When I gave my kids an AI study helper, the hardest question wasn’t technical. It was a parenting one: how much should a parent see? Most “parental” tech answers this badly. It either surveils — a dashboard of everything your child typed, every wrong answer — or it’s opaque, a black box you have to trust blindly. Neither felt right for my family. So I built a third way.

The study tutor

Alongside the family group chat, each of my daughters has a private one-to-one with the assistant — and that’s where the schoolwork lives. It does a handful of genuinely useful things, all in her own DM:

  • Snap → Quiz. She photographs a worksheet or her notes, and it turns them into a short quiz — a fast way to check she actually understood, not just highlighted.
  • Dictation practice (听写). For her Chinese, it runs 听写 drills — the exact kind of repetitive practice that’s tedious for a parent to sit through and perfect for a patient machine.
  • Spaced-repetition decks. Things she got wrong come back at the right interval, so revision compounds instead of cramming.
  • Exams + a private revision plan. She tells it when an exam is; it counts down and, when a topic’s thin, quietly offers a revision plan — for her to accept, in her DM, never announced to the family.

The line that makes it work: content vs. signal

Here’s the whole design in one distinction. I split what the tutor knows into two kinds of information, and I treat them completely differently.

The content is private to the kid. The actual answers she got wrong. Her marks. The topics she’s shaky on. The revision plan she’s following. All of it lives in her DM and never surfaces in the family chat or a parent view. That’s hers.

The signal is visible to a parent. Not the content — the fact of it. That she did her homework. That the quiz got done. That she’s engaging. The accountability, without the intrusion.

Said plainly: I can see that she studied. I can’t see what she struggled with.

Why that line matters

This isn’t a technical nicety; it’s the difference between a tool my kids trust and one they’d route around.

A child who knows her mistakes are private will engage honestly — she’ll let the tutor find the gaps, because being wrong in front of it costs her nothing. The moment she suspects every wrong answer is being reported upstairs, the honesty evaporates and she starts performing instead of learning. Privacy isn’t the opposite of accountability here. It’s the precondition for it.

And on my side, I don’t actually want the wrong answers. I want to know she’s putting the work in. A completion signal gives me exactly that — the same thing a good teacher gives a parent at pickup: “she’s working hard,” not a transcript of every error. It turns out the design I wanted already existed; it’s just how trust between a teacher, a student, and a parent has always worked.

Enforced, not promised

A privacy promise you can’t verify is just marketing. So this boundary isn’t a policy line — it’s in the architecture. The graded, personal study — quizzes, marks, dictation, the revision plan — is DM-scoped by design: it physically cannot enter the family digest or the group chat, because the summariser only ever reads the shared-group data, and that rule is guarded by a test that fails the build if anyone breaks it. The kid’s content and the family’s shared space are separated in code, not in good intentions. It all runs on local, open-source models on hardware at home, so none of it is a row in someone else’s database either.

Design notes on coach mode and content-only feedback
From my design notes — the rules the private tutor has to keep: coaching that survives the follow-up, and never a comment on how she speaks. Content only.

The bigger principle

Once you see it, this pattern is everywhere. Separate the signal from the content. The accountability signal — did the thing happen? — is safe to expose. The sensitive content — what exactly happened? — should be protected by default. It’s true for a kid’s homework, and it’s just as true for health data, HR systems, or any AI product built on top of information people would rather keep to themselves. Most systems collapse the two: to prove something happened, they surface everything about it. The better design proves the fact and protects the detail.

That’s the principle I care about most as these systems get more capable. The question isn’t only “what can the AI see?” It’s “what does anyone else get to see, and is that the minimum that respects the person on the other side?”

The result

My daughters have a tutor they trust — one that’s seen every mistake and told no one. And I have the one thing I actually needed: the quiet confidence that the work is getting done. No surveillance, no black box. Just a line, drawn carefully, between what’s theirs and what’s mine.


Building an AI Agent for My Family — a seven-part build log

  1. I Built an AI Agent for My Family
  2. A Voice Nobody Wants to Mute
  3. Propose, Don’t Act
  4. Find, Surface, Hand Off
  5. A Bot That Teaches
  6. The Homelab Behind the Family AI
  7. Homework Stays Private — you are here

Related: Put the Model Where Being Wrong Is Cheap.

Part of a personal DIY hobby, tinkered together on weekends for my own family, built entirely with open-source, self-hosted models.


Discover more from Digital Reflections

Subscribe to get the latest posts sent to your email.

Leave a Reply

The Blog

At the intersection of data, AI, and imagination lies the path to transformation. Our greatest evolutions occur when we use technology not just to improve what is, but to reimagine what could be.

Discover more from Digital Reflections

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Digital Reflections

Subscribe now to keep reading and get access to the full archive.

Continue reading