/decisions · 2026-09-02 · scribble-works · account-relationship-model

Scribble Works accounts — the relationship model, before v2 starts

Source: your 11:08 ET iMessage (lead parent, household adults, teachers, classrooms, linking). Full brief: ~/rdco-vault/01-projects/printables-product/2026-09-02-account-relationship-model-decision.md. Owner: Founder (8 picks). Priority: High. Status: decided (amended), 2026-09-02 18:15 ET.

Founder decision, 2026-09-02 18:15 ET: AMEND. D2 full birthday (charter §6 stands, Ray's month+year narrowing overruled). D3 lead-only adds adults, and a lead can promote any other adult to lead. D4 agreed as revised 11:55; the teacher/classroom paradigm is planned into the schema and not actioned in v2. D0, D1, D5, D6, D7, D8 at Ray's default. Counsel sourcing done 2026-09-02 (shortlist in the vault); outreach PARKED by the founder 18:30 ET until “ready for counsel”. Ruling 30 (18:33 ET): counsel is not a gate; v2 builds as planned with the D5 diligence posture. Cadence: now.

Yes, the entities work — with one structural rule that carries most of the legal weight: every child record is created by a parent and owned by a household, never by a teacher. When the school phase arrives, a teacher creates an empty seat and a parent redeems a join link to attach her own child profile to it. That keeps a child's information always collected from a parent under their own account, keeps us from ever holding a school roster, and makes the consent flow double as the acquisition flow.

Twelve entities, six of them built now: Household · Adult (lead | adult, max 3) · Identity (magic link / Google / Apple / SMS) · Child profile (household-owned, no photos, no last name) · Consent (who consented to what, when, how verified, how revoked — the record everything else checks) · Consent event. Deferred to v3: Organization · Org membership · Classroom · Seat · Enrollment · Link invite.

Your 11:22 ruling is applied throughout — "start with parents/households and we can expand to teachers/schools… Teachers may use this independently, but we would treat them as a household for now." So: v1 lead parent + identities (in flight) → v2 household adults + kid profiles + consent + paid fill-on-demand (M) → v3 schools as a separate, later, evidence-gated phase (L). Teachers ride along as ordinary households in the meantime, with no class rosters and no child data from schools. The state-by-state school-law plan is an appendix, not a gate on v2.

The one legal item that gates v2 is whether the live site reads as "directed to children" under the COPPA rule. If it does not — and the FTC's own guidance says COPPA does not cover information about children collected from their parents — our exposure is materially lighter than the charter assumed. That is a lawyer's call, not Ray's. Nothing here is legal advice.

Decision 0 — the one that actually unblocks v2

Authorize counsel, on two questions: (1) is the live site "directed to children" under the COPPA rule, and (2) does the school-to-parents growth test trip Florida's operator statute? That second one is new and it matters — Florida's test is disjunctive: school-facing marketing alone can trigger it, with no school relationship and no actual knowledge. Our home state is the one that does not fit the "we're a parent product" argument, and §3 proposes exactly that kind of school-facing test — nothing is scheduled; it does not run until this is answered.

Ray's default: bring you three children's-privacy attorneys with quotes and turnaround times inside a week, scoped to a written opinion on those two questions, at a ceiling Ray proposes rather than asks you to invent — you pick one or say no. Until an opinion lands, v2 builds behind a flag, nothing child-profile-related reaches production, and the growth test runs as a parent offer ("ask your child's teacher") rather than a school offer.

Decided: default. Counsel sourcing done 2026-09-02 (shortlist in the vault); outreach PARKED by the founder 18:30 ET until “ready for counsel”. Ruling 30 (18:33 ET): counsel is not a gate; v2 builds as planned with the D5 diligence posture.

