Field notes / 2020 · Family Link · Transparency by design
The child is watching too
A supervision product can feel like surveillance from the inside. The work that mattered most was making the kid’s side of it honest — and not spending their battery to reassure their parent.
Live question
How do you make a child feel watched-over rather than watched — when the same data reassures a parent and exposes a kid?
There’s a principle I keep returning to: we are constantly balancing the privacy of the child against the expectations of the parent. Those are not the same person, and they do not want the same thing. A parent wants to see; a child wants to be a person, not a feed. The product sits exactly on that seam, and the easy version of it (show the parent everything, all the time) is the version that turns a safety tool into surveillance and quietly teaches a kid that being watched is the price of having a device.
So I’ve been treating the child’s side of the experience as a thing we owe honesty to, not an afterthought. Supervision is never silent: there’s a persistent notification on the supervised device telling the kid, in their own words, that this is on. When supervision ends — when a kid ages out or a parent lifts it — the device tears it down through the same channel that enforced it, so the moment they’re free, the device behaves free. The kid should never have to wonder whether they’re still being watched. The answer should be visible on the device they’re holding.
This year the question got concrete in a place I didn’t expect: battery. Parents kept seeing stale data, location and app activity hours behind, and the naive fix is to make the child’s device upload everything, constantly. That would work. It would also burn a kid’s battery and bandwidth all day so a parent could have a fresher dashboard they glance at twice. I find that objectionable, and not only as engineering.
The cheapest way to reassure a parent is to quietly tax the kid’s device. That’s exactly why we shouldn’t.
So the orchestration we built computes fresh data on the child’s device only when a parent is looking — a request triggers an on-demand refresh, and only if what we have is already stale. No one is watching, nothing runs. Latency becomes a contract, a freshness target per data type, instead of an accident, and the child’s resources get spent only when there is a real person on the other end with a real reason. ‘Be not wasteful with our user’s resources’ sounds like a performance note. Here it is a statement about whose comfort gets to cost whose battery.
The honesty cuts the other way too. When we measured how often we could even reach a child’s device in real time, the truthful number was nowhere near perfect, and the temptation was to paper over it. Instead we changed the parent-facing UI to set the expectation, to admit that ‘live’ has a ceiling, rather than show a confident green dot we couldn’t stand behind. A reassurance the system can’t honor is worse than an honest gap, because the day it fails is the day a parent stops believing anything we tell them.
What I haven’t resolved is the asymmetry underneath all of it — the parent gets transparency by design, and the child mostly gets to know they’re seen, not to negotiate what’s seen. I can make supervision visible. I’m far less sure I’ve made it dignified, and I don’t think a notification, however honest, fully closes that gap.