CYBER WELFARE

Protect your Digital Privacy

Scam Apps Child Safety: The Phone Handed Over

Additional resource for the lesson “Scam Apps and Children: Two Settings That Prevent It” — Online Security course

A phone passed to a child for twenty minutes is a phone with a payment method attached. Scam apps child safety is mostly about two settings and one conversation — not about supervision.

A. Why this matters

Children use phones, often ones belonging to an adult. Those phones have a payment method attached, and many apps aimed at children are built around purchases a child cannot reasonably evaluate.

This is not principally a security problem, and it is not a supervision problem. It is a configuration problem with a well-defined solution, plus a conversation that tends to work better than any restriction.

The key idea: two settings prevent nearly all of this. Require authentication for every purchase, and do not leave a payment method stored on a device a child uses.

B. Key concepts

Six ideas, weighted towards what actually prevents the problem.

In-app purchases

Buying inside an app: extra lives, currency, features, subscriptions.

Why it matters to you: Entirely legitimate as a model, and designed by people who study how to encourage the next purchase. A child is not the intended adversary of that design, and does not stand a chance against it.

Purchase authentication

Requiring a password, fingerprint or face check for every purchase, rather than remembering it for fifteen minutes.

Why it matters to you: This is the single most effective setting, and both platforms default to something more permissive.

Ask to buy

Family settings where a child’s purchase request goes to an adult’s device for approval.

Why it matters to you: Better than a blanket block, because it keeps the conversation rather than removing it.

The stored payment method

A card saved to the store account, usable by whoever is holding the device.

Why it matters to you: Removing it, and adding credit through gift cards instead, caps the exposure at a fixed amount rather than at a card limit.

Fleeceware aimed at children

The same mechanism described in the companion resource, applied to apps that look like games.

Why it matters to you: Short trials, prominent subscribe buttons, cancellation several screens deep. A child will not read any of it.

The conversation

Explaining that things inside games cost real money from a real account, and that asking first is the rule.

Why it matters to you: This works better and lasts longer than restriction, and it transfers to devices you do not control.

C. A practical example: twenty minutes

A phone is handed to a child in a waiting room. A game is installed from the store — free, brightly designed, aimed at children.

  • The game offers a starter pack. The purchase requires no authentication, because the store remembers a recent one.
  • Several purchases follow over the next twenty minutes.
  • One of them is a weekly subscription.

None of this required doing anything wrong. The purchases were made through the ordinary flow, on a device where that flow does not ask for confirmation.

The same twenty minutes, configured

  • Every purchase requires a fingerprint the child does not have.
  • No card is stored; the account holds a fixed gift-card balance.
  • Purchase requests, if family settings are on, arrive on the adult’s phone for approval.

The difference is ten minutes of setup, done once. Nothing here requires watching what a child is doing.

D. Try it yourself: the ten-minute setup

On any device a child uses, including yours.

Step 1 — Require authentication for every purchase

  • iPhone: Settings, your name, Media and Purchases, Password Settings — always require.
  • Android: Play Store, settings, authentication for purchases — for all purchases.

Step 2 — Remove the stored payment method

  • Use gift-card balance instead, which caps the exposure at what you added.

Step 3 — Set up family settings if a child has their own device

  • Ask to buy, so requests come to you.
  • Age-appropriate content restrictions in the store.

Step 4 — Check the subscription list

  • The same list as in the fleeceware resource.
  • Do this once now and periodically afterwards.

Step 5 — Have the conversation

  • Things inside games cost real money from a real account.
  • Asking first is the rule, and asking is never a problem.
  • Nobody is in trouble for reporting something that already happened.

Step 5 matters more than the rest over time. Settings apply to devices you control; understanding travels with the child.

E. Videos, articles and further resources

Independent and institutional sources in English.

ConnectSafely — Parent and educator guides
The most relevant source here: guides written for parents and educators on apps, spending and online safety.
https://www.connectsafely.org/guides-2/

FTC — Protect your personal information from hackers and scammers
Consumer guidance on unauthorised charges and how to dispute them.
https://consumer.ftc.gov/articles/protect-your-personal-information-hackers-and-scammers

eSafety Commissioner (AU) — Online dating: how to stay safe
Broader material from Australia’s online safety regulator, which covers children and online platforms in depth.
https://www.esafety.gov.au/key-topics/staying-safe/online-dating

Google — Use Play Protect to keep your apps safe and your data private
Where family settings and purchase authentication live. Platform documentation.
https://support.google.com/android/answer/2812853?hl=en

NCSC (UK) — Cyber security advice for you and your family
The UK national authority’s advice hub for individuals: short, practical guidance written for people who are not IT professionals.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family

FTC — How to spot, avoid and report tech support scams
The rule worth remembering: a genuine security warning never asks you to call a number.
https://consumer.ftc.gov/articles/how-spot-avoid-and-report-tech-support-scams

Links checked in August 2026. Apple Family Sharing and Google Family Link are documented directly by each company and are the practical reference for setup.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson sits on the Secure Behavior pillar at level FL2 and is unusual in being mostly configuration.

Skills

  • Setting purchase authentication to always.
  • Configuring family settings and ask-to-buy.
  • Disputing an unauthorised charge with the store.

For professionals and organizations

  • Applicable to shared devices generally, where a stored payment method is a standing exposure.

Awareness

  • Understanding that purchase flows are designed by people who study persuasion.
  • Recognising that a child cannot reasonably evaluate these decisions.
  • Knowing that most charges of this kind are disputable.

For future instructors and ambassadors

  • Framing this as configuration rather than as parenting. It is a settings problem, and saying so removes the blame.

Secure Behavior

  • Requiring authentication for every purchase.
  • Not storing a card on a device a child uses.
  • Checking the subscription list periodically.

For organizations

  • Removing stored payment methods from shared devices.

G. Questions to sit with

  1. Does your phone require a fingerprint or password for every purchase, or only occasionally?
  2. Is a card stored on the store account of any device a child uses?
  3. When did you last look at the subscription list on that device?
  4. Would a child in your household tell you if they had bought something by mistake?

H. What to do now

The recommendations (R) and security measures (MS) that apply.

The device

  • R5, MS4 — A device code, which also prevents purchases being made while it is unattended.
  • R7 — A short screen lock timeout.

Minimum commitment: Then the two settings: authentication for every purchase, and no stored card.

The account

  • R8 — Turn on transaction alerts from your bank, which surface unexpected charges quickly.
  • MS7 — Review app permissions on devices children use, particularly location.
  • R17 — Install only from official stores.

In short

  • Two settings prevent nearly all of this: authentication for every purchase, and no stored card.
  • Purchase flows are designed by people who study persuasion; a child is not the intended adversary.
  • Most unauthorised charges are disputable through the store.
  • The conversation outlasts the settings, because it travels to devices you do not control.

Related resources in this course

Related mechanisms:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program