What did my kid just install? :: A.I. Prompts :: Claude
What did my kid just install? Turning your AI into a second opinion
This post was written by Claude from our standing brief. We never edit a platform’s prompts — a defect gets a public note, never a quiet fix. Before publishing, we ran every prompt; what came back appears beneath each card, unedited, with its run conditions.
Directions given to the A.I.
The complete topic brief this post was written from, published so you can judge the answer against the ask. Two standing instruction files (the required post structure, and the audience/standards/forbidden list) travelled with it, identical for every post in this batch, as of 2026-08-19.
# THEME PROMPT — batch 02: "What did my kid just install?"
The moment
You picked up the tablet to check the time and there's an icon you've never seen — some game with a grinning mascot, installed sometime this week. Your kid says everyone at school has it. You're not assuming the worst, but you'd like to know what this thing actually is before it becomes a fixture of the household. The device is in your hand; the answer shouldn't require a research project.
What this post offers
What follows is a set of copy-paste prompts that turn your AI assistant into a working session about the app on that device: what to find out, what the findings mean, and how to have the family conversation that follows — plus, for each prompt, how the AI reads it and what its answer can and can't settle. This is first-hand work: you, the device, and the AI in one sitting, and if you're the family's tech helper rather than the parent, the same rule holds — sit down at the device together, with the family, rather than working from a description relayed over the phone. That is all this post offers.
The prompt cards
Seven prompts, each with what came back when we ran it.
The route — seven cards, three moves
Look · get the picture
Check · permissions, money, fit, identity
02 Does what it asks for match what it does?
03 The accounts, the strangers, the money
Talk & keep · the conversation and the habit
06 The talk
Look · get the picture
Card 1: What is this thing?
Use this when: an unfamiliar app has appeared and you want a plain-language picture of it before deciding anything.
I'm looking at an app installed on a device in my household, and I want a plain-language picture of what it is before I decide what to do. Work from what I give you here. App name as shown in the store: [PASTE THE APP NAME] Developer name from the store listing: [PASTE THE DEVELOPER NAME] What the listing says it does: [PASTE A SHORT SUMMARY — remove personal details first] What the kid who installed it says it's for: [PASTE IN YOUR OWN WORDS — no names] Tell me: 1) what category of app this appears to be and what apps of this kind are generally known for, 2) how apps of this kind typically make money, 3) which claims in the listing I should confirm on the store page itself, and 4) three specific things to look for in the app's own settings. Where you're not certain, say so plainly instead of guessing.
How the AI reads this prompt: The opening line scopes the session to what you supply — the AI works from what you give it here, not from a live look at the store. Feeding it the developer's name alongside the app's name lets it flag when the two don't sit together the way this kind of app usually does. The four numbered asks split the answer into orientation (category, money model) and homework (what to confirm, where to look). The last sentence licenses "I'm not certain" as a valid answer, which is exactly what you want instead of confident filler.
What to do with the answer: Treat the category and money-model picture as orientation, not verdict. What this build actually does, and what the store page says today, you confirm in the listing and the device's settings — the prompt's job was to tell you what to look for there.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
How to read what follows: we ran the complete prompt above, exactly as written, in a fresh AI session before publishing. One run is one sample — your answer will differ. The AI’s read is a first opinion, never a clearance: what you paste is read by the AI as content and can shape its answer, so verify through a channel you already trust — the store listing and the device’s own settings.
The response, as received — unedited
Here's a plain-language picture based on what you've given me.
1) What category of app this appears to be
Based on the listing, this looks like a free-to-play match-3 puzzle game with social features — the same broad family as games like Candy Crush. The important detail is that it's not just a puzzle game: the "join a clan and compete with friends" and "friend code" parts mean it has social/multiplayer features layered on top, which is a different thing to evaluate than a purely solo puzzle game.
Apps in this category are generally known for: - Simple, level-based gameplay designed to be played in short, frequent sessions - Engagement mechanics: daily rewards, streaks, limited-time events, "lives" that run out and regenerate — all designed to bring players back and make stopping feel costly - Social pressure features: clans, leaderboards, and gifting, which can make a kid feel obligated to keep playing so they don't let their team down - Friend codes and clan chat, which in many games of this type means some ability to interact with strangers, even when the store rating is "Everyone"
One caution: I don't recognize "Gem Stackers Blast" or "Luminary Pixel Works Ltd." specifically, so I can't tell you anything about this particular app's reputation, and I won't guess. Everything above is what the category is known for. A 4.6-star rating and an E/PEGI 3 rating tell you about the puzzle content, not about the chat, spending, or data practices — content ratings largely don't cover those.
2) How apps of this kind typically make money
The listing itself tells you the two channels: ads and in-app purchases. Typically that means: - Ads: banner, interstitial, and "rewarded" ads (watch a video to get an extra life or currency). Rewarded ads are effective with kids because the game trains them to want the reward. Ad networks also commonly collect device data for targeting — that's a data-sharing question, not just an annoyance question. - In-app purchases: usually virtual currency (gems/coins), extra lives, boosters, and often timed bundles or battle-pass-style subscriptions. Common pressure tactics include limited-time offers, "you're so close!" prompts after a failed level, and purchases priced in virtual currency so real-money cost is obscured. - The business model generally depends on a small fraction of players spending a lot, so the design nudges toward spending. That's normal for the category, not proof this app is predatory — but it's the thing to have your guard up about with a kid's device.
3) Claims to confirm on the store page itself
- The developer name and track record. Check whether "Luminary Pixel Works Ltd." has other apps, a real website, and a working support contact. A lone app from a developer with no footprint deserves more caution than one from an established studio. I can't verify this developer from what you've given me.
- The data safety / privacy section (Google Play "Data safety," Apple "App Privacy"). The listing blurb you pasted says nothing about data. The store page will list what the app claims to collect and share — location, contacts, identifiers, etc. Note these sections are developer-self-reported, so treat them as a floor, not a guarantee.
- The in-app purchase price range. Store pages usually list the range (e.g., "$0.99–$99.99 per item"). A $99.99 top-end item in an E-rated game is worth knowing about before a kid has access.
- The actual reviews, not the star average. Sort by recent and look specifically for mentions of chat, strangers, aggressive ads, or surprise charges. Also sanity-check the review pattern — a high average with very few reviews, or bursts of generic five-star reviews, is a flag.
- Whether the "interact with others" element is disclosed. On Google Play, look for "Users interact" or similar labels; the E/PEGI 3 rating alone does not mean the social features are safe or moderated.
