Skip navigation menu
Hero background image
REAL PARENTS. REAL SOLUTIONS.

Protecting Kids Online

Our mission is to protect children and defend parental rights by equipping families and citizens with the tools to keep kids safe online. We oppose government surveillance disguised as child safety legislation and build an informed, independent coalition that changes policy and culture.

Explaining Social Media Bans

Every few months, a new bill arrives promising to keep kids off social media until they're old enough to handle it. Different sponsor, different state, different age cutoff: Florida's HB 3, Mississippi's HB 1126, Utah's Social Media Regulation Act, Texas's HB 18. Read past the press release, and they all build the same thing.

At the core of every one of these bills is the same five-part structure: an identity gate, a categorical restriction by age, an ongoing monitoring system, a data carve-out for the vendors who run it, and a definition of "social media platform" broad enough to cover almost anything with a comment section. The names change, but the architecture does not.

The identity gate

Before any of these bills can restrict who holds an account, they first have to establish how old every user is. That requirement takes different forms (government ID upload, biometric age estimation, a parent's notarized consent), but the function is identical. You cannot enforce an age-based rule without first collecting the age of every user, not just the ones the rule targets.

Some versions frame this as "age verification." Others frame it as "age assurance" or a "commercially reasonable" standard. The softer language doesn't change what gets built. A platform that can't prove it knows a user's age carries the liability, so the identity infrastructure gets built for the adult population too, as the only way to sort out who's exempt.

The categorical restriction.

Once the gate exists, the bill uses it. No accounts under 14. Parental consent required at 15 and 16. A hard cutoff at 18 absent a parent's sign-off. This is the part that gets quoted in the press release, and it's the part that's easiest to support; nobody wants an eleven-year-old alone in an algorithmic feed at midnight.

But the restriction only exists downstream of the gate. Support the age cutoff, and you've already accepted the identity infrastructure required to enforce it against everyone, adult users included.

The monitoring problem.

This is where these bills go further than most people realize. Beyond the one-time gate, the compliance architecture requires ongoing verification: session-level age re-checks, parental dashboards showing a minor's activity and contacts, algorithmic curfews that cut access at set hours, and consent records that have to be maintained and produced on demand.

A system built to track when a minor logs on, who they talk to, and what hours they're active is a surveillance mechanism regardless of the intention behind it. None of these bills specify how long that activity data is retained, who else can request it, or what happens to a minor's account and connection history once they age into adulthood and the monitoring is supposed to stop.

The vendor exemption.

Every one of these bills contains data minimization language: no selling verification data, limited retention, encryption requirements. Read the next clause and the protections apply only to the platform itself, not to the third-party age verification vendor the bill explicitly permits the platform to hire. The company actually holding the ID scan or the biometric estimate operates under its own privacy policy, not the bill's. Several versions say nothing about how long a vendor can retain a rejected verification attempt, or whether that data can be resold, aggregated, or repurposed for something other than age assurance.

The elastic definition.

"Social media platform" gets defined broadly enough in most of these bills to sweep in far more than the Instagram-and-TikTok target the sponsor described at the press conference. A platform is often defined by the presence of user-generated content and an algorithmic feed, which catches discussion forums, multiplayer games with chat, and even some educational platforms alongside the apps the bill is nominally aimed at. News and sports sites get a carve-out; almost nothing else does.

That breadth isn't incidental. A narrow definition would require narrow infrastructure. A broad one requires the same identity and monitoring architecture to be built for every interactive platform a minor might touch.

What real protection would look like.

A bill built to keep kids safer on social media would target the specific design choices driving harm: autoplay, infinite scroll, engagement-optimized notifications, algorithmic amplification of self-harm content without requiring an identity and behavioral-tracking system for every user, adult and minor, to get there. It would hold a platform accountable when a specific feature caused documented harm to a specific child. It would not require a permanent age-verified account architecture on every user as the price of restricting the ten million who are minors.

None of the bills built on this template do that. They deliver the identity infrastructure first and the child-safety outcome as a byproduct, if at all.

What parents can do today.

You don't need this architecture to limit your child's social media use right now. Device-level screen time controls, app-level parental supervision tools, and a running conversation about what your child sees online are available today, with no new data collection on your family required. An engaged parent, not a government age-verification mandate, is still the most effective safeguard that exists. No compliance template, federal or state, replaces that.