The eight picks (v2 only)

  1. Passwords? Ray's default: no. Magic link + Google + Apple. A password creates the MFA obligation and the breach surface; districts want federation (Google Workspace, Clever, ClassLink), not passwords. Decided: default.
  2. Child birth date — month+year or full birthday? Ray's default: month + year, narrowing charter §6. Blocking for the v2 schema. Expensive but not irreversible: a birth date we never collect cannot be back-filled, so reversing means asking every existing parent to re-enter it. Free today, awkward the day after launch. Decided: full birthday, charter §6 stands (founder, 18:15 ET).
  3. Who can add adults? Ray's default: lead only; spouse and grandparent get equal read/print, lead alone touches billing, membership, children, consent. Decided: amended (founder, 18:15 ET) - the lead alone adds adults, and a lead can promote any other adult to lead; a second lead has full lead rights, the promoting lead keeps theirs unless they step down.
  4. Can a teacher ever create a child profile? Ray's default (revised 11:55 ET after the founder's push-back): teachers create classrooms and seats; parents create and own the child record. A seat is a teacher-labelled placeholder (nickname or initials, never a full name until counsel and a district DPA allow it) with a referral code the teacher hands parents along with the class education plan; a parent claims the seat with her own child profile. School→parents and parents→schools both work; consent stays with the parent. Flagged honestly as a v3 pre-commitment: in v2 there is no linking and no teacher role, so nothing in the schema stops a teacher-household typing in 25 students. In v2 the rule is contractual, not technical, backed by an eight-profile-per-household cap whose over-cap prompt asks "setting this up for a class?" and routes to a waitlist. That turns an invisible compliance risk into a visible demand signal for v3. Agreed as revised 11:55 (founder, 18:15 ET); v3 pre-commitment: schema carries classroom and seat as planned entities, nothing built in v2.
  5. Consent posture for v2. Ray's default: design to stay outside COPPA's collect-from-a-child trigger (adult-only sign-in, no child login, every child field typed by a parent) and hold to COPPA-grade practice anyway. Counsel confirms the "directed to children" read before v2 ships. Stated plainly: if counsel reads it the other way the defence does not weaken, it disappears — notice duties attach and persistent identifiers become the bigger exposure. That is a different v2, not a modified one. Decided: default.
  6. UGC pipeline scope. Ray's default: unchanged from ruling 21, plus an explicit consent scope a parent can switch off. Decided: default.
  7. Accept the teachers-as-households roster exposure for a quarter? Ray's default: yes. A teacher-household can enter her students as child profiles and nothing in the schema stops her; the alternative is blocking teachers (which your ruling 23 explicitly does not want) or building v3 now. This is a live choice about what ships this quarter, not a future one. Decided: default.
  8. Cap child profiles per household? Ray's default: yes, at eight — arbitrary until measured, above a large family and well below a class of 25. The over-cap prompt asks "setting this up for a class?" and routes to a waitlist instead of silently raising the limit, which turns an invisible compliance risk into a visible demand signal for the classroom tier. Decided: default.

Classroom tier boundaries and whether we ever sign district paper are deferred to v3 with the rest of the school phase, per your ruling.

Growth — both funnels (school phase), and the cheapest test of each

Caveat added after review: the school-to-parents test as originally drafted is school-facing marketing, which is exactly what Florida's operator statute can trigger on. Until counsel answers, it runs as a parent offer.

The three items that need counsel

  1. Is the live site "directed to children" under 16 CFR §312.2? The test weighs visual content, animated characters, child-oriented activities and our marketing copy. This is the only one that gates v2, and it makes marketing copy a compliance surface.
  2. If it is, which consent method we may rely on — and whether the lighter "email plus" path survives our planner, our UGC pipeline, and our subprocessors.
  3. Florida's disjunctive operator test (Fla. Stat. §1006.1494) versus our own school-facing growth marketing — the live one, above. Then the rest state by state; Illinois is the sharpest, requiring a written school agreement before any covered information is transferred.

Lock in

Approve all defaults

Ray builds v2 on the defaults above, sources counsel candidates, and stops at the three blocking rows until you answer.

Approve + send
Amend — change specific picks

Name the numbers you want changed and what to instead (e.g. "2: full birthday").

Amend + send
Counsel first

Hold v2's child profiles until a lawyer has cleared the three items. Ray builds the household-adults half only.

Counsel + send
Defer

Push the whole relationship model to a date. v1 accounts keep shipping; kid profiles wait.

Defer + send