Spare Android phone only

Prove each control. Leave no test data behind.

Run this checklist after checksum-pinned QR enrollment. Test only the optional features you intend to evaluate, keep every control visible on the phone, and use harmless synthetic content.

Core gateDevice Owner passes

Required for app blocking and schedules.

Privacy gateNo private report data

Status and counts only.

Recovery gateEvery test change reverses

Apps restore and disposable data is deleted.

Optional technical preflight

Check the physical phone without changing it.

After QR enrollment, connect the factory-reset spare phone to a computer with Android Platform Tools and USB debugging. This read-only physical-phone preflight verifies the exact ChildPhone release, Device Owner, launcher, APK checksum, signing certificate, and optional permission states.

Download the 0.18.6 physical-phone preflight
Run with the phone's Android serialsh childphone-managed-0.18.6-physical-preflight.sh ANDROID_SERIAL

It does not grant permissions, change settings, or read app data, coordinates, notifications, messages, phrases, pairing secrets, tokens, accounts, or personal files. A PASS does not replace the manual feature, recovery, and factory-reset checks below.

Before enabling ChildPhone Home, prefix the command with CHILDPHONE_EXPECT_HOME_STATE=android. After syncing a suggested or locked Home policy, use CHILDPHONE_EXPECT_HOME_STATE=childphone. Both checks are read-only.

No-phone network check

Verify the QR download before retrying.

Run this read-only check from a computer to confirm that the public enrollment JSON, HTTPS APK download, URL-safe checksum, package identity, and Managed version all agree. It does not require USB debugging and does not change the phone.

Download the enrollment-endpoint preflight
Run from any computersh childphone-managed-0.18.6-enrollment-preflight-v2.sh

A PASS confirms the endpoint. If the phone still shows a generic setup error afterward, factory-reset it again and record the model and Android/ColorOS version.

Browser-local evidence session

Record the result without recording the child.

Nothing is uploaded or saved in browser storage. Reloading clears this session. The export schema has fixed result categories and no field for notes, device serial, family identifier, app list, location, message, phrase, or credential.

Current decisionPhysical-device acceptance is incomplete0/23 recorded · 0 passed · 0 failed · 0 inconclusive
Read-only physical-phone preflight

Record the script's final Core preflight result. A passing script does not pass the manual checks below.

Core preflight result
01

Verify the encrypted launcher-app list

After pairing and sync, open the parent dashboard app picker. Confirm the phone's visible launcher apps appear with names and package identifiers, then install or replace one disposable app and sync again.

Pass: the bounded list updates, the relay envelope remains ciphertext, and no usage or screen-time data appears.
Verify the encrypted launcher-app list result
02

Verify suggested and locked ChildPhone Home

In the parent dashboard, select Suggest a layout, choose two disposable apps, set their order and column count, save, then sync the phone. Long-press an app on ChildPhone Home and move it. Next choose Lock the layout, reverse the parent order, save, and sync again. Finally turn off ChildPhone Home and sync.

Pass: suggested mode allows the child's local reorder, locked mode restores the encrypted parent order, Phone, Settings, and ChildPhone remain available throughout, and turning the feature off restores Android Home.
Verify suggested and locked ChildPhone Home result
03

Confirm Device Owner enrollment

Open ChildPhone. The top status should say Protection is active. Open Setup readiness and confirm Enrollment core: PASS before testing app controls.

Pass: both the visible status and privacy-safe report confirm Device Owner.
Confirm Device Owner enrollment result
04

Verify local app-rule drafts and protected apps

Before pairing, open Edit app rules and schedules. Confirm neither ChildPhone edition nor Settings, the launcher, dialer, System UI, package installer, or permission controls appears. Select one disposable app and turn on Block selected apps now; confirm the app remains available before Save, then tap Cancel and reopen the editor. Repeat and use Save rules, verify suspension, then save again with immediate blocking off.

Pass: Cancel stores nothing, Save applies the complete draft at once, the disposable app suspends and restores, and protected phone functions never become selectable.
Verify local app-rule drafts and protected apps result
05

Verify encrypted parent delivery

Create a disposable family link in the parent dashboard, pair the phone, then use Send encrypted test alert. Refresh the dashboard without sharing the recovery link.

Pass: the synthetic TEST event arrives and the phone has no waiting encrypted events after sync.
Verify encrypted parent delivery result
06

Verify the child-visible recent-activity summary

After harmless GPS, test-alert, policy, sync, and access-request checks, return to Recent activity on this phone. Review every row without sharing the phone screen publicly.

Pass: the summary shows timestamps only for the five activity types, keeps at most seven days, and contains no coordinate, place, app, message, sender, phrase, family, key, token, or policy content.
Verify the child-visible recent-activity summary result
07

Review the child-visible routine explanation

Open Parent routine suggestions on the phone. Read it as the child would, then compare its claims with the synthetic Routine Lab linked from the parent dashboard.

Pass: the phone says it cannot know whether the browser setting is enabled, explains coincidence and missed-routine risk, lists excluded message/app/GPS data, states prompts cannot change controls, and offers questions for challenging a prompt.
Review the child-visible routine explanation result
08

Verify visible GPS sharing

Enable GPS on the phone, accept Android location and notification permissions, and confirm the ongoing ChildPhone location notice. Move only if it is safe to do so.

Pass: Setup readiness reports GPS PASS; encrypted samples show age and accuracy in the private dashboard; the 1-hour, 24-hour, and 7-day history filters do not trigger a new phone request.
Verify visible GPS sharing result
09

Verify independent place boundaries

In the parent dashboard add two harmless test places using distinct names and coordinates, enable different arrival or departure choices, save, and sync. Use only safe, controlled movement or test coordinates you can verify.

