compliance
๐ŸŒŽ Americas (1 Region) โ€” Brazil
  • BRAZIL_ECA_2026 โ€” Brazil Digital Statute of the Child and Adolescent (ECA) compliance
๐Ÿ•Œ Middle East (1 Region) โ€” United Arab Emirates
  • UAE_CABINET_RESOLUTION_106 โ€” UAE Cabinet Resolution No. 106 Under-15 Social Media Ban compliance
๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom (1 Region) โ€” United Kingdom
  • UK_LAW_2026 โ€” UK Online Safety Act compliance
Screenshot #24

11 Category-Based Blocking

In addition to blocking 72 individual platforms by name, LexMatrix Guard enforces 6 restricted categories that catch unknown or emerging apps by their type. Even if a niche app isn't in our 72-platform list, category blocking ensures it's still blocked based on what kind of app it is.

11.1 Restricted Categories

CategoryDescriptionDefault State
Social MediaSocial networking apps (Facebook, Instagram, TikTok, etc.)LOCKED
Live-StreamingLive broadcast platforms (Twitch, Kick, DLive, Trovo)LOCKED
Gaming/SocialGaming platforms with social features (Roblox, Fortnite, Minecraft, VRChat)LOCKED
Anonymous SocialAnonymous/ephemeral social apps (Whisper, NGL, Yik Yak, Sarahah)LOCKED
AI/SocialAI companion and social AI apps (Character.ai, Replika, Chai)LOCKED
Video/StreamingVideo sharing and streaming platforms (YouTube, Bilibili, Dailymotion, Rumble)TIMED

11.2 How Category Blocking Works

11.3 Toggling a Category

  1. Scroll to the "Category-Based Blocking" section in the dashboard.
  2. Find the category you want to change.
  3. Click the desired state button: ALLOW, BLOCK, or TIMED.
  4. Enter your 6-digit Security PIN in the modal.
  5. Click "VERIFY & ENFORCE" to confirm.
Why category blocking matters: New niche apps appear on app stores every day. By the time a platform is added to our 72-platform list, your child may have already installed it. Category blocking closes this gap by blocking any app in a restricted category, even if we've never seen it before.
Screenshot #25

12 DNS-Level Category Filtering

LexMatrix Guard maintains a DNS domain blocklist on iOS devices that mirrors your category and platform blocking settings. When the iOS Network Extension is active, DNS queries for blocked domains are intercepted and resolved to NXDOMAIN, preventing the child from reaching restricted sites via alternative DNS servers, VPN apps that route DNS externally, or DNS-over-HTTPS (DoH) / DNS-over-TLS (DoT) services.

12.1 How DNS Filtering Works

When category or platform blocking is active on iOS and the Network Extension is operational, the enforcement app intercepts DNS queries and blocks resolution of any domain in the DNS blocklist. Blocked queries receive an NXDOMAIN response, causing the device to believe the domain does not exist โ€” rather than simply timing out.

The DNS blocklist is maintained on all plans, but network-level interception only occurs when the iOS Network Extension is active. When the extension is not active, domain matching is still performed at the app level. DNS filtering is currently supported on iOS devices only.

12.2 The DNS Filtering Status Card

The dashboard displays a "DNS FILTERING" status card in the Mobile Protection section (visible only for iOS devices), next to the Core Legislation Layer and Device Integrity cards. The card shows one of the following states:

The card also shows the resolver type โ€” Network Extension for iOS โ€” based on the child's device platform.

Why DNS filtering matters: Tech-savvy children can bypass app-level blocking by configuring their device to use alternative DNS servers (like Google DNS or Cloudflare DNS) that resolve blocked domains anyway. DNS-level filtering closes this loophole by intercepting all DNS traffic inside the enforcement tunnel and blocking resolution of restricted domains at the network level.
Important limitation: If no active iOS Network Extension is present, DNS-level interception cannot occur. In this case the status card will show CONFIGURED or MONITORING_ONLY, and domain blocking is limited to app-level matching. A technically capable child may bypass network-level filtering in this state. App-level blocking and browser URL checking remain enforced regardless of DNS state.
Screenshot #26

13 Installed App Inventory & New-App Alerts

LexMatrix Guard scans your child's device every 30 minutes and reports all installed apps to your dashboard. This gives you complete visibility of what's on your child's device, not just the platforms you've explicitly configured.

