How kids' apps handle your child's data: what to look for in a privacy policy

By the Scribblie team · Published · 9 min read

Close-up of a person multitasking, typing on a laptop while holding a book on their lap.
Photo by kaboompics.com on Pexels
In this guide
  1. Start with the store label, not the policy
  2. What "personal data" means for a child
  3. The words to search for
  4. A short, high-level tour of the big privacy laws
  5. Green flags and amber flags
  6. What happens to a voice or a drawing
  7. Free apps, ads and the data that pays for them
  8. Apps that talk back raise one extra question
  9. The fifteen-minute routine
  10. Rights you may have, and how to use them
  11. A last practical habit
  12. Common questions

A good privacy policy answers five questions in plain words: what the app collects about your child, why, who else gets it, how long it is kept, and how you can delete it. If you can find all five in fifteen minutes, that is a good sign. If the answers are vague, buried or missing, that is information too.

You do not need a law degree for this. You need a phone, a cup of tea and a list of words to search for. This guide gives you the list, explains what the large privacy laws are broadly about, and ends with a routine you can repeat for any app.

Start with the store label, not the policy

Both major app stores now ask developers to fill in a short privacy summary on the listing page. Apple calls its version a privacy label, and Google calls its version a data safety section. They are the quick way in.

Treat them as a claim by the developer, not as a verified audit. They can be incomplete or out of date, and the wording differs from store to store, so check the current layout on your device. But they are useful as a first filter. They tell you in a few lines whether an app says it collects things like identifiers, usage data, location, contacts, audio or photos, and whether any of it is used for tracking or shared with other companies.

Compare what you see to what the app does. A drawing app that lists contacts and precise location should make you stop. A drawing app that lists audio makes sense only if it has a voice feature, and then you would want to know what happens to the recording.

What "personal data" means for a child

Most of us think of a name and an address. For a child's app, the list is longer.

It can include a name or nickname, an email address (often the parent's), the child's age or birthday, a voice recording, a photo, a drawing, the device's identifiers, and records of how the app is used. Even without a name, a mix of these can point to one child, which is why privacy laws take a wide view of the term.

Drawings are an interesting case. A scribble of a cat is not very revealing. But a drawing with a name written on it, a school logo in the corner, or one tied to an account and a voice, becomes part of a picture of a particular child. We would treat drawings with the same care as photos, which is more caution than most parents expect, and the right amount.

A mother and child playing with wooden blocks and a smartphone on the floor.
Photo by kaboompics.com on Pexels

The words to search for

Open the policy and use the search function in your browser. Look for these words one at a time, and read the sentence around each.

  • Collect. What does it say it gathers, and does the list match what the app needs?
  • Share. With whom? Look for "partners", "affiliates", "service providers" and "third parties". A service provider that processes data on the company's behalf is different from a company that receives it for its own use, though the policy may not make the difference obvious.
  • Advertising and analytics. Does the app use them, and does it say they are turned off for children?
  • Retain or keep. How long is data stored? "As long as necessary" is common and vague, so see whether anything more specific appears.
  • Delete. Can you remove an account and the data in it, and how?
  • Sell. If the policy mentions selling data, that is worth a slow read.
  • Transfer. Data may be processed in other countries, which is common and not automatically a problem, but should be stated.
  • Contact. Is there a real way to reach the company about privacy?

You will not understand every sentence, and that is fine. You are looking for plain answers and for gaps.

A short, high-level tour of the big privacy laws

Three laws come up most often in conversations about children's apps. We will describe them very broadly, and we are not giving legal advice. Laws are updated, interpreted and enforced differently over time, so check the current official text or guidance for anything that matters to you.

COPPA is a United States law about online services that collect personal information from children under 13. In broad terms it is concerned with notice to parents and with getting a parent's permission. It is the reason many apps ask a grown-up to sign in or confirm something before a child can use them.

GDPR is the European Union's general data protection law. It applies to everyone's data, and it gives particular attention to children. In practice, parents may see clearer notices, consent steps and rights to ask for access to or deletion of data.

India's DPDP Act 2023 is the Digital Personal Data Protection Act. Among other things it addresses how children's data is handled, including a role for a parent or guardian's consent. The detailed rules have been developing, so look for current official sources.

What does this mean for you? Mostly that you have a right to ask questions and a right to expect clear answers. It does not mean that every app with a privacy policy is doing the right thing. We would never say an app is safe because it mentions a law, and we would be wary of any app that says it is "compliant" as though that closed the question.

Green flags and amber flags

After reading a handful of policies you start to develop a nose. Here is ours.

Good signs include: a policy written in plain language; a short, specific list of what is collected; a statement that there is no advertising or third-party tracking in the app; a clear description of what happens to recordings and images; a deletion route inside the app; and contact details for a real person or team.

Amber flags include: a policy that is mostly general text about "our services" with nothing about children; data collected that the app does not obviously need; broad sharing with unnamed partners; a requirement to create a child account with a full name; and no way to delete without emailing and waiting.

