Naven Open Naven
Safety & compliance

Ten things, checked before a message sends.

Exactly what Naven screens for, exactly what it deliberately leaves alone, how age bands work, and what is stored. Written so a school, a library, or a parent can assess it against their own internet safety policy without reading any code.

Last updated 23 August 2026
Screening
Every message, before it sends
Age bands
Under 13 · Teen · Adult
Under-13 messaging
Strictest screening from the first message
Member directory
None — nobody is browsable

Naven is a social platform for messaging, voice and video calling, and communities, used by adults, teenagers and children. Every message is checked before it is delivered, against a policy of exactly ten categories:

Spam and scams · malware and malicious links · harassment and bullying · hate speech · credible threats of violence · sexual exploitation or abuse · illegal transactions · doxxing and privacy violations · encouraging self-harm · graphic violence.

Display names are screened too, and to a stricter standard than messages. A name is shown beside everything an account ever sends, to people who never chose to hear from it — including on a lock screen. So a name may not carry a slur, pose as Naven staff, or be a link or a phone number. Naven screens a name when it is saved and again every time it renders one, so a name that fails reaches nobody.

Self-harm is the one category Naven does not block. Somebody telling a friend they are struggling is doing the right thing, and a product that deletes that message teaches them not to say it again. Naven delivers it, and offers a helpline alongside it. What is refused is content encouraging or instructing somebody else to hurt themselves, which is a different act entirely.

Two more things are screened for every member: slurs, and strong language. A message containing either does not send, and the person who wrote it is told which rule it met rather than being left to guess. Naven ran without an obscenity filter for a period and has reinstated one; this page is updated whenever that changes, because a safety claim that no longer matches the code is worse than no claim at all.

What is still not screened matters as much as what is. Naven does not screen insults, disagreements, dark humour, or someone saying they are struggling. "You are being an idiot" and "I hate this" are things people say to each other, and an app that reads a private message and refuses to deliver an argument is not protecting anyone. Naven does not claim alignment with the Children's Internet Protection Act.

1 Pre-send screening Always on

Every message is checked against the ten categories before it is delivered — not reported afterwards. The check runs in three independent layers, so protection never depends on one provider being available.

  1. Deterministic pattern screening

    Runs on every message. No network call, no third-party quota, and it cannot be skipped or switched off by anyone. Covers child sexual abuse material, self-harm encouragement, credible threats, sexual content, hate speech and slurs, drug sales, and known grooming phrasing. Text is normalised first, so spacing, punctuation and leetspeak do not evade it.

  2. Classifier screening

    A hosted moderation model reviews anything the first layer allows through.

  3. Fallback classifier

    A second, independent provider takes over whenever the first is unavailable or out of quota.

How the layers combine

Layers two and three can only add blocks, never remove them. If both are unreachable, the verdict falls back to layer one rather than allowing unscreened content through — the system fails closed, not open. Naven AI is screened on both sides: the question before it reaches a model, and the answer before it reaches the member.

2 Age bands and protection levels

Every account is asked for a birth year once at sign-up. Naven derives a coarse band from it and stores only the band — the birth year itself is never written to the database.

BandAgeProtection applied
Under 130–12 Strictest filtering, plus blocking of addresses, phone numbers and ID numbers written in messages. May message under the strictest screening; suspended pending guardian approval once that screen is repeatedly tripped. See section 3.
Teen13–17 Sexual content, drug-sale and grooming filters applied in addition to the universal categories.
Adult18+ Universal categories only: CSAM, credible threats, hate speech, harassment and self-harm encouragement.

A member can correct their band, but can never move themselves into a less protected one. That restriction lives in the database security rules, not in the browser, so it holds even against a modified client.

3 Guardian consent for under-13 accounts On conduct

An under-13 account can message. Naven used to block every one of them on sight, before the child had done anything at all, and the honest result was not a parent being asked for consent — it was the child closing the tab. Consent-before-first-message is the strictest possible reading of the rule and it protected nobody, because nobody stayed.

The gate fires on conduct instead. A young account that repeatedly trips the safety screen — including for swearing, which counts for a minor and not for an adult — has messaging suspended until a guardian confirms it, and a guardian is the only way an under-13 account can clear it: the code-to-your-own-inbox route adults get is not offered. That verification record can only be written by Naven's server, and the security rules reject any attempt to write it from a browser, so a child cannot grant themselves consent by editing anything on their own device.

4 Monitoring of minors' activity

Where an institution has its own obligation to monitor minors' activity, Naven supports it by screening every message at the point of sending and recording safety events on the server, under records the member can neither read nor clear. Naven does not read private conversations for any purpose other than this screening, and does not sell or share message content.

5 No public directory, no stranger discovery

Naven publishes no browsable member directory and has no algorithmic feed that surfaces strangers. A conversation can only begin when someone already knows the other person's email address, and that address is looked up as a one-way hash, so no list of members can be enumerated from it. Email addresses are never shown to other members, and being named in response to such a lookup is opt-in.

6 What Naven stores

Stored

  • Display name and optional profile photo
  • Age band (not the birth year)
  • Theme preference
  • Messages and their delivery state
  • Conversation membership

Not stored

  • Birth year
  • Precise location
  • Contact lists
  • Browsing history
  • Advertising identifiers

Not done at all

  • No advertising
  • No sale of personal information
  • No profiling of minors
  • No engagement ranking

7 Reporting and enforcement

Blocked messages are refused at the point of sending, with an explanation to the sender. Members can mute a conversation, and messages can be unsent by their author within two minutes.

To report content or an account, or to ask a question about this policy:

8 Known limits Read this

Naven states these plainly rather than implying more coverage than exists. An institution assessing Naven should assume exactly this much and no more.

This page describes the measures Naven operates. It is not legal advice, and no software product makes an institution compliant with anything by itself — a school or library's own obligations attach to the institution, and Naven is one input to a policy you write, not a substitute for writing one.