Vibe Coded Disclaimer
This application was entirely vibe coded using Claude Code with Claude Opus 4.6 (High) and should be treated as such. The code was generated through conversational AI-assisted development — no line was hand-written. While functional and tested on the developer's machine, it has not undergone formal code review, security audit, or extensive QA. Use at your own discretion, review the source before deploying in any sensitive environment, and expect rough edges.
Download the latest installer (ParentalControlSetup.exe) from the GitHub Releases page. Run it as administrator and follow the on-screen instructions.
Parental Control is a Windows desktop application that lets administrators enforce screen time limits and usage schedules on local Windows user accounts. It consists of two components:
- Admin UI — a WPF desktop app where you configure per-user time limits and schedules, view usage, and monitor events.
- Background Service — a Windows Service that runs silently, tracks active sessions, enforces limits, and forcefully logs users off when they exceed their allowed time or fall outside their permitted schedule.
- Automatically discovers all local Windows user accounts
- Filters out built-in system accounts (DefaultAccount, WDAGUtilityAccount, Guest)
- Distinguishes between standard users and administrators
- Administrator accounts are protected — they cannot be restricted (displayed as read-only in the UI)
- Set a maximum number of minutes per day for each user (default: 120 minutes)
- Usage is tracked in real time, accumulating every 60 seconds
- Administrators can directly edit a user's current daily usage from the Admin UI (useful for granting extra time or correcting usage)
- Resets automatically at midnight
- Define allowed hours for each user (e.g., 08:00 to 22:00)
- Users are forcefully logged off if they are still logged in when their schedule window closes
- Login attempts outside the schedule window are denied
- The background service checks all active sessions every 60 seconds
- If a user exceeds their daily limit, they are immediately logged off
- If a user is logged in outside their allowed schedule, they are immediately logged off
- Login attempts are blocked if the user has already exhausted their daily limit or is outside their schedule
All enforcement actions are logged with timestamps, user SIDs, and details:
| Event Type | Description |
|---|---|
LOGIN |
User logged in successfully |
LOGOUT |
User logged out |
SLEEP |
System entered sleep mode |
WAKE |
System resumed from sleep |
LIMIT_REACHED |
Daily usage limit was reached |
FORCED_LOGOUT |
User was forcefully logged off |
LOGIN_DENIED |
Login attempt was rejected |
CLOCK_TAMPER |
System clock manipulation was detected |
- Detects when the system clock is set backwards (e.g., a user trying to gain extra screen time)
- Immediately fills the restricted user's daily usage to their maximum allowed minutes, locking them out for the rest of the day
- Forces the user off the system
- Logs a
CLOCK_TAMPERevent with timestamps showing the time reversal
- Usage tracking pauses when the system enters sleep mode
- Resumes accurately on wake — sleep time is not counted against the user
- All active session times are flushed to the database before sleep
- Retroactively detects undetected sleep/hibernate events by identifying gaps in session activity greater than 2 minutes
- Events and usage records older than 30 days are automatically deleted
- Cleanup runs daily at midnight
- Keeps the database size manageable over time
- The
C:\ProgramData\ParentalControl\directory is locked via ACLs to SYSTEM and Administrators only - Restricted users cannot directly access or modify the database
- The admin UI polls the Windows Service status every 5 seconds
- Displays a green indicator when the service is running, red when it's down
+---------------------------+ +---------------------------+
| ParentalControl.Admin | | ParentalControl.Service |
| (WPF Desktop App) | | (Windows Service) |
| | | |
| - Dashboard View | | - Session Tracker |
| - User Detail View | | - Usage Monitor Worker |
| - Service Status Monitor | | - Session Change Handler |
+------------+--------------+ +------------+--------------+
| |
| Shared Library |
+---------> ParentalControl.Core <-+
| |
| - Data Models |
| - Repositories |
| - Database Manager |
| - Session Manager |
| - Native Methods |
+----------+-----------+
|
SQLite Database
(C:\ProgramData\ParentalControl\data.db)
Both the Admin UI and the Service share the same SQLite database. When you change a user's limits in the Admin UI, the Service picks up those changes on its next 60-second tick.