Prerequisite โ€” Telemetry Consent: App inventory reporting requires that Telemetry Consent is enabled in your dashboard. Go to the Telemetry Consent section (above the Installed App Inventory section) and toggle it ON. The child's device syncs this setting automatically in real time. If consent is not granted, no app inventory data will be reported and the section will remain empty.

13.1 The App Inventory Section

The "Installed App Inventory" section appears on the dashboard below the Platform Interaction Audit. It lists every non-system app installed on your child's device, sorted alphabetically, showing:

Screenshot #27

13.2 New-App Alerts

When the device scan detects a new app that isn't in the known platform map, LexMatrix Guard immediately sends you a NEW_APP_DETECTED alert. The alert appears as a banner at the top of the dashboard and includes:

You must enter your Security PIN to classify the app. Once classified, the enforcement app on the child's device receives the update in real time.

Why this matters: Children often download niche or regional apps (e.g. Rednote, Yope, Lemon8) that aren't yet on any blocklist. The app inventory scan ensures no new app goes unnoticed โ€” you'll know within 30 minutes of installation.
Screenshot #28

14 Community-Sourced Blocklist & Watch List

The Community-Sourced Blocklist lets parents crowdsource threat discovery. When a parent discovers a suspicious app that isn't in the 72-platform list or a restricted category, they can report it to the community. Once enough parents in the same region report the same app, it's automatically promoted to a watch list and all other parents in that region receive an alert.

14.1 Reporting an App

  1. Find the app you want to report in the Installed App Inventory section (see Section 13).
  2. Click the "REPORT" button next to the app.
  3. A confirmation modal appears showing the app name and asking you to confirm the report.
  4. Click "CONFIRM REPORT" to submit.

The report is sent to the reportCommunityApp Cloud Function, which records it in the community_blocklist Firestore collection, scoped to your region.

Double-reporting prevention: Each parent can only report a specific app once. The system tracks which parents have already reported an app and prevents duplicate reports.

14.2 How Promotion Works

14.3 Community Watch List Alerts

When an app is promoted to the watch list, the alert on your dashboard shows:

Community-powered protection: This feature means that even brand-new niche apps are flagged by the community before they go viral. If a parent in your region discovers a risky app, you'll know about it automatically โ€” without having to monitor app stores yourself.
Screenshot #29

15 Behavioral Classification & Alerting

LexMatrix Guard uses accessibility event pattern analysis on Android to detect when an unclassified app is behaving like a social media platform. Even if an app isn't in the 72-platform list or a restricted category, the behavioral classifier can flag it based on its UI patterns.

15.1 What It Detects

The BehavioralClassifier on Android monitors accessibility events (window state changes, content changes, view clicks) and looks for three behavioral patterns:

15.2 Behavioral Alert Banner

When a behavioral pattern is detected, a BEHAVIORAL_FLAG alert appears on the dashboard with:

Alerts use a 30-minute cooldown to prevent spam. If you tap BLOCK App, the app is added to the behavioralFlags list and will be blocked on the child's device in real time.

Why this matters: New social apps appear constantly, often disguised as utilities or games. Behavioral classification catches apps that behave like social media even if they're not categorized as such.

17 Gaming Lobby Chat Detection

Many gaming platforms (Roblox, Fortnite, Minecraft, Rec Room, VRChat) have in-game chat systems that children use for unmoderated communication. LexMatrix Guard's GamingChatDetector on Android analyzes the accessibility node tree to detect chat UI patterns within these gaming apps.

17.1 What It Detects

The detector looks for gaming-specific chat UI elements:

17.2 Gaming Chat Alert

When chat UI is detected in a gaming app, a GAMING_CHAT_DETECTED alert is created with a 5-minute cooldown. The alert banner shows:

If the gaming app is already in the blocked set, the enforcement service shows a lock screen overlay when chat is detected.

Why this matters: Gaming lobby chat is one of the primary ways children bypass social media bans. They migrate to gaming platforms and use in-game chat as a social network substitute.

18 Messenger Feature-Level Blocking

WhatsApp and Telegram are exempt from legal bans so children can communicate with family. However, their Communities, Channels, and Public Groups features are used by children to join unmoderated mass-communication spaces. LexMatrix Guard can block access to these specific features within the apps, without blocking the apps entirely.

