---
title: "Research: Where the Child-Safety Handoff Breaks — Apple & Google to Apps and Ad Tech"
description: New research reveals where child-safety protections break down as responsibility shifts from Apple and Google to apps and the ad tech ecosystem—exposing gaps that put children at risk.
---

[![pixalate-logo-red-small](https://www.pixalate.com/hs-fs/hubfs/2018NewTemplate/pixalate-logo-red-small.png?width=150&height=46&name=pixalate-logo-red-small.png "pixalate-logo-red-small")](https://www.pixalate.com/?hsLang=en)

A Pixalate Know Your Developer (KYD) Research Report

# Research: Where the Child-Safety Handoff Breaks - from Apple & Google to Apps and Ad Tech

Apple and Google can identify child-configured devices, but Pixalate identified 12 large developers of child-directed apps whose ad requests did not transmit child-directed flags to ad partners—enabling downstream collection of IP address, location, and other device signals that can be used for fingerprinting.

36

Device Attributes Collected

254

Ad Platform Partners

12

Developers Reviewed

The Problem

## Structural Failures in Google & Apple Ecosystems

Apple & Google do not provide clear and reliable labeling of apps that may be child-directed across all apps, nor do they provide developers with a notification mechanism that identifies when a child-configured device is accessing the developers' apps. This gap can lead to ad SDKs (software development kits) freely collecting device identifiers, rich attributes, and other environment signals of children.

1

### Store Labelling Gaps

Apple and Google lack a universal, verified "Child-Directed" designation visible to all partners. Instead, there's patchwork system in which only some apps are clearly categorized as for-kids.

2

### Device Signal Break

Apple and Google know when a device is child-configured, but they do not automatically pass this 'Child Device' status to the apps installed on that device, leaving developers blind to who is holding the phone.

3

### Self-Declaration Cascade

Audience status is self-declared by developers and is not routinely audited by the app stores. Downstream ad platforms typically trust these flags; Pixalate commonly observes that when the COPPA flag is set to false, user data is processed as general-audience traffic.

4

### Weak Parental Controls

Age gates are easily bypassed, and apps rarely require Verifiable Parental Consent (VPC)—such as a credit card or ID check—meaning a child can grant permission to track data without a parent ever knowing.

5

### SDK Override is Rare

A few ad SDKs override missing or incorrect COPPA flags using their internal child-app lists, but most SDKs observed by Pixalate rely on developer-provided settings and do not correct these misconfigurations.

6

### Broadcasting Data in Ad Bidstream

Because the safety flags are missing, apps broadcast children's IP addresses and location data to ad partners while treating the child's device as if it belongs to an adult.

Interactive Explorer

## The Developer Portfolios

Click on any developer portfolio to explore reviewed app(s) and see which apps are at risk of transmitting children's personal information without verifiable parental consent (VPC) alongside user attributes and potential fingerprinting signals.

This research endeavors to highlight systemic child-safety risk conditions that online safety and privacy regulators have previously cited as points of contention in enforcement actions, without making specific determinations of legal compliance. No assertions or determinations are made regarding whether any identified app developer(s) or associated partner(s) is legally compliant with, or in violation of, the Children’s Online Privacy Protection Act (COPPA).

Any references to parent ownership, or majority-ownership are shared solely for the purposes of corporate context and should not be construed as implying parent-ownership level operational involvement in, or control over, app-level data processing and compliance practices.

All

🇺🇸 USA

🌏 Asia

🇪🇺 Europe

Legal Context

## KYD: Trusting Developers to Signal Child Traffic

KYD is about developer-level accountability: ad partners need developers to clearly notify them when child traffic enters the app ecosystem. Pixalate's analysis examines whether child-directed signaling parameters (e.g., the coppa=1 flag in ad requests) are transmitted alongside device and environment signals observed from these likely child-directed apps. This research does not argue that app stores are the sole responsible party, but demonstrates how current store-level design choices amplify downstream compliance failures.

### Key Precedent

**FTC v. HyperBeard Inc., No. 3:20-cv-03683 (N.D. Cal.)** [FTC Complaint link](https://www.ftc.gov/legal-library/browse/cases-proceedings/192-3109-hyperbeard-inc)

In its action involving HyperBeard, the Federal Trade Commission (FTC) alleged COPPA violations based on claims that the app developer did not adequately signal that certain apps were child-directed and failed to appropriately limit targeted advertising.

### Why It Matters

- **Required Signal & Configuration:** COPPA obligates operators to identify child-directed traffic when disclosing personal information to downstream partners. This obligation is generally operationalized via child-directed flags (e.g. coppa=1) in SDK/API calls.
- **Chain of Control:** When such signals are present, ad/attribution networks are expected to limit use to only activities permitted as “support for internal operations” under 16 C.F.R. § 312.2 and to refrain from interest-based and targeted advertising. Unflagged traffic is typically handled under general-audience assumptions.
- **Operator Liability:** If the child-directed flag is absent, downstream partners may process personal information using standard general-audience assumptions and can further build cross-app/device graphs using IP addresses, device identifiers (IDFV/IDFA), and user agent strings (UA). Under COPPA, the developer remains responsible for ensuring that the SDK configurations and third party collection practices remain compliant with the applicable COPPA requirements.

