What we did to check these posts
charades.net · prompt post
written by ChatGPT · prompts uneditedWhat did my kid just install?
This post was written by ChatGPT from our standing brief. We never edit a platform’s prompts — a defect gets a public note, never a quiet fix. Before publishing, we ran every prompt; what came back appears beneath each card, unedited, with its run conditions.
Directions given to the A.I.
The complete topic brief this post was written from, published so you can judge the answer against the ask. Two standing instruction files (the required post structure, and the audience/standards/forbidden list) travelled with it, identical for every post in this batch, as of 2026-08-19.
# THEME PROMPT — batch 02: "What did my kid just install?"
You are writing one complete blog post for a new section of charades.net. Two
files are attached: FILE A (the exact structure your post must follow) and
FILE B (the audience, voice, standards, and forbidden list that bind everything
you write). Read both before writing.
## THIS BATCH'S TOPIC: "What did my kid just install?"
A new app has appeared on a kid's phone or tablet — a game, a chat app,
something from an ad — and the reader wants to know what it actually is before
deciding what to do about it. Write to the person WITH THE DEVICE IN REACH —
usually the parent, sometimes a family helper sitting down at the kid's phone
WITH the family. Your post gives them copy-paste prompts that turn their AI
assistant into a working session about the app: what to find out, what the
findings mean, and how to have the conversation that follows. **This is
first-hand work: the person, the device, and the AI in the same session. Do
not write prompts for assessing an app secondhand — from a description
relayed by phone, or to produce an answer to pass along to someone who isn't
there.** (If a relative asks for help, the post's answer is: be there — look
at the device together, with the AI.)
Cover the ground a real reader stands on:
- **The first look:** prompts that work from the app's name and what the
reader can observe (store listing basics, the developer's name, what the
kid says it does) to build a plain-language picture: what kind of app this
is, what it is known for, how it makes money.
- **The permissions conversation:** what the app asks for (camera,
microphone, location, contacts) and whether that is proportionate to what
it does — prompts that help the reader reason about proportion, not
memorize lists.
- **The data and money questions:** accounts it requires, what it collects,
chat-with-strangers features, in-app purchases and loot-box mechanics —
prompts that surface what to check, with the reader confirming specifics in
the app's own store listing and settings.
- **The age and content fit:** prompts that help the reader weigh an age
rating against what the app actually does, for THEIR kid — the AI helps
structure the judgment; it does not make it.
- **The knockoff check:** clone apps and ad-stuffed copycats exist — prompts
that help the reader judge substance (developer, permissions, what it asks
for) rather than polish.
- **The conversation with the kid:** at least one card that makes the talk
easier and keeps the kid's dignity — curiosity first, not confiscation
first. The reader is answering for someone else's family peace as well as
their security.
- **The follow-through:** turning what was learned into a family device habit
the reader can actually run — the AI helps draft the rule or the checklist;
the reader sets the controls in the platform's own settings.
**Where verification belongs, say so plainly:** the AI works from what the
reader gives it. What the app currently does, what this build asks for, and
what the store page says today are checked in the store listing and the
device's own settings — the AI conversation prepares that check; it does not
replace it. **Which is also why this work is first-hand: the person in the
session must be the person who can look at the device.**
ANGLE: a working session, not a lecture. The reader already knows apps can be
junk and already uses AI — what they have never had is the two put together:
a repeatable way to go from "unknown app" to "informed answer" to "reasonable
family rule," with their assistant doing the structuring.
## BOUNDARY (states the pack's own rule — do not cross it)
Do not write prompts that demonstrate, simulate, or explain how an attack or a
scam is performed. Every prompt helps the reader assess, harden, verify,
respond, or recover — nothing else. Do not claim any prompt makes the reader
or their family safe; certainty claims are forbidden per FILE B. Do not write
anything that shames the parent or the kid. **And per FILE B item 10: no
prompt or advice for working a security or app question on someone else's
behalf, secondhand — helping another person is taught first-hand only, at the
device, together.**
## STRUCTURAL CHECKLIST (mirrors FILE A Part I — self-verify before returning)
Your post must contain, in order, with these exact `##` headings:
[ ] Title options — exactly 3, each ≤ 80 characters, reader-voice
[ ] The moment — 2–4 sentences, no statistics
[ ] What this post offers — one paragraph
[ ] The prompt cards — 6 to 9 cards, each with: **Use this when:** · the
complete prompt in a fenced code block with a [PASTE …] placeholder or the
literal token NO INPUT NEEDED · **How the AI reads this prompt:** (2–5
sentences) · **What to do with the answer:** (1–3 sentences)
[ ] Before you paste anything — one paragraph (remove personal details —
real names, the kid's identity, account details)
[ ] When AI is the wrong tool — non-empty (e.g. an app that has already taken
money → the card issuer and the app store's refund process first; anything
suggesting contact with a minor by a stranger → the platform's reporting
tools and, where warranted, law enforcement)
[ ] Where this leaves you — 1–3 sentences, no achieved-state claims
[ ] Global: 800–1,800 words excluding code blocks · every statistic sourced
and dated inline or omitted · no sections beyond the seven
Do not include execution examples, sample AI responses, or an FAQ — those are
added after your draft is received, from real runs of your prompts.
## RETURN FORM
One complete post, in markdown, following FILE A exactly, under your own
platform name. One shot: no follow-up questions — flag unresolvables inline.
The moment
A new app has appeared on your kid's phone or tablet, and you do not recognize it. Maybe it is a game, a chat app, or something installed after an ad. The device is in front of you, and you want enough information to decide what deserves a closer look and what conversation needs to happen next.
What this post offers
The cards below give you copy-paste prompts for working through that app with your AI while the device is in reach. They help you organize what you can observe, identify what still needs verification, and read the AI's answer without treating it as the final authority.
The prompt cards
Seven prompts, each with what came back when we ran it.
The route — seven cards, three moves
Look · get the picture
Check · permissions, money, fit, identity
03 Check data, accounts, and money
04 Judge the age and content fit
05 Check for a knockoff or copycat
Talk & keep · the conversation and the habit
Look · get the picture
Card 1: Take the first look
Use this when: You know the app's name but want a structured picture of what it appears to be before deciding what to investigate next.
I am sitting with the phone or tablet that has this app installed. Help me investigate it without assuming that its name, appearance, or store description tells the whole story. Before pasting anything here, I will remove or replace personal details, including real names, usernames, email addresses, account numbers, addresses, passwords, one-time codes, and identifying details about a child. Here is what I can see: App name: [PASTE THE APP NAME HERE — remove personal details first] Developer or publisher shown in the store or device: [PASTE THE DEVELOPER NAME HERE — remove personal details first] Store description or other visible details: [PASTE RELEVANT STORE-LISTING TEXT HERE — remove personal details first] What the person using the app says it does: [PASTE A SHORT DESCRIPTION HERE — do not include the child's name or identity] Build a plain-language first-look assessment. Please separate your answer into: 1. WHAT THE EVIDENCE SAYS - What kind of app this appears to be. - What its main functions appear to be. - What business model may be involved, such as advertising, subscriptions, in-app purchases, or paid upgrades. 2. WHAT YOU ARE INFERRING - Clearly label anything that is an inference rather than something supported by what I pasted. 3. WHAT I SHOULD CHECK ON THE DEVICE OR STORE PAGE - Developer identity. - Current store listing. - Age or content rating. - Purchase model. - Account requirements. - Permissions. - Recent update information. 4. QUESTIONS STILL OPEN - List the most important questions that cannot be answered from the information I provided. If you can reliably access current public information about this app, identify the source and date separately. Do not treat an app as trustworthy merely because it looks polished or appears in an app store. Do not tell me to open unfamiliar links or test suspicious content.
How the AI reads this prompt: The first section makes the AI distinguish observations from assumptions instead of collapsing everything into one verdict. The verification section turns uncertainty into a short list of things you can inspect while the device is still in front of you. Asking for sources and dates also makes current information visibly different from details supplied in the session.
What to do with the answer: Use it as an investigation map, not a verdict. Confirm the current developer, listing, rating, account requirements, and other specifics in the app store and on the device itself.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
How to read what follows: we ran the complete prompt above, exactly as written, in a fresh AI session before publishing. One run is one sample — your answer will differ. The AI’s read is a first opinion, never a clearance: what you paste is read by the AI as content and can shape its answer, so verify through a channel you already trust — the store listing and the device’s own settings.
