Lanternbeta

Beta tester agreement

beta-agreement v0.2. Effective September 2, 2026. Between Blue Camel Consulting LLC, a New York limited liability company, at 265 Sunrise Hwy. Ste. 1-452, Rockville Centre, NY 11570 ("Lantern", "we") and the adult who ticks the box ("you"), effective at the moment of the tick. Questions to support@lantern.family.

1. What this is

1.1 Lantern is a hosted, invite-only service at alpha.lantern.family. We run it. It screens public YouTube videos against limits you set and serves each of your children a wall of videos that passed.

1.2 You are a beta tester, for your own household's personal, non-commercial use, so you can use it with your own children and tell us what breaks.

1.3 Lantern is unreleased. Nothing here is a promise of a future product, a price, or continued service.

1.4 This agreement sits on top of the terms of service and the privacy policy, which are incorporated by reference and are not repeated here. Where this agreement and those pages disagree about what the service does with data, the privacy policy wins and this document is the one that is wrong.

2. Your access

2.1 We grant you a personal, non-transferable, revocable right to use the hosted service and the child wall links issued to your family, for the purpose in 1.2, for as long as this agreement runs.

2.2 You will not resell access, use Lantern to run a service for anyone outside your household, share your sign-in link, or pass your invite code to another family. Invites are issued per household. If another parent wants in, send them to us and we will issue their own.

2.3 A child's wall link is a credential. Treat it like a house key. You can rotate or retire one from settings at any time, and the old link stops working immediately.

3. Confidentiality

3.1 What is confidential. Lantern's screening prompts and evaluation sets; its internal documents, research notes and roadmap; your invite link and any child wall link; screenshots of the parent surface or of your child's wall; and the existence and contents of the beta programme. Anything you learn about how Lantern works that is not on the published how it decides page is confidential.

3.2 Your side is confidential too, and mostly we do not have it. What is about your family, your children's display names, their settings, what they watched, what you typed, is yours. We hold it because we run the service; section 5 says exactly what that means. We will not disclose it, and we will not use it to say anything public about your family.

3.3 Publicity. Do not post about Lantern publicly, demo it outside your household, or share the invite link, until we release publicly or say in writing that you may.

3.4 The exceptions, so this is livable. You may talk about Lantern freely (a) inside your own household; (b) using anything Jeff has already published at alpha.lantern.family/how or on jeffpinto.com; and (c) with anyone you need to in order to get help using it, so long as you do not hand over a link. Telling another parent that Lantern rates videos on named dials, in the words the how it decides page uses, is not a breach. Explaining how the scoring machinery behind those dials works is.

3.5 Screening internals are trade secrets. The wording of the screening and judging prompts, which models run in which lane, the numeric thresholds and gates, and the evaluation corpora and their results, derive value from not being generally known and we keep them secret. Your duty as to these survives without time limit for as long as they stay secret.

3.6 Standard exclusions. None of this covers information that is or becomes public other than through a breach, that you already lawfully had, that you independently develop without using ours, or that you must disclose by law or court order, with prompt notice to us where you lawfully can.

4. No reverse engineering, no benchmarking

4.1 Do not probe, scrape, or analyse the service in order to extract or reimplement its screening prompts, model configurations, thresholds, or evaluation method.

4.2 Do not run comparative benchmarks or publish accuracy or safety measurements of Lantern. "It missed this video" and "it blocked this and shouldn't have" are exactly what we want and are not benchmarks. Send them.

4.3 Do not use Lantern, or anything you learn from it, to build or assist a competing product.

4.4 Do not probe other families' data, or the admin surfaces. The terms say this too; it is repeated here because it is the one that ends the beta immediately.

5. What the service does with your family's data

5.1 We operate the server. Your family's data lives on infrastructure we run at Cloudflare, in your family's own database and your family's own storage area. Nightly jobs that build your children's shelves run at Modal. We can read your family's data, and we do when you report a bug or ask for help.

5.2 What the child surface sends us. It has no account and no login and sets no cookies. It does send a play record, which video and when, when your child watches, likes, asks for, or taps "tell a grown-up"; and it keeps two things in the browser itself, a random per-browser id that marks the browser, not the child, and a running count of minutes watched today. The random id is stored next to the play records in your family's own storage, so inside your family it does connect a device to a child. It goes nowhere else.

