Skip to content
Safe Screen Time

A Parent's COPPA Checklist: How to Tell If a Kids' App Is Actually Safe

A plain-English guide to COPPA and children's app privacy — with a 10-point checklist you can use before downloading any app for your child.

S

Skyako

Last updated on 9 June 2026

Share

You found a colorful, well-reviewed app that promises to teach your child to read. The screenshots look great. The rating says “ages 4 and up.” You hit Install.

But what happens next — behind the cheerful animations and friendly sound effects — is often invisible. Does the app track your child’s location? Does it send data to advertisers? Could your three-year-old accidentally end up in a chat room with strangers?

These are not hypothetical fears. A 2023 study from the International Computer Science Institute found that the majority of children’s apps on major app stores transmitted device identifiers to third-party services, many in probable violation of U.S. privacy law. The truth is, a cartoon parrot on the icon does not make an app safe.

This guide will help you figure out which apps actually are.

What Is COPPA, and Why Should You Care?

COPPA stands for the Children’s Online Privacy Protection Act. It is a U.S. federal law, enforced by the Federal Trade Commission (FTC), that governs how companies collect and handle personal information from children under 13.

In plain terms, COPPA says:

  • Apps and websites directed at children cannot collect personal information (name, email, photos, location, device identifiers) without verifiable parental consent.
  • Companies must post a clear, complete privacy policy explaining exactly what they collect, how they use it, and who they share it with.
  • Parents have the right to review and delete any data collected from their child.
  • Companies cannot condition a child’s participation on collecting more data than is reasonably necessary for the activity.

Violations are not trivial. The FTC has levied multimillion-dollar fines against companies including TikTok, Epic Games, and several popular children’s app developers.

But here is the catch: COPPA does not pre-approve apps. There is no government seal on compliant apps and no automatic filter in the App Store or Google Play. The burden of evaluating an app’s safety often falls on you.

That is what this checklist is for.

A Quick Note for International Families

If you are outside the United States, similar protections may apply under different names. The EU’s General Data Protection Regulation (GDPR) includes specific provisions for children’s data — sometimes referred to as GDPR-K — which generally require parental consent for data processing of children under 16 (though individual EU member states can lower this to 13). The UK has its own Age Appropriate Design Code. South Korea, Brazil, and Australia have comparable frameworks.

The checklist below is grounded in COPPA, but the principles apply regardless of where you live. If an app passes these ten checks, it is likely a responsible actor in any jurisdiction.

The 10-Point COPPA Checklist

Before you download a kids’ app — or to evaluate one already on your child’s device — work through these ten questions.

1. Does It Have a Clear Privacy Policy?

COPPA requires any app directed at children to have a privacy policy that is easy to find and written in language a non-lawyer can understand. Look for a direct link in the app store listing or on the app’s website.

Red flags: no privacy policy at all, a policy hidden behind three layers of menus, or one written entirely in dense legalese with no plain-language summary.

What to look for: a policy that explicitly states the app is designed for children, names the specific types of data it collects (or confirms it collects none), and explains how parents can get in touch.

2. Does It Collect Personal Information?

This is the big one. Under COPPA, “personal information” includes names, email addresses, phone numbers, photos, audio recordings, geolocation, and persistent identifiers like advertising IDs that can track a child across apps.

Some apps legitimately need limited data to function — a reading app might process camera images to perform text recognition, for example. The key question is whether that data leaves the device.

An app like LoroBuddy processes camera images for OCR entirely on-device and stores all user data locally. Nothing is uploaded to a server. That is the gold standard: functionality without data collection.

3. Are There Ads? What Kind?

Not all ads are created equal when it comes to children’s privacy.

Personalized ads use behavioral tracking — cookies, device identifiers, browsing history — to target content to individual users. Under COPPA, serving personalized ads to children under 13 without parental consent is a violation.

Non-personalized, contextual ads display generic content that is not based on a child’s behavior or identity. These are generally permissible, though the ad content itself still needs to be age-appropriate.

The safest option is no ads at all. The next safest is non-personalized ads that are explicitly tagged as child-directed. When evaluating an app, check whether it mentions ad partners in its privacy policy, and whether it offers an ad-free tier. LoroBuddy, for instance, shows only non-personalized, child-safe ads in its free tier and offers a $2/month plan that removes advertising entirely.

4. Does It Require an Account or Email?

Many children’s apps ask kids (or parents) to create an account with an email address, username, or profile photo. Under COPPA, collecting this information from a child requires verifiable parental consent.

Ask yourself: does my child actually need an account for this app to work? A drawing app, a read-aloud tool, or a math game can often function perfectly well without any login at all.

Prefer apps that work without accounts. If an account is required, verify that the app uses a proper parental consent mechanism — not just a checkbox that says “I am over 13.”

