Children’s privacy

Does COPPA apply to my app if it is not aimed at children?

It can, yes. COPPA has two independent triggers and only one of them is about who your app is aimed at. The Rule binds an operator of a website or online service directed to children under 13, and — separately — any operator with actual knowledge that it is collecting or maintaining personal information from a child. The second prong does not consider your target audience at all: once you actually know a particular user is under 13, you are inside the Rule for that user, however grown-up your product is. Deciding you are a general-audience app is therefore a decision about the first trigger only, and it does not dispose of the second. The app-store children’s policies ask a different question again, and Amazon in particular treats a mixed-audience app as child-directed by default unless the developer confirms children are not using it.

COPPA has two triggers, and they are independent

The Children’s Online Privacy Protection Rule — 16 CFR Part 312, the FTC rule implementing the 1998 Act, as amended in 2025 — makes it unlawful for two different kinds of operator to collect a child’s personal information in breach of the Part. The first is an operator of a website or online service directed to children. The second is any operator with actual knowledge that it is collecting or maintaining personal information from a child. They are joined by “or”, not by “and”. Most of the confusion about COPPA scope comes from reading only the first and treating “we are not a kids app” as the end of the analysis. It is the end of the analysis for the first trigger and irrelevant to the second.

The actual-knowledge trigger is what catches general-audience apps

Actual knowledge is a factual state, not a design intent, and it does not require you to have gone looking. If a user tells you their birthdate and it puts them under 13, if a parent emails to say their nine-year-old uses the account, if a support ticket makes it plain — you now actually know, and the Rule attaches to that user’s personal information from that point. This is why a general-audience product can be squarely outside the first trigger and squarely inside the second. It is also why the ways you might acquire that knowledge are worth designing deliberately rather than stumbling into: an age field added for an unrelated reason changes your regulatory position the moment somebody fills it in with a low number.

What being in scope actually asks of you

Once COPPA applies, the duties are concrete rather than atmospheric. You must give parents direct notice and post an online notice of your children’s information practices. You must obtain verifiable parental consent before collecting, using or disclosing a child’s personal information, subject to a defined set of exceptions. You must give a parent a reasonable means to review what was collected and to refuse its further use or maintenance. You must not condition a child’s participation in a game, a prize offering or another activity on disclosing more personal information than the activity reasonably needs. You must establish and maintain a written children’s information security programme. And you must not keep the information longer than reasonably necessary, with a written retention policy and secure deletion. Keel authors these at the Rule’s own paragraph level, so the obligation you are scored against is the paragraph, not a summary of it.

The 2025 amendments added a “mixed audience” defined term

The 2025 amendments to Part 312 added a definition of a “mixed audience website or online service”, alongside additions to the definition of personal information — biometric identifiers and government-issued identifiers among them. Keel cites the definitions section but does not score it, on the straightforward ground that you cannot comply with a definition; the defined terms do their work inside the duties that reference them. What matters practically is that the mixed-audience case is now named in the Rule rather than living only in FTC guidance, so it is worth reading the current text of §312.2 directly rather than relying on a pre-2025 summary — including this page, which deliberately does not paraphrase what that definition says.

The app stores ask a different question, and answer it differently

COPPA is US law. The Apple, Google Play and Amazon children’s rules are programme terms inside a developer agreement, and each decides its own scope on its own terms. Amazon is the one that most often surprises a general-audience developer: where an app is aimed at several audiences and one of them is children, Amazon treats it as child-directed unless the developer confirms children are not using it — child-directed is the default and the confirmation is the thing you have to evidence. Amazon also defines children as under 13, or under 16 in the European Union, Australia and Japan, together with children of any age whose personal data applicable law restricts collecting, which is wider than COPPA’s under-13 in three markets. Google’s ads, identifier and SDK rules for mixed-audience apps reach not only known children but users whose age is unknown, which is why a neutral age screen is the usual mechanism. Apple’s Kids Category duties are triggered by the category and by an app being intended primarily for kids — and once customers have come to expect the app to meet them, they persist even if the developer later deselects the category.

How to settle the question for your own app

Answer the two COPPA triggers separately and write down each answer with its reasoning. For the first, assess whether the service is directed to children on its actual characteristics rather than on your intent. For the second, inventory every place a user could tell you they are under 13 — registration, support, in-app forms, a parent’s correspondence — and decide what happens when they do. Then, separately again, run the scope test of each store you ship to, because those are contracts you can breach without ever attracting a regulator. Removal from a store is a commercial outcome that does not wait for an enforcement action. This page is a control-mapping aid and not legal advice; a scope determination with real money behind it is worth putting in front of counsel.

FAQ

If my app is rated 12+ and marketed to adults, am I outside COPPA?

Outside the first trigger, probably — but the rating and the marketing are evidence about who the service is directed to, not a safe harbour. And neither touches the second trigger. If you acquire actual knowledge that a particular user is under 13, COPPA attaches to that user’s personal information regardless of your rating, your marketing or your intent.

Does COPPA cover teenagers?

No. COPPA’s “child” is a person under 13, and the Rule is not a general children’s-privacy or teen-privacy law. Other regimes reach further: Amazon’s Appstore policy treats a child as under 16 in the European Union, Australia and Japan, and state age-appropriate-design statutes and the GDPR provisions on a child’s consent are separate regimes with their own thresholds. Scoping a programme to COPPA alone leaves those unaddressed.

We have an age gate. Does that put us outside COPPA?

Not by itself, and the mechanism matters. An age screen is a way of avoiding acquiring actual knowledge for users who say they are over 13, and of routing under-13 users into a compliant path — it is not an exemption, and it does nothing about a service that is directed to children in the first place. It is also a different mechanism from Apple’s parental gate and from COPPA’s verifiable parental consent, which are frequently conflated.

Does complying with COPPA get my app through store review?

No. COPPA is law and the store children’s policies are contracts, and each store is stricter than COPPA in places — Amazon bars its own advertising and affiliate programmes from child-directed apps outright, and says parental consent does not lift that. You need COPPA and the policy of every store you ship to. Nobody can promise a review outcome: Apple’s guidelines bind an app in their entirety and the decision is Apple’s, and Amazon reserves the final call on rejection or suppression.

Related

COPPA in Keel → What is COPPA? → Can I show ads in a kids app? → Amazon Appstore Child-Directed Apps in Keel →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free