Is This AI Product Safe for My Child's Data? A Privacy Checklist
Beginner7 min readParenting & Education

Is This AI Product Safe for My Child's Data? A Privacy Checklist

A seven-point checklist — age rules, collection, retention, training use, sharing, controls, and deletion — for deciding whether an AI product gets allow, allow-with-controls, or do-not-use for your child.

What you should be able to do

'Is it safe?' is too vague to answer about an AI product and a child. 'What does it collect, how long does it keep it, does it train on it, who does it share it with, and can I delete it?' has actual answers you can check today.

AI Expert TeamPublished: Jul 30, 2026
Saved only in this browser.
In this article

A new AI-powered app arrives every month with a pitch aimed straight at parents: it tutors, it helps with reading, it’s “designed for kids.” Whether it deserves access to your child’s data is a separate question from whether it’s educationally useful, and it has a checkable answer if you look in the right seven places before installing anything.

This is a workflow, not a one-time judgment: run any new AI product through these seven points, reach one of three decisions — allow, allow with controls, or do not use — and re-check when the product’s terms change, which happens more often in this category than in most software.

Why “it’s for kids” is not the same as “it’s safe for kids”

A product marketed at families can still be built on a general-purpose AI model with adult-grade data practices wrapped in a child-friendly interface. The interface tells you nothing about what happens to the conversation data behind it. You have to check the actual privacy policy and terms, not the app-store description or the marketing page.

The seven-point checklist

1. Age rules. What does the product’s own terms of service state as the minimum age, and does it match how you’re actually planning to use it — your own account with the child, or an account for the child directly? Under the EU’s GDPR Article 8, where consent is the lawful basis for offering information-society services directly to a child, processing a child’s personal data generally needs parental authorisation below 16 (member states may lower that floor to 13). Providers must make reasonable efforts to verify that consent. This is not a blanket ban on every form of child data processing — other lawful bases and offline contexts can differ — but a product with no age gate and no child-consent mechanism for a consent-based consumer chat service has not designed for the common online case.

2. Collection. What does it actually collect beyond the text you type — voice recordings, camera access, contacts, device location, browsing history? Read the permissions requested at install, not just the privacy policy’s prose. A reading-tutor app that asks for microphone access to hear a child read aloud is reasonable; the same app asking for contacts or precise location is a mismatch between stated purpose and actual collection worth questioning directly.

3. Retention. How long is a conversation or a voice recording kept, and does the product state a concrete retention period, or only a vague “as long as necessary”? A concrete, short retention window is a good sign. “As long as necessary for our business purposes” with no number attached is not something you can verify or plan around.

4. Training use. Is the child’s input used to train or improve the underlying AI model, and can that be turned off? Several major providers exclude data from users they know to be under 18 from targeted-advertising uses specifically — OpenAI’s privacy policy states it does not use these practices for users it knows to be under 18 — but training-data use is a related, separate setting that needs its own explicit check, because a company excluding minors from ad targeting is not automatically excluding them from model training too (OpenAI Privacy Policy).

5. Sharing. Does the product share data with third parties — analytics vendors, advertising partners, or other companies — and can you see a list of who those are? A privacy policy that names specific categories of recipients is checkable. One that says “trusted partners” with no further detail is not.

6. Controls. Can a parent see, export, or manage what the account has stored? OpenAI’s account-linking feature for teens lets a parent manage some settings and receive safety alerts, but explicitly does not give the parent access to the teen’s actual conversations — know which kind of control a product is actually offering before you rely on it (OpenAI, parental controls).

7. Deletion. If you decide to stop using the product, can you actually delete the child’s data, and does deletion happen on request or only when an account is closed entirely? Test this once, early, with a low-stakes account, rather than discovering the answer only when you actually want to leave.

From checklist to decision

Turn the seven answers into one of three verdicts:

VerdictWhen it applies
AllowAge rules match your actual use, collection matches stated purpose, retention is short and stated, no use of the child’s data for model training or ad targeting, sharing is limited and named, parental controls exist, and deletion is real and testable.
Allow with controlsMostly acceptable, but one or two points need an active setting change — for example, training-data use can be turned off but defaults to on, or voice recordings need to be manually deleted rather than expiring automatically. Set the control before the first real use, not after.
Do not useVague or missing answers on retention or sharing, no way to delete data, no age-appropriate consent mechanism, or the child’s data trains the model with no opt-out. A product failing on two or more points rarely improves with a single setting change.

A product that fails the deletion test — no real way to remove a child’s data on request — should move to “do not use” regardless of how well it scores elsewhere. Every other setting is reversible; data already used to train a model or already shared with a third party generally is not.

A concrete example

A homework-help chatbot app states a minimum age of 13 with no parental-consent flow for younger children, collects chat text and, by default, voice recordings with no stated deletion timeline, uses input to “improve our services” without a training opt-out, and its privacy policy names no specific third parties for sharing. Checked against the table: age rules do not fit a 10-year-old user without a proper consent mechanism, retention is unstated, training use has no opt-out, and sharing is vague. That is at least three failure points — a “do not use” for a 10-year-old, regardless of how good its tutoring feature is. The same app, used only by a supervised 15-year-old under the household’s own judgment about the product’s terms, and with voice recording manually disabled, might land at “allow with controls” instead — the age rules, collection, and training-use answers change what the checklist supports.

What this checklist does not cover

It does not tell you whether the product’s educational content is accurate, whether the interaction is age-appropriate emotionally, or whether it is a companion-style product a child could form an unhealthy attachment to — that is a separate, more serious question covered in do not give a child an AI friend. Run both checks; passing this privacy checklist does not mean a product is otherwise appropriate.

It also does not replace what ChatGPT remembers, sees, and shares for the general-purpose assistants your household already uses under an adult’s account — that article covers the mechanics this checklist assumes you already understand before applying it to a new, child-specific product.

Try it today

Pick one AI-powered app your child currently uses or has asked to use, and actually open its privacy policy — not the app-store summary — and answer all seven questions above in writing. Most parents skip this because privacy policies are long; the seven-point structure exists specifically so you only need to search the document for seven things, not read it end to end.

The child AI product privacy checklist gives you a printable version of the seven points with the verdict table, so you can run the same check consistently across every new product your household considers.

Read next

Continue through the same learning path with the next practical articles.