How Do We Make Privacy Work for the Sandwich Generation?
A Community Hub Lab for Private, Portable, Multi-Actor AI
Summary of Proposal
The sandwich generation coordinates sensitive data across children, aging parents, healthcare, finance, schools, families and institutions. This hub uses caregiving as a real-world stress test for privacy, identity and delegation, inviting builders and people of all ages to co-design private, portable, user-controlled patterns for multi-actor AI systems together at Devcon.
Motivation and Rationale
How do we make privacy work for people who are already too overloaded to become privacy experts?
The sandwich generation gives us an unusually powerful environment in which to investigate that question.
Caregiving increasingly requires one person to coordinate information and responsibility across multiple generations, institutions, systems and relationships. Someone may manage a child’s education and healthcare information, coordinate an aging parent’s appointments and medications, share responsibilities with siblings or partners, communicate with clinicians, interact with financial institutions, and still manage their own work, health and household.
Much of this work is invisible labor. It is not simply the act of providing care, but the constant administrative work of finding information, remembering context, coordinating people, navigating institutions, repeating the same information across fragmented systems, and making sure the right thing happens at the right time. This burden is not distributed evenly. People with financial resources can sometimes outsource portions of it to paid caregivers, household support, professional advocates, private services, or better technology. Those without those resources are often left carrying more of the coordination themselves, with less time, less leverage, and fewer alternatives.
That makes this not only a technology problem, but also a question of power, access and digital rights.
As AI becomes an increasingly tempting answer to this overload, the people who most need assistance may also be the people least able to scrutinize the privacy tradeoffs attached to that assistance. A caregiver trying to solve an urgent problem should not have to choose between getting help and surrendering an entire family’s health, financial, behavioral, or relational data to a system they cannot meaningfully inspect or control.
We want to explore a future in which technological assistance does not require that bargain.
The goal should not be to teach every exhausted caregiver how to become a privacy engineer. It should be to build systems where privacy, minimization, consent, portability and revocation are designed into the infrastructure from the beginning, so that the safest choice can also be the easiest choice.
This is not simply a large-data problem. It is a multi-actor privacy problem.
Who should know what? Who can act for whom? Who granted that authority? What happens when a child becomes an adult, a parent loses or regains capacity, a caregiver changes, a relationship ends, or an AI agent begins participating in the system?
Family caregiving is particularly valuable as a stress test because responsibilities, authority, context and information evolve among care recipients, families, clinicians, organizations and other trusted participants. It also brings together children, older adults, people with disabilities and people whose decision-making capacity may change over time.
But this Hub is not only about caregivers.
Every person is potentially part of one of these systems. We are children, parents, partners, siblings, friends, patients, professionals, caregivers, care recipients, delegates and eventually older adults ourselves.
The problems exposed by the sandwich generation therefore become a useful lens for something much larger:
How should privacy work when AI stops interacting with one isolated user and begins participating in long-lived human systems involving many people?
Today’s AI systems are still largely designed around individual interactions, relatively stable users and permissions, and isolated requests. Those assumptions become much harder to maintain when context, authority and privacy boundaries change continuously.
Why Devcon?
This is fundamentally a privacy, identity, authorization and user-sovereignty problem.
Ethereum and adjacent open-source communities have spent years developing technologies and philosophies that may provide pieces of the solution.
Decentralized Identifiers can support identity that is not dependent on a conventional centralized identity provider. Verifiable Credentials can make claims portable and independently verifiable. Zero-knowledge technologies create opportunities to prove something without unnecessarily revealing the underlying information. Smart accounts and programmable authorization create new possibilities for limiting what another person, application, or agent is permitted to do.
But the existence of these primitives does not mean we have solved the human problem.
The Devcon community is uniquely poised to wade through such questions as:
What does decentralized identity look like inside a family? What happens when authority is shared? Can someone prove that they are authorized to schedule an appointment without revealing an entire health record? Could a caregiver prove a relationship or delegated responsibility without exposing unnecessary identity information? What would a portable personal data wallet look like if identity, permissions, credentials and context could move with a person while highly sensitive underlying information remained private? Can access be granted for one purpose, to one person, for one period of time? Can that authority be modified or revoked as life changes? Can an AI agent receive enough context to complete a task without receiving someone’s entire personal history?
And critically: can we make these protections usable by the people who have the least time, money, energy, or technical expertise to manage them manually?
