Lanternhow it decides

How Lantern decides

Every video gets read before your child ever sees it. The first reader looks at the title, the channel, and the words the video uses about itself. That reading is fast. It covers everything. A second reader then watches the video itself. It sees the pictures. It hears the words. It checks whether the video is really what its title claimed. Watching costs money. So it runs in the order your child is most likely to see next. Videos already on your child's page get watched first. If the second reader finds something the first one missed, the video comes off every page it is on. You are told why. You can open the wall yourself, any time, and see what made it through. Your report card shows how many of your child's videos have been watched. Want that number to climb faster? Add your own Gemini key in settings. Your child's page then moves to the front of the line.

What the reader finds becomes fourteen small scores. Each one covers a different thing. It might be how scary a video feels, or how loud and busy it is. You set the highest number allowed on each dial. You do this when you set up your child's page. Evening hours can carry a stricter number than daytime. A video above your number on even one dial gets dropped. It does not matter how good the rest of it looks. When a reader cannot tell what a video carries, that dial counts as unsafe. It never counts as safe by default.

The path of a video A video is read, scored on each dial, and either reaches the wall or is dropped for going over a ceiling. Video Reader Dial scores Your child's wall Above a ceiling: dropped
A video is read, scored on each dial, and either reaches the wall or is dropped for going over a ceiling.

You do not need to learn all fourteen names. You can write, in your own words, what worries you about what your child watches. Lantern turns that into the right numbers on the right dials. More than one reader looks at anything that matters. Those readers come from different companies. So one reader's blind spot is never the only opinion your child's page gets. When readers disagree, the video does not quietly slip through. It waits for a person to look at it instead.

One dial, one ceiling A dial with a ceiling line. A score under the ceiling is a filled dot and passes. A score over the ceiling is an outlined, slashed dot and is blocked. ceiling passes blocked
A score under the ceiling is a filled dot and passes. A score over the ceiling is an outlined, slashed dot and is blocked.

Right now, the readers are general-purpose thinkers. We ask them to act like a careful babysitter. The next version is a reader trained just for this job. It will be small enough to run on your own computer. It will be able to grow the way your child grows. It can tighten or loosen as they get older. It will not stay fixed at the day you set it up. Nothing about that reader is finished yet. Nothing here is a promise of when it arrives. We are building it this way for a reason. You should be able to see every dial. You should be able to move it, too, instead of trusting a machine to already know best. Read why in the Primer problem. Or keep reading below for the long version, with its sources.


The rest of this page is the version we wrote for someone who wants to check our sources.

For the curious: the long version

This is the referenced version of Lantern's method, written for a reader who wants to check the sources. Every claim here links to something you can open. Receipts for each link, including the date it was fetched, are in _SOURCES.md.

1. What a dial is

A dial is a rating from 0 to 10 that describes one property of one video. Zero means the property is absent from the video. Ten means the property is extreme for a children's media context, not extreme for media in general. A horror film and the most menacing thing that plausibly reaches a child's feed both sit at the top of it.

The ratings are produced by language models reading what the platform publishes about a video: title, channel, description, tags, duration, and a transcript where the platform provides one. Lantern does not download video files.

A second tier watches. Google's Gemini accepts a public YouTube URL as an input and ingests the video on its own servers, so the model observes frames and audio directly: what is depicted, what is said, the cut rate, the loudness range, and whether the video's own metadata described it honestly. Only the public URL leaves Lantern. No frame, no audio track and no downloaded file ever reaches a Lantern machine, which is what keeps this tier inside the metadata-only ceiling the platform's terms impose. Watching costs a great deal more than reading, so videos already on a child's shelf are watched first. Where the two readings disagree, the watched one wins, and a video the watcher refuses comes off every shelf.

Each child has ceilings, one per dial, and evening ceilings may be stricter than daytime ceilings. A shelf is built by taking candidate videos and removing every video whose rating on any dial sits above that child's ceiling for that dial.

The failure direction is deliberate and it is the part worth checking. Where several readers disagree, the strictest reading is the one that gates. Where a rating is missing or cannot be read, the video is not treated as a zero on that dial; unknown is not safe. Readers are instructed to report low confidence rather than score an unobserved property as absent. This matters because the metadata is adversarial in the specific sense Papadamou and colleagues measured: inappropriate content aimed at young children mimics or is derived from content that is appropriate for them, and a child browsing from a benign starting point is likely to reach it.

2. Where the fourteen axes came from

The seed was Common Sense Media's public rating rubric, which is the closest production system to what Lantern needed: nine content categories, each rated 0 to 5 dots, plus an ease of play assessment for games. Lantern departs from it in three ways. The scale is 0 to 10 rather than 0 to 5, because ceilings need finer resolution than review dots. Violence and scariness are separate axes rather than one combined category. And the set is sized to what a reader can actually judge from published metadata.

