Skip to content

What Data Do Kids' Apps Collect? A Plain-English Guide

The fruutium Team · Last updated: July 26, 2026

Reviewed for accuracy against AAP/CDC guidance

TL;DR

Kids' apps can collect more than a name and birthday. COPPA, the federal children's privacy law, defines personal information as eleven categories, including persistent identifiers, geolocation, and biometric data, and it only covers kids under 13, not teens (15 U.S.C. section 6501). If an app is directed at children, the law requires notice of what it collects, verifiable parental consent before collection, and your ongoing right to stop further use of your child's data. A 2023 study of 20,195 Google Play apps found 81.25 percent of children's Family-category apps used trackers, a practice the Play Store itself does not allow in that category. This guide walks through the categories, your actual rights, and a five-minute checklist for reading any privacy policy.

What actually counts as "data" in a kids' app?

Most parents picture a name and maybe an email address when they hear "the app collects data." The federal law that actually governs this, the Children's Online Privacy Protection Act, defines personal information as eleven specific categories, and several of them have nothing to do with a name at all (16 CFR §312.2, Cornell Legal Information Institute).

CategoryWhat it means in practice
NameFirst and last name, or a full name
AddressHome or other physical address
Online contact infoEmail, or any way to contact the child online
Screen or user nameEven a made-up in-app handle
Telephone numberAny phone number on file
Government-issued IDSocial Security number, state ID, and similar
Persistent identifierA code that recognizes the same user over time and across apps
Photo, video, or audioAnything containing the child's image or voice
GeolocationPrecise location data
Biometric identifierFingerprint, voiceprint, retina scan, and similar
Combined informationAny of the above tied to other data the app holds

The one most parents miss is the persistent identifier. It is legally defined as an identifier that lets a company recognize the same user over time and across different apps or sites (16 CFR §312.2, Cornell Legal Information Institute). It does not need a name attached to be personal information under the law. An advertising ID quietly picked up by a game your child plays can, on its own, count.

What does COPPA require, and what does it not require?

COPPA only binds an "operator," meaning a site or app that itself collects or maintains children's data, and only when that service is commercially targeted to children, or a general-audience app has actual knowledge a child is using it (15 U.S.C. §6501(2) and §6501(10)(A)). It also has a strict age line: a "child" under the statute is an individual under the age of 13, full stop, so a teen-focused app is not covered by COPPA at all (15 U.S.C. §6501(1)).

Where it applies, COPPA requires three things up front. The operator must post notice of exactly what it collects, how it uses that data, and who it discloses it to (15 U.S.C. §6502(b)(1)(A), U.S. Code). It must get verifiable parental consent before collecting, using, or disclosing anything, meaning you say yes first, not find out after (15 U.S.C. §6502(b)(1)(A)(ii), U.S. Code). And it must keep whatever data it holds reasonably secure and confidential (15 U.S.C. §6502(b)(1)(D), U.S. Code).

Here is what it does not require, and this trips people up: there is no fixed deletion deadline in the statute. You will not find a "must delete within 30 days" rule anywhere in COPPA. The law's security duty is written as "reasonable procedures," which is a standard, not a countdown clock. And enforcement runs through the Federal Trade Commission under its general authority, not through a lawsuit you file yourself (15 U.S.C. §6505(a), U.S. Code).

What rights do you have as a parent under COPPA?

Three rights matter most day to day. First, you can see exactly what specific types of personal information an app collected about your child, not a vague summary (15 U.S.C. §6502(b)(1)(B), U.S. Code). Second, you have a standing right at any time to refuse further use or retention of that data, which functions like a deletion request even though the statute does not use that word (15 U.S.C. §6502(b)(1)(B), U.S. Code). Third, nothing should be collected in the first place without your affirmative consent, given before collection starts, not buried in a settings screen you find later.

How many kids' apps really carry trackers they shouldn't?

A single peer-reviewed study gives a real number here, and it is worth naming precisely rather than repeating "studies show" the way a lot of compliance blogs do. Researchers analyzed 20,195 mobile apps from the Google Play Store, either built specifically for children or listing children among their target users (Sun et al., "Not Seen, Not Heard in the Digital World," The Web Conference 2023).

Among the apps Google Play itself classifies as "Family" apps, a category where Google's own rules do not permit trackers, 81.25 percent used them anyway (Sun et al. 2023). Just under 4.5 percent of those Family apps requested location permissions, despite location collection from children being against Play Store policy (Sun et al. 2023). And this was not limited to small, fly-by-night developers: the study found that even developers with 40 or more kids' apps on Play used ad trackers (Sun et al. 2023). A smaller, separate finding from the same paper worth a footnote: 19.25 percent of the apps studied carried inconsistent content age ratings across different rating authorities, meaning the same app was labeled differently depending on where you checked (Sun et al. 2023).

A few caveats matter here. This is one 2023 study of Android apps on Google Play specifically, not a universal audit of every kids' app on every platform. And the paper's own framing is that these trackers were "not allowed" under Play Store category rules, which is a platform policy finding, not a legal ruling that every one of those apps broke COPPA. A tracker being present does not automatically mean a law was broken; it means the app is worth a closer look. If you want to see what the alternative looks like in practice, we wrote up how we keep trackers out of a kids' app as a worked example of what a from-scratch, no-tracker build actually involves.

