Skip to main content

    Minor Recipients and Guardians Policy

    How Y.O.D.O. handles Recipients who are under 18 and the role of a parent or legal guardian.

    Version 2.7.0Last Updated

    Toggle changelog details. What changed in v2.7.0 (9 September 2026)

    Version 2.7.0 · 9 September 2026

    • 4.9 is marked not yet available. The clause was written in the present tense -- “we may tell the Minor Recipient”, “we do not send this notice below 13” -- and read as a live capability. It is not built. There is no notice feature in the application, no age floor applying to it, and no notice email. Until it ships, every route to a Message runs through a Guardian under 4.2. The clause stays published, with a status note, because the terms and the reasoning are worth settling before the feature exists rather than after.
    • The 2.5.0 entry below is corrected. It said the age-13 floor stated a floor the application already enforced. That was wrong, and it was published. The floor is a commitment for when the feature is built, not a description of current behaviour.

    Earlier revisions

    Version 2.6.0 · 7 September 2026

    • Delegates found to be under 18 (§1.1a). We now say what happens when we learn a Delegate is a child: we end that delegation, however we came to know. The Account Holder is told their Delegate was removed, on the same terms as any other removal, and we do not disclose the person's age or who told us. We record that the removal happened and why, without keeping a date of birth in order to do so. Anyone can ask us to act on this by writing to info@yodo.ltd.

    Version 2.5.0 · 7 September 2026

    • An age floor for notices (§4.9). We do not send the “a Message is being held for you” notice to a Minor Recipient under 13; below that age everything routes to the Guardian instead, which reaches the same outcome without asking the child to carry the request to an adult. The threshold follows section 9 of the Data Protection Act 2018, the age at which a child in the United Kingdom can consent to information society services on their own behalf. The limit narrows who we contact directly, not who may receive a Message. Corrected on 9 September 2026: an earlier version of this entry said the floor was one the application already enforced. It is not. The notice feature is not built, so there is nothing yet applying the floor; see the status note at 4.9.

    Version 2.4.0 · 7 September 2026

    • A warning before naming a child (§3.3). A Message for a Minor Recipient is not held until they grow up. It is released to a verified Guardian for the same 12 months that applies to every Recipient, and if no Guardian completes verification in that time and no extension is agreed, the Message is deleted and cannot be recovered. We would rather an Account Holder knew that when naming a child than discovered it afterwards, so it is now stated at the point of the decision.

    Version 2.3.0 · 7 September 2026

    • Letting a Minor Recipient know a Message exists (§4.9). Where the Account Holder has given us the child's own email address and chosen this option, we may tell the Minor Recipient that a Message is being held for them. The access window is finite, and a child who does not know a Message exists cannot ask anyone to start the Guardian process in time.
    • Notice is not access. The notice says only that a Message is being held, that an adult with parental responsibility must complete a verification step first, and how that adult can reach us. It contains no part of the Message, no preview and no attachment. No access is granted to a Minor Recipient under this clause; access still follows §4.2, §4.7, §4.8, or §4.5 if they turn 18 while the window is open.
    • Retention corrected (§4.1). Our previous wording described the access window for a Minor Recipient loosely as “a limited period”. It is 12 months from the delivery trigger, the same window that applies to every Recipient, including a Guardian acting for a child. Extensions may be requested under Terms section 11.4.

    Version 2.2.0 · 7 September 2026

    • If the named Guardian cannot act (§4.8). The Guardian an Account Holder named may have died, lost capacity, become unreachable, declined the role, or ceased to hold parental responsibility. In any of those cases a person who is in fact the Minor's parent or legal guardian may now apply to us for access on the child's behalf, whether or not the Account Holder named them and whether or not the Account Holder knew of them. We ask for identity verification and evidence of parental responsibility, and we pause the access window while a properly made application is assessed, so Messages are not deleted under §4.3 while someone is waiting on us. The purpose is narrow: the Account Holder wrote to a child, and that child should receive it.

    Version 2.1.0 · 15 May 2026

    • The last version published before the September 2026 revisions above. Versions 2.2.0 to 2.6.0 were prepared together and take effect on the same date; they are listed separately here so each change can be read on its own.

