Skip to main content
Skip to main content

COPPA Compliance for Parents — App Privacy Guide

Understand COPPA compliance for kids apps. Learn how privacy laws protect your toddler and what to look for in safe, compliant educational apps for kids.

Sean Record, Founder of Little Wheels10-min read
Understanding COPPA compliance for children's app privacy

FREE 7-day trialThen $4.99 to own forever

TL;DRKey Takeaways

  • COPPA requires verifiable parental consent before collecting data from children under 13
  • Enforcement is limited—major companies violate COPPA regularly and face fines years later after profiting from violations
  • Apps directed at children must provide clear privacy policies, limit data collection, and protect children's information
  • True protection comes from apps that don't collect data at all—offline apps can't violate what they don't collect

Our Philosophy

COPPA provides baseline legal protections, but relying on legal compliance alone is insufficient. True privacy protection comes from choosing apps designed from the start not to collect data—apps where privacy isn't a compliance checkbox but a core architectural decision. The best protection isn't trusting apps to follow COPPA; it's choosing apps that don't need COPPA because they collect nothing.

Core Values

🌱

Privacy by design

🌱

No data collection

🌱

Parental control

🌱

Transparency

🌱

Child safety first

COPPA—the Children's Online Privacy Protection Act—supposedly protects children's privacy online. But most parents don't understand what it actually does, what it doesn't do, and why it's insufficient for protecting your toddler.

This guide explains COPPA in plain language, reveals its limitations, and shows you how to actually protect your child beyond legal minimums.

Little Wheels apps go beyond COPPA compliance—we collect zero data, work completely offline, and never show ads or track behavior.

What Is COPPA?

COPPA is a federal law enacted in 1998 (updated in 2013) that regulates how websites and online services can collect personal information from children under 13.

Core COPPA Requirements

Apps and websites directed at children under 13 must:

  • Provide clear privacy policies: Explain what data is collected, how it's used, and who it's shared with
  • Obtain verifiable parental consent: Before collecting, using, or disclosing personal information from children
  • Allow parents to review information: Parents can see what data has been collected about their child
  • Give parents deletion rights: Parents can request deletion of their child's information
  • Implement reasonable security: Protect the confidentiality and security of children's information
  • Limit data collection: Only collect information reasonably necessary for the activity

What Triggers COPPA?

An app must comply with COPPA if it's:

  • Directed at children under 13: Content, design, marketing clearly target kids
  • General audience with actual knowledge: Knows it's collecting data from children even if not specifically targeting them

Toddler apps clearly fall under COPPA—they're explicitly directed at young children.

What COPPA Requires for Data Collection

Understanding COPPA's specific requirements helps you evaluate apps.

Verifiable Parental Consent

Before collecting personal information, apps must obtain consent through methods that reasonably ensure the person providing consent is the child's parent:

Acceptable methods include:

  • Signed consent form (email, fax, or physical mail)
  • Credit card or payment verification
  • Video conference with staff
  • Photo ID verification
  • Knowledge-based authentication (answering questions only parents would know)

What this means: Apps can't just collect data and assume parents consent. They must actively verify parental permission.

Personal Information Covered

COPPA protects a broad range of information:

  • Full name
  • Email address
  • Phone number
  • Physical address
  • Social Security number
  • Persistent identifiers (cookies, IP addresses, device IDs used for tracking)
  • Photos, videos, audio files
  • Geolocation information
  • Any information combined with the above identifiers

Essentially: anything that identifies a specific child or allows tracking across services.

Required Privacy Policy Disclosures

Apps must clearly disclose:

  • Contact information for the operator
  • Types of personal information collected
  • How information is used
  • Whether information is disclosed to third parties
  • Parental rights (review, deletion, refusing further collection)
  • Practices regarding tracking technologies

COPPA's Limitations: What It Doesn't Protect

COPPA provides baseline protections but has significant gaps.