### Policy Context

As federal and state lawmakers advance proposals that would make app stores responsible for age assurance and parental consent, the [largest app-store operators have pushed back](https://www.reuters.com/legal/litigation/apple-ceo-pushes-changes-us-child-online-safety-bill-citing-privacy-concerns-2025-12-11)—warning that store-level mandates could drive broad collection and sharing of sensitive age data, and advocating approaches that rely more heavily on parental controls and developer-side implementation. Our findings highlight the core weakness in that model: when child-status or age-related signals do not propagate reliably end-to-end across the app ecosystem, shifting obligations to parents and downstream developers predictably creates enforcement gaps at the handoff points, reducing the real-world effectiveness of the protections policymakers intend.

### Practical Example

Apps transmit IP addresses, user agents, and device models to ad/attribution network partners without a child safety flag (e.g., coppa=true) and consequently treat the user as a general-audience app user. This practice also permits cross-app/device tracking that can be used to amass profiles on misidentified child app users and goes beyond COPPA’s “internal operations” limit, leaving the developer exposed due to such misconfigurations. Furthermore, under COPPA § 312.2(11), ‘information concerning the child…that the operator collects online from the child and combines with an identifier’ constitutes personal information that requires parental consent. Failing to notify downstream partners via appropriate child safety flags allows this type of tracking to proceed as if the app user were an adult, creating a significant risk of COPPA non-compliance.

Research Steps

## Methodology

### Know Your Developer (KYD)

All data is derived from Pixalate's Know Your Developer database, which provides risk ratings for 356,095 developers across Google Play and Apple App Store.

- KYD Inclusion: developer has an app-ads.txt file (a public list of authorized ad sellers, indicating ad-funded inventory)
- KYD inventories all apps under each in-scope developer (3,179,949 apps)
- Risk is computed at the developer level

### Selection Criteria

- From 356,095 developers, manually reviewed 664 largest (≥1B estimated total lifetime users)
- Identified 123 developers majority-owned by publicly traded companies
- Manually tested 12 of the most popular apps from the 123 developers lacking VPC, per manual review from Pixalate's Trust & Safety Advisory Board, downloadable as of November 2025 on a child-device

### Legal Framework

Under COPPA, IP addresses, geolocation, and other persistent identifiers constitute personal information. Operators collecting children's personal information must obtain Verifiable Parental Consent (VPC) prior to any collection of personal information.

All 12 in-scope apps are likely child-directed, have U.S.-based traffic, did not observe VPC during testing, and transmit IP and/or geolocation coordinates in the programmatic advertising bidstream, according to Pixalate's data.

Disclaimer

Pixalate’s Mobile Application Know Your Developer Ratings (“KYD”) reflect Pixalate’s opinions that Pixalate believes may be useful to parents, guardians, educators, regulators, researchers, and participants in the digital media industry. Any data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements, affiliations, or associations with any third-parties. Pixalate is sharing this data not to impugn the standing or reputation of any entity, person or app, but, instead, to report research findings and trends pertaining to the time period studied.

It is important to note however, that classification of a mobile application developer (“app developer”) within a particular risk tier does not mean that the app developer, its applications, or any associated practices are in violation of any laws or regulations, including the Children’s Online Privacy Protection Act (COPPA) or any other global privacy framework. Further, the app(s) of an app developer(s) that appear(s) to be directed to children (e.g., users under 13 years of age, as defined by the COPPA Rule) does not mean that any such app, or its operator, is failing to comply with the COPPA Rule.

Pixalate’s determinations are based on a proprietary methodology that incorporates a combination of signals and automated processes. Additionally, with respect to app developers that appear to have characteristics that, in Pixalate’s opinion, may trigger related privacy law or regulatory compliance obligations and/or risk, such assertions reflect Pixalate’s opinions i.e., they are neither facts nor guarantees. While Pixalate endeavours to apply rigorous standards in compiling this KYD, no assurances or guarantees can be, or are, made as to the accuracy or completeness of any classification. This article/expose, including all content set forth herein–constitutes Pixalate “Materials” under Pixalate’s [Terms of Use](https://www.pixalate.com/terms?hsLang=en), and is licensed subject to–and conditioned expressly upon–compliance with each of the applicable terms and conditions of such Pixalate Terms of Use. Per the [MRC](https://mediaratingcouncil.org/sites/default/files/Standards/081815%20Viewable%20Ad%20Impression%20Guideline_v2.0_Final.pdf), “'Fraud' is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes. Also per the [MRC](https://mediaratingcouncil.org/sites/default/files/Standards/IVT%20Addendum%20Update%20062520.pdf), “‘Invalid Traffic’ is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.”.

