← Mahanu

Safety, for parents

Mahanu guide · FAQ · For builders & learners · Hosted-service policies

Written for the adult responsible for a learner — the privacy, permissions, and age model without jargon.

The shape of the place

Mahanu has no feed, no followers, and no personal social graph. Explore is a catalogue of projects, not people. A project's workspace is private — like a family folder, not a social profile — and members are invited one by one.

What outsiders can see

Exactly two things, both deliberate:

  • The project card — name, tagline, and purpose, screened whenever written or edited. It never shows a roster, an account, or the other projects a member belongs to.
  • The public folder — work a team decides to publish (clear material passes automated checks, flagged material waits for human review, everything public is reportable). Nothing becomes public by accident.

Everything else — notes, plans, photos, conversations in the margins — is visible only to members.

How strangers can and can't reach a project

There is no direct messaging and no outside commenting. The only door is a join request: someone who found a card asks to join, and the owner decides whether to allow it and what they may do (edit, comment, or read). A project with a supervised member has join requests off by default; only that member's guardian can turn them on or handle them. Every public thing carries a report button, and a project can block an account so its requests never return.

Accounts and ages

Independent accounts require being 18 or older and exist only by invitation from someone already here, who stakes their own standing on it. There is no open sign-up, no government-ID check, and no behavior-watching to guess ages.

A parent may create a supervised sub-account for their child from day one. The child signs in from approved devices to collaborate, while the parent controls recovery, devices, memberships, public actions, assistant provider, and each project's privacy mode. The child's account and the guardian link are never public; the card is public but cannot identify the child, school, location, or sensitive circumstances.

The assistant

The assistant refuses harmful work, proposes rather than silently applying edits, and records every approved change in the Timeline. For a supervised account, a local safety gate checks a request before any project context reaches a hosted provider. The parent selects that provider per project — local model, custom endpoint, personal API key, or Mahanu-hosted service — and any non-local route sends content off the device; Mahanu says so plainly and never promises what a parent-selected provider does with it. The binding rules: Acceptable Use Policy, Guardian Addendum, and Reporting & Appeals.

Bots

A project can add bots — automated members, always labelled, always tied to a responsible operator, able to do only what their role allows. In your child's projects you approve a bot the way you approve a person, and a third-party bot's operator is outside Mahanu's promises, like any provider you choose.

One bot isn't optional. Every project with a supervised member — and every large project — includes Mahanu's conduct bot as a visible member. It checks conversations against the conduct rules, nudges in place, and flags anything involving your child to you, not to us. It keeps no copy of what it read, builds no profile, and its flags expire on a schedule. Only the gravest categories — child endangerment, imminent violence — reach Mahanu, a person reviews before anything happens to an account, and in an encrypted project even that alert is content-free: we learn the category, you get the details, and the files stay unreadable to us. Precise rules: Bot & Automation Policy.

What we never do

Sell data. Run behavioral advertising. Add likes, follower counts, streaks, or an infinite feed. Mahanu never uses a child's content or use for advertising, paid placement, profiling, or AI training. A guardian may apply for a grant or approve a vetted sponsor as a normal project member, but sponsors gain no child data and no direct channel to the child. The Support & Resources directory is searched deliberately by owners; it is not an ad system. Open source and self-hosting reinforce these boundaries — they aren't just a promise.

Honest limits

We can't see inside private projects, and we won't pretend otherwise: safety here comes from structure — invite-only interiors, a tiny screened public surface, an accountable web of invitations, and a conduct bot that works for the project and its parents rather than reporting to us. On our hosted service, reports are acted on: warning, then delisting, then account removal. Families who run their own server govern themselves, like any software you run at home.

If something goes wrong

Use the report button on the thing itself — every card and public page has one. Reports reach the hosted service's operators (us), and the enforcement ladder above applies.