5.3 What your child types stays on their device. The wall's search box filters the shelf already loaded. It is never sent to us as a request and never sent to YouTube. It does appear in the page's own web address, so a mid-search reload puts that word in our host's request log for a few days; we do not read those logs for search words.

5.4 What we collect from you. Your email address; a display name you pick for each child (pick a nickname); each child's age band, dial settings, and any reason you type; the sentences you type into the "work out their settings" helper; and, if you report a bug, what you write, the page you were on, and a screenshot if you attach one. We do not ask for your name, address, or phone number, we store no password, and our application code never reads or records your IP address.

5.5 Who else touches it. Google (the YouTube player, thumbnails, video details, search), Google Gemini (reading and screening public video details), Anthropic (the "work out their settings" helper and the weekly report-card paragraph), Cloudflare (hosting and storage), Modal (the nightly jobs), Gmail (invites). Each does one job and gets no more than that job needs. The privacy policy is the current list and it is the one that is maintained.

5.6 What families share with each other is knowledge about videos, never about children. When our readers score a video, that score is about the video, carries nothing about any child, and saves the next family from paying to screen it again. Your child's name, your child's settings, what your child watched, and what you typed are never part of it and never reach another family.

5.7 Your controls. From settings, at any time: download your family's whole record as one file, or delete the whole family and get a receipt. Deletion is real; the privacy policy names the three things we keep afterwards.

5.8 COPPA. You are the parent or guardian of the children on your account, you set them up, and the child surface is built to collect as little as it can.

6. Beta reality

6.1 It will break. It is a beta run by one person on infrastructure that has never carried more than a handful of families. Expect outages, jobs that fail, and pages that are wrong.

6.2 It will get videos wrong, in both directions. It will block something fine and it will let through something you would not have chosen. It helps you supervise. It is not a substitute for supervision, and it makes no safety guarantee. You remain responsible for what your children watch.

6.3 Data loss, stated honestly. Every night we export both control databases and copy your family's storage off the Cloudflare account, encrypted, with thirty days of local retention, and we test-restore those copies rather than trusting that they worked. A stale backup raises an alarm within roughly a day. What that buys you: if something goes badly wrong we can usually put your family back to roughly where it was the night before. What it does not buy you: a promise of no data loss. Up to about a day of changes can go, and a bad enough failure could take everything. Use "download your family's record" if anything in there matters to you.

6.4 No warranty, and features move. As-is, no promise of uptime, no promise of continued service, and we may change or remove features while the beta runs. If we wind it down we will give notice and time to download your record. This mirrors the terms.

7. Feedback

7.1 Your bug reports, ideas, and suggestions may be used by us without payment, obligation, or attribution.

7.2 Your family's own content, the settings you write, what you type about your children, your approvals and refusals, stays yours. Section 5 is the only description of what we do with it.

8. Money

8.1 The beta is free. Nothing is charged, no card is asked for, and no price appears anywhere in the journey. If paid plans arrive, they will come with their own clear terms first, and you will be able to decline and either keep your data or delete it. This mirrors what the terms say today: "Nothing costs money today; if paid plans arrive, they will come with their own clear terms first."

9. Ending it, and survival

9.1 Either of us can end this at any time, for any reason, by writing. An email counts.

9.2 We may end it immediately on a breach of section 3 or section 4.

9.3 On ending, your access stops. Download your record first if you want it; delete your family from settings if you want it gone. We are not obliged to keep your data after you leave.

9.4 Survives: section 3 (confidentiality, with 3.5 surviving without time limit while the information stays secret), section 4, 6.2, 7.1, and this section.

10. General

10.1 This is the whole agreement about the beta, together with the terms and the privacy policy it incorporates.

10.2 We may change it. If we change it in a way that matters we will email you and ask you to tick again; the version you ticked is the one recorded against your account.

10.3 Not assignable by you. We may assign it to a successor of the Lantern project.

10.4 Governed by the laws of the State of New York, as the terms already state.

10.5 If a provision is unenforceable, the rest stands.

11. Signature

11.1 You accept by ticking the box before setup. We record, against your parent record and nothing else, which version of this agreement you accepted, and when. We do not record your IP address, because our application code never reads one.