The response, as received — unedited
Good approach — treating the store listing as a claim to verify rather than a fact. Here is a first-look assessment based only on what you pasted.
A note up front: I cannot browse the app store live from here, and I don't have verified, dated information about an app called "Gem Stackers Blast" by "Luminary Pixel Works Ltd." in my knowledge. So everything below is analysis of what you provided, not a lookup. Treat the store page on the device itself as your primary source.
1. WHAT THE EVIDENCE SAYS
What kind of app this appears to be. The listing describes a free match-3 puzzle game (the "swap gems, clear levels" genre). The rating shown — E (Everyone) / PEGI 3 — is the lowest content tier, which speaks only to the game's content (no violence, profanity, etc.), not to its data practices or spending mechanics.
Main functions, per the listing and the player. - Match-3 puzzle gameplay in levels. - Social features: "join a clan," "compete with friends," and — per the person using it — friend codes for adding people. That means the app supports some form of contact or interaction between users, potentially including strangers. This is the single most consequential fact in what you pasted. - The 4.6-star figure is a popularity signal only; ratings can be inflated, purchased, or simply reflect the game being fun. It says nothing about safety.
Business model. The listing states two revenue streams explicitly: - Advertising ("Contains ads") — in a free game, this often means third-party ad networks, which typically involve data collection for ad targeting and can show ad content the developer doesn't fully control. - In-app purchases — in match-3 games these are commonly consumables: extra moves, lives, boosters, currency bundles. These games are frequently designed so that difficulty spikes create purchase pressure. The E/PEGI 3 rating does not restrict or evaluate spending mechanics.
2. WHAT YOU ARE INFERRING (labeled as inference)
- Inference: "Join a clan" very likely implies chat or messaging of some kind — clan features in this genre usually include at least a group text channel. The listing does not actually say "chat," so verify this on the device.
- Inference: Friend codes suggest the developer intended a semi-closed friend system (safer than open matchmaking), but codes get shared publicly on Discord, YouTube comments, and school group chats, so in practice it can still connect a child with strangers.
- Inference: Clan and friend features almost certainly require an account and a persistent player identity (a visible username), and likely network transmission of gameplay/social data.
- Inference: A free, ad-supported match-3 with a generic three-word name and an unfamiliar developer fits a very crowded template. Many such apps are perfectly ordinary; a smaller number are low-effort clones with aggressive ad or data practices. Nothing you pasted distinguishes which this is — that's exactly what the checks below are for.
- Inference: "Everyone at school plays it" tells you about popularity, not safety, and popular kid-facing games are also popular targets for impostor/clone apps with near-identical names.
3. WHAT TO CHECK ON THE DEVICE OR STORE PAGE
- Developer identity. On the store page, tap the developer name "Luminary Pixel Works Ltd." Do they have other apps? A working website and support email? A physical address (required in some regions)? Compare the developer name on this install against the listing — a clone often copies the game name but not the publisher. If the game is one your kid's friends play, confirm the friends' copies show the same developer name.
- Current store listing. Confirm the installed app actually matches the store entry (same icon, same name spelled the same way — watch for "Gem Stacker Blast" vs "Gem Stackers Blast!"-style near-duplicates). Check download count and read a page of recent, critical reviews — sort by newest, and skim the 1–2 star ones; that's where problems surface.
- Age/content rating. Note that E/PEGI 3 rates content only. Look for the interaction disclosures many stores now show, such as "Users Interact," "In-Game Purchases," or "Shares Location" — these appear near the rating and matter more than the rating itself.
- Purchase model. On the store page, expand the in-app purchases section to see the price range (e.g., "$0.99–$99.99 per item"). On the device, check whether purchases require authentication (Ask to Buy / purchase password / biometric) and review the purchase history for this app.
- Account requirements. Open the app's settings: is there a logged-in account? Tied to which email or platform (Game Center, Google Play Games, Facebook, the developer's own account)? What username is publicly visible to clan members?
- Permissions. In device settings (not the app), check what the app has been granted: contacts, microphone, camera, location, photos. A match-3 game needs essentially none of those. Also check the store's data-safety / privacy label for what data the app says it collects and shares.
- Recent update information. When was it last updated, and what do the update notes say? A long-abandoned app keeps its vulnerabilities; a very recently renamed or transferred app is worth a closer look.
- The social features themselves. Open the clan screen with your kid and look: is there free-text chat? Can strangers message them? Is there a setting to restrict friend requests to friend-code-only, or to disable chat? This check is the one the store page can't do for you.
4. QUESTIONS STILL OPEN
These cannot be answered from what you pasted:
- Is there chat, and who can use it? Free-text chat with strangers vs. preset phrases vs. none — this changes the risk picture more than anything else here.
- Is this the genuine app or a clone? Nothing pasted verifies that the installed app, the store listing, and the game the schoolmates play are all the same app from the same developer.
- What data does it actually collect and share, especially given ads — and does the developer make any children's-privacy commitments (e.g., COPPA-related statements, an under-13 mode)?
- What is the real spending exposure? Maximum purchase price, whether purchase confirmations are enabled on this device, and whether any purchases have already happened.
- What account identity is exposed? What name/photo other players see, and whether the account links to a real email or social profile.
- Who is the developer, really? Track record, other apps, responsiveness to support requests.
- What do recent reviews complain about? Recurring themes (surprise charges, inappropriate ads, chat problems) are strong signals either way.
Suggested order: verify the developer/listing match first (question 2), then sit down with your kid and open the clan/chat screens together (question 1), then lock down purchase confirmations. Those three cover most of the practical risk, and the middle one has a side benefit: it keeps this a conversation rather than an inspection.
One boundary to keep: as you said, don't paste usernames, friend codes, or anything identifying about your kid into any AI chat — describe features generically, as you did here, and do the account-specific checks on the device itself.
What we found
It did what the card teaches, in the card's own order: evidence, labeled inference, device checks, open questions — and it opened by saying it had no verified knowledge of this app and would not guess, which is exactly the behavior the card promises. It accuses nothing and routes the identity question to the developer checks. One line to notice: "I cannot browse the app store live from here" is a statement about the product that ran it; yours may behave differently.
Check · permissions, money, fit, identity
Card 2: Put permissions in context
Use this when: The app is asking for camera, microphone, location, contacts, photos, or other access and you want to judge whether the request fits the app's actual job.
I am reviewing an installed app while the device is in front of me. Help me reason about whether the permissions I can see are proportionate to the functions the app appears to provide. Before pasting anything here, I will remove personal details, usernames, account information, addresses, passwords, one-time codes, and identifying information about a child. App name and purpose as I understand it: [PASTE THE APP NAME AND PURPOSE HERE — remove personal details first] Permissions currently shown on the device: [PASTE THE PERMISSIONS HERE — remove personal details first] For each permission: 1. Explain what legitimate app function could reasonably use it. 2. Tell me whether that connection is obvious, plausible but worth checking, or unclear from the information provided. 3. Give me one concrete question to ask before leaving that permission enabled. 4. Tell me what function might stop working if the permission is denied or limited, if that can be determined from the evidence. 5. Identify anything I need to verify in the device's own permission settings or the current store listing. Do not use a checklist that treats every permission as automatically good or bad. Judge proportion: what the app does versus what access it requests. Separate observed facts, reasonable inferences, and unknowns. Do not make a certainty claim about the app from permissions alone.
How the AI reads this prompt: The app's purpose becomes the baseline, so a permission is evaluated in context rather than by reputation alone. The prompt also forces the AI to expose uncertainty and consider the tradeoff of limiting access. That keeps the discussion focused on proportion instead of a generic list of dangerous permissions.
What to do with the answer: Compare the reasoning with the permissions actually shown on the device. The AI cannot settle why this particular build requests access, so confirm the setting and the app's current behavior directly.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
Good framing — a match-3 game with social features is exactly the kind of app where some permissions have plausible uses and others deserve a hard look. I'll work through each permission using only what you've told me: the genre (match-3 puzzle), the social features (clans, friend lists), and the six permissions shown. Where the connection can't be determined from that, I'll say so rather than guess.
One note before the per-permission analysis: the fact that a permission is listed doesn't tell us whether it's currently granted, whether the app has actually used it recently, or why it was requested. Those are three different facts, and your device's settings screens can answer the first two. I'll flag where that matters.