18.1 Blockable Messenger Features

FeatureAppWhat It Does
WhatsApp CommunitiesWhatsAppBlocks access to community group feeds and discovery
WhatsApp ChannelsWhatsAppBlocks access to broadcast channels and following
Telegram ChannelsTelegramBlocks access to broadcast channels and join/view
Telegram GroupsTelegramBlocks access to public group join and view

18.2 How It Works (Android)

The MessengerFeatureBlocker analyzes the accessibility node tree for known UI patterns (tab labels, screen titles, button texts) associated with restricted features. When a restricted feature is detected:

  1. The enforcement service presses the Back button to navigate the child away from the restricted feature
  2. A MESSENGER_FEATURE_BLOCKED alert is created with a 10-minute cooldown
  3. An FCM push notification is sent to the parent

18.3 How It Works (iOS)

On iOS, the Screen Time API does not support feature-level blocking within apps. When any messenger feature block is active, LexMatrix Guard blocks the entire app (WhatsApp or Telegram) as a fallback.

18.4 Messenger Feature Alert Banner

The alert banner on the dashboard shows (in blue):

Family communication preserved: Direct messaging (1-on-1 chats with family and friends) remains fully accessible. Only Communities, Channels, and Public Groups are blocked.

19 Tamper Alerts & Alert History

19.1 Active Tamper Alert Banner

When your child disables the enforcement service on their device, a red, pulsing TAMPER ALERT banner appears at the top of the dashboard. It shows:

Screenshot #30

19.2 Stale Heartbeat Warning

If the child's device hasn't sent a heartbeat in over 10 minutes (but no tamper alert has been triggered), an amber warning appears: "No heartbeat from child device in over 10 minutes."

Screenshot #31

19.3 Tamper Alert History

At the bottom of the dashboard, the TAMPER ALERT HISTORY section shows a complete log of all alerts. The list shows the 5 most recent alerts by default. If there are more than 5, you can scroll vertically within the list to see older entries.

Each alert entry shows:

Screenshot #32

20 SIM Detection & Device-Switch Alerts

LexMatrix Guard monitors your child's SIM card state in real time. If the SIM card is removed, swapped for a different one, or the child switches to an entirely different device, an instant alert is sent to your parent dashboard. This prevents children from bypassing enforcement by moving their account to a new, unmonitored device.

20.1 How SIM Monitoring Works

The mobile enforcement app records a cryptographic hash of the child's SIM card at sign-in time and stores it as the authorized SIM hash on the server. On every heartbeat (every 30 seconds), the app checks the current SIM state and compares it to the authorized hash:

When any of these events is detected, a tamper alert is written to the child's alert history and a push notification is sent to the parent's devices immediately.

20.2 Accepting or Rejecting a SIM Change

When a SIM_CHANGED alert appears on the dashboard, two PIN-gated buttons are shown:

Both actions require your 6-digit Security PIN, which is verified server-side by the authorizeSimChange Cloud Function.

Important: Rejecting a SIM change does not automatically restore enforcement on the new SIM. The alert is marked as escalated and remains visible on your dashboard. You should contact your child and verify the situation before accepting.

20.3 SIM Alerts in Alert History

SIM-related alerts appear in the Tamper Alert History feed at the bottom of the dashboard, alongside other tamper alerts. Each SIM alert shows:

Screenshot #33

21 Desktop Enforcer Daemon

The Desktop Enforcer Daemon is a lightweight background program that runs on your child's Windows, macOS, or Linux computer and terminates forbidden applications at the operating system level โ€” even if they are launched outside the browser. This works alongside the browser extension to provide complete desktop coverage.

21.1 What It Does

21.2 How to Install

The daemon is designed for non-technical parents โ€” no manual configuration required.

  1. Open the browser extension popup on your child's computer (after pairing).
  2. The popup automatically detects the child's operating system and architecture (e.g., "Windows 64-bit").
  3. Click the "Download Desktop Enforcer" button.
  4. Two files will download: the daemon binary and a daemon_config.json file.
  5. Place both files in the same folder on the child's computer.
  6. Run the daemon binary (double-click the .exe on Windows).
Automatic OS detection: The extension popup detects whether the child's computer is Windows (64-bit/ARM/32-bit), macOS (Intel/Apple Silicon), or Linux (64-bit/ARM) and downloads the correct binary automatically. You don't need to know the architecture.

