COPPA-Compliant AI for Kids: What Parents Should Look For
A COPPA-compliant AI app for kids is one that tells parents exactly what it collects from children under 13, gets verifiable parental consent before collecting it, lets parents review and delete it, keeps it only as long as needed, and protects it. Since April 2026 the amended COPPA Rule also requires separate consent before sharing a child's data with third parties, a written retention policy, and a written security program.
What is COPPA?
The Children's Online Privacy Protection Act (COPPA) is a US federal law, enforced by the Federal Trade Commission through the COPPA Rule. It applies to online services that are directed at children under 13, and to general-audience services that have actual knowledge they are collecting personal information from a child under 13.
That second part matters for AI. According to the FTC's COPPA FAQ, a general-audience service does not have to investigate its users' ages, but once it learns a particular user is under 13 it must either meet COPPA's notice and consent requirements or delete that child's information.
COPPA is not the only law in play. In the UK, the ICO's Age Appropriate Design Code (the Children's Code) sets 15 standards for online services likely to be used by under-18s. In the EU, Article 8 of the GDPR requires parental consent below an age of digital consent that each member state sets between 13 and 16. In Australia, the OAIC is developing a Children's Online Privacy Code, which the law requires by 10 December 2026.
What changed in the amended COPPA Rule
The FTC finalised the first major update to the COPPA Rule since 2013 in January 2025. It was published in the Federal Register on 22 April 2025, took effect on 23 June 2025, and most companies had until 22 April 2026 to comply. So any children's app you download today should already meet it.
The changes that matter most for parents:
- Separate consent for sharing. Apps must get separate verifiable parental consent before disclosing a child's personal information to third parties, for example for targeted advertising, unless the disclosure is integral to the service.
- No indefinite retention. Children's data may be kept only as long as reasonably necessary for the purpose it was collected for, and operators must have a written data retention policy.
- A written security program. Operators must maintain a written information security program sized to the sensitivity of the children's data they hold.
- A wider definition of personal information. It now includes biometric identifiers such as voiceprints and facial templates, as well as government-issued identifiers. For voice-first apps, that makes a child's voice recordings an explicit part of the conversation.
- More transparency from Safe Harbor programs. FTC-approved Safe Harbor programs must publish their membership lists.
Why AI apps raise the stakes
Children talk to AI the way they talk to a trusted adult. In a single chat a child might mention their full name, their school, their street, a friend's name, or that their parents are arguing. None of that is a failure on the child's part; it is what children do.
What happens next depends on the service. Some AI products store conversations, use them to improve their models, or link them to an account profile. That is why the questions below matter more than any badge on an app store page.
Where the big AI chatbots stand
The major general-purpose chatbots handle children mainly through age limits in their terms. Here is what each company says as of October 2026:
| AI tool | Minimum age in the terms | Route for younger children | Source |
|---|---|---|---|
| ChatGPT | 13, with a parent's permission under 18 | None. Parents can link to a teen account for controls | OpenAI Terms of Use, parental controls |
| Google Gemini | 13 for a standard account | Parents can enable it for under-13s through Family Link, outside the EEA, Switzerland and the UK | Google Gemini Help |
| Claude | 18 | None | Anthropic Consumer Terms |
| Microsoft Copilot | 13, higher in some countries | None, regardless of parental consent | Microsoft Support |
An age limit in the terms is not the same as a product designed for a child. If your child is under the minimum age for a tool, the honest answer is that the tool was not built for them, whatever its privacy policy says about adults. For a fuller look at one of these, see Is ChatGPT safe for kids? What parents need to know about AI chatbots.
A 7-point COPPA checklist for any kids' AI app
You do not need to read legal text to check an app. Work through these in ten minutes, mostly in the privacy policy.
- Does the privacy policy have a children's section? It should say what is collected from children, why, and who it is shared with. A policy that never mentions children was not written for them.
- Was a parent involved at sign-up? COPPA requires verifiable parental consent before collecting a child's personal information. If your child could create an account and start chatting alone, be cautious.
- Are conversations stored, and for how long? Under the amended rule there should be a written retention policy. Look for a time period, not "as long as necessary" with nothing else.
- Is your child's data used to train AI models? The policy should answer this directly.
- Is anything shared with third parties or used for ads? Sharing now needs separate parental consent. An ad-free app removes the most common reason to share.
- Can you see and delete your child's data? Parents have the right to review what was collected and have it deleted. Check how you would actually do that.
- What about voice? If the app listens, check how recordings and transcripts are handled, since voiceprints now count as personal information.
If you cannot find clear answers, email the company. A children's service should be able to reply plainly. For the controls side of the decision, see our checklist of parental controls to demand from AI apps.
Independent seals: what they do and do not mean
The FTC approves a small number of COPPA Safe Harbor programs: CARU, ESRB, iKeepSafe, kidSAFE, PRIVO and TRUSTe. An app that belongs to one has agreed to be assessed against that program's COPPA guidelines, and under the amended rule those programs must publish who their members are, so you can check a claim yourself.
Educational reviews, such as the Educational App Store's certification, are useful for judging learning value and usability, but they are not COPPA Safe Harbor certifications. Treat them as a different signal.
A seal is a good sign, not a guarantee. The checklist above still applies.
How Askie approaches children's privacy
Askie is built for children ages 4 to 15, so children's privacy is the starting point rather than an add-on. Askie provides COPPA-compliant child privacy protection, does not sell child data to third parties, and has no advertisements in the product.
Parents stay in the loop: they manage their children's profiles, can review conversation transcripts and the artwork their child creates, and settings are protected by a parent-only PIN. Askie's published safety methodology, linked from its website, explains how it handles moderation, PII redaction and data retention, so you can check the details rather than take a badge on trust.
What about AI at school?
Schools often choose AI tools on families' behalf. Under FTC guidance, a school can consent for parents only when a service uses children's data for the school's educational purpose and for no other commercial purpose. In the US, FERPA also governs student education records.
It is reasonable to ask your child's school which AI tools are in use, whether they have reviewed each provider's privacy terms, and how long student data is kept. Our guide to using AI safely in schools covers what a good answer looks like.
Frequently asked questions
Is ChatGPT COPPA compliant?
ChatGPT is not designed for children under 13. OpenAI's terms set a minimum age of 13 and require a parent's permission for users under 18, so a child under 13 should not be using it.
What age does COPPA cover?
Children under 13. Teens aged 13 to 17 are outside COPPA, although some US states and other countries have their own rules for older minors.
When did the new COPPA rules start?
The amended COPPA Rule took effect on 23 June 2025, and companies had until 22 April 2026 to comply with most of the new requirements.
Does a "COPPA compliant" label mean an app is safe?
No. COPPA is about privacy and data, not content. A compliant app can still show unsuitable answers, so check content safety and parental controls as well.
The bottom line
COPPA compliance is the minimum for any AI app your under-13 child uses, not a bonus feature. The amended rule raised that minimum: separate consent before sharing, a real retention limit, and a written security program. Use the checklist, read the children's section of the privacy policy, and choose tools that were built for children from the start.
Choose an AI Built for Children
Askie is made for ages 4-15, with COPPA-compliant privacy protection, no ads, and no selling of your child's data.