Android test build · 0.18.11-dev

ChildPhone Managed

A visible test agent for a spare Android phone. An ordinary sideload can test local GPS collection, incoming-notification safety checks, and optional end-to-end encrypted delivery. Fully managed app controls use a separate factory-reset Device Owner setup.

App blocking, schedules, allow-only mode, and ChildPhone Home require the factory-reset enrollment path. Downloading or sideloading the APK alone cannot enable them. The enrollment guide deliberately uses the permanently signed 0.18.6 release; this development-key build publishes no enrollment QR.

01

What works in this test

  • Visible foreground GPS sampling with encrypted seven-day storage
  • A protected safety setup with visible phrase ownership, live validation, and installed communication-app selection
  • Screenshot-protected one-time parent pairing with explicit paste, bounded input, encrypted offline queue, and remote event delivery
  • A synthetic encrypted test alert that reads no notification or message
  • Optional generic background notices on supported parent browsers
  • A private visual app-rules editor with explicit Save, live active-now preview, app selection, and overnight schedule labeling
  • App suspension and restoration when enrolled as Android Device Owner; both ChildPhone editions and core phone functions remain outside the selectable list
  • Allow-only windows that preserve approved apps and protected Android/emergency functions
  • A recurring blocking window for parent-selected weekdays plus a manual Block now switch
  • End-to-end encrypted app-control mode, app selections, and schedules with encrypted phone receipts
  • Offline one-time Quick unlock codes that pause ChildPhone app suspension for about 15 minutes
  • A child-visible, rate-limited request for 15 more minutes containing no typed reason, app name, activity, location, or communication content
  • A bounded encrypted list of visible launcher app names, package identifiers, and real phone-supplied icons for parent app selection
  • An optional ChildPhone Home screen with parent-suggested or locked app order, protected Phone, Settings, and recovery shortcuts, and automatic Android Home restoration when management disconnects
  • Up to five encrypted place boundaries with on-device arrival and departure detection
  • Optional per-place day-and-time windows evaluated in the phone's local time zone
  • Up to 20 encrypted parent-managed safety phrases, visible on the phone
  • Checksum-pinned factory-reset QR enrollment with Android 12+ provisioning support
  • Latest-only encrypted device health with stale-sync, permission, service, queue, and low-battery warnings
  • A shareable setup-readiness report containing status and counts but no family, location, message, phrase, app-package, or policy data
  • A local seven-day recent-activity summary with timestamps only for GPS collection, safety matches, parent controls, encrypted delivery, and access requests
02

Current limits

  • The recovery link or encrypted recovery file remains a possession-based parent credential; production account login and recovery are not connected yet
  • Background delivery depends on the parent browser and its notification settings; it is not an emergency-delivery guarantee
  • The relay and browser push provider learn that a requested alert or access request occurred and when, but not its private details
  • Communication inspection covers readable incoming notification previews only
  • It cannot read chat history, outgoing messages, hidden previews, or encrypted content
  • A parent policy cannot enable communication inspection, select inspected apps, or grant Notification Access
  • Managed 0.18.11-dev can separately request optional seven-day preview history for WhatsApp and supported Messages/SMS apps; the exact app list must be visibly approved on the phone
  • Device Owner app controls require a factory-reset test phone; the new QR flow still needs a physical-phone test
  • Android may delay the roughly 15-minute background policy check; remote controls are not an instant emergency channel
  • Quick unlock depends on the browser and phone clocks, is not a tamper-proof time source, and cannot be confirmed remotely
  • Android package visibility and manufacturer behavior can limit which launcher apps appear in the encrypted list
  • Place alerts require visible GPS collection and reliable samples; Android timing and GPS accuracy can delay or misclassify a transition
  • The local recent-activity summary confirms only that a feature acted; it does not reveal content or prove the parent read an event
03

Before installing

  1. Use a spare Android 10 or newer phone with no personal data.
  2. Download the APK on that phone and allow installation from your browser.
  3. Open the private parent dashboard in the parent's browser and create a family link.
  4. Open ChildPhone Managed, review each disclosure, and paste the one-time pairing string.
  5. Optionally enable background alerts and save encrypted app controls, up to five place boundaries, parent-managed safety phrases, or a Managed-only message-preview request in the dashboard.
  6. Tap Sync encrypted events now on the phone to apply the policy immediately and return a private receipt.
  7. During an active blocking window, use Request 15 more minutes on the phone and confirm the parent sees only the text-free encrypted request.
  8. If the parent chooses, generate a Quick unlock code in the dashboard and enter it on the phone.
  9. Review parent-managed phrases on the phone; separately choose inspected apps and enable visible communication inspection there.
  10. If message preview history was requested, review its WhatsApp or Messages/SMS app list on the phone and explicitly allow it before opening Android Notification Access.
  11. Tap Send encrypted test alert to verify safety-alert delivery.
  12. Return to Recent activity on this phone and confirm it shows timestamps only, with no coordinates, app, message, phrase, family, or policy content.
  13. Use ordinary installation for GPS/safety testing, or follow the checksum-pinned enrollment guide for Device Owner testing.
Open factory-reset enrollment guideOpen guided field-test checklistDownload no-phone QR preflight
04

Verify the file

SHA-256

cacde89f8e24e06917989892db7100a8c290cb46516512fdfd976b05eb41cf63

Debug signing certificate SHA-256

2ac25242cae09dea72f43286e517c7c8c5a5902016a55f7a6a3289c26bcafd30

If the downloaded file has a different checksum, do not install it.

Visible by design

Location and communication inspection are separate switches. Android permission screens and ongoing ChildPhone notices remain visible while monitoring is active. Remote delivery is a third, separate pairing step. Safety alerts never save or upload message content, sender names, or matched phrases. Optional Managed message-preview history is separate: approved WhatsApp or Messages/SMS notification text is encrypted for the parent, never placed in push notices, capped at 5,000 previews, and deleted after no more than seven days. The relay cannot decrypt it. Push notices contain no event details, although the relay and browser push provider can observe their occurrence and timing. Parent app selections, schedules, place names, coordinates, and safety phrases are encrypted too; the relay can observe only policy envelope size and update time. Parent-managed phrases remain visible on the phone and never grant monitoring access. The bounded launcher-app list and small launcher icons are also encrypted and child-visible; they contain no usage, screen-time, install-history, or app-activity data and are never fetched from an app-store service. Quick unlock codes are derived in the paired browser, checked locally on the phone, never uploaded, and change only app suspension. Access requests contain only a timestamp and fixed duration, are encrypted before upload, and never unlock an app by themselves. The recent-activity summary remains on the phone, keeps timestamps for at most seven days, and is never uploaded. Place detection runs on the phone and sends no coordinates in transition events.

Report a test issue