Limitation 1: Enforcement Is Reactive and Slow

The FTC enforces COPPA, but:

  • Limited resources: Can't monitor every app constantly
  • Complaints drive enforcement: Violations continue until enough complaints trigger investigation
  • Years to resolve: Companies violate COPPA for years before facing consequences
  • Fines often less than profits: Companies calculate violations are worth the risk

YouTube violated COPPA for years, collecting children's data and serving targeted ads, before the 2019 settlement. By then, they'd profited substantially from the violations.

Limitation 2: Only Covers Children Under 13

COPPA protects children under 13. Your toddler is covered, but:

  • Different privacy standards apply to teenagers
  • Apps can argue mixed-age audience to avoid strictest COPPA requirements
  • General-audience apps have fewer restrictions even when children use them

Limitation 3: "Verifiable" Consent Has Loopholes

Some COPPA-compliant consent mechanisms are weak:

  • Email plus confirmation: Email parent, parent clicks link to confirm. But companies can't actually verify that email belongs to the parent.
  • Knowledge-based authentication: Questions only parents should know answers to. But information might be discoverable by children or others.

These meet COPPA's letter while potentially failing its spirit.

Limitation 4: Doesn't Prevent Collection—Just Regulates It

COPPA doesn't say "don't collect children's data." It says "follow these rules when collecting it."

Apps can legally collect extensive data from children if they:

  • Get parental consent
  • Disclose practices clearly
  • Implement security measures
  • Allow parental control

Compliance doesn't mean minimal data collection—just documented, consented collection.

Limitation 5: Self-Certification

Apps essentially certify their own compliance. There's no pre-approval process. Apps implement COPPA requirements, claim compliance, and operate until enforcement action occurs—if it ever does.

How Apps Violate COPPA

Despite legal requirements, violations are common.

Common Violation Patterns

Collecting data without consent: Apps collect identifiers or behavior data without obtaining parental permission first.

Inadequate age screening: Apps don't properly verify users' ages, allowing children to use services meant for older users without COPPA protections.

Sharing data with third parties: Passing children's information to advertisers or analytics companies without proper disclosure and consent.

Using persistent identifiers for tracking: Collecting device IDs, cookies, or other identifiers that track children across apps and websites.

Misleading privacy policies: Claiming not to collect data while actually doing so, or burying critical information in lengthy policies.

Why Violations Happen

Companies violate COPPA because:

  • Data is valuable: Children's behavior patterns inform product development and advertising
  • Detection is unlikely: Most violations never get caught
  • Fines are manageable: Even large settlements (YouTube's $170 million) are often less than profits from years of violations
  • Competitive pressure: Competitors collecting data have advantages; compliant companies face pressure to do the same

The economic incentive favors violation when enforcement is weak.

Documented COPPA Violations in Kids' Apps

Major cases show COPPA's limitations in protecting children.

YouTube ($170 million, 2019)

The FTC found YouTube:

  • Collected persistent identifiers from viewers of children's content
  • Used that data for targeted advertising
  • Did this for years despite clear COPPA requirements
  • Made hundreds of millions in advertising revenue from the violations

Settlement required changes but came only after years of violations and massive profit.

TikTok/Musical.ly ($5.7 million, 2019)

Musical.ly (acquired by TikTok):

  • Collected names, email addresses, and other information from users under 13
  • Did so without parental consent
  • Continued after receiving complaints about children on the platform

Violations occurred for years before enforcement action.

Pattern Across Cases

Notice the pattern:

  1. Company violates COPPA
  2. Violations continue for years
  3. Company profits substantially
  4. Eventually faces FTC action
  5. Pays fine less than profits gained
  6. Makes required changes going forward

COPPA enforcement is reactive—protecting children only after harm has occurred.

How to Actually Protect Your Child

Don't rely on COPPA alone. Take active protection steps.

Choose Apps That Don't Collect Data

The best protection: apps that architecturally cannot violate COPPA because they collect nothing.

Offline apps:

  • No internet connection = no data transmission
  • Can't track across apps or websites
  • Can't share data with third parties
  • Can't violate COPPA because they collect nothing to violate with

Little Wheels apps work completely offline. Not "mostly offline with some data collection"—entirely offline. No data leaves your device.