- Download count and last-updated date, as a rough gauge of whether "everyone at school plays it" matches reality and whether the app is actively maintained.
4) Three specific things to look for in the app's own settings
- Chat and social controls. Open the clan/friends area and find out: is there free-text chat? Can strangers message or friend-request the account? Is there an option to disable chat, restrict it to preset phrases, or block friend requests? What a "friend code" exposes varies by game — you'll only know by looking.
- Purchase and account settings. Check whether the app is signed into an account with a stored payment method, and whether there's any spending limit or purchase-confirmation setting. Also do this at the device level (require a password/biometric for every purchase in the app store settings) — that protection is more reliable than anything inside the game.
- Privacy and ads settings. Look for anything like "personalized ads," "share data with partners," account visibility, or profile discoverability, and turn off what you can. Also check what permissions the app has been granted at the OS level (contacts, location, microphone) — a match-3 game has no obvious need for any of those.
Where I'm uncertain, stated plainly: I have no information about this specific app or developer — whether the game is legitimate, whether its chat is moderated, or what it actually collects. Everything above is either read directly from the listing text you pasted or is a well-established pattern of the free-to-play match-3 category. The store page checks in section 3 and a five-minute look through the app's own settings with the kid present are how you close that gap.
What we found
All four asks landed — category, money model, claims to confirm, three settings checks — and it drew the line the card licenses: "I won't guess" about this specific app, category patterns only. On a well-known real app you'd likely get app-specific detail on top; this run shows the honest floor. Because it makes no claim about the specific app, the store checks it prescribes are where truth lands.
Check · permissions, money, fit, identity
Card 2: Does what it asks for match what it does?
Use this when: you've opened the device's settings and want to reason about whether each permission is proportionate to what the app claims to do.
I've opened the device's settings and I'm looking at the permissions this app has requested or been granted. Help me reason about whether each one is proportionate to what the app says it does. Work from what I give you here. What the app says it does: [PASTE THE LISTING'S DESCRIPTION IN ONE OR TWO LINES] Permissions I can see it has or wants: [PASTE THE LIST FROM THE DEVICE'S SETTINGS — e.g. camera, microphone, location, contacts] For each permission: 1) name a legitimate reason an app with this stated purpose might want it, 2) name what the same permission could serve beyond that purpose, and 3) tell me whether the stated function plausibly needs it at all. Then tell me which permissions I could turn off first to test whether the app still works without them. Don't tell me it's fine or not fine — give me the reasoning so I can decide.
How the AI reads this prompt: Pasting the permission list from the device's own settings — not from memory — anchors the session in what's actually granted. The three-part ask per permission forces both sides of the ledger: the plausible reason and the broader use. The turn-off-first list gives you a test you run yourself, on the device. The final line strips the AI of the verdict, which keeps the judgment where it belongs.
What to do with the answer: The reasoning is the product; the test is yours to run. Whether this version of the app genuinely needs a permission is settled by turning it off in the device's settings and seeing what breaks — not by the chat.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
Good approach — permission-by-permission, reasoning first. Here's the breakdown for a free match-3 puzzle game with clans and friend competitions.
Camera
- Legitimate reason: Setting a profile photo/avatar for your clan identity by taking a picture. Some games use it for AR-style features or QR-code scanning (e.g., adding friends by scanning a code).
- What else it could serve: Capturing images without an obvious in-game trigger; some ad SDKs have historically probed camera availability for device fingerprinting. Any camera grant is also a standing capability the app keeps until revoked, regardless of why it asked.
- Does the stated function need it? No. Match-3 gameplay needs no camera. Profile photos can be handled by letting the OS photo picker supply an image, which on modern Android/iOS doesn't require a blanket camera grant. This is a convenience feature at best, not a core need.
Microphone
- Legitimate reason: Voice chat with clanmates is the only plausible story. A few games also use mic access for "voice commands" or in ad SDKs that once did audio-based ad attribution.
- What else it could serve: Ambient audio capture; audio-beacon ad tracking (listening for inaudible tones to link your devices/TV viewing) — a real, documented practice in some ad SDKs.
- Does the stated function need it? Almost certainly not. Most clan features in match-3 games are text chat. Unless you've seen a voice-chat feature in the app itself, there's no gameplay path that requires a microphone. This is the permission with the weakest justification on the list.
Location
- Legitimate reason: Regional leaderboards ("top players in your country"), matching you with nearby players, or region-locked events. Ads can also be "more relevant" with location.
- What else it could serve: Precise location is high-value ad-targeting and data-broker material — a continuous record of where you are. Country-level features only need coarse info, which apps can get from your IP address or store region without any permission at all.
- Does the stated function need it? No. Every legitimate use here is achievable with IP-based coarse location, which requires no grant. A puzzle game asking for the location permission — especially precise/fine location — is asking for more than its features require.
Contacts
- Legitimate reason: "Find friends who also play" — matching your address book against their user base to populate friend competitions. This is a real feature in social games.
- What else it could serve: Uploading your entire address book (names, numbers, emails of people who never consented) to the developer's servers, where it can feed growth marketing, social-graph building, or resale. Once uploaded, you can't un-share other people's data.
- Does the stated function need it? Not strictly. Friend features work fine via invite links, friend codes, or platform friend systems (Game Center / Google Play Games), none of which need address-book access. The feature is real; the permission is an aggressive way to build it.
Photos/Media
- Legitimate reason: Picking an existing photo as your avatar; saving screenshots of high scores to share.
- What else it could serve: Broad media access can mean reading your whole photo library — which carries location metadata, faces, documents you've photographed. Older Android versions also lumped this with general storage access.
- Does the stated function need it? No — same as camera. Modern OS photo pickers hand the app one selected image without a library-wide grant, and saving a screenshot doesn't require read access on current OS versions. Full library access is disproportionate to an avatar feature.
Full network access
- Legitimate reason: Genuinely required. Leaderboards, clans, syncing progress, downloading levels, and serving the ads that make a free game free all need the network.
- What else it could serve: It's the exfiltration channel for everything above — any data the other permissions collect leaves the device through this one. It also enables ad/analytics SDK traffic you never see.
- Does the stated function need it? Yes, this one is proportionate for an online social game. Note that on Android it's a "normal" permission — every networked app has it and you generally can't revoke it. Its significance is mainly as the pipe that makes the others matter.
Suggested revoke-and-test order (least likely to break the game first):
- Microphone — no visible feature depends on it; revoke and expect zero impact.
- Camera — worst case, in-app photo-taking for an avatar stops working; gameplay unaffected.
- Location — regional features should silently fall back to IP-based region; if anything, ads get less targeted.
