Safety & Design
Privacy by default
Setting a product's strongest privacy options as the starting point, so a child or parent does not have to find a menu and change them.
- Businesses
- Policymakers and staff
- Parents
What parents should know
Privacy by default means the quiet setting is the one you get first. Location off, profile private, public sharing off, data collection limited to what the service needs. The UK Children's Code made this a standard. You can ask for it on any kids' product, including ones outside the UK.
On this page
What is privacy by default?
A default is the state before anyone taps. Privacy by default puts the more protective state there. Turning a protection on later is privacy by effort, and most people never finish the effort. Children are even less likely to hunt for a submenu that reduces attention or features.
The ICO's Age Appropriate Design Code includes high-privacy defaults among its standards for services likely to be used by children. Settings that allow sharing, contact from strangers, or precise location should not start in the open position. The code is UK law's companion. The idea travels.
Why privacy by default matters
Parents are handed a dashboard and told they are in control. Control that starts unsafe, and requires twenty taps to close, is a design that expects you to fail. Look at a brand-new child profile before you praise the settings page.
Public by default is how a school project becomes a stranger's link. Off until a parent approves is the opposite default. The second one survives a busy Thursday. The first one does not.
How it shows up in practice
- A new account cannot be found in search, and the parent has to choose to loosen that.
- Location is off until there is a reason to turn it on.
- A kid-built game has no public link until a parent allows one.
- A product asks the child to accept a long policy that weakens the default. That nudge is the thing to refuse.
- A parent checks a brand-new profile before praising the settings page.
How HeyOtto helps
A HeyOtto family account starts with a parent, not with a child who self-enrolls. Public sharing of a project stays off until that parent approves it, and the parent can revoke the link. There are no ads. Conversations are not used to train models. Under 13, verifiable parental consent is part of setup. HeyOtto does not claim a UK Children's Code certification. These are the defaults you can check on a new account.
- The child does not hold the approval switch for a public link.
- Parents can read chats without first opting into a monitoring add-on.
- Tool permissions are per child, so a louder tool can stay off.
For families
Try freeFAQs
Is privacy by default the same as a privacy policy?
No. A policy is a document. A default is what the product does before you read the document. Ask to see a new child profile. If it is public, contactable, and collecting more than the service needs, the default is not private.
What does the UK code say?
The ICO's Children's Code includes high-privacy settings as a default for services likely to be used by children. It is a UK standard, in force since 2021, not a US statute. Families can still use it as a shopping test.
Can my child switch the default off?
On a well-built family product, the parent holds that switch. On HeyOtto, public sharing and tool permissions sit with the parent. If the child can open a separate profile you cannot see, the default on the family profile is incomplete.
Does no ads mean privacy by default?
It is one piece. HeyOtto has no ads and does not sell kids' chats. You still want the account owner, the transcript, and the public-share default. A single feature is not the whole setting.
Sources
Last reviewed September 26, 2026. This entry is reviewed twice a year.
