Research · Privacy
AI and children’s privacy — the questions that actually matter
By Whizbee · Updated June 15, 2026 · Reviewed against primary research
It can be safe — but most general AI tools weren’t built around children’s privacy law. The questions that matter for a 7–11-year-old are concrete: is your child’s data used to train AI, can you review and delete it, is it sold, and is the tool built for under-13s? As of 2025, US law treats using a child’s data to train AI as needing separate parental consent.
The law just moved — in your child’s favour
For most of the AI era, a child’s conversations were treated like anyone else’s data. That changed. The US Federal Trade Commission’s amended COPPA Rule — published in April 2025 and effective that June — updated the rules for children under 13, and it speaks directly to AI.
Most striking: the FTC’s commentary treats disclosing a child’s personal information to train or develop AI as not integral to a service — meaning it requires separate, verifiable parental consent. The amendments also expanded what counts as “personal information” (now including biometrics such as voiceprints) and tightened companies’ ability to monetize children’s data.
In the EU, GDPR Article 8 has long set a digital-consent age between 13 and 16, below which a parent must consent. The throughline on both sides of the Atlantic: a child’s data is meant to carry special protection — but a general adult tool isn’t built around that, and the burden lands on you to check.
Four questions to ask any AI
Is the data used to train AI? Many consumer tools may use conversations to improve their models unless you opt out. Under the FTC’s 2025 COPPA amendments, using a child’s personal information to train AI isn’t treated as “integral” to a service — it needs separate, verifiable parental consent.
Can I review and delete it? A tool built for children gives a parent a clear way to see and remove a child’s data. General adult products often don’t — the right to access and delete is a key thing to check.
Is it sold, shared, or used for ads? The 2025 COPPA changes specifically limit companies’ ability to monetize kids’ data. An ad-funded product has an incentive a subscription product simply doesn’t.
Is it built for under-13s? The real tell: is the tool built around children’s privacy law (COPPA/GDPR) from the start — or an adult product with a 13+ gate bolted on?
Where Whizbee stands
Whizbee is built around a child’s privacy, not around monetizing it. It runs in a closed environment with no open web and no ads, a child signs in with a Magic PIN (so there’s no email to collect), children’s data isn’t sold, and the product is designed to be COPPA- and GDPR-conscious. Parents see proof of learning — not a raw transcript of everything their child typed.
Frequently asked questions
Is my child’s data safe with AI?
It depends on the tool. Most general AI assistants are built around adult consumer terms, not children’s privacy law. The safer choice for a 7–11-year-old is a tool built around COPPA and GDPR from the start: one that doesn’t sell data, lets a parent review and delete it, and doesn’t quietly use a child’s conversations to train models.
Does AI use my child’s conversations to train its models?
It can. Many consumer AI tools may use conversations to improve their models unless you opt out. Notably, under the FTC’s 2025 COPPA amendments, using a child’s personal information to train AI is not treated as integral to a service — it requires separate, verifiable parental consent.
What is COPPA, and does it cover AI?
COPPA is the US children’s privacy law protecting under-13s; it requires verifiable parental consent before collecting a child’s personal information. The FTC’s 2025 amendments expanded what counts as personal information (including biometrics like voiceprints), limited monetizing kids’ data, and addressed using children’s data to train AI.
Can I delete what an AI knows about my child?
With a tool built for children, you should be able to review and delete your child’s data. With a general adult product, that’s often harder and not designed for a parent. The right to access and delete is a key thing to check before a child uses any AI.
How do I protect my child’s privacy when they use AI?
Ask four questions: is the data used to train models, can you review and delete it, is it sold or used for ads, and is the tool built around children’s privacy law (COPPA/GDPR) rather than adult terms? Favour closed, ad-free, subscription tools that don’t depend on monetizing your child’s data.
Sources and methodology
This piece favours primary legal and regulatory sources, and describes the law as it stands rather than predicting how it will be enforced.
- FTC — Children’s Online Privacy Protection (COPPA) The US children’s privacy program: protects under-13s and requires verifiable parental consent before collecting a child’s personal information.
- FTC — 2025 COPPA Final Rule (limiting monetization of kids’ data) Amended Rule (published April 2025, effective June 2025): expanded “personal information” (incl. biometrics), limited monetizing kids’ data, and treats training AI on a child’s data as needing separate consent.
- GDPR — Article 8 (a child’s consent for online services) EU digital-consent age is 16 by default; member states may lower it to no less than 13. Below the threshold, a parent must consent.
Explore related kid topics
Free explainers with a short quiz — useful after reading this research.
Privacy built in, not bolted on
Whizbee is built around a child’s privacy — closed, ad-free, no email, nothing sold — with proof of learning for parents instead of a transcript.
← Back to all research