Last updated: August 2026 · Version 1.2.0 · ChildSafe AI by Privacomply Ltd
| Field | Detail |
|---|---|
| Version | v1.2.0 — ChildSafe AI |
| Release Date | August 2026 |
| Developer | Privacomply Ltd |
| DPO / Architect | Kevin Morrison, IAPP CIPP/E, CIPM |
| Website | childsafe-ai.privacomply.co.uk |
| Component | Technology | Notes |
|---|---|---|
| AI Engine | Google Gemini gemini-3.6-flash | Direct API mode (120s timeout); 5-attempt exponential backoff on 429/503/504 |
| Backend | Netlify Serverless Functions (Node.js ESM) | Functions: gemini.mjs, proxy-download.mjs, scrape-website.mjs, get-regulatory-updates.mjs |
| Database | Google Cloud Firestore — europe-west2, London UK | User reports, audit history, My Library documents. UK data sovereignty enforced at infrastructure level. |
| Authentication | Firebase Authentication (Google Sign-In) | europe-west2, London UK |
| Hosting / CDN | Netlify | Global CDN with UK/EU edge nodes; serverless function execution in UK region |
| Frontend | Vanilla JavaScript (ES2022) | Single-page app; no framework dependencies |
| Integrity | SHA-256 (Web Crypto API) | HITL certificate hash: SHA-256(reportId|reviewerId|reviewDecision|reviewTimestamp) |
| Framework | Authority | Jurisdiction | Standards |
|---|---|---|---|
| UK GDPR | ICO | United Kingdom | 14 articles assessed (Arts. 5–35) |
| ICO Children’s Code | ICO | United Kingdom | All 15 Age Appropriate Design Code standards |
| DUAA 2025 | UK Parliament | United Kingdom | Digital Use and Access Act 2025 |
| Online Safety Act 2023 | Ofcom | United Kingdom | Child safety provisions |
| EU AI Act | European Commission | EU/EEA | High-risk AI provisions |
| KCSIE 2024 | DfE | United Kingdom | Keeping Children Safe in Education |
| Digital Services Act | European Commission | EU/EEA | Platform obligations |
| UNCRC Digital | UN / 5Rights | International | General Comment 25 — children’s digital rights |
| SEND Framework | DfE / NHSE | United Kingdom | Special Educational Needs and Disabilities |
Compliance scores are computed automatically from the findings returned by the AI analysis pipeline. Each RED finding deducts 10 points from the base score of 100; each AMBER finding deducts 5 points. The minimum achievable score is 0.
RAG classification thresholds:
| Score Range | RAG Status | Meaning |
|---|---|---|
| 80–100 | ● GREEN | Compliant |
| 50–79 | ● AMBER | Requires Attention |
| 0–49 | ● RED | Critical Risk |
| Task | Parameters | Retry Strategy |
|---|---|---|
| Main Analysis | temperature: 0, maxOutputTokens: 5,000–20,000 (5,000 base + 4,000 per framework, capped at 20,000) | 5-attempt retry: 0s / 8s / 16s / 25s / 35s backoff |
| CC Standards + UK GDPR Articles Breakdown | temperature: 0, maxOutputTokens: 10,000 | 5-attempt retry with 5s initial delay after main analysis |
| DPIA Generation | temperature: 0, maxOutputTokens: 8,000 | 5-attempt retry: 0s / 8s / 16s / 25s / 35s backoff |
| 90-Day Roadmap | temperature: 0, maxOutputTokens: 8,000 | 5-attempt retry: 0s / 8s / 16s / 25s / 35s backoff |
HITL certification is required before compliance certificates are issued, in accordance with the ICO AI Governance Framework 2024 and Article 22 UK GDPR. The reviewer selects one of four Review Decisions, authenticates with a professional PIN (SHA-256 hashed, stored in browser localStorage only), and their name, qualifications, and timestamp are recorded. A SHA-256 integrity hash of the review record is computed and stored alongside the certificate.
Review Decisions:
| Data Type | Storage Location | Notes |
|---|---|---|
| Document content submitted for analysis | Browser memory only (JS state object) | Never persisted to disk, localStorage or database. Discarded after analysis. |
| Documents saved to My Library | 🇬🇧 Firestore, europe-west2, London UK | Stored per authenticated user UID. Deleted on user request. |
| Compliance reports (scores, findings, breakdowns) | 🇬🇧 Firestore, europe-west2, London UK | Stored per authenticated user UID. |
| Audit history | 🇬🇧 Firestore, europe-west2, London UK | Timestamped HITL-certified review records. |
| Reviewer registry | Browser localStorage only | Reviewer name, qualifications, SHA-256 hashed PIN. Never transmitted to server. |
| Browser history | Browser localStorage only | Up to 25 analysis summaries — no document content. |
The website scanner feature (marked WORLD FIRST) automatically extracts publicly accessible privacy policies, cookie banners, and consent mechanisms from a target URL using the scrape-website.mjs serverless function. Deterministic signal detection checks for cookie consent banners, age gate mechanisms, data collection indicators, and tracking scripts. Results are then analysed against all selected compliance frameworks using the same AI pipeline as document analysis.
© 2026 Privacomply Ltd. All rights reserved. ChildSafe AI is a proprietary product of Privacomply Ltd. Designed and developed by Kevin Morrison IAPP CIPP/E, CIPM.
ChildSafe AI Technical Specification v1.2.0 · August 2026 · Privacomply Ltd · Designed by Kevin Morrison CIPP/E CIPM