Each axis had to earn its place against primary literature. The reading is listed under References.

AxisWhat it rates
scarinessthreat, menace, dread, horror imagery
sensory_loadpacing, loudness, busyness, and density of impossible events
consumerismproduct, brand and purchase pushing
violence_intensityamount, graphicness and realism of violence, and whether it is rewarded
language_profanityprofanity, slurs, insults, trash talk
sexual_romantic_contentinnuendo, sexualised framing, explicit reference
substance_usealcohol, vaping and drugs, weighted by glamorisation rather than presence
risk_imitationcopyable dangerous stunts and challenges
parasocial_influencer_pressurehost bonding used to persuade, including sponsored selling
sleep_disruptionarousal against wind-down, the evening question
misinformation_pseudosciencefalse or pseudo-authoritative claims presented as fact
body_image_pressureappearance ideals, diet talk, ranking by looks
prosocial_modelingkindness, cooperation and empathy modelled
educational_valuesubstantive intentional teaching

Two of these carry an explicit evidence caveat. The body image literature was collected mostly in adolescent and adult female samples, so it is extrapolated downward with caution. The misinformation axis rests on policy language about inaccurate and unsafe content rather than on a per-video effect study.

3. How the readers are kept honest

Three rules, stated as what they achieve rather than how they are built.

Several readers from different model families look at anything that matters, and a concern any one of them raises is kept rather than voted away. Where they disagree sharply, the video goes to a person rather than to a shelf.

Models are scored against a hand-labelled exam under a false-safe veto: a model that passes something it should have caught is disqualified, whatever its average accuracy looks like. That is why Lantern is several independent readers with a person at the disagreement points, and not a single model with a good average.

Human ratings are interleaved throughout, and a parent's rulings on their own shelf are recorded.

Lantern also reads the public comments under a video and looks for parents saying something went wrong, and it shows you what it found on the why page. A comment never blocks a video by itself.

4. The hosted alpha, in one paragraph

Each family is a separate tenant with its own database. A new family starts with hand-curated preset shelves, and every preset item is still passed through that family's own dial ceilings before it can reach a child's wall. Families that go beyond the presets bring their own API keys, so screening runs on the family's own quota and the operator holds no shared corpus. What crosses out of a family is stated on the settings page in these words: "Once a day, one thing leaves your family: yesterday's totals. How many times each video was played and finished across all families, and which sources those videos came from. The totals carry no name, no child, no time of day and nothing that points back to you, and a video's count is only ever shown once at least three different families have watched it. It is how we work out which sources are worth screening more of. Nothing else about your family leaves." The same paragraph appears in four places in the product and a build check fails if the four ever drift apart.

When a family adds its own Gemini key, what it buys is pooled the same way: "When you add your own Gemini key, the screening and the watching it pays for join the shared library that every Lantern family draws from. What joins is the video and what the reader found about it. Never your child, and never what your child watched." That sentence appears in four places in the product and the how page, and the same build check holds all five to it.

5. Limits

The evidence base is one family. Every number Lantern has produced about a real child's viewing is one child's diet under Lantern's own labels, and it is not a population claim.

The labels are machine-generated and are not clinically validated. There is no institutional review, and inter-rater reliability against a second human annotator has not been computed. Pacing figures are a model's estimate made while watching, not the output of a deterministic shot detector.

Published metadata is the ceiling, not a temporary gap. The platform's developer policies require stored data to be refreshed or deleted within thirty days and restrict derived data, so Lantern refreshes and purges on that cycle and does not download video or scrape transcripts. Some properties, notably visual pacing and loudness, are therefore judged from proxies.

The literature behind the axes is largely television and social media research carried into short-form video. Direction transfers well. Magnitudes should not be assumed to.

6. What is next

The current readers are general-purpose models asked to behave like children's media raters. A reader trained for this job is the direction of work, with no results to report yet.

7. Why any of this

The argument underneath the product is in The Primer problem: owning a machine you cannot drive is not really owning it. Parents nominally control what their children watch, but the controls belong to someone else, they are coarse, and they do not explain themselves. Dials a parent sets, on a shelf a parent can inspect, with the reasoning printed, is the same argument applied to one household screen.

8. My list

Your child can save videos to their own list. They tap "+ Add to my list" on any video, and it stays there. The list now survives closing the app, and it looks the same on a second tablet opened with the same link.

The list only ever holds videos that already passed screening for your child. If a video later comes off their shelf, it comes off the list too.

Nothing about the list leaves your family. It is kept with your family's own files, next to everything else Lantern holds for you. What leaves your family once a day is unchanged: yesterday's totals, and nothing about which videos your child saved.

What would change it: excluding a video in your review queue takes it off your child's list that same night.

References

Written 2026-08-29, revised 2026-09-02. Updated whenever the method changes.

Guardian home · Settings · Try the demo shelf