21.3 Desktop Enforcer Alert Banner

When the daemon terminates a forbidden executable, a green DESKTOP ENFORCER banner appears on the parent dashboard. It shows:

Screenshot #34

21.4 Anti-Tamper Protection (Windows)

On Windows, the daemon installs three independent layers of persistence to prevent your child from disabling it:

LayerWhat It Does
Windows ServiceAuto-starts on boot. If the child kills the process via Task Manager, Windows automatically restarts it within 30 seconds.
Scheduled Task WatchdogRe-launches the daemon every 5 minutes if it's not running. Survives even if the service is deleted.
Registry Run KeyAuto-launches the daemon when the child logs into their Windows account.
What if my child deletes the daemon file? If the binary is deleted, all three persistence layers will fail. However, the parent dashboard will show a DESKTOP_HEARTBEAT_STALE tamper alert within 3 minutes because the daemon stops sending heartbeats. You'll know immediately that something is wrong.

21.5 macOS & Linux Persistence

On macOS, the daemon installs a LaunchAgent plist at ~/Library/LaunchAgents/com.lexmatrix.guard.plist with KeepAlive set to true. This ensures the daemon auto-starts when the child logs in and is automatically restarted if killed.

On Linux, a systemd user service is installed at ~/.config/systemd/user/lexmatrix-guard.service with Restart=always, providing the same auto-start and restart-on-crash behaviour.

Config file security: The daemon_config.json file is created with 0600 permissions (owner read/write only) to prevent other users on the system from reading the daemon's Ed25519 key material (or legacy HMAC secret).

21.6 Improved Process Matching

The daemon doesn't just match by binary name โ€” it also checks alias names for each target platform. This catches renamed binaries, portable variants, and beta/canary builds. For example:

On Windows, the daemon also detects WSL (Windows Subsystem for Linux) processes. If wsl.exe is running, the daemon checks Linux processes inside the WSL container for blocked platform binaries.

21.7 Daemon Heartbeat on the Dashboard

The daemon's heartbeat appears in the Desktop Protection section of the dashboard, alongside the browser extension's heartbeat. The device card shows:

Silent enforcement mode: If the daemon_config.json file is missing, the daemon still runs and terminates forbidden executables โ€” it just can't send alerts or heartbeats to the cloud. This ensures enforcement continues even if the config file is accidentally deleted.

21.8 Alert History

Daemon block events also appear in the Tamper Alert History feed at the bottom of the dashboard, tagged with a green DESKTOP DAEMON badge so you can distinguish them from browser extension and mobile app alerts.

Screenshot #35

22 Security PIN Management

Your 6-digit Security PIN protects all sensitive actions on the dashboard and is required to sign out of the enforcement app on your child's device. You can change your PIN at any time.

Changing Your PIN

  1. Click the "SET PIN" button in the navigation bar.
  2. Enter your new 6-digit PIN in the "NEW PIN" field.
  3. Re-enter the same PIN in the "CONFIRM PIN" field.
  4. Click "SAVE PIN".
  5. A green "Security PIN set successfully" message confirms the change.
Choose a PIN your child cannot guess. Avoid birthdays, 123456, 000000, or any number your child knows. The PIN is the last line of defence against your child disabling enforcement.
Screenshot #36

23 Signing Out of the PWA

Signing out of the parent dashboard requires your Security PIN for security.

  1. Click "SIGN OUT" in the navigation bar.
  2. Enter your 6-digit Security PIN in the modal.
  3. Click "VERIFY & ENFORCE" to sign out.

If you enter the wrong PIN, an "Incorrect security PIN" error appears and you can try again.

Screenshot #37

24 Installing the Android Enforcement App

The Android enforcement app runs on your child's Android phone (Android 8.0 / API 26 or later). It uses an Accessibility Service to detect and block app launches, and Device Admin to prevent uninstallation.

24.1 Installation Steps

  1. Install the LexMatrix Guard app on your child's Android phone (via APK or Play Store when available).
  2. Open the app. The setup wizard will appear.
  3. Tap "Enable Accessibility Service" โ€” you'll be taken to Android Settings โ†’ Accessibility.
  4. Find "LexMatrix Guard" in the list and enable it.
  5. Return to the app and tap "Enable Device Admin" โ€” confirm the Device Admin prompt.
  6. Tap "Continue".
Device Admin prevents uninstallation. Once enabled, your child cannot uninstall the app without the Device Admin password. This is intentional โ€” it prevents bypassing enforcement by removing the app.
Screenshot #38
Screenshot #39
Screenshot #40

24.2 Battery Optimisation

Some Android manufacturers (Xiaomi, Oppo, Vivo, Samsung) aggressively kill background services to save battery. To ensure reliable enforcement:

Split-screen protection: The app also detects split-screen and multi-window attempts to access blocked apps. The lock screen will appear even in multi-window mode.