- Contacts — friend competitions should still work with existing friends and invite links; only "find friends from contacts" breaks, and note revoking now doesn't recall anything already uploaded.
- Photos/Media — may break avatar-from-gallery; on recent OS versions you can often set this to "selected photos only" instead of off.
- Network — don't bother; the game legitimately can't function offline-social without it, and on Android you can't revoke it anyway.
After each revocation, play a session including clan/friend features. If the game refuses to run at all after losing a permission its stated purpose doesn't need, that refusal is itself informative — a well-built app degrades the specific feature, not the whole game.
One pattern worth noticing across the whole list: for camera, photos, location, and contacts, there exists a less-privileged mechanism (OS photo picker, IP-based region, invite links) that delivers the same user-facing feature. When an app chooses the broad permission over the narrow mechanism repeatedly, that's a pattern you can weigh — each individual permission has a defensible story, but the aggregate choice is the signal. The decision on what that pattern means for keeping the app is yours.
What we found
Both sides of the ledger per permission, plus the revoke-and-test order the card promised — and one durable teaching it added on its own: when a narrower mechanism exists for every permission an app requests, the pattern of choosing the broad one is itself the signal. One claim in this response — that some ad software has used microphone access for "audio-beacon" tracking — is the AI's own; we have not verified it, and the deny-and-observe advice doesn't depend on it.
Card 3: The accounts, the strangers, the money
Use this when: you want to know what the app involves beyond the game or feature itself — sign-ups, chat with strangers, purchases.
Before this app stays on a kid's device, I want to understand what it involves beyond the game or feature itself. Work from what I give you here; I'll confirm specifics in the app's own store listing and settings. The app (name and one-line description): [PASTE — remove personal details first] What I've noticed so far (sign-up screens, chat features, purchase prompts, ads): [PASTE YOUR OBSERVATIONS — no account details, no names] Walk me through: 1) what an account requirement typically means for an app like this and what to look at in its sign-up flow, 2) how to tell whether it lets my kid talk with strangers, and where those settings usually live, 3) how in-app purchases and randomized-reward mechanics (loot boxes) tend to show up in this category and what a store listing discloses about them, and 4) a short list of exactly what to check on the store page and in the app's settings before I decide. Flag anything you can't settle from what I've given you.
How the AI reads this prompt: Your observations of the actual sign-up and purchase screens are the raw material — the AI works from what you noticed, so noticing first matters. The four asks turn a vague unease into a checking plan split by where each answer lives: the sign-up flow, the app's settings, the store page. The closing line makes it name the gaps instead of papering over them.
What to do with the answer: The output is a checking plan, not a finding. What this app's current build collects, charges, and allows is confirmed in its own listing and settings, checklist in hand.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
This is a smart way to approach it — most of what matters here is visible before your kid ever plays a level. Let me take your four questions in order, working only from what you've described, and I'll flag what I can't settle at the end.
1) What the account requirement means, and what to look at in the sign-up flow
An email sign-up in a free match-3 game typically serves three purposes, in roughly this order of importance to the developer:
- Marketing and re-engagement. The email becomes a channel for "come back and play" messages and offers. Expect a marketing-consent checkbox somewhere in the flow — note whether it's pre-checked.
- Cross-device identity and purchase recovery. The account ties Gem Vault purchases and progress to your kid rather than the device. This is the legitimate function.
- Data profiling. The account links gameplay behavior, ad interactions, and purchase history into one profile that can persist across the developer's other games.
What to look at in the sign-up flow specifically:
- Is there a guest/skip option? Many games let you play without an account and only push sign-up later. If a guest mode exists, that's usually the better choice for a kid's device — less data tied to a persistent identity.
- Does it ask for a birthdate? This is the key screen. Apps directed at or attractive to children are subject to children's-privacy rules (COPPA in the US, and similar rules elsewhere), and the age gate is how they sort users. If your kid enters an under-13 birthdate, the app should restrict chat, targeted ads, and data collection — or refuse the account. If there's no age gate at all, that's a yellow flag: it suggests the app is treating every user as an adult.
- Third-party login buttons (Google, Facebook, Apple). "Sign in with Apple" is generally the most privacy-protective if a login is unavoidable, because it can hide the real email address.
- What the email actually unlocks. If sign-up is required just to reach the first level, the account exists mostly for the developer's benefit, not yours.
2) Whether it lets your kid talk with strangers — and this app almost certainly does
You've already answered the core question yourself: a clan feature with free-text chat plus friend codes is stranger contact, full stop. Here's how to read each piece:
- Free-text clan chat is the highest-risk element you listed. Clans in match-3 games are typically open or semi-open groups of unrelated players, often adults. Free-text (as opposed to preset phrases or emoji-only chat) means anything can be typed — including requests to move the conversation to Discord, WhatsApp, or another platform, which is the standard pattern in grooming cases. The in-game chat is rarely the endpoint; it's the introduction point.
- Friend codes cut both ways. A code system means strangers can't cold-add your kid without the code — good. But codes get shared on Reddit, Discord, and YouTube comments specifically to farm friends for in-game bonuses, so in practice the friend list can fill with strangers anyway.
Where the controls usually live, in the order I'd check them:
- In-app settings → often under "Social," "Privacy," "Account," or inside the clan screen itself. Look for: chat off/on, chat filtered mode or "friends only," clan join set to "invite only" vs. "open," and a mute/block/report option (the presence of a report button tells you the developer at least acknowledges the risk; its absence is a flag).
- The age gate again. In well-behaved apps, an under-13 account has chat disabled or restricted automatically. Test this: if the app knows the user is a child and still opens free-text chat with strangers, that tells you a lot about the developer.
- Platform-level parental controls (Apple Screen Time or Google Family Link). These generally cannot turn off chat inside a specific game — they operate at the app/purchase/time level. So don't assume the phone's parental controls cover this; the chat setting has to exist inside the game itself, and if it doesn't, your only options are "no clans" as a house rule or not keeping the app.
One practical alternative if the settings are weak: many of these games let you play the entire core game without ever joining a clan. "You can play, but no clans" is an enforceable rule if you check the clan tab occasionally.
3) How purchases and randomized rewards show up in this category
What you've listed is the standard monetization stack for free match-3, and each piece has a known function:
- Premium currency ("Gem Vault"). Two-step spending — real money → gems → items — is deliberate. It obscures real cost (odd bundle sizes ensure leftover gems), and once money becomes gems, kids stop perceiving it as money. Purchase prompts typically spike at moments of frustration: you fail a level "one move short" and are offered +5 moves for gems. That fail-state timing is designed, not incidental.
