DRAFT — not legally published. Counsel review pending. Do not rely on this text as a published policy.
Responsible AI & AI Limitations
How the AI is used, where it can be wrong, and what is never claimed.
PHASE B — DOCUMENT 6: RESPONSIBLE AI / AI LIMITATIONS
Status: draft for review. Public location: kidchat.io/trust/ai.
A. PLAIN STATEMENT
KidChat is built on large language models supplied by third parties and reached through an AI gateway. KidChat can be wrong, incomplete, or out of date. (C-20) It is a place to think, not an authority. It gives no medical, legal, psychological, or other professional advice.
B. HOW A QUESTION IS HANDLED (target pipeline)
child input -> personal-data detection [TECHNICAL CONTROL REQUIRED - C-06] -> redaction/removal of detected value [TECHNICAL CONTROL REQUIRED - C-07] -> safety classification -> approved provider + pinned model [TECHNICAL CONTROL REQUIRED - C-08] -> output safety review -> answer shown to child
The detection and redaction stages are not yet verified in production. Until they are, no public copy may claim them. See §E.
C. PROVIDER GOVERNANCE
- The gateway is an abstraction layer, not an open door to arbitrary providers.
- KidChat maintains an allowlist of approved providers, models, and configurations. Models are pinned per route; there is no fallback routing to an unapproved model in production.
- Gateway prompt/content logging is disabled for child traffic.
- Before any provider or model may process real child traffic, we document: retention, training policy, logging, subprocessors, security posture, DPA/contract terms, data location and transfer mechanism, deletion, and incident notification.
- Policy intent: no provider is approved if child content may be used to train a general-purpose model under the selected configuration. This is our requirement, not yet a substantiated public claim — see §E. (C-08)
D. COST AND SAFETY LEDGER (no content)
Every real AI call writes a server-side ledger row: provider, model, tokens, actual cost, feature, internal child profile ID, timestamp, latency, safety result. The ledger stores no prompt or completion content. (C-18)
E. COPY THAT MAY NOT BE PUBLISHED YET
[DO NOT PUBLISH UNTIL C-06/C-07 VERIFIED]
- "We remove your private information before it reaches AI."
- Child-facing: "Let's keep that private." · [private information removed] · "I removed that before asking KidChat." — the animation must fire from the actual server-side redaction event, never as decoration.
[DO NOT PUBLISH UNTIL C-08 SUBSTANTIATED]
- "We never allow AI providers to train on your child's conversations."
- Any equivalent no-training, no-retention, or no-logging assurance about an upstream provider.
Until each control is implemented, verified, and evidenced, documents describe the intent as an internal requirement and say nothing to parents or children about a capability that does not exist.
F. WHAT WE DO NOT DO
No advertising or ad-targeting. No sale of children's data. No behavioral profiling of children. No profile is built for any purpose other than running the service. No automated decision with a legal or similarly significant effect on a child.
G. IA RESPONSABLE — español (México)
- KidChat usa inteligencia artificial y puede equivocarse. No es maestro, médico, terapeuta ni consejero, y no da asesoría profesional.
- Mantenemos una lista de proveedores y modelos aprobados; el modelo está fijado por función y no hay enrutamiento a modelos no aprobados en producción.
- El registro interno de costos no guarda el contenido de las preguntas ni de las respuestas.
- No usamos los datos de la niñez para publicidad, no los vendemos y no creamos perfiles de comportamiento.
- Cualquier afirmación sobre eliminación de datos personales antes de llegar a la IA o sobre no entrenamiento no se publica hasta estar verificada técnicamente y respaldada por contrato.
H. EU AI ACT
KidChat is region-blocked for UK/EU. If that changes, transparency, risk-classification, and child-protection obligations under the EU AI Act must be assessed first. [COUNSEL REVIEW REQUIRED — EU AI ACT, ONLY IF UK/EU SCOPE OPENS]
Who operates KidChat
KidChat is a technology service operated by NOXON, LLC, a Texas limited liability company.
KidChat es un servicio tecnológico operado por NOXON, LLC, sociedad de responsabilidad limitada constituida en Texas, Estados Unidos.
NOXON, LLC — Texas, United States. privacy@kidchat.io · safety@kidchat.io · security@kidchat.io · legal@kidchat.io
© 2026 KidChat. Operated by NOXON, LLC.
