Kids' and edtech apps face two distinct federal regimes. COPPA (FTC-enforced) applies to any service directed to children under 13, requiring verifiable parental consent before collecting personal information — violations run up to per child, per day. FERPA (Dept. of Education) applies to schools and reaches vendors through the "school official" exception; it carries no fines and no private lawsuit right, but non-compliance means losing district contracts. AI app builders scaffold neither consent flow, and the amended COPPA Rule's full-compliance deadline lands 2026-04-22.
Get a Free Compliance Scan See Audit PricingCOPPA triggers when a service is "directed to children" under 13 (the FTC weighs subject matter, visuals, animated characters, music, child models, ads, and audience evidence), or when a general-audience service has actual knowledge it's collecting personal information from an under-13 user. "Personal information" now includes biometric identifiers under the 2025 amendments, alongside names, emails, geolocation, photos/video/audio, and persistent identifiers like cookies and device IDs.
| Law | Penalty | Notable cases |
|---|---|---|
| COPPA (FTC) | Up to per violation — each child, each day can count (2025 inflation figure, carried into 2026 after the adjustment was cancelled) | Cognosphere/Genshin M (Jan 2025); Disney M (Sept 2025, approved Dec 2025); Apitor K suspended (2025); TikTok/ByteDance suit pending (filed Aug 2024) |
| FERPA (Dept. of Ed) | No fines, no private lawsuit (Gonzaga Univ. v. Doe, 2002) — the lever is loss of federal funding and exclusion from district contracts | ED Student Privacy Policy Office can require corrective action; funding withholding has never actually been used |
| NY Education Law §2-d | first violation / second / subsequent, against contractors | Adds direct, penalizable vendor obligations FERPA itself lacks |
| California SOPIPA | AG-enforced via the Unfair Competition Law (no set penalty schedule) | Bans targeted ads, profiling, and sale of K-12 student data (effective 2016-01-01) |
Sources: federalregister.gov 2025/04/22 (amended COPPA Rule); ftc.gov (2025 civil penalty inflation adjustment, ); davispolk.com (Cognosphere); hunton.com (Disney); supreme.justia.com (Gonzaga v. Doe, 536 U.S. 273); nysenate.gov EDN §2-d; leginfo.legislature.ca.gov (SOPIPA).
| Requirement | Detail |
|---|---|
| Direct notice + privacy policy (COPPA) | Must list all data collected and every third-party recipient. |
| Verifiable parental consent (COPPA) | An approved method — signed form, payment-card or gov-ID verification, knowledge-based auth, face-match-to-ID, or a phone/video call — before collecting a child's data. |
| Separate opt-in for third-party disclosure (COPPA, new) | The amended Rule requires distinct consent before sharing a child's data for targeted ads — on top of the base VPC. |
| Written security & retention programs (COPPA, new) | A designated coordinator, annual risk assessments, and a written data-retention policy that bans indefinite retention — full compliance required by 2026-04-22. |
| School official exception (FERPA) | A vendor may access education records only if it performs a school function, stays under the school's direct control (written agreement, including deletion rights), and never re-discloses or reuses data commercially. |
| NY §2-d | Encryption of student PII in transit AND at rest, a Parents' Bill of Rights attached to every contract, employee training, and subcontractor flow-down. |
Sources: federalregister.gov/documents/2025/04/22/2025-05904; ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions; studentprivacy.ed.gov Vendor FAQ; nysenate.gov EDN §2-d.
Sources: respectlytics.com (SDK leakage, Tilting Point K 2024); support.google.com/admob/answer/6219315; studentprivacy.ed.gov Vendor FAQ; bassberry.com (amended-Rule retention/security).
| Platform | COPPA / FERPA posture |
|---|---|
| Lovable | Users must be 18+ ("not intended for under 18"); has SOC 2 Type II and GDPR/CCPA coverage, but no COPPA/FERPA mention and no student-data agreement — the app's compliance is entirely on you. |
| Bolt (StackBlitz) | SOC 2 Type II; Enterprise adds SSO/audit logs and own-tenant deploy, but no COPPA/FERPA posture or student-data agreement is published. |
| Replit | States it's "not directed to under-13" and will delete under-13 data or seek consent; historically offered Teams for Education, but whether it currently signs district or NY §2-d DPAs is unverified. |
| v0 / Vercel | Users must be 16+; GDPR/CCPA DPA available on Pro/Enterprise, but no FERPA/COPPA program or student-data agreement. |
| Supabase | SOC 2 Type 2 + HIPAA BAA on Team+, standard DPA, AES-256 encryption — supports the security prong if you implement consent, retention, and deletion yourself, but has no FERPA/COPPA-specific offering. |
| Google Workspace for Education | The gold standard — Google contractually acts as the FERPA "school official" and supports school-consent-on-behalf-of-parents for COPPA, with ISO 27001/27701/42001. |
None of the general-purpose AI builders offer a COPPA/FERPA compliance program out of the box — that layer has to be built and, for schools, contracted separately with each district.
Sources: lovable.dev/privacy; stackblitz.com/privacy-policy; replit.com/privacy-policy; vercel.com/legal/dpa; supabase.com/docs/guides/security/soc-2-compliance; workspace.google.com/terms/education_terms; cloud.google.com/security/compliance/ferpa.
Yes, if it's "directed to children" under 13 by the FTC's multi-factor test, or if it's a general-audience app with actual knowledge it's collecting personal information from an under-13 user. Persistent identifiers like device IDs and cookies count as personal information, not just names and emails.
The amended Rule (published 2025-04-22, effective 2025-06-23) adds biometrics as personal information, a separate opt-in before disclosing kids' data to third parties for targeted ads, a written information-security program, and a written data-retention policy. Full compliance is required by 2026-04-22.
No. Firebase "doesn't offer any of the functionality needed to comply with COPPA" by default — you have to actively configure it, disabling ad personalization and setting the appropriate child-directed flags, or use Google AdMob's setTagForChildDirectedTreatment(true) alongside G-rated content.
It lets a vendor access education records without separate parental consent only if it performs a school function, stays under the school's direct control via a written agreement, and doesn't re-disclose or commercially reuse the data. Skipping the written agreement breaks the exception and can get an app banned from district use.
Not directly. FERPA carries no monetary fines and no private right of action (Gonzaga Univ. v. Doe, 2002) — the Department of Education's real lever is withholding federal funding, which has never actually been used, or excluding the vendor from future district contracts. State laws like NY Education Law §2-d add real per-violation fines that FERPA itself lacks.
Yes. The FERPA school-official exception and laws like NY §2-d require a signed, district-specific student-data agreement covering permitted purposes, direct control, no re-disclosure, and deletion at contract end — a generic terms-of-service page doesn't satisfy this.
We audit AI-built apps against COPPA and FERPA — consent flows, SDK configuration, student-data agreements — and hand you a fix-it list before the 2026-04-22 deadline or a district review finds the gap.
Get a Free Compliance ScanRelated searches: COPPA compliance checklist for apps · does my app need COPPA compliance · new COPPA rule 2025 changes · COPPA fines per violation 2026 · verifiable parental consent methods COPPA · is Firebase COPPA compliant · FERPA school official exception vendor · student data privacy agreement template · NY Ed Law 2-d vendor requirements