Pass: the phone receipt confirms two place alerts, each transition names the correct place after browser decryption, and no readable name or coordinate appears at the relay.
Verify independent place boundaries result
10

Verify per-place alert windows

For one harmless test place, enable a short local-time window and choose today. Sync the policy, observe the phone's visible GPS status, then let the window close before testing the next transition.

Pass: the phone establishes a fresh baseline when the window opens, sends no transition while the window is closed, and the parent sees no readable schedule at the relay.
Verify per-place alert windows result
11

Verify communication inspection boundaries

Open Review safety setup on the phone. Add one harmless, agreed test phrase, select one installed supported communication app, and save. Confirm inspection is still off; then enable it separately and grant Notification Access yourself.

Pass: saving setup does not activate inspection, the visible monitoring notice remains present after separate activation, and the parent receives only metadata—not the phrase, sender, or message.
Verify communication inspection boundaries result
12

Verify app blocking and restoration

For a local unpaired test, use Edit app rules and schedules, select a disposable non-critical app, turn on Block selected apps now, and use Save rules. Reopen the editor, turn immediate blocking off, and save again. For a paired test, make the equivalent encrypted parent-policy change instead.

Pass: the test app is unavailable during blocking and restored afterward.
Verify app blocking and restoration result
13

Verify allow-only mode and protected functions

In the parent dashboard choose Allow only selected apps, approve one disposable app, and turn on Block now. Confirm another disposable launcher app is unavailable while ChildPhone, Settings, the launcher, and dialer remain available. Then turn blocking off.

Pass: only the approved and protected apps remain available during the window, and every ChildPhone-suspended app restores afterward.
Verify allow-only mode and protected functions result
14

Verify the selected-day schedule

In the local app-rules editor or paired parent policy, choose today and one unselected comparison day, set a short test window a few minutes ahead, save, and wait for both edges. Also review one harmless overnight draft and confirm it is labeled as ending the next day. Disable and save afterward. Android can delay background work, so record observed times rather than treating this as an emergency control.

Pass: the selected test app changes state at both schedule boundaries and is restored at the end.
Verify the selected-day schedule result
15

Verify the text-free access request

While a disposable app is suspended by an active parent policy, tap Request 15 more minutes on the phone. Refresh the private dashboard before creating any Quick unlock code.

Pass: the parent sees only the encrypted request time and fixed duration, the phone remains blocked, a repeat request is rate-limited, and no reason, app, activity, location, message, or phrase appears.
Verify the text-free access request result
16

Verify offline Quick unlock and automatic re-lock

While a disposable app is suspended by an active parent policy, generate a Quick unlock code in the dashboard and enter it on the phone immediately. Do not reuse the code. Confirm GPS and communication inspection switches do not change.

Pass: ChildPhone restores its suspended apps for about 15 minutes, shows the temporary state on the phone, rejects reuse, and reapplies blocking automatically afterward.
Verify offline Quick unlock and automatic re-lock result
17

Verify encrypted device health

Sync once after pairing, then refresh the parent dashboard. Check the reported build, battery, Device Owner, and enabled-feature readiness without sharing the recovery link.

Pass: the dashboard receives one latest-only health snapshot and the relay-facing envelope contains ciphertext rather than health fields.
Verify encrypted device health result
18

Share the privacy-safe report

Open Setup readiness, review every line, and use Share report. It includes app version, Android SDK, manufacturer/model, readiness states, and counts only.

Pass: the report contains no family ID, key, token, coordinates, place name, phrase, message, app package name, or policy ID.
Share the privacy-safe report result

Mandatory cleanup

Recover the spare phone after testing.

Cleanup is part of acceptance. The record cannot pass until all four steps pass.

  1. 1. Stop GPS and communication inspection, then delete their local histories.
    Cleanup step 1 result
  2. 2. Disconnect the parent dashboard on the phone to remove its pairing key, waiting uploads, and remote policy, and restore suspended apps.
    Cleanup step 2 result
  3. 3. Delete encrypted events and revoke the disposable family connection in the parent dashboard.
    Cleanup step 3 result
  4. 4. Factory reset the spare phone to remove Device Owner and erase the test installation.
    Cleanup step 4 result
Device-level result

Physical-device acceptance is incomplete

This record covers one model and one release only. Even a pass does not approve a family pilot, prove safety-alert accuracy, replace representative parent/child testing, or satisfy legal and independent security review.

Physical enrollment is still the external checkpoint.

Automated checks validate the APK, enrollment payload, privacy boundaries, and website. A current Android 16 stable-release smoke passed the exact signed 0.18.6 APK, Device Owner, child-visible launcher, process restart, reboot persistence, and a bounded no-crash/ANR check. The deeper optional-feature emulator rehearsal used an earlier development build and is not stable-release proof. That older rehearsal covered app suspension and restoration, live encrypted pairing, synthetic alert decryption, visible GPS collection, encrypted GPS delivery and parent-side decryption, local GPS history deletion, controlled notification inspection with an ongoing notice, one metadata-only local safety event, encrypted parent delivery and decryption, local safety-history deletion, Notification Access revocation, and disconnect cleanup. A real factory-reset phone is still required to record manufacturer-specific QR setup behavior and repeat every chosen feature and recovery step above on physical hardware. Use the browser-local recorder to export one content-free JSON result; it is device evidence only and cannot change the platform's NO-GO pilot decision.