Digital Safety Plan

How we keep children safe on ThinkSmith

ThinkSmith is a learning platform where children work with an AI coach and AI classmates. This document sets out the risks we have identified, what we do about each of them, and how to reach us.

Published 19 August 2026  ·  Last reviewed 19 August 2026  ·  Owner ThinkSmith Multiplier Inc.  ·  Contact contact@thinksmith.ca

ThinkSmith is not a crisis line. It is an educational tool. If a child is in immediate danger, call your local emergency services. In Canada, Kids Help Phone is available 24/7 on 1-800-668-6868. In the United States, the 988 Suicide & Crisis Lifeline is available 24/7 on 988.

1. What ThinkSmith is

Children work through challenges built from their provincial or state curriculum. An AI coach, Ms. Rivera, gives feedback on their thinking. Three AI classmates produce solutions the child critiques, and feedback on the child's own work.

There is no messaging between users, no public posting, no feed and no friending. A child cannot contact another child through ThinkSmith, and nothing a child writes is visible to anyone outside their own family and our review team. Most of the risks associated with social platforms do not arise here — the risks that do arise come from the AI itself, and that is what this plan addresses.

2. Risks we have identified

RiskWhat we do
A child discloses distress, self-harm or abuse while workingEvery message is screened before the coach replies. Coaching stops; the child is directed to a human crisis service. Section 4.
The AI generates something harmful, even from an innocent questionEvery generated response is screened before the child sees it. Flagged responses are discarded, not shown. Section 5.
A child believes the AI is a personThe coach and the classmates are identified as AI on screen and beside every name. Section 6.
The AI is shaped over time into something it should not beNo cross-session memory or profile is built. Section 7.
A child is given advice we are not qualified to giveMedical, legal, psychological and financial advice are blocked categories for the coach. Section 5.
Personal information is over-shared in a safety reportReports are limited to what an authority needs to assess risk. Section 8.

3. Two layers of protection

Tier 1 — the foundation. Our AI runs on Claude, made by Anthropic. Anthropic's safety systems apply to everything the model produces. This protection is always on and does not depend on us.

Tier 2 — ThinkSmith. The foundation layer cannot know what a good lesson looks like, or what Ms. Rivera is supposed to be. That is our responsibility, and it is where we concentrate our work. Sections 4 to 8 describe it.

4. When a child may be at risk

Every message a child writes is screened for distress before the coach is allowed to reply. Where the content indicates self-harm or serious distress:

Flags are recorded permanently and cannot be deleted. Each one records who reviewed it, when, what was decided and whether a parent or authority was notified.

5. Screening what the AI says

Screening what a child writes is not enough on its own. A child can ask something entirely innocent and a model can still produce an answer we would not want shown. So every response is screened independently before it reaches the child — the coach's replies, the classmates' solutions, and the classmates' feedback.

A flagged response is discarded and never displayed. The child sees a neutral message inviting them to try again, and the incident is recorded for our team to review, including what was generated and why it was stopped.

Categories that stop a response: sexual content involving a minor; self-harm; hate; violence; violent extremism; intimate imagery shared without consent; and any claim by the AI to be a human being. For the coach specifically we also stop advice given as though from a licensed professional, anything designed to keep a child engaged against their interest, and content unsuitable for the child's age.

Why the AI classmates are held to a different standard. They are designed to make mistakes. The whole point of the activity is that a child reads a flawed solution and works out what is wrong with it. So a classmate being incorrect, hesitant or muddled is the product working, not a failure — and we do not stop a response for it. We stop a classmate only on the categories above, where the harm has nothing to do with being wrong.

6. Making clear the AI is not a person

Ms. Rivera has a human name and speaks warmly. The classmates write like children, including hesitantly and imperfectly. A child could reasonably mistake either for a person, so we say plainly that they are not:

7. Memory and profiling

Ms. Rivera has no memory of your child across their work. Within a single challenge she can see the last few exchanges about that one piece of work, so her coaching follows the conversation. Nothing carries between challenges.

She builds no profile, forms no impression over time, and cannot be gradually shaped by one child into something she is not. When a child submits the same work again, she reviews it fresh rather than judging them for asking twice.

She also works to fixed teaching rules — she guides thinking rather than supplying answers, and those rules are the same for every child, every time.

8. What we share, and what we never share

Where a report to a child-protection authority is required, we share only what an authority needs to assess immediate risk and contact a parent:

We do not include a home address, date of birth, telephone number, location data or billing details in a safety report.

In rare cases where notifying a parent could itself place a child at risk — for example where the concern involves the household — we do not notify the parent, and the matter goes to the authority directly.

Learner records are held in Canada. We do not sell or share family information, and we show no advertising.

9. Human review

Conversations between a child and the coach are retained and read by ThinkSmith team members as part of ongoing quality and safety checks. Parents are told this before their child begins.

Two separate review queues exist. Child-safeguarding flags are reviewed for urgency — a possible risk to a child needs a person quickly. Flagged AI responses are reviewed for pattern — whether our screening is calibrated correctly, and whether it is stopping things it should not. Each review records who carried it out and when.

10. Reporting a concern

Anyone — a parent, a child, or anybody else — can raise a concern about content or conduct on ThinkSmith by emailing contact@thinksmith.ca. We acknowledge every report and tell you what we have done.

If a child is in immediate danger, contact emergency services first. We are not a crisis service and cannot respond immediately.

11. Reviewing this plan

We review this plan at least annually, and whenever we make a significant change to how the AI works or what it can do. The date at the top records the last review. This layer of the system is the part we work on most, and this document will change as it does.

Questions about this plan? Write to contact@thinksmith.ca and we will answer.