How do you read a kids' app privacy policy in five minutes?

You do not need a law degree. Open the policy and the app's store listing side by side and run this checklist:

StepWhat you're checking
Search the policy for "third part"Catches "third party" and "third-party" mentions in one search
Search for "advertis"Catches "advertising," "advertiser," and ad-related SDKs
Search for "SDK" or "software development kit"Named tools the app embeds from other companies
Search for "location"Whether geolocation is collected and why
Search for "identifier"Persistent or device identifiers, often glossed over
Check the store listing's data safety sectionCompare what it claims against what the policy says
Look for a named contact, not just a formYou want a real way to reach someone about your child's data
Check the consent flowDoes it ask before collecting, or only disclose after

If a policy makes you search more than five minutes to answer these, or if it uses only vague language like "we may share data with our partners" without naming who those partners are, treat that as a strike against the app on its own.

What are the specific red flags to look for?

Four things are worth flagging every time you see them. Third-party SDKs you do not recognize by name, especially ad networks or analytics companies bundled into an app that has no obvious need for them. Ad identifiers, meaning any advertising ID or device identifier used to track behavior across apps rather than just to run the app itself. Location requests with no clear gameplay reason, since a coloring app or a math game has no legitimate need to know where your child is standing. And persistent identifiers generally, since they are the mechanism that turns "this app" into "this company can now recognize my kid across other apps too."

None of these four are automatically illegal on their own. What they tell you is that the operator built infrastructure for tracking into an app aimed at children, and that is worth understanding before you decide the app stays on the device.

What should you do if you find something you don't like?

Start with the app itself. Check whether it has in-app parental controls that let you review or delete a child's data directly, many do. If it does not, or the policy is vague about how to reach anyone, email the developer directly. Ask what specific data they collected about your child, and tell them plainly that you want them to stop further use and retention of it. That request tracks your actual legal right under COPPA, and a legitimate operator should be able to respond to it.

If you get no real answer, or the response confirms something you are not comfortable with, uninstall the app and move on. You can also raise a concern with the Federal Trade Commission, the agency that enforces COPPA. We won't spell out an exact filing process here, since that is worth checking directly on the FTC's own site when you're ready.

We built fruutium with these same categories in mind before a single line of tracking code went in, not after a complaint. If you are comparing options, our guides to ad-free learning apps for kids and how much screen time is too much for kids are both good next reads, and the full pillar overview lives at building healthy habits as a family. You can see fruutium's own approach at fruutium.web.app.

Free printable

The Picky Eater Rescue Kit

A week of kid-approved dinners, the grocery list to match, and five dinner-table games — one printable PDF, sent to your inbox. We follow up with two short emails about fruutium, and you can unsubscribe anytime. This list is for grown-ups.

Frequently Asked Questions

Does COPPA protect teenagers too?
No. COPPA legally defines a child as an individual under the age of 13, so the statute stops at a child's thirteenth birthday and does not cover teens at all. If you have a 14-year-old, an app can collect and use their data under a different, much looser set of rules than what applies to a younger sibling. Some states have separate teen privacy laws, but COPPA specifically is a strict under-13 law only.
Can I actually make an app delete my child's data?
COPPA does not use the word deletion, but it gives you something close: the right, at any time, to refuse to let the operator keep using or maintaining your child's personal information. In practice that means you can write to the app and demand it stop using and retaining the data it has. The law does not set a specific deadline like 30 days for the company to comply, only a general duty to handle your request and keep data reasonably secure.
Are trackers in a kids' app automatically illegal?
Not automatically. A 2023 academic study found trackers in the large majority of Google Play Family-category apps, and framed that as against Play Store policy, not as a confirmed legal violation. Whether a tracker actually breaks COPPA depends on what data it collects, whether that data counts as personal information under the law, and whether the operator had valid parental consent. A tracker is a red flag worth investigating, not proof of a violation on its own.
What counts as a persistent identifier, and why does it matter so much?
A persistent identifier is any code that lets a company recognize the same user over time and across different apps or websites, things like an advertising ID or a device fingerprint. It matters because it is explicitly listed as personal information under the COPPA Rule, even though it does not look like a name or address. An app that quietly attaches a persistent identifier to your child's device can build a profile of them across many apps without ever asking for a name.
Who actually enforces COPPA if a company breaks it?
The Federal Trade Commission enforces COPPA under its general authority over unfair and deceptive practices. That means your practical path for a violation runs through the FTC, not a personal lawsuit against the app. You can still contact the developer directly to ask questions or request your rights, and you can raise a concern with the FTC in general terms, but COPPA itself does not give parents a private right to sue.

Sources & References

  1. 15 U.S.C. Chapter 91 (COPPA), U.S. Code (govinfo.gov). https://www.govinfo.gov/content/pkg/USCODE-2021-title15/html/USCODE-2021-title15-chap91.htm
  2. 16 CFR §312.2, Cornell Legal Information Institute. https://www.law.cornell.edu/cfr/text/16/312.2
  3. Sun, Xue, Tyson, Wang, Camtepe & Nepal, "Not Seen, Not Heard in the Digital World!" The Web Conference 2023 (arXiv:2303.09008). https://arxiv.org/abs/2303.09008

Try fruutium with your kid

Free to start. Private, no ads, and you can delete everything anytime.

Create Free Account