- The daily spin wheel. This is a randomized reward on a daily schedule — a habit-formation loop (variable reward + daily appointment). By itself it's usually free, but it trains the pull-the-lever behavior that paid random rewards then monetize. Watch for a "premium spin" or "spin again for gems" option — that's where it converts from retention mechanic to gambling-adjacent spending.
- Loot-box-style mechanics in this genre usually appear as mystery chests, prize boxes after levels, or gem-priced "surprise" bundles. What the store listing discloses: both Apple and Google require apps with paid random items to show drop-rate odds disclosures — but usually inside the app near the purchase, not on the store page. The store page will show:
- An "In-App Purchases" label with a price range (e.g., "$0.99–$99.99 per item"). Look hard at the top of that range. A $99.99 tier in a children's match-3 game tells you who the monetization actually targets.
- App Store: a list of the top in-app purchase items under the "Information" section. Google Play: a "Contains ads · In-app purchases" line and a Data Safety section.
- The age rating (ESRB/PEGI-style), which now often carries interaction descriptors like "Users Interact" and "In-App Purchases (Includes Random Items)" — that last descriptor is your loot-box confirmation.
- Frequent full-screen ads matter for two reasons beyond annoyance: (a) ads in kids' games routinely advertise other games with worse content, and ad networks are the weakest-vetted part of the pipeline — misleading "playable ads" and fake close buttons are common; (b) a "remove ads" purchase is often the first thing a kid will ask for, and it's typically the most reasonable purchase in the whole app if you decide to keep it.
The single most effective control here is platform-level: require a password/approval for every purchase (Screen Time → Content & Privacy → iTunes & App Store Purchases → Always Require, or Family Link's purchase-approval setting), and don't leave a card on a kid-accessible account. That neutralizes the entire spending stack regardless of how aggressive the prompts are.
4) The checklist — store page first, then in-app settings
On the store page:
- Developer name — tap through to their other apps. A portfolio of dozens of near-identical games churned out quickly is a different risk profile than an established studio. Note the developer's listed address/contact; a missing or vague one is a flag.
- Age rating and its descriptors — specifically look for "Users Interact," "In-App Purchases," and "Includes Random Items."
- In-app purchase price range — note the maximum tier.
- Data Safety (Google Play) / App Privacy (App Store) section — what's collected, whether it's linked to identity, whether it's shared with third parties. "Data shared: location, identifiers" in a match-3 game deserves a why.
- Recent reviews, sorted by newest, and search reviews for "chat," "scam," and "charged" — parent complaints about chat content or surprise charges surface here fast.
- Last-updated date and download count — an abandoned app keeps its chat servers but loses its moderation.
In the app itself (do this yourself before handing it back):
- Run the sign-up flow with an under-13 birthdate and see what changes — chat disabled? Ads still targeted? Account refused? This one test reveals the developer's compliance posture.
- Find the chat/social settings — confirm whether chat can be turned off or set to friends-only, and whether block/report exist.
- Open the clan browser — see whether clans are open-join and glance at a chat feed to see what the actual conversation looks like.
- Find the odds disclosure near any mystery-box purchase — its presence/absence, and the actual odds.
- Check for a "restore purchases" / account-deletion option — apps are supposed to offer account deletion in-app now; its absence is a flag.
- On the device: turn on purchase approval, disable the stored payment method for the kid's profile, and (Android) check what permissions the app was granted — a match-3 game needs essentially none beyond network.
What I can't settle from what you've given me
Flagging these honestly, since you asked:
- Whether this specific app enforces its age gate — you'll only know by running the sign-up with a child birthdate (item 7).
- Whether clan chat is moderated or filtered at all — nothing you've described tells me; only the in-app settings and the chat feed itself will.
- Whether the spin wheel or any chest requires payment — you've described the mechanics but not whether real money touches the random elements. The "Includes Random Items" store descriptor and the in-app gem prices will settle it.
- What the app actually collects and shares — only the Data Safety/App Privacy section and (if you're motivated) the privacy policy answer this; sign-up screens don't.
- The developer's track record — I haven't verified anything about this specific title or its studio, so treat everything above as the pattern for the category, to be confirmed against the store listing exactly as you planned.
- Your kid's age, which changes the weight of everything: for an under-10, free-text stranger chat is close to disqualifying on its own; for a young teen, "no clans, purchases require approval" may be a workable middle ground.
If the app fails on chat controls but your kid loves match-3, there are titles in the genre with no social layer at all — that's often the cleaner fix than trying to fence a chat system the developer didn't build safeguards into.
What we found
The four walk-throughs arrived split by where each answer lives — the sign-up flow, the app's settings, the store page — and the under-13 birthdate test turns a vague worry into one decisive check. Long, but every section ends in a check you can run rather than an opinion. On the sign-up test itself, there's a real tension — see the questions section below for our answer.
Card 4: Is this right for my kid?
Use this when: you're weighing the store's age rating against what the app actually does, for your kid specifically.
I'm weighing an app's age rating against what it actually does, for my own kid. You help me structure the judgment; the decision is mine. Work from what I give you here, and use no names. The app and its store age rating: [PASTE] What the app actually involves, from what I've seen: [PASTE — chat, user-made content, ads, purchases, and so on] My kid, in general terms: [PASTE AGE ONLY, plus anything relevant about how they use devices — no name, no identifying details] Give me: 1) what this kind of age rating does and doesn't evaluate, 2) which of the features I described the rating may not capture, 3) five questions that would tell me whether this app fits this kid — not kids in general, and 4) what I'd want to observe in the first week if I let it stay. Don't make the call for me.
How the AI reads this prompt: Age and context go in as general terms only, which is enough for structure and keeps your kid out of the chat. Asking what a rating does and doesn't evaluate gets you its limits before you lean on it. The five questions and the first-week watch list convert "is this okay?" into observations you can actually make. The last line keeps the decision yours.
What to do with the answer: Use the questions on the real app with the real kid in the room. The rating itself, and any parental-approval options, you read on the store page and in the platform's own settings.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
Good structure for this decision — the four pieces you asked for, in order.
1) What an E / PEGI 3 rating does and doesn't evaluate
What it evaluates: Almost exclusively the content the developer ships — depicted violence, blood, language, sexual content, scary imagery, references to drugs or gambling mechanics that are literally slot machines. For a match-3 style game with cartoon gems, "E / PEGI 3" is basically a statement that nothing on screen will disturb a small child.
