Complete protocol logic

From a real student at school to safer interaction across the internet.

UuLApp is a process for establishing a trustworthy “this user is a minor” signal and requiring participating digital services to use that signal to separate adults from child-only interaction and to apply age-appropriate communication rules.

The problem with today’s model

A date of birth typed into a box is not verification.

Online services often rely on information entered by the user. This makes the same weakness available to both sides: a minor can claim to be an adult and an adult can claim to be a minor. UuLApp removes self-certification from the child identity process.

Typical self-declared model

  1. User opens an account.
  2. User types a date of birth.
  3. Service assumes the age is true.
  4. Adult and child accounts may enter the same discovery, chat or gaming systems.

UuLApp model

  1. A school verifies the student from its records.
  2. A verified minor ID is issued/authorised under the protocol.
  3. The ID carries only the status/age attributes required.
  4. Participating services enforce child-only and age-group interaction rules.
Step by step

The UuLApp trust chain.

Each step has a different purpose. Skipping any of them weakens the model.

01

The school joins the protocol

The participating school is validated as an authorised educational institution and receives controlled access to the issuance process.

02

The school verifies the real student

The school confirms that the person is enrolled and determines the minimum relevant age or education band from records it already lawfully holds. The child cannot perform this certification and a parent cannot replace the school as the verifier.

03

A unique minor credential is created

The UuLApp ID proves the status needed by a service — for example, verified minor, age band, school/education group and credential validity. It should not expose the child’s full school record, address or unnecessary identity information.

04

Parent/guardian permissions are applied where required

Parental responsibility remains distinct from school verification. Consent, permissions and service choices can be managed according to applicable law, school policy and family settings.

05

The child presents the ID to a participating service

A game, social network, communication tool, learning service or website checks the UuLApp status instead of relying only on a self-entered birthday.

06

The service applies mandatory interaction rules

Adopting UuLApp means more than displaying a badge. The service must use the verified status to prevent adult accounts entering child-only social/gaming pools and to allow interaction only with the age groups permitted by its UuLApp implementation and applicable rules.

07

The credential is renewed, changed or revoked

Child status is not permanent. School-year changes, transfer, graduation, errors, lost credentials or security concerns must be able to trigger update, expiry or revocation.

Students in a school environment
Why the school?

Because the school already has the relationship an anonymous website does not.

A school normally knows whether the person is an enrolled student and their educational level. UuLApp uses that existing institutional relationship as the trust anchor rather than asking the internet to guess.

  • Issuance is linked to a real institution and an accountable process.
  • A fake child credential cannot be created through ordinary public signup.
  • Every issued credential can be auditable against the school’s authorised issuance records.
  • Unusual issuance volumes can be compared with actual enrolment.
  • Credentials can expire and require school revalidation.
A graduated interaction model

Verification tells the service who the child is. Policy decides how wide the child’s online social circle should be.

One of the useful ideas from the original UuLApp design is that access does not have to expand all at once. Schools, families, public authorities and participating services can define progressive rules based on age, experience and digital-safety education.

1

Start close

For younger or first-time users, interaction can be limited to verified classmates, the same class or the same school and age band.

2

Learn before expanding

Digital-safety guidance and age-appropriate checks can teach children about personal information, photos, suspicious behaviour and reporting before permissions widen.

3

Expand gradually

As the child grows and gains experience, the permitted circle can extend to verified minors of the same or neighbouring age groups, other schools, regions or countries under the applicable policy.

The exact age bands and progression should not be hard-coded globally. They should be configurable to local law, education policy, child-development guidance and family/school choices.

Trust-anchor abuse

What if someone at a school deliberately creates a false child identity for an adult?

This is the most serious institutional abuse scenario in the UuLApp model. It is also materially different from today’s anonymous self-registration because the false issuance is traceable to an authorised school process rather than disappearing behind an unverifiable birthday field.

Issuance audit trail

Each credential should record which authorised school process issued it and when, without exposing that audit data publicly.

Enrolment reconciliation

The number and status of active credentials should be reconcilable with the school’s legitimate student population.

Expiry & revocation

Credentials should expire, be revalidated and be rapidly revocable when misuse, theft or an issuance problem is suspected.

A secure implementation must also address stolen credentials, compromised devices, account sharing and integration errors. School verification is the trust foundation; strong credential security and service enforcement complete the protection model.

What the protocol is not

UuLApp does not need to become the child’s destination.

Earlier concepts combined the protocol with e-learning, libraries, games and support tools. Those remain possible use cases, but the protocol is stronger when treated as an independent trust layer that existing services can adopt.

Not a social network

UuLApp does not need to replace Instagram, Discord, gaming communities or future social services. It can provide a verified child status they recognise.

Not a game store

Games remain operated by their publishers. UuLApp can supply the verified age-group signal used for matchmaking and communication controls.

Not an identity database for marketing

The protocol should reveal only what is needed for child-safety decisions and should not become a profiling dataset.

What comes after the protocol

The verification layer is intentionally simple. The broader UuLApp vision can be built on top of it.

The same trusted relationships can later support digital-safety education, school e-learning, libraries, partner services and authority-validated alerts. These additions do not change the core rule: only schools certify child identities.

Beyond the protocol →