    Company: Y.O.D.O. Ltd (Company No. 15736034)
    Registered Office: 42 Mayfair Gardens, Southampton, SO15 2TW, United Kingdom
    ICO Registration: ZC015883 (Data Protection Lead: Mrs Theodosia Kouraki)
    EU Representative under Article 27 EU GDPR: Christina-Eloiza Kouraki, Marasli 29, Athens 10676, Greece, email eloizakouraki@yahoo.gr.
    Contact: info@yodo.ltd

    This policy explains how Y.O.D.O. handles Recipients who are under 18 ("Minor Recipients") and the role of a parent or legal guardian ("Guardian").

    This policy should be read with our Terms and Conditions, our Privacy Policy, and the ICO's Age Appropriate Design Code (the Children's Code). If there is any conflict, the Terms and Conditions apply.

    1. Scope

    1.1 Y.O.D.O. is designed for adults. Account Holders and Delegates must be 18 or over. We ask this twice: once of you when you set up your account, and once of the Account Holder at the moment they name a Delegate, because they are the person who knows. Neither is a check of identity documents, and we do not ask any Delegate for a date of birth.

    1.1a If we learn that a Delegate is under 18, we end that delegation. We do this whether the person tells us themselves, the Account Holder tells us, a parent or guardian tells us, or we establish it another way. The Account Holder is told their Delegate has been removed, as they would be for any removal, and we do not disclose the person's age or who told us. We record that the removal happened and why, and we do not keep a date of birth in order to do so. Anyone can ask us to act on this by writing to info@yodo.ltd.

    1.2 A person under 18 can be included only as a Recipient.

    1.3 The ICO's Age Appropriate Design Code applies to the parts of the Service likely to be accessed by children, principally the Recipient access flow when a Minor Recipient retrieves a delivered Message. We design those flows to the Code's standards by default.

    2. Principles

    2.1 We prioritise safeguarding, privacy, and fraud prevention.

    2.2 We apply data minimisation and collect only what is needed to apply these safeguards.

    2.3 We do not profile children, do not target them with marketing, and do not use their data for any analytics or product testing beyond what is necessary to operate the Recipient access flow.

    3. Adding a Minor Recipient (Account Holder responsibilities)

    3.1 If you add a Minor as a Recipient, you confirm you have a lawful basis to share their details with us. For example, as a parent, legal guardian, or person with parental responsibility for the Minor Recipient, you may share their details on that basis. If you are unsure whether you have the right to share a Minor's details, seek legal advice before proceeding.

    3.2 You are responsible for the content you create. Y.O.D.O. does not review Messages for suitability for minors.

    3.3 Please read this before you name a child. A Message for a Minor Recipient is not held until they grow up. It is released to a verified Guardian for the same 12 months that applies to every Recipient, and that Guardian has to download it and keep it. If no Guardian completes verification within those 12 months, and no extension has been agreed, the Message is deleted and cannot be recovered. We would rather you knew that now than found it out later. When you name a child, name an adult who is likely to be able to act as well, tell that adult they have been named, and consider recording a chosen guardian in your will. Sections 4.7 to 4.10 explain what happens if that adult cannot act.

    4. How Minor Recipient access works

    4.1 Delivered Messages are available for 12 months from the delivery trigger, as set out in Terms sections 11.3 and 11.4. The same 12-month window applies to every Recipient, including a Guardian acting for a Minor Recipient. Extensions may be requested under Terms section 11.4.

    4.2 If the Recipient is under 18 at the start of the access window, we may require a Guardian to complete additional steps before access is granted, which can include:

    • identity verification (via our verification provider), and
    • evidence of parental responsibility or legal authority where appropriate (for example a birth certificate, adoption order, or court order). We will confirm what is required when you contact us.

    4.3 If the required steps are not completed within the access window, the Message may be deleted in line with our retention rules.

    4.4 If a Recipient or Guardian contacts us within the access window and access is delayed due to our systems or our verification provider, we may extend the access window for a reasonable period.

