CMK Kids Android — Owner Visual Review (R11)
This page is the Owner-facing review surface for the CMK Kids Android app. It presents the real Android (Emulator) screenshots and interaction video produced in R8, plus an explicitly-labelled Web Simulation for light/dark and four-language inspection. Nothing here authenticates, writes, or exposes real data.
Visual authority status: NOT APPROVED (O-5). This is a review candidate for Owner decision, not a final visual approval.
What's new in R11
- 15-minute guardian idle re-lock: the guardian area returns to the child HUB and re-locks after inactivity (R-1).
- PIN hardening: the PIN hash is device-bound through an Android Keystore key (R-2), root/debug signals are surfaced as a warning (R-3), and the lockout escalates 10 → 20 → 40 min … capped at 6 h (R-4).
- DSAR honesty: guardian export/deletion requests are recorded on-device and shown as “server not connected”; success is never faked.
- Region-aware emergency resources: a region framework that never fabricates official contacts; unconfigured regions say so, and no action contacts an external authority.
- Integration status: surfaces classify LIVE / STAGING / MOCK / NOT_IMPLEMENTED; only the local mock gateway is MOCK, everything else is NOT_IMPLEMENTED.
- Explore/Grow keep honest “sync not connected” labels; four locales (287 keys) and light/dark remain complete.
Four modules
The app shell has four bottom-navigation modules. Select one to jump to its Web Simulation and native screenshots.
Web Simulation
Simulation controls
The PIN input in this simulation is display-only; it never stores or verifies anything. Real PIN verification happens only in the native app.
Key states
Security-relevant states rendered by the candidate UI. Each state is fail-closed unless explicitly successful.
Native evidence (real Emulator screenshots)
10 screenshots captured from the Android Emulator running the R11 APK (0.9.0-r11). These are real Android native captures (not the Web Simulation). Click any thumbnail to view full size.
Interaction video
Screen recording covering the four tabs, parent gate, consent grant, chat success, four-language switch, offline and retry recovery.
Test APK (controlled download)
R11 security, privacy & integration status
- R-1 idle re-lock: 15 min — implemented and unit-tested (
GuardianSessionPolicy); native re-lock is deterministic. - R-2 Keystore device binding: the stored PIN hash is wrapped with a non-exportable Android Keystore AES key, with an explicit fail-safe plain fallback. The Guardian security card shows the live binding state.
- R-3 root/debug posture: probed and warned, never hard-blocks the child surface.
- R-4 escalating lockout: 10/20/40/80 min capped at 6 h. Behaviour change — Owner acceptance required.
- DSAR: request entry recorded on-device; the server flow is NOT_IMPLEMENTED, so no success is shown.
- Emergency / SOS: region framework only; official contacts are NOT_CONFIGURED pending Owner-approved data. No external request is sent.
- AI Gateway: local MOCK server,
legacyDetected=false, credential fingerprint645db6c9…; LIVE not enabled. Security P0 remains OPEN (Owner action).
Acceptance matrix
| Module | Locales | Themes | Native shot | Status |
|---|