25 Installing the iOS Enforcement App

The iOS enforcement app runs on your child's iPhone or iPad (iOS 16.0 or later). It uses Apple's Family Controls (Screen Time API) to block apps at the OS level.

25.1 Installation Steps

  1. Install the LexMatrix Guard app on your child's iPhone (via TestFlight or App Store when available).
  2. Open the app. It will request Family Controls permission.
  3. Tap "Allow" on the iOS permission dialog.
  4. The app will sign in and start listening for policy changes.
How iOS enforcement works: When a platform is locked, iOS shows a shield screen when your child tries to open the blocked app. The app icon may appear greyed out with an hourglass symbol. This is Apple's built-in Screen Time enforcement โ€” it cannot be bypassed by the child.

Screenshot #41
Screenshot #42
Screenshot #43

26 Signing In on the Child's Mobile Device

After installing the enforcement app on your child's device, you need to sign in using the child's credentials that were generated when you created their profile (see Section 4.2).

Steps

  1. Open the LexMatrix Guard app on the child's device.
  2. Enter the child's email (the long generated email from the "Child Profile Created" notice).
  3. Enter the password you set when creating the child profile.
  4. Sign in.
Need the email? On the parent dashboard, create a new child profile or check your saved credentials. You can use the "COPY EMAIL" button to copy it to your clipboard and paste it into the mobile app.
What happens after sign-in: The app connects to the cloud, downloads the current policy for that child, and begins enforcing it. It also starts sending heartbeats so the parent dashboard shows the device as online.
Screenshot #44

27 How Mobile Enforcement Works

Once signed in, the enforcement app runs silently in the background. Here's what happens:

27.1 App Blocking

Screenshot #45

27.2 Timed App Usage

For TIMED apps (Twitch, YouTube), the child can use them freely until the time budget runs out. The mobile app reports usage to the server every 30 seconds. When the budget is exhausted, the app is automatically locked.

Additionally, the Parent-Controlled Platforms (Discord, Telegram, and WhatsApp) can be set by the parent to a TIMED state on the dashboard. When set to TIMED, they are subject to this same hourly Time Wallet budget and will be automatically locked as soon as the wallet exhausts.

27.3 Tamper Detection (Android)

27.4 Tamper Detection (iOS)

Screenshot #46
Screenshot #47

28 Signing Out from the Mobile App

Signing out from the enforcement app on the child's device requires the parent's Security PIN. This prevents children from disabling enforcement by signing themselves out.

Steps

  1. Open the LexMatrix Guard app on the child's device.
  2. Tap "Sign Out" on the enforcement screen.
  3. Enter the parent's 6-digit Security PIN.
  4. Confirm sign-out.

After Sign-Out (Android)

A "Protection Disabled" screen appears with instructions to disable Accessibility in Settings. The parent can re-enable protection at any time by tapping "Re-enable Protection".

Only sign out when necessary. While signed out, the child's device is not enforced. Always sign back in after maintenance or device changes.
Screenshot #48
Screenshot #49

29 Troubleshooting & FAQ

Q: The dashboard shows "CONNECTING" and never changes to "HEARTBEAT_OK"

The child's device hasn't sent a heartbeat yet. Check that:

Q: I see "HEARTBEAT_STALE" โ€” what should I do?

The child's device hasn't reported in over 10 minutes. The device may be:

Q: My child disabled the Accessibility Service (Android)

The app's AccessibilityGuardService should detect this and lock the device. You'll see a TAMPER_DETECTED alert on the dashboard. On the child's device, a full-screen lock prevents use until the Accessibility Service is re-enabled. Go to Settings โ†’ Accessibility โ†’ LexMatrix Guard โ†’ ON to restore enforcement.

Q: The lock screen isn't appearing on Android

Q: I forgot my Security PIN

Contact LexMatrix Guard support. For security reasons, PIN reset is not available through the app interface.