1. Camera
Legitimate function that could use it: Scanning a QR code to add a friend or join a clan; taking a profile photo; AR-style features or photo-based avatar creation. Some games also use the camera for video chat features, though that's uncommon in match-3 titles.
Proportionality judgment: Plausible but worth checking. Friend-adding via QR code is a real pattern in social games, but it's an occasional convenience feature, not core to matching gems. Nothing you've described requires a camera.
Concrete question to ask: "Can I find any feature in the app's own menus — profile setup, friend adding, clan screens — that visibly uses the camera?" If you can't find one in a few minutes of looking, the request is unexplained.
What might break if denied: If a QR-scan or profile-photo feature exists, that specific feature would fail — typically with a prompt to re-enable. Core gameplay should be unaffected; a match-3 game does not need a camera to run. This is a good candidate for "deny and see what happens."
Verify on the device / store listing: Check whether camera access is currently granted or merely requested. On both major platforms, the permission settings show grant status, and recent OS versions show a usage log (privacy dashboard / app privacy report) indicating whether the camera was actually accessed and when. Also check whether the store listing's data-safety or privacy section mentions camera data at all.
2. Microphone
Legitimate function that could use it: Voice chat with clan members is the main candidate — some clan-based games offer it. Occasionally, ad networks embedded in free games have requested microphone access, which is a company's use, not a game function.
Proportionality judgment: Plausible but worth checking — leaning toward unclear. Voice chat in a match-3 game is possible but not typical of the genre. If there's no visible voice-chat feature, this permission has no evident justification from what you've described.
Concrete question to ask: "Is there a voice chat button anywhere in the clan or friends interface?" If yes, the request has a candidate explanation. If no, ask: "What in this app could possibly need to hear anything?"
What might break if denied: Voice chat, if it exists. Nothing else determinable from the evidence. Match-3 gameplay, matchmaking, and text-based clan chat do not need a microphone.
Verify on the device / store listing: Same as camera — grant status and the OS-level usage indicator/log. Microphone access on modern devices triggers a visible indicator when active; the privacy dashboard will show whether it has actually been used. If the app has used the microphone and you've never touched a voice feature, that's a meaningful finding worth acting on.
3. Location
Legitimate function that could use it: Weakest legitimate case of the six for this genre. Possible candidates: regional leaderboards or matchmaking, location-targeted ads, regional content/pricing. Note that none of these require precise location — country or region can be inferred from network information without this permission.
Proportionality judgment: Unclear from the information provided. A match-3 game with clans has no evident gameplay need for device location. "Nearby players" features exist in some games, but you haven't described one. Location-targeted advertising is a common actual reason, and that serves the ad network, not you.
Concrete question to ask: "Does the app offer any feature framed around 'near me' or local players — and if not, who benefits from this app knowing where the device is?"
What might break if denied: From the evidence available: probably nothing visible. If a nearby-players feature exists, it would stop working. Ads may become less targeted, which is not a loss to the user. This is the permission I'd be most comfortable denying outright and observing.
Verify on the device / store listing: Check whether the grant is "precise" or "approximate" and whether it's "always" or "only while using" — those distinctions matter a great deal and are visible in the device's permission settings. Check the privacy dashboard for actual access events. Check the store listing's data-safety section for whether location is declared as collected and whether it's marked as shared with third parties.
4. Contacts
Legitimate function that could use it: "Find friends who already play" — the app matches your address book against its user base to populate the friend list, or lets you send invites. This is a real feature in social games.
Proportionality judgment: Plausible but worth checking — with a caveat about cost. The function is plausible given the friend-list feature. But the price is high: this permission typically uploads other people's information — names and contact details of everyone in the address book, who never consented — to the app's servers. Proportionality isn't just "is there a matching feature," it's "is the feature worth what it takes." Friend-finding also usually works fine through invite links or friend codes, which need no contacts access at all.
Concrete question to ask: "Does the app offer a way to add friends without contacts access — a friend code, username search, or shareable link?" If it does, the permission is a convenience, not a necessity.
What might break if denied: The automatic "friends from contacts" discovery and possibly an invite-by-SMS flow. Manual friend adding (codes, usernames, links) and all clan features should be unaffected if they exist — which you can check in the app's own menus.
Verify on the device / store listing: Grant status on the device; the data-safety section of the store listing for whether "Contacts" is declared as collected and whether it's shared. If the listing doesn't declare contacts collection but the app requests the permission, that inconsistency is itself worth noting.
5. Photos / Media
Legitimate function that could use it: Choosing a profile picture from the gallery; saving screenshots of achievements or sharing images in clan chat. On older Android versions, this permission was also historically requested just to store game data — a platform-level quirk, not a spying signal by itself.
Proportionality judgment: Plausible but worth checking. Profile pictures and image sharing fit the social features you described. The key variable is scope: modern OS versions offer "selected photos only" or a system photo picker that requires no standing permission at all. Full-library access for a profile picture is disproportionate when a narrower option exists.
Concrete question to ask: "When I set a profile picture, does the app let me use the limited/selected-photos option, or does it insist on full library access?" An app that refuses the narrower grant when the OS offers one is choosing broader access than its feature needs.
What might break if denied: Setting a custom avatar from the gallery; saving or sharing images. Gameplay should be unaffected.
Verify on the device / store listing: Whether the device offers a limited-access grant for this app and what level is currently set; the OS privacy log for actual access; the store listing's declaration for "Photos" or "Files."
6. Full network access
Legitimate function that could use it: Nearly everything you described — clans, friend lists, leaderboards, cloud saves, updates, and (in a free game) ads. An online social game genuinely cannot function without network access.
Proportionality judgment: Obvious. This is the one permission on the list that is clearly proportionate to the described functions. Two honest caveats: (a) on Android this is a "normal" permission granted automatically, so its presence carries almost no signal either way; (b) it says nothing about what is transmitted — it's the pipe, not the contents. The other five permissions determine what could flow through it.
Concrete question to ask: Not really about disabling it — instead: "Given that this app has a network connection, which of the other granted permissions am I comfortable pairing with it?" Camera access without network is a local matter; camera plus network is a transmission capability.
What might break if denied: Effectively the whole app, where denial is even possible. Not a practical lever.
Verify on the device / store listing: Nothing specific to verify for this one beyond the data-safety declarations, which describe what the developer says travels over that connection.
Facts, inferences, and unknowns — kept separate
Observed facts (from what you've provided): - The app presents itself as a match-3 game with clans and friend lists. - Six permissions appear on the device: camera, microphone, location, contacts, photos/media, network.
Reasonable inferences: - Network, and probably photos/media and contacts, have plausible connections to the described social features. - Camera has a weaker but real candidate explanation (QR friend-adding, profile photos). - Microphone and location have no evident connection to anything you've described; their most common real-world explanations in this genre involve advertising or features you haven't observed.
Unknowns (cannot be determined from permissions alone): - Whether each permission is granted or merely requested; whether it has ever actually been used. The device's privacy dashboard can convert several of these unknowns into facts. - What data is actually collected or transmitted, and to whom. Permissions bound what an app may do, not what it does. - Whether the in-app features that would justify camera, microphone, or contacts access actually exist. A few minutes exploring the app's own menus answers this directly. - The developer's intent. A disproportionate permission is a reason to restrict and investigate, not proof of anything.
A closing point on method, since you asked for proportion rather than a checklist: the strongest single move available to you costs nothing — deny microphone, location, and camera, keep playing normally for a few days, and see what (if anything) actually breaks. On modern devices, denying a permission doesn't crash a well-built app; the associated feature prompts for re-enablement when genuinely needed. That experiment converts "plausible but worth checking" into observed evidence, on your schedule, with the permission off in the meantime. And since this device appears to involve a child's use — you mentioned removing identifying details about a child — it's worth knowing that both major platforms let a parent set permissions that the child can't silently re-grant, which makes the deny-and-observe approach durable rather than one-time.
What we found
The per-permission structure arrived complete — plausible use, broader use, a concrete question, what breaks if denied, where to verify — and it ends with a deny-and-observe test you run on the device. If any single judgment here is wrong in either direction, the remedy is that test, not the AI's opinion: a missed over-grab costs exposure until the test runs; a false alarm costs one toggled-off convenience.
