FlySport Child Safety Standards
FlySport is built specifically for youth mountain bike teams. Many of our users are minors, some under 13. This document explains the standards we hold ourselves to, how we enforce them in code, and how to reach us if something goes wrong. If you're a parent, coach, or league director, this is the page to read first.
1. Our commitment
FlySport exists because youth mountain biking deserves better tools than a group text and a shared Google Sheet. The athletes are kids. That puts the bar higher than it would be on a general-purpose app. We treat child safety as the first design constraint, not the last review item.
Specifically, we commit to:
- Building safety controls into the database, not on top of it. The rules below are enforced server-side, before content reaches another user.
- Never selling, renting, or sharing data about minors with advertisers or marketing partners. Ever.
- Responding to credible safety reports within one business day.
- Reporting suspected child sexual abuse material (CSAM) to the National Center for Missing & Exploited Children (NCMEC) as required by 18 U.S.C. § 2258A.
- Cooperating with law enforcement on lawful requests related to child safety.
- Publishing an annual summary of enforcement activity (see Section 8).
2. What we prohibit
The following behavior and content is prohibited on FlySport. Accounts that engage in this content are subject to immediate suspension and, where applicable, reporting to law enforcement.
Sexual content involving minors
- Any sexually explicit text, image, video, audio, or link involving a person under 18.
- Grooming behavior: cultivating a private, trust-based relationship with a minor for the purpose of sexual contact, requests for images, or in-person meetings outside team activities.
- Solicitation of nude or sexually suggestive images of minors.
- Sharing of, or links to, child sexual abuse material (CSAM) of any kind.
Other prohibited conduct
- Sexual harassment of any user.
- Bullying, threats, intimidation, or coordinated harassment of athletes, coaches, parents, or league staff.
- Doxing: sharing another user's home address, school name, phone number, family identity, or other identifying information without consent.
- Hate speech targeting race, ethnicity, national origin, religion, disability, gender, gender identity, sexual orientation, or other protected characteristic.
- Violent content or threats of physical harm.
- Content promoting self-harm or suicide, or that disparages people who have experienced either.
- Sale or solicitation of regulated goods (alcohol, tobacco, vapes, firearms, prescription drugs, controlled substances) to minors.
- Spam, scams, phishing, or impersonation of another user, coach, or team.
3. How we enforce it
Enforcement runs in three layers. None of them depend on user-side toggles. A coach cannot disable them; a parent cannot disable them; the user posting the content cannot disable them.
Layer 1: automated moderation at post-time
Every message posted in a team-scoped channel where any participant is a minor passes through automated content moderation (OpenAI Moderation API) before it lands. Messages flagged for sexual content involving minors, severe harassment, hate speech, or self-harm are stamped with the flag, severity, and the model's reasoning. Severity-high flags page the team's Head Coach and Team Director in real time.
Layer 2: nightly conversational review
A separate process runs each night across channels containing minors. It reads conversational context — multiple messages in sequence, not just single-message keyword matches — and surfaces patterns that single-message moderation misses (grooming arcs, coercion patterns, escalating threats). Findings are routed to the Team Director, Head Coach, and the League Director responsible for the team.
Layer 3: audit and human review
Every flagged message is preserved in an immutable audit log even if the author deletes it. Team Directors, Head Coaches, and League Directors see a flag dashboard that lists current and historical flags for the channels they administer. Deletions are visible to those reviewers.
What happens to violators
- First-level flags (mild harassment, off-topic adult content): warning logged, the team's Head Coach is notified, the user is contacted.
- Repeat offenses or severity-high flags: account suspended pending review by Limestone Labs LLC. The user's coach, team director, and league director are notified.
- Sexual content involving minors, credible grooming behavior, CSAM: account immediately locked. We preserve evidence, report to NCMEC, and cooperate with law enforcement. We do not engage in "just delete it" resolutions for this category.
4. Adult-minor interaction guardrails
Coaches, parents, and league staff regularly need to communicate with minor athletes. We allow that, but with structural controls that are enforced in the database itself, not in policy alone.
