This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend
What I Built
My parents don't trust their phones.
It isn't that they can't learn. Every few weeks someone in our neighbourhood has a new story: a fake KYC message, a "new number" asking for money, an account emptied. So every app feels like a trap to them. When I tried to teach them UPI, I told them again and again: "Nothing happens until you enter your PIN." It didn't help. My mom's answer was always some version of "I'll press something and the money will go."
One day my dad got a call from "the police". The caller was official, urgent and frightening. It turned out to be fake. That's when I realised that explaining wasn't enough. They needed somewhere to practise without fear.
So I built Saathi (साथी, "companion"): practice copies of the apps they're afraid of, where every person and every rupee is fake, so nothing can actually go wrong. A patient AI companion talks them through every step, out loud, in Hindi or English.
-
12 guided lessons, grouped the way they think about their day:
- Talk to family: send a message, make and answer a video call, send a voice note (because typing on a small phone is hard).
- Money: pay ₹50 to the vegetable seller, scan a shop's QR code, pay the electricity bill, and the most common UPI trick of all: a stranger's "refund" payment request where entering your PIN actually sends money out.
- Daily needs: book an auto to the hospital (and learn the one OTP you may say aloud), order medicines with cash on delivery.
- Stay safe: block and report a scam number, and remember 1930, India's cyber fraud helpline.
The next button glows. A wrong tap never scolds; it just says "That's okay, nothing happened. Look for the glowing button." After a second miss, Saathi explains the step again in different words. And if she taps a genuinely dangerous button, like Pay on that fake request, Saathi stops and explains exactly why it's a trap.
- Ask Saathi: tap the mic and ask anything: "UPI PIN kya hota hai?" The answer is grounded in exactly what's on screen at that moment.
- Spot the scam: a quiz built from the scams we've actually heard about: KYC links, "new number, send money", KBC lottery OTPs, fake customer care asking you to install AnyDesk, "I sent my WhatsApp code to you by mistake", electricity disconnection threats, and the fake "digital arrest" police call my dad received.
- Is this message safe? Paste a real message and get a calm verdict and an explanation.
- Huge buttons, one action per screen, no timeouts, a permanent "Practice mode — nothing real happens" banner, and it installs to the home screen like a normal app.
🛠️ More apps to practise, in more languages, are coming soon.
Demo
🔗 Live: https://saathi-8w8q.onrender.com

The most common UPI trick: a "refund" that is really a request to PAY. Saathi explains it before she taps Decline.

Every step: one glowing button and one short sentence, spoken aloud.

Spot the scam: the kinds of messages people around us really get, including the fake police call my dad received.
Code
Saathi — practice phone apps where nothing can go wrong
🔗 Live app: https://saathi-8w8q.onrender.com (free plan, so give it ~30 seconds to wake up) ·
Many older people are scared of everyday apps. What if I tap the wrong thing and lose money? Saathi ("companion") gives them practice copies of the apps they're afraid of, with fake people and fake money. A patient AI companion talks them through every step, out loud, in their language.
- 12 guided lessons in 4 groups: talk to family (send a message, make and answer a video call, send a voice note), money (pay with UPI, scan a QR code, pay the electricity bill, spot a fake payment request), daily needs (book a cab, order medicines), and staying safe (spot the scam, block and report a scam number and call 1930). The next button glows, a wrong tap gets "That's okay,…
How I Built It
Phone (Next.js PWA) → Next.js API routes → Mastra agents → Gemma
├─ tools + memory → MongoDB Atlas
└─ traces → Sentry
Voice: ElevenLabs · Hosting: Render · CI/CD: GitHub Actions
- Gemma, at the core. On a laptop, Saathi runs Gemma 3 (4B) through Ollama, completely offline. The deployed version runs Gemma 4 (31B) on DigitalOcean Serverless Inference. Both are the same OpenAI-compatible API, so switching is a single environment variable.
-
Mastra runs two agents: a patient tutor and a scam explainer. Every question is grounded before Gemma sees it: what's on her screen right now, plus the most relevant trusted help notes. Because Gemma 4 supports tool calling, the tutor also has working memory. In a test conversation ("My name is Kamla. UPI PIN kya hota hai?"), it called
updateWorkingMemory, wrote itself a note ("Preferred language: Hindi. Finds confusing: UPI PIN."), and a minute later answered "हाँ कमला जी, मुझे याद है।" - MongoDB Atlas stores agent memory, every tap as a progress event, and help notes embedded with EmbeddingGemma for Atlas Vector Search (on the laptop version; online, where there's no serverless embedding model, it falls back to keyword search), so answers rely on trusted facts instead of guesses.
- ElevenLabs gives Saathi a warm, slightly slower voice. Scripted lesson lines are generated once at build time (lessons without clips yet use the browser's voice) and never fetched live, so practising sends nothing to ElevenLabs and replaying a lesson costs nothing. If the voice service is unavailable, the browser's built-in voice takes over.
-
Rules + AI for scams. Fixed red-flag rules decide the verdict (an OTP request should never be missed by a model having a bad day), and Gemma explains it kindly. One bug I'm glad I caught: JavaScript's
\bdoesn't work with Devanagari letters, so my Hindi scam keywords were silently never matching. - Sentry traces every agent run: latency, tokens, cost (under $0.01 per conversation) and tool calls, such as the memory update above. Zero errors so far.
- Render hosts the app, and GitHub Actions lints, typechecks and builds every push before deploying.

A test conversation traced in Sentry: the memory tool call, Gemma 4's Hindi answers, 3.5K tokens, under $0.01.

Every Saathi conversation so far: zero errors, under a cent each.
Why Does Open Innovation Matter?
Scams are the reason my parents are afraid. So it would be strange to build them a "scam checker" that pastes their private messages into a closed AI company's servers.
- Their data stays with us. The messages they check go only to open-weight Gemma. On the laptop version, nothing leaves the house at all.
- It works with no internet. Gemma 3 runs locally through Ollama, so a parent with patchy Wi-Fi can still practise.
- It costs almost nothing. Free on a laptop, and about $0.0002 per answer on DigitalOcean. That matters for a family tool used every day, not a demo used once.
- We control how it behaves. I could tune Saathi to speak in short sentences, never say "error", always reassure first, and switch between model sizes, all without asking anyone's permission.
What She Said
My mom tried the lessons, and something shifted. She's more confident now. Not because I explained UPI one more time, but because she could tap the wrong thing, hear "nothing happened", and try again until it felt normal.
When she finished, she said:
"It feels light. I have done it, and nothing went wrong."
Prize Categories
- Best Use of Gemma: Gemma 3 locally via Ollama, Gemma 4 serverless, EmbeddingGemma for vector search
- Best Use of DigitalOcean: Gemma 4 on Serverless Inference, with a Model Access Key limited to Gemma only
- Best Use of Render: hosts the Next.js app and Mastra agents
- Best Use of Mastra: agents with tools, working memory, and Sentry tracing
- Best Use of MongoDB Atlas: Vector Search, agent memory, progress events
- Best Use of ElevenLabs: pre-generated bilingual narration, speech-to-text for questions
- Best Use of Sentry Agent Tracing: traces of every agent run and tool call
- Best Use of GitHub Copilot: GitHub Actions CI/CD that lints, typechecks, builds and deploys
Made with 🧡 by Onkar Dhingra · 2026
Top comments (0)