Kids apps & mobile games

Four children’s rulebooks, and they disagree

A studio shipping a kids app or a family game to more than one store is subject to COPPA and to Apple’s, Google Play’s and Amazon’s children’s rules at the same time. COPPA is law. The other three are contracts inside a developer agreement — and satisfying COPPA satisfies none of them.

Start free Which ad SDK can I use? →

Why this is not one project

The three stores do not define a child the same way, do not permit advertising on the same terms, and do not agree on what puts you in scope. There is no single ad configuration that ships on all three: Amazon bars its own advertising and affiliate programmes in child-directed apps outright and parental consent does not lift that, while Apple and Google each leave contextual advertising available but qualify the supplier differently. Plan per store, and keep the law separate from the contracts.

Where the four rulebooks disagree

Summarised from the requirements Keel authors for each. Follow any column into its framework page for the full scope, including what Keel does not model.

COPPA Apple App Store Google Play Amazon Appstore
What it is US federal law — the FTC’s Children’s Online Privacy Protection Rule, 16 CFR Part 312. Contract. Programme terms inside a developer agreement, revised in place without notice. Contract. Programme terms inside a developer agreement, revised in place without notice. Contract. Programme terms inside a developer agreement, revised in place without notice.
Who counts as a child Under 13. Duties are triggered by the Kids Category, by an app intended primarily for kids, or by handling a minor’s data. The Kids Category age bands are 5 and under, 6–8, and 9–11. The children in your declared target audience — and the ads and identifier rules reach users whose age is unknown as well, not only known children. Under 13, or under 16 in the European Union, Australia and Japan, plus children of any age whose personal data applicable law restricts collecting. Wider than COPPA’s band.
What puts you in scope Operating a service directed to children under 13, or having actual knowledge you collect personal information from a child. Selecting the Kids Category — and once customers expect the app to meet those requirements, updates must keep meeting them even if you later deselect the category. The target audience you declare in Play Console. Google reserves the right to reach its own conclusion: imagery and terminology that read as targeting children can be assessed differently from your declaration. A multi-audience app is treated as child-directed unless the developer confirms children are not using it. Child-directed is the default; the confirmation is the thing you evidence.
Third-party advertising Not addressed as advertising. COPPA governs collecting, using and disclosing a child’s personal information, gated by notice to the parent and verifiable parental consent. Excluded by default. Permitted in limited cases only where it is contextual and the ad service publicly documents Kids Category practices that include human review of ad creatives. Separately, any advertising displayed must be human-reviewed for age appropriateness — which reaches your own house ads. Only from a Families Self-Certified Ads SDK, and certification is per version, not per vendor. No interest-based advertising and no remarketing. In-house cross-promotion of your own apps, media or merchandise, and direct deals where the SDK only manages inventory, sit outside the self-certification requirement. No ads through any Amazon Advertising programme or Amazon Associates to anyone you know to be a child, or anywhere in a child-directed area — and parental consent does not lift it. An app directed only at children may not use those programmes at all.
SDKs and analytics Personal information collected through your service is yours to notice, consent for, secure and delete when it is no longer needed. Third-party analytics excluded by default, with a narrow carve-out for services that transmit neither the advertising identifier nor anything identifying children, their location or their devices. Separately, no personally identifiable or device information may go to third parties — a rule that reaches sections intended for adults, with explicit parental consent the only stated route through. A child-only app may contain only APIs and SDKs approved for child-directed services — a question answered in the dependency’s terms, not its behaviour. A mixed-audience app may use an unapproved SDK only behind a neutral age screen, or implemented so it collects no data from children, and may never make it the only path to content. In a child-only app, every SDK that collects personal information must be child-suitable. No SDK whose own terms of service forbid use in child-directed apps, however it is configured. A mixed-audience app may use a non-child-suitable SDK only behind reasonable age measures.
Device identifiers and location A persistent identifier is personal information under the Rule, so collecting one engages the notice and consent duties — unless a narrow exception applies, such as an identifier collected for the sole purpose of supporting internal operations, with the notice that exception requires. Covered by the third-party transfer rule above: device information may not be sent to third parties, whatever the SDK’s stated purpose. A child-only app must not transmit the AAID, SIM serial, Build serial, BSSID, MAC, SSID, IMEI or IMSI, must not declare the AD_ID permission when targeting API level 33 or above, and must not request or collect precise location. In a mixed-audience app the transmission ban covers users of unknown age too. Governed through the SDK rules above rather than a named identifier list.
How you know it changed Amended by rulemaking and published. Keel models the Rule as amended in 2025. No version number and no change log for the Kids Category rules. Keel carries the date it retrieved the source pages instead. No version number and no change log. Keel carries the retrieval date instead. Google’s replacement Families policy has an effective date of 26 August 2026. No version number. Amazon prints a last-updated date, which the other two do not; Keel carries both that and its own retrieval date.

