AI products marketed to parents may promise tutoring, reading support or child-friendly design. Whether a product should receive a child’s data is separate from whether it appears educationally useful. The seven questions below can expose missing facts, but they cannot establish that a product is safe, lawful or suitable.
This is a preliminary privacy screen, not a legal determination or full child-safety assessment. Document the seven answers, unresolved questions, jurisdiction, account type, and date. A responsible adult or qualified privacy reviewer still owns the decision, and school or organizational rules may prohibit a product regardless of the checklist.
Why “it’s for kids” is not the same as “it’s safe for kids”
A product marketed at families can still be built on a general-purpose AI model with adult-grade data practices wrapped in a child-friendly interface. The interface tells you nothing about what happens to the conversation data behind it. You have to check the actual privacy policy and terms, not the app-store description or the marketing page.
The seven-point checklist
1. Age rules. What does the product’s own terms of service state as the minimum age, and does it match how you’re actually planning to use it — your own account with the child, or an account for the child directly? Under the EU’s GDPR Article 8, where consent is the lawful basis for offering information-society services directly to a child, processing a child’s personal data generally needs parental authorisation below 16 (member states may lower that floor to 13). Providers must make reasonable efforts to verify that consent. This is not a blanket ban on every form of child data processing — other lawful bases and offline contexts can differ — but a product with no age gate and no child-consent mechanism for a consent-based consumer chat service has not designed for the common online case.
2. Collection. What does it collect beyond the text entered — voice recordings, camera access, contacts, device location, browsing history, telemetry, inferred attributes or identifiers? Read permissions and technical disclosures, not just marketing prose. A microphone may be necessary for a stated read-aloud feature, but necessity alone does not establish lawful basis, security, retention, proportionality or child suitability.
3. Retention. How long are prompts, outputs, recordings, logs, backups and derived data kept, and what event starts deletion? A concrete period is easier to assess than “as long as necessary,” but a short stated period is not proof that retention is lawful, implemented, or complete.
4. Training use. Is the child’s input used to train or improve the underlying AI model, and can that be turned off? OpenAI’s privacy policy states it does not use targeted advertising for users it knows to be under 18 — but training-data use is a related, separate setting that needs its own explicit check, because excluding minors from ad targeting is not the same as excluding them from model training (OpenAI Privacy Policy).
5. Sharing. Does the product share data with third parties — analytics vendors, advertising partners, or other companies — and can you see a list of who those are? A privacy policy that names specific categories of recipients is checkable. One that says “trusted partners” with no further detail is not.
6. Controls. Can a parent see, export, or manage what the account has stored? OpenAI’s account-linking feature for teens lets a parent manage some settings and receive safety alerts, but explicitly does not give the parent access to the teen’s actual conversations — know which kind of control a product is actually offering before you rely on it (OpenAI, parental controls).
7. Deletion. If you decide to stop using the product, can you actually delete the child’s data, and does deletion happen on request or only when an account is closed entirely? Test this once, early, with a low-stakes account, rather than discovering the answer only when you actually want to leave.
From checklist to decision
Turn the seven answers into one of three verdicts:
| Verdict | When it applies |
|---|---|
| Eligible for broader review | Age rules match the intended use, collection appears proportionate, retention is stated, training and advertising uses are understood, recipients are disclosed, controls exist, and deletion can be requested. This is not yet proof the product is safe or lawful. |
| Candidate for qualified decision with controls | Material facts are documented and a responsible adult or qualified reviewer has identified settings and supervision needed for this child and jurisdiction. This checklist alone cannot issue an “allow” decision. |
| Do not use pending resolution | Required age or consent rules do not fit, material privacy facts are missing, deletion rights cannot be exercised, or the intended data use conflicts with household, school, or legal requirements. Do not invent a numeric failure threshold. |
If the provider gives no usable deletion or rights-request route, do not submit the child’s data while you seek qualified advice. Deletion and objection rights, backups, derived data, and model-training effects vary by law and provider; the checklist cannot promise that every downstream use is reversible.
A concrete example
A homework-help chatbot states a minimum age of 13, collects chat text and voice recordings, gives no clear deletion timeline, uses input to “improve our services,” and describes recipients vaguely. For a 10-year-old, the provider’s own age rule already makes the proposed direct account ineligible. The other unanswered questions independently require resolution. For an older child, meeting the minimum age would not resolve retention, training, sharing, supervision or jurisdiction-specific requirements.
What this checklist does not cover
It does not tell you whether the product’s educational content is accurate, whether the interaction is age-appropriate emotionally, or whether it is a companion-style product a child could form an unhealthy attachment to — that is a separate, more serious question covered in do not give a child an AI friend. Run both checks; passing this privacy checklist does not mean a product is otherwise appropriate.
It also does not replace what ChatGPT remembers, sees, and shares for the general-purpose assistants your household already uses under an adult’s account — that article covers the mechanics this checklist assumes you already understand before applying it to a new, child-specific product.
Try it today
Pick one AI-powered app your child currently uses or has asked to use, and actually open its privacy policy — not the app-store summary — and answer all seven questions above in writing. Most parents skip this because privacy policies are long; the seven-point structure exists specifically so you only need to search the document for seven things, not read it end to end.
The child AI product privacy checklist gives you a printable version of the seven points with the verdict table, so you can run the same check consistently across every new product your household considers.



