

Correct. A (non-admistrator) user of a Android cannot disable software. This too also applies to a Windows Limited user.
Pi-Hole + packet inspection + whitelisting + switch routing = universal lockdown against every known form of data obfuscation. This is now a server machine.
Switch routing is network hardware that manages only one side\subnet\layer of clients – it’s like one layer of an onion will only ever see the next layer.
This reddit thread cites a real-world parent’s example of packet inspection solutions…
https://www.reddit.com/r/selfhosted/comments/piarcj/selfhosted_parental_control/