Q: Can my child reset the time budget by clearing app data?

No. Time usage is tracked server-side. The mobile app reports usage every 30 seconds, and clearing app data does not affect the server's record of accumulated usage.

Q: Can my child uninstall the enforcement app?

Q: What happens if I lose internet on my phone (parent)?

The dashboard will not update in real time, but enforcement continues on the child's device โ€” it operates independently based on the last received policy. When your internet returns, refresh the dashboard to see the latest status.

Q: What happens if my child's device loses internet?

The enforcement app continues to enforce the last received policy offline. The dashboard will show HEARTBEAT_STALE after 10 minutes. When the device reconnects, it resumes sending heartbeats and the dashboard updates automatically.

Q: Can I use the same parent account on multiple devices?

Yes. Sign in to the PWA on any browser/device with your parent email and password. The dashboard syncs in real time.

Q: The "+15 MIN UPLINK" or "+1 HR UPLINK" button isn't working

Check for a red error banner below the child selector โ€” it will show any policy save errors. Ensure you have a stable internet connection and try the REFRESH button. If the buttons are greyed out, the time budget has already reached the 360-minute (6 hour) maximum.

Q: The desktop daemon isn't showing up on the dashboard

If the daemon is running but the dashboard doesn't show a heartbeat:

Q: My child killed the daemon via Task Manager โ€” what happens?

On Windows, the Windows Service layer automatically restarts the daemon within 30 seconds. If the service is also disabled, the Scheduled Task watchdog re-launches it within 5 minutes. If both fail, you'll receive a DESKTOP_HEARTBEAT_STALE tamper alert within 3 minutes.

Q: Can my child delete the daemon?

The child can delete the binary file, but this breaks all persistence layers and stops heartbeats โ€” triggering a DESKTOP_HEARTBEAT_STALE alert on your dashboard within 3 minutes. You'll know immediately that the daemon has been tampered with. Re-download it from the browser extension popup.

Q: I see a "SIDELOADED_APP_DETECTED" alert โ€” what does this mean?

Your child has installed an app from a source other than the official Play Store (Android) or App Store (iOS). This is called "sideloading" and can be a security risk. The alert shows which app was sideloaded and its installer source. You can block the app directly from the alert banner on the dashboard.

Q: I see a "STALE_TIMED_USAGE" alert โ€” what does this mean?

Your child's device is online and sending heartbeats, but the timed usage reporter has stopped reporting for more than 10 minutes while the child still has remaining timed budget. This may indicate the child has found a way to interfere with the usage tracking service. Check the child's device to ensure the enforcement app is running properly and hasn't been tampered with.

Q: How will the iOS App be installed once available?

Once compiled on a macOS environment using Xcode, the iOS Enforcement App can be deployed via TestFlight or Apple Developer provisioning profiles. During setup, the child's device will prompt to enable the Family Controls API. This configuration requires the parent's Apple ID password to confirm and prevent the child from deleting or disabling the app.

Q: How does the UAE region regulation work?

UAE Cabinet Resolution No. 106 imposes age restrictions on social media platforms for children under 15 years old. When you select the UAE region during parent sign-up or profile creation, the legal compliance shield automatically configures the platform access defaults to align with this under-15 legal ban.

Q: Can I manage children in different regulatory regions on one account?

Yes. Each child profile has its own settings. The platform automatically tracks and enforces the correct local compliance rules (Australia, Brazil, UAE, or UK) based on the region selected when you create or edit the child's profile on the dashboard.

30 Recent Integrations, Security Updates & PWA Dashboard Upgrades

This section summarises the integrations and security hardening released in recent updates. It covers the new Indonesia and Malaysia compliance regions, PWA dashboard upgrades, and client-hardening features that parents should know about.

30.1 Indonesia & Malaysia Regional Compliance

LexMatrix Guard now supports two additional compliance regions, bringing the total to six:

During parent sign-up and when creating or editing a child profile, select the correct compliance region so the correct legal floor and regional defaults are loaded. Region-specific bans (for example YouTube and Twitch locked in the UAE, Brazil, Indonesia and Malaysia) are enforced automatically.