What it largely doesn't evaluate: - User-generated content and social features. Free-text chat between players is user content, not developer content. Both ESRB and PEGI typically handle this with a small disclaimer ("Users Interact" / "In-Game Purchases") rather than by raising the age number — and on store listings that disclaimer is easy to miss or absent. - Monetization pressure. Premium currency, timers, daily streak mechanics, and "spend to continue" loops don't move the rating. PEGI added a paid-random-item descriptor, but the headline age stays 3. - Advertising. Ratings cover the game, not the ad network. Full-screen ads are served dynamically and can be for other games, gambling-adjacent apps, or anything the network sells that day — the rating body never saw them. - Contact and data risk. Friend codes, clans, profile exposure, data collection — none of it is in scope for the age number.
Short version: the rating answers "will the pictures upset a 4-year-old?" It does not answer "is this app's environment appropriate?"
2) Which of the features you listed the rating likely doesn't capture
Ranked roughly by how far outside the rating's scope they fall:
- Clan free-text chat — the biggest gap. Open text with strangers is exactly what the age number doesn't price in, and it's the one that collides with what you said about your own kid.
- Frequent full-screen ads — unrated third-party content, changing daily. The effective content rating of the app is the rating of its worst ad.
- Premium currency shop — indirection between money and goods is a persuasion technique the rating ignores; at most it earns an "in-app purchases" footnote.
- Daily reward wheel — a habit-formation and chance mechanic. Unless it's purchased randomized items, it doesn't register with raters at all.
- Friend codes — partially captured by "Users Interact"-type notices, but the rating says nothing about whether codes get traded on Discord/YouTube with strangers, which is the common pattern.
3) Five questions specific to this kid
You told me: 11, shared family tablet, fine with multiplayer, not comfortable with open text chat with strangers. So:
- Is the clan chat avoidable or is it load-bearing? Can the game be played fully without joining a clan, or does progression push toward it? If clan membership is effectively mandatory, the feature your kid is uncomfortable with isn't optional content — it's the game.
- Can chat be disabled or restricted at the account/device level, and does it stay disabled? Check whether settings survive updates, and whether "off" means off or means "receive but can't send."
- What happens on the shared tablet? Whose store account is logged in? Can your kid see others' notifications, spend against a stored payment method, or inherit an adult ad profile (which changes what ads are shown)?
- How does your kid actually handle "not comfortable"? When something crosses their line — a chat message, a weird ad — do they close it and tell you, or freeze and keep it to themselves? That determines whether "chat exists but they'll steer clear" is a real mitigation or a hope.
- What's the spend-pressure exposure? Does your kid understand premium currency as real money? Have they previously asked for in-app purchases, and how did they take "no"? An 11-year-old who shrugs at the shop is a different risk profile from one who's already streak-anxious about a daily wheel.
4) What to observe in the first week if it stays
- Chat behavior, unprompted. Do they join a clan? Do they read chat, respond, go quiet about it? Ask casually ("anyone say anything funny in there?") rather than auditing — you want their honest posture, not a performance.
- Friend-code traffic. Any mention of adding people they don't know in person, or looking up codes on YouTube/Discord/Reddit.
- The ads themselves. Sit nearby for a few sessions and watch two or three full-screen ads with your own eyes. This is the fastest way to learn what the rating couldn't tell you.
- Session pattern and the wheel. Are they playing when they want to, or logging in because the streak demands it? Irritation or anxiety at missing a daily reward in week one is a strong early signal.
- Purchase pressure. Any asks for gems, any "it's only $1.99," any curiosity about the stored payment method on the shared tablet.
- Exit behavior. How do sessions end — naturally, or with negotiation and "one more spin"? And does their mood after playing look like after other games they enjoy, or worse?
One practical note before day one: whatever chat and purchase restrictions you decide on, set them before the first session — retracting access after they've tasted it is a much harder conversation than never granting it.
The decision's yours, as you said. But notice that of everything you listed, only one feature directly conflicts with something you already know about this specific kid — the open text chat — so a lot of the judgment may reduce to question 1: whether that feature is avoidable inside this particular app.
What we found
All four asks: what the rating does and doesn't evaluate, which described features it may not capture, five questions about this kid specifically, and a first-week watch list. It kept the decision with the parent and noticed the judgment may reduce to one question: whether the chat is avoidable inside this app.
Card 5: Is this the real one?
Use this when: the app might be a copycat of a better-known app, and you want to judge substance rather than polish.
I think this app might be a copycat of a better-known app. Help me judge substance rather than polish. Work from what I give you here; I'll verify on the store pages themselves. The app on the device (name, developer, what its listing says): [PASTE — remove personal details first] The app I think it's imitating (name and developer, if I know it): [PASTE, OR WRITE "NOT SURE"] What made me suspicious: [PASTE YOUR OBSERVATIONS] Tell me: 1) which of the details I gave carry real signal about whether an app is what it claims to be — the developer name, what it asks for, its sign-up flow — and which are easy to imitate, 2) what a side-by-side check of the two store listings should compare, and 3) what to look at inside the store listing (the developer's other apps, contact information, listing history) before deciding. If you can't tell from what I've given you, say so.
How the AI reads this prompt: The prompt separates what you saw from what you suspect, so the AI can weigh signal against hunch. Asking which details are hard to imitate versus easy teaches the durable skill — copycats reproduce polish much faster than substance. The comparison list and the in-store checks give your verification a shape before you go do it.
What to do with the answer: The AI's read is a hypothesis. The developer's catalog, contact details, and the two listings side by side — in the store itself — are what settles it, and if it settles badly, the store's own report function is the next stop.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
Good instinct to separate substance from polish here — most of what makes a listing look trustworthy is exactly the stuff that's cheapest to fake. Let me take your three questions in order, then tell you plainly what I can and can't conclude from what you've given me.
1) Which details carry real signal, and which are easy to imitate
Easy to imitate (treat as near-zero evidence of legitimacy):
- Name and icon. These are the copycat's whole trade. A close-copy name like "Gem Stackers Blast" costs nothing and is chosen because it resembles something famous. Similarity here is a reason for suspicion, never reassurance.
- The listing description. "Swap gems, clear levels, join a clan" is generic match-3 boilerplate that could be pasted onto any app. It tells you nothing.
- The star rating by itself. 4.6 stars is easy to farm with purchased reviews, especially on a new app with few raters. The number of ratings and what the reviews actually say carry the signal, not the average.
- The content rating (E / PEGI 3). This comes from a self-completed questionnaire by the developer. It is not a vetting stamp.
- "Contains ads / Offers in-app purchases" labels. Standard disclosures; both legitimate games and junk apps carry them.
