The Moment I Started Paying Attention
It was a Thursday evening in November. Ella was sitting at the kitchen table with her school Chromebook, working on a math assignment. I walked past and glanced at the screen—she was using an educational app I’d never heard of.
I asked: "What's that?"
"It's for math. We use it in class sometimes. It's fun."
I watched for a minute. She was answering questions, earning stars, moving through levels. The app was colorful and engaging. It looked harmless.
Then I looked at the browser address bar. And I noticed the URL wasn't from her school's domain. It was from a third-party platform.
That night, I started looking into what educational apps actually collect. The findings surprised me—and I'm a cybersecurity professional.
I realized that the apps Ella uses at school might be collecting more than just her math scores.

Why This Matters for Families
Before I get into the data, let me be clear about one thing: this isn't about panic. I'm not writing this post to scare parents or to tell you to pull your child out of digital learning.
I'm writing this because most parents don't know what's happening when their child uses an educational app. And I believe you deserve to know.
Here's the simple truth:
Educational technology (EdTech) is a massive commercial industry
Many school-approved apps collect data that goes beyond educational purposes
Some of this data is shared with advertisers and analytics companies
Privacy policies are often written at a level most parents can't understand
What an app says in its privacy policy doesn't always match what it actually does
The goal isn't to make you afraid. The goal is to make you aware.
The Data That Educational Apps Actually Collect
Let me walk you through what research has found about educational apps. I'm drawing on several studies—one from the University of New South Wales that audited nearly 200 educational apps , another from Utah that examined network traffic from 100 apps used in schools .
What They Collect
Here's what these apps typically collect:
Data Type | What It Includes | Why It Matters |
|---|---|---|
Personal identifiers | Student name, date of birth, grade level, school, teacher name, email address | This is the baseline—it identifies who the child is |
Device identifiers | Unique codes that track a device across sessions and across different apps | These are like a digital fingerprint that follows the child |
Persistent identifiers | Identifiers that can track a device across different apps and sessions | 83.6% of educational apps transmit these |
Usage data | Time spent on each question, pages visited, answers given, login/logout times | This is performance and behavioral data that builds a detailed profile |
Behavioral data | Click patterns, hesitation times, interaction patterns | This goes beyond academic performance—it's about how the child thinks |
Location data | City-level or more precise location | Even without GPS, apps can infer general location from IP addresses |
Third-party tracking data | Sent to analytics platforms like Google's Firebase, Facebook, Unity Analytics | These services track behavior for purposes beyond education |
Advertising data | Information shared with advertisers | 36% of tested apps shared data with advertisers |
When They Start Collecting
This is the part that surprised me the most.
A study of nearly 200 educational apps found that 89.3% began transmitting data to third parties before a user had interacted with the app at all .
Just opening the app was enough to send device identifiers, location metadata, and other sensitive information to analytics platforms and advertising networks .
The quote from the researcher:
"Even if you are not interacting with the app—you just open it and that's it—it is still transferring lots of data." — Dr Rahat Masood, UNSW cybersecurity expert
The data being transmitted includes telemetry data—tracker-related identifiers used for the automatic collection and transmission of data to remote servers. Despite just opening the app and not using any educational feature, the app is still transferring enough information to identify the device .
Where the Data Goes
The data isn't staying in the app.
Researchers found that:
83.6% of apps transmitted persistent identifiers—unique codes that can track a device across sessions and different apps
67.9% of apps contained at least one embedded tracker or analytics tool, such as Google's Firebase, Facebook SDK, or Unity Analytics
These tracking tools serve no educational purpose
61% of tested apps shared student data with third parties
36% transmitted data to advertising platforms
Some individual apps communicated with 32, 33, or 54 separate advertising entities
The concern: Your child's educational app may be using the same tracking infrastructure as commercial entertainment apps—the same tools used to track adults across the internet .
The Privacy Policy Problem
Here's another issue: most parents can't understand the privacy policies.
Research found that only 3% of educational app privacy policies were written at a level considered "fairly easy" to read—meaning accessible to someone with a tertiary-level education .
The remaining 97% required university-level literacy or higher .
"Nobody will understand these terminologies and jargon." — Dr Rahat Masood
Even if you can read the policy, it often doesn't match what the app actually does.
Researchers found that only about one in four apps were fully consistent between their stated privacy policy and their observed behavior during testing .
