· Child safety
Designing a safe digital experience for children: less data, no addiction loops, a clear role for parents
Three safety commitments translated into concrete design decisions: which data is never collected, which mechanics are never used, and how a session is designed to end well.
What makes a digital experience safe for a child?
A safe experience is not merely one without hazards. It is one where the child's interest was designed in ahead of the product's. In practice it rests on three commitments we hold to in everything we build: we collect as little data as possible, we use no addictive tricks such as daily streaks or random rewards, and we design a clear role for parents inside every experience.
Those sentences are easy to say and hard to keep once they meet engagement numbers. What follows turns them into decisions a buyer can verify rather than take on trust.
Minimal data: what does it look like as a decision?
The principle starts with a question asked of every field before it is added: what breaks if we do not collect this? Whatever the experience runs fine without is not collected. In children's products that usually means:
- Doing without real names, phone numbers and precise location; a nickname the child picks or the system generates is enough.
- Keeping on the device whatever can stay there instead of sending it to a server. What never travels cannot leak.
- Separating the parent's contact details from the child's usage data: different purposes, different retention.
- Setting a retention period per data type and actually deleting at the end of it. The US Children's Online Privacy Protection Rule (COPPA) requires personal information to be kept only as long as reasonably necessary for the purpose it was collected for, not indefinitely.
- Keeping advertising trackers out of a children's experience, because one small field becomes a full profile once joined with others.
Responsible Data for Children, a collaboration between UNICEF and The Governance Lab at New York University, sets out seven principles for the data life cycle, among them proportionality and preventing harm across the whole cycle rather than at collection alone.
We apply the rule to ourselves: our contact form asks you not to send information about a specific child, and your message is used only to reply to you and shared with no one.
No addiction loops: what we rule out, and what replaces it
The mechanics are familiar: the daily streak lost after one missed day, the random reward that keeps a child trying because the timing is unknown, the infinite feed with no bottom, the countdown that manufactures urgency, and the message that makes a child feel they let someone down by stopping.
The problem is not that they fail. It is that they succeed at the wrong goal: they build a motive to reopen the app, not a motive to learn. The motivation literature has long held that external rewards lift enthusiasm at first, then fade with familiarity, and that what endures is whatever attached itself to mastery.
The alternative is not boredom but a different design: a clear goal with an ending the child reaches and feels, visible progress that pauses and resumes without penalty, a reward tied to what was learned rather than to opening the app daily, and pacing the child controls rather than the server.
How does a session end well?
How a session ends is a full design decision, and many products never make it. A good session stops at a natural boundary: a chapter closes, a level completes, or a short summary says what the child accomplished today. It ends without a manufactured cliffhanger, and respects a parent's timer by reaching a stopping point instead of cutting off mid-attempt.
For the youngest children, less screen time is itself the goal. The World Health Organization recommends no screen time for infants and one-year-olds, and no more than one hour a day at two and at three to four, with less being better. That is one reason we care about what happens away from a screen entirely: our next device does not glow.
A clear role for parents: inside the experience, not around it
A real role answers three questions: what is my child doing, what can I change, and how will I know when something needs my attention? A dashboard that takes ten minutes to understand is not a role. It is another chore.
One ethical condition often gets skipped: the child should know the parents can see. Covert monitoring breaks trust the moment it is discovered, and it is always discovered. Better design makes visibility explicit and turns it into conversation rather than inspection. That is the thinking behind Drayesh, which is in development: a window bringing child and parents closer through a safe virtual friend that opens conversation instead of closing it. In Noody, social interaction between children happens under full parental oversight.
Age-appropriate defaults
The working rule: the safest setting is the default, not an option in a menu. Most people never change settings, and a child's safety should not depend on finding a hidden switch.
So chat, sharing and in-app purchase start off and open only by a deliberate parental decision, settings are built around age bands rather than one number, and the child is never asked to configure their own protection.
What to ask a vendor before signing
- What is the full list of fields collected about the child, and what breaks without each one?
- Where is the data stored, how long is it kept, and who inside the company can read it?
- What third-party tools are embedded, and what do those collect?
- Does the design include a daily streak, a random reward, or an endless feed? If so, why?
- How does a session end, and what happens when a parent's time limit runs out?
- What exactly does the parent see, and does the child know they are seen?
- What are the defaults for a seven-year-old, and for a fifteen-year-old?
- Who tested it with children before launch, and how was parental consent obtained?
Written answers to those eight make a serviceable contract annex. A supplier reluctant to put them in writing has already answered.
Where to start
If you are preparing to commission a children's experience, put these questions in the tender document rather than the final review. You can read our short answers to the questions we get most, or tell us your idea through the Start a project form.
References
- World Health Organization, guidance for children under five: https://www.who.int/news/item/24-04-2019-to-grow-up-healthy-children-need-to-sit-less-and-play-more
- US Federal Trade Commission, COPPA compliance plan: https://www.ftc.gov/business-guidance/resources/childrens-online-privacy-protection-rule-six-step-compliance-plan-your-business
- Responsible Data for Children (UNICEF and The GovLab at NYU): https://rd4c.org/
Quick questions
Why avoid daily streaks and random rewards?
They build a motive to return to the app rather than a motive to learn, and they tie persistence to the fear of breaking a chain. We replace them with goals that have a clear end and rewards tied to what the child actually learned.
What counts as minimal data in a children's product?
Ask of every field: what breaks if we do not collect this? Whatever the experience survives without is not collected. Real names, phone numbers and precise location are rarely necessary for a child.
What does a clear role for parents look like?
Parents should understand in under a minute what the child is doing and what they can change, and the child should know the parents can see. Covert monitoring destroys trust the moment it is discovered.