Safeguarding and Online Safety

AgentChamp - Safeguarding and Online Safety

Effective 25 August 2026


For designated safeguarding leads

This is the answer to "what are the safeguarding risks of putting this in front of our children?", written for the person who has to sign it off under *Keeping Children Safe in Education*.

The short version: AgentChamp has no contact risk and no content-upload risk, because the features that create them do not exist. The detail is below so you can verify rather than take that on trust.


The four Cs

*KCSIE* frames online risk as content, contact, conduct and commerce. Taking them in turn.

Contact - can a child be reached by anyone?

No.

  • No chat, no messaging, no comments, no forums, no direct messages. None of it exists anywhere in AgentChamp
  • No child can see another child's data - not their name, not their reading, not their progress. There is no route to it
  • No public leaderboards of real names. Where a child appears on a shared surface, such as a reading challenge, it is under their agent name - chosen from a curated pool of literary names, never free text, never their real name
  • No user profiles to browse, no friend lists, no follows
  • No email address. A child's account carries an internal identifier that is not a real mailbox and cannot receive mail. There is no path by which a message reaches a child
  • No external links. Children cannot navigate out of AgentChamp to a third-party site from within the reading experience

An adult with a school-issued link code can connect to a specific named child - that is the parent-visibility feature. Codes are issued only by the school, are single-use, expire, are rate-limited against guessing, and reveal only the child's first name and school before linking. The school sees every linked adult and can sever any link at any time.

Content - what can a child see?
  • The library is curated. Every story is written for a UK primary audience and validated for reading level and content appropriateness before publication
  • AI-generated stories are validated before any child can open them, and any story can be withdrawn immediately
  • No adverts. None, anywhere, ever
  • No third-party content is embedded in any page a child can reach - no videos, no widgets, no external images
  • Reading-level placement means a child is offered books suited to them, and a teacher can pin, raise or lower that at any time

If you find a story you think is unsuitable, report it and we will pull it. We would rather over-remove than argue.

Conduct - what can a child do?

Almost nothing that could harm anyone, by design.

  • There is nowhere in AgentChamp for a child to type free text. No chat, no comments, no story creation, no custom avatar names, no feedback box. Quizzes are answered by choosing an option. This is enforced by an automated test, so it stays true as the product grows
  • This means a child cannot bully another child, cannot share personal information, and cannot inadvertently disclose something into a box nobody is watching
  • It also means AgentChamp is not a disclosure route. If a child needs to tell someone something, the platform does not offer them a way to tell us - and that is the correct design. Our child-facing privacy notice tells children plainly: if something worries you, tell a grown-up you trust
Commerce - can a child spend money?

No.

  • Children cannot make purchases. There is no payment surface anywhere a child can reach
  • No in-app purchases, no loot boxes, no premium currency bought with real money. Points are earned by reading and spent on avatar items, and cannot be bought
  • No marketing is ever sent to children, and none can be - there is no email path to a child
  • No advertising, no sponsored content, no data sold to anyone

Screen time and engagement design

The Children's Code expects providers not to use design techniques that extend engagement against a child's interests. Concretely, in AgentChamp:

  • No notifications to children. We never ping a child to come back
  • No infinite feed. Content is bounded - a story ends
  • No time pressure in the standard reading mode
  • Streaks and points reward reading having happened, not time spent on screen. A child who reads for ten focused minutes is rewarded the same as one who leaves the tab open

The honest caveat: streaks are a motivational mechanic and motivational mechanics create some pressure. We think a reading streak is worth it and teachers tell us it works. If you disagree, the reward surfaces are visible in the teacher dashboard and we welcome the argument.


Filtering, monitoring and your obligations

AgentChamp is a closed platform with no user-generated content, no external navigation and no communication features, so there is nothing within it for a filtering or monitoring system to catch - no messages, no search of the open web, no uploads.

That does not displace your own duties. Your school's filtering and monitoring obligations under KCSIE apply to the device and the network; AgentChamp sits inside that, it does not replace it.

What we do not do: we do not monitor children's behaviour for safeguarding signals, and we do not flag pupils to staff. We hold no free text to analyse and no communications to scan. If you use a safeguarding monitoring product, AgentChamp gives it nothing to work with - because there is nothing.

Data protection

Covered in full elsewhere: the Privacy Policy, the Data Processing Agreement (which your school accepts at registration), the Sub-Processor Inventory, and the DPIA Support Pack written specifically to help you complete your own assessment. There is also a Privacy Notice for Children, written for the readers themselves.

Two points that matter most to a DSL:

  • No company outside our published sub-processor list sees a child's device. Since 25 August 2026 every font, script and graphic on a child's page comes from us; covers and audio come from our own storage buckets at our hosting provider. No advertiser, analytics service, font host or CDN is involved at any point
  • No child's personal data leaves the UK, and none is used to train AI
Reporting a concern
  • Safeguarding or child-safety concern about content - support@agentchamp.co.uk, marked urgent. We will respond the same working day
  • Data protection - privacy@agentchamp.co.uk
  • Security vulnerability - security@agentchamp.co.uk

If a child is at immediate risk, follow your school's safeguarding procedures and contact the appropriate authorities. We are a reading platform; we are not, and must not be treated as, part of a referral route.

Last reviewed 25 August 2026.

AgentChamp keeps you signed in and remembers your reading settings using cookies and browser storage. What we store, in full.