Real signal (harder to fake, or fake attempts leave traces):
- The developer name — but only when you check it, not read it. Anyone can register "Luminary Pixel Works Ltd." The signal isn't the name; it's the record behind it: how long the developer account has existed, what else it has published, and whether the famous game's actual publisher matches. The big gem-matching games are published by long-established studios with recognizable names and enormous portfolios. An unknown developer publishing something that looks like a household-name game is a genuine yellow flag.
- The absence of a website. You spotted this yourself, and it's meaningful. Real studios — even small ones — maintain a website, a support email, and a privacy policy that names the company. A listing with no web presence is a negative signal that's hard for a fly-by-night operation to fix convincingly, because a hastily built site is itself checkable (registration date, placeholder pages, mismatched company names).
- What the app asks for (permissions / data safety). You haven't given me this, but it's one of the strongest tells. A match-3 puzzle needs essentially nothing: network access for ads, maybe storage. If it requests contacts, SMS, accessibility services, device admin, or "install unknown apps," that's a red flag regardless of everything else.
- The sign-up flow. Also strong, also not in what you gave me. A puzzle game that pressures you to log in — especially with credentials for some other service (Google password typed into the app's own form, Facebook login on a non-Facebook-looking page) — has crossed from "derivative game" into "credential harvesting" territory. Legitimate games let you play as a guest.
2) What a side-by-side of the two store listings should compare
Once you identify the famous game (more on that below), put the two listings next to each other and compare:
- Developer name and developer page. Tap through to each developer's profile. The real one will have an established portfolio; note the exact publisher name so a near-miss spelling jumps out.
- Install/download count. This is the hardest thing to fake at scale. A famous match-3 game will show tens or hundreds of millions of downloads. A copycat will show a tiny fraction of that. A huge gap between fame-of-name and size-of-install-base is the single clearest tell.
- Number of ratings, not just the average. Millions of ratings vs. a few hundred tells you which one the world has actually vetted.
- Release date and update history. Established games are years old with a steady update cadence. A listing that appeared recently, with a version history measured in weeks, doesn't match a famous title.
- Screenshots and promo art. Copycats often lift or lightly alter the original's screenshots. Look for inconsistent art styles between screenshots, or gameplay images that don't match the icon's style.
- Data safety / privacy sections. Compare what each says it collects. A puzzle game declaring collection far beyond the original's is informative.
- Contact details. The real publisher lists a working website, support email, and usually a physical address. Compare completeness, not just presence.
3) What to examine inside the suspect listing before deciding
- The developer's other apps. This is often decisive. An account whose portfolio is a dozen lookalikes of different famous games — a gem game, a bird-slingshot game, a candy game — is a clone farm. A legitimate small studio has a coherent, original portfolio, even if it's short.
- Contact information, followed to the end. No website (as here) is one strike. If there's an email, does its domain exist? If a site appears later, check whether it names "Luminary Pixel Works Ltd." consistently and has a real privacy policy, not a template with blanks.
- The reviews' text, not their stars. Farmed reviews cluster in date, repeat phrasing, and stay vague ("great game! fun!"). Also sort by newest and by lowest: genuine victims often leave recent one-star reviews saying "fake," "scam," "not the real game," or describing surprise charges. Those are worth more than the 4.6 average.
- Listing age and churn. Copycats get taken down and republished under new names. A very recent publish date, or reviews that reference a different app name than the current one, suggests the listing has been renamed — a strong red flag.
- The in-app purchase price list. Some stores show the IAP range. Copycats sometimes carry oddly priced or unusually expensive items relative to the original.
What I can't tell you from what you've given me
Two honest limits:
-
I can't tell you which game it's imitating. "Gem-matching, famous, gem in the name" narrows it to a small field of well-known titles, but guessing wrong would send your side-by-side comparison against the wrong target. The reliable way to find the original: search the store for the famous game as you remember it (or search the web for "gem match game" plus whatever you remember of its real name), and confirm it's the one with the massive install count and the recognizable publisher. Then run the comparison above.
-
I can't tell you whether this app is malicious, a cynical-but-legal clone, or even legitimate. Everything you've quoted — name, description, rating, content rating — is consistent with all three. What you've observed (near-copy name and icon + unknown developer + no website) is a legitimate basis for suspicion and fully justifies checking before installing or signing into anything, but it isn't proof. The evidence that would actually settle it is the stuff in sections 2 and 3: install counts, developer portfolio, review text, permissions, and the sign-up flow.
One last practical note: if your checks do point to a copycat, don't just uninstall — make sure you never entered any credentials into it (if you did, change that password from another device), and use the store's "report" or "flag" option on the listing. And be aware there's a middle category that's common in this space: apps that aren't impersonating anyone in a legal sense but exist purely as ad-delivery vehicles wrapped in a familiar-looking skin. Those won't steal your password, but they're still not worth your time — and the same checks above will surface them too.
What we found
Signal versus imitable sorted as promised, a side-by-side comparison list, in-store checks — and its two limits stated plainly: it can't name the imitated game from "not sure," and it can't render a verdict. The install-count check — which the post calls the hardest thing to fake at scale — is the strongest single teaching in this batch's copycat coverage.
Talk & keep · the conversation and the habit
Card 6: The talk
Use this when: you've done the homework and now want a conversation with your kid that starts from curiosity, not confiscation.
A new app showed up on my kid's device and I've already done some homework on what it is. Now help me have the conversation with my kid — one that starts from curiosity, not confiscation. I want to understand why they got it and what they like about it, keep their dignity intact, and still reach a real decision about whether and how it stays. Context, in general terms only: [PASTE THE KID'S AGE AND WHAT KIND OF APP IT IS — no names, no other identifying details] Draft: 1) three opening lines that invite my kid to show me the app and tell me about it, 2) four questions that surface what the app actually is in their world — who they use it with, what happens in it, what they'd miss without it, 3) two ways to raise a concern I have without accusing them of doing something wrong, and 4) one way to close the conversation that sets a next step we decide together.
How the AI reads this prompt: The framing line — curiosity, not confiscation — does real work: it sets every draft the AI produces inside that stance. The general-terms context keeps the drafts age-appropriate without putting your kid in the chat. The four numbered pieces map to the arc of an actual conversation: opening, understanding, raising the concern, deciding together.
What to do with the answer: These are drafts, not scripts — say them in your own voice. What your kid tells you about the app is also first-hand data for the other cards, and better than anything in a listing.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
This is a great way to approach it — kids can smell an interrogation from a mile away, and an 11-year-old who feels accused will shut down before you learn anything. Here's a full conversation kit.
