Part of the Privacy & AI lesson guide. Teaching a different grade? 🌈 Explorer (5–7) · 💻 Hacker (11–14) · ⚡ Architect (15–18)
This age band can handle a slightly more pointed opening than Explorer's reassurance-first tone — curiosity and a bit of healthy suspicion work well here.
"Raise your hand if you or your family has a phone at home. [Most hands go up.] Okay — keep your hand up if you think that phone knows more about you than your best friend does. [Pause for reactions.] I'm serious. Let's find out what it actually knows."
Follow with the app's own hook line for this age band, said aloud: "Your phone tracks your location. Apps analyze your photos and messages. What does AI know about you? More than you think." Let that sit for a second before moving into the activity — this age group responds well to a slightly unsettling true fact, as long as it's followed quickly by "and here's what you can actually do about it," so don't linger too long on the mystery before pivoting to something actionable.
It's worth being direct with this age group about the goal of the lesson: this isn't about scaring anyone away from technology they use every day, and it isn't about memorizing rules to recite. It's about noticing something that's mostly invisible by design — most apps aren't built to make you think about what they collect — and building the habit of checking on purpose instead of clicking "allow" automatically.
Quick warm-up: ask students to guess, out loud, how many times a day they think their family's phone checks its own location. Take a few guesses (answers will range wildly), then reveal: "Believe it or not, it can happen hundreds of times a day — way more than any of your guesses, probably." This sets up Scene 1 nicely.
Walk through the app's three scenes as a guided discussion before students go through it themselves on-device — What AI Knows, How Data Spreads, and Protect Yourself.
Go through each item and ask students to guess "AI or not AI?" before revealing: Location Data (AI — logs your phone's position hundreds of times a day to build a picture of everywhere you go), Voice Data (AI — smart speakers record and analyze voice commands, and some companies keep those recordings for a long time), Face Data (AI — facial recognition can identify people in a crowd and even estimate mood), and then the contrast: Paper Diary (not AI — no cloud, no servers, no data collection, just paper).
A good follow-up question after all four: "Notice that three of these four things happen automatically, in the background, without you doing anything extra — you just carry your phone, or talk near a speaker. Does that change how you feel about them, compared to something like typing your name into a form?" This age band is old enough to start noticing the difference between data they actively hand over and data that's collected passively just by existing near a device — a distinction that matters a great deal in how privacy actually works.
Expected response: students are usually most surprised by voice data retention ("wait, they KEEP it?") — that's a good moment to pause and ask "why do you think a company might want to keep old voice recordings?" (expected answer, with prompting: to improve their AI, or sometimes just because deleting things costs effort and there's no rule forcing them to).
Introduce this scene with a direct question: "If an app is free, how does the company that made it make money?" Let students guess before confirming: often, by collecting data about what you do and selling access to advertisers, or selling the data itself to companies called data brokers. Cover App Permissions (a flashlight app asking for your contacts and location is a red flag — it doesn't need either to shine a light), Tracking Cookies (small files that follow you across websites building a profile of your interests), and Data Brokers (real companies whose whole business is buying and selling personal data profiles — the lesson notes there are thousands of these operating, mostly invisible to the people whose data they hold). Contrast with Postal Mail — a letter goes straight from sender to receiver, no third party reading or selling anything about it.
This is the most actionable scene — spend real time here. Cover: Strong Passwords (unique, long password per account — a password manager helps, but the core habit is "don't reuse the same password everywhere"), Privacy Settings (actually check what permissions an app has — "does a flashlight app really need your location and contacts?" is the lesson's own sharp example, and it's worth repeating verbatim, it lands well), Encryption (end-to-end encryption scrambles messages so only the sender and receiver can read them — even the company running the app can't read them), and Say No (you're allowed to decline permissions, delete cookies, and opt out — "your data, your choice").
Spend an extra minute on why reusing passwords is specifically risky, since this age band can understand the mechanism, not just the rule: if one website or app gets hacked and its password list leaks, anyone who reused that same password on other accounts is now vulnerable everywhere they reused it — not just on the site that got hacked. This is why "one strong password for everything" is actually one of the riskiest habits, even though it feels convenient. A password manager solves the real problem this creates (remembering many different passwords) without needing anyone to actually memorize dozens of them.
On encryption, a simple demonstration works well here without needing any real cryptography: write a short message on the board, then show a "scrambled" version of it (shift every letter forward by a fixed number, a basic substitution). Ask, "if someone intercepted this scrambled version without knowing the trick, could they read it?" Point out that real encryption is vastly more complex and secure than a simple letter shift, but the core idea is the same: turn a readable message into something unreadable to anyone without the right key, and only unscramble it for the intended reader.
After the group walkthrough, hand out devices and let students complete the lesson individually. Circulate and ask "what's one setting you could check on your own family's phone tonight?" — this age band responds well to a concrete take-home task tied directly to what they just learned.
A useful mid-activity moment: ask the class to guess how many apps might be installed on a typical family phone, then ask "if even half of those apps collect some data, how many little pieces of information about your family do you think exist somewhere on a server right now?" There's no exact number to land on — the point is helping students feel the scale of this, which a single example app can't convey on its own. Follow with reassurance: "That number feels big, and it should feel a little surprising — but it doesn't mean anything bad is happening to you specifically. It means this is a habit worth building now: checking, asking, and deciding on purpose, instead of just clicking 'allow' out of habit."
Push a little on the "so what" of each answer at this age — not just "companies collect data" but "why does that matter, specifically, for me or my family?" The privacy-policy question tends to generate a genuinely good discussion at this age, since most students have clicked "I agree" on something without reading it, and naming that honestly (without shame) opens the door to talking about why that's such a common, almost universal habit rather than a personal failing.
This age band uses its own quiz override, distinct from the base lesson, with slightly reordered options — walk through the reasoning, not just the letter.
Close with the lesson's own summary line: "AI collects location, voice, face, and browsing data — often without clear consent. Protect yourself by managing permissions and understanding data collection." Add: "None of this means you should be scared of your phone — it means you get to be the one deciding what it knows, instead of just going along with whatever the default settings are."
Extension activity: With a parent or guardian's help at home (frame this clearly as a family activity, not something to do alone), have students check the permissions list of three apps on a shared family device and write down one thing that surprised them — an app that asks for more access than they'd expect, or one that asks for less. Bring findings back to share as a "permission audit" the next class period.
If you have more time in the same session, run a quick classroom debate: split the class into two sides and have them argue "Is it fair for a free app to collect data to pay for itself?" — one side defends the free-app-for-data trade, the other argues it should be more limited or better disclosed. This age band engages well with structured debate, and there's no single right answer here — the goal is practicing the reasoning, not reaching a verdict.
A smaller optional add-on if the class finishes early: have students design, on paper, an imaginary "privacy label" for one app they use — like a nutrition label, but for data instead of calories. What three things would it have to list honestly (e.g., "collects: location, contacts, browsing history")? This is a real idea some app stores have started experimenting with in practice, so it's a nice bridge between a classroom exercise and something genuinely happening in the industry right now.