    4.5 If a Minor Recipient turns 18 during the access window, they may contact us to request direct access. We will verify their identity and, if satisfied, grant access without requiring Guardian involvement.

    4.6 If you are unable to complete Guardian verification due to circumstances outside your control (for example a verification provider outage or lost documents), contact Support and we will try to find a suitable alternative approach, subject to our security and fraud prevention requirements.

    4.7 If the Account Holder was the child's only parent or guardian. Where the Account Holder who passes away was the Minor Recipient's sole parent or legal guardian, Messages addressed to the child are kept securely and remain unreleased until a new legal guardian has been formally appointed (for example through a guardian named in the Account Holder's will, or by a court). Once appointed, the new guardian may contact us to verify their identity and authority, after which the standard Guardian access steps in 4.2 apply. We will pause the access window during this period where reasonably necessary so that Messages are not lost while formal guardianship is being arranged. If you are concerned about this scenario when adding a child Recipient, we encourage you to name a chosen guardian in your will and to record their details in your Y.O.D.O. account notes.

    4.8 If the named Guardian cannot act. The Guardian the Account Holder named may be unable to act when the time comes. They may have died, lost capacity, become unreachable, declined the role, or ceased to hold parental responsibility for the Minor Recipient. In any of those cases, a person who is in fact the Minor's parent or legal guardian may apply to us for access on the child's behalf, whether or not the Account Holder named them, and whether or not the Account Holder knew of them. They do not need to have been recorded in the Account Holder's Y.O.D.O. account.

    To apply, contact Support at info@yodo.ltd. We will ask for identity verification and for evidence of parental responsibility or legal authority for that child, as set out in 4.2, for example a birth or adoption certificate, a court order, a special guardianship order, or a local-authority placement decision. We will also ask what has happened to the named Guardian, so far as the applicant knows it. Where the claim is contested, or where we are not satisfied on the evidence, we will not release the Messages and will say so.

    We will pause the access window while a properly made application is being assessed, so that Messages are not deleted under 4.3 while guardianship is being established. We do not hold Messages indefinitely: if no eligible guardian comes forward before the 12-month window closes, the Messages are deleted under 4.3. That is why we would rather hear from someone early, even if their authority is not yet fully documented, than not hear from them at all.

    The purpose of this clause is narrow and worth stating plainly: the Account Holder wrote to a child, and that child should receive what was written for them. The Guardian mechanism exists to protect the child, not to become the reason the Messages are lost.

    Status: not yet available. Clause 4.9 describes a feature we have designed but not yet released. We do not send any notice to a Minor Recipient today. Every route to a Message currently runs through a Guardian under 4.2. The clause is published in advance so the terms and the reasoning are settled before it is built; it is written below in the present tense to describe how it will operate. We will update this policy, with a new version and a changelog entry, when it goes live.

    4.9 Letting the Minor Recipient know a Message exists. Where the Account Holder has given us the Minor Recipient's own email address and has chosen this option when adding them, we may tell the Minor Recipient that a Message is being held for them. We do this because the access window is finite. A child who does not know a Message exists cannot ask anyone to act, and if nobody acts before the window closes the Message is deleted under 4.3. It is the child, more than anyone, who has a reason to get the Guardian process started in time.

    No notice below the age of 13. We do not send this notice to a Minor Recipient under 13. Below that age everything routes to the Guardian, who is told that a Message is being held and can begin the process under 4.2. We set the threshold at 13 by analogy with section 9 of the Data Protection Act 2018, which is the age at which a child in the United Kingdom can consent to information society services on their own behalf. The reasoning is recorded in our data protection impact assessment for this feature.

    Why an age limit at all. A notice of this kind asks the child to take it to a trusted adult. Below 13 we do not think that is a fair thing to ask, and the Guardian route reaches the same outcome without placing the request on the child. The limit narrows who we contact directly; it does not narrow who may receive a Message.

    Notice is not access. The notice tells the Minor Recipient only that a Message is being held, that an adult with parental responsibility for them needs to complete a verification step first, and how that adult can contact us. It does not contain the Message, any part of it, any preview, any attachment, or anything about what it says. No access is granted to a Minor Recipient at any point under this clause. Access follows 4.2, 4.7 or 4.8, or 4.5 if they turn 18 while the window is still open.

