Stray Note

Last updated 18 July 2026

Children’s access assessment

Conclusion: Stray Note is likely to be accessed by children, so we design and operate it on that basis.

Why this is our conclusion

Stray Note has no age restriction and does not use highly effective age assurance. The service is simple, consumer-facing and based on anonymous messages, so it is possible and reasonably foreseeable that people under 18 will use it. Under the UK Online Safety Act, a child means anyone under 18.

Main risks identified

Current safeguards

We remove links and contact details, moderate before delivery, provide reporting and pair blocking, restrict ordinary letters to one delivery and one reply, keep profiles and attachments out of the product, and maintain operator quarantine and emergency controls. Country sharing is optional and off by default. The service stores only the minimum private routing data needed, as one-way HMAC values.

Rewarded advertising is disabled unless deliberately configured with an appropriate consent process. It never unlocks an unlimited loop: one completed ad can add one extra send per day.

Residual risk and review

No filter can guarantee that every anonymous message is safe. The operator must monitor reports, test moderation across supported languages, review emerging harms, train reviewers, document response decisions, and reassess before significant product changes. This assessment is reviewed at least every 12 months and sooner after a material safety incident or feature change.

Regulatory basis

This conclusion follows Ofcom’s children’s access assessment guidance and its current protection of children duties. Privacy design is assessed against the ICO’s Children’s code. A fuller internal record is maintained for operator review; this page is the plain-language summary.