Card 3: Check data, accounts, and money
Use this when: You want to understand what the app may collect, whether strangers can interact with the user, and where purchases or recurring charges can enter the picture.
I am reviewing an installed app with the device in front of me. Help me identify the data, account, communication, and money questions I should check before making a family decision about it. Before pasting anything here, I will remove personal details, real names, usernames, email addresses, payment information, account numbers, passwords, one-time codes, and identifying information about a child. What I can see in the app or store listing: [PASTE RELEVANT TEXT OR OBSERVATIONS HERE — remove personal details first] Organize the review into four areas: A. ACCOUNT - Does it appear to require an account? - What information does it appear to request? - What should I verify before creating or keeping that account? B. DATA - What categories of data does the material suggest the app collects or uses? - Which claims must be confirmed in the current store privacy information, privacy policy, or device settings? C. COMMUNICATION - Does anything I pasted suggest messaging, public posting, friend requests, user-generated content, voice chat, or contact with people the user does not already know? - What controls or settings should I inspect on the device? D. MONEY - Does the material suggest subscriptions, in-app purchases, virtual currency, randomized rewards, advertising, or other spending mechanisms? - What purchase controls and renewal settings should I inspect through the platform's own settings? For every section, distinguish: - what is supported by what I pasted, - what you are inferring, - what I still need to verify. Do not tell me to enter payment information, contact strangers, or test a questionable feature.
How the AI reads this prompt: Four separate buckets prevent the review from stopping at privacy while overlooking communication or spending. The repeated fact/inference/verification split makes the answer easier to audit against the device. It also pushes platform controls back to the platform rather than treating the AI as the control surface.
What to do with the answer: Check the app's current listing, privacy information, account screens, communication settings, and platform purchase controls. The AI can structure the questions, but the device and platform show what is actually configured now.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
Here's a structured review based on what you've pasted. Throughout, I'll separate what your material actually shows, what I'm inferring from common patterns, and what you still need to verify on the device or in the store listing.
A. ACCOUNT
Supported by what you pasted: - First launch asked for an email sign-up, so the app requests at least an email address. - Friend codes exist, which implies some persistent identity even if it's not a full profile.
What I'm inferring: - Games like this usually make the account optional at first (playable as a guest) but push sign-up for cross-device sync, clan membership, or reward claims. The sign-up may also be a gateway to marketing email. - The email account may be linkable to a platform account (Google Play Games, Apple Game Center, or a social login), which changes what data is shared.
What to verify: - Can the app be used without creating the account at all? Try declining or skipping the sign-up and see what's actually lost. - What exactly is requested at sign-up beyond email — birth date, name, phone number? A birth-date request matters: it determines whether the app applies any child-specific handling. - Is there an age gate, and does entering a child's age change the experience (chat disabled, ads adjusted) or do nothing? - Whether an account, once created, can be deleted from inside the app or only by emailing the developer — check the settings screen and the privacy policy for a deletion path. - Who the developer actually is (company name, country) in the store listing — this tells you whose terms and jurisdiction the account lives under.
B. DATA
Supported by what you pasted: - Email address is collected (the sign-up). - "Contains ads" plus frequent full-screen ads means ad networks are involved, and ad networks are themselves data recipients — the ads aren't just content, they're a data channel. - Clan chat with free-text means the app handles user-generated message content.
What I'm inferring: - Free-to-play match-3 games with ads typically collect: device identifiers, advertising ID, IP-derived location, gameplay/behavioral analytics, purchase history, and crash data — often shared with third-party ad and analytics SDKs. This is the norm for the genre, but I can't confirm it from your paste. - The E/PEGI 3 rating is a content rating (no violence, no mature themes). It says nothing about data collection, chat, or spending. Don't read it as a privacy or safety endorsement — that's the most common misreading of these labels. - 4.6 stars measures whether players enjoy the game, not whether it handles data well. Reviews rarely surface privacy issues.
What to verify: - The store listing's data-safety / privacy "nutrition label" section (Google Play "Data safety" or App Store "App Privacy"): what's listed as collected, what's shared with third parties, and whether anything is "linked to you." Note these labels are developer-self-reported. - The actual privacy policy: whether it addresses children's data at all, whether data is sold or shared for advertising, and what the retention/deletion terms are. - On the device: what permissions the app has actually been granted (contacts, location, microphone, photos). A match-3 game needs essentially none of these. - Whether the platform's ad-personalization / advertising-ID settings are limited for this device or the child's profile.
C. COMMUNICATION
Supported by what you pasted: - Yes — this is the clearest risk area in your material. "Clan feature with free-text chat" means unmoderated-or-unknown text messaging with people the player does not already know. "Friend codes" mean connections can be formed with anyone who shares a code — which includes strangers on forums, YouTube comments, or Discord, not just real-life friends. - "Compete with friends" in the listing confirms social features are core to the design.
What I'm inferring: - Clan chat in games at this rating tier is often filtered by keyword lists at best, and filters are routinely evaded. Clans typically accept open applications, so a child can end up in a group chat with adult strangers within minutes of joining. - Friend codes are frequently traded outside the app, which is a common vector for contact that parents never see. - There may also be player profiles, clan names/descriptions, or display names that are publicly visible — all user-generated content surfaces.
What to verify: - Whether chat can be disabled entirely, restricted to pre-set phrases, or restricted to approved friends — look in the app's own settings first. - Whether joining a clan is required for progression or rewards (if the game gates rewards behind clan membership, "just don't join one" won't hold up). - Whether there's a block/report function in chat and how visible it is. - Whether the display name defaults to the account name or email prefix — check what other players actually see. - On the platform side: whether the device's family/parental controls can restrict this app's social features, or whether the only lever is the app's internal settings. - Whether voice chat exists anywhere (your paste says text; confirm there isn't voice in clans or events).
D. MONEY
Supported by what you pasted: - In-app purchases are declared in the listing. - A premium currency ("Gem Vault") exists. Premium currencies deliberately obscure real cost — a $ price becomes gems, gems become items, and the exchange rate is hard to track, especially for a child. - A daily spinning-wheel reward is a randomized reward mechanic. At minimum it's a habit-forming daily-return hook; if the wheel (or anything similar in the game) can also be spun with purchased currency for randomized outcomes, that's functionally a loot-box-style mechanic. Your paste shows the free daily version; it doesn't show whether a paid version exists. - Frequent full-screen ads: expect the game to sell an ad-removal purchase, and expect "watch this ad for a reward" offers, which train the watch-ads habit.
What I'm inferring: - Games with this structure typically also run limited-time offers, "starter packs," and countdown-timer sales designed to create urgency — these are aimed squarely at impulse purchases. - There may be a subscription-style offer (a "gem pass" or "season pass" with auto-renewal). Not shown in your paste, but common enough to check for specifically. - Full-screen ads in E-rated games sometimes advertise other games with more mature content, and some ads have deceptive close buttons that lead to the store.
What to verify (through the platform's own settings, not the app): - Purchase authentication: require a password/biometric for every purchase, not every 15 minutes — the 15-minute window is how most surprise child purchases happen. - Whether the device is in a family group with "ask to buy"/purchase-approval turned on for the child's profile. - Any active subscriptions tied to this app in the platform's subscription manager, and their renewal dates and prices. - The actual price ladder of the in-app purchases in the store listing (they're listed as a range or itemized) — this tells you the ceiling; some games sell $99+ packs. - Whether purchased-currency spending on randomized outcomes exists anywhere in the game (paid wheel spins, paid chests). If so, treat it as gambling-adjacent when making the family decision. - Whether an ad-free purchase exists and what it does and doesn't remove (many remove interstitials but keep reward-video offers).
The shape of the decision
Pulling it together: the two things your paste most strongly establishes are open free-text chat with strangers (Section C) and a premium-currency spending system with a randomized-reward hook (Section D). Those are the two axes to settle as a family, and both have concrete verification steps above. The E/PEGI 3 rating and 4.6 stars don't speak to either one.
A reasonable sequence: check the store data-safety label and price list first (no device changes needed), then walk the app's own settings for chat controls, then lock down platform purchase controls regardless of what you decide — those settings protect you across every app, not just this one.
What we found
The four areas arrived as asked, each split into what's supported, what's inferred, and what to verify — and it read the age rating correctly as content-only. If its inferences are wrong in either direction, its own verification lists route you to the store label and the device settings.