Specific examples:
One app listed in its store description as "Data Not Collected" was observed initializing Firebase analytics and transmitting persistent identifiers the moment it launched
Another app stating "no ads, no tracking" was found to be sending data to Unity Analytics and Google before a user had done anything
Some of the policies appear to have been generated using AI tools .
Why This Gets Worse
The "Illusion of Safety"
Apps marketed to children aren't necessarily safer.
Researchers found that apps marketed to young children—with names or descriptions containing words like "Kids," "Preschool," or "ABC"—were no safer than general-audience apps .
In some cases, they were worse. 76% of apps targeted at children showed at least one form of policy distortion, compared with 67% of general educational titles .
The research paper described this as "the illusion of safety"—child-centric branding cultivates parental trust without providing genuine protection .
The researchers found that apps carrying child-friendly names often embedded the same advertising and analytics tools found in commercial entertainment apps—in some cases, the same tools used to track adults across the internet .
COPPA Isn't a Silver Bullet
COPPA exists. But it's not a perfect protection.
The Children's Online Privacy Protection Act (COPPA) bans online companies from collecting children's personal data without parental consent . The Federal Trade Commission can enforce it. But the reality is that:
There's limited enforcement capacity
Many apps are still collecting data that may violate COPPA
School authorization creates a loophole—schools can consent on behalf of parents for educational data uses
School authorization: Under COPPA, schools may act as the parent's agent and consent to the collection of student information on the parent's behalf . This means schools can approve apps without parents ever giving explicit consent .
The FTC has clarified that while schools may consent on behalf of parents for educational data uses, schools cannot bind parents to a vendor's extraneous terms . But this still means many apps are used in schools without parents ever being asked.
What the Research Told Researchers About Compliance
From the Utah study:
52% of apps with Data Privacy Agreements collected at least one student data element that was not permitted under the agreement
Some apps were collecting unique persistent identifiers that could be used for tracking and behavioral profiling
Vendors fell into three categories: those fully compliant, those who didn't realize they were breaking the law, and those who knew what they were doing and ignored requests
The Utah study led to new state legislation—H.B. 55, Privacy Compliance for Education Technology Vendors, which took effect July 1, 2026 . It requires educational entities to include specific student-data protections in vendor contracts, notify vendors of unauthorized use of student data, and terminate contracts when a vendor doesn't remedy a confirmed privacy violation .
But not every state has this kind of oversight.
What Parents Can Actually Do
I know this information is a lot. But here's what I want you to take away: you don't need to become a privacy expert to protect your child.
Here are practical steps you can take:
1. Ask the School Questions
Start with these:
What educational apps and platforms is my child using?
What data does each platform collect?
Is this data shared with third parties? If so, with whom?
Are these apps COPPA-compliant?
Can I review or request deletion of my child's data?
You can use a template like this:
"Hi [Teacher or School Admin],
Our daughter [Name] uses an educational app called [Platform Name] in class. Could you tell me what data this platform collects and whether that data is shared with any third parties? We're just trying to understand what protections are in place for student data."
This isn't being difficult. It's being informed.
2. Check the Apps Your Child Uses
Look for:
The app's privacy policy. If it's unreadable, that's a red flag
What the app collects
Whether it shares data with third parties
Whether it uses advertising or tracking tools
You might be surprised. I looked up the app Ella was using and found it was collecting more than I expected.
3. Use Separation Between School and Personal Accounts
This is one of the most practical things you can do.
The rule:
School accounts are for school
Personal accounts are for personal
Never the two shall meet
If your child uses a personal Gmail account to log into a school platform, that platform now has a link to your family's personal data. Keep them separate.
4. Use Pseudonyms When Possible
Some educational apps let educators use pseudonyms for students—names that aren't tied to personally identifiable information . Ask your school if this is an option.
5. Ask About Data Deletion
When your child leaves the school or the app is no longer needed, ask what happens to their data. It should be deleted. If it's not, that's a concern.

The Bigger Picture
Here's what I want you to remember:
Your child's school-approved educational app might be collecting more than just academic performance data.
It might be collecting behavioral data, device identifiers, and sharing information with advertisers.
This isn't necessarily malicious—often it's just the way the tech ecosystem works. But it's something parents should know about.
The goal isn't to pull your child out of school. It's to be aware, ask questions, and make informed decisions.
Next Week: I'll walk through the anatomy of a phishing message—how attackers use leaked email addresses to build convincing scams, and how to spot them before it's too late.
Dave C. — Five minutes now beats five hours later.
No notes on this sheet yet.