Guardian Addendum
Pre-launch draft · not effective. This addendum applies when a guardian creates or manages a supervised account. It supplements the Terms of Service and Privacy Notice; it does not claim to satisfy every jurisdiction’s child-privacy or child-safety law.
1. Guardian authority and consent
By creating a supervised account, you represent that you are the child’s parent, legal guardian, or otherwise authorised to make this decision. You authorise Mahanu to process the information needed to provide the supervised account and its selected project features, subject to this addendum and the Privacy Notice. Mahanu must record the consent event, the scope of the enabled features, and the withdrawal path before this flow launches.
Counsel must approve the verification method, direct notice, consent record, and age thresholds in every supported jurisdiction. Mahanu will not treat a guardian relationship as a substitute for any legally required verifiable parental consent, age assurance, school authorisation, or additional child safeguard.
2. Controls the guardian holds
The guardian approves the supervised account’s devices and recovery; project memberships; external join requests; public-card changes and publication; privacy mode; each external or hosted assistant route; and every bot other than the required Mahanu conduct bot. A supervised account has no independent email login, public profile, follower graph, automatic public roster, or direct-message surface.
A project with a supervised member always runs the Mahanu conduct bot described in the Bot & Automation Policy. Its flags involving the supervised member go to the guardian; neither the guardian nor the project can disable it while the child is a member. The bot’s checks are safety processing, not profiling: it keeps no copy of unflagged content, and the Privacy Notice and Retention & Deletion Policy govern what a flag or escalation contains and how long it is kept.
The guardian must use these controls in the child’s interests, keep recovery methods secure, review project membership and providers, and promptly revoke a lost device or unwanted access. Mahanu may require a guardian action before a high-risk change takes effect.
3. Privacy and outside parties
Mahanu does not use a child’s content or service use for advertising, profiling, paid placement, or AI training. A project with a supervised member may seek a grant through its guardian, but a sponsor receives only the application the guardian or project owner submits and has no direct channel to the child.
Before the guardian enables a custom endpoint, personal API-key provider, third-party bot, or other external service, Mahanu must identify that the provider is outside Mahanu’s data commitments and ask the guardian to confirm the selected disclosure. The guardian may withdraw permission by disabling the route, subject to the Retention & Deletion Policy.
4. Review, withdrawal, and deletion
Use [email protected] or the in-product guardian controls to review the supervised account, withdraw consent where applicable, request deletion, or report a concern. Mahanu will verify the request proportionately and explain the effects on the child’s access and shared projects. A withdrawal does not delete material already copied by other authorised project members or records Mahanu must retain by law.
The reporting and appeal route is here. If a guardian and a project owner disagree about a supervised account’s membership or publication, Mahanu may pause the affected access while it verifies authority and applies the service rules.
Mahanu