Safety

How we keep people safe here

HiveJournal is a journal, a family screen, and a few creative tools. Some of what people put here is private, some of it is a child’s, and some of it runs on a screen in a kitchen. This page says plainly what we do about that — and what we don’t. Everything below is how the product works today, not a plan.

See something wrong, unsafe, or that looks like an attack? Email support@hivejournal.com. For a security vulnerability, please write to privacy@hivejournal.com before posting it publicly and we will respond.

Keeping bad actors out

Most abuse never reaches a person because it never gets an account or a foothold.

  • Bot protection at the door. Sign-up, sign-in, and password reset run through Cloudflare Turnstile, and the site sits behind Cloudflare’s bot filtering.
  • Age gate. HiveJournal is for people 13 and older. You confirm that at sign-up, and if we learn an account belongs to someone under 13 we disable it and remove the data (see the Privacy Policy).
  • Every write is authenticated, and the database enforces it again. Every API route that changes data requires a signed-in user, and every table carries row-level security so one account cannot read or write another’s rows. Two automated audits run on every code change: one fails if a data-changing route lacks an auth check, the other if a table lacks row-level security. The few public routes that exist are reviewed by hand and listed by name, with the reason each is safe.
  • Shared screens are scoped to one family, by design. A Cornerstone Display opens by a long random link, and every action taken from that screen is re-checked on the server against that one family — a screen’s link can only ever reach its own household’s data.
  • Rate limits on the public surfaces. The wall’s “Ask JQ” is capped per screen per minute, and generating a custom JQ icon is capped per account per day.
  • You can leave, completely. Deleting your account deletes your rows and sweeps your uploaded files from storage in the same request.

Report and block

  • Report anything, block anyone. Wherever people can see each other’s content or connect, there is a Report action with a reason and a Block action. Blocking is immediate and mutual in effect: a blocked person’s content and invitations stop reaching you.
  • A human reads every report. Reports go to a review queue that the developer works through. There is no automated dismissal.
  • Small by design. HiveJournal is not a feed. Most of what you write is visible only to you, or to a family or group you chose.

Children and the kids’ chat

Families can give a child their own JQ chat on a Cornerstone screen. Because that is an AI talking to a child, it is the most guarded thing we run.

  • Off by default. A parent turns it on per child, sets an age band, and can set a daily cap and blocked topics.
  • Both sides are moderated. What the child says and what the AI replies are both checked by a moderation model before they go anywhere. If the moderation service is down, the child’s message is refused rather than let through.
  • A local safety filter runs first. Before anything leaves our server, a conservative filter blocks a small set of unambiguous high-harm requests — weapon and explosive how-tos, sexual content, stranger contact and “keep it secret from your parents” patterns. It is deliberately tuned not to false-block ordinary kid talk.
  • Distress is met with care, not deflection. The filter deliberately does not block sad, scared, or self-harm messages. Those reach an age-banded safety prompt that responds gently and steers the child to a trusted adult. A cold “let’s talk about something fun” there would be harmful, so we don’t do it.
  • Parents see everything. Every message in both directions is logged to the parent, and flagged messages are called out. The parent console shows this through age-graded visibility: younger children have full visibility, and the amount an older teen keeps private is a deliberate, documented setting, not an accident.
  • Photos of children are a line we haven’t crossed. The family display does not host a shared photo stream of children. We have kept that off until we have counsel’s guidance, and a parent’s own share link remains the preferred path.

The family display is never covert

A Cornerstone Display is a screen in a shared room, often near children. Its rules are hard rules, enforced on the screen itself, not preferences.

  • A PIN protects your screens. When you set a wall PIN, a new device must enter it once before it can show any wall, and changing the PIN re-locks every device. Connecting a calendar to a wall requires a PIN first, because a family’s schedule is sensitive.
  • Each capability is its own opt-in, per screen. Checking things off from the wall, adding items from the wall, asking JQ, the intercom, and audio check-ins are each separate switches, all off by default.
  • Quiet hours are a hard rule. During a screen’s quiet window, intercom messages arrive silently. A bedroom screen never speaks at 2 a.m.
  • Nothing listens without being asked, and never in secret. Check in — a short two-way audio call to a bedroom screen — only starts when a parent starts it, needs a one-time tap on the screen itself to allow, shows a full-width “Listening — Mom” banner with a timer for the whole call, ends itself after five minutes, and is logged in that screen’s settings for anyone in the household to see. Nothing is recorded. There is no cry detection, no motion sensing, and we do not call it a baby monitor, because it isn’t one.
  • Sensitive calendars can show as “Busy.” Each connected calendar can show full titles or time blocks only, so a work calendar on a kitchen wall never shows its details.

AI, voices, and your data

  • Nothing you write trains a model. Not ours, not our providers’. Journal entries are never sent to an AI provider as a side effect of saving; AI features that read your writing are opt-in and off by default.
  • Google data is under Limited Use. If you connect a Google Calendar, our use of that data adheres to Google’s Limited Use requirements: events are read to show them, written only when you ask, and never sold, transferred for advertising, or used to train anything. The full statement is in the Privacy Policy.
  • Your voice stays yours. A cloned voice is created only from a recording you make and confirm, with a consent scope you set. Nothing on the wall renders a voice without a clone the owner consented to, and children never trigger a paid voice render.
  • Generated images never contain people. Every image we generate — backdrops, mascots, avatars — is drawn without people or faces, and the prompts refuse requests for them. This is a network-wide rule, not a filter we hope holds.
  • No ads. HiveJournal is paid for by subscriptions, not by attention or data.

Encryption where you hold the key

The Cornerstone Vault is for the records a family cannot afford to lose. Its promise is the one that matters: if we could read your private data, “you own it” would be a lie.

  • Sealed in your browser. Notes, photos, and documents are encrypted on your device with AES-256-GCM before they leave it. Your passphrase never leaves your device.
  • The server refuses to receive a key. This is enforced in code and covered by tests: a request that carries a passphrase, a key, or plaintext is rejected outright. The server can only store something that already looks sealed. A vault whose server won’t even accept a key cannot quietly grow a back door later.
  • You can verify it. The vault shows a “what the server sees” panel: the actual ciphertext we hold, and nothing else.
  • Recovery is yours to design. You choose recovery holders. We cannot reset a vault passphrase, because we never had it.

Well-being

  • Crisis resources are in the product, not just in a policy. Surfaces that touch hard moments — journaling and Mantras among them — show crisis lines. We make no clinical claims: HiveJournal is not therapy and does not diagnose.
  • JQ is a companion with limits. It answers from what you have shared with it, it does not pretend to be a person, and on a shared family screen it answers only from what is on that screen.
  • Quiet by default. JQ’s nudges fire at most once a day for each kind, and the app does not manufacture urgency to bring you back.

What we don’t do, and what we’re still working on

  • We do not scan your private journal for anything. Moderation applies to what is shared with others and to the kids’ chat.
  • We do not run cameras, cry detection, or motion sensing on any screen, and we will not market a feature as a monitor unless it can honestly promise to be one.
  • We have not yet had a third-party security audit. The audits above are our own and run on every change; if you are a researcher who wants to look closer, write to us and we will talk.
  • Some features are gated on legal review before they ship, and we say so on the feature rather than shipping and hoping: hosted photos of children, and read-only voice for people who have died among them.

This page is kept in step with the code. If you find a sentence here that the product no longer lives up to, that is a bug — tell us at support@hivejournal.com. Related: Privacy · Terms · Ethos.

Safety at HiveJournal | HiveJournal