The Community Hub RFP explicitly welcomes privacy researchers, civil-liberties defenders, public-interest technologists, and people building resilient communities and essential systems - these are our people!
Why a Community Hub Rather Than a Talk?
There is no single answer to these questions, and we do not want to present one.
The Hub would operate as a four-day participatory research environment.
A zero-knowledge researcher might approach a caregiving scenario through selective disclosure.
An identity builder might consider credentials and delegation.
A wallet developer might approach it through programmable authorization.
A security researcher might immediately identify attack surfaces.
A civil-liberties advocate might ask who benefits from a particular architecture and who becomes vulnerable when it fails.
A parent, caregiver, teenager, or older adult may identify an assumption in all of those solutions that does not survive contact with real life.
That interaction is the point.
Participants should be able to walk into the Hub for ten minutes, contribute to a scenario or privacy map, leave, return the next day and see how the community’s thinking has evolved.
The Hub becomes both a learning environment and a community research project, one that asks not only what can we build?, but who does it serve, who bears the risk, and what protections should exist before these systems become unavoidable parts of everyday life?
Supporting Builders
Our goal is to help builders move from:
“We support privacy.”
to:
“Here is how privacy actually behaves when five humans, three institutions and two AI agents have different rights to the same evolving context.”
Caregiving makes abstract privacy questions concrete.
It also forces us to confront something easy to miss when designing for idealized users: privacy failures are not experienced equally. The person with the least time and fewest alternatives may be the one most pressured to accept invasive technology simply because it solves an immediate need.
We want builders to consider that reality before these systems become entrenched.
By the end of Devcon, we want participants to leave with scenarios, threat models, design patterns, privacy principles and unresolved questions they can take back into their own work.
The broader hypothesis is that caregiving exposes problems that will eventually appear across healthcare, education, finance, workplaces and other persistent human systems where AI must coordinate people rather than simply answer prompts.
If we can develop privacy patterns that protect people in one of the hardest, most emotionally charged and resource-constrained multi-actor environments in human life, those patterns may help us build more ethical systems for everyone.
Implementation
The physical space itself should function as an interactive research instrument rather than simply a place to watch presentations.
The Sandwich
The centerpiece would be a large visual representation of a fictional multi-generational family and care network.
At the center is the overloaded coordinator.
Around that person are: Children, Teenagers, Aging parents, Partners, Siblings, Friends, Clinicians, Schools, Employers, Financial institutions, Government services, Community organizations, AI agents etc…
Participants add pieces of information, responsibilities and relationships to the system.
Then we ask: Who should have access? What can they do? For what purpose? For how long? What should they be able to prove without revealing the underlying information? What changes when the relationship changes?
The installation becomes increasingly complex throughout Devcon, visually demonstrating why privacy in multi-actor systems cannot be reduced to a binary permission switch.
Privacy Primitive Wall
A second wall maps human requirements against potential technical approaches. For example:
Need: Prove a relationship Explore: Decentralized identity, credentials, attestations
Need: Prove eligibility without revealing underlying data Explore: Zero-knowledge proofs
Need: Delegate limited authority Explore: Smart accounts, scoped authorization, cryptographic delegation
Need: Carry identity and permissions between services Explore: Portable credentials and user-controlled identity
Need: Remove access when relationships change Explore: Revocation and credential lifecycle approaches
The purpose is not to promote any technology as the answer. It is to identify which existing primitives may help and where technical gaps remain.
Portable Data Wallet Exercise
Participants explore the idea of a portable personal data and identity layer.
Rather than asking:
“How do we put someone’s life onchain?”
we ask:
“What minimum information, proofs, credentials or permissions need to travel so that the person can remain in control across systems?”
This allows discussion of a future in which sensitive data remains distributed or user-controlled while cryptographic identity, authorization and proofs enable trusted interactions.
Threat Modeling Station
Participants attempt to break hypothetical systems through: Excessive permissions, Stale consent, Relationship changes, Lost credentials, Compromised AI agents, Malicious or coercive family member, Conflicting authority, Inference attacks, Incapacity, Death, Emergency access, Credential recovery, Unauthorized secondary use of data
Production Requirements
We can use most of the equipment Devcon already provides.