    How we word it. The notice is written to be read by a child, in plain language, without urgency, pressure, or any suggestion of what the Message might contain. It encourages the Minor Recipient to speak to a parent, guardian, or another adult they trust, and it gives that adult a direct route to us. We send it once, with at most one reminder, and the Minor Recipient can ask us to stop sending it.

    Control and choice. This is off unless the Account Holder turns it on for that Recipient, and the Account Holder can turn it off at any time while they are alive. We will not send a notice where we have not been given the Minor Recipient's own address, where the Account Holder has not chosen this option, or where we have reason to believe a notice would not be in the child's interests. A Guardian who has been verified for that child may also ask us to stop.

    We treat a Minor Recipient's email address as children's personal data under the ICO's Age Appropriate Design Code and process it only to send this notice and to answer a reply to it. It is not used for marketing, is never shared, and is deleted with the rest of the Recipient record under our retention rules.

    4.10 What a verified Guardian is expected to do. Once a Guardian has been verified under 4.2, 4.7 or 4.8, the Messages addressed to the Minor Recipient are made available to them for the remainder of the access window. It is for the Guardian to download those Messages and keep them safe, and to decide whether the child sees them now or when they are older. That judgement belongs to the person responsible for the child, not to us.

    Please download and store the Messages during that 12-month window. Y.O.D.O. is not a long-term archive for a Minor Recipient's Messages and does not keep them until the child turns 18. When the window closes, the Messages are deleted under 4.3 and cannot be recovered. If you need more time, ask us at info@yodo.ltd before it ends.

    4.11 How we use our discretion to extend, where a child is involved. Terms section 11.4 lets us extend an access window. Where the Recipient is a Minor, we start from the position that an extension should be granted, and we look for a reason to say yes rather than a reason to say no. We will normally extend where guardianship is being appointed, where a court or local authority process is under way, where an application under 4.8 is being assessed, or where a Guardian has been verified but needs longer to arrange safe storage.

    We take this approach because the consequence of getting it wrong falls on a child who did nothing to cause the delay, and because formal guardianship can take longer than 12 months to settle. It is not an unlimited commitment, and we will still refuse where a request is not genuine or where we are not satisfied about identity or authority, but a child should not lose a parent's last words to a calendar. If you are close to the end of a window and the position is unresolved, contact us anyway.

    5. Data we use (high level)

    We may process:

    • the Minor's contact details and date of birth (only to apply these safeguards), and
    • Guardian verification outcomes and authority evidence where required.

    Details are in our Privacy Policy.

    6. Verification

    6.1 Account Holders and Delegates must complete phone and email verification for account security.

    6.2 Recipients may access delivered Messages without creating an account, but identity verification may still be required before access is granted.

    7. Concerns and support

    7.1 Immediate risk

    If you believe a Minor is at immediate risk, contact emergency services.

    7.2 If you suspect misuse or misdelivery involving a Minor Recipient, contact us at info@yodo.ltd with the subject line "Minor Recipient Concern". We aim to acknowledge concerns involving minors within 2 Business Days. If a concern involves immediate risk, always contact emergency services first.

    8. Updates

    We may update this policy from time to time and will update the "Last Updated" date.

    EEA Minor Recipients

    If a Minor Recipient is in the European Economic Area, EU GDPR applies to our processing of their personal data alongside UK GDPR. EEA Guardians may exercise the same rights described in this policy and may also raise concerns with their local data protection authority. The Hellenic Data Protection Authority (HDPA) is named in our Privacy Policy as our expected primary EU supervisory contact, given our appointed EU representative is established in Greece.

    Important safety reminder

    Do not send one-time codes, identity documents, death certificates, passwords, or payment details via email or messaging apps. If you need to provide documents, we will direct you to the secure in-app flow.

    Questions about Minor Recipients?

    If you have questions about how Y.O.D.O. handles Messages for Recipients under 18, please contact us. We are happy to explain the process.