Card 4: Judge the age and content fit
Use this when: The store has an age rating but you want to decide whether the app's real features fit the particular child using it.
I am sitting with the device and reviewing an app for a child in my family. I want help structuring my judgment, not outsourcing the decision. Before pasting anything here, I will remove the child's name, username, school, location, account information, and other identifying details. App name: [PASTE THE APP NAME HERE — remove personal details first] Current age or content rating shown in the store: [PASTE THE RATING HERE] Features or content I can verify: [PASTE WHAT YOU CAN ACTUALLY SEE OR CONFIRM HERE — remove personal details first] Relevant family considerations: [PASTE NON-IDENTIFYING CONSIDERATIONS HERE, SUCH AS "comfortable with multiplayer games but not open voice chat"] Help me evaluate fit across: - communication with other users, - public posting or profiles, - user-generated content, - advertising, - purchasing pressure, - disturbing or mature content, - competitive or social pressure, - privacy and location features. For each area, tell me: 1. What the evidence I supplied actually shows. 2. What the store rating may not capture about day-to-day use. 3. What I should inspect directly in the app or device settings. 4. What family judgment remains mine to make. Do not decide whether my child should use the app. Give me the questions and tradeoffs that make that decision better informed.
How the AI reads this prompt: The rating is treated as one input rather than the answer. The family-considerations field gives the AI a real decision context without requiring identifying information. The final instruction keeps the judgment with the person who actually knows the child.
What to do with the answer: Compare the AI's questions with what you can observe in the current app, store listing, and settings. The age rating and AI analysis cannot decide fit for your family.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
Thank you for structuring this so carefully — you've given me verifiable features rather than asking me to guess about an app I may not have reliable information on. Everything below is reasoned from the evidence you supplied, not from claimed knowledge of this specific app. Where I say "check X," that's because your direct observation will beat any store listing or any answer I could give.
One thing worth naming up front: the single clearest tension in your evidence is between your stated boundary ("no open text or voice chat with strangers") and the verified clan feature with free-text chat. That doesn't settle the decision — it just tells you which sections below deserve your closest attention.
1. Communication with other users
What your evidence shows. A clan feature with free-text chat means the app contains an open communication channel with strangers by default. Free-text (as opposed to preset phrases or emotes) means anything can be typed, and moderation quality — not the existence of chat — becomes the real variable.
What the rating may not capture. E / PEGI 3 rates content the publisher ships, not content other users type. Both rating systems explicitly disclaim user interactions — you'll often see "In-Game Purchases" or "Users Interact" as a small descriptor, or nothing at all. A game can carry PEGI 3 while its chat contains anything an adult stranger chooses to write. The rating on the box and the chat experience are essentially unrelated.
What to inspect directly. - Open the clan browser yourself and read a few public clan chats for five minutes. This is the fastest ground truth available. - Look for a chat settings page: can chat be disabled entirely, restricted to friends, or filtered? Is the filter on by default? - Check whether joining a clan is required for progression or rewards (if clan membership gates content, "just don't join one" is not a stable answer). - Look for a report/block flow — try it on a message and see how many taps it takes and whether it's child-usable. - Check whether private/direct messages exist separately from clan chat.
What remains your judgment. Whether a disable-able chat is acceptable, or whether the mere presence of an open channel — one settings toggle away — crosses your line. Also: whether your child, specifically, would leave a disabled setting disabled.
2. Public posting and profiles
What your evidence shows. Nothing directly — but clan features almost always imply usernames, clan names, and possibly profiles visible to strangers. Assume some public surface exists until you verify otherwise.
What the rating may not capture. Ratings say nothing about whether usernames are searchable, whether profiles show stats/status/last-online, or whether clan descriptions are free-text (another user-generated surface).
What to inspect directly. - Create the account yourself and see what the profile displays and to whom. - Check whether the username is chosen or assigned, and whether it can be changed (children often pick identifying names). - See if clan names and descriptions are free-text and browsable.
What remains your judgment. How much passive visibility you accept — a stranger seeing "Player_7734, online now, level 40" is different from chatting with them, but you may reasonably count it as part of the same exposure.
3. User-generated content
What your evidence shows. The UGC surfaces implied by your evidence are: chat messages, usernames, clan names/descriptions, and possibly avatars. No level-editor or content-creation feature is in evidence.
What the rating may not capture. Same gap as chat: UGC is rated by disclaimer, not by inspection. Offensive usernames and clan names are the most common leakage path in games at this rating.
What to inspect directly. Browse the clan list and leaderboards (if any) and note what names actually appear. That sample is your evidence.
What remains your judgment. Your tolerance for occasional exposure to a crude username versus sustained exposure to a chat stream — these are different doses of the same thing.
4. Advertising
What your evidence shows. Full-screen ads between levels means third-party ad content is interleaved with play. Two distinct issues: (a) ad content is served by networks and is not covered by the game's rating — ads for other games can include content well above E, and mis-targeted ads happen; (b) full-screen interstitials frequently use deceptive close buttons and fake "X" placements that teach accidental taps.
What the rating may not capture. Almost everything. The rating covers the game, not the ad inventory, which changes daily and varies by region and profile.
What to inspect directly. - Play through several levels yourself and watch what the ads actually are. - Check whether there are "rewarded ads" (watch-to-earn) — these convert ad-watching from interruption into something the child seeks out. - Check whether a one-time purchase removes ads, and whether device-level settings (e.g., restricting ad tracking / personalized ads) change what's served. - Note whether an ad has ever opened the store or a browser from a single tap.
What remains your judgment. Whether ad exposure at whatever volume and content you observe is acceptable, and whether paying to remove ads is a resolution you're comfortable with (it removes the ads, not the shop or the wheel).
5. Purchasing pressure
What your evidence shows. Two verified mechanics: a premium currency shop and a daily spinning-wheel reward. Premium currency is a known technique for obscuring real cost (you buy gems, then spend gems, and the dollar amount of any one purchase becomes hard to track — for adults too). A daily wheel is a variable-reward, streak-forming mechanic: its purpose is to make not opening the app feel like a loss.
What the rating may not capture. "In-app purchases" as a store label tells you they exist, not how aggressively they're surfaced — sale popups on launch, timers ("offer ends in 04:59"), currencies priced so you always have a remainder, or difficulty tuned so progress stalls without spending.
What to inspect directly. - Play far enough to see whether difficulty spikes correlate with shop prompts. - Count purchase prompts per session — popups on launch, after losses, after the wheel. - Verify device-level purchase controls: password/biometric required for every purchase (not the 15-minute grace window), or spending disabled entirely for this profile. - Check whether the spin wheel ever offers a paid "spin again."
What remains your judgment. Two separate calls: whether purchases are acceptable at all (device settings can hard-block them), and — harder — whether you're comfortable with the wanting the shop and wheel are engineered to produce, even when spending is blocked. Also whether a daily-streak mechanic fits your family's intended rhythm of play, since it pushes toward daily engagement by design.
6. Disturbing or mature content
What your evidence shows. Nothing in your evidence suggests mature shipped content, and a gem-matching game at E/PEGI 3 likely has none. The realistic vectors for mature content here are the ads (section 4) and the chat (section 1), not the game itself.
What the rating may not capture. The rating is probably accurate for shipped content — this is the one area where it's doing its job. Its blind spots are the two channels above.
What to inspect directly. Nothing beyond what sections 1 and 4 already cover.
What remains your judgment. Minimal residual here, assuming your ad and chat inspections come back consistent with the rating.
7. Competitive and social pressure
What your evidence shows. Clans imply team obligation: clan events, contribution expectations, and the possibility of being messaged (or removed) for not playing enough. The daily wheel adds a solo version of the same pressure. Combined, the design pushes toward obligated daily play rather than casual play.
What the rating may not capture. Ratings do not assess engagement design at all. A PEGI 3 game and a PEGI 18 game can use identical retention mechanics.
What to inspect directly. - Whether clan events have schedules and participation requirements. - Whether the wheel has a streak that resets if a day is missed. - Whether leaderboards rank players against strangers or clanmates.
What remains your judgment. Whether your child experiences this kind of structure as fun or as pressure — this is knowledge only you have, and it varies enormously between children of the same age. Also what your family's rule is when a game starts setting the schedule instead of the child.
