Minors and guardian consent
How Pippa handles patients under 18: the age gate, guardian signing, 18th-birthday ratification, and the under-13 block.
Around one in five Pippa users is under 18, so the app is built to handle minors carefully. Before anyone gives any personal information, a neutral date-of-birth age gate runs. What happens next depends on their age.
The three age paths
- Under 13. Blocked from creating an account. The block persists on the device even after signing out, so a child cannot simply retry with a different birthday.
- 13 to 17. A parent or guardian is the contracting party. The guardian provides their email and agrees to the terms, and the teen gives their own assent. The account is marked as guardian-signed.
- 18 and over. Standard terms acceptance by the person themselves.
When you look at a patient's Terms and guardianship card, "Terms signed by" tells you whether an adult signed for themselves or a guardian signed for a minor. This is separate from the data-sharing consent you request.
The guardian consent email loop
Data-sharing consent for a minor follows the same waiver flow as an adult, with one difference: the signing link goes to the guardian, not the teen. When you request consent for a patient whose terms were guardian-signed and who has not yet ratified at 18, Pippa emails the parent or guardian a guardian-addressed version of the waiver. The guardian reviews the agreement and signs on the teen's behalf.

Turning 18: ratification
A guardian's signature covers the minority years. When a guardian-signed user turns 18, the app re-prompts them to accept the terms as an adult in their own name. This is the 18th-birthday ratification. On the patient page you will see one of:
- Not yet due while they are still under 18.
- Confirmation pending while a guardian email is out and unsigned.
- Ratified once the now-adult user has re-accepted the terms themselves.
Consent records survive deletion
Consent grants, guardian confirmations, and terms acceptances are compliance records. They are kept for roughly six years and are not erased when an account is deleted or purged. Everything else about the account is removed on the normal deletion schedule. See Data lifecycle for what is retained and why.
The guardian-signing and minor-consent design is the strongest available protection, but minor-consent rules vary by state and some elements remain under legal review. Follow your institution's own guidance for consenting minors alongside this flow.