Research
Children's privacy, AI safety for youth, and the policy and design interventions that could make a difference. The following cards are organized by research topic. For full citations of each paper—including the names of my many wonderful collaborators—please see the CV tab.
Active · Core Thread
Children's Privacy in K–12 Education
Empirical HCI research investigating what data is collected about children in K–12 school settings, how EdTech platforms behave relative to their stated privacy practices, and what oversight structures exist and where they fall short. Uses interviews, surveys, and privacy policy audits. Work spans the full ecosystem: teachers, administrators, students, and the technologies they interact with daily.
Empirical HCI
Privacy Auditing
K–12 EdTech
Policy Analysis
Working PaperExploring Data Trusts as a Way to Safeguard K–12 Student Data
Book ChapterOperationalizing the GKC-CI Framework for AI-Powered Plagiarism Detection in K–12 Environments
Under ReviewHigh school students' privacy perceptions of EdTech; K–12 cybersecurity concerns
Active · Core Thread
AI Safety for Youth
Children and youth encounter generative AI across classrooms, social platforms, consumer products, and the home. This thread investigates what they understand about these systems, what risks they face, and what developmentally appropriate safety looks like across those contexts. Includes workshop organization bringing together researchers, designers, educators, and policymakers to co-create frameworks for safe AI experiences for youth.
Generative AI
Youth
Developmental Safety
Qualitative Methods
Workshop
FAccT '26Investigating ChatGPT Usage in High Schools: Student Perspectives on Policy and Practice
Complete
Privacy Policy Automation with LLMs
Investigates whether large language models can automate annotation of privacy policies using the Governing Knowledge Commons and Contextual Integrity (GKC-CI) framework. Demonstrates both the promise and the systematic failure modes of LLM-assisted legal analysis, with implications for privacy auditing at scale.
NLP
LLMs
Contextual Integrity
Privacy Policies
Complete · Google Research
Online Harms & User Vulnerability
Qualitative study of people seeking help during online financial scams, examining the emotional motivations that lead people to engage with scammers, what people need at different stages of a scam, and what contextual factors elevate risk. Conducted during a research internship with Sunny Consolvo at Google. Contributes empirical grounding for the design of in-situ scam interventions.
Mixed Methods
Online Safety
User Studies
Vulnerable Populations
CHI '26"It didn't feel right but I needed a job so desperately": Understanding People's Emotions and Help Needs During Scams
My research sits at the intersection of technology, law, and policy. The questions I study are empirical. I go into schools, talk to students, and audit real systems. The goal is always to produce findings that can change how we design technology and write regulation. If you work on children's online safety, EdTech policy, or AI governance, the work below is directly relevant.
Public Policy Comments
Comment on Children's Online Privacy Protection Rule (COPPA) · FTC Docket FTC-2021-0019
, M.Z. Choksi, M. Chetty · February 2024
Comment on Dark Patterns in Social Media · European Data Protection Board
, M. Chetty, C. Crum, N. Feamster et al. · May 2022
Children's Privacy in K–12 Education
We studied the privacy and security landscape across K–12 public schools and found a consistent picture: data collection is pervasive, oversight is minimal, and most people responsible for protecting student data (teachers, administrators, even IT staff) have little visibility into what is being collected or why. EdTech platforms routinely exceed their stated data practices. Schools lack the technical capacity to audit what vendors actually do.
Why it matters
COPPA and FERPA provide a floor, not a ceiling, and the gap between legal compliance and genuine protection is wide. This work directly informed public comments to the FTC on the COPPA rulemaking and generated significant press coverage focused on education policy.
AI Safety for Youth
From classroom chatbots to consumer AI assistants, children and youth are encountering generative AI across every environment they inhabit. There is remarkably little empirical data on what they think about these systems, how they actually use them, and what harms they experience or anticipate. My current work spans multiple contexts, including qualitative research with high school students on their AI perceptions, and a CHI 2026 workshop that brought together researchers, designers, educators, and policymakers to co-create frameworks for developmentally safe AI across these environments.
Why it matters
Policy decisions about AI and youth are being made largely without young people's input and without empirical grounding. This work provides that voice and that evidence base. Developmentally safe AI requires more than content filters: it requires thoughtful design that accounts for how young people learn, form identity, and understand risk across the full range of their digital lives.
Privacy Policy Automation with LLMs
Regulators and researchers who want to audit whether platforms comply with privacy frameworks face a massive manual burden. Policies are long, technical, and inconsistent. We tested whether large language models could take on this work using a rigorous annotation framework. The short answer: partially, with systematic and predictable failure modes that matter for how you deploy these tools.
Why it matters
For agencies and advocates who want to conduct large-scale privacy audits without large research teams, LLM-assisted annotation is promising, but requires human oversight on specific categories of decisions. The paper details exactly where and why, and is directly applicable to enforcement and compliance work.
Online Harms & User Vulnerability
Online financial scams cause billions of dollars in losses annually, and most incidents go unreported. This research examines what people actually experience when they encounter a scam: the emotional state that led them to engage, what they need in the moment, and where existing support systems (platform tools, law enforcement, peer communities) fall short. The findings point to concrete opportunities for better-designed interventions at each stage of the scam lifecycle.
Why it matters
Scammers' tactics are constantly evolving and targets span all ages, genders, and demographics. Existing support resources are poorly matched to how people actually experience harm in the moment. This work identifies concrete opportunities for in-situ interventions that could help people avoid, diagnose, and recover from scams.