8. Privacy and location features
What your evidence shows. Nothing direct — this is the biggest gap in the evidence you supplied, and worth closing before deciding.
What the rating may not capture. Ratings say nothing about data collection. The store's privacy label ("Data Used to Track You" / Google's Data Safety section) is self-reported by the developer — useful, not authoritative.
What to inspect directly. - The app's permission requests on install and first run: does a puzzle game ask for location, contacts, microphone, or photos? Any of those is a flag worth understanding before granting. - The store's data-safety/privacy section: what's collected, and whether it's linked to identity. - Whether the app runs without an account, or with a child-designated account (which changes the developer's legal obligations in many jurisdictions). - After a few sessions: the device's permission dashboard, to see what the app actually accessed.
What remains your judgment. Your family's threshold for data collection in exchange for a free game — "free" here is financed by the ads, the shop, and plausibly the data, and you get to decide which of those currencies you're willing to pay in.
Pulling it together — the questions that decide it
You asked for the tradeoffs, not the verdict, so here is where your evidence leaves the decision:
-
The chat conflict is the threshold question. Your stated boundary excludes open text chat with strangers; the app verifiably contains it. The decision likely turns on what you find when you inspect: Can chat be fully disabled, does it stay disabled, and is clan membership avoidable without gutting the game? If yes to all three, this becomes a supervision question. If no to any, the app as designed conflicts with a boundary you've already set — and only you decide whether that boundary flexes for this app or this child.
-
Blocking purchases is solvable; the wanting is not. Device controls can make spending impossible. They cannot make the shop, the timers, and the wheel stop asking. Your call is whether you're okay with your child playing inside a machine built to create purchase desire, with the purchases themselves fenced off.
-
Decide what "playing this game" means before it decides for you. The wheel and clan structure reward daily, obligated play. If your family's intent is occasional casual play, you'd be swimming against the design — possible, but worth deciding explicitly and revisiting after a couple of weeks of actual use.
-
Your best evidence is 30 minutes of your own play. Everything above sharpens what to look for, but the store page, the rating, and this analysis are all secondhand. You sitting with the device — reading a clan chat, watching three ads, spinning the wheel, trying to disable chat — is the only first-hand evidence in the whole process, and it's the evidence your decision should rest on.
If you'd like, once you've done that inspection, come back with what you observed (again with identifying details removed) and I can help you weigh the specific findings against the boundaries you've described.
What we found
All eight areas, and the decision left with the family. Its best move: it surfaced the collision between the stated family boundary (no open chat with strangers) and the verified clan chat, and named it the threshold question. It runs long, and it closes by inviting a follow-up session — take or leave that.
Card 5: Check for a knockoff or copycat
Use this when: The app looks familiar or polished, but you are not sure whether it is the official product, a clone, or simply something using a similar name.
I am reviewing an installed app with the device in front of me. Help me assess whether I have enough evidence that this is the app I think it is. Before pasting anything here, I will remove personal details, account information, passwords, one-time codes, payment details, and identifying information about a child. App name: [PASTE THE APP NAME HERE] Developer or publisher: [PASTE THE DEVELOPER NAME HERE] Store description: [PASTE RELEVANT STORE TEXT HERE — remove personal details first] Other visible details such as icon wording, website name shown in the listing, permissions, purchase model, or update information: [PASTE THE DETAILS HERE — remove personal details first] Do not judge legitimacy from the icon, screenshots, star rating, or polished wording alone. Instead, help me compare: - exact app name, - developer or publisher identity, - whether the developer identity is consistent with the product I expected, - permissions versus stated function, - account requirements, - purchase model, - official website or publisher information shown in the store, - anything else that deserves direct verification. Separate: 1. MATCHES I CAN VERIFY 2. MISMATCHES OR ODDITIES 3. DETAILS THAT ARE INCONCLUSIVE 4. CHECKS I SHOULD MAKE OUTSIDE THIS CHAT Do not instruct me to open unfamiliar links, install another app, or interact with suspicious content to test it.
How the AI reads this prompt: The prompt deliberately downgrades visual polish and focuses on harder-to-fake relationships such as publisher identity, requested access, and product consistency. It also gives the AI an "inconclusive" category instead of forcing every clue into good or bad. The final section routes verification back outside the chat.
What to do with the answer: Verify the publisher and current listing through the platform and, where appropriate, the product maker's independently located official information. A resemblance or mismatch can justify more checking, but it does not settle identity by itself.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
This is a well-structured request, and the details you've provided are enough to do a meaningful assessment. Working only from what you've pasted, here is how the evidence sorts out.
1. MATCHES I CAN VERIFY
Honestly, very little rises to the level of "verified match" — and that's an important finding in itself.
- Name and genre are internally consistent. The name "Gem Stackers Blast," the stacked-gems icon, and the match-3 description all agree with each other. That tells you the listing is coherent, not that it's legitimate.
- The purchase model is typical for the genre. Free with ads and in-app purchases is the standard match-3 monetization model. Nothing anomalous there on its face.
- The age rating (E / PEGI 3) is consistent with the described content. Though note a rating describes content, not safety or data practices.
Nothing here connects the app to an identity you can check independently. Consistency within a listing is cheap to fake; every field you've quoted was written by the same party.
2. MISMATCHES OR ODDITIES
- Permissions versus stated function — this is the standout problem. A match-3 puzzle game has no functional need for camera, microphone, location, or contacts. Ads and "compete with friends" can be implemented without any of these (friend features in legitimate games typically use platform game services or friend codes, not your contacts list). Four sensitive permissions on a game whose core loop is swapping gems is a serious mismatch. This single item outweighs everything in section 1.
- No developer website link. Legitimate studios almost always list a website and a privacy policy link. Its absence removes your main path to verifying that "Luminary Pixel Works Ltd." exists outside this store listing. A developer with a "Ltd." company name but no web presence shown is odd.
- Generic, compound name pattern. "Gem Stackers Blast" fits a common pattern among clone/copycat apps: recombined keywords from popular titles ("Gems," "Blast," "Stack"). Not proof of anything, but it's the naming style copycats use to surface in searches for better-known games.
3. DETAILS THAT ARE INCONCLUSIVE
- Developer identity. "Luminary Pixel Works Ltd." is neither confirmed nor disproven by anything in the listing. You told me you're assessing "whether this is the app I think it is" — note that you haven't named what you expected it to be. If you expected a specific game (say, one a friend recommended or one your child asked about), the key inconclusive question is whether this developer is the developer of that game. If you can't state who you expected the publisher to be, that gap itself is worth resolving before trusting the app.
- 4.6 stars and "frequent ads" review mentions. Ratings can be inflated, and ad complaints are common in both legitimate and illegitimate free games. Neither direction is decidable from here.
- Account requirements. You didn't list any, and the listing text ("join a clan") hints at an account or social layer. Unknown until you check what the app demands at first launch.
- Update information. Not provided. Recency and cadence of updates would be mildly informative but you'd need to read it off the listing.
4. CHECKS I SHOULD MAKE OUTSIDE THIS CHAT
All of these use sources you already trust or the device itself — no unfamiliar links needed:
- Look up the developer's full catalog inside the store. Tap the developer name in the listing. A legitimate studio usually shows a coherent portfolio; a copycat often shows a grab-bag of keyword-named apps published recently.
- Search the developer name in a search engine you already use. Does "Luminary Pixel Works Ltd." have any presence — a website, a company registration, press mentions? A "Ltd." should be findable in a public company register (e.g., Companies House if UK). Absence everywhere is a strong signal.
- Compare against the app you expected. If this was recommended to you by name, go back to the source of the recommendation and confirm the exact name and developer. Copycats rely on near-miss names.
- Check the privacy policy / data-safety section in the store listing itself. Both major stores require a data-safety or privacy declaration. See whether it admits to collecting contacts/location and where the privacy policy is hosted.
- Check what permissions are actually granted on the device now (Settings → Apps → this app → Permissions, or Settings → Privacy on iOS). If it's already installed and has been granted camera/mic/location/contacts, revoke them — a match-3 game will run fine without all four.
- Check install count and review dates in the listing. A high star rating on a small or very recent review base, or bursts of same-day reviews, points toward manipulation.
- Sort reviews by most recent and most critical, not the default view. Complaints about unexpected charges, permission prompts, or the app impersonating another game tend to live there.
