ThinkSmith is a learning platform where children work with an AI coach and AI classmates. This document sets out the risks we have identified, what we do about each of them, and how to reach us.
ThinkSmith is not a crisis line. It is an educational tool. If a child is in immediate danger, call your local emergency services. In Canada, Kids Help Phone is available 24/7 on 1-800-668-6868. In the United States, the 988 Suicide & Crisis Lifeline is available 24/7 on 988.
Children work through challenges built from their provincial or state curriculum. An AI coach, Ms. Rivera, gives feedback on their thinking. Three AI classmates produce solutions the child critiques, and feedback on the child's own work.
There is no messaging between users, no public posting, no feed and no friending. A child cannot contact another child through ThinkSmith, and nothing a child writes is visible to anyone outside their own family and our review team. Most of the risks associated with social platforms do not arise here — the risks that do arise come from the AI itself, and that is what this plan addresses.
| Risk | What we do |
|---|---|
| A child discloses distress, self-harm or abuse while working | Every message is screened before the coach replies. Coaching stops; the child is directed to a human crisis service. Section 4. |
| The AI generates something harmful, even from an innocent question | Every generated response is screened before the child sees it. Flagged responses are discarded, not shown. Section 5. |
| A child believes the AI is a person | The coach and the classmates are identified as AI on screen and beside every name. Section 6. |
| The AI is shaped over time into something it should not be | No cross-session memory or profile is built. Section 7. |
| A child is given advice we are not qualified to give | Medical, legal, psychological and financial advice are blocked categories for the coach. Section 5. |
| Personal information is over-shared in a safety report | Reports are limited to what an authority needs to assess risk. Section 8. |
| Something upsets a child that our screening did not catch | The child can report Ms. Rivera or a classmate in one tap, from the screen they are on. Their parent and our team are told immediately. Section 10. |
Tier 1 — the foundation. Our AI runs on Claude, made by Anthropic. Anthropic's safety systems apply to everything the model produces. This protection is always on and does not depend on us.
Tier 2 — ThinkSmith. The foundation layer cannot know what a good lesson looks like, or what Ms. Rivera is supposed to be. That is our responsibility, and it is where we concentrate our work. Sections 4 to 8 describe it.
Every message a child writes is screened for distress before the coach is allowed to reply. Where the content indicates self-harm or serious distress:
Flags are recorded permanently and cannot be deleted. Each one records who reviewed it, when, what was decided and whether a parent or authority was notified.
Screening what a child writes is not enough on its own. A child can ask something entirely innocent and a model can still produce an answer we would not want shown. So every response is screened independently before it reaches the child — the coach's replies, the classmates' solutions, and the classmates' feedback.
A flagged response is discarded and never displayed. The child sees a neutral message inviting them to try again, and the incident is recorded for our team to review, including what was generated and why it was stopped.
Categories that stop a response: sexual content involving a minor; self-harm; hate; violence; violent extremism; intimate imagery shared without consent; and any claim by the AI to be a human being. For the coach specifically we also stop advice given as though from a licensed professional, anything designed to keep a child engaged against their interest, and content unsuitable for the child's age.
Where something does reach a child, we act within 24 hours. For the most serious categories — content sexualising a child, or intimate images shared without consent — anything reported to us is made inaccessible within 24 hours of the report. In practice ThinkSmith is well placed here: there is no user-posted content on the platform, and AI-generated content that fails screening is discarded before it is ever displayed, so removal is immediate rather than a race against a deadline.
Why the AI classmates are held to a different standard. They are designed to make mistakes. The whole point of the activity is that a child reads a flawed solution and works out what is wrong with it. So a classmate being incorrect, hesitant or muddled is the product working, not a failure — and we do not stop a response for it. We stop a classmate only on the categories above, where the harm has nothing to do with being wrong.
Ms. Rivera has a human name and speaks warmly. The classmates write like children, including hesitantly and imperfectly. A child could reasonably mistake either for a person, so we say plainly that they are not:
Ms. Rivera has no memory of your child across their work. Within a single challenge she can see the last few exchanges about that one piece of work, so her coaching follows the conversation. Nothing carries between challenges.
She builds no profile, forms no impression over time, and cannot be gradually shaped by one child into something she is not. When a child submits the same work again, she reviews it fresh rather than judging them for asking twice.
She also works to fixed teaching rules — she guides thinking rather than supplying answers, and those rules are the same for every child, every time.
Where a report to a child-protection authority is required, we share only what an authority needs to assess immediate risk and contact a parent:
We do not include a home address, date of birth, telephone number, location data or billing details in a safety report.
In rare cases where notifying a parent could itself place a child at risk — for example where the concern involves the household — we do not notify the parent, and the matter goes to the authority directly.
Learner records are held in Canada. We do not sell or share family information, and we show no advertising.
Conversations between a child and the coach are retained and read by ThinkSmith team members as part of ongoing quality and safety checks. Parents are told this before their child begins.
Three separate review queues exist, because they need different kinds of attention. Child-safeguarding flags are reviewed for urgency — a possible risk to a child needs a person quickly. Flagged AI responses are reviewed for pattern — whether our screening is calibrated correctly, and whether it is stopping things it should not. Reports raised by children themselves are reviewed as what they are: a child telling us directly that something bothered them, which is not a machine's guess and is not a calibration question. Each review records who carried it out and when.
Keeping them apart is deliberate. A child's disclosure must never be buried among routine notes about whether our filters are tuned correctly.
Where a safeguarding concern arises, we also record whether a guardian was informed, by whom, and when — and where the decision was not to inform them, that is recorded too. Both belong in the record: as section 8 sets out, there are situations where telling a parent would put a child at greater risk, and a decision of that weight should not rest on someone's memory of a phone call.
A child can report something themselves, in one tap. Wherever Ms. Rivera speaks there is a Report AI Coach to Parent link, and beside each classmate's work a Report Peer to Parent link. A child does not have to explain why, or write anything at all — pressing it is enough. Nothing is locked, paused or taken away because they used it.
When they do, their parent is emailed straight away with exactly what their child was looking at — Ms. Rivera's words, or the classmate's — together with anything the child chose to write. Our team receives the report at the same moment. The child sees a confirmation telling them plainly that their parent will see it, so nothing happens behind their back.
What we do about it is our job, not the parent's. A parent cannot correct Ms. Rivera, and we do not think they should have to try. If our AI said something it should not have, we fix it — and someone from ThinkSmith gets in touch to say what we found.
If a child's own words suggest they are struggling rather than simply uncomfortable, the crisis line for their region is shown to them immediately, and our team is alerted as urgent.
A parent can raise a concern at any time by emailing contact@thinksmith.ca. We acknowledge every report and tell you what we have done about it.
If a child is in immediate danger, contact emergency services first. We are not a crisis service and cannot respond immediately.
If you are not satisfied with how we have handled a report, you can escalate it to the Digital Safety Commission of Canada, which is independent of ThinkSmith and can require us to act.
We review this plan at least annually, and whenever we make a significant change to how the AI works or what it can do. The date at the top records the last review. This layer of the system is the part we work on most, and this document will change as it does.
Questions about this plan? Write to contact@thinksmith.ca and we will answer.