| Component | Technology |
|---|---|
| UI Framework | WPF (Windows Presentation Foundation) |
| UI Theme | Material Design Themes for WPF (Indigo/Amber) |
| Architecture Pattern | MVVM (CommunityToolkit.Mvvm) |
| Backend Service | .NET Worker Service (Windows Service) |
| Database | SQLite (Microsoft.Data.Sqlite) |
| Logging | Serilog (rolling file, 30-day retention) |
| Platform Integration | Windows Terminal Services API (P/Invoke) |
| Installer | Inno Setup 6 |
| Target Framework | .NET 8.0 |
| Target OS | Windows (x64 only) |
ParentalControl/
├── src/
│ ├── ParentalControl.Admin/ # WPF Admin UI
│ │ ├── App.xaml(.cs) # App startup, Material Design theme config
│ │ ├── MainWindow.xaml(.cs) # Main window with service status indicator
│ │ ├── Views/
│ │ │ ├── DashboardView.xaml(.cs) # User list, admin list, recent events
│ │ │ └── UserDetailView.xaml(.cs) # Per-user limits config and event history
│ │ ├── ViewModels/
│ │ │ ├── MainViewModel.cs # Service polling, view navigation
│ │ │ ├── DashboardViewModel.cs # User discovery, event loading
│ │ │ ├── UserDetailViewModel.cs # Limit editing, validation, save/remove
│ │ │ └── UserRow.cs # Per-user presentation model
│ │ ├── Helpers/
│ │ │ └── DataGridScrollHelper.cs # Shared DataGrid scroll behavior
│ │ └── Services/
│ │ └── UserDiscovery.cs # Windows local user enumeration
│ │
│ ├── ParentalControl.Core/ # Shared library
│ │ ├── Data/
│ │ │ ├── DatabaseManager.cs # SQLite initialization and schema
│ │ │ ├── UserRepository.cs # User CRUD
│ │ │ ├── LimitRepository.cs # Limit config CRUD
│ │ │ ├── UsageRepository.cs # Daily usage tracking
│ │ │ └── EventRepository.cs # Event logging and queries
│ │ ├── Models/
│ │ │ ├── User.cs # User model (Id, Sid, Username, IsRestricted)
│ │ │ ├── LimitConfig.cs # Limit model (DailyMinutes, ScheduleStart/End)
│ │ │ ├── UsageRecord.cs # Usage model (UserId, Date, MinutesUsed)
│ │ │ ├── EventRecord.cs # Event model (Timestamp, UserSid, EventType)
│ │ │ └── EventType.cs # Event type enum
│ │ ├── Platform/
│ │ │ ├── SessionManager.cs # WTS API wrapper (sessions, force logoff)
│ │ │ └── NativeMethods.cs # P/Invoke for wtsapi32.dll
│ │ └── Logging/
│ │ └── LoggingConfig.cs # Serilog configuration
│ │
│ └── ParentalControl.Service/ # Windows Service
│ ├── Program.cs # Host setup, DI registration
│ ├── ParentalControlServiceLifetime.cs # Session change & power event handlers
│ ├── SessionTracker.cs # Active session tracking & enforcement
│ └── UsageMonitorWorker.cs # 60-second enforcement loop
│
├── installer/
│ ├── ParentalControl.iss # Inno Setup installer script
│ └── Output/ # Generated installer output
│
├── build.ps1 # Build & package script
├── icon.ico # Application icon
├── ParentalControl.slnx # Solution file
└── .gitignore
git clone https://github.com/your-username/ParentalControl.git
cd ParentalControlTo run the Admin UI directly during development:
dotnet run --project src/ParentalControl.AdminTo run the Service in console mode during development:
dotnet run --project src/ParentalControl.ServiceNote: The service needs to run with administrator privileges to track sessions and enforce logoffs. Right-click your terminal and "Run as Administrator" before starting the service.
The build.ps1 script publishes both projects as self-contained win-x64 binaries and then invokes Inno Setup to create the installer:
.\build.ps1If the script fails with this error:
.\build.ps1 : File C:\Users\Robert\Desktop\ParentalControl\build.ps1 cannot be loaded because running scripts is
disabled on this system. For more information, see about_Execution_Policies at
https:/go.microsoft.com/fwlink/?LinkID=135170.
Run it with the execution policy bypassed:
powershell.exe -ExecutionPolicy Bypass -File .\build.ps1The build produces:
publish/service/— Self-contained service binariespublish/admin/— Self-contained admin UI binariesinstaller/Output/ParentalControlSetup.exe— The installer
Run ParentalControlSetup.exe as administrator. The installer will:
- Install files to
C:\Program Files\ParentalControl\ - Register and start the
ParentalControl.ServiceWindows Service (auto-start, runs as LocalSystem) - Configure automatic service restart on failure (10s, 30s, 60s intervals)
- Create Start Menu and Desktop shortcuts for the Admin UI
Navigate to C:\Program Files\ParentalControl\ and run uninst000.exe. This will launch the uninstaller, which will:
- Stop and remove the
ParentalControl.ServiceWindows Service - Remove all program files from
C:\Program Files\ParentalControl\ - Remove the database and logs from
C:\ProgramData\ParentalControl\ - Remove Start Menu and Desktop shortcuts
- Startup — The service initializes the SQLite database, recovers any existing active sessions, and begins the 60-second monitoring loop.
- Session Change — When a user logs on, the service checks their restrictions. If the user is outside their schedule or has exhausted their daily limit, login is denied (forced logoff). Otherwise, the session is tracked.
- Monitoring Loop — Every 60 seconds, the service iterates over all active sessions. For each restricted user, it increments their daily usage and checks limits. Violations trigger a forced logoff.
- Logoff — When a user logs off (or is forced off), accumulated session time is flushed to the database.
- Sleep/Wake — On system sleep, all session times are flushed and tracking pauses. On wake, tracking resumes without counting sleep time.
The Admin UI and the Service both read/write the same SQLite database at C:\ProgramData\ParentalControl\data.db. There is no API or IPC between them — the database is the shared state. SQLite's WAL (Write-Ahead Logging) mode ensures safe concurrent access.
| Table | Purpose |
|---|---|
users |
Local Windows users (SID, username, restricted flag) |
limits |
Per-user limit config (daily minutes, schedule start/end) |
usage |
Daily usage records (user, date, minutes used) |
events |
Audit log of all enforcement events |
| Path | Contents |
|---|---|
C:\Program Files\ParentalControl\admin\ |
Admin UI binaries |
C:\Program Files\ParentalControl\service\ |
Service binaries |
C:\ProgramData\ParentalControl\data.db |
SQLite database |
C:\ProgramData\ParentalControl\logs\ |
Rolling log files (30-day retention) |
This project is licensed under the MIT License.