Five Minute Security
Family Firewall

What Data Do Children’s Educational Apps Collect?

What Data Do Children’s Educational Apps Collect?
This article investigates the hidden privacy risks of school-issued educational apps. Written by a former threat analyst, it examines what data EdTech platforms collect—from device identifiers to behavioral profiles—often before children even interact with them. It provides practical guidance for parents on asking the right questions, separating school accounts from personal ones, and protecting their household's digital privacy.

The Moment I Started Paying Attention

It was a Thursday evening in November. Ella was sitting at the kitchen table with her school Chromebook, working on a math assignment. I walked past and glanced at the screen—she was using an educational app I’d never heard of.

I asked: "What's that?"

"It's for math. We use it in class sometimes. It's fun."

I watched for a minute. She was answering questions, earning stars, moving through levels. The app was colorful and engaging. It looked harmless.

Then I looked at the browser address bar. And I noticed the URL wasn't from her school's domain. It was from a third-party platform.

That night, I started looking into what educational apps actually collect. The findings surprised me—and I'm a cybersecurity professional.

I realized that the apps Ella uses at school might be collecting more than just her math scores.

A child using a school laptop at a dining room table while a parent looks on.

Why This Matters for Families

Before I get into the data, let me be clear about one thing: this isn't about panic. I'm not writing this post to scare parents or to tell you to pull your child out of digital learning.

I'm writing this because most parents don't know what's happening when their child uses an educational app. And I believe you deserve to know.

Here's the simple truth:

  • Educational technology (EdTech) is a massive commercial industry

  • Many school-approved apps collect data that goes beyond educational purposes

  • Some of this data is shared with advertisers and analytics companies

  • Privacy policies are often written at a level most parents can't understand

  • What an app says in its privacy policy doesn't always match what it actually does

The goal isn't to make you afraid. The goal is to make you aware.


The Data That Educational Apps Actually Collect

Let me walk you through what research has found about educational apps. I'm drawing on several studies—one from the University of New South Wales that audited nearly 200 educational apps , another from Utah that examined network traffic from 100 apps used in schools .

What They Collect

Here's what these apps typically collect:

Data Type

What It Includes

Why It Matters

Personal identifiers

Student name, date of birth, grade level, school, teacher name, email address

This is the baseline—it identifies who the child is

Device identifiers

Unique codes that track a device across sessions and across different apps

These are like a digital fingerprint that follows the child

Persistent identifiers

Identifiers that can track a device across different apps and sessions

83.6% of educational apps transmit these

Usage data

Time spent on each question, pages visited, answers given, login/logout times

This is performance and behavioral data that builds a detailed profile

Behavioral data

Click patterns, hesitation times, interaction patterns

This goes beyond academic performance—it's about how the child thinks

Location data

City-level or more precise location

Even without GPS, apps can infer general location from IP addresses

Third-party tracking data

Sent to analytics platforms like Google's Firebase, Facebook, Unity Analytics

These services track behavior for purposes beyond education

Advertising data

Information shared with advertisers

36% of tested apps shared data with advertisers

When They Start Collecting

This is the part that surprised me the most.

A study of nearly 200 educational apps found that 89.3% began transmitting data to third parties before a user had interacted with the app at all .

Just opening the app was enough to send device identifiers, location metadata, and other sensitive information to analytics platforms and advertising networks .

The quote from the researcher:

"Even if you are not interacting with the app—you just open it and that's it—it is still transferring lots of data." — Dr Rahat Masood, UNSW cybersecurity expert

The data being transmitted includes telemetry data—tracker-related identifiers used for the automatic collection and transmission of data to remote servers. Despite just opening the app and not using any educational feature, the app is still transferring enough information to identify the device .

Where the Data Goes

The data isn't staying in the app.

Researchers found that:

  • 83.6% of apps transmitted persistent identifiers—unique codes that can track a device across sessions and different apps

  • 67.9% of apps contained at least one embedded tracker or analytics tool, such as Google's Firebase, Facebook SDK, or Unity Analytics

  • These tracking tools serve no educational purpose

  • 61% of tested apps shared student data with third parties

  • 36% transmitted data to advertising platforms

  • Some individual apps communicated with 32, 33, or 54 separate advertising entities

The concern: Your child's educational app may be using the same tracking infrastructure as commercial entertainment apps—the same tools used to track adults across the internet .


The Privacy Policy Problem

Here's another issue: most parents can't understand the privacy policies.

Research found that only 3% of educational app privacy policies were written at a level considered "fairly easy" to read—meaning accessible to someone with a tertiary-level education .

The remaining 97% required university-level literacy or higher .

"Nobody will understand these terminologies and jargon." — Dr Rahat Masood

Even if you can read the policy, it often doesn't match what the app actually does.

Researchers found that only about one in four apps were fully consistent between their stated privacy policy and their observed behavior during testing .

