STEM
EpsilonForge
How do you publish a true statistic without leaking the people in it? Differential privacy adds calibrated noise scaled by epsilon - the privacy budget. Small epsilon: heavy noise, strong privacy, a fuzzy answer. Large epsilon: an accurate answer an attacker can pick apart. Predict the noise scale, the budget after two queries, and whether a differencing attack recovers one person's secret - then turn the epsilon knob and watch privacy and accuracy trade off. It's also why we collect nothing: the safest release is the one you never make. Ages 15-18.
#5b5bd6 Distributed-narrative cast
Meet the cast
EpsilonForge's crew ARE the four ideas behind differential privacy - the cast IS the curriculum, text-forward for ages 15-18 (no illustrations). Laplace is the noise-maker: it answers a count query by adding a draw of scale b = 1/epsilon, so a tight privacy budget forces heavy noise. Budget is the accountant: every query about the same data spends epsilon, and under composition those spends add up - you cannot query for free. Differ is the attacker: it subtracts two answers (count with Alice, count without Alice) to single out one person's secret, and it succeeds only when the noise is far below one (a large epsilon). Redact is the minimalist with the last word: the only perfectly private release is the one you never make. Epsilon, the mentor, turns the one knob and asks the three questions that matter: how private, how accurate, and who could be re-identified? A hands-on model of the privacy-accuracy trade-off that doubles as our own design rationale - Spark and Anvil collects nothing. Deterministic + on-device; only the lab's sample releases use a seeded, reproducible generator.
Laplace
The noise-maker - adds a Laplace draw of scale b = 1/epsilon to a count query; small epsilon means heavy noise
Budget
The accountant - every query spends epsilon, and under sequential composition the spends add up
Differ
The attacker - subtracts count-with-Alice and count-without-Alice to recover one person, but only when the noise is tiny
Redact
The minimalist - the safest release is the one you never make: no data, no epsilon to spend, nothing to leak
Epsilon
(Mentor) Turns the one knob and asks: how private, how accurate, and who could be re-identified?
What's inside
Learning goal
How do you publish a true statistic without leaking the people in it? Differential privacy adds calibrated noise scaled by epsilon - the privacy budget. Small epsilon: heavy noise, strong privacy, a fuzzy answer. Large epsilon: an accurate answer an attacker can pick apart. Predict the noise scale, the budget after two queries, and whether a differencing attack recovers one person's secret - then turn the epsilon knob and watch privacy and accuracy trade off. It's also why we collect nothing: the safest release is the one you never make. Ages 15-18.
Question kits
16 curriculum-aligned kits × 25 questions = 400 questions per app, mapped to recognized standards.
On-device AI mentor
FoundationModels-powered hints, feedback, and adaptive difficulty — all running locally.
Mentored by Epsilon — on-device AI, no data leaves the device.
How EpsilonForge handles your kid's data
- ✅ All progress, settings, and AI-generated content stays on the device
- ✅ No analytics, no tracking, no third-party SDKs
- ✅ No ads, no in-app purchases — you pay once
- ✅ No personal information collected from children — in line with COPPA (updated by the 2026 FTC amendments)
- ✅ Parental controls + session limits + content filters built in
EpsilonForge runs on ForgeKit — the open-source Swift Package Manager framework that powers every Spark & Anvil app. ForgeKit ensures consistent accessibility, COPPA compliance, and design language across the portfolio, so your kid's progress and preferences feel coherent across every app they touch.
Coming to the App Store
EpsilonForge is in active development. Email us to hear when it ships — no marketing, no spam, just a one-shot launch announcement.
Email me at launch