1) Three opening lines that invite them to show you the app
-
"Hey, I saw you've got a new game — is that the one with the matching puzzles? Show me how it works, I want to see what a good level looks like." Leads with the game itself, not the chat feature, and asks them to be the expert.
-
"What are you playing these days? I feel like I'm behind on what's good." Even more open — lets them bring the app up themselves, which tells you something about whether they see it as no big deal or something to be cagey about.
-
"Can I watch you play a round? I promise not to backseat-drive." Watching them play side-by-side is the single best format for this conversation. You'll see the clan chat naturally, without having to ask for it.
Tip: do this while they're relaxed — in the car, during a snack, not right at bedtime or right after a conflict.
2) Four questions that surface what the app actually is in their world
-
"Did a friend get you into this, or did you find it yourself?" Surfaces the social origin. "Everyone at school plays it" is a very different situation from "an ad showed it to me," and it tells you what's really at stake if the app went away.
-
"What's the clan thing? Who's in yours — do you know them from school, or are they people from the game?" Asked with genuine curiosity, this is the key safety question — but framed as interest in their team, not suspicion. Listen for whether clanmates are known kids, strangers, or a mix, and whether chat happens in the app or spills into other platforms.
-
"What's the best thing that's happened in the game so far? And has anything weird or annoying ever happened in the chat?" Pairing "best thing" with "weird thing" makes the second question feel like normal conversation instead of a trap. Kids will often volunteer the odd message from a stranger if you ask casually and don't react big when they answer.
-
"If the game disappeared tomorrow, what would you actually miss — the puzzles, the people, or your streak?" This one does the most work. It tells you whether the app is entertainment, a friendship space, or a habit loop (free match-3 games are engineered around streaks, timers, and purchase nudges) — and each of those calls for a different decision at the end.
3) Two ways to raise your concern without accusing them
-
Make the app the subject, not the kid: "You haven't done anything wrong — I'm not worried about you, I'm curious about the app. Games like this are free because they're built to keep people playing and sometimes to get them chatting with strangers or spending money. I want us to look at the chat settings together so we know how it works, not because I think you've messed up."
-
Use a shared-team frame with a story: "Can I tell you why I'm asking so many questions? Kids sometimes get messages in game chats from people who aren't who they say they are, or get pushed to buy stuff. If anything like that ever pops up, I want you to know you can show me and you won't be in trouble and you won't automatically lose the game. Deal?"
That last clause matters more than anything else in this conversation: the #1 reason kids hide problems is fear that reporting a problem = losing the app.
4) One way to close with a next step you decide together
"Okay, here's where I've landed: the game seems fine, and I get why you like it. Let's set it up together so it stays fun — you pick which of these we do: turn clan chat to friends-only, or keep chat on but you show me the clan once a week for a couple weeks. And let's agree on when it gets played. Then in two weeks we'll check in for five minutes — if it's all going fine, I back off. Sound fair?"
Why this shape works: - A real choice between two acceptable options gives them agency without giving up the safety outcome. - A defined check-in with an expiration ("then I back off") signals trust is the default, monitoring is temporary. - Concrete settings, not vague rules — while you're in there together, it's also the natural moment to check that purchases require a password and that the account doesn't display their real name, age, or photo.
One last thing: if the answers to section 2 raise a real flag — clanmates who are adult strangers, chat moving to another app, requests for photos or personal info — don't escalate in the moment. Stay calm, thank them for showing you, and come back to it after you've decided what to do. The goal of conversation #1 is to make sure there's a conversation #2.
What we found
The four numbered pieces, in the curiosity register the prompt sets, with the no-punishment-for-reporting promise carried twice. Nothing here is written for anyone who isn't in the room. One consistency slip worth noticing: it ends by inviting you to share the app name and your kid's age — keep those in general terms, as the post itself asks.
Card 7: Make it a habit
Use this when: you want to turn what this one app taught you into a family routine you'll actually keep.
We've just worked through an unfamiliar app together as a family, and I want to turn what we learned into a device habit we can actually keep — a routine, not a lecture. Help me draft it; I'll set any actual controls in the device's or store's own settings. What we decided about this app: [PASTE IN A LINE OR TWO — no names] Our household in general terms (number of kids and rough ages, shared or individual devices): [PASTE — general terms only] Draft: 1) a short family rule for new apps, in plain words a kid can repeat back — who asks whom, and when, 2) a five-minute checklist the adult runs when a new app comes up (listing, developer, permissions, purchases, chat), 3) a once-a-month, ten-minute review we could realistically do together, and 4) the one habit to keep if we keep nothing else. Keep it to one page, and keep the tone respectful of the kid.
How the AI reads this prompt: Leading with what you decided grounds the habit in a real case rather than a generic policy. The household description, in general terms, sizes the routine to your actual family. Asking for a kid-repeatable rule, a five-minute checklist, and a one-habit fallback forces realistic scope — routines fail by being too ambitious. The reminder that controls are set in the platform's own settings keeps the AI drafting and you operating.
What to do with the answer: Trim the draft to what your family will actually keep doing. Any real restriction — purchase approvals, download approvals, content filters — is set in the device's or store's own settings, where you can also see exactly what it covers.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
Love this approach — a routine built off a real decision you already made together sticks far better than rules handed down. Here's a one-page draft you can print or pin. Everything below is habits and conversation; any actual settings (purchase approval, chat toggles) stay in the device's or store's own controls, as you said.
Our Family App Routine
1. The Family Rule for New Apps
"Ask before you install. We look at it together before I play it."
That's the kid-repeatable version. The slightly longer version everyone agrees to:
- Who asks whom: Kids ask a parent before downloading anything new — even free apps, even ones friends have.
- When: Before the download, not after. Asking after isn't in trouble, but the app waits until we've looked at it together.
- The promise back: Parents will actually look at it with you, usually the same day — not just say no. "No for now" comes with a reason.
2. The Adult's Five-Minute Checklist (run it with the kid watching)
When a new app comes up, sit together and check:
- [ ] Listing — Read the store page. Does what it says it does match what the kid thinks it does? Check the age rating and skim a few recent reviews.
- [ ] Developer — Who made it? Do they make other things you recognize? A no-name developer isn't automatically bad, but it means look closer.
- [ ] Permissions — What does it want? Camera, microphone, contacts, location? Ask out loud: "Does a drawing app need to know where we live?" (Kids get good at this question fast.)
- [ ] Purchases — Does it have in-app purchases or a currency/loot mechanic? Confirm purchase approval is on before the first launch, not after the first "oops."
