Explainer
What Does COPPA Actually Require From AI Apps?
Published August 18, 2026 · By the Kidgeni team
COPPA — the Children's Online Privacy Protection Act — requires online services aimed at children under 13 (or that knowingly collect from them) to get verifiable parental consent before collecting personal information, to publish clear privacy practices, to let parents review and delete their child's data, and to keep only what's reasonably necessary. The FTC's amended rule (effective June 2025, full compliance by April 2026) tightened this further: separate parental consent for disclosing children's data to third parties, hard limits on retention, and a required written security program. What COPPA does NOT do is certify an app as 'safe' — it governs data, not content.
What the law actually demands
- Verifiable parental consent BEFORE collecting a child's personal information — name, email, photos, voice recordings, location, persistent identifiers.
- A clear, findable privacy policy saying what's collected, why, and who it's shared with.
- Parental rights to review the child's data and have it deleted.
- Data minimization: collect only what the activity needs, keep it only as long as needed.
- No conditioning participation on handing over more data than the activity requires.
The AI-era update
The FTC's amended COPPA rule (effective June 23, 2025, with full compliance due April 2026) speaks to the AI era directly: services must obtain SEPARATE verifiable parental consent before disclosing children's personal information to third parties — targeted advertising and other non-essential purposes included — may no longer retain children's data indefinitely, and must maintain a written security and retention program. In plain terms: a kids' app that quietly ships children's prompts, drawings, or voice recordings off to third parties — model-training pipelines included — without an explicit, separate parental yes is out of compliance.
How honest kid apps design for it
You can often tell a COPPA-conscious product from its architecture, not its badge. The tell-tale shape: the ACCOUNT belongs to the adult; the child gets a profile with no email or phone number; kid logins use something like a username and PIN; children's content is private by default; and there's a real path for a parent to see and delete everything. (This is, transparently, how Kidgeni is built — adult-owned accounts, kid username+PIN, no kid emails, parental review and deletion — because designing the law in beats bolting it on.)
What COPPA does NOT cover
- Content safety: COPPA says nothing about whether a chatbot gives a child terrible advice — that's a different (and newer) regulatory frontier.
- Teens: protection ends at 13; a 14-year-old is an adult as far as COPPA is concerned (some states now add teen rules).
- General-audience apps your kid sneaks into: an app 'not for under-13s' with an honor-system age gate largely sidesteps COPPA until it knowingly collects from kids.
- Quality, screen time, or accuracy — it is a privacy statute, not a parenting standard.
Five questions to ask any AI app your kid uses
- Who owns the account — me or my child?
- What does my kid have to hand over to log in? (An email is a bad sign.)
- Is children's data used to train models, and did anyone ask me first?
- Where do I go to see and delete everything my child made?
- Is my kid's work private by default, or public by default?
Questions parents ask next
Does 'COPPA-compliant' mean an app is safe for my kid?
No — it means the app handles children's DATA lawfully. Content safety, moderation quality, and design ethics are separate questions. Treat COPPA compliance as the floor, not the certificate.
Can an AI app train its models on my child's creations?
Handing children's data to third parties — training pipelines included — now requires separate verifiable parental consent under the updated rule, and any use must be disclosed in the privacy policy. If a kids' app is vague about training data, that vagueness is your answer.
Why do kid apps use usernames and PINs instead of email logins?
Because a child's email address is personal information COPPA restricts collecting — and an email account is a door to the wider internet. Username+PIN inside a parent-owned account gives the kid a login while the adult keeps the identity.
Does COPPA apply to ChatGPT or other general AI tools?
Those tools handle it by prohibiting under-13s entirely rather than building consent flows. That's legal — and it's exactly why under-13 kids belong in child-directed services rather than age-fudged adult ones.
Sources
Researched August 18, 2026. Products change; we re-check and re-date this article when they do.
See the law designed in
Adult-owned accounts, kid username+PIN, no kid emails, full parental review — read exactly how Kidgeni handles your family's data.