What Kids Should Never Tell AI: A Privacy Guide for Parents
Children tell chatbots things they would never type into a search box, because a chatbot feels like someone listening. Teaching them what to keep to themselves is one of the most useful AI lessons you can give.
What should kids never tell AI? Their full name, home address, school, phone number, passwords, photos of themselves, where they are or will be, and private details about family members or friends. A simple rule works at every age: if you would not say it to a stranger in the park, do not say it to an AI. Conversations with AI chatbots, voice assistants and AI toys are usually sent to a company's computers and may be stored, reviewed or, in the worst case, exposed.
Why kids overshare with AI
Children do not think of a friendly voice as a database. The AAP's parent site HealthyChildren.org warns parents not to assume private information shared with a chatbot stays confidential, and notes that children may treat chatbots as confidants for deeply personal problems.
Some products make this worse. When the U.S. PIRG Education Fund tested AI toys, two of them told testers their conversations were private, even though the companies behind them collect what children say.
Older children overshare too. In a 2025 Common Sense Media survey of US teens, 24% of those who used AI companions had shared personal or private information with one, such as their real name, location or secrets.
And stored data can leak. In January 2026, researchers found that the AI toy maker Bondu had left a web console open that let anyone with a Google account read about 50,000 children's chats, including names and birth dates, as Malwarebytes reported. The company fixed it quickly once told, but the lesson stands: anything a child says to AI may end up somewhere you did not expect.
The never-share list
US law gives a useful starting point. The FTC's COPPA rule treats all of the following as children's personal information: names, home addresses, online contact details, phone numbers, photos, videos or audio of a child's image or voice, and location precise enough to identify a street and town. Here is a family-friendly version.
| Never share | Kid-friendly example | Why |
|---|---|---|
| Full name | "I'm Mia Johnson" | First names in a children's app are fine; full names identify a real person |
| Home address or street | "I live on Oak Road" | Shows where they can be found |
| School or class | "I go to St Mary's, Year 3" | Narrows down where they are every day |
| Phone numbers and emails | Mum's mobile number | Contact details for strangers |
| Passwords and codes | The tablet PIN | AI never needs a password |
| Photos of themselves | Uploading a selfie "to make a cartoon" | Faces are among the most sensitive data |
| Where they are or will be | "We're at the park every Saturday" | Reveals routines |
| Family secrets and private details | "My parents are getting divorced" | Belongs with trusted adults, not a company's servers |
| Other people's information | A friend's name and secret | It is not theirs to share |
What is fine to share
A good rule is not a fearful one. Children can happily tell an AI:
- What they are curious about: "Why do cats purr?"
- Their interests and favourite things: dinosaurs, football, drawing
- Their age or school year, so answers fit their level, in an app built for children
- Their first name or a nickname, in a children's app their parent set up
- Ideas for stories and pictures
Feelings are a special case. It is fine for a child to say "I'm sad today", but big worries such as bullying, being hurt or feeling unsafe should go to a trusted grown-up. Teach that explicitly.
How to teach it, age by age
Ages 4 to 6: the "robot rule"
Keep it short and repeat it often.
"The robot is a computer. It's fun to ask it questions. But we don't tell it our last name, where we live, or our family's secrets. Those are for people we know."
Play a quick game at dinner: you say a fact, and your child shouts "share!" or "don't share!" ("Your favourite colour?" Share! "Our house number?" Don't share!)
Ages 7 to 9: the "postcard rule"
"Imagine everything you say to an AI is written on a postcard. The postcard goes to a company, and people there might read it. Would you write your address and your password on a postcard? No? Then don't tell the AI."
Ask them to sort a list of 10 statements into "postcard OK" and "not on a postcard."
Ages 10 to 12: the "data trail"
Older children can understand how data works.
"When you type or talk to an AI, your words are usually saved on the company's computers. Sometimes they're used to improve the AI. Sometimes they leak. Every detail you add makes it easier to work out who you are. So share ideas, not identity."
This is also the age to talk about photos. Uploading a selfie to an "AI cartoon" app hands over a child's face. For more on this age group, see AI for Tweens.
Make it a habit, not a lecture
- Model it. When you use AI in front of your child, narrate: "I won't put our address in here."
- Check settings together. Turn off features like memory or chat history where an app allows it.
- Praise good instincts. "You didn't tell it your school name. That was smart."
- Make it safe to confess. "If you ever tell an AI something and then worry about it, come tell me. You won't be in trouble."
What parents should check in any AI app
Children's rules are one layer. The app should do its part too. Before your child uses an AI product, check:
- Is it made for children, and does its privacy policy say how children's data is handled?
- Can you review and delete your child's data? Under COPPA, US parents of children under 13 have the right to review and have their child's personal information deleted.
- Does it sell data or show ads?
- Can you see the conversations?
- Does it tell children their chats are secret? If so, avoid it.
Our guide to COPPA-compliant AI covers the legal side in more depth.
How Askie approaches children's privacy
Askie is a voice-first AI app for children aged 4 to 15. It provides COPPA-compliant child privacy protection, does not sell children's data to third parties, and has no advertisements. Askie's published safety methodology includes PII redaction, and parents can review conversation transcripts, which makes the "come and tell me" conversation easier because you can look together.
Even so, we would rather children learn the never-share rules anyway. Privacy habits learned at 6 will protect them at 16, on every app they ever use.
AI Built With Children's Privacy in Mind
Askie provides COPPA-compliant child privacy protection, has no ads, and never sells children's data.