COPPA Ad Review for Child-Directed Apps and Games

Camille DelacroixProNew0 orders on this service
Ad Compliance and Legal · Children's privacy (COPPA) ad review

Instrumented teardown of the shipped build: which ad SDKs fire before consent, what identifier leaves, and the child-directed determination in writing.

About this service

Since 22 April 2026, consent to run your app and consent to disclose a child's personal information to advertising partners are two separate acts under the amended COPPA Rule. One parental verification covering both no longer works. Neither does a privacy notice saying data is kept as long as necessary: the amended Rule requires a written retention policy, published, with a stated purpose and an end, and indefinite retention is gone. What I look at: The shipped build, not the documentation. I take the production APK and IPA, list every embedded SDK with its version, then run the build on an instrumented device behind a proxy and record what leaves it in the first sixty seconds from a cold install, before any screen is touched. That capture is the finding. Ad and analytics SDKs commonly initialise in Application.onCreate, ahead of whatever consent screen the product team believes gates them, and they take the advertising identifier with them. Then the configuration meant to prevent exactly that. Whether tagForChildDirectedTreatment and tagForUnderAgeOfConsent are set before the mobile ads SDK initialises rather than after. Whether the equivalent flags in each mediation partner and each bidding adapter are set at all, since adapters are configured separately and are where this usually breaks. Whether your Play Families self-certification and declared ad SDK list match the SDKs actually present in the binary. Whether the build meets Apple's Kids Category rules on third-party analytics and advertising. The determination: Child-directed, mixed-audience or general-audience is the decision everything else hangs from, and it is made against the FTC's factors, which are subject matter, visual and audio content, characters, music, the advertising you already run, and your own audience evidence. Not against your intended audience. I write it down with the reasoning so it is a defensible position rather than an assumption nobody wants to own. Where the honest answer is mixed audience, the age screen has to be neutral and non-incentivising, and most of the ones I capture are neither. Deliverable: A per-SDK table of what fires, when, carrying which identifier, to which endpoint. The determination memo. The changes ranked by exposure with the code-level change named for each rather than described. A retention policy drafted against the amended Rule. The separate-consent flow specified wherever third-party advertising disclosure stays in scope. Not included: Verifiable parental consent vendor selection or integration. I review the flow you build and I do not resell a provider or take a referral fee from one. Writing your written information security programme, although I will tell you it is now required and what it has to cover. State minors codes beyond the ad surface. UK Age Appropriate Design Code work as a standalone engagement, though I mark where it bites harder than COPPA does. Who should not book this: A studio whose model needs behavioural advertising to under-13s. The amended Rule leaves a separate-consent path open and I will not build on it. The parental consent rate required makes the revenue model fiction, and the downside is real money: Epic paid 275 million dollars in 2022 and Microsoft 20 million in 2023. In a child-directed app the build I will sign is contextual, with rewarded video filled contextually. If that is not enough revenue, the audience is the problem and no amount of compliance work will fix it.

Scope

Target market
Worldwide, United States, France
Working language
English, French
Industry
Gaming, Mobile apps, Education and edtech, Kids and family
Engagement model
Audit only
Turnaround
2 weeks
Seller type
Fractional executive

What the seller needs from you

  1. 1Which store builds should I test, and can you supply a signed production artefact?
  2. 2List every ad, analytics, attribution and crash SDK you believe is in the build.
  3. 3What audience evidence do you hold?
  4. 4Is there an age screen today, and what happens on each branch?

Asked at checkout. Delivery time starts once you answer, not when you pay.

Reviews

No reviews on this service yet.

Reviews appear only after an order completes, and both sides review each other. Nothing here is seeded or bought.

Other sellers offering children's privacy (coppa) ad review

See all →

Starting at €6,500