Additional materials would likely include: Large printed scenario boards, Relationship and identity cards, Permission cards, Sticky notes, Markers, Voting dots, removable tape or string, Printed threat-modeling templates, Large-format technical diagrams, Paper prototyping materials
Sample Four-Day Programming
Daily Rhythm
Morning Lean Coffee | 09:00–10:00
Each day opens with an agenda-less, participant-driven Lean Coffee. Attendees add questions, provocations, lived experiences, and technical challenges to a shared board, vote on what feels most important, and discuss the highest-priority topics. Questions that cannot be addressed remain visible throughout the day and can influence workshops, contributor sessions, and later programming.
Open Question Board | All Day
Participants can continuously add new questions, challenge assumptions, or respond to themes emerging from the Hub.
Closing Lean Coffee + Synthesis | 17:00–18:00
Each day closes by returning to the community question board. Participants discuss newly surfaced questions, capture key learnings and disagreements, and identify themes worth carrying into the following day. On Day 4, this becomes the basis for the Hub’s shared research outputs.
Day 1 | Who Are You in Someone Else’s System?
| Time | Programming |
|---|---|
| 09:00–10:00 | Morning Lean Coffee + introduce The Sandwich multi-generational data map |
| 10:00–12:15 | Who Gets to Know What? + Identity Beyond One User, One Account |
| 12:15–13:30 | Open Hub, networking, and ongoing mapping |
| 13:30–17:00 | Portable Identity, Portable Data + Privacy Primitive Lab + open contributor sessions |
| 17:00–18:00 | Closing Lean Coffee + Daily Synthesis |
Day question: What needs to be known, proven, or carried with us as we move through different relationships and systems?
Day 2 | Who Gets Access?
| Time | Programming |
|---|---|
| 09:00–10:00 | Morning Lean Coffee + Permission Wall |
| 10:00–12:15 | Can You Prove It Without Revealing It? + The Multi-Party Data Problem |
| 12:15–13:30 | Open Hub and community research |
| 13:30–17:00 | Privacy Should Not Require a Privacy Expert + Caregiving Privacy Threat Model + Builder Clinic |
| 17:00–18:00 | Closing Lean Coffee + Daily Synthesis |
Day question: How do we provide the right access without exposing more information than a person, institution, or AI actually needs?
Day 3 | Who Gets to Act?
| Time | Programming |
|---|---|
| 09:00–10:00 | Morning Lean Coffee + Delegation Challenge: Would You Let an AI Do This? |
| 10:00–12:15 | Delegated Authority + Smart Accounts and Programmable Authorization |
| 12:15–13:30 | Open Hub and community research |
| 13:30–17:00 | Consent Has a Lifecycle + Agent Security Red Team + Recovery, Incapacity & Emergency Access |
| 17:00–18:00 | Closing Lean Coffee + Daily Synthesis |
Day question: How should authority be granted, constrained, transferred, expired, and revoked as people and circumstances change?
Day 4 | What Should We Build?
| Time | Programming |
|---|---|
| 09:00–10:00 | Morning Lean Coffee + review what The Sandwich has become over four days |
| 10:00–12:30 | What Existing Technology Already Solves + What Is Still Missing? |
| 12:30–13:30 | Open Hub and community review |
| 13:30–17:00 | Multi-Actor Privacy Framework Workshop + From Caregiving Problems to Protocol Problems + open synthesis |
| 17:00–18:00 | Final Lean Coffee + Community Synthesis & Publication Plan |
Day question: What privacy principles, technical primitives, threat models, and open questions should the community carry forward after Devcon?
Why Lean Coffee?
Lean Coffee gives the Hub a mechanism for remaining genuinely community-led rather than locking four days of discussion into an agenda designed before Devcon begins.
The organizing team will provide structure, scenarios, facilitation, and technical starting points, but participants will continuously influence what receives deeper attention. Questions raised by caregivers may reshape a technical workshop. A security concern surfaced during a builder session may become the next morning’s highest-voted topic. An unresolved identity problem may remain on the board across several days.
The program therefore has a clear structure without becoming rigid, allowing the Hub to respond quickly to the expertise, lived experience, and curiosity of the people who actually show up.
Community Outputs
A major objective of the Hub would be to ensure that the work continues after Devcon.
Rather than disappearing when the physical Hub closes, community contributions would be synthesized into openly available resources.