- [ ] Chat — Can strangers talk to my kid in this app? Group/clan chat, DMs, voice? Decide the setting together and say the reason out loud — like you did with this one.
Then say the decision plainly: "It can stay, with ___ off and ___ on." One sentence, so everyone can repeat it later.
3. The Monthly Ten-Minute Review (together, snacks allowed)
Once a month — tie it to something you already do, like the first Sunday dinner:
- (3 min) Each kid shows their current favorite app and one thing they like about it. Parents just listen first.
- (3 min) Quick scan together: any new apps, any changed settings, any purchase requests that came through. On the shared tablet, do this as a group.
- (2 min) One question, asked casually: "Anything weird happen in any app this month — a message, a pop-up, someone you didn't know?" No punishment for the answer, ever. That's the deal that keeps them talking.
- (2 min) Prune one app nobody uses, and let the kids pick it.
4. If We Keep Only One Habit
Ask-before-install, answered with "let's look at it together."
Everything else flows from that one exchange. It keeps parents in the loop without spying, teaches kids how to judge an app instead of just whether they're allowed, and — most importantly — it means the day something genuinely weird happens in an app, coming to you is already the normal move, not a confession.
A couple of notes on tone, since you asked for it to respect the kids:
- The 11-year-old can graduate into running parts of the checklist ("you check the permissions and tell me what you find"). That turns the routine from supervision into training, which is the whole point.
- The 8-year-old's version of success is just reciting the rule and sitting through the five minutes. That's enough at 8.
- Keep the "no punishment for telling us" promise sacred. One broken instance of that costs you the monthly question #3 forever.
Want me to trim this to an actual half-page fridge version, or adapt the wording so each kid has their own age-appropriate copy?
What we found
The four pieces landed sized to the actual household described, with different expectations for the 8- and 11-year-old, and controls routed to platform settings throughout. It ends offering variants; one page is the version worth keeping.
Before you paste anything
Before running any of these prompts, strip the personal details out of whatever you paste: your name, your kid's name or username, email addresses, the school, the street, account numbers, and any codes or passwords — none of it is needed for the reasoning. Describe people in general terms ("my 11-year-old") and let the app's public details — its name, its developer, its listing text — carry the specifics. The prompts work exactly as well on the anonymized version.
One line above deserves its own note: “exactly as well” is the post’s claim, not ours — anonymizing shouldn’t change the reasoning, and we haven’t measured it.
When AI is the wrong tool
Some moments call for acting directly, not asking:
- Money has already been charged. Go to the card issuer and the app store's own refund process first (both major stores have one, reachable from the purchase receipt or account purchase history); the research can wait.
- A stranger has been contacting your kid through the app. Use the platform's in-app reporting tools, keep the messages rather than deleting them, and where the contact is sexual, threatening, or persistent, involve law enforcement — in the US, reports can also go to the NCMEC CyberTipline (CyberTipline.org).
- A password went into something that now looks like a fake. Change that password from the real service's own app or site, right away, before any further investigating.
- Your kid is upset about something that happened in the app. That conversation comes before any of these cards — the app research can follow it.
Where this leaves you
You now have a repeatable route from unknown icon to informed family decision: look together, ask well, verify in the store and the settings, then talk. The next unfamiliar app won't require starting from zero — you'll be better prepared to ask.
Questions you might still have
The answers below are ours — the site’s, not the AI’s. They describe the runs published above, as of 2026-08-19.
Your answer will differ — differ how?
We don't know yet in any measured way — one run is one sample, and we ran each prompt once. The sources of difference we can name: your product and tier, whether it can browse, and what you paste. The prompts are built so the part that matters — what to check and where — survives the variation. Real re-run data, when we have it, gets published.
The examples all read confident, and all six are good. Did you get bad runs — and what would a wrong answer look like?
These are the runs we got — each one is the first and only roll, published unedited; nothing was re-rolled for a better take. We haven't yet seen a confidently wrong run on these prompts, which is a statement about a handful of samples, not about your odds. A wrong answer looks like a specific claim the store page or the device contradicts — which is why every card ends with a check you do outside the chat.
What does it actually look like when pasted content "shapes the answer"?
Usually: the answer adopts the pasted text's framing — a listing's marketing language starts appearing in the AI's own sentences, or the answer treats the listing's claims as observations. If you notice the answer agreeing with the pasted material more than examining it, that's the tell. The habit that counters it: label what you paste ("the listing claims…") and ask the AI to separate claims from evidence.
Your runs used no web access. Mine can probably browse. Does any of this still hold?
Yes — the structure holds either way; what changes is where the answer's facts come from. A browsing AI may pull current listing data, which can help — and then its sources need the same date-and-source scrutiny the cards teach. "Work from what I give you here" still scopes the session; a browsing product may look anyway, so treat anything it cites the way you'd treat the listing: a claim to check.
"The answer shouldn't require a research project" — then card 3 hands me a twelve-item checklist. What does this cost on a Tuesday night?
Fair. The full seven-card pass is an evening the first time — we won't pretend otherwise. It isn't the Tuesday-night version: cards 1 and 2 alone give a serviceable first pass in the time it takes the kid to lose interest, and card 7 exists so the next app costs far less. The long version is for the app that fails the short one.
The example suggests testing the age gate by signing up with an under-13 birthdate — on an app I already suspect. Doesn't that create the account and data trail the rest of the post warns about?
It can, and the tension is real. Run the store checks first — they need no account. If an app has already failed the knockoff or permissions checks, skip the sign-up test entirely; there's nothing left for it to tell you. If you do run it on an app still in consideration, use an address that isn't your kid's or your main one, invent the details, and use the account deletion path afterward — the example itself notes that an app with no way to delete an account is its own finding.
Built the way every post here is built: we brief, a platform writes, we run the prompts and publish what came back — including where it fell short. We never edit a prompt.
Site footer — appears once on every page (approved H024)
charades.net
About this content
Everything in this section is produced by AI. The prompts you see are the direct, unedited output of ChatGPT, Gemini, and Claude — and they may be incorrect. Any part of this site may be incorrect. We are not a security company and we do not have a legal team; nothing here is legal or professional security advice.
What we offer is exactly this: the results of asking the leading consumer AI tools how to use prompts that answer the question “How do I talk to A.I. about cybersecurity?” — plus our best effort to fact-check and review this content using current AI tools. Nothing more.
No prompt can make you or your business safe; our goal is to help you start better conversations with AI about becoming safer.
Details of how these posts were validated: How we check these posts.