Bottom line
Based only on what's visible: the listing is internally consistent but externally unanchored — there is currently no evidence tying this app to a verifiable developer, and the permission set is significantly out of proportion to a puzzle game. As it stands, you do not have enough evidence that this is the app you think it is. The two checks that will move this fastest are the developer's external footprint (check #2) and the developer's app catalog (check #1). If those come back empty or incoherent, treat the permission mismatch as disqualifying: don't grant the sensitive permissions, and consider uninstalling — especially given the E/PEGI 3 rating means children are the intended audience for an app requesting contacts and location.
What we found
It sorted the evidence into the four bins and weighted what the card teaches — publisher identity and permissions over polish — landing on the honest verdict: not enough evidence that this is the app you think it is. Neither a clearance nor a conviction; the in-store checks are where truth lands.
Talk & keep · the conversation and the habit
Card 6: Make the conversation easier
Use this when: You have learned enough about the app to talk with your kid and want curiosity to come before accusation or confiscation.
We are sitting together with the device here, and I want help having a calm conversation about an app that was installed. Before pasting anything here, we will remove names, usernames, school information, locations, account details, passwords, one-time codes, and other identifying information. What we know about the app so far: [PASTE A SHORT, NON-IDENTIFYING SUMMARY HERE] What I still want to understand: [PASTE THE OPEN QUESTIONS HERE] Help us create a short conversation guide that: 1. Starts with curiosity: what the app is for, how it was found, and what makes it interesting. 2. Lets the child explain what they actually do in the app before assumptions are made. 3. Raises the specific questions we still have about communication, permissions, spending, privacy, or content. 4. Separates facts we can check together from family rules that require judgment. 5. Ends with one or two concrete things we can inspect together on the device. Use neutral language. Do not shame, scare, interrogate, or assume wrongdoing. Do not write a speech for an absent parent or child. This is a first-hand conversation with the people involved and the device present.
How the AI reads this prompt: The AI is asked to organize a conversation, not pronounce guilt or innocence. The sequence gives the child room to explain the app before the adult moves into specific concerns. The final device check keeps the conversation connected to evidence the family can inspect together.
What to do with the answer: Use the guide as a starting structure and change the wording to sound like your family. The AI cannot know the child's intent or your family dynamics; the conversation itself supplies that context.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
This is a great way to approach it — sitting down together with the device beats any lecture. Here's a short guide you can follow at your own pace. Treat it as a menu, not a script: skip anything that's already been covered naturally.
Conversation Guide: Talking About the New Game Together
Part 1 — Start with their world (5 minutes, no device needed yet)
Open with genuine interest. Good starters:
- "Show me what this game is — what do you actually do in it?"
- "What's the best part? What made you want to try it?"
- "How did the friend code thing work? That's kind of a cool system — who sent it to you?"
- "Is your class into it? Are people in a clan together?"
Tip: Let them be the expert here. Kids often light up when they get to teach. If they say "it's just a puzzle game," ask them to show you a level — that naturally leads into Part 2.
Part 2 — Let them show you (device out, child driving)
Hand them the wheel: "Walk me through a normal session. What do you tap first?"
Things to just observe without commenting yet: - Do they open the clan chat? Who's in it? - Do they spin the daily reward wheel? What does it give? - How often do ads appear, and what are the ads for? - Do they ever get prompted to buy the premium currency?
Save your reactions. The goal of this part is an accurate picture, not a verdict.
Part 3 — Ask your open questions (curious tone, not quiz tone)
About the clan chat: - "Who can message you in here — just people you know, or anyone in the clan?" - "Has anyone you don't know ever chatted with you? What did they say?" - "Is there a way to see the chat settings together?"
About spending: - "Have you ever been tempted to buy the gems/coins? What do they get you?" - "Do you know what happens if you tap 'buy' — does it ask for a password, or just go through?"
About permissions: - "The app asked for camera and location — do you know what it uses those for? Does anything in the game seem to need them?"
(Honest answer you can share: many free games request camera access for AR features or profile photos, and location for regional ads and matchmaking. Often the game works fine with both denied. You'll verify this together in Part 5.)
Part 4 — Sort into two piles, out loud
Make this distinction explicit — it lowers defensiveness a lot:
Facts we can check together (no opinions needed): - Whether clan chat can be restricted, muted, or set to friends-only (in the game's settings) - Whether purchases can require approval (this is a device setting, not a game setting) - What permissions the app actually has, and whether the game still works without them - What the game's own parental or privacy settings offer
Family judgment calls (worth deciding together, and they get a voice): - Whether open clan chat is okay, or friends-only - Whether ad-heavy free games are worth the trade-off - What the rule is for spending — never, ask-first, or an allowance amount - When and how long the game gets played
Frame it as: "Some of this is just looking stuff up. Some of it is us deciding what our family's rules are — and I want your take on those."
Part 5 — End with one or two concrete inspections
Pick one or two, not all — you can do the rest another day:
- Chat settings: Open the game's settings together and look for chat/social options — friends-only mode, mute, block, report. If there's no way to limit it, that's a real finding worth discussing.
- Purchase approval: Set up "Ask to Buy" (Apple Family Sharing) or "Purchase approvals" (Google Family Link), or at minimum require a password/biometric for every purchase in the app store settings. Do it with them watching so it's transparent, not sneaky.
- Permissions test: Go to the device's app permissions, turn off camera and location for the game, then open it and play a round. If nothing breaks, leave them off. If something breaks, you'll see exactly what needed it and can decide if it's worth it.
Closing line ideas
- "Thanks for showing me — I get why it's fun."
- "If anyone in the chat ever says something weird or asks you for anything, you can tell me and you won't be in trouble for it. That's a promise."
That last one matters most: the goal of the whole conversation is that the next conversation happens voluntarily.
One caution for you as the adult: if you spot something concerning during Part 2 (a stranger's messages, a purchase you didn't know about), resist reacting in the moment. Note it, finish the conversation calmly, and address it separately — otherwise the lesson they learn is "showing my parent my screen gets me in trouble."
Good luck — the fact that you're doing this side-by-side and starting with curiosity means it will almost certainly go well.
What we found
The five-part guide arrived in order — curiosity first, the kid as the expert, the open questions, facts versus family rules, and joint device checks to close — in neutral language, with nothing written for anyone who isn't in the room. Its best line is advice the card didn't ask for: don't react mid-demonstration, or the lesson becomes "showing my parent my screen gets me in trouble."
Card 7: Turn the review into a family habit
Use this when: You are finished with this app review and want a repeatable rule for future installs without recreating the entire process each time.
We just reviewed an app together while the device was present. Help us turn what worked into a simple family habit for future app installs. Before pasting anything here, we will remove names, usernames, account details, addresses, passwords, one-time codes, payment information, and other identifying details. What we checked this time: [PASTE THE CHECKS THAT WERE USEFUL HERE — remove personal details first] What caused disagreement or confusion: [PASTE A SHORT, NON-IDENTIFYING SUMMARY HERE] What we want the family rule to accomplish: [PASTE THE GOAL HERE] Draft a short family app-review checklist that can be completed with the device present. It should cover only the checks that are useful before or shortly after installation, such as: - app and developer identity, - permissions in context, - account and data questions, - communication features, - purchases or subscriptions, - age and content fit, - anything that needs direct verification in the store listing or device settings. Keep the checklist short enough to use again. For every item, distinguish between: - something the family can inspect directly, - something an AI can help reason about, - something that must be decided as a family rule. Do not claim that completing the checklist removes risk. The goal is a repeatable review process and better questions.
How the AI reads this prompt: This card converts one investigation into a reusable routine while keeping direct observation, AI-assisted reasoning, and family judgment separate. The disagreement field helps the checklist reflect what actually caused friction instead of becoming a generic policy. The length constraint makes the result more likely to be used next time.
What to do with the answer: Edit the checklist until it matches the household and the devices actually in use, then set any chosen controls through the platform's own settings. Revisit the checklist when apps or family expectations change.
Actual execution example — what came back when we ran this prompt
Run: Claude (Fable 5) · fresh session · no web access · as of 2026-08-19 · one run per prompt · test data all synthetic — a fictional app (“Gem Stackers Blast”) and fictional developer; no real company or child appears.
One run, one sample — your answer will differ. A first opinion, never a clearance: verify outside the chat (how to read these examples: see the first card).