1. Multi-Actor Privacy Framework
A set of community-developed principles covering: Identity, Context, Delegation, Consent, Selective disclosure, Data minimization, Revocation, Recovery, Human oversight, Multi-party information, Agent authority, etc…
2. Privacy Primitive Matrix
A living map connecting human requirements to existing technical approaches, including decentralized identity, Verifiable Credentials, zero-knowledge proofs, programmable accounts and other privacy technologies.
The matrix should also explicitly document areas where existing technologies are insufficient.
3. Delegation and Revocation Pattern Library
Reusable scenarios demonstrating how authority changes through real life.
Examples might include: Parent and young child, Parent and teenager, Adult child and aging parent, Shared caregiving among siblings, Temporary caregiver, Clinician relationship, Emergency access, AI agent acting with limited authority, Incapacity, Death, Relationship termination etc…
4. Portable Identity and Data Map
A community exploration of what a user-controlled portable identity or personal data wallet could actually mean.
The framework would distinguish among: Raw personal data (self-reported to 3rd party integrated), Credentials, Claims, Permissions, Proofs, Relationships, Context, Keys, Audit information etc…
The goal is to explore how people can move between systems while minimizing unnecessary movement or duplication of sensitive information.
5. Multi-Actor AI Threat Model
An open threat-modeling resource based on the scenarios explored during Devcon.
All outputs would remain neutral and project-independent so that builders across the ecosystem can continue contributing after Devcon.
Alignment With Ethereum’s Core Properties and Open-Source Ethos
Privacy
Privacy is not an optional feature of this Hub. It is the central question.
Ethereum’s own privacy resources increasingly emphasize proving information without revealing unnecessary underlying data.
The Hub asks how those principles extend beyond transactions into human relationships and AI-mediated coordination.
Security
Giving software authority to act introduces new security boundaries.
The Hub explicitly explores permission scope, compromised actors, revocation, recovery, delegation and inappropriate information disclosure.
Censorship Resistance and User Sovereignty
A core question is whether individuals can retain meaningful control over their identity, information and relationships as more services become mediated by AI and owned by data brokers that currently extract.
Open Source
The Hub is designed to produce reusable public knowledge rather than proprietary research.
The frameworks, scenarios and threat models emerging from the Hub will be openly available for continued community development.
Community Bridge-Building
This topic intentionally connects communities that often approach the same problem from different directions:
Privacy researchers meet caregivers.
Cryptographers meet designers.
Wallet developers meet AI researchers.
Identity builders meet people navigating real multi-generational systems.
And every participant can contribute regardless of whether they write Solidity, design interfaces, care for a parent, raise a child or simply care about retaining control of their digital life.
Audience
The Hub is designed for both technical and nontechnical Devcon participants.
We particularly hope to engage: Privacy researchers, Ethereum developers, Zero-knowledge researchers, Identity builders, Wallet developers, AI and autonomous-agent builders, Security researchers, Product and UX designers, Digital-rights advocates, Public-interest technologists, Parents and caregivers, Younger participants thinking about their future digital autonomy, Older participants thinking about control, delegation and longevity of their digital identity, People from multi-generational households, Builders working in healthcare, education and finance
The broad audience is intentional as a privacy system designed entirely by privacy specialists risks missing the people who ultimately have to live inside it.
Caregiving creates a common human language through which deeply technical privacy problems become understandable.
India and Local Community Engagement
Mumbai is not simply the location for this Hub. India is an especially important place to explore these questions.
India is home to both a large young population and a rapidly growing older population. UNFPA estimates 153 million people in India were aged 60+ in 2023, rising to 347 million by 2050, while national time-use data shows unpaid caregiving falls disproportionately on women. These demographic and social pressures make intergenerational coordination, affordability, privacy and access increasingly important.
We do not want to arrive in Mumbai with a Western definition of the “sandwich generation” and assume it maps neatly onto every family or community. India-based participants can help challenge and expand the premise itself: how care works across joint families, smaller urban households, migration, different income levels, languages, digital literacy and varying access to support.
We would actively seek:
-
At least one India-based core organizer
-
India-based facilitators across Ethereum, privacy, identity, ZK, wallets and AI
-
Contributors with lived experience of intergenerational care
-
Collaboration with ETHIndia and adjacent open-source communities
-
India-led programming and locally grounded scenarios
I have had the pleasure of working on teams with India based person’s and would certainly be elated to have them support this hub and will reach out once the Community Hub proposal is approved.
