The Boundless PIN, and the control that matters more

How the parental PIN works, how it is stored, and why picking sources matters more than the PIN itself.

Boundless has a PIN for parental controls. It also has no built-in catalogue at all, and that second fact matters more than the first.

Setting a PIN

The PIN lives in the Settings tab.

  1. Open Settings.
  2. Go to the parental controls section.
  3. Choose a PIN and confirm it.

Write it down somewhere you'll find again. The next section explains why that matters more than it sounds like it should.

How the PIN is stored

Your PIN is stored as a salted hash in local device settings. The app stores the hash, never the plain number you typed, and the plain number is never sent anywhere. If you sign in and turn on Account Sync, off by default, the hash becomes one of the settings your account keeps, alongside your library and reading progress, so it can follow you to another device. Without Account Sync, none of it leaves this one.

A salted hash cannot be reversed. Two things follow from that:

  • The app cannot show you the PIN you set, even in its own settings screen.
  • Nobody at Boundless can recover it for you, because nobody at Boundless has it. There's no support ticket that fixes a forgotten PIN.

The bigger control: which sources exist

A PIN is one control. What a reader can reach in Boundless is entirely up to whoever installed the sources.

The app ships with zero content sources. Open it for the first time and there's nothing to browse and nothing to search. Content shows up only once someone adds a source repository by URL and installs a source from it, so everything a reader ever sees on screen is something a person deliberately put there.

For a device a child uses, that changes where your attention should go:

  • Install the sources yourself, rather than leaving that choice to whoever picks up the phone next.
  • Prefer the official repository, at https://boundless.moe/repo. It carries only public-domain and openly licensed material: Project Gutenberg, with more than 70,000 public-domain books, and Komga Demo, which points at Komga's own public demo server.
  • Remember that any repository can be added by URL. Boundless cannot vouch for a repository it did not publish, and it cannot filter what a third-party source returns.
  • Check what's installed from time to time. The list of repositories and installed sources sits in Settings, in plain sight, and removing a source stops it from appearing in Browse and Search.

Adding sources covers repositories and sources in more depth, including the part that matters most for this: source extensions run on the device itself and fetch directly from whatever site they target. There is no Boundless server sitting between the source and the site.

What Boundless does not have

Some of the usual worries about a reading app don't apply here.

No account is required, so a child can use the app without signing up for anything. Signed out, reading data stays on the device and is never sent anywhere. Comments are the one social feature, and there is no direct messaging. Posting a comment or having a profile needs a signed in account, so leaving the app signed out means a child cannot post. Comments are checked automatically, held for a moderator when flagged, and can be reported and blocked.

Using the platform's own controls alongside the PIN

The Boundless PIN is one layer. Because sources reach the wider internet straight from the device, the controls built into iOS, iPadOS, and macOS are worth setting up too. Screen Time and its content and privacy restrictions work at the level of the device and its network access, underneath any single app, Boundless included.

Running both makes sense: the operating system for broad limits on the device as a whole, source curation inside Boundless for what the app itself can reach. Neither one covers what the other does.

If you're setting this up for the first time, start with Adding sources to see exactly what installing a repository does before you hand the device over, or check Getting started for the full walkthrough from a fresh install.

More from the blog