30.2 PWA Dashboard Upgrades

The parent dashboard has received a number of new controls and status indicators:

30.3 Security Audit Frontend Hardening

Following the LexMatrix Guard security audit, several parent-facing and client-facing protections were added or strengthened:

30.4 Browser Extension & Desktop Daemon Updates

30.5 Mobile App Updates

30.6 BOCHA Identity Airlock

BOCHA ("Bring Our Children Home Again") is the dashboard indicator that LexMatrix Guard is acting as an on-device digital airlock. By blocking banned platform domain handshakes locally before any connection resolves, the system prevents Big Tech's age-verification prompts from requesting your child's passport scans, eID links or biometric facial sweeps. The card shows Identity Protection: Sovereign / Anonymous and Biometric Prompts: Pre-empted (0 Loaded) while the airlock is active.

31 Glossary

TermMeaning
PWAProgressive Web App โ€” a web app that installs like a native app on your phone's home screen
Enforcement AppThe mobile app installed on the child's device that blocks apps and enforces policies
Global ShieldThe master toggle for legally-banned platform enforcement
Kill SwitchEmergency toggle to disable non-banned platform blocking remotely
Security PIN6-digit code required for all sensitive actions (toggles, lockdown, sign-out)
HeartbeatPeriodic signal from the child's device confirming it's online and enforcement is active
Tamper AlertAlert triggered when the child disables or interferes with the enforcement service
Time AllocationThe shared time budget for TIMED platforms (Twitch, YouTube)
LOCKEDPlatform is completely blocked โ€” the child cannot open it
TIMEDPlatform is allowed but limited by the time budget
ALLOWEDPlatform is freely accessible (e.g. exempt apps like WhatsApp)
Accessibility ServiceAndroid system feature used to detect and block app launches
Family ControlsApple's Screen Time API used on iOS to block apps at the OS level
Device AdminAndroid feature that prevents the app from being uninstalled
Child Auth AccountDedicated sign-in credentials for a child's device (cannot modify policies)
Active BlocksRead-only data on the cloud that the mobile app reads to know which apps to block
Category Blocking6 restricted categories (Social Media, Live-Streaming, Gaming/Social, Anonymous Social, AI/Social, Video/Streaming) blocked by default to catch unknown apps by type
DNS FilteringCategory-aware DNS blocking at the network level. Intercepts DNS queries in the VPN tunnel (Android) or Network Extension (iOS) and blocks resolution of restricted domains, preventing circumvention via alternative DNS servers
NXDOMAINA DNS response code indicating the queried domain does not exist. Used by DNS filtering to block restricted domains
DoH/DoTDNS-over-HTTPS / DNS-over-TLS โ€” encrypted DNS protocols that can bypass traditional DNS filtering. LexMatrix Guard blocks 20 known DoH/DoT endpoints to prevent circumvention
App InventoryA complete list of all non-system apps installed on the child's device, scanned every 30 minutes and displayed alphabetically on the dashboard
New-App AlertAlert triggered when the device scan detects an app not in the known platform map, with one-tap BLOCK/TIMED/ALLOW buttons
Community BlocklistA region-scoped, parent-sourced list of reported apps. When 3 parents report the same app, it's promoted to the watch list and alerts are sent to all parents in that region
Watch ListStatus given to a community-reported app after 3 reports. Triggers alerts to all parents in the region whose children have the app installed
Behavioral ClassificationPhase 4 feature that analyzes accessibility event patterns on Android to detect apps behaving like social media (social feed UI, messaging infrastructure, profile systems). Alerts the parent with a BEHAVIORAL_FLAG alert
Trending Social AppPhase 4 feature that polls the Apple App Store RSS feed daily for trending Social Networking apps across five regions (AU, UK, AE, US, GB). Alerts parents whose children have newly trending apps installed
Gaming Chat DetectionPhase 4 feature that detects in-game chat UI in Roblox, Fortnite, Minecraft, Rec Room, and VRChat via accessibility node tree analysis. Creates GAMING_CHAT_DETECTED alerts with 5-minute cooldown
Messenger Feature BlockingPhase 4 feature that blocks access to WhatsApp Communities/Channels and Telegram Channels/Groups within the apps. On Android, presses Back to navigate away. On iOS, blocks the entire app as a fallback
Desktop Enforcer DaemonA lightweight Go background program that terminates forbidden executables at the OS level on Windows, macOS, and Linux. Auto-downloaded from the browser extension popup with OS detection. Authenticates with Cloud Functions using Ed25519 asymmetric keys (auto-migrated from legacy HMAC-SHA256) and sends signed block events and heartbeats