Store policies are rewritten in place without notice. Keel models each against the text it retrieved, carries that retrieval date in place of a version number, and re-checks the published sources monthly. Check the live policy before you rely on any of this for a submission.

What Keel does about it

Four frameworks, not one blended one

Each store is its own scored framework, so a studio shipping only to Google Play is never scored against Apple’s rules. Blending them into a single “children’s privacy” checklist would hide exactly the disagreements this page is about.

One add-on, one framework slot

COPPA, plus every app-store children’s programme Keel ships, on one add-on and one framework slot. It is one add-on — Children’s Privacy, $39/mo, bought once through COPPA — covering: COPPA, Google Play Families, Amazon Appstore Child-Directed Apps, Apple App Store Kids Category . Applying them spends one of your plan’s included framework slots, not four, so the rest stay free for SOC 2 or ISO 27001.

The overlap is done once

Every pair of these frameworks shares canonical controls — between 4 and 7 of them — so a control you implement for one counts toward the others it satisfies. The mappings are published, pair by pair: Apple App Store Kids Category & Google Play Families · Apple App Store Kids Category & COPPA · COPPA & Google Play Families · Amazon Appstore Child-Directed Apps & Google Play Families · Amazon Appstore Child-Directed Apps & Apple App Store Kids Category · Amazon Appstore Child-Directed Apps & COPPA .

A retrieval date instead of a fake version

None of the three store policies carries a version number, so Keel does not invent one: each framework records the date its source pages were retrieved, and a monthly monitor re-fetches those published pages and reports a change for a human to read. It never edits framework content on its own — a policy change is exactly the case where somebody has to decide what moved.

You can see the denominator

Each framework page publishes how much of its source Keel models, the scope rule it is complete against, and the authority that scope was checked from. A readiness percentage is only meaningful against a denominator you can read.

What Keel does not claim

Keel does not predict store review outcomes and does not try to. Apple decides App Review, and its guidelines bind an app in their entirety rather than only its children’s rules; Amazon expressly reserves the final decision on whether an app is rejected or suppressed. These frameworks are control-mapping aids for running the programme behind a submission. They are not legal advice.

Common questions

If we comply with COPPA, can we ship to the stores?

No. COPPA is US law and the three store rulebooks are contracts, and each store is stricter than COPPA somewhere. Amazon treats a child as under 13, or under 16 in the European Union, Australia and Japan. Apple excludes third-party analytics and advertising from the Kids Category by default. Google requires ads to children or unknown-age users to come from a self-certified ads SDK version. You need COPPA and the policy of every store you ship to.

Is there one ad setup that works on all three stores?

No. Amazon is the binding constraint: its bar on serving ads through Amazon Advertising or Amazon Associates in a child-directed context is absolute, parental consent does not lift it, and an app directed only at children may not use those programmes at all. Apple and Google both leave contextual advertising available but qualify the supplier differently — Google by a per-version SDK certification on its published list, Apple by the ad service publicly documenting Kids Category practices that include human review of creatives. The same build can satisfy one and not the other.

Can we get out of the Kids Category rules by leaving the category?

Not on Apple. Once customers have come to expect the app to meet the Kids Category requirements, later updates must continue to meet them, and Apple states that this holds even if the developer deselects the category. Apple also applies its analytics and advertising limits to apps intended primarily for kids whether or not they sit in the category.

Do we have to buy four framework add-ons?

No. COPPA, plus every app-store children’s programme Keel ships, on one add-on and one framework slot. Buying the COPPA add-on grants the rest, and applying all of them still spends one of your plan's included framework slots.

Will Keel tell us whether our app will be approved?

No, and it will not imply it. Apple decides App Review outcomes and its guidelines bind an app in their entirety, not only the children’s rules; Amazon expressly reserves the final call on whether an app is rejected or suppressed. Keel’s frameworks are control-mapping aids for running the programme behind a submission — not legal advice, and not a prediction of any store’s review decision.

Go deeper

Does COPPA apply to my app if it is not aimed at children? · Can I show ads in a kids app, and which ad SDK can I use? · What happens if my kids app collects an advertising ID? · Do I need a parental gate, an age screen, or parental consent?

Frameworks: COPPA · Google Play Families · Amazon Appstore Child-Directed Apps · Apple App Store Kids Category · Crosswalk explorer

Start free See pricing

Apple, App Store, Google Play, Amazon Appstore and the framework names above are referenced factually for guidance. Keel is not affiliated with, or endorsed by, Apple, Google, Amazon or the bodies that publish these rules. See our legal and trademarks page.