Amber is not red. A flag means you should ask the company a question before deciding. Many small teams will answer an email within days, and the quality of that answer is itself informative.

A close-up image of an illuminated security keypad mounted on a wall.
Photo by Brett Sayles on Pexels

What happens to a voice or a drawing

Two kinds of data deserve extra thought in a creative app, because they feel more personal than a tap count.

A voice recording is some of the most personal data a child produces. Check whether the app listens all the time or only when the child presses a button, whether the recording is stored or discarded, and whether it goes to another company for processing. If an app has a voice feature, the policy should say.

A drawing may be stored on the device only, uploaded to the developer's servers, or shared with other parties. Ask which. Also ask whether a drawing is ever used to train or improve a model; a good policy will say what it does and does not do.

For what it is worth, here is how our own app handles it, with the caveat that it is not in the stores yet and you should read our privacy policy for the details. A child's voice is sent for transcription and deleted after transcription. A parent can delete the account and all data from inside the app. There are no third-party advertising or analytics SDKs in it. We do not claim that makes it right for every family, only that you are entitled to these answers from us, as from anyone. How Scribblie works and Scribblie for parents describe it in plain words.

Free apps, ads and the data that pays for them

Data and advertising are tied together. An app that is free to download and funded by adverts has a reason to know something about who is looking at the screen. For children's apps, many stores and laws limit what advertising can do, but the rules differ and the practice varies.

That is one reason we would read the policy of a free app a little more slowly than that of a paid one. It is not a rule that free apps are worse, only that you should know what is paying for them. We go into the economics in why "no ads" matters.

Apps that talk back raise one extra question

If an app uses a voice or a model that writes replies, add a question: does the text of what my child says go to another company, and does that company keep it? A policy for such an app should name the kind of service involved, even if it does not name the vendor. See is AI safe for kids for the wider list of questions.

Close-up of hands typing on a laptop at home, showcasing a cozy work environment.
Photo by Ron Lach on Pexels

The fifteen-minute routine

Do this once per app, and again when it changes a lot.

  1. Open the store listing and read the privacy label or data safety section. Write down anything that surprises you.
  2. Open the policy. Search for the eight words above, one at a time.
  3. Find out how deletion works, and whether you could do it today.
  4. Open the app itself and see what permissions it asks for. They should match the story the policy tells.
  5. Look in the settings for controls: limits, voice on and off, a grown-up check.
  6. Decide if you are comfortable, or if you need to ask the company a question first.

If you are comfortable, tell your child the app's ground rules: no real names, no addresses, no school, and always tell a grown-up if something feels odd. If you want to sort through other items on the list at the same time, the checklist for drawing apps has ten more things to look at.

Rights you may have, and how to use them

Depending on where you live, you may have the right to ask a company what it holds about your child, to correct it and to have it deleted. How that works varies, and we cannot tell you your rights, but the practical route is similar everywhere.

First, look inside the app for a delete or export option. Second, if there is none, find the privacy contact in the policy and write a short, polite message that says who you are, which account it concerns, and what you want. Keep a copy. Third, if you do not get a clear answer, look up the official body in your country that handles data protection complaints, and check what it advises.

Ask early rather than late. It is easier to settle a question about a small app in its first week on the tablet than after a year of drawings.

A last practical habit

Pick one app your child already uses and run the routine on it this week. Chances are you will find something small that you want to change: a permission to switch off, a setting to tighten, a question to email. One change is plenty for an evening, and it is more than most of us have done.

Common questions

How do I know if a kids app is safe for my child's privacy?

No single check proves it. Read the store listing's privacy section, search the privacy policy for what is collected, shared and deleted, and test the app yourself. A clear, specific policy is a good sign, and vague or missing answers are worth a second look.

What is COPPA and does it matter to me?

COPPA is a United States law about how online services collect personal information from children under 13, and it usually involves getting a parent's permission. It matters mainly because it shapes what many apps ask of parents. We are not lawyers, so check the current text or official guidance if you need detail.

What does GDPR mean for a children's app?

GDPR is the European Union's data protection law, and it includes extra attention to children's data. For you as a parent it often shows up as consent steps, access and deletion rights, and plainer notices. For specifics about your situation, check the current rules or ask a qualified adviser.

What is the DPDP Act in India?

It is India's Digital Personal Data Protection Act of 2023, which among other things deals with how children's data is handled and the role of a parent or guardian's consent. Rules and timelines have been filling in, so check current official sources for the up to date position.

Can I delete my child's data from an app?

Often you can, but where and how varies a lot. Look for a delete account or delete data option inside the app, and otherwise for contact details in the privacy policy. If an app makes deletion hard to find, note that.

Do children's drawings count as personal data?

It depends on what is in them and how they are linked to a child. A drawing with a name written on it, or linked to an account or a voice recording, can identify a child. Treat them with the same care as photos.