Organizing Team
Alix Keller
Alix is a product and technology leader, researcher, facilitator, and longtime participant in Ethereum and other decentralized technology ecosystems. For more than a decade, her work has explored how emerging technologies intersect with privacy, identity, coordination, data ownership, and human agency. She has been in the tech-space approaching 30 years and has witnessed first-hand the evolution of these systems.
Her background spans technical architecture, molecular biology, product strategy, research, and organizational facilitation, with particular experience helping multidisciplinary groups work through complex questions where technology, policy, design, and human behavior overlap. She has facilitated workshops, working sessions, and multi-day programs that bring technical and nontechnical participants together to explore difficult systems problems collaboratively.
As a single-mother and caregiver, Alix also brings lived experience navigating fragmented systems across family, healthcare, education, and support services. That experience has informed an ongoing interest in how technology affects neurodivergent households, people with different cognitive and accessibility needs, and users who may not have the time, resources, or technical expertise to manage privacy and security manually.
Her approach to facilitation is grounded in translating abstract technical questions into tangible human scenarios, creating space for disagreement, surfacing hidden assumptions, and helping groups move from discussion toward shared frameworks and actionable research questions.
LinkedIn: https://www.linkedin.com/in/alix-keller-29b14227/
Kristie Weatherford
Kristie is an experience design leader, researcher, facilitator, and systems thinker with more than two decades of experience designing complex digital products and services in TradFi.
Her work sits at the intersection of human-centered design, emerging technology, organizational systems, and highly complex time-based user environments. Throughout her career, she has helped teams move from ambiguous problems to clearer models by facilitating research, design workshops, collaborative strategy sessions, and multidisciplinary product development.
As a mother of 4 and caregiver, she also brings lived experience with the realities of coordinating family life across generations, as well as a particular interest in designing for neurodivergent households and users whose needs are often poorly represented by conventional assumptions about the “average” user.
Her facilitation approach emphasizes curiosity, inclusion, visual thinking, and creating environments where technical specialists and people with lived experience can meaningfully contribute to the same conversation.
LinkedIn: https://www.linkedin.com/in/kristieweatherford/
Shared Facilitation Approach
Alix and Kristie have worked together for many years as facilitators, strategists, and builders, including co-owning a company (in the past) dedicated to helping organizations work through complex problems using workshops and collaborative design.
Over that time, they developed a broad facilitation toolkit spanning structured ideation, journey and systems mapping, scenario work, research synthesis, participatory design, prioritization exercises, prototyping, futures thinking, and open-format discussion. They are comfortable moving between technical and nontechnical groups and adapting the format in real time when a conversation reveals a more useful direction than the one originally planned.
That ability to pivot is central to how they would run the Hub. Rather than treating the program as fixed, they would use the four days as a living research environment, evolving activities and discussion prompts based on what participants surface and where the community finds the most productive tension.
To preserve the neutral, non-commercial spirit of the Community Hub, these bios intentionally omit current projects, previous employers, and client names. That experience informs their ability to facilitate the work, but the Hub itself is not intended to promote any organization, product, or commercial interest.
India-Based Ethereum / Privacy Organizer(s)
[To recruit.] Have several people in mind.
Ethereum Privacy / Identity Technical Organizer(s)
[To recruit.] Have several people in mind.
The final organizing team should combine technical privacy expertise, Ethereum experience, human-centered design, lived caregiving perspective and meaningful connection to India’s builder community.
Languages and Accessibility
English would be the primary working language, with multilingual participation encouraged through the local organizing team and contributors.
We would actively seek India-based organizers and volunteers who can help make discussions approachable to attendees from different linguistic and cultural backgrounds.
Visual scenario mapping, cards, voting exercises and diagrams will also allow participants to contribute without relying exclusively on long-form technical discussion.
Closing Thought
Caregiving may appear to be a niche use case for privacy infrastructure.
We believe it is almost the opposite.
It is one of the earliest environments where the assumptions behind single-user digital systems visibly break.
People change. Relationships change. Capacity changes. Responsibility changes. Context accumulates. Information crosses generations. Authority must be granted, shared and revoked.
The Caregiver AI research framing behind this proposal starts with a simple hypothesis: if AI can operate responsibly in caregiving, one of society’s most complex and sensitive multi-actor environments, the resulting principles may extend far beyond caregiving.
The question we want to bring to Devcon is:
Can the Ethereum community help make privacy work not only for the people who understand privacy technology, but for everyone whose life will increasingly depend on it?