- No 1-on-1 adult-minor DMs. The database refuses to create a private 1-on-1 channel between any adult and any minor. This is enforced at the channel-creation level: not a setting, not a toggle, not a workflow rule. The table will not accept the row.
- Two-adult floor on minor channels. Any group channel that contains at least one minor must also contain at least two adults. The second adult is a witness. If an adult leaves and the count drops below two, the channel is locked until another adult joins or the minor leaves.
- Full audit trail. Messages in adult-minor channels are retained and reviewable by the Team Director, Head Coach, and League Director regardless of deletion by the author.
- Parental-consent gate. Athletes under 13 cannot sign in until a parent or legal guardian grants verifiable parental consent through a signed e-form. Until that consent exists, the under-13's account has zero application access. See Section 6 and the Privacy Policy for the full mechanism.
- Lapsed-certification lockout. Coaches whose required safety, background-check, or first-aid certifications lapse are automatically restricted to a compliance-only channel with their Head Coach and Team Director. They cannot DM, post in team channels, or access roster details until certifications are restored.
5. Reporting child sexual abuse material (CSAM)
Report CSAM immediately
If you encounter what you believe to be CSAM on FlySport, or any other content depicting the sexual abuse or exploitation of a minor, report it to us right away:
- Email: child-safety@limestonelabs.cc (monitored daily; urgent reports get same-day response).
- In the app: long-press the message, tap Report, choose CSAM / sexual content involving a minor. Reports route directly to our safety queue.
- Imminent danger to a child: call 911 (United States) first, then report to us.
You may also report directly to the National Center for Missing & Exploited Children (NCMEC) CyberTipline or call 1-800-843-5678. We encourage parallel reporting for urgent situations.
What happens after you report
- We acknowledge receipt within one business day.
- We preserve all relevant content, message metadata, and account information. We do not delete evidence.
- We suspend the reported account pending review.
- We report to NCMEC under 18 U.S.C. § 2258A.
- We cooperate with law-enforcement subpoenas and preservation requests under 18 U.S.C. § 2703.
- We do not, and will not, disclose the identity of a reporter to the reported user.
6. Parental consent and access
FlySport collects personal information about minors only with the involvement and consent of a parent or legal guardian:
- Under 13: verifiable parental consent (VPC) is captured via a signed e-form, with the parent's typed legal name, e-signature, IP address, and acknowledgments preserved as an immutable audit record. Until consent is granted, the under-13 user has zero app access. We comply with the federal Children's Online Privacy Protection Act (COPPA) on this collection. The full VPC mechanism is described in the Privacy Policy.
- 13–17 (teen): the Texas SCOPE Act and similar state laws apply. Parents retain the ability to review their child's data, request corrections, and exercise deletion rights through /my-children in the app or by emailing the addresses below.
- Data export and deletion: a parent may at any time download a complete copy of their child's data or delete the child's account permanently. There is no "contact us and wait" gating: deletion is self-service in-app and cascades to chat messages, attachments, and audit logs as described in the Privacy Policy.
7. Designated contact
The point of contact for child-safety reports, NCMEC inquiries, and law-enforcement requests is:
Limestone Labs LLC
Child Safety / Trust & Safety
Austin, Texas
child-safety@limestonelabs.cc
General: info@limestonelabs.cc
For law-enforcement preservation requests under 18 U.S.C. § 2703(f), please include "LEO PRESERVATION" in the subject line. We acknowledge within one business day and preserve covered records for 90 days, extendable on request.
8. Transparency
We commit to publishing an annual transparency report covering the prior calendar year. The first report will be published by March 31, 2027 and will include:
- Total content flags raised by automated moderation, broken down by category.
- Total accounts suspended for child-safety violations.
- Total NCMEC reports submitted.
- Total law-enforcement requests received and the count complied with.
- Median and 90th-percentile response time to user safety reports.
Annual reports will be linked from this page when published.