Is this AI product safe for my child's data? A privacy checklist
Beginner7 min readParenting & Education

Is this AI product safe for my child's data? A privacy checklist

A seven-point screen for age rules, collection, retention, training, sharing, controls and deletion that records unresolved child-data risks without pretending to certify a product as safe or lawful.

What you should be able to do

'Is it safe?' is too vague to answer about an AI product and a child. 'What does it collect, how long does it keep it, does it train on it, who does it share it with, and can I delete it?' has actual answers you can check today.

Saved only in this browser.
In this article

AI products marketed to parents may promise tutoring, reading support or child-friendly design. Whether a product should receive a child’s data is separate from whether it appears educationally useful. The seven questions below can expose missing facts, but they cannot establish that a product is safe, lawful or suitable.

This is a preliminary privacy screen, not a legal determination or full child-safety assessment. Document the seven answers, unresolved questions, jurisdiction, account type, and date. A responsible adult or qualified privacy reviewer still owns the decision, and school or organizational rules may prohibit a product regardless of the checklist.

Why “it’s for kids” is not the same as “it’s safe for kids”

A product marketed at families can still be built on a general-purpose AI model with adult-grade data practices wrapped in a child-friendly interface. The interface tells you nothing about what happens to the conversation data behind it. You have to check the actual privacy policy and terms, not the app-store description or the marketing page.

The seven-point checklist

1. Age rules. What does the product’s own terms of service state as the minimum age, and does it match how you actually plan to use it: an adult operating their own account or a child holding an account directly? Do not share an adult’s credentials to work around an age rule. Under the EU’s GDPR Article 8, where consent is the lawful basis for offering information-society services directly to a child, member states set a threshold from 13 to 16 and require authorization from the holder of parental responsibility below it. Estonia sets that consent threshold at 13 (Estonian Personal Data Protection Act, section 8). This narrow rule is not a general age of digital adulthood: it does not override a provider’s higher minimum age, establish the provider’s lawful basis, or prove safety or suitability.

2. Collection. What does it collect beyond the text entered — voice recordings, camera access, contacts, device location, browsing history, telemetry, inferred attributes or identifiers? Read permissions and technical disclosures, not just marketing prose. A microphone may be necessary for a stated read-aloud feature, but necessity alone does not establish lawful basis, security, retention, proportionality or child suitability.

3. Retention. How long are prompts, outputs, recordings, logs, backups and derived data kept, and what event starts deletion? A concrete period is easier to assess than “as long as necessary,” but a short stated period is not proof that retention is lawful, implemented, or complete.

4. Training and other secondary uses. Is the child’s input used to train or improve the model, personalize content, measure engagement, build profiles or serve advertising, and which of those uses can be turned off? Treat every purpose separately. A statement about advertising does not answer training, and a training opt-out does not answer retention, human review, sharing or profiling.

5. Sharing. Does the product share data with third parties — analytics vendors, advertising partners, or other companies — and can you see a list of who those are? A privacy policy that names specific categories of recipients is checkable. One that says “trusted partners” with no further detail is not.

6. Controls. Can the child and responsible adult see, export, correct, restrict or delete what the account has stored? Record exactly what a linked or supervised account exposes. Settings access, safety alerts and conversation access are different capabilities; do not infer one from another. Also assess whether the control itself respects the child’s evolving privacy and whether it is appropriate for the child’s age and the risk.

7. Deletion. If you decide to stop using the product, can you request deletion, and does that require closing the account? What does the policy say about backups, legal retention and data already de-identified or used in model development? If you test the workflow, use fictional or non-personal data, not a child’s real data. A successful interface test proves only what that account exposed at that time, not complete erasure from every downstream system.

From checklist to decision

Turn the seven answers into one of three workflow outcomes, none of which certifies safety, legality or suitability:

VerdictWhen it applies
UnresolvedOne or more answers are missing, vague, untested or inconsistent with the intended use. Do not treat silence as permission.
Escalate for a responsible decisionThe facts are documented, but the responsible adult, school, data-protection role or qualified adviser must decide whether the proposed use and controls fit this child and jurisdiction.
Decline or pause this useThe product’s age rule does not fit, required controls cannot be established, or the responsible decision-maker rejects the proposed use. Do not invent a numeric failure threshold.

If the provider gives no usable deletion or rights-request route, do not submit the child’s data while you seek qualified advice. Deletion and objection rights, backups, derived data, and model-training effects vary by law and provider; the checklist cannot promise that every downstream use is reversible.

A concrete example

A homework-help chatbot states a minimum age of 13, collects chat text and voice recordings, gives no clear deletion timeline, uses input to “improve our services,” and describes recipients vaguely. For a 10-year-old, the provider’s own age rule already makes the proposed direct account ineligible. The other unanswered questions independently require resolution. For an older child, meeting the minimum age would not resolve retention, training, sharing, supervision or jurisdiction-specific requirements.

A strip of blank paper covers the identifying area of a child's drawing.
An illustration of removing identifying details before sharing a child's work. AI-generated illustration.

What this checklist does not cover

It does not tell you whether the product’s educational content is accurate, whether the interaction is age-appropriate emotionally, or whether it is a companion-style product a child could form an unhealthy attachment to — that is a separate, more serious question covered in do not give a child an AI friend. Run both checks; passing this privacy checklist does not mean a product is otherwise appropriate.

It also does not replace what ChatGPT remembers, sees, and shares for the general-purpose assistants your household already uses under an adult’s account — that article covers the mechanics this checklist assumes you already understand before applying it to a new, child-specific product.

Try it today

Pick one AI-powered app your child has asked to use and open its current privacy policy and terms, not only the app-store summary. Answer all seven questions in writing without creating a child account or submitting child data. Record the exact product, plan, account type, region, policy date and intended use because controls can differ across each of them.

The child AI product privacy checklist gives you a printable version of the seven points with the verdict table, so you can run the same check consistently across every new product your household considers.

Privacy sources and review boundary

Read next

Continue through the same learning path with the next practical articles.