5. Can My Child Chat With Strangers?

Social features are where children’s app safety gets genuinely dangerous. Open chat, friend lists, public profiles, and user-generated content feeds all create vectors for contact with unknown adults.

If the app has any social features, look for:

  • Whether messaging is limited to pre-written phrases (no free-text chat)
  • Whether friend connections require parental approval
  • Whether there is real-time human moderation

If the app is a single-player experience with no social features — no chat, no profiles, no sharing with other users — that risk is eliminated entirely.

6. Does It Share Data With Third Parties?

This question goes beyond advertising. Many apps embed third-party SDKs (software development kits) for analytics, crash reporting, A/B testing, attribution tracking, and social media integration. Each SDK is a potential pipeline sending your child’s data to a separate company with its own privacy practices.

Check the privacy policy for named third-party partners. Be wary of vague language like “we may share data with trusted partners.” Look for specifics.

The simplest approach — and the one most protective of your child — is an app that uses no third-party analytics or tracking services at all. LoroBuddy takes this approach: it embeds no third-party analytics SDKs, so there is no data pipeline to external companies.

7. Where Is Data Stored?

There are two models: cloud storage and on-device storage.

Cloud storage means your child’s data — recordings, progress, preferences, usage patterns — lives on a company’s servers. This introduces risks around data breaches, unauthorized access, and long-term retention.

On-device storage means data stays on the phone or tablet and never leaves. If the app is uninstalled, the data goes with it. This is inherently more private, though it does mean data is not recoverable if the device is lost.

For a children’s app, on-device storage is almost always the safer choice. Ask: does the app need a server to function? A reading app that scans and reads printed text does not need the cloud at all.

COPPA requires “verifiable parental consent” before collecting personal information from a child under 13. The FTC recognizes several methods:

  • Signing a physical consent form and returning it by mail, fax, or email
  • Requiring a parent to use a credit card or government ID
  • Having a parent call a toll-free number
  • Video conferencing with trained personnel
  • Providing a government-issued ID that is verified and then deleted

What does not count: a pop-up that says “Are you a parent? Click yes.” A simple age gate that a child can lie through is not verifiable consent.

If an app collects personal information from children and its only “consent” mechanism is a checkbox or a birthdate field, that is a red flag.

Of course, the cleanest solution is to avoid collecting personal information in the first place — removing the need for a consent mechanism entirely.

9. Can I Review and Delete My Child’s Data?

COPPA gives parents the right to:

  • Review the personal information an app has collected from their child
  • Request that the data be deleted
  • Refuse to allow further collection

Look for a clear process in the privacy policy. Is there an email address or in-app mechanism for data requests? Does the company commit to a response timeline?

For apps that store everything on-device, this question resolves simply: you control the device, so you control the data. Deleting the app deletes the data. There is nothing sitting on a remote server that you need to chase down.

10. Is It Independently Certified or Rated?

Several organizations offer COPPA Safe Harbor certification, meaning they independently audit apps for compliance:

  • kidSAFE Seal Program — one of the most recognized certifiers
  • ESRB Privacy Certified — the same organization that rates video games
  • PRIVO — provides age verification and parental consent services
  • TrustArc (formerly TRUSTe) — general privacy certification

A Safe Harbor seal is a strong positive signal but not a guarantee. Some excellent apps have not pursued certification simply because the process is expensive and time-consuming, particularly for small developers.

Use certification as a bonus indicator, not the sole criterion. The nine questions above are more important than any seal.

Putting the Checklist Into Practice

You do not need to spend an hour researching every app your child wants to try. Here is a quick workflow:

  1. Start with the privacy policy. If there is not one, stop. If it is unreadable, proceed with caution.
  2. Check for account requirements and social features. If the app needs a login or has open chat, dig deeper into how those are handled.
  3. Look at the ad model. Non-personalized or no ads is what you want.
  4. Check for third-party data sharing. Fewer external partners means less exposure.
  5. Verify data storage. On-device is safer. Cloud storage demands more scrutiny.

Most unsafe apps will reveal themselves in the first two steps.

No App Is a Substitute for Involvement

Even the most privacy-respecting, COPPA-compliant app in the world is not a replacement for parental awareness. Sit with your child when they first use a new app. Understand what it does. Talk about what is okay and what is not.

The goal of this checklist is not to make you paranoid — it is to give you a concrete, repeatable way to evaluate the digital tools in your child’s life. Most developers building children’s apps are well-intentioned. But intentions do not protect data. Architecture does.

Choose apps that are safe by design: minimal data collection, on-device processing, transparent policies, and honest business models. Your child’s privacy is worth the five minutes it takes to check.


Read our full privacy policy for details on how LoroBuddy handles data, or download the app to try it yourself.

Give your child a reading buddy