Last updated 2026-08-29. Written by the TernQuest team. This is for parents and teachers deciding whether to let a child under 13 use an app, and who want to check it in minutes rather than read a law.
What is COPPA and what does it actually require?
Direct answer: COPPA is the U.S. Children's Online Privacy Protection Act, enforced by the FTC. It applies to online services directed at children under 13 and requires verifiable parental consent before collecting personal information from them. It does not ban data collection; it puts a grown-up's consent in front of it.
That last point is the one most parents miss. "COPPA compliant" on an app's store listing means the company has a process for parental consent and a policy for what it collects. It does not tell you what it collects, whether there are ads, or whether the child's session is being measured for engagement. Those answers live in the privacy policy, which is why the rest of this post is about reading one quickly.
The FTC's own guidance for businesses is public at ftc.gov. It is written for companies, but it is the primary source, and it is more useful than any summary if you want the actual rules.
COPPA versus FERPA, for teachers
If you are choosing an app for a classroom, a second law applies. FERPA is the U.S. Family Educational Rights and Privacy Act; it protects the privacy of student education records. Schools may share records with a vendor acting as a "school official" with a legitimate educational interest. In practice that means a classroom app should be willing to act as a school official for your school, and your district may have a vetting process for exactly this. Ask before you hand out a class code.
Quotable version: "COPPA puts a grown-up's consent in front of data collection; it does not stop collection. Read the policy."
What are the 5 questions to ask any kids app?
Direct answer: Ask who creates the account, whether there are ads, whether there is analytics in the child's session, how you delete the data, and which grown-up is doing the consenting. An app that answers all five clearly in its privacy policy is usually one you can trust; an app that dodges any of them is telling you something.
1. Who creates the account, the child or a grown-up?
The safest pattern is that the child never has an account at all. A grown-up creates a profile for the child, and the child signs in with something that is not an email address or a password. If an app asks a 6-year-old for an email, it is collecting personal information at the first screen.
2. Are there ads?
"No third-party ads" and "no ads" are different claims. Some apps show no outside advertising but do promote their own upgrades to the child. Look for the word "ads" in the policy and in the app's store listing, and look at what the child sees when a level ends.
3. Is there analytics in the child's session?
This is the question almost nobody asks. Many apps run an analytics or behavioral tracking library inside the child's play session to measure engagement. Under COPPA that can be personal information requiring consent, and it is often the thing you consented to without noticing. Search the policy for "analytics," "third parties," and "SDK."
4. How do I delete the data?
A good policy names the mechanism: a button in the parent dashboard, or an email address, and what happens after you ask. A policy that only says "contact us" with no detail is a weak answer.
5. Who is the consenting grown-up, and how does the app know?
COPPA's consent is verifiable parental consent. Look at what the app does to establish that a grown-up, not the child, is agreeing: an email confirmation, a card on file for paid tiers, a grown-up gate in front of settings. An app that lets anyone tap "I am a parent" has done the minimum.
| Question | Good answer | Weak answer |
|---|---|---|
| Who creates the account? | A grown-up; the child has no account | The child enters an email |
| Ads? | None, including the app's own, in the child's session | "No third-party ads" only |
| Analytics in kid sessions? | None, stated explicitly | Not mentioned |
| Data deletion? | Named mechanism and timeline | "Contact us" |
| Consent? | Grown-up verified by email or card, gated settings | A tap-through "I am over 18" |
How do you read a privacy policy in 3 minutes?
Direct answer: Do not read it top to bottom. Search it for six words (children, under 13, ads, analytics, delete, third parties), read the sentence around each hit, and stop. If the policy is long and the six words are missing or vague, that is your answer.
The three-minute method:
- Minute one: find the children's section. Search for "children" or "under 13." A kids app with no dedicated children's section is not thinking about COPPA seriously. Read that section in full; it is usually short.
- Minute two: search for "ads," "analytics" and "third parties." Each hit tells you who else gets the data. Note whether the policy says these apply to the child's session, the grown-up's account, or both. The distinction matters: analytics on a parent dashboard is ordinary; analytics inside a 5-year-old's game is not.
- Minute three: search for "delete." Find the mechanism and the timeline. Then check the "changes to this policy" section for how they will tell you when it changes.
Two red flags that survive any wording:
- The policy is a generic template that never mentions children, even though the app is clearly for them.
- The policy describes data practices that contradict the app's marketing ("no ads" on the store page, an ad network in the third-parties list).
How does TernQuest handle each of these?
Direct answer: Children never create accounts; a grown-up creates a child profile with a first name and grade. There are no ads and no analytics in kid sessions, kids sign in with a class code or a short optional PIN, grown-ups sign in by magic link with no passwords, and the full policy is at ternquest.com/privacy.
Here is our own product run through the five questions, so you can hold us to the same standard:
| Question | TernQuest |
|---|---|
| Who creates the account? | A grown-up (parent or teacher). The child profile is a first name and a grade. Children never create accounts. |
| Ads? | None. There are no ads anywhere in the app. |
| Analytics in kid sessions? | None. We describe this as COPPA-minded: a child's play session is not measured by an analytics library. |
| Data deletion? | Described in the privacy policy; the grown-up who created the profile controls it. |
| Consent? | Grown-ups sign in by magic link sent to their email, with no passwords. Kids sign in with a class code or a short optional PIN and cannot reach grown-up settings. |
Two other things a parent might want to know:
- Pip, the AI tutor, is guard-railed. Pip gives hints and never answers. Personal information in what a child types or says is scrubbed before anything reaches a model, and a grown-up can turn the AI coach off entirely from the parent controls.
- Teachers. Classrooms use join codes; the teacher creates the roster and the students never enter an email. If your district requires a FERPA "school official" arrangement, read our privacy policy and raise it with us before rolling out.
Where TernQuest is not the answer
We launched in August 2026. We have no years-long third-party audit history to point to, and a careful district vetting team is right to weigh that. If your priority is a vendor with a long compliance record, an established product is the better choice today, and we would rather you choose it than trust a new company on faith. TernQuest is also PK–5 only, so a 12-year-old needs a different tool, and the privacy questions above apply just as much to whatever you pick.
Related reading
- Screen time for kids by age: what the AAP says (2026) — the other half of choosing a kids app: how much, and when.
- Best learning apps for kids in grades K–5 (2026) — run the five questions against each app on the list.
- Why the Arctic tern? The story behind Pip — how we think about a tutor that sits beside a child.
Next step
Read ternquest.com/privacy with the three-minute method, then try TernQuest with one child; it is free to start, with no password, no ads and no child account. If the policy fails your test, tell us; that is the point of publishing it.