daemon_config.jsonConfiguration file generated by the browser extension during pairing, containing the device's parentId, childId, deviceId, daemonSecret (legacy) or Ed25519 key material, and Cloud Function URLs. Placed alongside the daemon binary so it can authenticate with the backend
Ed25519 Device AuthAsymmetric key authentication used by the browser extension and desktop daemon. Private keys are generated as non-extractable CryptoKey objects (browser) or stored in encrypted config (daemon). The server verifies signatures using the registered public key, eliminating the need to transmit or store raw shared secrets
Per-Device Usage AccountingEach child device writes timed usage to its own sub-document under timed_usage/current/devices/. The server sums across all devices via sumDeviceUsage(), preventing multiple devices from double-draining a single time budget
Monotonic ClockA clock that never goes backwards, used for timed-budget calculations. Android uses SystemClock.elapsedRealtime(), iOS uses ProcessInfo.systemUptime, and the browser extension uses performance.now(). Prevents children from extending timed access by changing the device wall clock
daemonSecretA 64-byte hex secret generated during device pairing, used for legacy HMAC-SHA256 authentication between the Go daemon and Cloud Functions. The daemon auto-migrates to Ed25519 asymmetric keys on startup; the server supports both during the transition period. Stored in Firestore on the device doc and delivered to the daemon via daemon_config.json
DESKTOP_DAEMON_BLOCKEDAlert type created when the Go daemon terminates a forbidden executable. Displayed as a green "DESKTOP ENFORCER" banner on the parent dashboard with the platform name and binary details
Anti-Tamper PersistenceThree-layer Windows defense preventing the child from disabling the daemon: Windows Service (auto-start + restart-on-failure), Scheduled Task watchdog (re-launches every 5 min), and Registry Run key (auto-launch on login). macOS uses LaunchAgent with KeepAlive; Linux uses systemd with Restart=always
Sideloaded App DetectionSecurity feature that tracks the installer source of each app on the child's device. Apps installed from non-Play Store or non-App Store sources (sideloaded) trigger SIDELOADED_APP_DETECTED alerts with FCM push notifications to the parent
Stale Timed UsageAlert type triggered when a child has remaining timed budget and the device is actively heartbeating, but timed usage reporting has stopped for >10 minutes. Indicates potential client-side bypass of usage reporting
App CheckFirebase App Check enforcement โ€” verifies app integrity on all callable Cloud Functions in production via ENFORCE_APP_CHECK environment variable. Predeploy script blocks deployment if not set
Enterprise PoliciesChrome/Edge/Firefox managed policy templates for enterprise deployments: force-install extension, block removal, disable incognito/guest mode, disable developer tools. See browser-extension/ENTERPRISE-POLICIES.md
Webhook IdempotencyStripe and PayPal webhook event IDs are stored in the webhook_events Firestore collection to prevent duplicate invitation code generation from webhook retries
SIM DetectionReal-time monitoring of the child's SIM card state. Detects SIM removal, SIM swaps, and device switches by comparing a cryptographic hash of the current SIM against the authorized hash stored on the server
SIM_REMOVEDAlert type triggered when the SIM card is physically removed from the child's device
SIM_CHANGEDAlert type triggered when a different SIM card is inserted (the hash no longer matches the authorized hash). Parent can ACCEPT or REJECT the change via PIN-gated buttons
DEVICE_SWITCH_DETECTEDAlert type triggered when the child's account is signed in on a different device, indicating a potential attempt to bypass enforcement by migrating to a new phone
authorizeSimChangeCloud Function that processes parent ACCEPT or REJECT actions on SIM change alerts. Requires 6-digit PIN verification. ACCEPT updates the authorized SIM hash; REJECT marks the alert as escalated
Device ModeA per-child setting ('mobile_only' or 'mobile_desktop') selected during parent sign-up and toggleable via PIN-gated dashboard switch. When set to 'mobile_only', the Desktop Protection section is hidden, desktop device subscriptions and heartbeat polling are skipped, and server-side desktop alert generation is suppressed via the isMobileOnly() helper
isMobileOnly()Server-side helper in functions/lib/notifications.js that checks a child document's deviceMode field. Returns true when deviceMode === 'mobile_only', allowing Cloud Functions to skip desktop alert generation for mobile-only families