Apple and the Apple logo are trademarks of Apple Inc; Google, Google Ad Exchange, the brand “Google Play,” its logos, and other Google logos are trademarks of Google LLC. These companies are not affiliated with, nor do they endorse or sponsor, any products, data, content, reports, materials or services associated with Pixalate. Any other brand logos, names, or trademarks not explicitly mentioned herein – but otherwise mentioned, displayed, or used in any of Pixalate’s materials, including this report – are the property of their respective owners.

Close

## Something Powerful

### Tell The Reader More

The headline and subheader tells us what you're [offering](https://www.pixalate.com/investigations/child-online-safety-coppa-compliance-apple-google-app-developers-december-2025#), and the form header closes the deal. Over here you can explain why your offer is so great it's worth filling out a form for.

Remember:

- Bullets are great
- For spelling out [benefits](https://www.pixalate.com/investigations/child-online-safety-coppa-compliance-apple-google-app-developers-december-2025#) and
- Turning visitors into leads.

## Schedule a Demo

Interested in learning more about Pixalate’s ad fraud prevention solutions? Let’s connect. Share your challenges, and our team will be in touch shortly. Thank you for reaching out.

---

[** ](https://www.facebook.com/pixalate) [** ](https://twitter.com/pixalateinc) [** ](https://www.linkedin.com/company/pixalate)

![pixalate-logo-red-small](https://www.pixalate.com/hs-fs/hubfs/2018NewTemplate/pixalate-logo-red-small.png?width=208&name=pixalate-logo-red-small.png "pixalate-logo-red-small")

**

 By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms?hsLang=en) and [Privacy Policy](https://www.pixalate.com/privacypolicy?hsLang=en)

Products

[Analytics](https://www.pixalate.com/products/analytics?hsLang=en) [Blocking](https://www.pixalate.com/products/blocking?hsLang=en) [Media Rating Terminal](https://www.pixalate.com/products/mrt?hsLang=en) [Publisher Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex&hsLang=en) [Seller Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex&hsLang=en) [IoT Device Rankings](https://www.pixalate.com/rankings/?group=app&reportId=iotDeviceReach&hsLang=en)

Resources

[Blog](https://blog.pixalate.com/?hsLang=en) [Press](https://www.pixalate.com/press?hsLang=en) [Careers](https://www.pixalate.com/jobs?hsLang=en) [Team](https://info.pixalate.com/pixalate-leadership-team?hsLang=en)

Contact

Email

[** sales@pixalate.com ](mailto:sales@pixalate.com)

[** privacy@pixalate.com ](mailto:privacy@pixalate.com)

US:

[** +1 888 749 2528 ](tel:+1%20888%20749%202528)

EU:

[** +44 (0)800 011 2050 ](tel:+44%20(0)800%20011%202050)

Slack:

[Join ATSAPI Slack Channel ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

Offices

Global Offices

US

1775 Greensboro Station Place, Suite 425, McLean, VA 22102

UK

20 North Audley Street   
London, W1K 6WE, United Kingdom

EU

10 Earlsfort Terrace   
Dublin 2, D02 T380, Ireland

Singapore

10 Anson Road, #22-02 International Plaza, Singapore 079903

[![facebook](https://www.pixalate.com/hubfs/footer/icons/facebook.png) ](https://www.facebook.com/pixalate) [![x](https://www.pixalate.com/hubfs/footer/icons/twitter-x.png) ](https://twitter.com/pixalateinc) [![linkedin](https://www.pixalate.com/hubfs/footer/icons/linkedin.png) ](https://www.linkedin.com/company/pixalate) ![wechat](https://www.pixalate.com/hubfs/footer/icons/wechat.png) [![slack](https://www.pixalate.com/hubfs/footer/icons/slack.png) ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

[Terms of Use](https://www.pixalate.com/terms?hsLang=en) [Privacy Policy](https://www.pixalate.com/privacypolicy?hsLang=en) [GDPR Compliance](https://www.pixalate.com/gdpr?hsLang=en) Disclaimer

Copyright © 2025 Pixalate

[Back to top **](https://www.pixalate.com/investigations/child-online-safety-coppa-compliance-apple-google-app-developers-december-2025#)

# Disclaimer

 Disclaimer: The content of this page reflects Pixalate’s opinions with respect to the factors that Pixalate believes can be useful to the digital media industry. Any proprietary data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate’s opinions are just that - opinion, not facts or guarantees.

 Per the MRC, “'Fraud' is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes. Also per the MRC, “‘Invalid Traffic’ is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.”

**

**

*By clicking Download and entering your email address, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms?hsLang=en) and have read and acknowledge our [Privacy Policy](https://www.pixalate.com/hubfs/2024-08-20_Pixalate_Privacy_Policy.pdf?hsLang=en).

*Copyright © 2025 Pixalate** *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

*

*

* *

* *