Specific examples:

  • One app listed in its store description as "Data Not Collected" was observed initializing Firebase analytics and transmitting persistent identifiers the moment it launched

  • Another app stating "no ads, no tracking" was found to be sending data to Unity Analytics and Google before a user had done anything

Some of the policies appear to have been generated using AI tools .


Why This Gets Worse

The "Illusion of Safety"

Apps marketed to children aren't necessarily safer.

Researchers found that apps marketed to young children—with names or descriptions containing words like "Kids," "Preschool," or "ABC"—were no safer than general-audience apps .

In some cases, they were worse. 76% of apps targeted at children showed at least one form of policy distortion, compared with 67% of general educational titles .

The research paper described this as "the illusion of safety"—child-centric branding cultivates parental trust without providing genuine protection .

The researchers found that apps carrying child-friendly names often embedded the same advertising and analytics tools found in commercial entertainment apps—in some cases, the same tools used to track adults across the internet .

COPPA Isn't a Silver Bullet

COPPA exists. But it's not a perfect protection.

The Children's Online Privacy Protection Act (COPPA) bans online companies from collecting children's personal data without parental consent . The Federal Trade Commission can enforce it. But the reality is that:

  • There's limited enforcement capacity

  • Many apps are still collecting data that may violate COPPA

  • School authorization creates a loophole—schools can consent on behalf of parents for educational data uses

School authorization: Under COPPA, schools may act as the parent's agent and consent to the collection of student information on the parent's behalf . This means schools can approve apps without parents ever giving explicit consent .

The FTC has clarified that while schools may consent on behalf of parents for educational data uses, schools cannot bind parents to a vendor's extraneous terms . But this still means many apps are used in schools without parents ever being asked.


What the Research Told Researchers About Compliance

From the Utah study:

  • 52% of apps with Data Privacy Agreements collected at least one student data element that was not permitted under the agreement

  • Some apps were collecting unique persistent identifiers that could be used for tracking and behavioral profiling

  • Vendors fell into three categories: those fully compliant, those who didn't realize they were breaking the law, and those who knew what they were doing and ignored requests

The Utah study led to new state legislation—H.B. 55, Privacy Compliance for Education Technology Vendors, which took effect July 1, 2026 . It requires educational entities to include specific student-data protections in vendor contracts, notify vendors of unauthorized use of student data, and terminate contracts when a vendor doesn't remedy a confirmed privacy violation .

But not every state has this kind of oversight.


What Parents Can Actually Do

I know this information is a lot. But here's what I want you to take away: you don't need to become a privacy expert to protect your child.

Here are practical steps you can take:

1. Ask the School Questions

Start with these:

  • What educational apps and platforms is my child using?

  • What data does each platform collect?

  • Is this data shared with third parties? If so, with whom?

  • Are these apps COPPA-compliant?

  • Can I review or request deletion of my child's data?

You can use a template like this:

"Hi [Teacher or School Admin],

Our daughter [Name] uses an educational app called [Platform Name] in class. Could you tell me what data this platform collects and whether that data is shared with any third parties? We're just trying to understand what protections are in place for student data."

This isn't being difficult. It's being informed.

2. Check the Apps Your Child Uses

Look for:

  • The app's privacy policy. If it's unreadable, that's a red flag

  • What the app collects

  • Whether it shares data with third parties

  • Whether it uses advertising or tracking tools

You might be surprised. I looked up the app Ella was using and found it was collecting more than I expected.

3. Use Separation Between School and Personal Accounts

This is one of the most practical things you can do.

The rule:

  • School accounts are for school

  • Personal accounts are for personal

  • Never the two shall meet

If your child uses a personal Gmail account to log into a school platform, that platform now has a link to your family's personal data. Keep them separate.

4. Use Pseudonyms When Possible

Some educational apps let educators use pseudonyms for students—names that aren't tied to personally identifiable information . Ask your school if this is an option.

5. Ask About Data Deletion

When your child leaves the school or the app is no longer needed, ask what happens to their data. It should be deleted. If it's not, that's a concern.

A father focused on reviewing online security settings on a laptop at a clean home desk.

The Bigger Picture

Here's what I want you to remember:

Your child's school-approved educational app might be collecting more than just academic performance data.

It might be collecting behavioral data, device identifiers, and sharing information with advertisers.

This isn't necessarily malicious—often it's just the way the tech ecosystem works. But it's something parents should know about.

The goal isn't to pull your child out of school. It's to be aware, ask questions, and make informed decisions.


Next Week: I'll walk through the anatomy of a phishing message—how attackers use leaked email addresses to build convincing scams, and how to spot them before it's too late.


Dave C. — Five minutes now beats five hours later.

Revised · 2026-09-18 16:08
Margin Notes

No notes on this sheet yet.

Add a Note
© 2026 The Five Minute Security. All rights reserved. drawn by hand