Our approach
Parental controls vs. safe by design
You know the drill. You download the app your child asked for, and then you go hunting. Into settings, through submenus, past the options placed where they're least likely to be touched, flipping switches you hope are the right ones. The app arrived wide open, and the job of making it safe was quietly handed to you.
The default is open
This is the model almost every app follows, and it's worth naming plainly: the app ships in its most connected, most public, most engaging state, and safety is an optional layer you're invited to add on top. The burden sits with the parent. You have to know the risks exist, know which settings address them, find those settings, and set them correctly — before your child does anything you'd rather they didn't. Miss one, and the gap is open by default, not closed.
A safety net with holes you have to watch
Even parents who do all of it well are signing up for a job that never ends. Controls are scattered across different menus, and they use language that rarely matches the thing you're actually worried about. An app update can reset your choices or introduce a new feature that isn't covered by the settings you already found. And the whole arrangement quietly assumes a level of ongoing vigilance that no parent, however careful, can sustain across every app, every update, every child, forever. It's a safety net you're asked to keep re-tying by hand.
Safe if you set it up perfectly, or safe by design
There's a genuinely different way to think about this, and it comes down to where safety lives. In the controls model, an app is safe if you configure it perfectly — the protection is only as good as the last setting you remembered to check. Safe by design turns that around. The protections aren't options bolted on afterwards; they're the shape of the thing itself. There's no risky default to remember to switch off, because the risky option was never built. You're not administering safety. It's simply how the app works, out of the box, for everyone.
Starting closed
Tuck is built to start closed. A child can only message people they've met in person and a parent has approved — there's no search, no discovery, no way for a stranger to appear, because none of that machinery exists to be switched off. Messages are filtered for links and bad language on the server before they send, which means it isn't a toggle a child can find and disable; it's part of how a message travels. Oversight is on from the start, not something you enable: parents can read conversations, freeze a chat, or remove a contact, and those powers are there by default rather than buried behind a setup you have to complete.
None of this asks a parent to be an administrator. There's no console of switches to master, no checklist to work through before the app is safe to hand over, and nothing that silently reopens after an update. The safety isn't a layer you maintain on top of the product — it is the product. That's what we mean by limited on purpose: we made the safe thing the default thing, so that keeping your child safe doesn't depend on you finding every setting first.
Messaging that's limited on purpose.
In person only. No strangers, no feed, no ads — just your child and the friends they actually know. Free, coming soon to the App Store.
Get the app