Safety Isn't a Feature. It's the Foundation.
When the user is a child, safety cannot be a setting you switch on. It has to be the thing every other decision is built on top of.
Most products bolt safety on. We started there.
It is tempting to build the clever product first and add guardrails later. With children, that order is backwards. A filter added at the end only covers what its author happened to imagine.
We designed the safety review before the lessons. Every message a child sends and every reply a coach returns passes through layered checks before it is ever shown.
A crisis is not a place to improvise
If a child signals distress, a generative model should not be free-styling a response. Our crisis protocol is deterministic: fixed, human-reviewed wording that responds with care and points to real help. The same input always produces the same safe output.
Every Layer Assumes the Others Will Miss
One good filter is a single point of failure with good marketing. That is why our pipeline has seven layers, not one: checks before the AI, rules inside it, review after it — each built on the assumption that the others will occasionally miss.
Two consequences of that assumption are worth knowing. First, a coach's reply is never streamed to the screen as it is generated; the full response is buffered, reviewed, and only then shown. Second, if a safety layer itself breaks — an outage, an error — we block the message rather than wave it through. A jammed gate stays shut.
None of this is visible when it works, which is precisely the standard: the safest classroom is the one where nothing interesting ever happens at the door.
What the Foundation Costs Us
Building on safety is not free, and we would rather tell you the price than pretend there is none. Buffered, reviewed replies mean your child waits a beat longer than a raw chatbot would make them wait. Fail-closed means that when a safety layer goes down, homework help goes down with it until we fix it. Refusing behavioural profiles and advertising means walking away from the easiest revenue in consumer software.
We pay all three without much agonising, because the alternative prices are worse: a fast reply that should never have been shown, a broken gate swinging open, a business model that needs your child to stay online. Slow is annoying. Unsafe is unacceptable. That asymmetry decides every trade-off in the product.
What we refuse to do
We do not show advertising to children. We do not build behavioural profiles. We do not sell personal data, and photos sent to ask a question are used to answer it and then discarded.
None of this is a premium tier. It is the floor.