Read Privacy Policies—Actually Read Them

Yes, they're long. But for apps your toddler uses, read them. Look for:

Red flags:

  • "We collect device identifiers for analytics"
  • "We share data with partners"
  • "We use cookies for advertising"
  • Vague language about "improving the experience"
  • Long lists of collected information types

Green flags:

  • "We do not collect any personal information"
  • "This app works offline"
  • "No data is transmitted or stored"
  • Very short policies (nothing to collect = little to disclose)

Classroom App Privacy Checklist

If you're a preschool teacher or daycare director choosing apps for shared tablets, you can use a simple checklist to spot safer options in a few minutes—even without a legal background.

  • No child logins: The app does not require each child to create an account, enter their name, or sign in with email or student IDs. One adult account (or no account at all) is usually enough for classroom devices.
  • Minimal permissions: The app only requests camera, microphone, or location access when it clearly needs them for a feature you plan to use. For most toddler learning apps, microphone and location are rarely necessary.
  • No ads or ad trackers: The privacy policy and store listing explicitly state there are no ads and no advertising networks. If you see "ad partners," "ad SDKs," or "interest-based advertising," skip it for classroom use.
  • Short, specific data section: The privacy policy has a brief, concrete statement like "We do not collect personal information" rather than long, vague language about "improving the experience" and "sharing with trusted partners."
  • Works in airplane mode: When you turn Wi‑Fi off, the app still works normally. This usually means it is not constantly phoning home or dependent on servers that collect usage data.
  • Clear contact information: The developer lists a real email address or website where you can ask privacy questions or request more details for your school.
  • Easy to explain to families: You can summarize the app's privacy approach to parents in one or two sentences (for example, "This app works offline and does not collect personal data").

Prefer Indie Developers

Indie developers typically have better privacy practices:

  • No investor pressure to monetize data
  • Often don't have infrastructure to collect data even if they wanted to
  • Personal reputation matters—can't afford violations
  • Many are parents themselves, building apps they'd want

Corporate apps have teams dedicated to data collection and monetization. Indie apps often collect nothing because it's simpler and aligns with their values.

Check Developer Reputation

Research developers before trusting them with your child's app usage:

  • Have they had COPPA violations?
  • Do they have clear privacy values stated?
  • Are they responsive to privacy concerns in reviews?
  • Do other parents trust them?

Use Device-Level Protections

Enable privacy settings on devices:

iPhone/iPad:

  • Settings > Privacy & Security > Tracking > Turn off "Allow Apps to Request to Track"
  • Settings > Privacy & Security > Location Services > Disable for unnecessary apps

Android:

  • Settings > Google > Ads > Opt out of Ads Personalization
  • Settings > Location > App permissions > Review and restrict

These reduce tracking but don't eliminate data collection within apps.

What COPPA-Compliant Actually Means

Understanding compliance helps you evaluate app claims.

Compliance ≠ No Data Collection

Apps can be COPPA-compliant while extensively collecting data. Compliance means they:

  • Disclose collection practices
  • Obtain parental consent
  • Provide parental controls

But they still collect and use the data. Compliance is about process, not minimization.

Compliance ≠ Safety

COPPA addresses privacy and data collection. It doesn't address:

  • Content appropriateness
  • Advertising manipulation
  • Screen time concerns
  • Educational value
  • Addictive design

An app can be COPPA-compliant while using manipulative design, showing inappropriate ads (to parents, with child present), or providing no educational value.

What to Look for Beyond Compliance

The best apps go beyond legal minimums:

  • Privacy by design: Built from the start not to collect data
  • Offline functionality: No data transmission capability
  • No ads ever: Funded through fair pricing, not advertising
  • Transparent values: Developers clearly state privacy commitments
  • Simple, honest policies: "We don't collect data" beats pages of compliance language

The Future of Children's Privacy

COPPA is over 20 years old. The digital landscape has changed dramatically.

Proposed Reforms

Advocates push for stronger protections:

  • Raising age of protection from 13 to 16
  • Prohibiting targeted advertising to children entirely
  • Requiring default privacy-protective settings
  • Stronger enforcement with larger penalties
  • Mandatory privacy-by-design requirements

These reforms face industry opposition. Don't count on legal protections improving soon.