The response, as received — unedited
Great foundation — you've already done the hardest part, which is doing the review together once. Here's a checklist built from what worked, short enough to reuse.
Family App-Review Checklist
Use with the device present, before first play (or as soon after install as possible).
For each item: [Inspect] = the family checks directly · [AI] = an AI can help you reason about it · [Rule] = decided as a family rule
1. Who made this?
- [Inspect] In the store listing: developer name, other apps by them, when it was last updated.
- [AI] Ask: "Is this developer the official maker of [game/brand], or a lookalike?" Describe what you see; don't paste account details.
- [Rule] Decide: do we install lookalikes at all, or only apps from developers we can identify?
2. Do the permissions match the job?
- [Inspect] Device settings after install: what did it actually request? (Location, contacts, microphone, camera, photos.)
- [AI] Ask: "Why would a drawing app need my contacts?" — good for surfacing mismatches you might rationalize away.
- [Rule] Default: deny anything the app doesn't clearly need to function. Revisit only if a feature breaks.
3. What account does it want, and what does it learn?
- [Inspect] Does it require sign-up? Can you use it without one? What does the privacy label / data-safety section say it collects?
- [AI] Help translating the data-safety section into plain language, and flagging what "data linked to you" means in practice.
- [Rule] Decide: which sign-in method (if any) kids may use, and whether real names or birthdates ever go into game accounts.
4. Can strangers reach my kid here?
- [Inspect] In-app settings: chat, voice, friend requests, user-generated content. Find the actual toggles.
- [AI] Ask: "What communication features does this type of game usually have, and where are they typically hidden?"
- [Rule] Your stated default is a good one: chat and social features start OFF, and turning them on is a joint decision, not a solo one.
5. How does it ask for money?
- [Inspect] Store listing: in-app purchases listed? Device settings: purchase approval / ask-to-buy enabled? In-app: is there a store, a battle pass, a subscription?
- [AI] Help identifying pressure mechanics — timers, streaks, "limited" offers, currency that obscures real cost.
- [Rule] Default: purchases require a parent's approval every time. No stored payment method reachable from the child's profile.
6. Reward mechanics — the one you disagreed about
This deserves its own line, because your disagreement is actually the useful part. - [Inspect] Does the app use daily rewards, streaks, spinning wheels, loot boxes, or randomized prizes? Watch one cycle together. - [AI] Ask: "What's the difference between a daily login bonus and a gambling-like mechanic?" An AI can lay out the distinctions people draw (randomness, paid entry, escalating stakes, loss framing) — but it can't settle where your family's line is. - [Rule] This is genuinely a family-rule question, not a factual one. A workable compromise: mechanics that reward showing up are tolerated; mechanics that combine randomness + real money are not — and anything in the gray zone triggers a conversation, not an automatic yes or no.
7. Is it right for this kid, right now?
- [Inspect] Age rating and the reasons given for it (not just the number). A few recent reviews mentioning kids.
- [AI] Help interpreting what a rating descriptor like "interactive elements" or "mild fantasy violence" typically means.
- [Rule] Only the family can decide fit — ratings are a floor, not a verdict.
8. The exit question
- [Inspect] Before closing: do we know how to delete the account and the app if we change our minds?
- [Rule] Decide a re-check trigger: a major app update, a new social feature, or the child asking to turn something on reopens the checklist.
Making it a habit
- Keep it to ~10 minutes. If the review is longer than the first play session, it won't survive.
- The kid drives. Have them navigate the store listing and settings while you ask the questions. The goal is that they eventually ask these questions unprompted.
- Disagreement is a feature. Item 6 proved that — the conversation about why the wheel felt off is worth more than any single toggle.
- Log the decision, not the debate. One line somewhere shared: app name, date, what defaulted off, what would trigger a re-check.
One honest caveat, since you asked for it: completing this checklist doesn't make an app safe. Apps change after review, settings reset after updates, and no checklist catches everything. What it does is give your family a repeatable way to look before playing, and better questions each time — which is the accomplishment worth keeping.
What we found
The checklist keeps the three-way split on every item — inspect directly, reason with the AI, decide as a family — and treats the family's recorded disagreement about the reward wheel as the most useful item rather than smoothing it over. It closes by refusing the claim this site also refuses: completing a checklist doesn't make an app safe.
Before you paste anything
Remove or replace personal details before putting app information into any AI chat. That includes real names, the child's identity, usernames, email addresses, home or school information, account numbers, payment details, passwords, one-time codes, and government ID numbers; when a detail is necessary for context, substitute a generic description instead.
When AI is the wrong tool
Skip the AI conversation when something already requires direct action. If money has already been charged unexpectedly, use the card issuer's and app store's official dispute or refund process; if credentials were entered somewhere questionable, go directly to the affected account through its official app or site and follow its recovery steps. If the app shows threatening contact, sexual solicitation, coercion, or suspicious contact with a minor, preserve the relevant evidence without engaging the sender, use the platform's reporting tools, and contact law enforcement or another appropriate authority when warranted. If the device appears to be malfunctioning or an account is actively being taken over, address that problem first and return to analysis later.
Where this leaves you
You still have a judgment to make, but now you have a repeatable way to separate what you observed, what the AI inferred, and what needs verification elsewhere. The real payoff is being better prepared to ask the next question while the device and the people involved are still in the room.
Questions you might still have
The answers below are ours — the site’s, not the AI’s. They describe the runs published above, as of 2026-08-19.
Your answer will differ — differ how?
We don't know yet in any measured way: we ran each prompt once, and one run is one sample. What we can say is where difference comes from — the product you use, its tier and settings (web access especially), and what you paste. The prompt's structure — the way it makes the AI mark its guesses as guesses and end with a list of things for you to check — is the part built to survive those differences. When our re-runs accumulate real data on how much answers move, we'll publish it.
Every example answer sounds sure of itself — how would I know if mine is wrong?
From inside the chat, you can't — that's the honest answer, and it's why every card routes you to the store listing and the device's own settings. A wrong answer usually shows itself as a claim those checks don't confirm. When the chat and the store page disagree, the store page is the evidence.
Card 5's example said "consider uninstalling," while other cards calmly review the same app. Which is the verdict?
Neither — the cards ask different questions of the same evidence, and the review cards assume an app you're still considering while the knockoff check asks whether to consider it at all. A workable order: first look, then the knockoff check — and if that one comes back the way our example did, stop there; the remaining cards are for apps that pass it.
"Verify through a channel you already trust" — your own examples say listings, labels, ratings and reviews can all be faked. So which channel?
No single one — the method is convergence. Each signal can be faked; faking all of them coherently is much harder. The developer's catalog, their footprint outside the store, the install base, and what the device's own settings show after install point the same way for a real product and scatter for a fake. Your device's settings are the one channel nobody else writes: they show what is actually granted, right now.
The AI admits it can't look anything up and my own play is the real evidence. What am I getting that a printed checklist wouldn't give me?
For the repeat case — honestly — the checklist is the product, and card 7 exists to make you one. The session earns its place on the first pass: it organizes what you observed, tells you what you didn't paste, and adapts to the app in front of you. A printed list can't ask what your kid said the app does. After the routine exists, you'll use the AI less for this. That's the intended direction.
Every card warns that what I paste "can shape its answer." Could a slick store description talk the AI into going easy on the app?
It can pull in that direction — marketing copy is written to persuade, and the AI reads it as content. Two habits blunt it: paste the listing as a claim, not a fact ("the listing says X"), and ask the AI to separate what the evidence shows from what the listing asserts — which is exactly what card 1's prompt does. Then weigh the checks over the chat, as every card already tells you to.
Built the way every post here is built: we brief, a platform writes, we run the prompts and publish what came back — including where it fell short. We never edit a prompt.
Site footer — appears once on every page (approved H024)
charades.net
About this content
Everything in this section is produced by AI. The prompts you see are the direct, unedited output of ChatGPT, Gemini, and Claude — and they may be incorrect. Any part of this site may be incorrect. We are not a security company and we do not have a legal team; nothing here is legal or professional security advice.
What we offer is exactly this: the results of asking the leading consumer AI tools how to use prompts that answer the question “How do I talk to A.I. about cybersecurity?” — plus our best effort to fact-check and review this content using current AI tools. Nothing more.
No prompt can make you or your business safe; our goal is to help you start better conversations with AI about becoming safer.
Details of how these posts were validated: How we check these posts.