What Parents Can Do Now

While waiting for better laws:

  • Choose apps with strong privacy practices today
  • Support developers building ethical products
  • Spread awareness about privacy issues
  • Report COPPA violations to FTC
  • Advocate for stronger protections

The Bottom Line on COPPA

COPPA provides baseline legal protections for children's privacy online. But it has significant limitations:

  • Enforcement is reactive and slow
  • Violations are common and often unpunished
  • Compliance doesn't mean minimal data collection
  • Fines are often less than profits from violations

Real protection comes from choosing apps that don't collect data in the first place:

  • Offline apps that can't transmit information
  • Indie developers without data monetization infrastructure
  • Privacy-by-design architecture, not compliance checklists
  • Developers whose values align with protecting children

COPPA is better than nothing. But it's insufficient. Don't rely on legal minimums to protect your toddler's privacy.

Choose apps built to collect nothing. Apps like Little Wheels that work offline and never transmit data. Apps from developers who view privacy protection as core values, not legal obligations.

Your child's privacy deserves better than legal minimums. Choose apps that deliver it.

You Might Also Like

Frequently Asked Questions

Does COPPA apply to all apps kids might use?

COPPA applies to apps and websites 'directed at children under 13' or that have 'actual knowledge' they're collecting data from children under 13. Apps marketed to toddlers clearly fall under COPPA. General-audience apps that know children use them also must comply. However, enforcement depends on the FTC discovering violations—many apps operate outside compliance until caught.

What counts as 'personal information' under COPPA?

COPPA defines personal information broadly: name, email, phone number, physical address, Social Security number, persistent identifiers (cookies, IP addresses, device IDs), photos, videos, audio recordings, geolocation, and any information combined with identifiers. Essentially, anything that can identify or track a specific child is covered.

If an app's privacy policy says it complies with COPPA, is my child protected?

Not necessarily. Many apps claim COPPA compliance in privacy policies while violating it in practice. YouTube claimed compliance while collecting children's data for years before the FTC's $170 million settlement. Real protection comes from apps that architecturally cannot collect data—offline apps that never transmit information in the first place.

Can I report COPPA violations I discover?

Yes. You can file a complaint with the FTC at ftc.gov/complaint. Include details about the app, what data it collects, and how it violates COPPA. While enforcement is slow, complaints help the FTC identify patterns and prioritize investigations. More reports increase the likelihood of action.

How can I audit children's educational apps for hidden data collection?

Start with the app's privacy policy and store listing. Look for mentions of analytics SDKs, advertising partners, device identifiers, cookies, or 'sharing data with trusted partners.' Then check permissions on your device: does the app request access to camera, microphone, location, or contacts without a clear educational reason? Finally, test the app in airplane mode—if major features break or you see a lot of network activity when Wi‑Fi is on, the app is likely sending more data than a simple learning game needs.

How do I check if an educational app complies with COPPA and child privacy laws?

There is no simple stamp that guarantees COPPA compliance, but you can look for a few signals. First, confirm the app has a dedicated children's privacy policy that clearly explains what it collects and why. Second, see whether it requires parental consent before collecting any personal information. Third, look for third‑party certifications or reviews from trusted organizations that focus on kids' privacy. For classroom tablets, the safest option is to choose offline apps that don't collect personal data at all—there's nothing to violate if nothing is sent.

Explore more in

Other Topics

Screen time, safety, philosophy

Visit Other Topics →

Ready to Download & Start Learning?

Offline, ad-free apps that treat screen time as something to spend well rather than something to survive.

Download on the App Store

On the App Store as “Learn to Talk: First Words”

Ad-free & offline ready7 days free, then $4.99 onceChild development experts
💛

One small parenting win at a time

Occasional calm, practical tips and new printables as they ship. No schedule, no spam—unsubscribe anytime.

Instant download
No spam, ever

Educational Disclaimer: The strategies and information provided are for educational purposes only. Every child is unique and may respond differently to various approaches. Always supervise activities to ensure safety and consult with qualified professionals if you have concerns about your child's development or learning.

Share this article

7-day free trial • $4.99 once

Try Little Wheels Apps